Technical audit · 2026-07-02

interieur.gouv.fr

French Ministry of the Interior

France's Ministry of the Interior — 53 requests, one external domain. The policy states that cookies are set only after consent and that data is not transferred outside the EU, without naming a specific audience-measurement tool. In the measurement, Cloudflare Web Analytics (beacon.min.js plus a RUM request) runs before consent; the load transmits the visitor's IP address to Cloudflare Inc — a US company not named in the policy.

Timeline of the leak

+0 ms · portal load
Content and resources served from www.interieur.gouv.fr.
+219 ms · analytics beacon
static.cloudflareinsights.com/beacon.min.js — the Cloudflare Web Analytics script loads. The visitor's IP address goes to Cloudflare Inc (USA).
RUM request
POST to /cdn-cgi/rum — transmission of Cloudflare Real User Monitoring data (proxied through the proprietary domain, processed by Cloudflare).

Declared versus actual

Audience measurement mentioned in general terms ('mesurer sa fréquentation'); the specific tool is not named — declared
'Les cookies ne sont déposés que si vous les acceptez' — cookies only after consent — declared
'Ces données ne font pas l'objet d'un transfert en dehors du territoire de l'UE' — stated directly — declared
+ Cloudflare Web Analytics (static.cloudflareinsights.com) — the actual analytics service, not named in the policy; provider Cloudflare Inc is a US company — not declared

Transfer timings

+219 ms static.cloudflareinsights.com

Cloudflare Web Analytics beacon.min.js. Cloudflare Inc, USA. Not named in the policy.

Detected trackers

Indicators of GDPR non-compliance

Context

interieur.gouv.fr is the official website of France’s Ministry of the Interior (Ministère de l’Intérieur), responsible for the police, gendarmerie, civil security, and elections. Controller: the ministry’s délégué à l’Information et à la communication. The privacy policy was supplied and checked against the version currently in effect on the site. Measurement: 53 requests, one external domain, captured on a clean browser.

Cloudflare Inc (USA) — the visitor’s IP address, via loading Cloudflare’s analytics beacon.min.js.

Declared versus actual

The policy’s cookie section makes two explicit promises. First: cookies are set only if accepted (“Les cookies ne sont déposés que si vous les acceptez”). Second, in the data section: no transfer outside the territory of the European Union occurs (“Ces données ne font pas l’objet d’un transfert en dehors du territoire de l’Union européenne”). Audience measurement is mentioned in general terms — “mesurer sa fréquentation” — but the specific measurement tool is not named in the policy.

The measurement shows an unnamed tool at work. At +219 ms, beacon.min.js loads from the domain static.cloudflareinsights.com — this is Cloudflare Web Analytics, a service of Cloudflare Inc (USA). Real User Monitoring data is then sent via a POST request to /cdn-cgi/rum. The first promise, on cookies, is formally upheld: Cloudflare Web Analytics operates without cookies, and not a single cookie is set for the entire session. However, loading beacon.min.js itself transmits the visitor’s IP address to Cloudflare — a US company — which contradicts the second promise of no transfer outside the EU. Moreover, the analytics service actually in use is not named in the policy: it states only the general “mesurer sa fréquentation,” with no identification of the tool or its provider.

Cloudflare’s analytics beacon loads at +219 ms, right at the start of the session, before any user choice. Since the service uses no cookies, the literal condition of “cookies only after consent” is not violated — but data transmission to an American recipient occurs regardless of consent.

What cannot be claimed from the measurement

Cloudflare Web Analytics uses no cookies, so there is no violation of the cookie condition in the measurement; the subject of the discrepancy is the non-disclosure of the actual tool and the claim of no transfer outside the EU. Cloudflare Inc is a US company; at the same time, Cloudflare’s infrastructure makes wide use of edge nodes within the EU, so the conclusion is drawn based on the recipient’s affiliation (an American company), not the physical location of the specific processing node. The full contents of the RUM request cannot be fully reconstructed from the lightweight capture. Server-side processing is not visible in a browser-based measurement.

Conclusion

The Ministry of the Interior’s policy promises that cookies are set only after consent and that data does not leave the EU, without naming the specific audience-measurement tool. In the measurement, Cloudflare Web Analytics is at work — a service of the American company Cloudflare Inc: its beacon loads before consent and transmits the visitor’s IP address to Cloudflare. The cookie condition is formally upheld, since the service is cookieless, but the actual tool is not disclosed in the policy, and the promise of no transfer outside the EU is contradicted by the data transfer to a US recipient. For the website of a core security-sector ministry, the non-disclosure of the actual analytics service, combined with the discrepancy from the no-transfer-outside-the-EU claim, constitutes a violation of transparency requirements and cross-border transfer rules. Remedy: name the actual audience-measurement tool and its provider in the policy, bring the no-transfer-outside-the-EU claim into line with reality (or host the analytics on EU-based infrastructure with no American recipient involved), and include the service in the consent mechanism.

Evidence
Original (audit)
HAR file: fr/interieur-gouv-fr-2026-07-02.har
SHA-256: 0c782052c523f1bdc031bbbcf3d433fcfbe6beb8956c75f4c4fb0cca6146a45c
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Commission nationale de l'informatique et des libertés (CNIL)cnil.fr

To: Commission nationale de l'informatique et des libertés (CNIL)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website interieur.gouv.fr.

2. Circumstances
I visited the website interieur.gouv.fr and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 2 July 2026 (open methodology, reproducible measurements) documents the following indications:

1) The policy mentions audience measurement in general terms ('mesurer sa fréquentation') and names no specific tool. In the measurement, Cloudflare Web Analytics is at work: beacon.min.js loads from static.cloudflareinsights.com at +219 ms, with RUM data sent via a POST request to /cdn-cgi/rum. The actual analytics service and its provider (Cloudflare Inc) are not disclosed in the policy.

2) The policy states directly: 'Ces données ne font pas l'objet d'un transfert en dehors du territoire de l'Union européenne.' Loading beacon.min.js from static.cloudflareinsights.com transmits the visitor's IP address to Cloudflare Inc — a US company — before consent. The absolute claim of no transfer outside the EU is contradicted by the actual data transfer to a recipient in the USA.

Full technical documentation is published at: https://gdpru.eu/en/audits/fr-interieur-gouv-fr/

3. Provisions violated
GDPR Art. 13(1)(e) — disclosure of recipients and the tool; GDPR Art. 44 (Chapter V) + Art. 5(1)(a) — cross-border transfer and transparency

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]