An educational portal whose users are children and young people (GDPR Art. 8). DoubleClick and Google Analytics collect minors' data with no consent. Meanwhile, the same organization's sister site — rajaleidja.ee — runs with zero trackers. This means harno's choice was made deliberately.
Timeline of the leak
Declared versus actual
Transfer timings
Cloudflare Insights, status 200. Data to the USA
GTM/GA4, ID G-8TVS280V6G, status 200
No exact timing
Detected trackers
- Google Analytics (GA4)
- DoubleClick
- Google Tag Manager
- Cloudflare Insights
- browser-update.org
Indicators of GDPR non-compliance
- GDPR Art. 8Processing children's data requires special protection. DoubleClick and Google Analytics on an educational portal whose users are minors is a violation given the context.
- GDPR Art. 6(1), Art. 5(1)(a)GTM, Cloudflare Insights, and browser-update.org fire mere milliseconds before any consent. No consent banner exists.
- GDPR Art. 7There is no consent mechanism whatsoever. Zero consent requests, zero Set-Cookie.
- GDPR Art. 13(1)(e)Data recipients (Google, Cloudflare, DoubleClick, browser-update.org) are not declared.
- GDPR Art. 13(1)(f), Chapter VNo transfer mechanism to the USA is stated for any recipient. Privacy Shield was invalidated by the CJEU in 2020.
Context
Harno is Estonia’s Education and Youth Board. Through this site, the state manages educational programs, exams, teacher training courses, and scholarships. The portal’s users are children and young people — minors, for whom GDPR Art. 8 establishes a special protection regime. HAR: 102 requests, 8 external domains, all in the USA.
A familiar pattern
Google Tag Manager (GA4, G-8TVS280V6G) fires 507 ms after loading, before any consent. region1.analytics.google.com records 4 actual transfers to Google Analytics per session (status 204): each carries an IP address, an identifier, and user behavior. stats.g.doubleclick.net/g/collect — DoubleClick collects data on an educational portal for minors, using the same tracking ID. Plus Cloudflare Insights (status 200) and browser-update.org. There is no consent banner, zero Set-Cookie, zero consent requests. This is the same template seen at aki.ee, riigikogu.ee, emta.ee, tai.ee — one contractor, one CMS (Drupal vp_distro), all trackers present by default.
A benchmark next door — rajaleidja.ee
Within the same state ecosystem sits a second site — rajaleidja.ee, a career-counseling portal for schoolchildren. 166 requests, one domain, zero trackers: no Google Analytics, no Cloudflare, no DoubleClick, no browser-update.org. WordPress on Apache, all resources local. No Set-Cookie and no consent requests — and none are needed, because there’s nothing to ask about. The same .ee domain, the same users, the same Board — but a fundamentally different architecture.
The main takeaway
rajaleidja.ee proves that the Education and Youth Board knows how to build sites with no external trackers. harno.ee shows that on its main portal, it chose not to. One site sends children’s data to DoubleClick; the other sends it to no one. This is an architectural choice made deliberately in each case: within a single organization, two teams, two contractors, two philosophies. There are no technical excuses.
d1d18d95f2da8026faf27d90867cf54a34e49f7e3d85f177dfe2727574e67edfWhere to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee
Important: AKI only handles submissions in Estonian. Translate the letter before sending.
To: Estonian Data Protection Inspectorate (AKI) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website harno.ee. 2. Circumstances I visited the website harno.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 3 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) Processing children's data requires special protection. DoubleClick and Google Analytics on an educational portal whose users are minors is a violation given the context. 2) GTM, Cloudflare Insights, and browser-update.org fire mere milliseconds before any consent. No consent banner exists. 3) There is no consent mechanism whatsoever. Zero consent requests, zero Set-Cookie. 4) Data recipients (Google, Cloudflare, DoubleClick, browser-update.org) are not declared. 5) No transfer mechanism to the USA is stated for any recipient. Privacy Shield was invalidated by the CJEU in 2020. Full technical documentation is published at: https://gdpru.eu/en/audits/ee-harno-ee/ 3. Provisions violated GDPR Art. 8; GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 7; GDPR Art. 13(1)(e); GDPR Art. 13(1)(f), Chapter V 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]