Technical audit · 2026-05-13

acer.europa.eu

ACER — the European Union's Energy Market Regulator

The EU's energy market regulator — 10 domains, 5 American services with no consent. Google reCAPTCHA on the homepage, AddToAny, the Inter font served from a developer's personal CDN. The most dependency-heavy site in the EU institutions series.

Timeline of the leak

+262 ms · without consent
Bootstrap (cdn.jsdelivr.net) — a CSS framework from a public CDN.
+263 ms · without consent
Google reCAPTCHA (api.js) — loads immediately. IP address to Google, USA.
+279 ms · without consent
rsms.me — the Inter font, from a personal CDN. 5 woff2 files.
+328 ms · without consent
www.gstatic.com — reCAPTCHA resources. Google, USA.
+621 ms · without consent
cdnjs.cloudflare.com — Popper.js 1.14.3. USA.
+673 ms · without consent
AddToAny (static.addtoany.com) — 'share' buttons. USA.

Declared versus actual

+ Google reCAPTCHA — not declared
+ AddToAny (static.addtoany.com) — not declared
+ rsms.me CDN — not declared
+ cdn.jsdelivr.net — not declared
+ cdnjs.cloudflare.com — not declared
+ Google Fonts (via reCAPTCHA) — not declared

Transfer timings

+263 ms www.google.com

reCAPTCHA api.js — IP address to Google, USA

+279 ms rsms.me

Inter font, from a personal CDN

+673 ms static.addtoany.com

AddToAny share buttons. USA

Detected trackers

Indicators of GDPR non-compliance

Context

The Agency for the Cooperation of Energy Regulators (ACER) is the EU agency coordinating national energy market regulators, headquartered in Ljubljana. Governed by Regulation (EU) 2018/1725. HAR: 122 requests, 10 domains. The session covered two pages.

A break from the EU institutions pattern

All previous institutions in the series — Europol, the EDPS, ECDC, EEAS, the ECB, the Council of the EU — used exclusively europa.eu infrastructure. ACER stands apart: 10 domains, 5 American services, not a single consent given.

Google reCAPTCHA on the homepage

reCAPTCHA loads at +263 ms when the homepage opens — before any user interaction. This means Google receives the IP address of every visitor to the EU energy regulator’s website, regardless of whether they fill out a form. Alternatives for EU institutions: a proprietary CAPTCHA (as at bundesheer.at), Cloudflare Turnstile (an EU instance), or hCaptcha.

rsms.me — a personal CDN

rsms.me is the personal website and CDN of Swedish designer Rasmus Andersson, creator of the Inter font. This is not corporate infrastructure with an SLA and guarantees — it is a personal server. ACER loads 5 Inter woff2 files from it on every visit. The IP addresses of EU energy regulator visitors are transmitted to a private individual’s personal server. Fix: self-host Inter (the file is available on GitHub under the SIL Open Font License).

AddToAny — ‘share’ buttons

static.addtoany.com is a social-sharing button service. It loads a localized module for the Russian language (locale/ru.js) — meaning the browser session was identified as Russian-speaking. Visit and browser-language data goes to AddToAny (USA). A “share” function can be implemented without external JavaScript.

Conclusion

ACER is the only EU institution in the series with violations at the homepage level. Google reCAPTCHA with no consent, AddToAny, a font served from a personal CDN, Bootstrap and Popper.js from American CDNs. All of these problems are technically solvable: self-host the fonts and libraries, replace reCAPTCHA with a European alternative, remove AddToAny.

Evidence
Original (audit)
HAR file: eu/acer-europa-eu-2026-05-13.har
SHA-256: 2e0a89f94bcd96ce43329888db185fc1ffd32da6657b9541d35d808b5b5abe1c
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: European Data Protection Supervisor (EDPS)edps.europa.eu

To: European Data Protection Supervisor (EDPS)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website acer.europa.eu.

2. Circumstances
I visited the website acer.europa.eu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 13 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) Google reCAPTCHA (+263 ms) loads when the homepage opens, with no consent. The visitor's IP address is transmitted to Google (USA). There is no consent banner.

2) AddToAny (+673 ms) — an American 'share' button service (AddThis/Oracle). Loads three scripts, including a localized module for the Russian language. Data goes to the USA, with no consent.

3) rsms.me is the personal CDN of Swedish designer Rasmus Andersson, for the Inter font. Not corporate or European infrastructure. Bootstrap via jsDelivr, Popper.js via Cloudflare cdnjs — all in the USA.

Full technical documentation is published at: https://gdpru.eu/en/audits/eu-acer-europa-eu/

3. Provisions violated
Regulation 2018/1725 Art. 5; Regulation 2018/1725 Art. 5; Regulation 2018/1725 Art. 15

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]