The Chamber of Commerce — the voice of business, teaching entrepreneurs how to operate correctly. On its own site, the banner states: clicking any link constitutes consent — a practice explicitly prohibited by GDPR. By the time the user sees the banner, data has already been transmitted to six services.
Timeline of the leak
Declared versus actual
Transfer timings
GTM — blocked by the browser, but the request went out, IP address to Google
Status 200. ~1.5 MB per session. API key exposed in the HAR
Session recorder. Response blocked, request sent. Data to the USA
No exact timing
Detected trackers
- Google Maps API
- Microsoft Clarity (session recorder)
- Google Tag Manager
- AddToAny
- CartoCDN, unpkg, jsDelivr
Indicators of GDPR non-compliance
- GDPR Art. 6(1), Art. 5(1)(a)Google Maps API, basemaps.cartocdn.com, unpkg.com, and cdn.jsdelivr.net fire 248–545 ms before any consent — actual transfers, status 200.
- GDPR Art. 7, Recital 32'Consent by continued use': the banner states that clicking any link constitutes consent. This is a practice explicitly prohibited by EDPB Guidelines 05/2020. There is no 'Reject' or 'Customize' button.
- GDPR Art. 13(1)(e)Microsoft Clarity, basemaps.cartocdn.com, AddToAny, unpkg.com, and cdn.jsdelivr.net are not declared. The cookie table lists only Google Analytics.
- GDPR Art. 13(1)(f), Chapter VNo cross-border data transfer mechanism to the USA is stated for any recipient — neither SCC nor an adequacy decision.
- GDPR Art. 5(1)(e)The privacy policy has not been updated in 8 years (since 25.05.2018 — the date GDPR came into force), despite an actual change in the roster of processors.
Context
Eesti Kaubandus-Tööstuskoda is the Estonian Chamber of Commerce and Industry. It represents entrepreneurs’ interests, processes data on thousands of member companies, and advises on running a business, including in the digital environment. HAR: 319 requests per session, 5 pages.
The main issue — the consent mechanism doesn’t work
The site has a banner, but it’s structurally broken. Its text: “By clicking any link on this page, you confirm that you agree…” This is not consent: under GDPR Recital 32, consent requires an unambiguous affirmative action, and clicking an arbitrary link does not qualify — EDPB Guidelines 05/2020 explicitly prohibit this practice (“consent by continued use”). There is no “Reject” button, no “Customize” button — the only option is to agree. And by the time the user sees the banner, the data has already been transmitted: consent is requested after the fact.
What goes out before consent
On every page load, GTM (+248 ms), AddToAny (+253 ms), Google Maps API (+254 ms), and Microsoft Clarity (+268 ms) fire, along with CartoCDN, unpkg.com, and cdn.jsdelivr.net. Google Maps actually transmitted roughly 1.5 MB of data to Google per session (313,583 bytes on each of 5 pages), and the API key is exposed directly in the HAR file. Microsoft Clarity is a session recorder, capturing mouse movements and clicks. Some requests were blocked by the browser, but all of them had been initiated — the user’s IP address reached servers in the USA.
A policy frozen in 2018
The privacy policy was last updated on May 25, 2018 — the day GDPR came into force. Eight years, not a single update. Only Google Analytics is declared in the cookie table; Google Maps API, Microsoft Clarity, AddToAny, CartoCDN, unpkg, and jsDelivr go unmentioned. Six services actually run on the site, and the user knows nothing about them (Art. 13(1)(e)). A policy unchanged for 8 years, despite an actual change in the roster of processors, is a violation of Art. 5(1)(e).
Conclusion
The Chamber of Commerce sets standards, protects entrepreneurs’ interests, and teaches how to operate correctly. But customers’ digital rights don’t start with a brochure — they start with the organization’s own website. If an organization that advises businesses on legal matters doesn’t know what’s happening on its own site, that’s no longer just a technical question. It’s a question of trust.
b28ed794ea35cccd31aede1adc373f2bf30d1c99eb66ee89b680e94ecd711242Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee
Important: AKI only handles submissions in Estonian. Translate the letter before sending.
To: Estonian Data Protection Inspectorate (AKI) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website koda.ee. 2. Circumstances I visited the website koda.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 13 April 2026 (open methodology, reproducible measurements) documents the following indications: 1) Google Maps API, basemaps.cartocdn.com, unpkg.com, and cdn.jsdelivr.net fire 248–545 ms before any consent — actual transfers, status 200. 2) 'Consent by continued use': the banner states that clicking any link constitutes consent. This is a practice explicitly prohibited by EDPB Guidelines 05/2020. There is no 'Reject' or 'Customize' button. 3) Microsoft Clarity, basemaps.cartocdn.com, AddToAny, unpkg.com, and cdn.jsdelivr.net are not declared. The cookie table lists only Google Analytics. 4) No cross-border data transfer mechanism to the USA is stated for any recipient — neither SCC nor an adequacy decision. 5) The privacy policy has not been updated in 8 years (since 25.05.2018 — the date GDPR came into force), despite an actual change in the roster of processors. Full technical documentation is published at: https://gdpru.eu/en/audits/ee-koda-ee/ 3. Provisions violated GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 7, Recital 32; GDPR Art. 13(1)(e); GDPR Art. 13(1)(f), Chapter V; GDPR Art. 5(1)(e) 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]