curia.europa.eu
The Court of Justice of the EU streams its hearings via Microsoft Azure. Matomo Cloud (New Zealand) instead of self-hosted. The session captured a live hearing stream from May 7, 2026 — each viewer's data goes to American infrastructure.
Timeline of the leak
Declared versus actual
Transfer timings
Matomo Cloud — InnoCraft, New Zealand
Azure API Management. USA
HLS video stream. Azure, USA
Detected trackers
- Matomo Cloud (curia.matomo.cloud)
Indicators of GDPR non-compliance
- Regulation 2018/1725 Art. 5, Art. 48Matomo Cloud (+216 ms) — the cloud-hosted version of Matomo, managed by InnoCraft Ltd. (New Zealand). Unlike EBA's and eu-LISA's self-hosted Matomo, the CJEU's analytics data is transmitted to a third party outside the EU. No consent banner.
- Regulation 2018/1725 Art. 15, Chapter VLive streaming of CJEU hearings runs through Microsoft Azure: amcpwe-curia-cc-apim.azure-api.net (Azure API Management), amcpwecuriahls.azurewebsites.net (Azure HLS video), azurefd.net (Azure Front Door CDN). Every viewer's IP address is transmitted to Microsoft (USA).
Context
The Court of Justice of the European Union (CJEU) is the EU’s highest judicial body, interpreting Union law and ensuring its uniform application. It was this very court that issued the Schrems I (2015) and Schrems II (2020) rulings — declaring data transfers to the USA unlawful in the absence of adequate safeguards. Governed by Regulation (EU) 2018/1725. HAR: 76 requests, 7 domains. The session captured an embedded hearing broadcast.
Schrems II and Azure
The Schrems II ruling, issued by this same court in July 2020, found the Privacy Shield mechanism insufficient for transferring data from the EU to the USA. The court held that US surveillance law does not provide an equivalent level of protection for European citizens’ data.
The HAR shows that the CJEU itself streams its hearings via Microsoft Azure — American cloud infrastructure. Every viewer’s IP address passes through azure-api.net, azurewebsites.net, and azurefd.net. The data is processed by Microsoft (USA) with no explicit visitor consent.
curia.connectedviews.eu — a proprietary domain, someone else’s infrastructure
curia.connectedviews.eu looks like the court’s own domain. But behind it sits the ConnectedViews platform — a court-hearing broadcast service running on Microsoft Azure. The domain reads “curia.”, but the data goes to Azure.
Matomo Cloud vs. self-hosted
EBA and eu-LISA use self-hosted Matomo on their own servers — analytics data stays within the agency’s infrastructure. The CJEU uses curia.matomo.cloud — the cloud-hosted version, managed by InnoCraft Ltd. (Wellington, New Zealand). This is a transfer of analytics data to a third party outside the EU. Self-hosted Matomo would resolve this — the source code is open, and it can be deployed on the court’s own servers.
CSP — broad permissions
default-src https://* gap-iab://* wss://* data: blob: 'unsafe-inline' 'unsafe-eval' — this is an extremely broad CSP, effectively permitting any HTTPS request. Unlike Europol’s strict CSP, which limits sources to only self and europa.eu, the CJEU permits loading from any HTTPS domain.
Conclusion
The court that issued Schrems II uses Microsoft Azure to stream its own public hearings, and Matomo Cloud outside the EU. Architectural choices the court itself found insufficient for the private sector are used within its own infrastructure. Self-hosted Matomo and a European alternative for video streaming (such as ENISA’s proprietary PeerTube) would resolve both issues
7e7bd9e8874cfcb91237013cc38ef24a53f2118f4a497b27af376a9814b0fbbaWhere to file: European Data Protection Supervisor (EDPS) — edps.europa.eu
To: European Data Protection Supervisor (EDPS) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website curia.europa.eu. 2. Circumstances I visited the website curia.europa.eu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 13 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) Matomo Cloud (+216 ms) — the cloud-hosted version of Matomo, managed by InnoCraft Ltd. (New Zealand). Unlike EBA's and eu-LISA's self-hosted Matomo, the CJEU's analytics data is transmitted to a third party outside the EU. No consent banner. 2) Live streaming of CJEU hearings runs through Microsoft Azure: amcpwe-curia-cc-apim.azure-api.net (Azure API Management), amcpwecuriahls.azurewebsites.net (Azure HLS video), azurefd.net (Azure Front Door CDN). Every viewer's IP address is transmitted to Microsoft (USA). Full technical documentation is published at: https://gdpru.eu/en/audits/eu-curia-europa-eu/ 3. Provisions violated Regulation 2018/1725 Art. 5, Art. 48; Regulation 2018/1725 Art. 15, Chapter V 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]