Technical audit · 2026-05-14

tervisekassa.ee

Estonian Health Insurance Fund

A state institution managing Estonia's mandatory health insurance. Medical service payments, benefits, dentistry, pregnancy and child health, an electronic health portal. The site itself classifies its data as a special category under GDPR Art. 9.

Timeline of the leak

+214 ms · cdn.jsdelivr.net
The consent-banner plugin script (cookiesjsr-preloader) loads from a CDN on Cloudflare's US infrastructure before the banner has even appeared on screen. Status 200, an actual transfer. Not declared in the policy.
+229 ms · fonts.googleapis.com
Google Fonts (Open Sans, Noto Sans). Every request transmits the user's IP address to Google LLC, USA. Status 200. Not mentioned in the policy.
+282 ms · fonts.gstatic.com
Google's CDN for font files, server IP in the USA. Status 200. Before any consent. Not mentioned in the policy.
a banner with three buttons
A 'Reject All' button exists, and non-essential categories are off by default — correct. But the 'necessary' category includes Google reCAPTCHA, marked 'always active' with a 180-day expiration. It cannot be turned off.
US-based Cloudflare hosting
The site's server (172.67.183.114) — Cloudflare, USA. Every HTTP request passes through the American company's infrastructure: IP address, User-Agent, URL, visit time. Error reports go to a.nel.cloudflare.com.

Declared versus actual

Siteimprove / nmstat (Denmark) — заявлен
Google Tag Manager → Facebook Pixel / _fbp — заявлен
YouTube / VISITOR_INFO1_LIVE, YSC — заявлен
_grecaptcha, cookiesjsr, hc, SSESS — заявлен
Power BI (mentioned in passing, with no statement that data goes to Microsoft) — заявлен
+ Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — loaded before consent — не заявлен
+ cdn.jsdelivr.net — the banner plugin, via Cloudflare USA — не заявлен
+ Cloudflare as hosting (172.67.183.114) + NEL (a.nel.cloudflare.com) + Insights in the CSP — не заявлен
+ AWS eu-north-1 (US jurisdiction via AWS Inc.) — не заявлен
+ Tableau (Salesforce, USA) — не заявлен
+ TEHIK (*.tehik.ee) — not named as a separate recipient — не заявлен
+ unpkg.com, cdnjs.cloudflare.com, npmcdn.com — не заявлен

Transfer timings

+214 ms cdn.jsdelivr.net (cookiesjsr-preloader)

Cloudflare USA — before the banner appears

+229 ms fonts.googleapis.com (Open Sans / Noto Sans)

The user's IP address transmitted to Google, USA

+275 ms cdn.jsdelivr.net (cookiesjsr.min.js)

Before consent

+282 ms fonts.gstatic.com (Noto Sans woff2)

Google, USA, before consent

Detected trackers

Indicators of GDPR non-compliance

Getting to the substance

Tervisekassa handles data that its own policy classifies as a special category: health data, financial data, special categories of personal data under GDPR Art. 9. I opened the site, recorded the traffic, and analyzed the HAR file. 300 requests per session, 6 unique domains. And on this health-related site, undeclared American processors run before the user can click anything at all.

The banner: almost correct, but with a hole

The consent banner here is better than the ones at mil.ee, transpordiamet.ee, or valitsus.ee. Three buttons: settings, “reject all,” and “accept all.” A reject option exists. The category structure is correct — non-essential categories are off by default, as GDPR Art. 7 requires.

But there’s a detail. The “necessary cookies” category includes _grecaptcha — Google reCAPTCHA with a 180-day lifespan. The category is marked “always active” and cannot be turned off. This is the same dark pattern recorded at mil.ee. Google reCAPTCHA is not an Estonian service — it’s an American corporation, and technical alternatives exist. Placing Google in “necessary” with rejection blocked is a violation of Art. 7(4): consent is not freely given if it cannot be withdrawn without consequence.

The page start is logged. From there — by the timings.

At +214 ms, cdn.jsdelivr.net loads — the script of the consent-banner plugin itself, hosted on a Cloudflare server in the USA. The load happens before the banner has even appeared on screen. Status 200, an actual transfer. cdn.jsdelivr.net is not declared in the policy.

At +229 ms — fonts.googleapis.com. Google Fonts requests the Open Sans and Noto Sans typefaces. Each such request transmits the user’s IP address to Google LLC, USA. Status 200. Google Fonts is not mentioned in the policy.

At +282 ms — fonts.gstatic.com, Google’s CDN for font files, a server in the USA. Status 200.

All of this happened before the user clicked any button. With no consent. On a site that calls itself a health-data processor.

Hosting architecture

The tervisekassa.ee server — IP 172.67.183.114 — is Cloudflare, USA. Every HTTP request to the Estonian Health Insurance Fund’s website passes through the American company’s infrastructure. Cloudflare sees the user’s IP address, User-Agent, visited URLs, and visit time. In the response headers, the server returns server: cloudflare, a cf-ray request identifier, and report-to pointing to a.nel.cloudflare.com — network error reports go to the USA. Cloudflare, as a data processor, is not mentioned in the policy, and no legal transfer mechanism to the USA is stated.

