Technical audit · 2026-05-05

lasteabi.ee

State Helpline for Children and Adolescents

A state helpline for children in crisis situations. Matomo fires at the zero-millisecond mark — no banner, no consent. The privacy policy is copied from the Social Insurance Board's website and mentions none of the actual data recipients.

Timeline of the leak

+0 ms · on load
Matomo (matomo.tehik.ee) — the first request of the session. Analytics on the Estonian TEHIK server fires immediately, with no consent.
+408 ms · before consent
Google Fonts (fonts.gstatic.com) — the Jost typeface, 2 requests. The user's IP address to Google, USA.
Consent banner
Absent. Zero consent requests across a session lasting over 2 minutes.
+5175 ms · before consent
Siteimprove Analytics (siteimproveanalytics.com) — status 0, blocked. Cloudflare Insights (static.cloudflareinsights.com) — status 0, blocked.
+5176 ms · before consent
fonts.googleapis.com — fonts reload on navigation between pages.

Declared versus actual

Siteimprove — mentioned in the policy (nmstat cookie) — заявлен
Cloudflare (__cf_bm, _cfuvid) — mentioned as necessary — заявлен
AddThis (__atuvc, __atuvs) — declared, but discontinued by Oracle in 2023 — заявлен
+ Matomo (matomo.tehik.ee) — not mentioned in the policy — не заявлен
+ Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — not mentioned — не заявлен

Transfer timings

+0 ms matomo.tehik.ee

The first request of the session. 4 times per session

+408 ms fonts.gstatic.com

Google Fonts Jost. IP address to the USA

+5175 ms siteimproveanalytics.com

Status 0. Wired in, but did not execute

+5364 ms static.cloudflareinsights.com

Status 0. Wired in, but did not execute

Detected trackers

Indicators of GDPR non-compliance

Context

lasteabi.ee is Estonia’s state helpline for children and adolescents, run by Sotsiaalkindlustusamet (the Social Insurance Board). The site serves children and adolescents in crisis situations: abuse, bullying, psychological problems, family conflicts. Infrastructure is hosted on TEHIK (Ministry of Finance) servers. HAR: 195 requests, 8 domains, a session lasting over 2 minutes with navigation between pages.

Matomo from second zero

The first request of the session — matomo.tehik.ee/piwik/matomo.js — is initiated at the zero-millisecond mark. Before any page content. Matomo runs on the TEHIK server — Estonian state infrastructure, which is itself better than Google Analytics. But firing analytics with no consent on a site intended for children in crisis is a violation regardless of where the server is located. Matomo loads 4 times per session, on every page navigation.

Across a session lasting over 2 minutes, with multiple page navigations — zero consent requests, zero Set-Cookie responses. There is no banner at all. This is not a technical failure — it is an architectural choice.

Google Fonts

fonts.gstatic.com (+408 ms) — the Jost typeface, 2 requests on first load and again on every navigation. The user’s IP address is transmitted to Google (USA) on every page. For a child opening the site to seek help, this means Google knows about every one of their visits to the children’s helpline.

Siteimprove and Cloudflare — blocked

Siteimprove Analytics (+5175 ms) and Cloudflare Insights (+5364 ms) are wired into the code but return status 0 — they did not execute. This is partial protection, likely via a CSP or a blocker. The policy mentions Siteimprove (cookie nmstat) and Cloudflare (__cf_bm, _cfuvid) as necessary. Siteimprove was blocked — no data was transmitted in the HAR.

The policy is copied from sotsiaalkindlustusamet.ee

Every cookie in the policy is listed with the source www.sotsiaalkindlustusamet.ee — the Social Insurance Board’s website, not lasteabi.ee. An exact parallel to riigikontroll.ee, where the policy was copied from the Ministry of Finance. The policy declares AddThis (__atuvc, __atuvs) — a service discontinued by Oracle in May 2023. Matomo and Google Fonts — the actual data recipients — go unmentioned in the policy.

The GDPR Art. 8 context

GDPR Art. 8 establishes special requirements for processing children’s data. This site is addressed to minors in a vulnerable state — precisely those seeking help amid abuse or crisis. Processing their data with no consent and no special protective measures requires a separate legal justification, which the policy does not provide.

Conclusion

A state helpline for children fires analytics at second zero and transmits each child’s IP address to Google on every page navigation. There is no consent banner. The privacy policy is copied from another site and describes none of the actual data recipients. eesti.ee proves that a government site can operate with not a single external tracker. For a children’s helpline, that is not an option — it is an obligation.

Evidence
Original (audit)
HAR file: ee/lasteabi-ee-2026-05-05.har
SHA-256: 82f962cd2e6eac49c652091bbdcc247802467875b467b586241689089e35234c
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee

Important: AKI only handles submissions in Estonian. Translate the letter before sending.

To: Estonian Data Protection Inspectorate (AKI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website lasteabi.ee.

2. Circumstances
I visited the website lasteabi.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 5 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) Matomo fires at the zero-millisecond mark of the session — before any interaction. Google Fonts loads at +408 ms. There is no consent banner at all.

2) There is no consent mechanism. Zero consent requests, zero Set-Cookie responses across a session lasting over 2 minutes.

3) The site is intended for children and adolescents in crisis situations. Processing their data with no consent and no special protective measures violates the requirements for processing minors' data.

4) The privacy policy declares Siteimprove, AddThis, and Cloudflare. Matomo (matomo.tehik.ee) and Google Fonts are not mentioned as data recipients. AddThis is declared, but was discontinued by Oracle in 2023.

5) Google Fonts transmits the user's IP address to Google (USA). Siteimprove is a Danish company, with data partly processed in the USA. No transfer mechanism is stated.

6) The privacy policy was last updated 08.12.2025 and contains references to the source www.sotsiaalkindlustusamet.ee — the website of the Social Insurance Board, not lasteabi.ee. Analogous to riigikontroll: the policy was copied without adaptation.

Full technical documentation is published at: https://gdpru.eu/en/audits/ee-lasteabi-ee/

3. Provisions violated
GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 7; GDPR Art. 8; GDPR Art. 13(1)(e); GDPR Art. 13(1)(f), Chapter V; GDPR Art. 5(1)(a)

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]