Technical audit · 2026-04-05

euronics.ee

Electronics Retail Chain

A commercial site with 1,605 requests per session. Google Analytics and Microsoft Clarity fire before consent. After clicking 'Allow,' 44 advertising domains activate simultaneously — a real-time RTB auction. There is no 'Reject All' button.

Timeline of the leak

+5 sec · before consent
Google Analytics — data goes to the USA 5 seconds after the site opens. Before any interaction with the banner.
+11 sec · before consent
Microsoft Clarity — a session-recording service. Records every mouse movement, click, and scroll. Transmits data to the USA (Microsoft). Before consent.
Consent banner
Present, but with no 'Reject All' button. Only 'Allow selected' and 'Allow all.' Declining in one click is not possible — a violation of Art. 7.
+250.5 sec · after consent
TikTok (analytics.tiktok.com) — 16 requests. ByteDance. Data transfer to China.
+250.6 sec · after consent
Facebook/Meta (11 requests), Pinterest (116 requests), Reddit (8 requests), Criteo (257 requests) — all fire within the same second.
+261 sec · after consent
Adobe DMP/Demdex (156 requests), Index Exchange/Casale Media (78 requests), ID5 (39 requests), BidSwitch, PubMatic, Taboola, Outbrain, Teads, 3lift, Yieldlab, SmartAdServer, Media.net — the RTB auction.

Declared versus actual

Facebook / Meta — заявлен
Google Analytics — заявлен
Zendesk — заявлен
Vimeo — заявлен
TikTok — заявлен
Criteo — заявлен
Pinterest — заявлен
Reddit — заявлен
+ Microsoft Clarity — session recording, before consent — не заявлен
+ Adobe DMP / Demdex — 156 requests — не заявлен
+ ID5 — advertising identifier synchronization — не заявлен
+ BidSwitch — не заявлен
+ PubMatic — не заявлен
+ Index Exchange / Casale Media — не заявлен
+ Outbrain — не заявлен
+ Taboola — не заявлен
+ Teads — не заявлен
+ 3lift — не заявлен
+ SmartAdServer — не заявлен
+ Media.net — не заявлен
+ Yieldlab — не заявлен

Transfer timings

+5 sec Google Analytics

Data to the USA before the banner

+11 sec Microsoft Clarity

Session recording, data to the USA

+250.5 sec analytics.tiktok.com

16 requests. ByteDance, China

+250.6 sec connect.facebook.net

11 requests. Meta, USA

+250.6 sec ct.pinterest.com

116 requests. USA

+250.6 sec alb.reddit.com

8 requests. USA

+250.6 sec gum.criteo.com / sslwidget.criteo.com

257 requests — the absolute leader

+261 sec dpm.demdex.net

156 requests. Adobe DMP, USA

+261 sec r.casalemedia.com

78 requests. Index Exchange, USA

+261 sec id5-sync.com

39 requests. Advertising-profile synchronization

Detected trackers

Indicators of GDPR non-compliance

Context

Euronics is one of the largest electronics retail chains in Estonia, part of an international European group. The site serves retail customers: a product catalog, shopping cart, and order checkout. 1,605 requests were recorded in a single session browsing several products.

The site has a consent banner, but there is no “Reject All” button. Two options are offered: “Allow selected” and “Allow all.” Declining in a single click is not possible — the user must open the settings and manually uncheck each box individually. Under GDPR Art. 7, withdrawing consent must be as easy as giving it: one click to accept, one click to decline. This is not a technical oversight, but deliberate design.

The banner appears with a delay. By that point, two American services have already received visit data:

Google Analytics fires 5 seconds after the site opens — before any interaction with the banner. Data goes to the USA.

Microsoft Clarity (+11 sec) — Microsoft’s session-recording service. Records every mouse movement, every click, every scroll. Data is transmitted to the USA. Also before consent.

Within the first 12 seconds after clicking “Allow,” 44 advertising domains fire simultaneously.

TikTok (analytics.tiktok.com, +250.5 sec) — 16 requests. ByteDance. Data transfer to China. Ireland’s DPC officially confirmed a TikTok GDPR violation in 2025.

Facebook/Meta (connect.facebook.net, +250.6 sec) — 11 requests. USA.

Pinterest (ct.pinterest.com, +250.6 sec) — 116 requests. The second-most active tracker. USA.

Reddit (alb.reddit.com, +250.6 sec) — 8 requests. USA.

Criteo (gum.criteo.com, sslwidget.criteo.com, ag.gbc.criteo.com, +250.6 sec) — 257 requests, the absolute leader. A French company, international advertising infrastructure.

Adobe DMP / Demdex (dpm.demdex.net, +261 sec) — 156 requests. Adobe’s data-management platform. USA.

Index Exchange / Casale Media (r.casalemedia.com, +261 sec) — 78 requests. Canada/USA.

ID5 (id5-sync.com, +261 sec) — 39 requests. A shared advertising identifier: synchronizes the user’s profile across all advertising networks.

Following immediately, simultaneously: BidSwitch, PubMatic, Taboola, Outbrain, Teads, 3lift, Yieldlab, SmartAdServer, Media.net — all fire within the same second. This is an RTB auction: user data is sold to advertising buyers in real time.

Declaration versus fact

The privacy policy lists: Facebook, Google, Zendesk, Vimeo, TikTok, Criteo, Pinterest, Reddit.

