Technical audit · 2026-05-31

politi.dk

National Police of Denmark

The National Police of Denmark — 49 requests, 6 domains. The policy states that Google Maps connects when the user clicks on the map. In the capture, the Google Maps/Places API loads on page load, with no click and prior to consent, transmitting the visitor's IP address to Google (USA). A Cookiebot consent management platform is present but does not hold back the map.

Timeline of the leak

+0 ms · portal load
Content and resources served from politi.dk.
+124 ms · consent management platform
consent.cookiebot.com/uc.js — Cookiebot loads. The tool itself is not named in the policy.
+128 ms · Google Maps prior to consent
maps.googleapis.com/maps/api/js?libraries=places — the Google Maps/Places API loads on page load, with no click. The visitor's IP address is transmitted to Google (USA).
+125 ms · library from a CDN
cdnjs.cloudflare.com — jQuery-validation from Cloudflare. Not named in the policy.
+1979–2083 ms · full Maps initialization
maps-api-v3 common.js/util.js/controls.js/places_impl.js, plus images from maps.gstatic.com — full initialization of Google Maps.

Declared versus actual

Google Maps — declared as connecting when the user clicks on the map ('når du klikker på ... et Google Maps-kort') — заявлен
YouTube, Google reCAPTCHA — third-party cookies upon interaction — заявлен
Statistics cookies — require consent (samtykke) — заявлен
+ The actual loading of Google Maps/Places on page load, with no click and prior to consent — contradicts the statement about click-triggering — не заявлен
+ Cookiebot (consent.cookiebot.com) — the consent tool, not named in the policy — не заявлен
+ cdnjs.cloudflare.com — a library CDN, not named in the policy — не заявлен

Transfer timings

+124 ms consent.cookiebot.com

Cookiebot CMP. Not named in the policy.

+128 ms maps.googleapis.com

Google Maps/Places API on page load, with no click. Google, USA.

+2083 ms maps.gstatic.com

Google Maps images. Google, USA.

Detected trackers

Indicators of GDPR non-compliance

Context

politi.dk is the official website of the National Police of Denmark (Politi / Rigspolitiet). It publishes information on police services, filing reports, passports, and wanted persons. The data controller is the Danish Police. The privacy policy is extensive (approximately 60,000 characters) and detailed. Capture: 49 requests, 6 domains, recorded in a clean browser.

Google (USA) — the visitor’s IP address, via the loading of the Google Maps/Places API at +128 ms, with no click.

Declared versus Actual

The policy describes the connection of Google Maps as the result of a user action: third-party cookies appear when the user clicks on a Google Map. The wording directly links the loading to a click (’når du klikker’). YouTube and reCAPTCHA are similarly described as activated upon interaction.

The capture shows otherwise. At +128 ms, immediately upon page load and without any click, the Google Maps/Places API loads (maps/api/js with the places library). The trigger is the page parser, not a user action. Subsequently, at +1979–2083 ms, the full Maps code is pulled in, along with images from maps.gstatic.com. All of this occurs in a state of no consent: not a single cookie is set across the entire session, and no choice has been made in the consent management platform. The mere loading of the Maps API already transmits the visitor’s IP address to Google (USA). Thus, Google Maps connects on page load, rather than by click as the policy describes, and prior to consent.

The site’s consent management platform is Cookiebot (consent.cookiebot.com); it loads at +124 ms, but is not named by name in the policy itself. The form-validation library loads from cdnjs.cloudflare.com (Cloudflare); this CDN is likewise unmentioned in the policy. The social media icons (YouTube, Facebook, LinkedIn) are static SVGs served from politi.dk itself and do not constitute third-party calls.

Cookiebot loads at +124 ms and Google Maps at +128 ms — that is, practically simultaneously — and the map is not held back pending the user’s choice. Full Maps initialization completes at +2083 ms. No consent was requested as an outcome or given throughout the session (Set-Cookie is zero).

What Cannot Be Asserted from This Capture

The capture covers a single page. A Google Maps API key was present in the request and has been redacted from the published file; Maps client keys are not, by their nature, secret. reCAPTCHA, mentioned in the policy, did not fire in this session. The conclusion regarding the recipient (Google, USA) is based on the domain and IP address of the Maps requests. Server-side processing is not visible in a browser-based capture.

Conclusion

The website of the National Police of Denmark describes Google Maps in its policy as connecting when the user clicks on the map. In the capture, the Google Maps/Places API loads on page load, with no click and prior to consent, transmitting the visitor’s IP address to Google (USA); full map initialization completes two seconds later. A Cookiebot consent management platform is present but does not hold back the map prior to consent and is not itself named in the policy. The discrepancy between the “on map click” statement and the actual loading at the start of the page, together with the transfer of the IP address to a US-based recipient prior to consent, constitutes a violation of the requirements concerning consent and disclosure. Remedy: connect Google Maps only upon an actual user action, as the policy describes (or after consent is given in Cookiebot), and disclose the consent tool and the CDN in use in the policy.

Evidence
Original (audit)
HAR file: dk/politi-dk-2026-05-31.har
SHA-256: b7bdd2eb99b23a67fb7deaf9f96ac4a84eeca64709fceecd4b3103267fcbc413
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Danish Data Protection Agency (Datatilsynet)file a complaint online →

To: Danish Data Protection Agency (Datatilsynet)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website politi.dk.

2. Circumstances
I visited the website politi.dk and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 31 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) The policy states directly that third-party Google Maps cookies appear when the user clicks on the map: 'tredjeparts-cookies, når du klikker på ... et Google Maps-kort.' In the capture, the Google Maps/Places API (maps.googleapis.com/maps/api/js?libraries=places) loads at +128 ms on page load, with no click and prior to consent. The full Maps JS is then pulled in (+1979 ms), along with images from maps.gstatic.com. The loading is triggered by the page parser, not by any user action.

2) The loading of the Google Maps API transmits the visitor's IP address to Google (USA) prior to consent. The policy describes Google Maps as activated by click, not on page load, and does not disclose the transfer of the IP address at this stage. The library additionally loads from cdnjs.cloudflare.com (Cloudflare), not named in the policy; the Cookiebot consent tool is likewise not named in the policy.

Full technical documentation is published at: https://gdpru.eu/en/audits/dk-politi-dk/

3. Provisions violated
ePrivacy (Danish Cookiebekendtgørelse) — consent contrary to the policy's own stated rule; GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and transfer

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]