Technical audit · 2026-05-02

oiguskantsler.ee

Constitutional Ombudsman, Protecting Citizens' Rights Against the State

An institution that protects citizens' rights against state overreach — the last barrier before court. Technically, the site is nearly exemplary: zero Google Analytics, zero DoubleClick, a working CSP. But a single Google Fonts call transmits the visitor's IP address to the USA, and the privacy policy is one of the weakest in this series.

Timeline of the leak

+233 ms · before consent
fonts.googleapis.com — status 200, 4 requests. Followed by fonts.gstatic.com (+261 ms, 8 requests): the Roboto Flex typeface from Google's servers in the USA. IP address, User-Agent, and Referer (oiguskantsler.ee) go to Google.
Consent banner
Completely absent. The transfer to Google happens automatically on the first page load, with no asking.
What is blocked
Cloudflare Insights — status 0, the CSP worked, no data got out (a rarity in this series). Matomo on statistika.rik.ee (RIK's state server) — data stays within Estonia. Social media icons — local.

Declared versus actual

In abstract terms: 'a tool that collects general data' — with no names given — заявлен
'Data is available only in non-personalized form' — заявлен
+ Google Fonts — IP address to the USA, unnamed — не заявлен
+ Matomo / statistika.rik.ee — unnamed — не заявлен
+ No cookie policy whatsoever — не заявлен

Transfer timings

+233 ms fonts.googleapis.com

Google Fonts, 4 requests, status 200

+261 ms fonts.gstatic.com

The Roboto Flex typeface, 8 requests. IP address to Google (USA)

No exact timing

on load static.cloudflareinsights.comStatus 0 — the CSP worked, no data got out
per session statistika.rik.ee (Matomo)Matomo on RIK's state server (Estonia) — the correct choice

Detected trackers

Indicators of GDPR non-compliance

Context

oiguskantsler.ee is the website of Estonia’s Chancellor of Justice, the constitutional ombudsman. This institution exists for one purpose — to protect citizens’ rights against state overreach: verifying laws’ compliance with the Constitution, receiving complaints from people wronged by the state, advising parliament and government. The last internal barrier before court — the body people turn to when everything else has failed. HAR: 240 requests, 5 domains.

What is done correctly — and it deserves recognition

No Google Tag Manager, no Google Analytics, no DoubleClick, no browser-update.org — this alone sets the site apart from most government portals in this series. Analytics runs via Matomo on statistika.rik.ee (a server belonging to Estonia’s Information System Authority Registry Center) — visit data stays within the country. Cloudflare Insights attempted to load and was blocked by the CSP (status 0) — a rarity in this series; someone configured the CSP, and it works. Social media icons are local (.png and .svg served from the proprietary server), with no requests to Facebook, LinkedIn, or Twitter.

What is not done — Google Fonts

fonts.googleapis.com (+233 ms) and fonts.gstatic.com (+261 ms) load the Roboto Flex typeface from Google’s servers in the USA. Every request transmits the user’s IP address, User-Agent (browser, OS, version), Referer (oiguskantsler.ee), and the time of the request. In 2022, the CJEU, in a case against a German website, found this exact transfer to be a GDPR violation and ordered compensation to be paid — a precedent exists. There is no consent banner; the transfer to Google happens automatically on the first page load.

The policy — one of the weakest in this series

The policy states that data is available to the chancellery “only in non-personalized form” — yet an IP address transmitted to Google is, by definition, personal data (the Breyer case, C-582/14). Data recipients are not named at all: neither Google, nor Cloudflare, nor Matomo — only an abstract “a tool that collects general data” (Art. 13(1)(e)). Not a word about the transfer to the USA (Art. 13(1)(f)). There is no cookie policy whatsoever: no table, no list, no mention, despite the site using cookies via Matomo. By comparison, sotsiaalkindlustusamet.ee, within the same branch of government, has a full cookie table — a standard absent here.

Conclusion

Who visits the Chancellor of Justice’s website? Someone with a problem involving the state: an unlawful official decision, a violation of constitutional rights, a complaint against the police or the courts. The very fact of turning to the ombudsman says something about a person’s situation — and at that moment, their IP address goes to Google with no knowledge or consent. But the fix here is a single technical step: Roboto Flex can be self-hosted within a few hours, followed by updating the policy and naming recipients by name. The CSP already works, and Matomo on a state server is the right choice. One font and one policy separate this site from a clean architecture. The institution that teaches others how to protect citizens’ rights should start with its own website.

Evidence
Original (audit)
HAR file: ee/oiguskantsler-ee-2026-05-02.har
SHA-256: a4bcfc21c4837711043bfc59063833cf440b5c68e4c96480f67e3eb567603991
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee

Important: AKI only handles submissions in Estonian. Translate the letter before sending.

To: Estonian Data Protection Inspectorate (AKI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website oiguskantsler.ee.

2. Circumstances
I visited the website oiguskantsler.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 2 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) Google Fonts (fonts.googleapis.com +233 ms, fonts.gstatic.com +261 ms) transmits the user's IP address to Google (USA) with no consent. In 2022, the CJEU found this exact transfer to be a violation.

2) There is no consent mechanism whatsoever. Not a single consent request in the session. The transfer to Google happens automatically on the first page load.

3) The policy states that data is available to the chancellery 'only in non-personalized form.' Yet an IP address (personal data per the Breyer ruling) goes to Google. A direct contradiction.

4) Data recipients are not named at all — neither Google, nor Cloudflare, nor Matomo/RIK. The policy is abstract. There is no cookie policy whatsoever, despite the site using cookies via Matomo.

5) Data transfer to the USA (Google Fonts) with no mechanism stated — neither SCC nor an adequacy decision. Privacy Shield was invalidated in 2020.

Full technical documentation is published at: https://gdpru.eu/en/audits/ee-oiguskantsler-ee/

3. Provisions violated
GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 7; GDPR Art. 5(1)(a); GDPR Art. 12(1), Art. 13(1)(e); GDPR Art. 13(1)(f), Chapter V

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]