Not mentioned: Microsoft Clarity, Adobe DMP/Demdex, ID5, BidSwitch, PubMatic, Casale Media, Outbrain, Taboola, Teads, 3lift, SmartAdServer, Media.net, Yieldlab — and a number of others. More than 20 actual data recipients are absent from the policy. A violation of Art. 13(1)(e): a data subject must know all recipients of their data. No transfer mechanism to the USA or China is stated for any of them — a violation of Art. 13(1)(f) and Chapter V.

Conclusion

This is not an exception. This is the standard picture for an average online store in Estonia: a dark pattern in the banner, trackers before consent, an RTB auction afterward, and half the vendors undeclared. 1,605 requests per session — a number that speaks for itself.

Valmis kaebus AKI-le

AKI rakendab kaebuste menetlemisel ainult eesti keelt. Allpool on valmis tõlge, mille saab saata otse, ilma täiendava tõlketa.

Kellele: Andmekaitse Inspektsioon (AKI), info@aki.ee
Kellelt: [Teie nimi], [kontakt-e-post]

NB! Elektroonilised pöördumised peavad olema digitaalallkirjastatud.
1. Kaebuse ese Esitan kaebuse seoses minu isikuandmete töötlemisega veebisaidil euronics.ee.
2. Asjaolud Külastasin veebisaiti euronics.ee ja tuvastasin, et minu isikuandmeid töödeldi isikuandmete kaitse üldmääruse (IKÜM) nõudeid rikkudes. Tehniline analüüs, mis on avaldatud aadressil gdpru.eu 05.04.2026 (avatud metoodika, korratavad mõõtmised), dokumenteerib järgmist:
1) Nõusolekuriba ei pakuta võrdväärset nuppu „Lükka kõik tagasi“ — on olemas „Luba valitud“ ja „Luba kõik“, kuid ühe klikiga keeldumine ei ole võimalik. Tahtlik tume muster (dark pattern).
2) Google Analytics käivitub +5 sekundit pärast lehe avamist, Microsoft Clarity — +11 sekundit. Mõlemad enne kasutaja suhtlust nõusolekuribaga.
3) Rohkem kui 20 teenusepakkujat (Microsoft Clarity, Adobe DMP/Demdex, ID5, BidSwitch, PubMatic, Casale Media, Outbrain, Taboola, Teads, 3lift, SmartAdServer, Media.net, Yieldlab ja teised) puuduvad privaatsuspoliitikast.
4) Andmete edastamise mehhanism USA-sse ja Hiinasse ei ole iga vastuvõtja kohta märgitud.
5) Andmete edastamine Hiinasse (TikTok/ByteDance) sobivate kaitsemeetmeteta. Iiri DPC kinnitas ametlikult TikToki GDPR rikkumist 2025. aastal. Täielik tehniline dokumentatsioon on avaldatud aadressil: https://gdpru.eu/en/audits/ee-euronics-ee/
3. Rikutud sätted IKÜM art 7; IKÜM art 6 lg 1, art 5 lg 1 punkt a; IKÜM art 13 lg 1 punkt e; IKÜM art 13 lg 1 punkt f, V peatükk; IKÜM V peatükk
4. Nõue Palun viia läbi nimetatud rikkumiste kontroll ja kohaldada IKÜM artikli 58 lõikes 2 ette nähtud meetmeid.
5. Lisad Täielik tõendusmaterjal — HAR-fail, kontrollsumma SHA-256 ning veebisaidi privaatsuspoliitika tsitaat, mis dokumenteerib nimetatud vastuolu — on avaldatud ja kontrollitav punktis 2 viidatud lingil.
[Kuupäev] [Allkiri/nimi]

Below is the same letter in English (the text of this audit) — to understand its content or translate it into another language.

Evidence
Original (audit)
HAR file: ee/euronics-ee-2026-04-05.har
SHA-256: 61a1f25739581d67aa8671ec2468483f7d51a42b7310d0b52ab92143a4fc4b41
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee

Important: AKI only handles submissions in Estonian. Translate the letter before sending.

To: Estonian Data Protection Inspectorate (AKI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website euronics.ee.

2. Circumstances
I visited the website euronics.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 5 April 2026 (open methodology, reproducible measurements) documents the following indications:

1) The consent banner does not offer an equivalent 'Reject All' button — only 'Allow selected' and 'Allow all' are available, with no way to decline in one click. A deliberate dark pattern.

2) Google Analytics fires 5 seconds after the site opens, Microsoft Clarity — after 11 seconds. Both before any interaction with the consent banner.

3) More than 20 vendors (Microsoft Clarity, Adobe DMP/Demdex, ID5, BidSwitch, PubMatic, Casale Media, Outbrain, Taboola, Teads, 3lift, SmartAdServer, Media.net, Yieldlab, and others) are absent from the privacy policy.

4) No data-transfer mechanism to the USA and China is stated for any recipient.

5) Data transfer to China (TikTok/ByteDance) with no adequate safeguards stated. Ireland's DPC officially confirmed a TikTok GDPR violation in 2025.

Full technical documentation is published at: https://gdpru.eu/en/audits/ee-euronics-ee/

3. Provisions violated
GDPR Art. 7; GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 13(1)(e); GDPR Art. 13(1)(f), Chapter V; GDPR Chapter V

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]