Technical audit · 2026-05-26

holcim.at

Austrian Subsidiary of the Global Building Materials Manufacturer

Holcim Austria — 63 requests, 8 domains. GTM and GA4 start before consent. Google Fonts — 8 requests to Google (USA) without consent. The Elfsight widget is not declared. A CMP module is present in the code, but it blocks nothing.

Timeline of the leak

+109 ms · Google Fonts
fonts.googleapis.com — 8 CSS requests for Material Icons. IP address transmitted to Google (USA) without consent.
+114 ms · Elfsight
static.elfsight.com/platform/platform.js loads. Not declared in the policy.
+145 ms · GTM
www.googletagmanager.com/gtm.js?id=GTM-TWQSH47V — Google Tag Manager loads before consent.
+797 ms · OpenStreetMap
tile.openstreetmap.org — 9 map tiles. IP address transmitted to OSM infrastructure.
+922 ms · GA4
Google Analytics 4 (G-NLF2NM0R7E) loads via GTM.
+1027 ms · Elfsight ping
core.service.elfsight.com — widget registration with the page URL.
+1535 ms · GA4 ping
region1.google-analytics.com — GA4 tracking ping before consent.

Declared versus actual

Google Analytics / GTM — mentioned in the policy, appear in the HAR before consent — заявлен
Matomo — declared with consent, absent from the HAR — заявлен
OpenStreetMap — mentioned indirectly for maps — заявлен
+ Elfsight — absent from the policy — не заявлен
+ Google Fonts — loading from googleapis.com is not mentioned in the policy — не заявлен

Transfer timings

+109 ms fonts.googleapis.com

8 requests. Google (USA) receives the IP address without consent.

+145 ms www.googletagmanager.com

GTM without consent.

+1535 ms region1.google-analytics.com

GA4 tracking ping before consent.

Detected trackers

Indicators of GDPR non-compliance

Context

Holcim (Österreich) GmbH is the Austrian subsidiary of the Swiss group Holcim (cement, concrete, building materials). The site runs on Drupal. HAR: 63 requests, 8 domains.

A CMP is present, but no blocking

The site has the Drupal eu_cookie_compliance module installed — its CSS and JS are visible in the HAR. But GTM loads at +145 ms — before any banner could possibly have appeared. GA4 sends its ping at +1535 ms. Technically, the CMP module is present, but it is not configured as an autoblocker.

Material Icons load via fonts.googleapis.com — 8 separate requests on every page load. Each transmits the IP address to Google (USA). This is not declared in the policy.

Elfsight undeclared

static.elfsight.com and core.service.elfsight.com — a widget platform (most likely social feeds or reviews). Loads and pings with the page URL. Not mentioned in the privacy policy.

Conclusion

A CMP is installed — but it functions as a notice rather than a blocker. GTM, GA4, Google Fonts, and Elfsight all run before consent. This is a typical picture for a Drupal site with a GDPR-compliance module that isn’t actually wired up to block trackers.

Evidence
Original (audit)
HAR file: at/holcim-at-2026-05-26.har
SHA-256: 0f4cffb8e88cf1de59452fdb90f769d1cd78211d717964aa7d984d96a271b072
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Datenschutzbehörde (DSB)file a complaint online →

To: Datenschutzbehörde (DSB)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website holcim.at.

2. Circumstances
I visited the website holcim.at and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 26 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) GTM loads at 145 ms, GA4 sends a tracking ping at 1535 ms — before any consent. eu_cookie_compliance (a Drupal CMP) is present in the code but does not block trackers.

2) Google Fonts loads 8 times from fonts.googleapis.com (Google servers, USA) without consent. The IP address is transmitted to the USA on every visit.

3) Elfsight (static.elfsight.com, core.service.elfsight.com) loads and pings without consent. Not mentioned in the privacy policy.

Full technical documentation is published at: https://gdpru.eu/en/audits/at-holcim-at/

3. Provisions violated
GDPR Art. 6(1)(a), TKG § 165; GDPR Art. 44 ff.; GDPR Art. 13

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]