Technical audit · 2026-04-13

koda.ee

Representing Business Interests

The Chamber of Commerce — the voice of business, teaching entrepreneurs how to operate correctly. On its own site, the banner states: clicking any link constitutes consent — a practice explicitly prohibited by GDPR. By the time the user sees the banner, data has already been transmitted to six services.

Timeline of the leak

+248–268 ms · before consent
GTM (+248 ms), AddToAny (+253 ms), Google Maps API (+254 ms, status 200), Microsoft Clarity (+268 ms) fire on every page load. Some are blocked by the browser, but the requests had already gone out — the IP address reached servers in the USA.
Consent banner — broken
Text: 'By clicking any link, you confirm your consent.' This is not consent under Recital 32. There is no 'Reject' button, no 'Customize' button. There is one option — agree. The banner appears after all the requests.
Per session
Google Maps actually transmitted roughly 1.5 MB (313,583 bytes × 5 pages) to Google without consent, with the API key exposed in the HAR. CartoCDN — 164,836 bytes. unpkg and jsDelivr — CDNs in the USA.

Declared versus actual

Google Analytics — the only entry in the cookie table — заявлен
+ Google Maps API — ~1.5 MB per session, key exposed — не заявлен
+ Microsoft Clarity — a session recorder — не заявлен
+ AddToAny, basemaps.cartocdn.com, unpkg.com, cdn.jsdelivr.net — не заявлен

Transfer timings

+248 ms www.googletagmanager.com

GTM — blocked by the browser, but the request went out, IP address to Google

+254 ms Google Maps API

Status 200. ~1.5 MB per session. API key exposed in the HAR

+268 ms Microsoft Clarity

Session recorder. Response blocked, request sent. Data to the USA

No exact timing

in the background basemaps.cartocdn.comA mapping service, 164,836 bytes. Absent from the policy

Detected trackers

Indicators of GDPR non-compliance

Context

Eesti Kaubandus-Tööstuskoda is the Estonian Chamber of Commerce and Industry. It represents entrepreneurs’ interests, processes data on thousands of member companies, and advises on running a business, including in the digital environment. HAR: 319 requests per session, 5 pages.

The site has a banner, but it’s structurally broken. Its text: “By clicking any link on this page, you confirm that you agree…” This is not consent: under GDPR Recital 32, consent requires an unambiguous affirmative action, and clicking an arbitrary link does not qualify — EDPB Guidelines 05/2020 explicitly prohibit this practice (“consent by continued use”). There is no “Reject” button, no “Customize” button — the only option is to agree. And by the time the user sees the banner, the data has already been transmitted: consent is requested after the fact.

On every page load, GTM (+248 ms), AddToAny (+253 ms), Google Maps API (+254 ms), and Microsoft Clarity (+268 ms) fire, along with CartoCDN, unpkg.com, and cdn.jsdelivr.net. Google Maps actually transmitted roughly 1.5 MB of data to Google per session (313,583 bytes on each of 5 pages), and the API key is exposed directly in the HAR file. Microsoft Clarity is a session recorder, capturing mouse movements and clicks. Some requests were blocked by the browser, but all of them had been initiated — the user’s IP address reached servers in the USA.

A policy frozen in 2018

The privacy policy was last updated on May 25, 2018 — the day GDPR came into force. Eight years, not a single update. Only Google Analytics is declared in the cookie table; Google Maps API, Microsoft Clarity, AddToAny, CartoCDN, unpkg, and jsDelivr go unmentioned. Six services actually run on the site, and the user knows nothing about them (Art. 13(1)(e)). A policy unchanged for 8 years, despite an actual change in the roster of processors, is a violation of Art. 5(1)(e).

Conclusion

The Chamber of Commerce sets standards, protects entrepreneurs’ interests, and teaches how to operate correctly. But customers’ digital rights don’t start with a brochure — they start with the organization’s own website. If an organization that advises businesses on legal matters doesn’t know what’s happening on its own site, that’s no longer just a technical question. It’s a question of trust.

Evidence
Original (audit)
HAR file: ee/koda-ee-2026-04-13.har
SHA-256: b28ed794ea35cccd31aede1adc373f2bf30d1c99eb66ee89b680e94ecd711242
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee

Important: AKI only handles submissions in Estonian. Translate the letter before sending.

To: Estonian Data Protection Inspectorate (AKI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website koda.ee.

2. Circumstances
I visited the website koda.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 13 April 2026 (open methodology, reproducible measurements) documents the following indications:

1) Google Maps API, basemaps.cartocdn.com, unpkg.com, and cdn.jsdelivr.net fire 248–545 ms before any consent — actual transfers, status 200.

2) 'Consent by continued use': the banner states that clicking any link constitutes consent. This is a practice explicitly prohibited by EDPB Guidelines 05/2020. There is no 'Reject' or 'Customize' button.

3) Microsoft Clarity, basemaps.cartocdn.com, AddToAny, unpkg.com, and cdn.jsdelivr.net are not declared. The cookie table lists only Google Analytics.

4) No cross-border data transfer mechanism to the USA is stated for any recipient — neither SCC nor an adequacy decision.

5) The privacy policy has not been updated in 8 years (since 25.05.2018 — the date GDPR came into force), despite an actual change in the roster of processors.

Full technical documentation is published at: https://gdpru.eu/en/audits/ee-koda-ee/

3. Provisions violated
GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 7, Recital 32; GDPR Art. 13(1)(e); GDPR Art. 13(1)(f), Chapter V; GDPR Art. 5(1)(e)

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]