Technical audit · 2026-05-26

oeaw.ac.at

Austrian Academy of Sciences

Austrian Academy of Sciences — 65 requests, 4 domains. Self-hosted Piwik and Cloudflare Insights fire without consent and without declaration in the policy. Cloudflare — data goes to the USA with no legal basis stated.

Timeline of the leak

+1049 ms · Cloudflare email-decode
Cloudflare's email-decode.min.js script loads from www.oeaw.ac.at (a self-hosted copy).
+1054 ms · Cloudflare Insights
static.cloudflareinsights.com/beacon.min.js — an external request without consent. Data goes to Cloudflare (USA).
+1826 ms · Piwik
piwik.oeaw.ac.at/piwik.js — self-hosted Piwik. Without consent.
+2867 ms · tracking ping
piwik.php: action_name=Österreichische Akademie der Wissenschaften, idsite=1. Before consent.
Session total
65 requests. 60 — www.oeaw.ac.at, 2 — piwik.oeaw.ac.at, 2 — oeaw.ac.at (redirects), 1 — cloudflareinsights.com.

Declared versus actual

+ Piwik/Matomo — absent from the policy — not declared
+ Cloudflare Insights — absent from the policy, data sent to the USA — not declared

Transfer timings

+1054 ms static.cloudflareinsights.com

Cloudflare Insights beacon. Data goes to the USA, legal basis not declared.

+1826 ms piwik.oeaw.ac.at

Self-hosted Piwik. Data stays within ÖAW's infrastructure.

+2867 ms piwik.oeaw.ac.at

Tracking ping: idsite=1, without consent.

Detected trackers

Indicators of GDPR non-compliance

Context

ÖAW (Österreichische Akademie der Wissenschaften) is Austria’s principal academy of sciences, founded in 1847, comprising around 60 research institutes. HAR: 65 requests, 4 domains.

Two trackers, zero declarations

Self-hosted Piwik on piwik.oeaw.ac.at — data stays within the academy’s infrastructure. Cloudflare Insights (static.cloudflareinsights.com) — data goes to Cloudflare Inc. (USA). Both fire without consent. The privacy policy is a general document on data subject rights and processing principles, and says nothing about the site’s web analytics.

Cloudflare Insights — undeclared transfer to the USA

Cloudflare Insights is used as a performance and analytics tool. In doing so, beacon.min.js loads from Cloudflare’s external domain, and the data is processed on Cloudflare’s servers in the USA. Neither a legal basis for this processing nor a third-country transfer mechanism (SCC, DPF) is stated in the policy.

Conclusion

An academy that researches, among other things, questions of law and ethics sends data to two trackers without consent — one on its own infrastructure, one in the USA — and mentions neither of them in its privacy policy.

Evidence
Original (audit)
HAR file: at/oeaw-ac-at-2026-05-26.har
SHA-256: 93b46144d5837c9d3d6eb8d9a67f977b622dec398742f2d658be1376f7fda230
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Datenschutzbehörde (DSB)file a complaint online →

To: Datenschutzbehörde (DSB)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website oeaw.ac.at.

2. Circumstances
I visited the website oeaw.ac.at and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 26 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) Piwik loads at 1826 ms and sends a tracking ping at 2867 ms without consent. The privacy policy does not mention web analytics, Piwik, or Cloudflare Insights.

2) Cloudflare Insights (static.cloudflareinsights.com) loads at 1054 ms. Data is transmitted to Cloudflare Inc. (USA). Neither the legal basis nor the third-country transfer mechanism is declared.

Full technical documentation is published at: https://gdpru.eu/en/audits/at-oeaw-ac-at/

3. Provisions violated
GDPR Art. 6(1)(a), Art. 13, TKG § 165; GDPR Art. 44 ff.

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]