Technical audit · 2026-06-06

dpd.com

Courier Service, a Subsidiary of GeoPost SA (France)

A courier service with exemplary transparency: ConsentManager lists all 17 vendors by name, with individual toggles. The first site in this series where the recipient list is fully documented. But four services are enabled by default with no consent.

Timeline of the leak

+47 ms · before the banner
ConsentManager (cdn.consentmanager.net) — the banner begins loading.
+51 ms · before the banner
Brandcenter DPD Group (brandcenter.dpdgroup.com) — group SVG logos. France/EU.
+52 ms · before the banner
Amazon CloudFront (d2csxpduxe849s.cloudfront.net) — a media CDN. USA.
+55 ms · before the banner
Alturing AI chat (chatbot.alturing.eu) — the support chat. An EU domain.
+157 ms · banner visible
ConsentManager fully loaded. A Russian-language banner with 6 categories and 'Reject All' / 'Accept All' buttons.
+903 ms
ConsentManager loads personalized consent data — a cookie list covering all 17 vendors.

Declared versus actual

A/B Tasty — in the Cookie Declaration — заявлен
Amazon CloudFront — in the Cookie Declaration — заявлен
Cloudflare — in the Cookie Declaration — заявлен
consentmanager — in the Cookie Declaration — заявлен
Facebook (Meta) — in the Cookie Declaration — заявлен
Geopost — in the Cookie Declaration — заявлен
Google Ads — in the Cookie Declaration — заявлен
Google Advertising Products — in the Cookie Declaration — заявлен
Google Analytics — in the Cookie Declaration — заявлен
Google Fonts — in the Cookie Declaration — заявлен
Google General — in the Cookie Declaration — заявлен
Google Maps — in the Cookie Declaration — заявлен
Google Recaptcha — in the Cookie Declaration — заявлен
Google Tag Manager — in the Cookie Declaration — заявлен
TikTok (Analytics) — in the Cookie Declaration — заявлен
TikTok (Embed) — in the Cookie Declaration — заявлен
YouTube — in the Cookie Declaration — заявлен

Transfer timings

+47 ms cdn.consentmanager.net

ConsentManager SDK

+52 ms d2csxpduxe849s.cloudfront.net

Amazon CloudFront. USA

+55 ms chatbot.alturing.eu

Alturing AI chat

+157 ms a.delivery.consentmanager.net

The banner becomes visible to the user

Detected trackers

Indicators of GDPR non-compliance

Context

DPD Eesti AS is a courier service, a subsidiary of GeoPost SA (France, part of the La Poste group). It operates in Estonia, Latvia, and Lithuania. It uses the global dpd.com platform with Estonian localization (/ee/et/). HAR: 115 requests, 6 domains.

Screenshots from ConsentManager show something no other site in this series has had: a complete list of 17 vendors, each named individually, with a toggle for each:

A/B Tasty, Amazon CloudFront, Cloudflare, consentmanager, Facebook (Meta), Geopost, Google Ads, Google Advertising Products, Google Analytics, Google Fonts, Google General, Google Maps, Google Recaptcha, Google Tag Manager, TikTok (Analytics), TikTok (Embed), YouTube.

Each vendor has a link to its own privacy policy. The user can see exactly who they are authorizing. This is the standard of transparency required by Art. 13(1)(e) — one no other site in this series has reached.

What’s on by default — the problem

Of the 17 vendors, four are enabled by default (On), with no consent: Amazon CloudFront, Cloudflare, consentmanager, and Geopost. Plus Google reCAPTCHA is also marked as On. Cloudflare and consentmanager can technically be justified as “necessary” for the site to function. But Amazon CloudFront — a media-content CDN — and Google reCAPTCHA transmit data to the USA and are not strictly necessary within the meaning of GDPR. Enabling them by default with no consent violates the opt-in principle for non-essential services.

The HAR records only 6 domains — because the audit was conducted before consent was given. After clicking “Accept All,” all 17 vendors would activate, including Google Analytics, Facebook Pixel, TikTok, and YouTube. This is precisely the model GDPR should require: most trackers blocked until consent, unblocked afterward.

Conclusion

DPD demonstrates the best Cookie Declaration in this series: 17 vendors named individually, toggles, links to their policies, “Reject All” and “Accept All” buttons. This is a model of what transparency under Art. 13(1)(e) should look like. The one issue: Amazon CloudFront and Google reCAPTCHA are enabled by default with no consent. A minor technical fix against an otherwise sound architecture.

Evidence
Original (audit)
HAR file: ee/dpd-ee-2026-06-06.har
SHA-256: 9e53377076ffb9a6491ce35fd3fa73fda8ec361d918ad06dfbbaf8144c76941a
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee

Important: AKI only handles submissions in Estonian. Translate the letter before sending.

To: Estonian Data Protection Inspectorate (AKI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website dpd.com.

2. Circumstances
I visited the website dpd.com and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 6 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) ConsentManager (+47 ms) and the Alturing AI chat (+55 ms) fire before the banner has rendered and become visible to the user. Amazon CloudFront (+52 ms) transmits data to the USA before consent.

2) ConsentManager presets 'Function,' Amazon CloudFront, Cloudflare, consentmanager, and Geopost as enabled by default (On), with no user consent. Google reCAPTCHA is also marked as On by default. The remaining 13 vendors are off.

Full technical documentation is published at: https://gdpru.eu/en/audits/ee-dpd-ee/

3. Provisions violated
GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 7

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]