rahvastikuregister.ee
Almost the cleanest audit in this series: 217 requests, all on Estonian state servers, zero Google. One problem — at the most sensitive moment. When a citizen clicks 'Log in with ID card,' Cloudflare (USA) receives data from the authentication session. And this is TARA — the single sign-on gateway to ALL of Estonia's government services.
Timeline of the leak
Declared versus actual
Transfer timings
The start of ID-card authentication
Matomo on SMIT's state server (Estonia) — a plus
No exact timing
Detected trackers
- Cloudflare Insights (on tara.ria.ee)
Indicators of GDPR non-compliance
- GDPR Art. 6(1), Art. 5(1)(a)Cloudflare Insights loads on tara.ria.ee at the moment of authentication, with no consent. A POST to /cdn-cgi/rum — 939 bytes of session data to the USA.
- GDPR Art. 13(1)(e)Cloudflare, as a recipient of authentication-session data, is not declared.
- GDPR Art. 13(1)(f), Chapter VNo mechanism for transferring data to the USA (Cloudflare) is stated — neither SCC nor an adequacy decision.
Context
rahvastikuregister.ee is Estonia’s Population Register: the addresses of every resident, marital status, citizenship, family ties. Authentication runs via ID card through the TARA system. HAR: 217 requests, 5 domains, one external.
What is done correctly — almost everything
All resources on the proprietary domain. Analytics run through Matomo on piwik.smit.ee, a server operated by the Estonian Ministry of the Interior’s IT center (a state server). Authentication runs through TARA and GovSSO, RIA’s state infrastructure. No Google, no DoubleClick, no browser-update.org. This is one of the cleanest results in this series — alongside eesti.ee, rajaleidja.ee, edpb.europa.eu, and europark.ee.
One problem — but at the most sensitive point
static.cloudflareinsights.com loads on tara.ria.ee. That is, at the moment a citizen clicks “Log in with ID card,” Cloudflare (USA) receives data from the authentication session: a POST to tara.ria.ee/cdn-cgi/rum — 939 bytes, with every request carrying where they came from (rahvastikuregister.ee), what they started doing (auth/init), a unique pageloadId, and the device’s technical characteristics.
Why this matters more than a single script
TARA is the single sign-on gateway to ALL of Estonia’s government services: the Population Register, the Tax and Customs Board, digital medical records, all state e-services. Every single time any Estonian citizen logs into any government service via ID card, Cloudflare receives an RUM beacon. The most sensitive moment — the moment of ID-card authentication — is precisely where the American tracker operates. This isn’t a problem specific to rahvastikuregister.ee, but a problem with the shared login infrastructure.
Conclusion
The site itself proves that a government service can be built 99% free of foreign trackers — and Estonia knows how to do it. That leaves 1%, and it’s easily fixed: remove Cloudflare Insights from tara.ria.ee — one script, one change, and the entire authentication chain for Estonian citizens would stay within the country. The fix is simple. The only question is whether it will be made.
011c08ee2c6dcb171b9db8bd16a7cc7a3c8daa48eaeb25ac3677ddcac7aabb52Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee
Important: AKI only handles submissions in Estonian. Translate the letter before sending.
To: Estonian Data Protection Inspectorate (AKI) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website rahvastikuregister.ee. 2. Circumstances I visited the website rahvastikuregister.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 2 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) Cloudflare Insights loads on tara.ria.ee at the moment of authentication, with no consent. A POST to /cdn-cgi/rum — 939 bytes of session data to the USA. 2) Cloudflare, as a recipient of authentication-session data, is not declared. 3) No mechanism for transferring data to the USA (Cloudflare) is stated — neither SCC nor an adequacy decision. Full technical documentation is published at: https://gdpru.eu/en/audits/ee-rahvastikuregister-ee/ 3. Provisions violated GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 13(1)(e); GDPR Art. 13(1)(f), Chapter V 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]