Technical audit · 2026-07-02

ameli.fr

France's National Health Insurance

France's national health insurance — 42 requests, 7 domains. Piano Analytics audience measurement correctly operates in OPT-OUT mode. But Google Campaign Manager / DoubleClick sends a page_view carrying the medical page's URL to Google's advertising infrastructure with no consent given — advertising does not qualify for the consent exemption.

Timeline of the leak

+0 ms · portal load
Content and resources served from www.ameli.fr. The page being viewed is an actualités section on the new-parent benefit.
+136 ms · audience tag
tag.aticdn.net — the AT Internet / Piano Analytics library. Declared in the policy, exempt from consent.
+140 ms · CDN
cdn.jsdelivr.net — an external JS library CDN. Not mentioned in the policy.
+246 ms · GTM
www.googletagmanager.com/gtm.js?id=GTM-53ZCDGR — Google's tag container fires.
+458 ms · audience OPT-OUT
logs1412.xiti.com/event — a Piano Analytics beacon carrying idclient=OPT-OUT. The no-consent state is confirmed.
+648 ms · advertising before consent
pagead2.googlesyndication.com/ccm/collect?en=page_view — Google Campaign Manager receives a view event carrying the full URL of the medical page, despite the absence of consent.

Declared versus actual

Doubleclick (Google) / Campaign Manager — declared, transfer to the USA based on an adequacy decision — заявлен
Piano Analytics (AT Internet) — declared as an audience-measurement tool, exempt from consent, with a 'Refuser' button available — заявлен
Vimeo, Adform — declared as sub-processors — заявлен
Data transfer to the USA — disclosed in the policy — заявлен
+ Google Tag Manager (GTM-53ZCDGR) — the activation mechanism, not named specifically — не заявлен
+ cdn.jsdelivr.net — a JS library CDN, not mentioned — не заявлен

Transfer timings

+246 ms www.googletagmanager.com

GTM-53ZCDGR — the container. Google, USA.

+458 ms logs1412.xiti.com

Piano Analytics, idclient=OPT-OUT. Correctly exempt from consent.

+648 ms pagead2.googlesyndication.com

Campaign Manager / DoubleClick DC-15137949, page_view carrying the page URL. Google, USA.

Detected trackers

Indicators of GDPR non-compliance

Context

ameli.fr is the official portal of Assurance Maladie, France’s national compulsory health insurance system. Through it, insured persons manage reimbursements, sick leave, medical appointments, and benefits. Controller: l’Assurance Maladie. The privacy policy is extensive (roughly 64,000 characters) and detailed. Measurement: 42 requests, 7 domains, captured on a clean browser, on an actualités page about the new-parent benefit.

Who receives data directly

Google LLC (USA) — a page_view event carrying the full URL of the medical page being viewed, via Campaign Manager / DoubleClick, with no consent given.

Declared versus actual

ameli’s policy discloses data recipients in detail and, unlike a number of other government sites, honestly names its American sub-processors: Doubleclick (Google) and Campaign Manager are named directly, and the transfer to the USA is stated with its legal basis (an adequacy decision). Piano Analytics is declared as an audience-measurement tool exempt from consent, with an accessible “Refuser” button. The measurement confirms this: the Xiti/Piano beacon goes out carrying idclient=OPT-OUT, and no cookies are set. On this front, the policy matches the facts.

The discrepancy lies in the legal category assigned to Campaign Manager. Under French law, the consent exemption applies only to audience measurement meeting CNIL’s conditions. Campaign Manager / DoubleClick, by the policy’s own wording, serves to measure the effectiveness of advertising campaigns — this is advertising processing, requiring prior (opt-in) consent. In the measurement, the session state is unambiguously “no consent”: Xiti in OPT-OUT, zero cookies. Despite this, at +648 ms a request to pagead2.googlesyndication.com/ccm/collect carrying a page_view event goes out to Google. The advertising tracker is not held back by the opt-out state.

What is transmitted

The dl parameter of the ccm/collect request carries the full address of the page being viewed — a section on the childbirth benefit. In other words, what is transmitted to Google’s advertising infrastructure is not merely the fact of a visit to ameli.fr, but the specific medical topic the visitor is interested in — on the national health insurance portal, before any consent.

What cannot be claimed from the measurement

The measurement covers a single page in the actualités section. The transfer to the USA itself is disclosed by the policy, backed by an adequacy decision — the subject of the violation is not the fact of the transfer, but the advertising tracker firing with no consent. The conclusion that Campaign Manager belongs to the advertising category rests on the policy’s own explicit wording (“efficacité de nos campagnes”) and on the technical nature of the domain pagead2.googlesyndication.com. Behavior following an “Accepter” click is not observed in this session; what is recorded here is specifically the opt-out/no-consent state.

Conclusion

ameli.fr has built the audience-measurement side correctly: Piano Analytics runs in OPT-OUT mode, no cookies are written, and opting out is available. The policy is transparent in disclosing recipients and the transfer to the USA. But the advertising layer ignores this opt-out state: Google Campaign Manager / DoubleClick, via the GTM container, sends a page_view carrying the medical page’s URL to Google’s infrastructure even though there is no consent, and advertising does not qualify for the consent exemption. For a compulsory health insurance portal, transmitting the topic of the medical page being read to an advertising system before consent is a violation of the requirements on legal basis and prior consent for advertising trackers. Remedy: gate Campaign Manager’s activation on the outcome of the consent module’s choice, the same way this has already been done for the audience-measurement layer.

Evidence
Original (audit)
HAR file: fr/ameli-fr-2026-07-02.har
SHA-256: f0978babf21b2ae4dd39fe8c22bedaa2859233c8d6ed4ad47571c16b11006d3d
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Commission nationale de l'informatique et des libertés (CNIL)cnil.fr

To: Commission nationale de l'informatique et des libertés (CNIL)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website ameli.fr.

2. Circumstances
I visited the website ameli.fr and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 2 July 2026 (open methodology, reproducible measurements) documents the following indications:

1) Google Campaign Manager / DoubleClick (the GTM-53ZCDGR container activates gtag DC-15137949) sends a request to pagead2.googlesyndication.com/ccm/collect with a page_view event at +648 ms. Session state: no consent — Xiti transmits idclient=OPT-OUT, zero Set-Cookie for the entire session. Despite this, Google's advertising tracker fires. By the policy's own wording, Campaign Manager serves to 'mesurer l'efficacité de nos campagnes' — this is advertising measurement, which does not qualify for the consent exemption reserved for audience-measurement tools alone (Piano Analytics).

2) The dl parameter of the ccm/collect request carries the full URL of the page being viewed — a section on the childbirth benefit on the health insurance portal. Information about which medical topic the visitor is reading goes to Google's advertising infrastructure before any consent.

Full technical documentation is published at: https://gdpru.eu/en/audits/fr-ameli-fr/

3. Provisions violated
ePrivacy / Art. 82 Loi Informatique et Libertés + GDPR Art. 6(1); GDPR Art. 9 (context) / Art. 5(1)(a)

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]