Policy changed — see what exactly · 2026-08-14 →
A courier service with exemplary transparency: ConsentManager lists all 17 vendors by name, with individual toggles. The first site in this series where the recipient list is fully documented. But four services are enabled by default with no consent.
Timeline of the leak
Declared versus actual
Transfer timings
ConsentManager SDK
Amazon CloudFront. USA
Alturing AI chat
The banner becomes visible to the user
Detected trackers
- ConsentManager (cdn.consentmanager.net)
- Alturing AI chat (chatbot.alturing.eu)
- Brandcenter DPD Group (brandcenter.dpdgroup.com)
- Amazon CloudFront (d2csxpduxe849s.cloudfront.net)
Indicators of GDPR non-compliance
- GDPR Art. 6(1), Art. 5(1)(a)ConsentManager (+47 ms) and the Alturing AI chat (+55 ms) fire before the banner has rendered and become visible to the user. Amazon CloudFront (+52 ms) transmits data to the USA before consent.
- GDPR Art. 7ConsentManager presets 'Function,' Amazon CloudFront, Cloudflare, consentmanager, and Geopost as enabled by default (On), with no user consent. Google reCAPTCHA is also marked as On by default. The remaining 13 vendors are off.
Context
DPD Eesti AS is a courier service, a subsidiary of GeoPost SA (France, part of the La Poste group). It operates in Estonia, Latvia, and Lithuania. It uses the global dpd.com platform with Estonian localization (/ee/et/). HAR: 115 requests, 6 domains.
An exemplary Cookie Declaration — a first for this series
Screenshots from ConsentManager show something no other site in this series has had: a complete list of 17 vendors, each named individually, with a toggle for each:
A/B Tasty, Amazon CloudFront, Cloudflare, consentmanager, Facebook (Meta), Geopost, Google Ads, Google Advertising Products, Google Analytics, Google Fonts, Google General, Google Maps, Google Recaptcha, Google Tag Manager, TikTok (Analytics), TikTok (Embed), YouTube.
Each vendor has a link to its own privacy policy. The user can see exactly who they are authorizing. This is the standard of transparency required by Art. 13(1)(e) — one no other site in this series has reached.
What’s on by default — the problem
Of the 17 vendors, four are enabled by default (On), with no consent: Amazon CloudFront, Cloudflare, consentmanager, and Geopost. Plus Google reCAPTCHA is also marked as On. Cloudflare and consentmanager can technically be justified as “necessary” for the site to function. But Amazon CloudFront — a media-content CDN — and Google reCAPTCHA transmit data to the USA and are not strictly necessary within the meaning of GDPR. Enabling them by default with no consent violates the opt-in principle for non-essential services.
HAR vs. Cookie Declaration
The HAR records only 6 domains — because the audit was conducted before consent was given. After clicking “Accept All,” all 17 vendors would activate, including Google Analytics, Facebook Pixel, TikTok, and YouTube. This is precisely the model GDPR should require: most trackers blocked until consent, unblocked afterward.
Conclusion
DPD demonstrates the best Cookie Declaration in this series: 17 vendors named individually, toggles, links to their policies, “Reject All” and “Accept All” buttons. This is a model of what transparency under Art. 13(1)(e) should look like. The one issue: Amazon CloudFront and Google reCAPTCHA are enabled by default with no consent. A minor technical fix against an otherwise sound architecture.
9e53377076ffb9a6491ce35fd3fa73fda8ec361d918ad06dfbbaf8144c76941aWhere to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee
Important: AKI only handles submissions in Estonian. Translate the letter before sending.
To: Estonian Data Protection Inspectorate (AKI) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website dpd.com. 2. Circumstances I visited the website dpd.com and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 6 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) ConsentManager (+47 ms) and the Alturing AI chat (+55 ms) fire before the banner has rendered and become visible to the user. Amazon CloudFront (+52 ms) transmits data to the USA before consent. 2) ConsentManager presets 'Function,' Amazon CloudFront, Cloudflare, consentmanager, and Geopost as enabled by default (On), with no user consent. Google reCAPTCHA is also marked as On by default. The remaining 13 vendors are off. Full technical documentation is published at: https://gdpru.eu/en/audits/ee-dpd-ee/ 3. Provisions violated GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 7 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]