Policy changed — see what exactly · 2026-07-11 →
Docmorris.de — the website of DocMorris, a major online pharmacy. Homepage measurement: 146 requests, 12 domains; the session entered via a redirect from docmorris.nl to docmorris.de. The site has a full consent banner on the consentmanager platform, and in many respects it is set up correctly: tag-collector containers (a primary domain, measure.docmorris.de, layered over Google Tag Gateway, plus a standard Google Tag Manager) load, but neither Google analytics, nor Criteo, nor advertising pixels deploy in the clean session — Criteo is merely allowed in the CSP and held behind consent. Before the banner interface renders (15956 ms), two marketing items fire: the Exactag attribution library (5380 ms, which the pharmacy itself classifies as consent-based processing) and a beacon request to a third-party, unidentified domain, spapi.io (7630 ms). Both purposes are marketing-related and fire before the user's choice.
Timeline of the leak
Declared versus actual
Detected trackers
- Exactag (marketing attribution, before consent)
- Third-party tracker spapi.io (before consent, vendor not identified)
- Google Tag Manager / Google Tag Gateway (container loaded, tags not deployed)
- consentmanager (consent mechanism)
- Criteo (allowed in the CSP, held behind consent — did not fire)
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR (and § 25 TDDDG/TTDSG) — marketing attribution and a third-party tracker fire before consentThe site has a fully functioning consent mechanism (the consentmanager platform), and the pharmacy's own documentation classifies marketing tools, including Exactag, as processing based on consent (Art. 6(1)(a) GDPR). However, in a clean session with no consent given, the Exactag marketing-attribution library loads at 5380 ms — before the consent banner has even had time to render (the banner interface appears at 15956 ms). Exactag's purpose is to measure the user journey and conversions (touchpoints, views, on-site events) — a non-technical, marketing purpose. In addition, at 7630 ms, a beacon request goes to a third-party domain: the payload is encoded directly in the request address (address length — 1087 characters), with docmorris.de as the source; this tracker's vendor is not publicly identified and is not named in the site's policy. The fact that heavier tools (Google analytics, Criteo, advertising pixels) did not deploy works in the site's favor, but does not resolve the issue: marketing attribution and a third-party beacon contact third parties before the user's choice, contrary to the very basis (consent) the pharmacy itself relies on.
Context
www.docmorris.de is the website of DocMorris, one of Europe’s largest online pharmacies (medication and health-product delivery, a personal account, a loyalty program). Data controllers: DocMorris N.V. and DocMorris Services B.V. (Heerlen, Netherlands); the site serves a German audience under the .de domain. Given that this is a pharmacy, the sensitivity of the context is high.
Measurement: 146 requests to 12 domains, homepage, captured on a clean browser with no VPN and no blocker. The session entered via a redirect from www.docmorris.nl to www.docmorris.de — which explains the Dutch domain appearing in the list. The site has its own consent mechanism on the consentmanager platform.
Who receives the data
Directly, before consent: Exactag, the third-party tracker spapi.io.
Exactag is marketing attribution: measuring touchpoints, views, on-site events, and conversions across the user journey. Its library loads at 5380 ms, before the banner interface renders (15956 ms). spapi.io is a third-party domain to which, at 7630 ms, a beacon request goes carrying a visit-linked payload (request address length — 1087 characters); the vendor could not be publicly identified and is not named in the site’s policy.
Tag-collector containers (the primary subdomain measure.docmorris.de layered over Google Tag Gateway, plus a standard Google Tag Manager) load, but do not deploy commercial trackers: there is neither Google analytics nor advertising traffic in this session. Criteo is allowed in the CSP header, but is held behind consent and did not fire. On the functional side: the chat-assistant widget (Zowie), declared in the policy.
Was there a consent banner
Yes, a full banner on the consentmanager platform is present, and in many respects it is set up correctly: the bulk of commercial tools are held behind it. The consent platform script loads at 5818 ms, the banner interface renders at 15956 ms, and the decision is recorded at 40255 ms (a request to consent.php).
The key point is that some marketing activity fired before the banner: by the time its interface rendered (15956 ms), the Exactag library (5380 ms) and the third-party beacon (7630 ms) had already gone out to the network.
What fires before consent
Before the banner renders and before any consent, the following fire:
- Exactag marketing attribution (5380 ms) — loading of a user-journey measurement library;
- a beacon request to the third-party domain spapi.io (7630 ms) — carrying a visit-linked payload;
- tag-collector containers — they load, but do not deploy commercial tags in this session;
- the Zowie chat assistant (8315 ms) — a functional support service.
The tag containers and the chat widget raise no concerns: the former deployed nothing without consent, and the latter is functional and declared. The issue lies with Exactag and the third-party beacon: these are marketing, non-technical purposes, and they contact third parties before the user’s choice.
Why “the container loaded” is not yet a violation, but Exactag already is
This distinction matters. Loading a tag-collector container is, on its own, neutral: if it deployed neither analytics, nor advertising, nor pixels without consent — there is no issue, and that is the case here. So Google Tag Manager, in this measurement, is not counted as a violation.
Exactag is different. It is not a container, but a specific marketing tool with its own purpose — measuring the journey and conversions. DocMorris’s own documentation classifies marketing tools, including Exactag, as processing based on consent (Art. 6(1)(a) GDPR). Launching such a library before consent contradicts that stated basis. Compounding this is the third-party beacon to spapi.io, which is not named in the policy at all — worsening the transparency issue as well.
Conclusion
Docmorris.de is, on the whole, a case of disciplined configuration with one leak at the marketing level. Much works in the site’s favor: a full consent banner is present, Google analytics, Criteo, and advertising pixels do not deploy in the clean session, and Criteo is held behind consent. But the Exactag marketing-attribution library (5380 ms) and the beacon to the unidentified third-party domain spapi.io (7630 ms) fire before the banner interface renders (15956 ms), and before any consent. The key takeaway: switching marketing attribution and the third-party beacon into consent-gated mode — the same way this has already been done for Google analytics and Criteo — would make the configuration clean for a pharmacy operating in a sensitive context.
e1abf7637d90e8e91695c3184b29760190616e1a7674bfce48e38001234030ccWhere to file: Federal Commissioner for Data Protection (BfDI) — file a complaint online →
To: Federal Commissioner for Data Protection (BfDI) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website docmorris.de. 2. Circumstances I visited the website docmorris.de and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 23 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site has a fully functioning consent mechanism (the consentmanager platform), and the pharmacy's own documentation classifies marketing tools, including Exactag, as processing based on consent (Art. 6(1)(a) GDPR). However, in a clean session with no consent given, the Exactag marketing-attribution library loads at 5380 ms — before the consent banner has even had time to render (the banner interface appears at 15956 ms). Exactag's purpose is to measure the user journey and conversions (touchpoints, views, on-site events) — a non-technical, marketing purpose. In addition, at 7630 ms, a beacon request goes to a third-party domain: the payload is encoded directly in the request address (address length — 1087 characters), with docmorris.de as the source; this tracker's vendor is not publicly identified and is not named in the site's policy. The fact that heavier tools (Google analytics, Criteo, advertising pixels) did not deploy works in the site's favor, but does not resolve the issue: marketing attribution and a third-party beacon contact third parties before the user's choice, contrary to the very basis (consent) the pharmacy itself relies on. Full technical documentation is published at: https://gdpru.eu/en/audits/de-docmorris-de/ 3. Provisions violated Art. 6(1)(a) GDPR (and § 25 TDDDG/TTDSG) — marketing attribution and a third-party tracker fire before consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]