The National Police of Denmark — 49 requests, 6 domains. The policy states that Google Maps connects when the user clicks on the map. In the capture, the Google Maps/Places API loads on page load, with no click and prior to consent, transmitting the visitor's IP address to Google (USA). A Cookiebot consent management platform is present but does not hold back the map.
Timeline of the leak
Declared versus actual
Transfer timings
Cookiebot CMP. Not named in the policy.
Google Maps/Places API on page load, with no click. Google, USA.
Google Maps images. Google, USA.
Detected trackers
- Google Maps / Places API (maps.googleapis.com, maps.gstatic.com)
- Cookiebot (consent.cookiebot.com) — CMP
- Cloudflare cdnjs (cdnjs.cloudflare.com) — library CDN
Indicators of GDPR non-compliance
- ePrivacy (Danish Cookiebekendtgørelse) — consent contrary to the policy's own stated ruleThe policy states directly that third-party Google Maps cookies appear when the user clicks on the map: 'tredjeparts-cookies, når du klikker på ... et Google Maps-kort.' In the capture, the Google Maps/Places API (maps.googleapis.com/maps/api/js?libraries=places) loads at +128 ms on page load, with no click and prior to consent. The full Maps JS is then pulled in (+1979 ms), along with images from maps.gstatic.com. The loading is triggered by the page parser, not by any user action.
- GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and transferThe loading of the Google Maps API transmits the visitor's IP address to Google (USA) prior to consent. The policy describes Google Maps as activated by click, not on page load, and does not disclose the transfer of the IP address at this stage. The library additionally loads from cdnjs.cloudflare.com (Cloudflare), not named in the policy; the Cookiebot consent tool is likewise not named in the policy.
Context
politi.dk is the official website of the National Police of Denmark (Politi / Rigspolitiet). It publishes information on police services, filing reports, passports, and wanted persons. The data controller is the Danish Police. The privacy policy is extensive (approximately 60,000 characters) and detailed. Capture: 49 requests, 6 domains, recorded in a clean browser.
Direct Recipients of Data (prior to consent)
Google (USA) — the visitor’s IP address, via the loading of the Google Maps/Places API at +128 ms, with no click.
Declared versus Actual
The policy describes the connection of Google Maps as the result of a user action: third-party cookies appear when the user clicks on a Google Map. The wording directly links the loading to a click (’når du klikker’). YouTube and reCAPTCHA are similarly described as activated upon interaction.
The capture shows otherwise. At +128 ms, immediately upon page load and without any click, the Google Maps/Places API loads (maps/api/js with the places library). The trigger is the page parser, not a user action. Subsequently, at +1979–2083 ms, the full Maps code is pulled in, along with images from maps.gstatic.com. All of this occurs in a state of no consent: not a single cookie is set across the entire session, and no choice has been made in the consent management platform. The mere loading of the Maps API already transmits the visitor’s IP address to Google (USA). Thus, Google Maps connects on page load, rather than by click as the policy describes, and prior to consent.
The site’s consent management platform is Cookiebot (consent.cookiebot.com); it loads at +124 ms, but is not named by name in the policy itself. The form-validation library loads from cdnjs.cloudflare.com (Cloudflare); this CDN is likewise unmentioned in the policy. The social media icons (YouTube, Facebook, LinkedIn) are static SVGs served from politi.dk itself and do not constitute third-party calls.
Timing Relative to Consent
Cookiebot loads at +124 ms and Google Maps at +128 ms — that is, practically simultaneously — and the map is not held back pending the user’s choice. Full Maps initialization completes at +2083 ms. No consent was requested as an outcome or given throughout the session (Set-Cookie is zero).
What Cannot Be Asserted from This Capture
The capture covers a single page. A Google Maps API key was present in the request and has been redacted from the published file; Maps client keys are not, by their nature, secret. reCAPTCHA, mentioned in the policy, did not fire in this session. The conclusion regarding the recipient (Google, USA) is based on the domain and IP address of the Maps requests. Server-side processing is not visible in a browser-based capture.
Conclusion
The website of the National Police of Denmark describes Google Maps in its policy as connecting when the user clicks on the map. In the capture, the Google Maps/Places API loads on page load, with no click and prior to consent, transmitting the visitor’s IP address to Google (USA); full map initialization completes two seconds later. A Cookiebot consent management platform is present but does not hold back the map prior to consent and is not itself named in the policy. The discrepancy between the “on map click” statement and the actual loading at the start of the page, together with the transfer of the IP address to a US-based recipient prior to consent, constitutes a violation of the requirements concerning consent and disclosure. Remedy: connect Google Maps only upon an actual user action, as the policy describes (or after consent is given in Cookiebot), and disclose the consent tool and the CDN in use in the policy.
b7bdd2eb99b23a67fb7deaf9f96ac4a84eeca64709fceecd4b3103267fcbc413Where to file: Danish Data Protection Agency (Datatilsynet) — file a complaint online →
To: Danish Data Protection Agency (Datatilsynet) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website politi.dk. 2. Circumstances I visited the website politi.dk and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 31 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) The policy states directly that third-party Google Maps cookies appear when the user clicks on the map: 'tredjeparts-cookies, når du klikker på ... et Google Maps-kort.' In the capture, the Google Maps/Places API (maps.googleapis.com/maps/api/js?libraries=places) loads at +128 ms on page load, with no click and prior to consent. The full Maps JS is then pulled in (+1979 ms), along with images from maps.gstatic.com. The loading is triggered by the page parser, not by any user action. 2) The loading of the Google Maps API transmits the visitor's IP address to Google (USA) prior to consent. The policy describes Google Maps as activated by click, not on page load, and does not disclose the transfer of the IP address at this stage. The library additionally loads from cdnjs.cloudflare.com (Cloudflare), not named in the policy; the Cookiebot consent tool is likewise not named in the policy. Full technical documentation is published at: https://gdpru.eu/en/audits/dk-politi-dk/ 3. Provisions violated ePrivacy (Danish Cookiebekendtgørelse) — consent contrary to the policy's own stated rule; GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and transfer 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]