Technical audit · 2026-07-02

ansm.sante.fr

France's National Agency for the Safety of Medicines and Health Products

France's national medicines safety agency — 49 requests, 4 domains. The policy states 12 times that no data is transferred outside the EU. The measurement records the opposite: the visitor's IP address goes to Google (fonts) and Fastly (jQuery) before the consent banner initializes. Matomo analytics, meanwhile, is correctly held back until consent, with not a single cookie set.

Timeline of the leak

+0 ms · portal load
Content, styles, and scripts served from ansm.sante.fr. Hosted behind Varnish, with an X-Varnish header present.
+278 ms · banner core
tarteaucitron.min.js — the core of the consent manager loads from the proprietary domain.
+292 ms · before consent
fonts.googleapis.com — Google Fonts CSS (Roboto). The visitor's IP address goes to Google LLC (USA). The banner is not yet ready.
+321 ms · before consent
fonts.gstatic.com — Roboto font files (woff2). The IP address goes to Google LLC (USA).
+376 ms · before consent
code.jquery.com — the jQuery 1.12.4 library via the Fastly CDN (USA). The IP address goes to Fastly Inc.
+679 ms · banner ready
tarteaucitron.services.min.js — the banner's service configuration finishes loading. By this point, three external calls have already fired.
Matomo — not activated
Piwik/Matomo analytics did not fire once in the measurement — correctly held back until consent, exactly as the policy promises. Set-Cookie — zero.

Declared versus actual

TarteAuCitron — the consent manager (self-hosted) — declared
PHPSESSID — a session cookie, technical — declared
Matomo / Piwik — analytics, only after consent, 'data is anonymous' — declared
YouTube, Dailymotion — third-party video-player cookies — declared
Facebook, LinkedIn, X — social buttons, 'no cookie is set' — declared
'Aucun transfert de données hors UE' — stated directly, 12 times — declared
+ Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — IP address transmitted to Google LLC, USA — not declared
+ jQuery / Fastly (code.jquery.com) — IP address transmitted to Fastly Inc, USA — not declared

Transfer timings

+292 ms fonts.googleapis.com

Google Fonts CSS. Google LLC, USA.

+321 ms fonts.gstatic.com

Google Fonts woff2. Google LLC, USA.

+376 ms code.jquery.com

jQuery 1.12.4. Fastly Inc, USA.

Detected trackers

Indicators of GDPR non-compliance

Context

ANSM (Agence nationale de sécurité du médicament et des produits de santé) is France’s national agency for the safety of medicines and health products. It oversees the circulation of medicines, pharmacovigilance, and product recalls. Controller: ANSM itself. The privacy policy is provided as a separate document of roughly 28,500 characters, covering all processing on the portal. Measurement: 49 requests, 4 domains, captured on a clean browser with no VPN and no blocker.

Google LLC (USA) — via Google Fonts; Fastly Inc (USA) — via the jQuery CDN.

Declared versus actual

The policy contains an unambiguous, repeatedly stated formula: data is not transferred outside the European Union. This claim appears 12 times — once for each described processing activity. It is a categorical statement, not a caveat.

The measurement records three external calls, each transmitting the visitor’s IP address to a recipient outside the EU. The Google Fonts CSS and font files load from fonts.googleapis.com and fonts.gstatic.com — infrastructure belonging to Google LLC, a US company. The jQuery library loads from code.jquery.com — the Fastly Inc CDN, also US-based. None of these three calls is mentioned in the policy: the list of recipients includes Matomo, YouTube, Dailymotion, and social networks, but Google Fonts and jQuery are absent from it.

The discrepancy, then, is not a matter of an unlisted cookie — Google Fonts and jQuery set no cookies. The discrepancy is that the claim “nothing goes outside the EU” is contradicted by the fact that the visitor’s IP address goes to two American companies.

The core of the TarteAuCitron consent manager loads at +278 ms, yet the banner’s service configuration only finishes at +679 ms. Both Google Fonts calls (+292 ms and +321 ms) and the jQuery call (+376 ms) fire in the interval between them — that is, before the banner is ready to record a user’s choice. Consent could not physically have been given at the moment the IP address was transmitted.

What is done correctly

A substantial portion of what the policy declares is upheld in practice. Matomo/Piwik analytics did not activate once in the measurement — correctly held back until consent, exactly as the policy promises. Not a single cookie is set for the entire session. A consent manager is present and loads from the agency’s own domain. Video players and social buttons are not activated on the homepage. The violation is confined to the three external calls and the cross-border transfer claim — it does not affect the analytics layer, which is built correctly.

What cannot be claimed from the measurement

The measurement covers the homepage. Matomo’s behavior after clicking “accept,” as well as YouTube and Dailymotion calls on pages with video, are not observed in this single-session capture of the homepage. The server IPs in the measurement belong to Google and Fastly; the conclusion that the recipient is located outside the EU rests on the legal affiliation of these companies (USA), not on the geolocation of a specific edge node. Server-side processing (Protokolldateien, logs) does not surface in a browser-based measurement.

Conclusion

ANSM has built its analytics layer correctly: Matomo is held back until consent, no cookies are written, and the consent manager is self-hosted. But the policy contains a categorical claim, repeated 12 times, that no data is transferred outside the EU — and this claim is contradicted by the measurement: the visitor’s IP address goes to Google (via fonts) and Fastly (via jQuery), both American companies, both calls occurring before the consent banner is ready. For a national health authority, the gap between the explicit claim “hors UE — aucun transfert” and the actual transfer of the IP address to the USA constitutes a violation of transparency requirements and cross-border transfer rules. The remedy is simple: host the fonts and jQuery locally on the proprietary domain — the infrastructure for this already exists.

Evidence
Original (audit)
HAR file: fr/ansm-sante-fr-2026-07-02.har
SHA-256: 5d28652a0880ec436f83ea7161127aeded410b2637d4723d6e2c61ebd2c5c00a
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Commission nationale de l'informatique et des libertés (CNIL)cnil.fr

To: Commission nationale de l'informatique et des libertés (CNIL)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website ansm.sante.fr.

2. Circumstances
I visited the website ansm.sante.fr and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 2 July 2026 (open methodology, reproducible measurements) documents the following indications:

1) The policy states 12 times: 'Aucun transfert de données hors de l'Union européenne n'est réalisé.' The measurement records the visitor's IP address being transmitted to fonts.googleapis.com (142.251.38.74) and fonts.gstatic.com (216.58.198.195) — Google LLC — and to code.jquery.com (151.101.1.155) — Fastly Inc. Both companies are American. The claim of a complete absence of transfer outside the EU is directly contradicted by the measurement.

2) Google Fonts and jQuery/Fastly are not mentioned in the policy even once. The policy lists recipients (Matomo, YouTube, Dailymotion, social networks), but the two recipients that actually received the IP address are absent from that list.

3) External calls to Google Fonts (+292 ms) and jQuery (+376 ms) fire before the TarteAuCitron consent banner finishes initializing (the services file loads at +679 ms). The IP address is transmitted outside the EU before any user choice is made.

Full technical documentation is published at: https://gdpru.eu/en/audits/fr-ansm-sante-fr/

3. Provisions violated
GDPR Art. 44 (Chapter V) — cross-border transfer; GDPR Art. 13(1)(e) — disclosure of recipients; GDPR Art. 5(1)(a) — transparency

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]