Technical audit · 2026-06-15

rik.cy

Cyprus Broadcasting Corporation

The site of Cyprus's public broadcaster — 94 requests, nine hosts, 60 outbound requests. A consent-management platform is installed on the site, but Google's counter is written into the markup 1,606 lines above it and is requested nine milliseconds earlier. The client identifier is created during the capture itself, on the first visit, and at 1388 ms went out to Google along with screen resolution and client hints. The policy's cookie section names no recipients and refers the user to browser settings and two advertising trade bodies.

Timeline of the leak

+0…+22 ms · entry via the old domain
A request to cybc.com.cy, two redirects — to a secured connection and then to rik.cy. The main domain is served via Cloudflare, from a processing node in Tallinn.
+313 ms · homepage
The document from rik.cy. Among protective headers, a restriction on being embedded in a frame from an external source and a same-origin referrer policy are set. The site does not set its own Content-Security-Policy header. The browser sent a DNT: 1 header.
+551 ms · counter beats the banner
www.googletagmanager.com/gtag/js?id=G-824TYMK4KN. The initiator is parsing of the main document's markup, line 106.
+552…+558 ms · media from external hosts
Fifty requests to three Divio hosts: cybc-live-…aldryn-media.com, riknews-live-…divio-media.org, riksports-live-…divio-media.org. Channel logos, program covers, news illustrations. In parallel, five requests to i.vimeocdn.com for video thumbnails.
+1388 ms · data transmission to Google
region1.google-analytics.com/g/collect, a page_view event: client identifier, screen resolution of 1536x864, the Windows platform, x86/64 architecture, a list of browser versions, interface language ru, the address https://rik.cy/, and the page title. Markers of a first visit, a new visitor, and a session start are set.
+2167…+2337 ms · Cloudflare device-signal collection
Redirect to /cdn-cgi/challenge-platform/h/g/scripts/jsd/…/main.js, followed by a POST to the same platform's internal path. An automated-request detection mechanism, running via the first party.

Declared versus actual

Cookies are used to facilitate navigation and visitor convenience — заявлен
The browser may accept these cookies automatically; declining or deleting them can be done via the browser's help documentation — заявлен
Session and persistent cookies are used; persistent ones so the site can recognize the visitor — заявлен
IP addresses, browser type, internet service provider, entry and exit pages, operating system, date and time are automatically collected — заявлен
This information does not identify users and is used to analyze trends and gather aggregated demographic information — заявлен
The corporation may allow third-party organizations to use cookies to provide services — заявлен
Legal bases for processing — consent, contract, legal obligation, legitimate interest; for journalistic purposes — Article 85 of the Regulation — заявлен
A commitment to carry out processing transparently, following privacy-by-design principles — заявлен
+ Google Analytics and the Google tag manager — not named — не заявлен
+ CookieScript — the consent-management platform is not named — не заявлен
+ Divio — three media hosts, accounting for more than half of all requests in the capture — не заявлен
+ Vimeo — the source of video thumbnails — не заявлен
+ Client identifier, screen resolution, and browser client hints transmitted to Google — не заявлен
+ Cloudflare's automated-request detection mechanism, which collects device signals — не заявлен

Transfer timings

+551 ms www.googletagmanager.com

gtag/js for the GA4 stream, parsed from the markup, line 106.

+552 ms aldryn-media.com

Divio media host, 30 requests.

+553 ms divio-media.org

Two Divio media hosts, 20 requests.

+554 ms i.vimeocdn.com

Vimeo video thumbnails, five requests.

+560 ms cdn.cookie-script.com

CookieScript, parsed from the markup, line 1712.

+1388 ms region1.google-analytics.com

page_view: client identifier, screen resolution, client hints, language, page address and title. First visit.

+2337 ms rik.cy/cdn-cgi/challenge-platform

POST to Cloudflare's internal path via the first party.

Detected trackers

Indicators of GDPR non-compliance

Context

rik.cy is the website of the Cyprus Broadcasting Corporation (Ραδιοφωνικό Ίδρυμα Κύπρου), the republic’s public broadcaster, registration number E2218. It publishes news, programming for four radio stations and TV channels, a sports section, and materials for the diaspora. The old address cybc.com.cy redirects here.

Scan: 94 requests, nine hosts. Thirty-four requests to the site’s own domain, 60 outbound — of which 50 go to media hosts on the Divio platform. Capture duration: 2.76 seconds; full page load completed at 2658 ms. Captured on June 15, 2026, on the homepage.

A single document — a “Privacy and Confidentiality Policy,” fourteen sections — describes the processing, with the second-to-last section devoted to the site’s operation.

Who receives data directly

Google, CookieScript, Divio, Vimeo.

