Technical audit · 2026-08-16

www.inforegister.ee

Estonian business register and credit information Inforegister

The Estonian business register and credit-information service Inforegister — 109 requests, 6 nodes, a 146-second recording. Consent-management plugins are installed on the site, but Google analytics sends data with the consent marker gcs=G100 already in the first second, before the user's actual choice: the client identifier and page_view, scroll and click events go to Google. The Webpushr push-notification service starts independently of consent. The policy is detailed, but does not name the specific recipients of web data — Google Analytics and Webpushr — individually.

Timeline of the leak

+0 ms · loading the page
The recording begins on the Russian-language version www.inforegister.ee/ru/. Served through Apache. Set: strict transport with subdomain inclusion and preload, the content-type-sniffing ban, the referrer policy strict-origin-when-cross-origin, a permissions policy banning camera, microphone and sensors, and a detailed content-security-policy with nonce, strict-dynamic and a node allow-list. The browser was sending the DNT: 1 header.
+333…+831 ms · Webpushr
cdn.webpushr.com/app.min.js is loaded, then requests to bot.webpushr.com (get_info, subscribe/attributes) and analytics.webpushr.com (impression/prompt) — a push-notification service with its own impression analytics. It starts before Google analytics and independently of consent.
+1130 ms · Google Analytics 4 transmits data
POST to region1.google-analytics.com/g/collect: property G-3M0JH1H9F3, client identifier, page URL and title, page_view event. The consent-mode marker gcs=G100 — consent to analytics is set as granted, although the user's choice in the banner is not recorded by this point.
+6138…+96049 ms · stream of events to Google
Over the recording, scroll and click events go to Google Analytics with the same client identifier and the gcs=G100 marker. Each interaction with the register site is reflected in the analytics.
+32462 ms · navigation to a new page
Navigation to another register page: GTM, Google Site Kit, wp-consent-api and Webpushr start again; GA4 sends a new page_view.

Declared versus actual

Controller — Inforegister (OÜ Register), Estonian business register and credit-information service; privacy policy in Estonian — заявлен
Section 18: cookies, analytics and similar technologies may be used for operation, security, statistics, development and — with consent — marketing — заявлен
The precise cookie principles are described in a separate cookie notice or cookie terms — заявлен
When processing is based on consent, the user has the right to withdraw it at any time — заявлен
Direct marketing can be opted out of via the link in the notice or through the contacts — заявлен
Section 12: the categories of recipients are described in detail — technical providers, legal advisers, auditors, public authorities, third parties by consent — заявлен
International transfers and storage are described in separate sections; security measures are declared (section 19) — заявлен
+ Google Analytics 4 (G-3M0JH1H9F3) — the counter is not named individually; sends with gcs=G100 before the user's choice — не заявлен
+ Google Tag Manager — the loader via Google Site Kit, not named — не заявлен
+ Webpushr — the push-notification service with impression analytics, not named — не заявлен

Transfer timings

+143 ms www.googletagmanager.com

Container GT-M34QRD4 via Google Site Kit.

+333 ms cdn.webpushr.com

Push-notification service, script app.min.js.

+828 ms analytics.webpushr.com

Push-notification impression analytics, impression/prompt.

+1130 ms region1.google-analytics.com

GA4 G-3M0JH1H9F3, client identifier, page_view, gcs=G100.

Detected trackers

Indicators of GDPR non-compliance

Context

www.inforegister.ee is the Estonian business register and credit-information service Inforegister (OÜ Register): company data, credit scores, beneficial-owner information, financial forecasts. The site is built on WordPress and served through Apache. The recording was made on the Russian-language version.

The recording: 109 requests, 6 nodes, a recording length of 146.3 seconds, taken on 16 August 2026. Besides the main domain, the page addresses three third-party recipients: Google (Analytics 4 and Tag Manager via the Google Site Kit plugin) and Webpushr (a push-notification service on three subdomains). The session runs across several register pages.

The processing is described by a detailed privacy policy in Estonian: twenty-two sections of the main part, separate documents on the categories of recipients and on the legitimate-interest analysis. Section 18 is devoted to cookies, analytics and marketing, section 12 to recipients and third parties.

Who receives data directly

Google (Analytics, Tag Manager), Webpushr.

Declared versus actual

A consent mechanism is installed — but analytics does not depend on its result. Consent-management plugins run on the site: cookie-consent, wp-consent-api and Google Site Kit, all starting from the markup in the first milliseconds. That is, the consent infrastructure is present, and this is noticeably better than its complete absence. The problem is that the actual loading of analytics is not tied to the result of the user’s choice. The first Google Analytics 4 request goes out at +1130 ms with the consent-mode marker gcs=G100 — “consent granted” — and carries the client identifier, page URL and title, a page_view event. The G100 marker means that analytics cookies are allowed; but it is set before the choice in the banner is recorded in the recording. Later, throughout the recording, scroll and click events go out with the same marker.

The push-notification service works independently of consent. Webpushr is loaded at +333 ms — earlier than Google analytics — and calls its three nodes: cdn.webpushr.com (the script), bot.webpushr.com (obtaining settings and subscription) and analytics.webpushr.com (impression analytics impression/prompt). This is a third-party service with its own analytics, and its loading is not made conditional on consent.

