ohtuleht.ee
883 requests, 149 domains. An InMobi CMP with TCF 2.0 — yet cookie-sync requests fire with gdpr=0, the same pattern found at Temu. The partner list includes Baidu USA and IFLYTEK (Hong Kong). GPT loads before the banner, and no consent decision was ever recorded across the entire session.
Timeline of the leak
Declared versus actual
Transfer timings
advertising.js — before consent
GPT — advertising infrastructure
TCF 2.0 banner
fbevents.js — the Pixel fires
Cookie sync with gdpr=0&gdpr_consent=
The same pattern as InMobi
Detected trackers
- InMobi CMP with TCF 2.0 (cmp.inmobi.com)
- Google Publisher Tag / GPT (securepubads.g.doubleclick.net)
- Google Tag Manager (GTM-NJBX26)
- Google Analytics GA4 (G-4VJVM198JT)
- Google Ads (AW-950017448, AW-944384132)
- TikTok Pixel (analytics.tiktok.com)
- Meta Pixel (connect.facebook.net, www.facebook.com)
- Temu / PDD Holdings (www.temu.com)
- Gemius (gaee.hit.gemius.pl)
- Cxense (cdn.cxense.com)
- NPTTech (www.npttech.com)
- JW Player (jwplatform.com, jwplayer.com)
- Setupad (wb.setupad.com, prebid-stag.setupad.net)
- Criteo (gum.criteo.com, ssp-sync.criteo.com)
- OneSignal (onesignal.com)
- Prebid header bidding (numerous SSP partners)
- Cookie sync: Sparteo, SmileWanted, OpenX, Adform, Onetag, Lijit, BetweenDigital, 1rx, RichAudience, FreeWheel, and others
Indicators of GDPR non-compliance
- GDPR Art. 6(1), Art. 5(1)(a)GPT (DoubleClick, +1729 ms), npttech.com (+186 ms), Cloudflare Insights (+162 ms), and Google Fonts (+314 ms) load before the InMobi CMP appears (+2166 ms). Advertising infrastructure initializes before the banner.
- GDPR Art. 4(11), Art. 7(1)Across the entire session (roughly 65 seconds), the InMobi CMP logs record not a single consent-acceptance or consent-rejection event — only system events for the banner opening. Meanwhile, Google Tag Manager (+5910 ms), Meta Pixel (+6150 ms), and TikTok Pixel (+6156 ms) fire and send events regardless of the fact that no user decision has been made.
- GDPR Art. 7, TCF 2.0The InMobi CMP sends cookie-sync requests carrying the parameters gdpr=0 and an empty gdpr_consent=: sync.inmobi.com/oRTB?gdpr=0&gdpr_consent=. This means identifier synchronization across ad networks occurs as if the user were outside the scope of GDPR. The same flag independently appears in Temu's pixel requests.
- GDPR Art. 13(1)(e)The partner list includes hundreds of vendors, including Baidu USA LLC, IFLYTEK (HONG KONG) COMPANY LIMITED, and TECDO TECHNOLOGY CO. LIMITED — Chinese companies subject to Chinese data-access legislation. No mechanism for transferring data to China is stated.
- GDPR Art. 44, Chapter VAmong the IAB partners are Baidu USA LLC (a Baidu subsidiary, PRC) and IFLYTEK Hong Kong (an iFLYTEK subsidiary, PRC). Additionally, Temu (operated by Whaleco Inc., a subsidiary of PDD Holdings, headquartered in Shanghai) is recorded directly in network requests. European users' data is potentially accessible to Chinese authorities.
Context
Õhtuleht is Estonia’s largest tabloid. Publisher: AS Õhtuleht Kirjastus, jointly owned in equal shares by Ekspress Grupp and AVH Grupp until 2026; in April 2026, Estonia’s Competition Authority approved Ekspress Grupp’s buyout of the remaining stake. One of the country’s most-visited news sites. HAR: 883 requests, 149 unique domains. Session on an article page.
