Technical audit · 2026-05-10

kaitseliit.ee

Voluntary Paramilitary Defense Organization

An organization whose members work with state-secret-classified information. The policy describes nonexistent Google analytics and says nothing about the real one — Usercentrics — whose servers sit on Google Cloud, in the USA.

Timeline of the leak

+241 ms · before consent
The Usercentrics engine loads (web.cmp.usercentrics.eu), along with a script blocker. Data goes to Google Cloud servers in the USA.
~+1400 ms · consent banner
The banner appears at the moment the SDK loads. All requests to Usercentrics occur before it or in parallel. The user's choice is no longer primary.
After interaction
The data subject's decision to decline is stored on Usercentrics' servers in the USA. graphql.usercentrics.eu (204), consent-api (201) — an actual transfer.

Declared versus actual

Google Analytics (Google LLC) — absent from the HAR, not a single request — заявлен
+ Usercentrics GmbH — the consent-management system, 7 subdomains, 40+ requests — не заявлен
+ Google Cloud — Usercentrics' sub-processor, all infrastructure in the USA — не заявлен

Transfer timings

+241 ms web.cmp.usercentrics.eu

The CMP engine. IP 34.149.254.14 (Google Cloud, USA)

+241 ms privacy-proxy.usercentrics.eu

A script blocker. IP 35.190.14.188 (Google Cloud, USA)

+492 ms v1.api.service.cmp.usercentrics.eu

An API request, account p35w8mDt59xABk. IP 34.102.170.124 (Google Cloud)

+892 ms app.usercentrics.eu

A pixel-based session tracker. IP 35.190.14.188 (Google Cloud)

+1443 ms uct.service.usercentrics.eu

Telemetry carrying the page URL in the r= parameter. Status 0 — the request is initiated

+1679 ms graphql.usercentrics.eu

Status 204. A transfer with no response body. IP 34.120.238.166 (Google Cloud)

Detected trackers

Indicators of GDPR non-compliance

Context

Kaitseliit is Estonia’s voluntary paramilitary defense organization, operating under a dedicated statute (Kaitseliidu seadus). It processes data on members, prospective recruits, and staff, including data on state-secret clearances. The legal basis here spans Kaitseliit’s own law, the State Secrets Act, and GDPR simultaneously. The site is built on WordPress + Elementor, hosted on a server in Estonia (IP 217.146.69.28, Elisa Eesti).

Declaration versus fact — the reverse situation

Usually, sites fail to declare what’s actually running. Kaitseliit does the opposite: it declares something that doesn’t exist, and says nothing about what does.

The policy’s section on visitor data processing contains a detailed table of eight Google Analytics cookies (__utma, __utmb, __utmc, __utmt, __utmv, __utmz, fontSize, BWSIDc...) and states directly that the site uses Google Analytics from Google LLC. The session HAR from May 10, 2026: not a single request to any Google Analytics domain, not a single cookie from the declared table. Google Analytics is declared, but not running — it was quietly removed.

An undeclared sub-processor

What actually runs on the site is Usercentrics — a consent-management system. All 7 of its domains are served by Google Cloud infrastructure (IPs 34.149.254.14 / 35.190.14.188 / 34.102.170.124 / 34.120.238.166 / 35.201.111.240 — all USA). Usercentrics is a German company, but its entire technical infrastructure is American. The policy names Usercentrics neither as processor nor sub-processor; Google Cloud, as Usercentrics’ sub-processor, is not mentioned at all.

Checking the policy’s claims

The policy states that IP addresses are not linked to identifying information and are disclosed only in anonymized form. The HAR shows the opposite: the visitor’s IP address is transmitted to Usercentrics with every request, including the request to the consent-api, where the IP address is part of the browser’s HTTP connection setup. The CJEU’s Breyer ruling (C-582/14, 2016) established that a dynamic IP address is personal data if the operator has a legal means of identifying the user. The claim that the IP address is “anonymized” matches neither actual transfer practice nor the legal definition.

Conclusion

An organization whose members work with information classified as state secrets has a privacy policy that describes nonexistent analytics and says nothing about the real one. The site is connected to Usercentrics, whose servers sit on Google Cloud (USA), and the policy states no transfer mechanism. For comparison: eesti.ee — Estonia’s state portal — operates with not a single external domain, a strict CSP, and an allowlist. This proves it is architecturally possible to do otherwise.

Evidence
Original (audit)
HAR file: ee/kaitseliit-ee-2026-05-10.har
SHA-256: bf4d7d967eb07aeb0e6a5195cb731cc3bb22d4a9efd47e686bcff18bbc2c0653
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee

Important: AKI only handles submissions in Estonian. Translate the letter before sending.

To: Estonian Data Protection Inspectorate (AKI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website kaitseliit.ee.

2. Circumstances
I visited the website kaitseliit.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 10 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) A violation of the transparency principle. The policy declares Google Analytics, absent from the HAR, while failing to name the processor that actually runs: Usercentrics.

2) There is no legal basis for transmitting data to Usercentrics before consent is obtained. Requests fire before the user's choice.

3) Usercentrics GmbH and Google Cloud are not disclosed as data recipients. 7 subdomains, 40+ requests per session.

4) Personal data (IP address, URL, session identifiers) is transmitted to servers in the USA with no legal mechanism stated (SCC, adequacy decision).

5) Google Cloud, as Usercentrics' sub-processor, is not documented in the policy.

Full technical documentation is published at: https://gdpru.eu/en/audits/ee-kaitseliit-ee/

3. Provisions violated
GDPR Art. 5(1)(a); GDPR Art. 6(1); GDPR Art. 13(1)(e); GDPR Art. 13(1)(f), Chapter V; GDPR Art. 28(2)–(4)

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]