Declared versus actual

The document is detailed where broadcasting activity is concerned: the roles of controller and processor are broken down, all six legal bases for processing under Article 6 are listed, journalistic processing is separately addressed with reference to Article 85, and a glossary of terms is provided. Against this backdrop, the section on the site looks like an afterthought — and it is precisely there that all the discrepancies are concentrated.

First: the counter beats the consent platform. Both lines can be read directly from the capture: the Google tag is requested via parsing of the main document’s markup, line 106; the CookieScript platform via parsing of the same markup, line 1712. There are fifteen hundred lines between them, and in loading order this translates to nine milliseconds: the counter at +551 ms, the platform at +560 ms.

The difference seems trivial, but it’s fundamental. A consent-management platform only makes sense when it stands ahead of what it manages. Here it stands after — and by the time it appears, the browser has already requested the Google counter.

What follows is the very thing the counter is set up for. At +1388 ms, a pageview event goes out with a client identifier, screen resolution of 1536x864, the Windows platform, bitness and architecture, a full list of browser versions, interface language, the page address, and its title.

Second: the identifier was created right in this capture. Usually a caveat is needed that the identifier might have originated from an earlier visit. No such caveat is needed here. The request carries markers of a first visit, a new visitor, and a session start, and the timestamp embedded within the identifier itself points to 09:25:20 — one second after the capture’s first request, made at 09:25:19. The identifier was created before the scan’s own eyes, before any user choice.

Third: not a single recipient named. The cookie section contains a single sentence about third parties: the corporation may allow third-party organizations to use cookies to provide services. Neither Google, CookieScript, Divio, nor Vimeo is named.

Divio deserves separate mention, since it accounts for more than half of all requests in the capture. Three hosts — cybc-live-…aldryn-media.com for the main site, riknews-live-…divio-media.org for news, and riksports-live-…divio-media.org for sports — serve channel logos, program covers, and news illustrations: 50 requests. The domains belong to the Divio platform (formerly Aldryn), on which the site is built. Formally, this is the broadcaster’s own infrastructure, but the domains are external, and the visitor’s IP address along with the referrer goes out to them on every page load. The platform is not mentioned in the documents.

Fourth: the declared non-identifiability. The policy describes automatically collected information and concludes by stating that this information does not identify users and serves to analyze trends and aggregated demographics. This statement relates to server logs — and with respect to those it may be accurate. But a user reading the section on the site’s operation comes away with a general impression that they are not being tracked by name. A client identifier, created on the first visit and retained for recognition on subsequent ones, contradicts that impression. All the more so since, three paragraphs earlier, the same document states outright that persistent cookies are needed so the site can recognize the visitor.

Fifth: where users are sent for settings. The section states that the browser may accept cookies automatically, and suggests consulting the browser’s help documentation if the user wants to decline them. Nothing is said about the consent platform installed on the site itself. For further information, the document links to two sources — the European Interactive Digital Advertising Alliance and the Internet Advertising Bureau. Both are advertising-industry trade bodies; for a public broadcaster, the choice of source to which readers are directed for explanations of their rights looks, at minimum, unexpected.

Separately worth noting is the Cloudflare mechanism: at +2167 ms, a redirect occurs to the internal path /cdn-cgi/challenge-platform, followed by a POST with a body at +2337 ms. This is automated-request detection, running via the first party — no external domain is visible in the address bar. It is not described in the documents.

Proven: the consent platform is installed, but loads after the counter. Both markup line numbers are recorded in the capture: 106 for the Google tag, 1712 for the platform. The order of requests confirms this — +551 ms versus +560 ms.

Proven: the counter’s loading does not depend on the user’s choice. The tag is written directly into the HTML and executes during its parsing; there is no condition preceding it, and by its very construction it cannot wait for a choice. This claim is verified by the initiator and does not depend on whether anyone clicked a button in the banner.

Proven: no choice was made in this session, and the identifier was created during the capture. There is not a single request across all 94 recording a user decision. Markers of a first visit and a session start are set in the GA4 request itself, and the timestamp embedded within the identifier falls in the second second of the capture.

Not proven and not required: whether the banner was displayed on screen. Response bodies have been stripped from the published file, so the platform’s visual state cannot be reconstructed from it. This is immaterial to the conclusion: the counter does not depend on the platform in any case.

Separately: the browser sent a DNT: 1 header during the capture. This had no effect on the composition or volume of the transmissions. The GA4 request carries markers of non-personalized advertising and Digital Markets Act mode — the advertising component is limited; this does not affect the analytics transmission carrying the client identifier.

Limits of observation

The scan covers a single page — the homepage — in a single state. The observation records browser behavior, not the internal workings of the services: server-side processing, contractual relationships with recipients, and the services’ own settings on their owners’ side are not verified by a browser-based scan. Legal assessment falls to the competent authority — the Office of the Commissioner for Personal Data Protection.

