e-kaubanduseliit.ee
The organization uses the same privacy policy for both of its sites — and neither has a consent banner. GTM, Google Fonts, the Webflow CDN, and CloudFront all load with no user interaction of any kind. Its own policy declares no data is transferred outside the EEA — the HAR contradicts this.
Timeline of the leak
Declared versus actual
Transfer timings
Webflow CDN
jQuery via Amazon CloudFront
GTM-NW7WV5R5. No banner
Detected trackers
- Google Tag Manager (GTM-NW7WV5R5)
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com)
- Webflow CDN (cdn.prod.website-files.com)
- Amazon CloudFront (d3e54v103j8qbb.cloudfront.net)
- Google Web Fonts API (ajax.googleapis.com)
Indicators of GDPR non-compliance
- GDPR Art. 7There is no consent banner whatsoever. Zero consent requests across the entire session — among 7 domains, not a single CMP appears. GTM loads at +141 ms with no consent of any kind.
- GDPR Art. 6(1), Art. 5(1)(a)GTM (+141 ms), Google Fonts (+137–157 ms), Webflow CDN (+118 ms), Amazon CloudFront (+119 ms), and the Google Web Fonts API (+119 ms) load on page open, with no consent.
- GDPR Art. 13(1)(e)The organization's privacy policy declares that no data is transferred outside the EEA. The HAR records requests to Webflow CDN, Amazon CloudFront, Google Tag Manager, and Google Fonts — all four services belong to American companies. None is mentioned in the policy.
Context
MTÜ Eesti E-Kaubanduse Liit is the Estonian E-Commerce Association, a nonprofit organization. It brings together online stores, issues a trust mark, and lobbies for e-commerce interests. The site is built on Webflow. HAR: 30 requests, 7 domains.
One operator, two sites with no consent
esmaspaev.ee is not a third-party aggregator that happened to link to someone else’s policy — it is a second site belonging to the same organization: also run by MTÜ Eesti E-Kaubanduse Liit. Neither site has a consent banner, and both use the same privacy policy, which directly declares that no data is transferred outside the EEA.
An organization that is supposed to set the standard for Estonian e-commerce fails to meet GDPR’s basic requirements on either its main site or the second one it administers itself.
Webflow and CloudFront — American companies
The site is built on Webflow, a no-code platform run by an American company. All content, CSS, and JavaScript load from cdn.prod.website-files.com. jQuery loads from Amazon CloudFront. In this particular session, both responses physically arrived from European nodes (Webflow via a Cloudflare edge in Tallinn, CloudFront via an edge in Helsinki), but this does not resolve the issue: Webflow Inc. and Amazon are companies registered in the USA, subject to American jurisdiction regardless of which physical node a particular request passed through. The policy of an organization declaring it operates within the EEA mentions none of these services.
GTM with no banner
GTM loads at +141 ms — and nothing further happens regarding consent. No CookieYes, no Cookiebot, no OneTrust. 30 requests per session, zero calls to any consent-system domain. GTM is wired into the code and active — what exactly it loads is determined by the container’s configuration, which is not visible in the HAR.
Conclusion
The Estonian E-Commerce Association — an organization that, by definition, should know GDPR’s requirements and serve as an example for its members — has no consent banner on either of its two sites, transmits data to American companies’ infrastructure, and declares the opposite in its policy. This is not a technically difficult problem: Webflow supports CMP integration, and GTM supports Consent Mode. The question is one of priorities.
f6f4b0e81ef467cfcc26cc5eefb2b1ed16d554e4d66bdf5c71748876bdf9fb96Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee
Important: AKI only handles submissions in Estonian. Translate the letter before sending.
To: Estonian Data Protection Inspectorate (AKI) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website e-kaubanduseliit.ee. 2. Circumstances I visited the website e-kaubanduseliit.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 6 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) There is no consent banner whatsoever. Zero consent requests across the entire session — among 7 domains, not a single CMP appears. GTM loads at +141 ms with no consent of any kind. 2) GTM (+141 ms), Google Fonts (+137–157 ms), Webflow CDN (+118 ms), Amazon CloudFront (+119 ms), and the Google Web Fonts API (+119 ms) load on page open, with no consent. 3) The organization's privacy policy declares that no data is transferred outside the EEA. The HAR records requests to Webflow CDN, Amazon CloudFront, Google Tag Manager, and Google Fonts — all four services belong to American companies. None is mentioned in the policy. Full technical documentation is published at: https://gdpru.eu/en/audits/ee-e-kaubanduseliit-ee/ 3. Provisions violated GDPR Art. 7; GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 13(1)(e) 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]