Technical audit · 2026-05-29

bmv.de

German Federal Ministry for Digital and Transport

Federal Ministry for Digital and Transport. 32 requests, 2 domains. etracker loads without a banner, based on Art. 6(1)(e) + a Do-Not-Track opt-out. etracker GmbH is a Hamburg-based company; data stays in Germany. Fonts served locally. The same legal question as at ard.de: whether DNT is sufficient as an opt-out mechanism under TDDDG § 25.

Timeline of the leak

+461 ms · load
CSS, SVG logos, images — all from www.bmv.de. Fonts: font.css loads from /cae/static/bmdv/ — a local CSS file with @font-face rules.
+619 ms · JS
www.bmv.de/allInOne.js — the only JS file. A minimalist stack.
+711 ms · etracker
code.etracker.com/code/e.js — etracker Analytics. Loads without a consent banner. Response status 0 — blocked by the browser. Hamburg, Germany.

Declared versus actual

etracker — documented with Art. 6(1)(e) DSGVO and a DNT opt-out — заявлен
IP anonymization — documented — заявлен
Session cookies — documented as technisch notwendig — заявлен

Transfer timings

+711 ms code.etracker.com

etracker e.js. Blocked by the browser (status 0). Hamburg, Germany.

Detected trackers

Indicators of GDPR non-compliance

Context

BMDV (Bundesministerium für Digitales und Verkehr) is the Federal Ministry for Digital and Transport. It regulates road, rail, waterway, and air transport, as well as telecommunications and digital infrastructure. HAR: 32 requests — one of the most minimalist stacks in the series. 31 requests to www.bmv.de, 1 to code.etracker.com.

The policy takes an approach similar to ARD: etracker is used on the basis of Art. 6(1)(e) DSGVO (public interest) with no cookie banner. The opt-out mechanism is Do-Not-Track: “Wenn Sie mit der Speicherung und Auswertung dieser Daten aus Ihrem Besuch nicht einverstanden sind, dann können Sie in Ihrem Browser die Option Do-Not-Track aktivieren.” The policy describes in detail how to enable DNT in Chrome, Firefox, Internet Explorer, Safari, and Opera.

The problem with DNT as an opt-out mechanism is twofold. First, DNT is an HTTP request header the browser sends to the server, but which the site can simply ignore; it is not a technically binding mechanism. Second, TDDDG § 25 requires active prior consent — the user must express consent before data processing begins, rather than configure their browser in the hope that the site will honor that setting. The BfDI has repeatedly pointed out that DNT is not a sufficient substitute for an active consent banner.

etracker — a German company

etracker GmbH (Hamburg, founded 2000) is a German analytics platform that positions itself as a GDPR-compliant alternative to Google Analytics. Data is stored in Germany; there is no transatlantic transfer. This is a fundamental difference from most violations found in the Irish series: the data does not leave Germany. Nonetheless, TDDDG § 25 makes no exception for national providers.

etracker loads with a response status of 0 and a response time of 0 ms — the request was blocked by the audit browser’s content blocker (uBlock Origin or similar), not by any consent mechanism on the site. The request to code.etracker.com was nonetheless initiated — the JS code executed and dispatched the request to the external server. The browser-level blocker intercepted it after initiation.

Conclusion

bmv.de takes the same legal approach as ard.de, but with etracker instead of Piano Analytics: analytics with no banner, based on public interest, with DNT as the opt-out. The architecture is minimalist (32 requests, 2 domains), fonts are local, and data stays in Germany. The open legal question — whether DNT is sufficient as an opt-out mechanism under TDDDG § 25 — remains a subject of debate between German state authorities and data protection supervisory bodies.

Evidence
Original (audit)
HAR file: de/bmv-de-2026-05-29.har
SHA-256: 859ccc44f328fe18c385891e814b3367d2860907f1f40d57b7cc5d62f8f157d5
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Federal Commissioner for Data Protection (BfDI)file a complaint online →

To: Federal Commissioner for Data Protection (BfDI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website bmv.de.

2. Circumstances
I visited the website bmv.de and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) etracker (code.etracker.com/code/e.js) loads at +711 ms with no cookie banner and no user consent. The policy applies Art. 6(1)(e) DSGVO (public interest) as its legal basis and offers the browser's Do-Not-Track (DNT) signal as an opt-out mechanism. Per the EDPB and BfDI's position, DNT is not a sufficient consent mechanism under TDDDG § 25: consent must be active and must precede data processing, rather than relying on a browser setting. A response status of 0 (request blocked by the browser) means etracker was initiated but intercepted by a content blocker.

Full technical documentation is published at: https://gdpru.eu/en/audits/de-bmv-de/

3. Provisions violated
GDPR Art. 7; TDDDG § 25

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]