Technical audit · 2026-05-29

dihk.de

Federal Association of German Chambers of Industry and Commerce

Federal Association of German Chambers of Industry and Commerce. 34 requests, 3 domains. CoreMedia CMS. Epilogue served locally. Cookieless etracker on Art. 6(1)(f) — before the banner. CSP-Report-Only discloses planned integrations with byside.com and coremedia.cloud. Set-Cookie — zero.

Timeline of the leak

+0 ms · homepage
www.dihk.de/ — CoreMedia CMS, Varnish cache (x-cae: cae-live-0-0). CSP-Report-Only (not enforced): allows *.engagement.coremedia.cloud and *.byside.com — inactive in the HAR.
+110 ms · styles
dihk-relaunch CSS bundles — local.
+111 ms · etracker
code.etracker.com/code/e.js — loads at the same time as the styles. Followed at +178 ms by t.js?et=1BEWo9 (account ID). At +278 ms — www.etracker.de/cntcc — a tracking pixel carrying pagename=https://www.dihk.de/.
+138 ms · fonts
Epilogue v17 (Regular, Medium/500) — two woff2 files from /resource/crblob/, local. No Google Fonts.

Declared versus actual

etracker — declared, Art. 6(1)(f), cookieless by default, processing in Germany, ePrivacyseal — заявлен
YouTube (enhanced privacy mode) — declared for videos on internal pages — заявлен
Social media (Facebook, Instagram, X, LinkedIn, Spotify, YouTube) — static links in the footer only — заявлен

Transfer timings

+111 ms code.etracker.com

etracker web analytics. etracker GmbH, Hamburg. Art. 6(1)(f). Cookieless.

+278 ms www.etracker.de

etracker /cntcc tracking pixel. pagename transmitted.

Detected trackers

Indicators of GDPR non-compliance

Context

DIHK (Deutscher Industrie- und Handelskammertag) is the federal association of 79 German chambers of industry and commerce, representing roughly 3.5 million businesses. CoreMedia CMS, Varnish. HAR: 34 requests, 3 domains.

etracker without a banner — Art. 6(1)(f)

At +111 ms, code.etracker.com/code/e.js loads (account ID 1BEWo9). At +178 ms — t.js with a version and account identifier. At +278 ms — www.etracker.de/cntcc, carrying the full page URL (pagename=https://www.dihk.de/) and a timestamp. There is no consent banner.

The policy declares etracker via Art. 6(1)(f) DSGVO (legitimate interest) and describes a cookieless mode by default: data is processed in Germany, and etracker is certified under the ePrivacyseal. Whether Art. 6(1)(f) can lawfully be used for web analytics without consent remains a matter of debate in supervisory practice: the DSK (Datenschutzkonferenz) has, in a number of positions, pointed to the need for consent. The policy does not reference TDDDG, which is itself a gap for the website of a German organization that uses cookies and similar technologies.

CSP-Report-Only: byside.com and coremedia.cloud

The Content-Security-Policy-Report-Only header (not enforced) allows *.engagement.coremedia.cloud and *.byside.com. byside is a LiveChat and customer engagement platform (a Portuguese company owned by Nuvei). engagement.coremedia.cloud refers to CoreMedia CMS’s cloud services. Neither domain is active in the HAR — the integrations are apparently planned or being tested. Neither is mentioned in the policy.

Epilogue — local

The Epilogue v17 typeface (Regular, Medium) — two woff2 files from /resource/crblob/. Epilogue was designed by typographer Tyler Finck (Etcetera Type Company) and is distributed via Google Fonts, yet DIHK hosts it locally. No Google Fonts.

Conclusion

www.dihk.de has one violation: etracker is active before the banner, based on legitimate interest — a legal basis that is disputed, and the policy does not reference TDDDG. The architecture is otherwise minimalist: no GTM, no advertising pixels, no external CMP.

Evidence
Original (audit)
HAR file: de/dihk-de-2026-05-29.har
SHA-256: efa15fab95ae7f4431a22cd35dcfebc8684eb90a34e197df5008c5f09b2b645a
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Federal Commissioner for Data Protection (BfDI)file a complaint online →

To: Federal Commissioner for Data Protection (BfDI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website dihk.de.

2. Circumstances
I visited the website dihk.de and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) etracker's e.js loads at +111 ms, with a tracking request to www.etracker.de/cntcc at +278 ms — with no preceding consent banner. The policy justifies this via Art. 6(1)(f) (legitimate interest) and declares a cookieless mode by default. Nonetheless, browser, URL, and user-behavior data goes to etracker with no prior choice. The policy does not reference TDDDG.

Full technical documentation is published at: https://gdpru.eu/en/audits/de-dihk-de/

3. Provisions violated
GDPR Art. 5(1)(a); TDDDG § 25(1)

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]