Technical audit · 2026-06-06

smartposti.ee

A Network of Parcel Lockers in Estonia

Finnish Posti Group in Estonia. GTM loads at +574 ms — 267 ms before OneTrust. New Relic uses the EU instance (bam.eu01.nr-data.net) — a deliberate choice. But the load order of GTM violates the principle of consent before processing.

Timeline of the leak

+128 ms · before the banner
Posti CDN (cdn.posti.fi) — fonts and styles from the Finnish parent company. Finland/EU.
+132 ms · before the banner
Contentful CDN (images.ctfassets.net) — CMS images. USA.
+574 ms · before the banner
GTM (GTM-NHWQ4B77) — loads 267 ms before OneTrust.
+663 ms · before the banner
www.posti.fi/federated-module — a JavaScript module from the Finnish parent. Finland.
+841 ms · banner begins
OneTrust (cdn-ukwest.onetrust.com) — loading begins. UK West CDN.
+880 ms
unpkg.com (web-vitals@5.0.1) — performance measurement. USA.
+1145 ms · banner ready
OneTrust fully loaded — the banner is visible to the user.
+1472 ms
New Relic (js-agent.newrelic.com) — performance monitoring.
+1651 ms
A New Relic collect (bam.eu01.nr-data.net) — the EU instance. Data to the EU.

Declared versus actual

Google Analytics — mentioned in the policy — заявлен
Facebook — mentioned in the policy — заявлен
+ New Relic (js-agent.newrelic.com) — не заявлен
+ Contentful CDN (images.ctfassets.net) — не заявлен
+ unpkg.com (web-vitals) — не заявлен
+ Posti CDN (cdn.posti.fi, www.posti.fi) — не заявлен

Transfer timings

+128 ms cdn.posti.fi

Posti Group fonts and styles

+574 ms www.googletagmanager.com

GTM-NHWQ4B77 — 267 ms before OneTrust

+841 ms cdn-ukwest.onetrust.com

OneTrust begins loading

+1145 ms cdn-ukwest.onetrust.com

OneTrust fully ready

+1472 ms js-agent.newrelic.com

The New Relic SPA agent

+1651 ms bam.eu01.nr-data.net

New Relic's EU instance. Data to the EU

Detected trackers

Indicators of GDPR non-compliance

Context

SmartPost Estonia OÜ is a network of parcel lockers in Estonia, a subsidiary of the Finnish Posti Group Oyj. A competitor to Omniva in Estonia’s parcel-locker market. HAR: 55 requests, 9 domains. Session on a page for business clients.

GTM before the banner — 267 milliseconds

GTM loads at +574 ms. OneTrust begins loading at +841 ms. The gap: 267 ms. OneTrust is fully ready by roughly +1145 ms. Between GTM loading and the banner appearing, there is nearly a 600-millisecond window. This is the same problem seen at Zalando, Omniva, and SmartPost — the script load order violates the principle of consent before processing.

New Relic EU — a deliberate choice

New Relic collects SPA performance data: transactions, JavaScript errors, events. SmartPost uses the EU instance: bam.eu01.nr-data.net — data is processed within the EU. This is the third site in the series, after IIZI and Zalando’s Sentry EU, where performance monitoring is deliberately kept on European infrastructure.

Posti CDN — dependency on the parent company

cdn.posti.fi loads fonts and CSS from the Finnish Posti Group (+128 ms). www.posti.fi/federated-module (+663 ms) loads a JavaScript module via Webpack Module Federation — a smart component pulled directly from the Finnish site. This is an architectural choice: the Estonian site imports live components from its Finnish parent. Every visitor’s IP address is transmitted to Finland on every site open.

Contentful and unpkg

images.ctfassets.net — the CDN for Contentful, an American CMS platform. Images are hosted on US servers. unpkg.com loads web-vitals@5.0.1 — Google’s performance-measurement library. Neither is mentioned in the privacy policy.

Comparison with Omniva

Both are postal operators in the Estonian market, both use a CMP (Omniva — Cookiebot, SmartPost — OneTrust). Both load GTM before the banner. SmartPost chose New Relic’s EU instance — an advantage over Omniva. Omniva uses Cloudflare Turnstile; SmartPost does not.

Conclusion

SmartPost demonstrates deliberate choices regarding EU infrastructure: New Relic EU, Posti CDN in Finland. But GTM loads 267 ms before OneTrust — the standard load-order problem. Contentful CDN and unpkg.com are undeclared. The privacy policy describes Google Analytics and Facebook in general terms, without naming the other actual recipients.

Evidence
Original (audit)
HAR file: ee/smartposti-ee-2026-06-06.har
SHA-256: 82ad889d7edfee4be865fcbcf5cb8651e5e11f0344981079a91d5cc45f48c85d
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee

Important: AKI only handles submissions in Estonian. Translate the letter before sending.

To: Estonian Data Protection Inspectorate (AKI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website smartposti.ee.

2. Circumstances
I visited the website smartposti.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 6 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) GTM (+574 ms) loads 267 ms before OneTrust begins loading (+841 ms). Posti CDN (+128 ms) and Contentful CDN (+132 ms) fire immediately. New Relic (+1472 ms) activates after OneTrust, but before any user interaction with the banner.

2) GTM loads 267 ms before OneTrust. OneTrust fully loads by roughly +1145 ms. Between GTM loading and the banner appearing, there is a roughly 600 ms window during which analytics could have initialized.

3) The privacy policy mentions Google Analytics in general terms. New Relic, Contentful CDN, unpkg.com, and Posti CDN (www.posti.fi) are not mentioned as data recipients.

4) GTM, unpkg.com, and Contentful — servers in the USA. No transfer mechanism is stated for any recipient.

Full technical documentation is published at: https://gdpru.eu/en/audits/ee-smartposti-ee/

3. Provisions violated
GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 7; GDPR Art. 13(1)(e); GDPR Art. 13(1)(f), Chapter V

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]