Technical audit · 2026-07-02

economie.gouv.fr

French Ministry of the Economy and Finance

France's Ministry of the Economy and Finance — 47 requests, infrastructure on proprietary domains plus a Cloudflare beacon. Eulerian and Piano Analytics are declared by name, citing a CNIL exemption — transparency about the tools themselves is present. But the Eulerian beacon, via the first-party subdomain nmmt.economie.gouv.fr, transmits the title of the article being read, a content_id, and screen resolution (a fingerprinting parameter) with no consent given — at odds with the claimed anonymity of the audience-measurement processing.

Timeline of the leak

+0 ms · portal load
Content and resources served from www.economie.gouv.fr. The page being viewed is an Actualités article on economic support measures.
+97 ms · Cloudflare beacon
static.cloudflareinsights.com/beacon.min.js — the Cloudflare Web Analytics beacon. Declared in the policy only as a security cookie.
+113 ms · tracker script
nmmt.economie.gouv.fr/ufU302.js — the Eulerian script, served from a first-party subdomain (Server EWS).
+795 ms · data transmission without consent
nmmt.economie.gouv.fr/col657a — the Eulerian beacon transmits the full article title, content_id=3240361, and a screen resolution of 1920x1080.

Declared versus actual

Piano Analytics (formerly AT Internet) and Eulerian — declared by name, citing a CNIL exemption — declared
Audience processing declared as anonymous visit statistics — declared
Cloudflare — declared in connection with security cookies (cf_clearance, __cf_bm) — declared
Eulerian cookies (etuix, et0, et1) — 13 months, collecting data on the device, browser, and interactions with advertising elements (PDF) — declared
+ static.cloudflareinsights.com — Cloudflare's analytics beacon, not covered by the security-cookie declaration — not declared
+ Eulerian's CNAME placement on the subdomain nmmt.economie.gouv.fr — not disclosed — not declared

Transfer timings

+97 ms static.cloudflareinsights.com

Cloudflare Web Analytics beacon.min.js. Declared only in connection with security.

+113 ms nmmt.economie.gouv.fr

Eulerian ufU302.js via the CNAME subdomain. Server EWS.

+795 ms nmmt.economie.gouv.fr

Eulerian beacon col657a. Article title + content_id + screen resolution.

Detected trackers

Indicators of GDPR non-compliance

Context

economie.gouv.fr is the official portal of France’s Ministry of the Economy and Finance (Bercy). It publishes economic policy news, support measures, and information for citizens and businesses. Controller: the ministry. The privacy policy is provided as two documents: a main text and a separate PDF listing internal cookies. Measurement: 47 requests, infrastructure on proprietary domains, captured on a clean browser. The page being viewed is an article on economic support measures.

Eulerian (via the first-party subdomain nmmt.economie.gouv.fr) — the title of the article being read, a content_id, screen resolution.

Declared versus actual

On disclosure of its tools, the site behaves more honestly than many others: the policy directly names both audience-measurement platforms — Piano Analytics (formerly AT Internet) and Eulerian — and cites a CNIL exemption from consent collection. A separate PDF details the cookies for each service. Unlike a number of other government sites, Eulerian’s existence is not hidden.

The discrepancy lies in the scope and nature of the processing versus the claimed anonymity. The policy describes the audience data as anonymous visit statistics: the number of pages viewed, the number of visits, their frequency. The measurement shows something different. The Eulerian beacon, served from the subdomain nmmt.economie.gouv.fr (response header Server: EWS — the signature of the Eulerian platform, deployed via CNAME), transmits the full title of the specific article being read, its content_id, and a screen resolution of 1920x1080. Screen resolution is one of the parameters used for device fingerprinting. The site’s own PDF describes Eulerian as collecting data on the device, browser, and interactions with advertising elements, with a 13-month retention period. Taken together, these characteristics exceed the anonymous audience measurement that the claimed exemption relies on.