What the site permits itself

In the Content-Security-Policy header, the site lists which external resources it permits itself to load. Among them: Meta (*.facebook.net, *.facebook.com), Google Analytics, Google Tag Manager, Cloudflare Insights, Siteimprove (Denmark), AWS eu-north-1, Tableau (Salesforce), US CDNs (unpkg.com, cdnjs.cloudflare.com, npmcdn.com), as well as Estonia’s own TEHIK and the crossword site ristsonad.ee. The CSP is applied in enforce mode — block-all-mixed-content is present, and there is no Report-Only suffix. In other words, this is not a theoretical possibility, but active permission to load everything listed at any moment.

The homepage’s HTML, via the cookiesjsr configuration, discloses a Google Analytics identifier, G-0FEP5VSTYR, with the parameter consentMode:false — GA activates only after consent. In the captured session, no consent was given, so no transfers to Google Analytics appear in the HAR. This is correct behavior — but only on the condition that the declared list of recipients matches reality. Here, it doesn’t.

Discrepancy between policy and reality

The policy (last updated 06.03.2026) declares SSESS, cookiesjsr, hc, _grecaptcha under necessary cookies; Siteimprove/nmstat under analytics, with a Danish address stated; Google Tag Manager and Facebook Pixel under marketing; YouTube under video; and Power BI is mentioned in passing, with no note that data may go to Microsoft.

Not declared are actually running or permitted recipients: Google Fonts, cdn.jsdelivr.net, Cloudflare as hosting and NEL, AWS eu-north-1, Tableau, TEHIK as a separate recipient, Insights in the CSP, unpkg.com, cdnjs.cloudflare.com, npmcdn.com. This is a violation of Art. 13(1)(e): the data subject must know all recipients of their data.

reCAPTCHA leads to Google

At the bottom of the policy page and beneath the contact form is a note that the site is protected by reCAPTCHA, and that Google’s privacy policy and terms of service apply. The words “privacy policy” and “terms” are clickable links leading directly to google.com. This is the same pattern recorded at inforegister.ee: a user trying to learn how their own data is processed is redirected to Google. The browser sends a Referer header carrying the address of Tervisekassa’s policy page — Google learns who came, from where, when, and what they were reading.

Context that changes everything

Tervisekassa is not an online store. It is an organization that processes data on every insured person’s medical cases, prescribed medications, dental treatment, pregnancy and child health, medical services received abroad, sick leave, and insurance payments. In its own policy, it explicitly classifies this as a special category of personal data under GDPR Art. 9 — the highest level of protection provided by law.

The homepage has a section titled “My Data: Health Portal” — a direct link to a citizen’s personal medical data. In a session where a citizen authenticates via ID card or Mobile-ID, undeclared American processors are running: Cloudflare as hosting, Google Fonts, AWS in the CSP. This requires separate legal justification under Art. 9 — which does not exist.

Conclusion

On the banner, Tervisekassa is making an effort: there’s a reject option, categories are off by default, Google Analytics doesn’t fire without consent. But all of this is undone by what happens before any click. Google fonts, the consent-banner plugin from a US CDN, and the Cloudflare hosting itself all transmit visitor data to the USA before consent — on a site that, by its own definition, processes a special category of health data.

Evidence
Original (audit)
HAR file: ee/tervisekassa-ee-2026-05-14.har
SHA-256: 6055b61b5cc490199127482bcec4e29eb26d5a1c08cc725f9ef75e5e674a323a
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee

Important: AKI only handles submissions in Estonian. Translate the letter before sending.

To: Estonian Data Protection Inspectorate (AKI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website tervisekassa.ee.

2. Circumstances
I visited the website tervisekassa.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 14 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) Google reCAPTCHA is included in the 'necessary' category, marked 'always active' — declining it is technically blocked. Consent is not freely given.

2) cdn.jsdelivr.net (+214 ms), fonts.googleapis.com (+229 ms), and fonts.gstatic.com (+282 ms) fire before any interaction with the banner. An actual transfer, status 200.

3) Actual data recipients are not declared: Google Fonts, cdn.jsdelivr.net, Cloudflare (hosting + NEL + Insights), AWS, Tableau, TEHIK as a separate recipient, unpkg.com, cdnjs.cloudflare.com, npmcdn.com.

4) No transfer mechanism to the USA (SCC, adequacy decision, or otherwise) is stated for Google, Cloudflare, or AWS.

5) Data transfer to the USA via Cloudflare hosting, Google Fonts, and NEL, with no legal mechanism stated.

6) On the site of an organization whose core activity is processing health data, undeclared processors run before consent. This occurs within a session that may involve eID authentication for access to the Terviseportaal — with no separate legal basis.

Full technical documentation is published at: https://gdpru.eu/en/audits/ee-tervisekassa-ee/

3. Provisions violated
GDPR Art. 7(4); GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 13(1)(e); GDPR Art. 13(1)(f); GDPR Chapter V; GDPR Art. 9

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]