The recipients of web data are not named individually. The policy is detailed as regards business data: section 12 thoroughly analyses the categories of recipients — technical providers, legal advisers, auditors, public authorities, third parties by consent. But as regards web analytics, section 18 is limited to general terms: cookies, analytics and similar technologies may be used, and the precise principles are described in a “corresponding cookie notice”. Neither Google Analytics, nor Google Tag Manager, nor Webpushr is named individually in the policy, and there is no separate cookie notice in the materials provided.

Security headers are set well. The site sets strict transport with subdomain inclusion and preload, the content-type-sniffing ban, a referrer policy and a permissions policy banning camera, microphone and sensors. The content-security-policy is built up solidly: nonce, strict-dynamic, report-uri and a node allow-list including Google Analytics, Tag Manager, DoubleClick and Webpushr. That is, the loading of third-party scripts is controlled at the CSP level — but not at the consent level.

Proven: a consent infrastructure is present on the site. The plugins cookie-consent, wp-consent-api and Google Site Kit are loaded from the markup at +141…+145 ms.

Proven: Google analytics sends data with the consent marker before the choice is recorded. The GA4 request at +1130 ms carries gcs=G100 and the client identifier; scroll and click events over the recording continue to go out with the same marker.

Proven: Webpushr starts independently of consent. The requests to its three nodes are initiated by the markup at +333…+831 ms, before the Google analytics requests.

Not proven and not unambiguously established: the origin of the consent marker. The gcs=G100 marker could have been set either as a default value in the consent-mode configuration or as a saved choice from an earlier visit. Response bodies and cookie headers were removed from the published file during sanitisation, so the source of the marker cannot be reconstructed from the recording. What is recorded is that, in the observed session, the data went to Google with a granted-consent marker without a prior interaction with the banner in the recording itself.

Not proven and not asserted: the state of cookies on the device. Cookie headers and response bodies were removed from the published file during sanitisation.

Separately: the browser was sending the DNT: 1 header during capture. This had no effect on the composition and addressing of the requests.

Boundaries of observation

The recording covers several register pages. The observation records the browser’s behaviour, not the services’ internal workings: server-side processing, contractual relationships with recipients and settings on their side are not verified by a browser recording. The legal assessment is made by the competent authority — Andmekaitse Inspektsioon.

The file is published sanitised of personal data: cookie headers in requests and response bodies were removed. Because of the absence of response bodies, the origin of the consent marker gcs=G100 — a default value or a saved choice — cannot be established from the recording; what is recorded is only that the data went out with this marker without an interaction with the banner in the observed session. The full client identifier is not reproduced in the analysis.

The identification of services rests on domains and address patterns: Google Analytics 4 — by google-analytics.com/g/collect and the property G-3M0JH1H9F3; Google Tag Manager — by googletagmanager.com and the container GT-M34QRD4; Webpushr — by the webpushr.com subdomains and the paths app.min.js, impression/prompt; the serving provider — by the server: Apache header.

Conclusion

The Estonian business register Inforegister has installed a consent-management infrastructure on the site — WordPress plugins and Google Site Kit — and built up a solid content-security-policy with a node allow-list. But the actual loading of analytics is not tied to the result of the user’s choice: Google Analytics 4 sends the client identifier and page_view, scroll and click events with the granted-consent marker gcs=G100 already in the first second, before the choice in the banner is recorded. The Webpushr push-notification service with its own impression analytics starts even earlier and independently of consent.

The detailed policy, meanwhile, discloses the recipients of business data thoroughly, but describes web analytics only in general terms and refers to a separate cookie notice; Google Analytics, Google Tag Manager and Webpushr are not named in it individually.

Remediation: make the actual loading of Google Analytics and Webpushr conditional on the user’s choice, so that no data with the gcs=G100 marker is sent before consent; name all recipients of web data in the policy or in a separate cookie notice individually — Google Analytics, Google Tag Manager, Webpushr — with the fields transmitted and the purposes; ensure that the default consent mode is set to “denied” until explicit consent to analytics cookies is obtained.

Evidence
Original (audit)
HAR file: ee/inforegister-ee-2026-08-16.har
SHA-256: c25e5645419ed4a8d473c6bf7a79673cf5311e0a72ed16a6e8166ff3e280346b
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee

Important: AKI only handles submissions in Estonian. Translate the letter before sending.

To: Estonian Data Protection Inspectorate (AKI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website www.inforegister.ee.

2. Circumstances
I visited the website www.inforegister.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 August 2026 (open methodology, reproducible measurements) documents the following indications:

1) Consent-management plugins are installed on the site (cookie-consent, wp-consent-api, Google Site Kit), but Google analytics sends data before the user's actual choice. The first Google Analytics 4 request with the client identifier and a page_view event goes out at +1130 ms with the consent-mode marker gcs=G100 — that is, consent to analytics cookies is set as granted before any interaction with the banner. Later in the recording, scroll and click events go out with the same marker. The Webpushr push-notification service, meanwhile, starts at +333 ms independently of any consent and calls its own impression analytics.

2) Section 18 of the policy describes the use of cookies, analytics and marketing technologies only in general terms and refers to a separate cookie notice. The specific recipients of web data are not named: Google Analytics, Google Tag Manager and Webpushr are absent from the policy by name. For a service processing credit scores and beneficial-owner information, the composition of external recipients is not fully disclosed.

Full technical documentation is published at: https://gdpru.eu/en/audits/ee-inforegister-ee/

3. Provisions violated
ePrivacy — Directive 2002/58/EC, Art. 5(3) (in conjunction with GDPR Art. 6(1)(a)); GDPR Art. 13(1)(e) — disclosure of recipients

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]