Technical audit · 2026-05-13

curia.europa.eu

The CJEU — the European Union's Highest Court

The Court of Justice of the EU streams its hearings via Microsoft Azure. Matomo Cloud (New Zealand) instead of self-hosted. The session captured a live hearing stream from May 7, 2026 — each viewer's data goes to American infrastructure.

Timeline of the leak

+216 ms · without consent
curia.matomo.cloud — Matomo Cloud (InnoCraft, New Zealand). Data goes outside the EU.
+295 ms
webtools.europa.eu — shared EU infrastructure.
+308 ms
curia.connectedviews.eu — a proprietary domain hosting the embedded hearing player.
+777 ms
amcpwe-curia-cc-apim.azure-api.net — Azure API Management. Data goes to Microsoft, USA.
+2486 ms
amcpwecuriahls.azurewebsites.net — the hearing's HLS video stream. Azure, USA.
+2503 ms
azurefd.net — Azure Front Door CDN. Video thumbnails. Microsoft, USA.

Declared versus actual

+ Matomo Cloud (curia.matomo.cloud — InnoCraft, New Zealand) — not declared
+ Microsoft Azure (azure-api.net, azurewebsites.net, azurefd.net) — not declared

Transfer timings

+216 ms curia.matomo.cloud

Matomo Cloud — InnoCraft, New Zealand

+777 ms azure-api.net

Azure API Management. USA

+2486 ms azurewebsites.net

HLS video stream. Azure, USA

Detected trackers

Indicators of GDPR non-compliance

Context

The Court of Justice of the European Union (CJEU) is the EU’s highest judicial body, interpreting Union law and ensuring its uniform application. It was this very court that issued the Schrems I (2015) and Schrems II (2020) rulings — declaring data transfers to the USA unlawful in the absence of adequate safeguards. Governed by Regulation (EU) 2018/1725. HAR: 76 requests, 7 domains. The session captured an embedded hearing broadcast.

Schrems II and Azure

The Schrems II ruling, issued by this same court in July 2020, found the Privacy Shield mechanism insufficient for transferring data from the EU to the USA. The court held that US surveillance law does not provide an equivalent level of protection for European citizens’ data.

The HAR shows that the CJEU itself streams its hearings via Microsoft Azure — American cloud infrastructure. Every viewer’s IP address passes through azure-api.net, azurewebsites.net, and azurefd.net. The data is processed by Microsoft (USA) with no explicit visitor consent.

curia.connectedviews.eu — a proprietary domain, someone else’s infrastructure

curia.connectedviews.eu looks like the court’s own domain. But behind it sits the ConnectedViews platform — a court-hearing broadcast service running on Microsoft Azure. The domain reads “curia.”, but the data goes to Azure.

Matomo Cloud vs. self-hosted

EBA and eu-LISA use self-hosted Matomo on their own servers — analytics data stays within the agency’s infrastructure. The CJEU uses curia.matomo.cloud — the cloud-hosted version, managed by InnoCraft Ltd. (Wellington, New Zealand). This is a transfer of analytics data to a third party outside the EU. Self-hosted Matomo would resolve this — the source code is open, and it can be deployed on the court’s own servers.

CSP — broad permissions

default-src https://* gap-iab://* wss://* data: blob: 'unsafe-inline' 'unsafe-eval' — this is an extremely broad CSP, effectively permitting any HTTPS request. Unlike Europol’s strict CSP, which limits sources to only self and europa.eu, the CJEU permits loading from any HTTPS domain.

Conclusion

The court that issued Schrems II uses Microsoft Azure to stream its own public hearings, and Matomo Cloud outside the EU. Architectural choices the court itself found insufficient for the private sector are used within its own infrastructure. Self-hosted Matomo and a European alternative for video streaming (such as ENISA’s proprietary PeerTube) would resolve both issues

Evidence
Original (audit)
HAR file: eu/curia-europa-eu-2026-05-13.har
SHA-256: 7e7bd9e8874cfcb91237013cc38ef24a53f2118f4a497b27af376a9814b0fbba
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: European Data Protection Supervisor (EDPS)edps.europa.eu

To: European Data Protection Supervisor (EDPS)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website curia.europa.eu.

2. Circumstances
I visited the website curia.europa.eu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 13 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) Matomo Cloud (+216 ms) — the cloud-hosted version of Matomo, managed by InnoCraft Ltd. (New Zealand). Unlike EBA's and eu-LISA's self-hosted Matomo, the CJEU's analytics data is transmitted to a third party outside the EU. No consent banner.

2) Live streaming of CJEU hearings runs through Microsoft Azure: amcpwe-curia-cc-apim.azure-api.net (Azure API Management), amcpwecuriahls.azurewebsites.net (Azure HLS video), azurefd.net (Azure Front Door CDN). Every viewer's IP address is transmitted to Microsoft (USA).

Full technical documentation is published at: https://gdpru.eu/en/audits/eu-curia-europa-eu/

3. Provisions violated
Regulation 2018/1725 Art. 5, Art. 48; Regulation 2018/1725 Art. 15, Chapter V

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]