Technical audit · 2026-05-26

statistik.at

Austrian Federal Statistical Office

Austria's Federal Statistical Office — 27 requests, 1 domain. Zero external requests. Matomo and Google reCAPTCHA are declared in the policy — neither appeared in the HAR. The CSP permits Google, but Google stays silent.

Timeline of the leak

+444 ms · SgCookieOptin
A TYPO3 cookie-management plugin loads from www.statistik.at. No external requests.
Session total
27 requests, 1 domain. Neither Matomo nor Google reCAPTCHA appeared in the HAR.

Declared versus actual

Matomo — mentioned in the policy, no legal basis stated, absent from the HAR — заявлен
Google reCAPTCHA — mentioned in the policy, Art. 6(1)(f), absent from the HAR — заявлен

Indicators of GDPR non-compliance

Context

Statistik Austria (Bundesanstalt Statistik Österreich) is the federal statistical office, a public-law institution. HAR: 27 requests, 1 domain. The privacy policy is in English, last updated January 2026.

One domain, zero external

27 requests — all to www.statistik.at. Source Sans 3 fonts, icons, jQuery — all local. Zero cookies, zero external requests. The CSP allows *.google.com, *.gstatic.com, and *.highcharts.com — but none of them appeared in the HAR.

Matomo and reCAPTCHA — in the policy, not in the HAR

The policy mentions Matomo for “statistical analysis of access” — with no legal basis and no mention of a consent gate. SgCookieOptin (a TYPO3 plugin) loads, but Matomo was not activated on this page. Google reCAPTCHA is declared on the basis of legitimate interest (Art. 6(1)(f)) — absent from the HAR, likely used only on pages with forms.

Conclusion

In practice, this is a clean HAR — one domain, zero trackers. The policy describes tools that were not activated during this session. The weak point: Matomo is declared without a stated legal basis, which creates a gap for when it is actually activated.

Evidence
Original (audit)
HAR file: at/statistik-at-2026-05-26.har
SHA-256: d3430b1e0a2480238817afde40a532cc995bd71ba76d4f90f21df8e0929ec8a0
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Datenschutzbehörde (DSB)file a complaint online →

To: Datenschutzbehörde (DSB)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website statistik.at.

2. Circumstances
I visited the website statistik.at and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 26 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) Matomo is declared in the privacy policy without a stated legal basis. No consent gate is traceable in the HAR: SgCookieOptin loads, but Matomo did not appear in the session — possibly inactive on the current page or blocked by settings.

2) Google reCAPTCHA is declared on the basis of Art. 6(1)(f) — legitimate interest. It did not appear in the HAR, but the CSP allows *.google.com and *.gstatic.com. No legal basis for the data transfer to the USA is stated.

Full technical documentation is published at: https://gdpru.eu/en/audits/at-statistik-at/

3. Provisions violated
GDPR Art. 6(1)(a), TKG § 165; GDPR Art. 13

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]