holcim.at
Holcim Austria — 63 requests, 8 domains. GTM and GA4 start before consent. Google Fonts — 8 requests to Google (USA) without consent. The Elfsight widget is not declared. A CMP module is present in the code, but it blocks nothing.
Timeline of the leak
Declared versus actual
Transfer timings
8 requests. Google (USA) receives the IP address without consent.
GTM without consent.
GA4 tracking ping before consent.
Detected trackers
- Google Analytics 4 (G-NLF2NM0R7E)
- Google Tag Manager (GTM-TWQSH47V)
- Google Fonts (fonts.googleapis.com)
- Elfsight (static.elfsight.com)
Indicators of GDPR non-compliance
- GDPR Art. 6(1)(a), TKG § 165GTM loads at 145 ms, GA4 sends a tracking ping at 1535 ms — before any consent. eu_cookie_compliance (a Drupal CMP) is present in the code but does not block trackers.
- GDPR Art. 44 ff.Google Fonts loads 8 times from fonts.googleapis.com (Google servers, USA) without consent. The IP address is transmitted to the USA on every visit.
- GDPR Art. 13Elfsight (static.elfsight.com, core.service.elfsight.com) loads and pings without consent. Not mentioned in the privacy policy.
Context
Holcim (Österreich) GmbH is the Austrian subsidiary of the Swiss group Holcim (cement, concrete, building materials). The site runs on Drupal. HAR: 63 requests, 8 domains.
A CMP is present, but no blocking
The site has the Drupal eu_cookie_compliance module installed — its CSS and JS are visible in the HAR. But GTM loads at +145 ms — before any banner could possibly have appeared. GA4 sends its ping at +1535 ms. Technically, the CMP module is present, but it is not configured as an autoblocker.
Google Fonts — 8 requests without consent
Material Icons load via fonts.googleapis.com — 8 separate requests on every page load. Each transmits the IP address to Google (USA). This is not declared in the policy.
Elfsight undeclared
static.elfsight.com and core.service.elfsight.com — a widget platform (most likely social feeds or reviews). Loads and pings with the page URL. Not mentioned in the privacy policy.
Conclusion
A CMP is installed — but it functions as a notice rather than a blocker. GTM, GA4, Google Fonts, and Elfsight all run before consent. This is a typical picture for a Drupal site with a GDPR-compliance module that isn’t actually wired up to block trackers.
0f4cffb8e88cf1de59452fdb90f769d1cd78211d717964aa7d984d96a271b072Where to file: Datenschutzbehörde (DSB) — file a complaint online →
To: Datenschutzbehörde (DSB) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website holcim.at. 2. Circumstances I visited the website holcim.at and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 26 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) GTM loads at 145 ms, GA4 sends a tracking ping at 1535 ms — before any consent. eu_cookie_compliance (a Drupal CMP) is present in the code but does not block trackers. 2) Google Fonts loads 8 times from fonts.googleapis.com (Google servers, USA) without consent. The IP address is transmitted to the USA on every visit. 3) Elfsight (static.elfsight.com, core.service.elfsight.com) loads and pings without consent. Not mentioned in the privacy policy. Full technical documentation is published at: https://gdpru.eu/en/audits/at-holcim-at/ 3. Provisions violated GDPR Art. 6(1)(a), TKG § 165; GDPR Art. 44 ff.; GDPR Art. 13 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]