bmwsb.bund.de
Policy changed — see what exactly · 2026-08-06 →
Federal Ministry for Housing, Urban Development and Building. 50 requests, 2 domains. GSB platform, Apache. BundesSchrift v3 and Fira Sans served locally. The Instagram CDN loads before the banner, without consent. The policy describes Instagram as an external channel, without mentioning the embedded feed. Set-Cookie — zero.
Timeline of the leak
Declared versus actual
Transfer timings
Meta / Instagram CDN. Düsseldorf edge. Six feed images. Before the banner.
Detected trackers
- Meta / Instagram CDN (scontent-dus1-1.cdninstagram.com) — Instagram feed images without consent
Indicators of GDPR non-compliance
- GDPR Art. 5(1)(a); TDDDG § 25(1)scontent-dus1-1.cdninstagram.com loads six images from BMWSB's Instagram account (+250–251 ms) — before the GSB cookie banner (+564 ms). The visitor's IP address is transmitted to Meta Platforms' servers in the USA on every page load. The privacy policy describes Instagram solely as an external channel and does not mention the embedded Instagram feed on the site's homepage.
Context
BMWSB (Bundesministerium für Wohnen, Stadtentwicklung und Bauwesen) is the Federal Ministry for Housing, Urban Development, and Building. GSB platform, Apache. HAR: 50 requests, 2 domains.
Instagram CDN before the banner — the policy does not describe the embedding
At +250 ms, six JPEG images from BMWSB’s Instagram feed load from scontent-dus1-1.cdninstagram.com (Meta CDN, Düsseldorf data center). The GSB cookie banner appears at +564 ms — the Instagram CDN beats it by ~314 ms. The visitor’s IP address is transmitted to Meta’s servers on every homepage visit.
BMWSB’s privacy policy contains a Social Media section describing Instagram as an external channel that users manage on their own responsibility: “Nutzerinnen und Nutzer nutzen diese Dienste in eigener Verantwortung.” The embedding of an Instagram feed directly on the ministry’s homepage is not mentioned in the policy — a substantial discrepancy between the declared and actual behavior.
BundesSchrift v3 and Fira Sans — local
BundesSansWeb v3-014 (Regular, Italic, Bold) and FiraSans v4-301 Regular — four woff files from /static/fonts/. No Google Fonts.
CSP — a rich stack for internal pages
The Content-Security-Policy permits *.intercom.io and js.intercomcdn.com (Intercom — support chat), *.castr.com (video streaming), *.newsletter2go.com (newsletters), multiplatform-f.akamaihd.net (Akamai CDN), hls-hd.myrasec.de (Myra Security). None of these are active on the homepage.
Conclusion
www.bmwsb.bund.de violates TDDDG §25(1): the Instagram CDN loads before the consent banner. The privacy policy describes Instagram only as an external channel, without disclosing the fact that a feed is embedded on the homepage.
7853ab424a383f7aeaf5a9a5bb1eeae3fd3a3127e7b88fd0c10733085ff4df1bWhere to file: Federal Commissioner for Data Protection (BfDI) — file a complaint online →
To: Federal Commissioner for Data Protection (BfDI) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website bmwsb.bund.de. 2. Circumstances I visited the website bmwsb.bund.de and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) scontent-dus1-1.cdninstagram.com loads six images from BMWSB's Instagram account (+250–251 ms) — before the GSB cookie banner (+564 ms). The visitor's IP address is transmitted to Meta Platforms' servers in the USA on every page load. The privacy policy describes Instagram solely as an external channel and does not mention the embedded Instagram feed on the site's homepage. Full technical documentation is published at: https://gdpru.eu/en/audits/de-bmwsb-bund-de/ 3. Provisions violated GDPR Art. 5(1)(a); TDDDG § 25(1) 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]