Policy changed — see what exactly · 2026-08-21 →
France's Ministry of the Armed Forces — 51 requests, infrastructure on proprietary domains. The policy declares AT Internet as its audience-measurement tool, exempt from consent. AT Internet is absent from the measurement; instead, via the first-party subdomain cyee.defense.gouv.fr, Eulerian fires (CNAME-masked, EWS server signature), transmitting the page URL, a Ministere_des_Armees tag, and the screen resolution — without consent and without mention in the policy.
Timeline of the leak
Declared versus actual
Transfer timings
Eulerian ufU302.js via the CNAME subdomain. EWS server signature.
Eulerian beacon col657a. Page URL + Ministere_des_Armees tag + screen resolution.
Detected trackers
- Eulerian (cyee.defense.gouv.fr — CNAME, EWS server signature)
Indicators of GDPR non-compliance
- GDPR Art. 13(1)(e) + Art. 5(1)(a) — transparency and disclosure of recipientsThe policy declares AT Internet as its audience-measurement tool. AT Internet does not appear once in the measurement. What actually fires is Eulerian: the subdomain cyee.defense.gouv.fr serves the script ufU302.js and a beacon at col657a carrying parameters evariant, pggrp, pglbl — technical signatures of Eulerian, including the EWS server signature. Eulerian, the cyee subdomain, and the very fact of CNAME-masking a third-party tracker as a first-party subdomain are not disclosed in the policy. The declared recipient of data is absent; the actual one is not named.
- Art. 82 Loi Informatique et Libertés (ePrivacy) — consent for a non-exempt trackerThe beacon at cyee.defense.gouv.fr/col657a fires at +574 ms in a no-consent state (zero Set-Cookie for the session, no consent cookie present). The consent exemption cited by the policy was granted by the CNIL for a specific audience-measurement tool (AT Internet), on the condition of declared anonymity. In practice, a different, unnamed tool is running, transmitting among other things the screen resolution (1920x1080) — a parameter used for fingerprinting, which departs from the claimed anonymity of the audience-measurement processing.
Context
defense.gouv.fr is the official portal of France’s Ministry of the Armed Forces (Ministère des Armées). It publishes material on the structure and mission of the armed forces, defense policy, national service, and recruitment. Controller: the ministry. Privacy policy of roughly 15,500 characters. Measurement: 51 requests, infrastructure on proprietary domains, captured on a clean browser. The page being viewed is a section on the new army model and national service.
Who receives data directly (before consent)
Eulerian (via the first-party subdomain cyee.defense.gouv.fr) — the page URL, a Ministere_des_Armees tag, the page category, screen resolution.
Declared versus actual
The policy explicitly names AT Internet as the site’s audience-measurement tool and states that this tool is exempt from consent collection under CNIL authorization, with the collected audience data being anonymous. The measurement does not confirm this: there is not a single request to AT Internet (xiti / ati-host domains) in the session.
Instead of the declared tool, a different one fires. The subdomain cyee.defense.gouv.fr, which at first glance appears to belong to the ministry itself, serves the script ufU302.js and then sends a beacon at the path col657a carrying parameters evariant, pggrp, pglbl. These signatures, along with the response header Server: EWS, correspond to the Eulerian platform. Hosting a third-party tracker on a proprietary subdomain is a known CNAME-delegation scheme, in which a third-party service takes on the appearance of first-party. Neither Eulerian, nor the cyee subdomain, nor the very fact of this masking is mentioned in the policy.
The discrepancy is therefore twofold: the declared data recipient (AT Internet) is absent from the measurement, while the tool actually running (Eulerian) is unnamed and technically disguised as the ministry’s own infrastructure.
Timing relative to consent
TarteAuCitron loads at +133 ms, with its configuration finishing at +481–485 ms. The Eulerian script arrives at +492 ms, and the data-transmitting beacon at +574 ms. The session state at this point is no consent: not a single cookie has been set for the entire session, and no consent-decision cookie is present. Eulerian’s data transmission occurs before any user choice is made.
What is transmitted
The Eulerian beacon carries the full address of the page being viewed, a Ministere_des_Armees section tag, the page category (Article), and a screen resolution of 1920x1080. Screen resolution is one of the parameters used for device fingerprinting; its transmission departs from the policy’s claim of fully anonymous audience-measurement processing.
What cannot be claimed from the measurement
The measurement covers one page and one state — before consent. Identifying the tool as Eulerian rests on technical signatures: the EWS server signature, the parameter scheme, and the script name; there is no direct self-identification as “Eulerian” in the traffic, as is typical with CNAME hosting. The legal classification of the consent exemption applies to the audience-measurement tool named in the policy; since the tool actually running is different and unnamed, whether the exemption applies to it cannot be established from a single measurement — what is recorded is the fact that it fires without consent and without disclosure. Server-side processing is not visible in a browser-based measurement. A CSP header for the relevant responses is not recorded in this lightweight capture.
Conclusion
The Ministry of the Armed Forces’ portal declares one audience-measurement tool in its policy (AT Internet, exempt from consent and anonymous), while a different one runs in the measurement — Eulerian, hosted via the CNAME subdomain cyee.defense.gouv.fr and thereby appearing to be the ministry’s own infrastructure. The actual tracker is not named in the policy, fires before consent, and transmits the page URL, a ministry tag, and the screen resolution. For the website of a defense ministry, the gap between the declared and the actually running tool — compounded by disguising a third-party service as a first-party domain — constitutes a violation of transparency requirements and the requirement to disclose data recipients. Remedy: bring the policy into line with the tool actually in use, disclose its third-party nature and CNAME hosting, and gate its activation on the outcome of the consent module’s choice.
7ded1c0878ecab7eebc20a049573bba443bb0df742f964353f697dc2c6a571faWhere to file: Commission nationale de l'informatique et des libertés (CNIL) — cnil.fr
To: Commission nationale de l'informatique et des libertés (CNIL) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website defense.gouv.fr. 2. Circumstances I visited the website defense.gouv.fr and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 2 July 2026 (open methodology, reproducible measurements) documents the following indications: 1) The policy declares AT Internet as its audience-measurement tool. AT Internet does not appear once in the measurement. What actually fires is Eulerian: the subdomain cyee.defense.gouv.fr serves the script ufU302.js and a beacon at col657a carrying parameters evariant, pggrp, pglbl — technical signatures of Eulerian, including the EWS server signature. Eulerian, the cyee subdomain, and the very fact of CNAME-masking a third-party tracker as a first-party subdomain are not disclosed in the policy. The declared recipient of data is absent; the actual one is not named. 2) The beacon at cyee.defense.gouv.fr/col657a fires at +574 ms in a no-consent state (zero Set-Cookie for the session, no consent cookie present). The consent exemption cited by the policy was granted by the CNIL for a specific audience-measurement tool (AT Internet), on the condition of declared anonymity. In practice, a different, unnamed tool is running, transmitting among other things the screen resolution (1920x1080) — a parameter used for fingerprinting, which departs from the claimed anonymity of the audience-measurement processing. Full technical documentation is published at: https://gdpru.eu/en/audits/fr-defense-gouv-fr/ 3. Provisions violated GDPR Art. 13(1)(e) + Art. 5(1)(a) — transparency and disclosure of recipients; Art. 82 Loi Informatique et Libertés (ePrivacy) — consent for a non-exempt tracker 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]