dihk.de
Policy changed — see what exactly · 2026-08-16 →
Federal Association of German Chambers of Industry and Commerce. 34 requests, 3 domains. CoreMedia CMS. Epilogue served locally. Cookieless etracker on Art. 6(1)(f) — before the banner. CSP-Report-Only discloses planned integrations with byside.com and coremedia.cloud. Set-Cookie — zero.
Timeline of the leak
Declared versus actual
Transfer timings
etracker web analytics. etracker GmbH, Hamburg. Art. 6(1)(f). Cookieless.
etracker /cntcc tracking pixel. pagename transmitted.
Detected trackers
- etracker (code.etracker.com, www.etracker.de) — web analytics, before the banner
Indicators of GDPR non-compliance
- GDPR Art. 5(1)(a); TDDDG § 25(1)etracker's e.js loads at +111 ms, with a tracking request to www.etracker.de/cntcc at +278 ms — with no preceding consent banner. The policy justifies this via Art. 6(1)(f) (legitimate interest) and declares a cookieless mode by default. Nonetheless, browser, URL, and user-behavior data goes to etracker with no prior choice. The policy does not reference TDDDG.
Context
DIHK (Deutscher Industrie- und Handelskammertag) is the federal association of 79 German chambers of industry and commerce, representing roughly 3.5 million businesses. CoreMedia CMS, Varnish. HAR: 34 requests, 3 domains.
etracker without a banner — Art. 6(1)(f)
At +111 ms, code.etracker.com/code/e.js loads (account ID 1BEWo9). At +178 ms — t.js with a version and account identifier. At +278 ms — www.etracker.de/cntcc, carrying the full page URL (pagename=https://www.dihk.de/) and a timestamp. There is no consent banner.
The policy declares etracker via Art. 6(1)(f) DSGVO (legitimate interest) and describes a cookieless mode by default: data is processed in Germany, and etracker is certified under the ePrivacyseal. Whether Art. 6(1)(f) can lawfully be used for web analytics without consent remains a matter of debate in supervisory practice: the DSK (Datenschutzkonferenz) has, in a number of positions, pointed to the need for consent. The policy does not reference TDDDG, which is itself a gap for the website of a German organization that uses cookies and similar technologies.
CSP-Report-Only: byside.com and coremedia.cloud
The Content-Security-Policy-Report-Only header (not enforced) allows *.engagement.coremedia.cloud and *.byside.com. byside is a LiveChat and customer engagement platform (a Portuguese company owned by Nuvei). engagement.coremedia.cloud refers to CoreMedia CMS’s cloud services. Neither domain is active in the HAR — the integrations are apparently planned or being tested. Neither is mentioned in the policy.
Epilogue — local
The Epilogue v17 typeface (Regular, Medium) — two woff2 files from /resource/crblob/. Epilogue was designed by typographer Tyler Finck (Etcetera Type Company) and is distributed via Google Fonts, yet DIHK hosts it locally. No Google Fonts.
Conclusion
www.dihk.de has one violation: etracker is active before the banner, based on legitimate interest — a legal basis that is disputed, and the policy does not reference TDDDG. The architecture is otherwise minimalist: no GTM, no advertising pixels, no external CMP.
efa15fab95ae7f4431a22cd35dcfebc8684eb90a34e197df5008c5f09b2b645aWhere to file: Federal Commissioner for Data Protection (BfDI) — file a complaint online →
To: Federal Commissioner for Data Protection (BfDI) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website dihk.de. 2. Circumstances I visited the website dihk.de and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) etracker's e.js loads at +111 ms, with a tracking request to www.etracker.de/cntcc at +278 ms — with no preceding consent banner. The policy justifies this via Art. 6(1)(f) (legitimate interest) and declares a cookieless mode by default. Nonetheless, browser, URL, and user-behavior data goes to etracker with no prior choice. The policy does not reference TDDDG. Full technical documentation is published at: https://gdpru.eu/en/audits/de-dihk-de/ 3. Provisions violated GDPR Art. 5(1)(a); TDDDG § 25(1) 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]