Technical audit · 2026-05-29

dpa.com

Germany's Leading News Agency

Deutsche Presse-Agentur — Germany's leading news agency. 35 requests, 4 domains. Next.js, nginx. FuturaPT and Inter served locally. Cookieless Matomo on dpa's own servers, Art. 6(1)(f). Storyblok is declared without a name. No GTM, no advertising pixels. Set-Cookie — zero.

Timeline of the leak

+0 ms · homepage
www.dpa.com/en — Next.js, nginx. 304 from cache. CSP: frame-ancestors 'self' *.storyblok.com — discloses the CMS.
+95 ms · Storyblok CDN
a.storyblok.com — 10 image requests loaded directly (hero, portraits, whitepaper covers). The Next.js image proxy is not used for Storyblok resources. The visitor's IP address is transmitted to Storyblok's servers.
+171 ms · fonts
FuturaPT/FuturaPTBook.woff2 and Inter/Inter-Regular.woff2 — both local, from /fonts/. No Google Fonts.
+539 ms · Matomo (used.dpa.com)
used.dpa.com/js/container_dkuvDkTV.js — the Matomo Tag Manager. Then, at +591 ms — /js/?action_name=dpa%20German%20Press%20Agency&idsite=8&rec=1 — page tracking. Cookieless, IP anonymization, hash ID valid for 24 hours.

Declared versus actual

Matomo Analytics (used.dpa.com) — declared, cookieless, proprietary server, Art. 6(1)(f), 24-hour hash ID — заявлен
Matomo Tag Manager — declared — заявлен
content management service provider (Storyblok) — declared without a name — заявлен
YouTube, LinkedIn, X, XING, TikTok, Instagram — mentioned as dpa's social networks — заявлен
+ Storyblok (a.storyblok.com) — name and domain not disclosed in the policy — не заявлен

Transfer timings

+539 ms used.dpa.com

Cookieless Matomo. dpa's own server. Art. 6(1)(f). No cookies.

Detected trackers

Indicators of GDPR non-compliance

Context

dpa (Deutsche Presse-Agentur) is Germany’s principal news agency, serving roughly 1,000 media organizations. Corporate website in English. Next.js, nginx. HAR: 35 requests, 4 domains.

Cookieless Matomo — no banner, on proprietary servers

used.dpa.com is dpa’s own domain for Matomo. At +539 ms, the Matomo Tag Manager loads (container_dkuvDkTV.js); at +591 ms, a tracking request fires with idsite=8. The policy describes Matomo in detail: no cookies, a cookieless mode using a 24-hour hash, immediate IP anonymization, with data staying on dpa’s servers. The legal basis is Art. 6(1)(f) GDPR (legitimate interest). There is no consent banner, and under the declared scheme none is required — TDDDG §25(2)(2) for technically necessary technologies and Art. 6(1)(f) for cookieless analytics. Set-Cookie — zero.

Storyblok — declared without a name

The CSP contains frame-ancestors 'self' *.storyblok.com — this is the Storyblok headless CMS. 10 requests to a.storyblok.com (images) load directly, without proxying through Next.js. The policy describes a “content management service provider” as a processor (Art. 4 No. 8, 28 GDPR) without disclosing the company’s name or domain. Art. 13(1)(e) requires the recipients of personal data to be named: an anonymous description does not meet the transparency requirement.

FuturaPT and Inter — local

The corporate typeface FuturaPT (Book) and Inter Regular — both woff2, served locally from /fonts/. No Google Fonts, no Adobe Fonts.

Conclusion

www.dpa.com has one violation: Storyblok is not disclosed by name in the privacy policy. The technical stack is otherwise clean — no GTM, no advertising pixels, no external CMP. The cookieless Matomo setup on proprietary servers is correctly declared.

Evidence
Original (audit)
HAR file: de/dpa-com-2026-05-29.har
SHA-256: 1116d64b97f16b1a04446d80d42bf6cee9c5bab8a7fece9a5a9ca846ea04dd5a
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Federal Commissioner for Data Protection (BfDI)file a complaint online →

To: Federal Commissioner for Data Protection (BfDI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website dpa.com.

2. Circumstances
I visited the website dpa.com and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) Storyblok is described in the privacy policy solely as a 'content management service provider,' without disclosing the company's name, domain (a.storyblok.com), or country of registration. Art. 13(1)(e) requires disclosure of the recipients or categories of recipients of personal data. Direct requests to a.storyblok.com (10 image requests) transmit the visitor's IP address to Storyblok GmbH's servers (Austria/USA).

Full technical documentation is published at: https://gdpru.eu/en/audits/de-dpa-com/

3. Provisions violated
GDPR Art. 13(1)(e)

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]