853 requests, 13 domains. Google reCAPTCHA fires at the zero-millisecond mark, the Askly chat at +334 ms. A consent banner is wired in, but broken — status 0 on every attempted load. The privacy policy names not a single external data recipient.
Timeline of the leak
Declared versus actual
Transfer timings
reCAPTCHA webworker. Data to Google, USA
Roboto. IP address to Google, USA
Support chat, config + WebSocket
4 font families. IP address to Google
Consent banner — status 0, fails to load
Klaviyo — status 0
GTM-TSXS8GB — status 0
The LHV installment widget
Monotype CDN. USA
Detected trackers
- Google reCAPTCHA (www.google.com)
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com)
- Askly (chat.askly.me) — support chat
- Klaviyo (static.klaviyo.com) — email marketing
- Google Tag Manager (GTM-TSXS8GB)
- Monotype/fast.fonts.net — a font CDN
Indicators of GDPR non-compliance
- GDPR Art. 6(1), Art. 5(1)(a)Google reCAPTCHA (+0 ms), Google Fonts (+29 ms), and the Askly chat (+334 ms) fire within the first seconds of the session — before the cookie-script consent banner appears (+9957 ms). Data goes to the USA before any interaction with the banner.
- GDPR Art. 7The cookie-script consent banner is wired into the code and initiates requests, but all of them return status 0 — it fails to load. GTM and Klaviyo also return status 0. Meanwhile, reCAPTCHA, Google Fonts, and Askly operate normally (status 200) with no consent whatsoever.
- GDPR Art. 13(1)(e)The privacy policy does not mention Google reCAPTCHA, Google Fonts, Askly, Klaviyo, GTM, or fast.fonts.net as data recipients. Only data categories are listed, with no specific third parties named.
- GDPR Art. 13(1)(f), Chapter VGoogle (USA), Askly (Estonia/USA), Klaviyo (USA), Monotype/fast.fonts.net (USA) — no data-transfer mechanism is stated for any recipient.
Context
Puumarket AS is an Estonian home improvement and hardware retail chain, registration number 10363212. The site operates as an online store, with a cart, online orders, and a loyalty program. HAR: 853 requests, 13 domains. The session included browsing products.
A broken consent banner
The central finding of this audit isn’t the trackers — it’s the consent mechanism. Cookie-script is wired into the code and initiates requests to cdn.cookie-script.com at +9957 ms — but every request returns status 0. The banner fails to load at all. Along with it, GTM (GTM-TSXS8GB, status 0) and Klaviyo (status 0) also fail to load. This means Cookie-script, GTM, and Klaviyo are blocked — likely by a CSP or a network error — and in this session, no data went out through them.
But this isn’t user protection — it’s an accidental block. By the time the banner should have appeared, three external services were already running with no consent whatsoever.
What runs before the banner
+0 ms — Google reCAPTCHA (www.google.com/recaptcha/api2/webworker.js) — the first request of the session. Data to Google (USA) before any interaction.
+28 ms — www.gstatic.com — reCAPTCHA resources. Google.
+29 ms — fonts.gstatic.com — the Roboto typeface, status 200. IP address to Google, USA.
+334 ms — chat.askly.me — an Estonian support-chat service. A config request, status 200, followed by a WebSocket connection (wss://sessions.chat.askly.me) at +1156 ms. An active connection before consent.
+1008 ms — fonts.googleapis.com — four font families: Flow Circular, Lato, Montserrat, Roboto. IP address to Google, USA.
All five domains — status 200, data transmitted — within the first 10 seconds, before the banner is supposed to appear.
The privacy policy — no recipients named
The policy describes in detail what data Puumarket collects (name, address, phone, email, purchase data, IP address). It declares that data is transferred only where a lawful right exists. It names not a single specific recipient: not Google, not Askly, not Klaviyo, not Monotype. Under Art. 13(1)(e), the user is entitled to know all recipients — the policy does not meet this requirement.
The LHV installment widget
On the product page, a partners.lhv.ee widget loads with parameters for the specific product — price 1602.90, company code EE-10363212. LHV is an Estonian bank, and the data stays within the EEA. This is not a violation, but the fact that information about the product being viewed is transmitted to a bank’s infrastructure, unmentioned in the policy, is worth noting.
Conclusion
Puumarket has a consent banner — but it’s broken and fails to load. By the time it would have appeared, reCAPTCHA, Google Fonts, and Askly had already transmitted data. GTM and Klaviyo were accidentally blocked along with the banner. The privacy policy appears written in good faith, but it doesn’t meet the Art. 13(1)(e) requirement — specific data recipients are named nowhere.
5ffbc0ca497fb9c29d766586a763b6b00d4b4b6fc94e1f3d89a21b8693349039Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee
Important: AKI only handles submissions in Estonian. Translate the letter before sending.
To: Estonian Data Protection Inspectorate (AKI) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website puumarket.ee. 2. Circumstances I visited the website puumarket.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 28 March 2026 (open methodology, reproducible measurements) documents the following indications: 1) Google reCAPTCHA (+0 ms), Google Fonts (+29 ms), and the Askly chat (+334 ms) fire within the first seconds of the session — before the cookie-script consent banner appears (+9957 ms). Data goes to the USA before any interaction with the banner. 2) The cookie-script consent banner is wired into the code and initiates requests, but all of them return status 0 — it fails to load. GTM and Klaviyo also return status 0. Meanwhile, reCAPTCHA, Google Fonts, and Askly operate normally (status 200) with no consent whatsoever. 3) The privacy policy does not mention Google reCAPTCHA, Google Fonts, Askly, Klaviyo, GTM, or fast.fonts.net as data recipients. Only data categories are listed, with no specific third parties named. 4) Google (USA), Askly (Estonia/USA), Klaviyo (USA), Monotype/fast.fonts.net (USA) — no data-transfer mechanism is stated for any recipient. Full technical documentation is published at: https://gdpru.eu/en/audits/ee-puumarket-ee/ 3. Provisions violated GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 7; GDPR Art. 13(1)(e); GDPR Art. 13(1)(f), Chapter V 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]