Estonia's largest real estate portal — 120,000 visitors a day. OneTrust with TCF 2.0 is implemented correctly in structure. But GA4 loads 1.3 seconds before the banner. Sentry uses an American CDN instead of the EU instance.
Timeline of the leak
Declared versus actual
Transfer timings
Open Sans. IP address to Google, USA
GA4 G-XSSYYGNPKF — 1,318 ms before OneTrust
GA4 collect
Sentry's American CDN
OneTrust TCF 2.0
Detected trackers
- Google Analytics GA4 (G-XSSYYGNPKF)
- Google Tag Manager (gtag via GTM)
- OneTrust with TCF 2.0 (cdn.cookielaw.org)
- Sentry (browser.sentry-cdn.com)
- Google Fonts (fonts.googleapis.com)
Indicators of GDPR non-compliance
- GDPR Art. 6(1), Art. 5(1)(a)Google Fonts (+225 ms), GTM/GA4 (+333 ms), and a GA collect (+568 ms) load before OneTrust appears (+1651 ms). Gap: 1,318 ms. Visit data goes to Google before the user sees the banner.
- GDPR Art. 7The GA collect fires at +568 ms. OneTrust only appears at +1651 ms. The GA collect transmits data with no consent.
- GDPR Art. 13(1)(e)The privacy policy is detailed and current (02.05.2024). Sentry loads from browser.sentry-cdn.com — an American CDN, not the EU instance. Not explicitly mentioned as a recipient.
- GDPR Art. 13(1)(f), Chapter VSentry, via an American CDN (browser.sentry-cdn.com) — data may be processed in the USA. No transfer mechanism is stated.
Context
kv.ee is Estonia’s largest real estate portal, operated by AllePal OÜ. The banner’s screenshot shows: 120,251 visitors yesterday. It carries listings for the sale and rental of apartments, houses, land plots, and commercial property. The privacy policy is current (02.05.2024) and detailed. HAR: 237 requests, 13 domains.
GA4 1.3 seconds before the banner
GTM/GA4 loads at +333 ms. OneTrust only at +1651 ms. The GA collect fires at +568 ms — almost a full second before the banner appears. Data about the visit to a real estate portal — including the IP address, listings viewed, and search price ranges — is transmitted to Google before any user interaction with the banner.
OneTrust with TCF 2.0 — correct structure
The banner is structurally implemented correctly: three cookie categories (functional, strictly necessary, targeting), “Luba kõik” / “Lükka kõik tagasi” / “Kinnita mu valikud” buttons, a link to the partner list. The IAB vendor list loads. The problem isn’t the banner’s structure, but the load order: GA4 should be blocked until consent.
Sentry — an American CDN
browser.sentry-cdn.com is Sentry’s American CDN, unlike ingest.de.sentry.io (the EU instance) used by IIZI, Zalando, and Yaga. Switching to the EU instance is a one-line configuration change.
Partner images
The page loads images from img-osta.ee (a listings portal), img13.img-bcg.eu (a Baltic Classifieds Group CDN), and img-kb.ee (Kuldne Börs). This means kv.ee aggregates listings from several platforms — the user’s IP address is transmitted to each of their infrastructures when viewing the page.
Conclusion
kv.ee is a major portal with a current privacy policy and OneTrust TCF 2.0. The main problem is that GA4 loads 1,318 ms before the banner. Sentry uses an American CDN instead of the EU instance. Both issues are technically simple: script load order, and one line of Sentry configuration.
0d26b1bee725a2944e6386e1e0b73a2d20c772c085149e575483b4a2a935eb44Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee
Important: AKI only handles submissions in Estonian. Translate the letter before sending.
To: Estonian Data Protection Inspectorate (AKI) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website kv.ee. 2. Circumstances I visited the website kv.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 6 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) Google Fonts (+225 ms), GTM/GA4 (+333 ms), and a GA collect (+568 ms) load before OneTrust appears (+1651 ms). Gap: 1,318 ms. Visit data goes to Google before the user sees the banner. 2) The GA collect fires at +568 ms. OneTrust only appears at +1651 ms. The GA collect transmits data with no consent. 3) The privacy policy is detailed and current (02.05.2024). Sentry loads from browser.sentry-cdn.com — an American CDN, not the EU instance. Not explicitly mentioned as a recipient. 4) Sentry, via an American CDN (browser.sentry-cdn.com) — data may be processed in the USA. No transfer mechanism is stated. Full technical documentation is published at: https://gdpru.eu/en/audits/ee-kv-ee/ 3. Provisions violated GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 7; GDPR Art. 13(1)(e); GDPR Art. 13(1)(f), Chapter V 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]