149 domains — a full-cycle advertising ecosystem
A full-fledged programmatic infrastructure: Google Publisher Tag, Prebid header bidding via Setupad, cookie sync with dozens of SSPs, analytics via Gemius and Cxense. The homepage carries no Content-Security-Policy header whatsoever, but a CSP header on one of the site’s internal backend domains reveals staging environments pointing to use of the Piano platform (paid access) — a service not directly visible through ordinary third-party requests.
Consent: the banner appeared, the decision didn’t
The InMobi CMP starts at the two-second mark and fully loads by the four-second mark. But the CMP’s own logs, across the entire session (roughly 65 seconds), record only system events for the banner opening — not a single acceptance or rejection event. The user never made a decision. Despite this, throughout the entire session, the following run without pause: the Google tag and the GTM container itself, Meta Pixel, TikTok Pixel, the Temu pixel, and the cookie-sync chain across dozens of SSPs. The banner’s appearance had no effect on their operation — they don’t wait for a decision, because a decision isn’t actively requested.
gdpr=0 — not an isolated case
The InMobi CMP implements TCF 2.0 and loads a vendor list in Estonian. But cookie-sync requests fire with the parameter gdpr=0&gdpr_consent= (an empty string) — identifier synchronization proceeds as if the user were physically located outside GDPR’s scope. The same pattern is independently found in Temu’s pixel requests: this match across two unrelated vendors points to a systemic CMP configuration issue, not an isolated error.
Direct leaks with no consent
Before the banner: Cloudflare, NPTTech, Google (Fonts). After the banner, but with no decision recorded: Google (Ads, Analytics, Publisher Tag, GTM), Meta, TikTok, Temu, InMobi, OpenX, Criteo, SmileWanted, SmartAdserver, Adform, Onetag, Setupad — and roughly forty more SSP partners via cookie sync.
e0a0c71a3634c90996d27e2eb72f50aaa0961c238f77a827592aca66f513556eWhere to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee
Important: AKI only handles submissions in Estonian. Translate the letter before sending.
To: Estonian Data Protection Inspectorate (AKI) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website ohtuleht.ee. 2. Circumstances I visited the website ohtuleht.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 6 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) GPT (DoubleClick, +1729 ms), npttech.com (+186 ms), Cloudflare Insights (+162 ms), and Google Fonts (+314 ms) load before the InMobi CMP appears (+2166 ms). Advertising infrastructure initializes before the banner. 2) Across the entire session (roughly 65 seconds), the InMobi CMP logs record not a single consent-acceptance or consent-rejection event — only system events for the banner opening. Meanwhile, Google Tag Manager (+5910 ms), Meta Pixel (+6150 ms), and TikTok Pixel (+6156 ms) fire and send events regardless of the fact that no user decision has been made. 3) The InMobi CMP sends cookie-sync requests carrying the parameters gdpr=0 and an empty gdpr_consent=: sync.inmobi.com/oRTB?gdpr=0&gdpr_consent=. This means identifier synchronization across ad networks occurs as if the user were outside the scope of GDPR. The same flag independently appears in Temu's pixel requests. 4) The partner list includes hundreds of vendors, including Baidu USA LLC, IFLYTEK (HONG KONG) COMPANY LIMITED, and TECDO TECHNOLOGY CO. LIMITED — Chinese companies subject to Chinese data-access legislation. No mechanism for transferring data to China is stated. 5) Among the IAB partners are Baidu USA LLC (a Baidu subsidiary, PRC) and IFLYTEK Hong Kong (an iFLYTEK subsidiary, PRC). Additionally, Temu (operated by Whaleco Inc., a subsidiary of PDD Holdings, headquartered in Shanghai) is recorded directly in network requests. European users' data is potentially accessible to Chinese authorities. Full technical documentation is published at: https://gdpru.eu/en/audits/ee-ohtuleht-ee/ 3. Provisions violated GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 4(11), Art. 7(1); GDPR Art. 7, TCF 2.0; GDPR Art. 13(1)(e); GDPR Art. 44, Chapter V 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]