A portal explaining to citizens how to use their digital identity — the ID card, Mobile-ID, Smart-ID. A person comes here to authenticate via eID. In that same session, 0.63 seconds in and before any consent, Matomo has already transmitted data about their visit.
Timeline of the leak
Declared versus actual
Transfer timings
The Cloudflare beacon. Blocked by the browser, but the IP address reached servers in the USA
Analytics on the Estonian RIA domain — but before consent. Status 200
Status 204. Page URL, idsite=49, timestamp. An actual transfer
SMIT's anti-bot service. An Estonian domain, 9 requests. Not mentioned in the policy
Detected trackers
- Matomo (matomo.ria.ee)
- Cloudflare Insights
- antirobot.smit.ee
Indicators of GDPR non-compliance
- GDPR Art. 6(1), Art. 5(1)(a)Matomo fires 0.63 seconds before any consent — an actual data transfer (status 200/204). Cloudflare Insights initiates a request on every page before consent.
- GDPR Art. 7(3)There is no equivalent 'Decline' button. The banner offers only 'Read the terms' and 'Agree' — declining in one click is not possible.
- GDPR Art. 13(1)(e)Matomo, Cloudflare Insights, and antirobot.smit.ee are not declared in the privacy policy as data recipients. No recipients are named at all.
- GDPR Art. 5(1)(a)The policy states that the IP address is 'not linked to identifying information.' Under the CJEU's 2016 Breyer ruling, an IP address is personal data. The claim is legally incorrect.
- GDPR Chapter VData transfer to Cloudflare (USA) with no legal mechanism stated. Additionally, CSP reporting goes to csp-reporting.cloudflare.com — data about RIA site events transmitted to the USA.
Context
id.ee is the official information portal for the ID card, Mobile-ID, and Smart-ID, run by the Estonian Information System Authority (RIA). This is the entry point for citizens trying to understand how their electronic identity works. HAR: 128 requests, 3 external domains. Someone visiting id.ee is most likely about to authenticate via eID or trying to understand their digital identity credentials.
What happens before the banner
0.63 seconds after the page loads — before the user has had physical time to read the banner — Matomo (matomo.ria.ee) sends visit data (status 204). The next request, at +0.66 sec, already carries the page name, the site identifier idsite=49, and a timestamp in its URL. The consent banner loads in parallel: by the time the user sees it, the data has already gone out. Of the three external domains, two are Estonian — Matomo on RIA’s server and the anti-bot service antirobot.smit.ee (SMIT); this is a plus for localization, but both fire before consent. The third — static.cloudflareinsights.com (USA) — was blocked by the browser, but the request is initiated on every page, and the IP address reached Cloudflare’s servers.
CSP — a lock is there, but the door is open
The site has a Content Security Policy set — better than most sites reviewed. But the list is written such that any inline script executes without restriction: a strict CSP doesn’t work that way. Additionally, a second header, content-security-policy-report-only, was found, reporting to csp-reporting.cloudflare.com — data about RIA site CSP events being transmitted to the USA. The portal itself runs on WordPress (banner plugin cookie-law-info 3.2.8, from third-party developer WebToffee) — a public CMS with a broad attack surface, where every plugin is a potential entry point.
Declaration versus fact
The policy declares collection of IP address, pages, browser, OS, time, device, language, and region — but names not a single data recipient. It also states that the IP address is “not linked to identifying information,” which is legally incorrect under the CJEU’s ruling: an IP address is personal data, and Matomo transmits it. The actual recipients — Matomo, Cloudflare Insights, and antirobot.smit.ee — are not stated in the policy (Art. 13(1)(e)).
Conclusion
This is the portal that explains to citizens how to use the card the entire country trusts. Context sharpens the picture: the physical ID card was made by France’s IDEMIA (a €40 million contract), and before that by the Netherlands’ Gemalto, whose contract ended in a scandal over generating citizens’ private keys on its own servers. The very portal explaining this card runs on WordPress and transmits visitor data 0.63 seconds after the page opens — before a person has had time to even read the banner. Estonia calls this a digital state.
d90b0990449f4e4873549879b4b759ce133b97bdbd43a0c2190795be4f9a52a4Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee
Important: AKI only handles submissions in Estonian. Translate the letter before sending.
To: Estonian Data Protection Inspectorate (AKI) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website id.ee. 2. Circumstances I visited the website id.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 April 2026 (open methodology, reproducible measurements) documents the following indications: 1) Matomo fires 0.63 seconds before any consent — an actual data transfer (status 200/204). Cloudflare Insights initiates a request on every page before consent. 2) There is no equivalent 'Decline' button. The banner offers only 'Read the terms' and 'Agree' — declining in one click is not possible. 3) Matomo, Cloudflare Insights, and antirobot.smit.ee are not declared in the privacy policy as data recipients. No recipients are named at all. 4) The policy states that the IP address is 'not linked to identifying information.' Under the CJEU's 2016 Breyer ruling, an IP address is personal data. The claim is legally incorrect. 5) Data transfer to Cloudflare (USA) with no legal mechanism stated. Additionally, CSP reporting goes to csp-reporting.cloudflare.com — data about RIA site events transmitted to the USA. Full technical documentation is published at: https://gdpru.eu/en/audits/ee-id-ee/ 3. Provisions violated GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 7(3); GDPR Art. 13(1)(e); GDPR Art. 5(1)(a); GDPR Chapter V 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]