The file is published stripped of personal data: cookie headers, response bodies, the tab header, and the analytics session identifier have been removed. The set of cookies on a device cannot be reconstructed from the published file, and no conclusion in this analysis relies on it. The fact that the analytics identifier was created rests on something else and is verified directly: the identifier, along with its timestamp and first-visit markers, was transmitted to Google in the request body visible in the file.

The Divio media hosts technically serve the broadcaster’s own content, not a third-party service. The analysis records not their purpose, but the fact that they are external domains receiving the visitor’s IP address and referrer, and that they are not described in the documents.

Identification of services relies on domains, address patterns, and response headers: Google — via googletagmanager.com and google-analytics.com with a stream identifier; CookieScript — via cdn.cookie-script.com; Divio — via aldryn-media.com and divio-media.org with a characteristic project-naming pattern; Vimeo — via i.vimeocdn.com; the Cloudflare mechanism — via the internal path /cdn-cgi/challenge-platform and the cf-ray header.

Conclusion

Cyprus’s public broadcaster installed a consent-management platform on its site and placed it in the markup 1,606 lines below Google’s counter. In loading order, this translated to a nine-millisecond difference — enough to nullify the entire purpose of the platform: by the time it appears, the browser has already gone out for the Google tag, and 1,388 milliseconds later a client identifier went out to Google along with screen resolution, platform, a list of browser versions, and interface language. The markers within that request and the timestamp embedded within the identifier show that it was created right during the capture, in the second second of the first visit.

The policy section devoted to the site names not a single recipient — not Google, not the consent platform, not Divio (whose hosts account for more than half of all requests), not Vimeo. In place of a list, there is a sentence stating that the corporation may allow third-party organizations to use cookies. The user is directed to manage this via browser help documentation, and for explanations, is sent to the websites of two advertising trade bodies.

Remediation: move the counter tag below the consent platform in the markup and place its loading under the platform’s control; list all recipients in the policy along with the fields transmitted, including the media hosts and the consent platform; correct the claim of non-identifiability of collected information as it applies to analytics; describe, in the section on cookie management, the platform running on the site itself, and replace the references to advertising trade bodies with a pointer to the site’s own consent-withdrawal mechanism.

Evidence
Original (audit)
HAR file: cy/rik-cy-2026-06-15.har
SHA-256: 9eb187c3352b79afc03c7853c0d79c73337f9a9fb68ec37e64895e470bf08525
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Office of the Commissioner for Personal Data Protectiondataprotection.gov.cy

To: Office of the Commissioner for Personal Data Protection
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website rik.cy.

2. Circumstances
I visited the website rik.cy and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The Google Tag Manager tag is written into the homepage markup at line 106 and is requested at +551 ms. The CookieScript consent-management platform is written in at line 1712 and is requested at +560 ms — nine milliseconds after the counter it was supposed to manage. At +1388 ms, a page_view event goes out with a client identifier. Markers within the request itself confirm this is a first visit and session start, and the timestamp embedded within the identifier points to 09:25:20 — meaning the identifier was created during this very capture, one second after the page opened and before any user choice.

2) The policy's cookie section names no recipients at all. The only relevant sentence states that the corporation may allow third-party organizations to use cookies to provide services. In fact, visitor data goes to Google (the counter and tag manager), CookieScript (the consent platform), Divio (three media hosts, 50 of 94 requests), and Vimeo (video thumbnails). None of these names appears in the document.

3) The policy states that automatically collected information — IP addresses, browser type, internet service provider, entry and exit pages, operating system, date and time — does not identify users. The GA4 request transmits to Google a client identifier, screen resolution of 1536x864, the Windows platform, x86/64 architecture, a list of browser versions, interface language, page address, and page title. A client identifier by definition serves to recognize the visitor on repeat visits, and screen resolution together with client hints are fingerprinting parameters.

4) The cookie section states that the browser may accept cookies automatically, and suggests the user consult the browser's help documentation if they want to decline or delete them. The document says nothing about the consent-management platform installed on the site itself. For further information, it refers to two advertising-industry trade bodies — the European Interactive Digital Advertising Alliance and the Internet Advertising Bureau.

Full technical documentation is published at: https://gdpru.eu/en/audits/cy-rik-cy/

3. Provisions violated
ePrivacy — Law 112(I)/2004, Art. 99 (in conjunction with GDPR Art. 6(1)(a)); GDPR Art. 13(1)(e) — disclosure of recipients; GDPR Art. 5(1)(a) — transparency; GDPR Art. 12(1) — accessibility of control mechanisms

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]