A state institution managing Estonia's mandatory health insurance. Medical service payments, benefits, dentistry, pregnancy and child health, an electronic health portal. The site itself classifies its data as a special category under GDPR Art. 9.
Timeline of the leak
Declared versus actual
Transfer timings
Cloudflare USA — before the banner appears
The user's IP address transmitted to Google, USA
Before consent
Google, USA, before consent
Detected trackers
- Google reCAPTCHA (in 'necessary')
- Google Fonts
- Cloudflare (hosting + NEL + Insights)
- Google Analytics (G-0FEP5VSTYR, consentMode:false)
Indicators of GDPR non-compliance
- GDPR Art. 7(4)Google reCAPTCHA is included in the 'necessary' category, marked 'always active' — declining it is technically blocked. Consent is not freely given.
- GDPR Art. 6(1), Art. 5(1)(a)cdn.jsdelivr.net (+214 ms), fonts.googleapis.com (+229 ms), and fonts.gstatic.com (+282 ms) fire before any interaction with the banner. An actual transfer, status 200.
- GDPR Art. 13(1)(e)Actual data recipients are not declared: Google Fonts, cdn.jsdelivr.net, Cloudflare (hosting + NEL + Insights), AWS, Tableau, TEHIK as a separate recipient, unpkg.com, cdnjs.cloudflare.com, npmcdn.com.
- GDPR Art. 13(1)(f)No transfer mechanism to the USA (SCC, adequacy decision, or otherwise) is stated for Google, Cloudflare, or AWS.
- GDPR Chapter VData transfer to the USA via Cloudflare hosting, Google Fonts, and NEL, with no legal mechanism stated.
- GDPR Art. 9On the site of an organization whose core activity is processing health data, undeclared processors run before consent. This occurs within a session that may involve eID authentication for access to the Terviseportaal — with no separate legal basis.
Getting to the substance
Tervisekassa handles data that its own policy classifies as a special category: health data, financial data, special categories of personal data under GDPR Art. 9. I opened the site, recorded the traffic, and analyzed the HAR file. 300 requests per session, 6 unique domains. And on this health-related site, undeclared American processors run before the user can click anything at all.
The banner: almost correct, but with a hole
The consent banner here is better than the ones at mil.ee, transpordiamet.ee, or valitsus.ee. Three buttons: settings, “reject all,” and “accept all.” A reject option exists. The category structure is correct — non-essential categories are off by default, as GDPR Art. 7 requires.
But there’s a detail. The “necessary cookies” category includes _grecaptcha — Google reCAPTCHA with a 180-day lifespan. The category is marked “always active” and cannot be turned off. This is the same dark pattern recorded at mil.ee. Google reCAPTCHA is not an Estonian service — it’s an American corporation, and technical alternatives exist. Placing Google in “necessary” with rejection blocked is a violation of Art. 7(4): consent is not freely given if it cannot be withdrawn without consequence.
What happens before consent
The page start is logged. From there — by the timings.
At +214 ms, cdn.jsdelivr.net loads — the script of the consent-banner plugin itself, hosted on a Cloudflare server in the USA. The load happens before the banner has even appeared on screen. Status 200, an actual transfer. cdn.jsdelivr.net is not declared in the policy.
At +229 ms — fonts.googleapis.com. Google Fonts requests the Open Sans and Noto Sans typefaces. Each such request transmits the user’s IP address to Google LLC, USA. Status 200. Google Fonts is not mentioned in the policy.
At +282 ms — fonts.gstatic.com, Google’s CDN for font files, a server in the USA. Status 200.
All of this happened before the user clicked any button. With no consent. On a site that calls itself a health-data processor.
Hosting architecture
The tervisekassa.ee server — IP 172.67.183.114 — is Cloudflare, USA. Every HTTP request to the Estonian Health Insurance Fund’s website passes through the American company’s infrastructure. Cloudflare sees the user’s IP address, User-Agent, visited URLs, and visit time. In the response headers, the server returns server: cloudflare, a cf-ray request identifier, and report-to pointing to a.nel.cloudflare.com — network error reports go to the USA. Cloudflare, as a data processor, is not mentioned in the policy, and no legal transfer mechanism to the USA is stated.
What the site permits itself
In the Content-Security-Policy header, the site lists which external resources it permits itself to load. Among them: Meta (*.facebook.net, *.facebook.com), Google Analytics, Google Tag Manager, Cloudflare Insights, Siteimprove (Denmark), AWS eu-north-1, Tableau (Salesforce), US CDNs (unpkg.com, cdnjs.cloudflare.com, npmcdn.com), as well as Estonia’s own TEHIK and the crossword site ristsonad.ee. The CSP is applied in enforce mode — block-all-mixed-content is present, and there is no Report-Only suffix. In other words, this is not a theoretical possibility, but active permission to load everything listed at any moment.
