ansm.sante.fr
France's national medicines safety agency — 49 requests, 4 domains. The policy states 12 times that no data is transferred outside the EU. The measurement records the opposite: the visitor's IP address goes to Google (fonts) and Fastly (jQuery) before the consent banner initializes. Matomo analytics, meanwhile, is correctly held back until consent, with not a single cookie set.
Timeline of the leak
Declared versus actual
Transfer timings
Google Fonts CSS. Google LLC, USA.
Google Fonts woff2. Google LLC, USA.
jQuery 1.12.4. Fastly Inc, USA.
Detected trackers
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com)
- jQuery CDN (code.jquery.com / Fastly)
- TarteAuCitron CMP (self-hosted)
Indicators of GDPR non-compliance
- GDPR Art. 44 (Chapter V) — cross-border transferThe policy states 12 times: 'Aucun transfert de données hors de l'Union européenne n'est réalisé.' The measurement records the visitor's IP address being transmitted to fonts.googleapis.com (142.251.38.74) and fonts.gstatic.com (216.58.198.195) — Google LLC — and to code.jquery.com (151.101.1.155) — Fastly Inc. Both companies are American. The claim of a complete absence of transfer outside the EU is directly contradicted by the measurement.
- GDPR Art. 13(1)(e) — disclosure of recipientsGoogle Fonts and jQuery/Fastly are not mentioned in the policy even once. The policy lists recipients (Matomo, YouTube, Dailymotion, social networks), but the two recipients that actually received the IP address are absent from that list.
- GDPR Art. 5(1)(a) — transparencyExternal calls to Google Fonts (+292 ms) and jQuery (+376 ms) fire before the TarteAuCitron consent banner finishes initializing (the services file loads at +679 ms). The IP address is transmitted outside the EU before any user choice is made.
Context
ANSM (Agence nationale de sécurité du médicament et des produits de santé) is France’s national agency for the safety of medicines and health products. It oversees the circulation of medicines, pharmacovigilance, and product recalls. Controller: ANSM itself. The privacy policy is provided as a separate document of roughly 28,500 characters, covering all processing on the portal. Measurement: 49 requests, 4 domains, captured on a clean browser with no VPN and no blocker.
Who receives data directly (before consent)
Google LLC (USA) — via Google Fonts; Fastly Inc (USA) — via the jQuery CDN.
Declared versus actual
The policy contains an unambiguous, repeatedly stated formula: data is not transferred outside the European Union. This claim appears 12 times — once for each described processing activity. It is a categorical statement, not a caveat.
The measurement records three external calls, each transmitting the visitor’s IP address to a recipient outside the EU. The Google Fonts CSS and font files load from fonts.googleapis.com and fonts.gstatic.com — infrastructure belonging to Google LLC, a US company. The jQuery library loads from code.jquery.com — the Fastly Inc CDN, also US-based. None of these three calls is mentioned in the policy: the list of recipients includes Matomo, YouTube, Dailymotion, and social networks, but Google Fonts and jQuery are absent from it.
The discrepancy, then, is not a matter of an unlisted cookie — Google Fonts and jQuery set no cookies. The discrepancy is that the claim “nothing goes outside the EU” is contradicted by the fact that the visitor’s IP address goes to two American companies.
Timing relative to consent
The core of the TarteAuCitron consent manager loads at +278 ms, yet the banner’s service configuration only finishes at +679 ms. Both Google Fonts calls (+292 ms and +321 ms) and the jQuery call (+376 ms) fire in the interval between them — that is, before the banner is ready to record a user’s choice. Consent could not physically have been given at the moment the IP address was transmitted.
What is done correctly
A substantial portion of what the policy declares is upheld in practice. Matomo/Piwik analytics did not activate once in the measurement — correctly held back until consent, exactly as the policy promises. Not a single cookie is set for the entire session. A consent manager is present and loads from the agency’s own domain. Video players and social buttons are not activated on the homepage. The violation is confined to the three external calls and the cross-border transfer claim — it does not affect the analytics layer, which is built correctly.
What cannot be claimed from the measurement
The measurement covers the homepage. Matomo’s behavior after clicking “accept,” as well as YouTube and Dailymotion calls on pages with video, are not observed in this single-session capture of the homepage. The server IPs in the measurement belong to Google and Fastly; the conclusion that the recipient is located outside the EU rests on the legal affiliation of these companies (USA), not on the geolocation of a specific edge node. Server-side processing (Protokolldateien, logs) does not surface in a browser-based measurement.
Conclusion
ANSM has built its analytics layer correctly: Matomo is held back until consent, no cookies are written, and the consent manager is self-hosted. But the policy contains a categorical claim, repeated 12 times, that no data is transferred outside the EU — and this claim is contradicted by the measurement: the visitor’s IP address goes to Google (via fonts) and Fastly (via jQuery), both American companies, both calls occurring before the consent banner is ready. For a national health authority, the gap between the explicit claim “hors UE — aucun transfert” and the actual transfer of the IP address to the USA constitutes a violation of transparency requirements and cross-border transfer rules. The remedy is simple: host the fonts and jQuery locally on the proprietary domain — the infrastructure for this already exists.
5d28652a0880ec436f83ea7161127aeded410b2637d4723d6e2c61ebd2c5c00aWhere to file: Commission nationale de l'informatique et des libertés (CNIL) — cnil.fr
To: Commission nationale de l'informatique et des libertés (CNIL) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website ansm.sante.fr. 2. Circumstances I visited the website ansm.sante.fr and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 2 July 2026 (open methodology, reproducible measurements) documents the following indications: 1) The policy states 12 times: 'Aucun transfert de données hors de l'Union européenne n'est réalisé.' The measurement records the visitor's IP address being transmitted to fonts.googleapis.com (142.251.38.74) and fonts.gstatic.com (216.58.198.195) — Google LLC — and to code.jquery.com (151.101.1.155) — Fastly Inc. Both companies are American. The claim of a complete absence of transfer outside the EU is directly contradicted by the measurement. 2) Google Fonts and jQuery/Fastly are not mentioned in the policy even once. The policy lists recipients (Matomo, YouTube, Dailymotion, social networks), but the two recipients that actually received the IP address are absent from that list. 3) External calls to Google Fonts (+292 ms) and jQuery (+376 ms) fire before the TarteAuCitron consent banner finishes initializing (the services file loads at +679 ms). The IP address is transmitted outside the EU before any user choice is made. Full technical documentation is published at: https://gdpru.eu/en/audits/fr-ansm-sante-fr/ 3. Provisions violated GDPR Art. 44 (Chapter V) — cross-border transfer; GDPR Art. 13(1)(e) — disclosure of recipients; GDPR Art. 5(1)(a) — transparency 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]