acer.europa.eu
The EU's energy market regulator — 10 domains, 5 American services with no consent. Google reCAPTCHA on the homepage, AddToAny, the Inter font served from a developer's personal CDN. The most dependency-heavy site in the EU institutions series.
Timeline of the leak
Declared versus actual
Transfer timings
reCAPTCHA api.js — IP address to Google, USA
Inter font, from a personal CDN
AddToAny share buttons. USA
Detected trackers
- Google reCAPTCHA (www.google.com, www.gstatic.com)
- AddToAny (static.addtoany.com)
- rsms.me CDN (the Inter font)
- cdn.jsdelivr.net (Bootstrap)
- cdnjs.cloudflare.com (Popper.js)
- Google Fonts (fonts.gstatic.com)
Indicators of GDPR non-compliance
- Regulation 2018/1725 Art. 5Google reCAPTCHA (+263 ms) loads when the homepage opens, with no consent. The visitor's IP address is transmitted to Google (USA). There is no consent banner.
- Regulation 2018/1725 Art. 5AddToAny (+673 ms) — an American 'share' button service (AddThis/Oracle). Loads three scripts, including a localized module for the Russian language. Data goes to the USA, with no consent.
- Regulation 2018/1725 Art. 15rsms.me is the personal CDN of Swedish designer Rasmus Andersson, for the Inter font. Not corporate or European infrastructure. Bootstrap via jsDelivr, Popper.js via Cloudflare cdnjs — all in the USA.
Context
The Agency for the Cooperation of Energy Regulators (ACER) is the EU agency coordinating national energy market regulators, headquartered in Ljubljana. Governed by Regulation (EU) 2018/1725. HAR: 122 requests, 10 domains. The session covered two pages.
A break from the EU institutions pattern
All previous institutions in the series — Europol, the EDPS, ECDC, EEAS, the ECB, the Council of the EU — used exclusively europa.eu infrastructure. ACER stands apart: 10 domains, 5 American services, not a single consent given.
Google reCAPTCHA on the homepage
reCAPTCHA loads at +263 ms when the homepage opens — before any user interaction. This means Google receives the IP address of every visitor to the EU energy regulator’s website, regardless of whether they fill out a form. Alternatives for EU institutions: a proprietary CAPTCHA (as at bundesheer.at), Cloudflare Turnstile (an EU instance), or hCaptcha.
rsms.me — a personal CDN
rsms.me is the personal website and CDN of Swedish designer Rasmus Andersson, creator of the Inter font. This is not corporate infrastructure with an SLA and guarantees — it is a personal server. ACER loads 5 Inter woff2 files from it on every visit. The IP addresses of EU energy regulator visitors are transmitted to a private individual’s personal server. Fix: self-host Inter (the file is available on GitHub under the SIL Open Font License).
AddToAny — ‘share’ buttons
static.addtoany.com is a social-sharing button service. It loads a localized module for the Russian language (locale/ru.js) — meaning the browser session was identified as Russian-speaking. Visit and browser-language data goes to AddToAny (USA). A “share” function can be implemented without external JavaScript.
Conclusion
ACER is the only EU institution in the series with violations at the homepage level. Google reCAPTCHA with no consent, AddToAny, a font served from a personal CDN, Bootstrap and Popper.js from American CDNs. All of these problems are technically solvable: self-host the fonts and libraries, replace reCAPTCHA with a European alternative, remove AddToAny.
2e0a89f94bcd96ce43329888db185fc1ffd32da6657b9541d35d808b5b5abe1cWhere to file: European Data Protection Supervisor (EDPS) — edps.europa.eu
To: European Data Protection Supervisor (EDPS) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website acer.europa.eu. 2. Circumstances I visited the website acer.europa.eu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 13 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) Google reCAPTCHA (+263 ms) loads when the homepage opens, with no consent. The visitor's IP address is transmitted to Google (USA). There is no consent banner. 2) AddToAny (+673 ms) — an American 'share' button service (AddThis/Oracle). Loads three scripts, including a localized module for the Russian language. Data goes to the USA, with no consent. 3) rsms.me is the personal CDN of Swedish designer Rasmus Andersson, for the Inter font. Not corporate or European infrastructure. Bootstrap via jsDelivr, Popper.js via Cloudflare cdnjs — all in the USA. Full technical documentation is published at: https://gdpru.eu/en/audits/eu-acer-europa-eu/ 3. Provisions violated Regulation 2018/1725 Art. 5; Regulation 2018/1725 Art. 5; Regulation 2018/1725 Art. 15 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]