The homepage’s HTML, via the cookiesjsr configuration, discloses a Google Analytics identifier, G-0FEP5VSTYR, with the parameter consentMode:false — GA activates only after consent. In the captured session, no consent was given, so no transfers to Google Analytics appear in the HAR. This is correct behavior — but only on the condition that the declared list of recipients matches reality. Here, it doesn’t.
Discrepancy between policy and reality
The policy (last updated 06.03.2026) declares SSESS, cookiesjsr, hc, _grecaptcha under necessary cookies; Siteimprove/nmstat under analytics, with a Danish address stated; Google Tag Manager and Facebook Pixel under marketing; YouTube under video; and Power BI is mentioned in passing, with no note that data may go to Microsoft.
Not declared are actually running or permitted recipients: Google Fonts, cdn.jsdelivr.net, Cloudflare as hosting and NEL, AWS eu-north-1, Tableau, TEHIK as a separate recipient, Insights in the CSP, unpkg.com, cdnjs.cloudflare.com, npmcdn.com. This is a violation of Art. 13(1)(e): the data subject must know all recipients of their data.
reCAPTCHA leads to Google
At the bottom of the policy page and beneath the contact form is a note that the site is protected by reCAPTCHA, and that Google’s privacy policy and terms of service apply. The words “privacy policy” and “terms” are clickable links leading directly to google.com. This is the same pattern recorded at inforegister.ee: a user trying to learn how their own data is processed is redirected to Google. The browser sends a Referer header carrying the address of Tervisekassa’s policy page — Google learns who came, from where, when, and what they were reading.
Context that changes everything
Tervisekassa is not an online store. It is an organization that processes data on every insured person’s medical cases, prescribed medications, dental treatment, pregnancy and child health, medical services received abroad, sick leave, and insurance payments. In its own policy, it explicitly classifies this as a special category of personal data under GDPR Art. 9 — the highest level of protection provided by law.
The homepage has a section titled “My Data: Health Portal” — a direct link to a citizen’s personal medical data. In a session where a citizen authenticates via ID card or Mobile-ID, undeclared American processors are running: Cloudflare as hosting, Google Fonts, AWS in the CSP. This requires separate legal justification under Art. 9 — which does not exist.
Conclusion
On the banner, Tervisekassa is making an effort: there’s a reject option, categories are off by default, Google Analytics doesn’t fire without consent. But all of this is undone by what happens before any click. Google fonts, the consent-banner plugin from a US CDN, and the Cloudflare hosting itself all transmit visitor data to the USA before consent — on a site that, by its own definition, processes a special category of health data.
6055b61b5cc490199127482bcec4e29eb26d5a1c08cc725f9ef75e5e674a323aWhere to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee
Important: AKI only handles submissions in Estonian. Translate the letter before sending.
To: Estonian Data Protection Inspectorate (AKI) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website tervisekassa.ee. 2. Circumstances I visited the website tervisekassa.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 14 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) Google reCAPTCHA is included in the 'necessary' category, marked 'always active' — declining it is technically blocked. Consent is not freely given. 2) cdn.jsdelivr.net (+214 ms), fonts.googleapis.com (+229 ms), and fonts.gstatic.com (+282 ms) fire before any interaction with the banner. An actual transfer, status 200. 3) Actual data recipients are not declared: Google Fonts, cdn.jsdelivr.net, Cloudflare (hosting + NEL + Insights), AWS, Tableau, TEHIK as a separate recipient, unpkg.com, cdnjs.cloudflare.com, npmcdn.com. 4) No transfer mechanism to the USA (SCC, adequacy decision, or otherwise) is stated for Google, Cloudflare, or AWS. 5) Data transfer to the USA via Cloudflare hosting, Google Fonts, and NEL, with no legal mechanism stated. 6) On the site of an organization whose core activity is processing health data, undeclared processors run before consent. This occurs within a session that may involve eID authentication for access to the Terviseportaal — with no separate legal basis. Full technical documentation is published at: https://gdpru.eu/en/audits/ee-tervisekassa-ee/ 3. Provisions violated GDPR Art. 7(4); GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 13(1)(e); GDPR Art. 13(1)(f); GDPR Chapter V; GDPR Art. 9 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]