Technical audit · 2026-05-06

politsei.ee

Passports, Visas, Residence Permits, Investigations

One of the best government sites in this series in terms of its own architecture: state-run Matomo, a state-run chatbot, zero Google, zero advertising networks. And yet — three layers of Cloudflare at entry, on the page, and in the content. The core problem isn't the site itself, but RIA's decision to put the entire country behind an American gateway.

Timeline of the leak

+797 ms · layer 1, entry
challenges.cloudflare.com — Cloudflare Bot Management (Turnstile, a replacement for Google reCAPTCHA), 16 requests, status 200. A 'Verifying you are human' challenge page appears before the site loads. IP address, browser, and fingerprint go to Cloudflare in the USA instantly, before any consent.
Consent banner
Absent. The entry-point check happens before any interaction. This is not politsei.ee's own decision — every Estonian government site sits behind this same gateway.
Layers 2 and 3
static.cloudflareinsights.com (behavioral analytics) and cdnjs.cloudflare.com (JS libraries). On first visit, the CSP blocks Insights (status 0), but on a repeat visit, it fires consistently (status 200).

Declared versus actual

Google Maps, Facebook, LinkedIn, Twitter — all with zero requests in the HAR — заявлен
'We do not transfer data to third parties' — заявлен
'IP is not linked to identity' — заявлен
+ Cloudflare at three levels — 19 transfers, not a word in the policy — не заявлен

Transfer timings

+797 ms challenges.cloudflare.com

Bot Management / Turnstile, 16 requests. Fingerprint to the USA before consent

+642386 ms static.cloudflareinsights.com

The first attempts are blocked (status 0), then it fires (200)

No exact timing

on a repeat visit static.cloudflareinsights.comStatus 200 immediately — no coincidence, consistent
per session piwik.smit.ee (Matomo)Matomo on SMIT's state server (Estonia) — a plus

Detected trackers

Indicators of GDPR non-compliance

Context

politsei.ee is the website of Estonia’s Police and Border Guard Board (PPA). It issues passports, visas, and residence permits, investigates crimes, and registers foreign nationals — one of the largest departments with direct citizen contact. HAR: 217 requests, 6 domains.

A systemic finding — three layers of Cloudflare

For the first time in this series, a government site shows an explicit challenge page: “Verifying you are human. This website uses a security service to protect against malicious bots.” This is Cloudflare Bot Management, and every Estonian government site sits behind it. Cloudflare operates at three levels. Level 1 — entry: challenges.cloudflare.com (16 requests, +797 ms) checks every visitor before the page loads, before any consent; the IP address, browser, and fingerprint reach Cloudflare in the USA instantly. Level 2 — the page: static.cloudflareinsights.com, behavioral analytics. Level 3 — content: cdnjs.cloudflare.com, JS libraries. This is not three separate decisions by three developers, but a single unified state IT policy: one decision, the entire country behind an American intermediary.

Why the CSP doesn’t hold

Two products from the same vendor work in tandem. challenges.cloudflare.com (Bot Management / Turnstile, a replacement for Google reCAPTCHA) checks the visitor and, on success, issues a pass. That pass opens the door for static.cloudflareinsights.com — Cloudflare’s second product. The CSP, which blocked Insights on the first visit (status 0, twice), stops working once Turnstile has issued its permission: on a repeat visit, Insights fires immediately (status 200). This is Cloudflare’s whitelisting mechanism — once Bot Management is passed, Cloudflare’s own scripts get automatic clearance. One vendor, two products: the first opens the door for the second, and the CSP becomes decorative.

What is done correctly — and there’s quite a bit

Analytics run through Matomo on the state server piwik.smit.ee (SMIT); data stays within Estonia. The chatbot buerokratt.politsei.ee runs on state servers, so conversations don’t go to American clouds. There is no Google Fonts, no Google Tag Manager, no DoubleClick, no browser-update.org, no advertising networks, zero unknown external domains. Among all the government sites in this series with violations, politsei.ee is one of the best in terms of its own architecture.

Declaration versus fact — four discrepancies

The policy states: “We do not disclose or transfer personal data to third parties” — yet Cloudflare receives every visitor’s data at three levels. This is the fourth time this exact wording has appeared in this series (president.ee, oiguskantsler.ee, sotsiaalkindlustusamet.ee) — a state-wide template that systemically ignores transfer via external services. The policy declares Google Maps, Facebook, LinkedIn, and Twitter — all with zero requests in the HAR; not a word about Cloudflare (19 actual transfers). It states “IP is not linked to identity” — but what the Police don’t link, Cloudflare might. And it implies control via a CSP that, in fact, doesn’t hold.

Conclusion

The Police consider their site clean — and by its own architecture, they’re almost right: state-run Matomo, a state-run chat, no Google, no advertising networks. The core problem lies elsewhere. The core problem is RIA’s decision to put the entire country behind Cloudflare’s American gateway, at three layers, before any consent. Knowing this is one thing; proving it publicly and factually is another. The HAR does exactly that.

Evidence
Original (audit)
HAR file: ee/politsei-ee-2026-05-06.har
SHA-256: 236c24719e88fc24eab3a15f3f86c1faa1e5c8dadbe8a422cd8f4acbf7f04183
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee

Important: AKI only handles submissions in Estonian. Translate the letter before sending.

To: Estonian Data Protection Inspectorate (AKI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website politsei.ee.

2. Circumstances
I visited the website politsei.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 6 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) Cloudflare receives every visitor's data at three levels (entry, page, content) with no consent and no legal basis.

2) There is no consent mechanism. Cloudflare's entry-point check happens before any consent or interaction.

3) Cloudflare (19 actual transfers) is not declared as a recipient. Meanwhile, the policy declares Google Maps, Facebook, LinkedIn, and Twitter — all with zero requests in the HAR.

4) No data-transfer mechanism to the USA (Cloudflare) is stated. The transfer occurs with no SCC.

5) The policy implies control, but the CSP is unstable: on a repeat visit, Cloudflare Insights fires consistently (status 200) after Bot Management has been passed.

Full technical documentation is published at: https://gdpru.eu/en/audits/ee-politsei-ee/

3. Provisions violated
GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 7; GDPR Art. 13(1)(e); GDPR Art. 13(1)(f), Chapter V; GDPR Art. 5(1)(a) — CSP stability

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]