Technical audit · 2026-06-06

e-kaubanduseliit.ee

Estonian E-Commerce Association — a Nonprofit Organization

The organization uses the same privacy policy for both of its sites — and neither has a consent banner. GTM, Google Fonts, the Webflow CDN, and CloudFront all load with no user interaction of any kind. Its own policy declares no data is transferred outside the EEA — the HAR contradicts this.

Timeline of the leak

+118 ms · on load
Webflow CDN (cdn.prod.website-files.com) — the site's CSS and JS. An American platform.
+119 ms · on load
Amazon CloudFront (jquery-3.5.1) and the Google Web Fonts API (ajax.googleapis.com) — simultaneously. Both companies American.
+137 ms · on load
Google Fonts (fonts.googleapis.com) — PT Sans, Oxygen. IP address within Google's range.
+141 ms · on load
GTM (GTM-NW7WV5R5) — loads. No banner is present, nor will one appear.
Consent banner
Completely absent. Zero consent requests across the entire session.

Declared versus actual

Data is not transferred outside the EEA — declared in the policy — заявлен
+ Google Tag Manager (GTM-NW7WV5R5) — не заявлен
+ Google Fonts — не заявлен
+ Webflow CDN (cdn.prod.website-files.com) — не заявлен
+ Amazon CloudFront — не заявлен
+ Google Web Fonts API (ajax.googleapis.com) — не заявлен

Transfer timings

+118 ms cdn.prod.website-files.com

Webflow CDN

+119 ms d3e54v103j8qbb.cloudfront.net

jQuery via Amazon CloudFront

+141 ms www.googletagmanager.com

GTM-NW7WV5R5. No banner

Detected trackers

Indicators of GDPR non-compliance

Context

MTÜ Eesti E-Kaubanduse Liit is the Estonian E-Commerce Association, a nonprofit organization. It brings together online stores, issues a trust mark, and lobbies for e-commerce interests. The site is built on Webflow. HAR: 30 requests, 7 domains.

esmaspaev.ee is not a third-party aggregator that happened to link to someone else’s policy — it is a second site belonging to the same organization: also run by MTÜ Eesti E-Kaubanduse Liit. Neither site has a consent banner, and both use the same privacy policy, which directly declares that no data is transferred outside the EEA.

An organization that is supposed to set the standard for Estonian e-commerce fails to meet GDPR’s basic requirements on either its main site or the second one it administers itself.

Webflow and CloudFront — American companies

The site is built on Webflow, a no-code platform run by an American company. All content, CSS, and JavaScript load from cdn.prod.website-files.com. jQuery loads from Amazon CloudFront. In this particular session, both responses physically arrived from European nodes (Webflow via a Cloudflare edge in Tallinn, CloudFront via an edge in Helsinki), but this does not resolve the issue: Webflow Inc. and Amazon are companies registered in the USA, subject to American jurisdiction regardless of which physical node a particular request passed through. The policy of an organization declaring it operates within the EEA mentions none of these services.

GTM with no banner

GTM loads at +141 ms — and nothing further happens regarding consent. No CookieYes, no Cookiebot, no OneTrust. 30 requests per session, zero calls to any consent-system domain. GTM is wired into the code and active — what exactly it loads is determined by the container’s configuration, which is not visible in the HAR.

Conclusion

The Estonian E-Commerce Association — an organization that, by definition, should know GDPR’s requirements and serve as an example for its members — has no consent banner on either of its two sites, transmits data to American companies’ infrastructure, and declares the opposite in its policy. This is not a technically difficult problem: Webflow supports CMP integration, and GTM supports Consent Mode. The question is one of priorities.

Evidence
Original (audit)
HAR file: ee/e-kaubanduseliit-ee-2026-06-06.har
SHA-256: f6f4b0e81ef467cfcc26cc5eefb2b1ed16d554e4d66bdf5c71748876bdf9fb96
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee

Important: AKI only handles submissions in Estonian. Translate the letter before sending.

To: Estonian Data Protection Inspectorate (AKI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website e-kaubanduseliit.ee.

2. Circumstances
I visited the website e-kaubanduseliit.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 6 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) There is no consent banner whatsoever. Zero consent requests across the entire session — among 7 domains, not a single CMP appears. GTM loads at +141 ms with no consent of any kind.

2) GTM (+141 ms), Google Fonts (+137–157 ms), Webflow CDN (+118 ms), Amazon CloudFront (+119 ms), and the Google Web Fonts API (+119 ms) load on page open, with no consent.

3) The organization's privacy policy declares that no data is transferred outside the EEA. The HAR records requests to Webflow CDN, Amazon CloudFront, Google Tag Manager, and Google Fonts — all four services belong to American companies. None is mentioned in the policy.

Full technical documentation is published at: https://gdpru.eu/en/audits/ee-e-kaubanduseliit-ee/

3. Provisions violated
GDPR Art. 7; GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 13(1)(e)

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]