Separately: the analytics beacon static.cloudflareinsights.com fires at +97 ms. Cloudflare’s documentation lists it as the source of security cookies (cf_clearance, __cf_bm); the Cloudflare Web Analytics service is not covered by a separate declaration.

Both external calls — the Cloudflare beacon (+97 ms) and the Eulerian script (+113 ms) — occur right at the start of the session, and the data-transmitting Eulerian beacon fires at +795 ms. The session state at this point is no consent: not a single cookie has been set for the entire session, and no consent-decision cookie is present.

What cannot be claimed from the measurement

The measurement covers one page and one state — before consent. Piano Analytics, also declared in the policy, did not fire in this session — only Eulerian was observed. Identifying Eulerian rests on the EWS server signature, the parameter scheme, and the script name. The CNIL exemption cited by the policy may indeed have been granted for audience measurement; the subject of observation here is not the revocation of that exemption, but a mismatch between the parameters actually transmitted (screen resolution, article title) and the claimed anonymous visit statistics. Assessing whether the exemption legally applies to such a dataset is a matter for the competent authority. Server-side processing is not visible in a browser-based measurement.

Conclusion

economie.gouv.fr discloses its audience-measurement tools more honestly than many government sites — Eulerian and Piano Analytics are named directly, with a dedicated PDF on cookies. But the claimed anonymity of the audience-measurement processing is at odds with the facts: the Eulerian beacon, deployed via the CNAME subdomain nmmt.economie.gouv.fr, transmits the title of the specific article being read, its identifier, and screen resolution — a fingerprinting parameter — with no consent given, and the site’s own document attributes interaction-with-advertising-elements collection and 13-month retention to Eulerian. In addition, the Cloudflare analytics beacon is not covered by the declaration, which names Cloudflare only as a security cookie. For a ministry portal, the gap between the claimed anonymous statistics and the fingerprinting parameters actually transmitted constitutes a transparency violation. Remedy: bring the description of audience-measurement processing into line with the fields actually transmitted, disclose Eulerian’s CNAME placement and the Cloudflare analytics service, and confirm that the dataset meets the conditions of the claimed exemption.

Evidence
Original (audit)
HAR file: fr/economie-gouv-fr-2026-07-02.har
SHA-256: 4c7f40a43931300d9e83ab987f929dc33d98083337168980ddadc7fe5fd21d43
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Commission nationale de l'informatique et des libertés (CNIL)cnil.fr

To: Commission nationale de l'informatique et des libertés (CNIL)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website economie.gouv.fr.

2. Circumstances
I visited the website economie.gouv.fr and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 2 July 2026 (open methodology, reproducible measurements) documents the following indications:

1) The policy characterizes audience-measurement processing as anonymous visit statistics (page views and visit counts) and relies on a CNIL exemption. At +795 ms, with no consent given, the Eulerian beacon (nmmt.economie.gouv.fr, Server EWS) transmits the full title of the article being read, content_id=3240361, and a screen resolution parameter ss=1920x1080. Screen resolution is a fingerprinting parameter; the site's own document (cookies-internes-necessaires) describes Eulerian as collecting data on the device, browser, and interactions with advertising elements, with a 13-month retention period. This exceeds the anonymous audience measurement covered by the claimed exemption.

2) The analytics beacon static.cloudflareinsights.com/beacon.min.js fires at +97 ms. The site's documentation declares Cloudflare only in connection with security cookies (cf_clearance, __cf_bm); the Cloudflare Web Analytics service is not covered by a separate declaration. In addition, Eulerian's placement on the first-party subdomain nmmt.economie.gouv.fr (via CNAME) is not disclosed in the policy as such.

Full technical documentation is published at: https://gdpru.eu/en/audits/fr-economie-gouv-fr/

3. Provisions violated
GDPR Art. 5(1)(a) — transparency and the scope of the consent exemption; GDPR Art. 13(1)(e) — disclosure of recipients

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]