Technical audit · 2026-05-02

etoimik.rik.ee

State E-File System — Party Access to Court Case Materials

A state e-file portal: through it, parties access materials for criminal, civil, and administrative cases. RIK understands privacy mode — youtube-nocookie is used for video. But Cloudflare Insights and Google Fonts remain: when a party to a court case visits the portal, visit data goes to the USA.

Timeline of the leak

+636 ms · on load
static.cloudflareinsights.com — an analytics beacon, loaded from etoimik.rik.ee itself, transferred to the USA. In parallel, Google Fonts (fonts.gstatic.com, 8 requests) — IP address to Google.
Consent banner
Absent. Zero Set-Cookie, zero consent requests. All external requests fire with no asking.
YouTube and WAA
youtube-nocookie.com is used for the embed (correct), but the ytembeds scripts are still pulled from the standard youtube.com (12 requests). jnn-pa.googleapis.com — YouTube WAA anti-bot tracking, 5 background requests.

Declared versus actual

+ Cloudflare Insights — a beacon from the portal itself — не заявлен
+ Google Fonts — IP address to the USA — не заявлен
+ YouTube WAA anti-bot tracking — не заявлен

Transfer timings

+636 ms static.cloudflareinsights.com

The Cloudflare beacon, loaded from the portal itself. Data to the USA

No exact timing

on load fonts.gstatic.comGoogle Fonts, 8 requests. IP address to Google (USA)
on load www.youtube.com12 requests — embed scripts from the standard domain, a side effect of YouTube's architecture
in the background jnn-pa.googleapis.com (WAA)YouTube WAA anti-bot tracking, 5 requests

Detected trackers

Indicators of GDPR non-compliance

Context

etoimik.rik.ee is Estonia’s state e-file system for court proceedings. Through this portal, parties to court cases access materials for their own proceedings: civil (property disputes, divorces, child custody), criminal (GDPR Art. 10 — a specially sensitive category), and administrative. Authentication via ID card. HAR: 99 requests, 12 unique domains, 11 external — all in the USA.

What is done correctly

For embedded video, youtube-nocookie.com is used — the privacy-enhanced version (28 requests), unlike terviseportaal.ee, which used standard youtube.com. There is no Google Tag Manager, no Google Analytics, no DoubleClick, no browser-update.org. RIK clearly understands what privacy mode is — and applied it for video.

What is done incorrectly

static.cloudflareinsights.com (+636 ms) — an analytics beacon, loaded from etoimik.rik.ee itself, transmitting data to the USA. Google Fonts (fonts.gstatic.com, 8 requests) — the user’s IP address goes to Google. Despite using youtube-nocookie for the embed, the ytembeds scripts are still pulled from standard youtube.com (12 requests), and jnn-pa.googleapis.com (YouTube WAA anti-bot) makes 5 background requests. There is no consent banner, zero Set-Cookie, zero consent requests.

One pattern within RIK

The same organization — RIK — operates both saada.rik.ee (AKI’s complaint-submission portal: cdn.form.io/AWS, Google Fonts, Cloudflare CDN) and etoimik.rik.ee (Cloudflare Insights, Google Fonts, YouTube). One pattern: external trackers on state portals handling specially sensitive data. Yet on etoimik, RIK applied youtube-nocookie — meaning it knows about privacy-enhanced solutions. But Cloudflare Insights remains, Google Fonts remains. The knowledge is there; it just wasn’t carried through to completion.

Conclusion

When a party to a court case visits the portal to read the materials of their own criminal or family proceeding, Cloudflare receives data about the visit, Google Fonts receives the IP address, and YouTube WAA runs in the background — on a state judicial system portal. eesti.ee, rajaleidja.ee, and edpb.europa.eu prove that zero external trackers on a government portal is achievable. Here, half the journey is complete: privacy mode is applied for video. The second half remains — removing Cloudflare Insights and Google Fonts.

Evidence
Original (audit)
HAR file: ee/etoimik-rik-ee-2026-05-02.har
SHA-256: 1b85da477d0647e0b5303b6309288459d15fe99ced928e0ee7f89fe8e99be40f
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee

Important: AKI only handles submissions in Estonian. Translate the letter before sending.

To: Estonian Data Protection Inspectorate (AKI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website etoimik.rik.ee.

2. Circumstances
I visited the website etoimik.rik.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 2 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) Cloudflare Insights (+636 ms), Google Fonts, and YouTube WAA tracking fire with no consent — no consent banner exists.

2) There is no consent mechanism. Zero consent requests, zero Set-Cookie.

3) Criminal cases (Art. 10 — a specially sensitive category), property disputes, and child custody matters pass through this portal. External trackers run during sessions accessing court case materials.

4) Cloudflare Insights, Google Fonts, and YouTube WAA are not declared as data recipients.

5) No data-transfer mechanism to the USA (Cloudflare, Google) is stated. All 11 external domains are in the USA.

Full technical documentation is published at: https://gdpru.eu/en/audits/ee-etoimik-rik-ee/

3. Provisions violated
GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 7; GDPR Art. 9, Art. 10; GDPR Art. 13(1)(e); GDPR Art. 13(1)(f), Chapter V

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]