Policy changed — see what exactly · 2026-08-21 →
Federal Ministry of the Interior. 112 requests, 3 domains — all state-owned. social.bund.de — a state Mastodon server. multimedia.gsb.bund.de — a state media server. ReadSpeaker — 10 files served locally. Matomo opt-in via the matomoTracking cookie. No tracking appears in the HAR. Full compliance.
Timeline of the leak
Declared versus actual
Transfer timings
Federal bodies' Mastodon server. social.bund.de. State infrastructure.
GSB media server. twemoji emoji. State infrastructure.
Context
BMI (Bundesministerium des Innern und für Heimat) is the Federal Ministry of the Interior, overseeing Bundespolizei, BKA, BfV, BBK, BAMF, and other agencies covered in this series. Responsible for internal security, migration, civil protection, and constitutional order. HAR: 112 requests, 3 domains.
social.bund.de — state Mastodon
BMI’s homepage displays a feed of posts from the ministry’s Mastodon account. social.bund.de is the state Fediverse server, operated within the bund.de infrastructure. Three requests: BMI’s account avatar, an image attachment to a post, a thumbnail image. This is not a third-party service: social.bund.de sits within state infrastructure, just like www.bmi.bund.de. The data transfer is between state servers. The policy contains a Social Media section but does not mention social.bund.de as a distinct technical recipient of data when the homepage loads.
multimedia.gsb.bund.de — Government Site Builder
multimedia.gsb.bund.de is the media server of Government Site Builder, the central CMS platform for federal bodies. One request: a twemoji emoji 👉 (1f449.png). Technically, this is the same state infrastructure as www.bmi.bund.de. Not explicitly mentioned in the policy.
ReadSpeaker — a fully self-hosted implementation
BMI goes further than BBK: ReadSpeaker is hosted not as a single JS file, but as a complete package of 10 files: Core.js, PlayerAPI.js, HL.js, ui.js, Config.js, Facade.js, Styles.css, Common.Settings.js, pub.Config.js, Customization.js — all served from www.bmi.bund.de/static/readspeaker/. Not a single request to external ReadSpeaker servers on page load. The IP address is transmitted only when “Vorlesen” is clicked — exactly as documented in the policy.
Matomo — opt-in via the matomoTracking cookie
The policy describes the mechanism in detail: the cookieBannerClosed cookie records that the banner was interacted with, and matomoTracking (value true/false) records the user’s statistics choice. “Nur dann wird das Javascript von Matomo geladen und ermöglicht statistische Auswertungen.” There are no Matomo requests in the HAR — consent has not been given, and the analytics tool is not activated.
Conclusion
bmi.bund.de is the eighth zero result in the German series. The ministry that oversees most of the agencies covered in this series reproduces the same standard: state hosting, local fonts, ReadSpeaker with no external calls, and Matomo with correct opt-in. The two additional domains (social.bund.de, multimedia.gsb.bund.de) are state infrastructure, not third-party services. Using a state-run Mastodon server instead of Twitter/X for the social widget is a deliberate choice in favor of infrastructural independence.
30c5e2d9c85cd3211e5014069aab8d2983f009421b1354ac8adbc234b33372eb