Technical audit · 2026-06-23

docmorris.de

Website of the Online Pharmacy DocMorris

Docmorris.de — the website of DocMorris, a major online pharmacy. Homepage measurement: 146 requests, 12 domains; the session entered via a redirect from docmorris.nl to docmorris.de. The site has a full consent banner on the consentmanager platform, and in many respects it is set up correctly: tag-collector containers (a primary domain, measure.docmorris.de, layered over Google Tag Gateway, plus a standard Google Tag Manager) load, but neither Google analytics, nor Criteo, nor advertising pixels deploy in the clean session — Criteo is merely allowed in the CSP and held behind consent. Before the banner interface renders (15956 ms), two marketing items fire: the Exactag attribution library (5380 ms, which the pharmacy itself classifies as consent-based processing) and a beacon request to a third-party, unidentified domain, spapi.io (7630 ms). Both purposes are marketing-related and fire before the user's choice.

Timeline of the leak

3747 ms · primary tag container
A tag-collector container (Google Tag Gateway / server-side tagging) loads from the proprietary subdomain measure.docmorris.de. On its own, it does not yet deploy any commercial trackers.
5380 ms · Exactag marketing attribution
The Exactag library loads — a marketing-attribution and user-journey measurement tool. This is a non-technical purpose that the pharmacy's own documentation classifies as consent-based processing, and it fires before consent.
5818–5844 ms · consent mechanism and Google container
The consentmanager platform script loads (5818 ms), followed by the standard Google Tag Manager container (5844 ms). Importantly: neither Google analytics nor advertising requests fire in this session — the containers load, but the tags are not deployed.
7630 ms · third-party beacon spapi.io
A beacon request goes to the third-party domain spapi.io: the payload is encoded directly in the request address (address length — 1087 characters), with docmorris.de as the source. The vendor is not publicly identified and is not named in the site's policy. Before consent.
8315 ms · chat assistant
A chat-assistant widget (Zowie) loads — a functional support service, declared in the policy; runs in an EU cloud.
banner interface — 15956 ms, consent recorded — 40255 ms; Exactag and the third-party beacon fired earlier
A full consent banner is present: its interface renders at 15956 ms, and the decision is recorded at 40255 ms (a request to consent.php). Exactag marketing attribution (5380 ms) and the third-party beacon spapi.io (7630 ms) have already fired by this point — before the banner and before any consent.

Declared versus actual

Zowie (chat assistant) — заявлен
Criteo (held behind consent, did not fire) — заявлен
Datadog (security, legitimate interest) — заявлен
+ Exactag (not named in the site's policy) — не заявлен
+ Third-party tracker spapi.io — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.docmorris.de is the website of DocMorris, one of Europe’s largest online pharmacies (medication and health-product delivery, a personal account, a loyalty program). Data controllers: DocMorris N.V. and DocMorris Services B.V. (Heerlen, Netherlands); the site serves a German audience under the .de domain. Given that this is a pharmacy, the sensitivity of the context is high.

Measurement: 146 requests to 12 domains, homepage, captured on a clean browser with no VPN and no blocker. The session entered via a redirect from www.docmorris.nl to www.docmorris.de — which explains the Dutch domain appearing in the list. The site has its own consent mechanism on the consentmanager platform.

Who receives the data

Directly, before consent: Exactag, the third-party tracker spapi.io.

Exactag is marketing attribution: measuring touchpoints, views, on-site events, and conversions across the user journey. Its library loads at 5380 ms, before the banner interface renders (15956 ms). spapi.io is a third-party domain to which, at 7630 ms, a beacon request goes carrying a visit-linked payload (request address length — 1087 characters); the vendor could not be publicly identified and is not named in the site’s policy.

Tag-collector containers (the primary subdomain measure.docmorris.de layered over Google Tag Gateway, plus a standard Google Tag Manager) load, but do not deploy commercial trackers: there is neither Google analytics nor advertising traffic in this session. Criteo is allowed in the CSP header, but is held behind consent and did not fire. On the functional side: the chat-assistant widget (Zowie), declared in the policy.

