An organization whose members work with state-secret-classified information. The policy describes nonexistent Google analytics and says nothing about the real one — Usercentrics — whose servers sit on Google Cloud, in the USA.
Timeline of the leak
Declared versus actual
Transfer timings
The CMP engine. IP 34.149.254.14 (Google Cloud, USA)
A script blocker. IP 35.190.14.188 (Google Cloud, USA)
An API request, account p35w8mDt59xABk. IP 34.102.170.124 (Google Cloud)
A pixel-based session tracker. IP 35.190.14.188 (Google Cloud)
Telemetry carrying the page URL in the r= parameter. Status 0 — the request is initiated
Status 204. A transfer with no response body. IP 34.120.238.166 (Google Cloud)
Detected trackers
- Usercentrics (Cookiebot CMP)
- Google Cloud (Usercentrics' sub-processor)
Indicators of GDPR non-compliance
- GDPR Art. 5(1)(a)A violation of the transparency principle. The policy declares Google Analytics, absent from the HAR, while failing to name the processor that actually runs: Usercentrics.
- GDPR Art. 6(1)There is no legal basis for transmitting data to Usercentrics before consent is obtained. Requests fire before the user's choice.
- GDPR Art. 13(1)(e)Usercentrics GmbH and Google Cloud are not disclosed as data recipients. 7 subdomains, 40+ requests per session.
- GDPR Art. 13(1)(f), Chapter VPersonal data (IP address, URL, session identifiers) is transmitted to servers in the USA with no legal mechanism stated (SCC, adequacy decision).
- GDPR Art. 28(2)–(4)Google Cloud, as Usercentrics' sub-processor, is not documented in the policy.
Context
Kaitseliit is Estonia’s voluntary paramilitary defense organization, operating under a dedicated statute (Kaitseliidu seadus). It processes data on members, prospective recruits, and staff, including data on state-secret clearances. The legal basis here spans Kaitseliit’s own law, the State Secrets Act, and GDPR simultaneously. The site is built on WordPress + Elementor, hosted on a server in Estonia (IP 217.146.69.28, Elisa Eesti).
Declaration versus fact — the reverse situation
Usually, sites fail to declare what’s actually running. Kaitseliit does the opposite: it declares something that doesn’t exist, and says nothing about what does.
The policy’s section on visitor data processing contains a detailed table of eight Google Analytics cookies (__utma, __utmb, __utmc, __utmt, __utmv, __utmz, fontSize, BWSIDc...) and states directly that the site uses Google Analytics from Google LLC. The session HAR from May 10, 2026: not a single request to any Google Analytics domain, not a single cookie from the declared table. Google Analytics is declared, but not running — it was quietly removed.
An undeclared sub-processor
What actually runs on the site is Usercentrics — a consent-management system. All 7 of its domains are served by Google Cloud infrastructure (IPs 34.149.254.14 / 35.190.14.188 / 34.102.170.124 / 34.120.238.166 / 35.201.111.240 — all USA). Usercentrics is a German company, but its entire technical infrastructure is American. The policy names Usercentrics neither as processor nor sub-processor; Google Cloud, as Usercentrics’ sub-processor, is not mentioned at all.
Checking the policy’s claims
The policy states that IP addresses are not linked to identifying information and are disclosed only in anonymized form. The HAR shows the opposite: the visitor’s IP address is transmitted to Usercentrics with every request, including the request to the consent-api, where the IP address is part of the browser’s HTTP connection setup. The CJEU’s Breyer ruling (C-582/14, 2016) established that a dynamic IP address is personal data if the operator has a legal means of identifying the user. The claim that the IP address is “anonymized” matches neither actual transfer practice nor the legal definition.
Conclusion
An organization whose members work with information classified as state secrets has a privacy policy that describes nonexistent analytics and says nothing about the real one. The site is connected to Usercentrics, whose servers sit on Google Cloud (USA), and the policy states no transfer mechanism. For comparison: eesti.ee — Estonia’s state portal — operates with not a single external domain, a strict CSP, and an allowlist. This proves it is architecturally possible to do otherwise.
bf4d7d967eb07aeb0e6a5195cb731cc3bb22d4a9efd47e686bcff18bbc2c0653Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee
Important: AKI only handles submissions in Estonian. Translate the letter before sending.
To: Estonian Data Protection Inspectorate (AKI) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website kaitseliit.ee. 2. Circumstances I visited the website kaitseliit.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 10 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) A violation of the transparency principle. The policy declares Google Analytics, absent from the HAR, while failing to name the processor that actually runs: Usercentrics. 2) There is no legal basis for transmitting data to Usercentrics before consent is obtained. Requests fire before the user's choice. 3) Usercentrics GmbH and Google Cloud are not disclosed as data recipients. 7 subdomains, 40+ requests per session. 4) Personal data (IP address, URL, session identifiers) is transmitted to servers in the USA with no legal mechanism stated (SCC, adequacy decision). 5) Google Cloud, as Usercentrics' sub-processor, is not documented in the policy. Full technical documentation is published at: https://gdpru.eu/en/audits/ee-kaitseliit-ee/ 3. Provisions violated GDPR Art. 5(1)(a); GDPR Art. 6(1); GDPR Art. 13(1)(e); GDPR Art. 13(1)(f), Chapter V; GDPR Art. 28(2)–(4) 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]