One of the best government sites in this series in terms of its own architecture: state-run Matomo, a state-run chatbot, zero Google, zero advertising networks. And yet — three layers of Cloudflare at entry, on the page, and in the content. The core problem isn't the site itself, but RIA's decision to put the entire country behind an American gateway.
Timeline of the leak
Declared versus actual
Transfer timings
Bot Management / Turnstile, 16 requests. Fingerprint to the USA before consent
The first attempts are blocked (status 0), then it fires (200)
No exact timing
Detected trackers
- Cloudflare Bot Management (Turnstile)
- Cloudflare Insights
- Cloudflare CDN (cdnjs)
- Matomo (piwik.smit.ee)
Indicators of GDPR non-compliance
- GDPR Art. 6(1), Art. 5(1)(a)Cloudflare receives every visitor's data at three levels (entry, page, content) with no consent and no legal basis.
- GDPR Art. 7There is no consent mechanism. Cloudflare's entry-point check happens before any consent or interaction.
- GDPR Art. 13(1)(e)Cloudflare (19 actual transfers) is not declared as a recipient. Meanwhile, the policy declares Google Maps, Facebook, LinkedIn, and Twitter — all with zero requests in the HAR.
- GDPR Art. 13(1)(f), Chapter VNo data-transfer mechanism to the USA (Cloudflare) is stated. The transfer occurs with no SCC.
- GDPR Art. 5(1)(a) — CSP stabilityThe policy implies control, but the CSP is unstable: on a repeat visit, Cloudflare Insights fires consistently (status 200) after Bot Management has been passed.
Context
politsei.ee is the website of Estonia’s Police and Border Guard Board (PPA). It issues passports, visas, and residence permits, investigates crimes, and registers foreign nationals — one of the largest departments with direct citizen contact. HAR: 217 requests, 6 domains.
A systemic finding — three layers of Cloudflare
For the first time in this series, a government site shows an explicit challenge page: “Verifying you are human. This website uses a security service to protect against malicious bots.” This is Cloudflare Bot Management, and every Estonian government site sits behind it. Cloudflare operates at three levels. Level 1 — entry: challenges.cloudflare.com (16 requests, +797 ms) checks every visitor before the page loads, before any consent; the IP address, browser, and fingerprint reach Cloudflare in the USA instantly. Level 2 — the page: static.cloudflareinsights.com, behavioral analytics. Level 3 — content: cdnjs.cloudflare.com, JS libraries. This is not three separate decisions by three developers, but a single unified state IT policy: one decision, the entire country behind an American intermediary.
Why the CSP doesn’t hold
Two products from the same vendor work in tandem. challenges.cloudflare.com (Bot Management / Turnstile, a replacement for Google reCAPTCHA) checks the visitor and, on success, issues a pass. That pass opens the door for static.cloudflareinsights.com — Cloudflare’s second product. The CSP, which blocked Insights on the first visit (status 0, twice), stops working once Turnstile has issued its permission: on a repeat visit, Insights fires immediately (status 200). This is Cloudflare’s whitelisting mechanism — once Bot Management is passed, Cloudflare’s own scripts get automatic clearance. One vendor, two products: the first opens the door for the second, and the CSP becomes decorative.
What is done correctly — and there’s quite a bit
Analytics run through Matomo on the state server piwik.smit.ee (SMIT); data stays within Estonia. The chatbot buerokratt.politsei.ee runs on state servers, so conversations don’t go to American clouds. There is no Google Fonts, no Google Tag Manager, no DoubleClick, no browser-update.org, no advertising networks, zero unknown external domains. Among all the government sites in this series with violations, politsei.ee is one of the best in terms of its own architecture.
Declaration versus fact — four discrepancies
The policy states: “We do not disclose or transfer personal data to third parties” — yet Cloudflare receives every visitor’s data at three levels. This is the fourth time this exact wording has appeared in this series (president.ee, oiguskantsler.ee, sotsiaalkindlustusamet.ee) — a state-wide template that systemically ignores transfer via external services. The policy declares Google Maps, Facebook, LinkedIn, and Twitter — all with zero requests in the HAR; not a word about Cloudflare (19 actual transfers). It states “IP is not linked to identity” — but what the Police don’t link, Cloudflare might. And it implies control via a CSP that, in fact, doesn’t hold.
Conclusion
The Police consider their site clean — and by its own architecture, they’re almost right: state-run Matomo, a state-run chat, no Google, no advertising networks. The core problem lies elsewhere. The core problem is RIA’s decision to put the entire country behind Cloudflare’s American gateway, at three layers, before any consent. Knowing this is one thing; proving it publicly and factually is another. The HAR does exactly that.
236c24719e88fc24eab3a15f3f86c1faa1e5c8dadbe8a422cd8f4acbf7f04183Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee
Important: AKI only handles submissions in Estonian. Translate the letter before sending.
To: Estonian Data Protection Inspectorate (AKI) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website politsei.ee. 2. Circumstances I visited the website politsei.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 6 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) Cloudflare receives every visitor's data at three levels (entry, page, content) with no consent and no legal basis. 2) There is no consent mechanism. Cloudflare's entry-point check happens before any consent or interaction. 3) Cloudflare (19 actual transfers) is not declared as a recipient. Meanwhile, the policy declares Google Maps, Facebook, LinkedIn, and Twitter — all with zero requests in the HAR. 4) No data-transfer mechanism to the USA (Cloudflare) is stated. The transfer occurs with no SCC. 5) The policy implies control, but the CSP is unstable: on a repeat visit, Cloudflare Insights fires consistently (status 200) after Bot Management has been passed. Full technical documentation is published at: https://gdpru.eu/en/audits/ee-politsei-ee/ 3. Provisions violated GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 7; GDPR Art. 13(1)(e); GDPR Art. 13(1)(f), Chapter V; GDPR Art. 5(1)(a) — CSP stability 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]