Yes, a full banner on the consentmanager platform is present, and in many respects it is set up correctly: the bulk of commercial tools are held behind it. The consent platform script loads at 5818 ms, the banner interface renders at 15956 ms, and the decision is recorded at 40255 ms (a request to consent.php).

The key point is that some marketing activity fired before the banner: by the time its interface rendered (15956 ms), the Exactag library (5380 ms) and the third-party beacon (7630 ms) had already gone out to the network.

Before the banner renders and before any consent, the following fire:

  • Exactag marketing attribution (5380 ms) — loading of a user-journey measurement library;
  • a beacon request to the third-party domain spapi.io (7630 ms) — carrying a visit-linked payload;
  • tag-collector containers — they load, but do not deploy commercial tags in this session;
  • the Zowie chat assistant (8315 ms) — a functional support service.

The tag containers and the chat widget raise no concerns: the former deployed nothing without consent, and the latter is functional and declared. The issue lies with Exactag and the third-party beacon: these are marketing, non-technical purposes, and they contact third parties before the user’s choice.

Why “the container loaded” is not yet a violation, but Exactag already is

This distinction matters. Loading a tag-collector container is, on its own, neutral: if it deployed neither analytics, nor advertising, nor pixels without consent — there is no issue, and that is the case here. So Google Tag Manager, in this measurement, is not counted as a violation.

Exactag is different. It is not a container, but a specific marketing tool with its own purpose — measuring the journey and conversions. DocMorris’s own documentation classifies marketing tools, including Exactag, as processing based on consent (Art. 6(1)(a) GDPR). Launching such a library before consent contradicts that stated basis. Compounding this is the third-party beacon to spapi.io, which is not named in the policy at all — worsening the transparency issue as well.

Conclusion

Docmorris.de is, on the whole, a case of disciplined configuration with one leak at the marketing level. Much works in the site’s favor: a full consent banner is present, Google analytics, Criteo, and advertising pixels do not deploy in the clean session, and Criteo is held behind consent. But the Exactag marketing-attribution library (5380 ms) and the beacon to the unidentified third-party domain spapi.io (7630 ms) fire before the banner interface renders (15956 ms), and before any consent. The key takeaway: switching marketing attribution and the third-party beacon into consent-gated mode — the same way this has already been done for Google analytics and Criteo — would make the configuration clean for a pharmacy operating in a sensitive context.

Evidence
Original (audit)
HAR file: de/docmorris-de-2026-06-23.har
SHA-256: e1abf7637d90e8e91695c3184b29760190616e1a7674bfce48e38001234030cc
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Federal Commissioner for Data Protection (BfDI)file a complaint online →

To: Federal Commissioner for Data Protection (BfDI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website docmorris.de.

2. Circumstances
I visited the website docmorris.de and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 23 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site has a fully functioning consent mechanism (the consentmanager platform), and the pharmacy's own documentation classifies marketing tools, including Exactag, as processing based on consent (Art. 6(1)(a) GDPR). However, in a clean session with no consent given, the Exactag marketing-attribution library loads at 5380 ms — before the consent banner has even had time to render (the banner interface appears at 15956 ms). Exactag's purpose is to measure the user journey and conversions (touchpoints, views, on-site events) — a non-technical, marketing purpose. In addition, at 7630 ms, a beacon request goes to a third-party domain: the payload is encoded directly in the request address (address length — 1087 characters), with docmorris.de as the source; this tracker's vendor is not publicly identified and is not named in the site's policy. The fact that heavier tools (Google analytics, Criteo, advertising pixels) did not deploy works in the site's favor, but does not resolve the issue: marketing attribution and a third-party beacon contact third parties before the user's choice, contrary to the very basis (consent) the pharmacy itself relies on.

Full technical documentation is published at: https://gdpru.eu/en/audits/de-docmorris-de/

3. Provisions violated
Art. 6(1)(a) GDPR (and § 25 TDDDG/TTDSG) — marketing attribution and a third-party tracker fire before consent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]