Dunakeszi Hűtőház Kft. (dkh.hu), a cold storage facility — 57 requests, 10 domains. A private commercial company; a brochure-style WordPress site. The site has no published privacy policy whatsoever — only a notice bar with a single 'accept' button. Prior to any consent, the visitor's IP address is transmitted to Google via several services at once: Google Analytics (deprecated Universal Analytics and GA4), an embedded Google Maps map, and Google Fonts. All recipients are undisclosed.
Timeline of the leak
Declared versus actual
Transfer timings
Google Fonts CSS (Montserrat). Google, USA.
gtag.js — containers UA-9217572-10 and G-949F1D20QC. Google, USA.
Google Maps embed. Google, USA.
analytics.js (classic Universal Analytics). Google, USA.
GA4 /g/collect — page_view event. EU regional endpoint.
Google Maps API (×12: geometry, search, places, static). Google, USA.
Detected trackers
- Google Analytics — two instances: Universal Analytics (UA-9217572-10, deprecated) and GA4 (G-949F1D20QC) — prior to consent, not named in the policy
- Google Maps (maps.googleapis.com, maps.gstatic.com, google.com/maps/embed) — prior to consent, not named in the policy
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com — Montserrat) — prior to consent, not named in the policy
Indicators of GDPR non-compliance
- GDPR Art. 13 + Art. 13(1)(e) + Chapter V — absence of disclosure, recipients, and cross-border transferThe site has no published privacy policy or cookie policy of any kind — only a notice bar with a single 'Elfogadom' button. Meanwhile, prior to any consent, Google Analytics loads in two variants (the deprecated Universal Analytics UA-9217572-10 and GA4 G-949F1D20QC, with a page_view event to region1.google-analytics.com), an embedded Google Maps map (maps.googleapis.com ×12, maps.gstatic.com, google.com/maps/embed), and Google Fonts (Montserrat). All of these transmit the visitor's IP address to Google (USA). No recipient is disclosed, because there is nowhere for such disclosure to appear: the site contains no transparency information regarding processing whatsoever.
- ePrivacy (Hungarian implementation) — invalid consent and trackers prior to consentThe sole consent element is a notice stating 'by continuing to use the site, we consider that you consent,' with a single 'Elfogadom' button, with no rejection option and no settings. Google Analytics, Google Maps, and Google Fonts fire at +4245–6230 ms, prior to any interaction with the notice. Set-Cookie across the entire session is zero; there is no valid consent, yet the transfer of the IP address to Google has already taken place.
Context
dkh.hu is the website of Dunakeszi Hűtőház Kft. (Dunakeszi Cold Storage Facility), a private commercial enterprise providing low-temperature storage, freezing, and related logistics services for the food industry. The data controller is Dunakeszi Hűtőház Kft. The site is a brochure-style WordPress build (sections for “About Us,” “Services,” “Gallery,” “Contacts,” and a directions map); hosting, based on the server header, is Aruba. Capture: 57 requests, 10 domains, recorded in a clean browser.
Direct Recipients of Data (prior to consent)
Google (USA) — the visitor’s IP address, via several services at once: Google Analytics (Universal Analytics and GA4), the embedded Google Maps map, and Google Fonts. There are no other third-party recipients in the capture.
Declared versus Actual
The distinctive feature of this case is that there is effectively nothing declared at all. The site has no published privacy policy or cookie policy: there is no “Adatvédelem,” “Süti tájékoztató,” or “Adatkezelési tájékoztató” link in the navigation or footer. The sole privacy-related element is a bar at the bottom of the page stating that by continuing to use the site, the visitor expresses consent, with a single “Elfogadom” button. There is no rejection option, no settings, and no description of the services in use.
The capture shows that, meanwhile, the site actively communicates with Google. Prior to any action by the visitor, Google Fonts (the Montserrat font) loads, along with two Google Tag Manager containers and Google Analytics in two variants at once: the deprecated Universal Analytics (identifier UA-9217572-10, the classic analytics.js) and the current GA4 (G-949F1D20QC), which sends a page_view event to region1.google-analytics.com. In addition to analytics, the contacts page embeds a Google Maps map — approximately twelve calls to maps.googleapis.com, plus maps.gstatic.com and google.com/maps/embed. All of these calls transmit the visitor’s IP address to Google (USA).
The discrepancy here is thus absolute: the site discloses no recipient, because there is nowhere for such disclosure to appear — the site contains no transparency information regarding processing whatsoever, and its sole consent mechanism is invalid. Meanwhile, the visitor’s data actually leaves for Google on every visit.
Timing Relative to Consent
External calls occur at +4245–6230 ms. The timing is late (the page takes several seconds to fully execute), but this changes nothing in principle: all calls occur before any interaction with the cookie notice, and the notice itself does not hold them back. No valid consent was given during the session (Set-Cookie is zero).
What Cannot Be Asserted from This Capture
The identifier UA-9217572-10 belongs to Universal Analytics, processing for which Google has discontinued; the container and analytics.js nevertheless still load, so the capture cannot establish that data within UA continues to be processed on Google’s side — but the fact of the IP address being transmitted to Google upon loading these resources did occur. GA4 communicates with an EU regional endpoint (region1) and sends a page_view event. The embedded Google Maps map transmits the visitor’s IP address and the fact of the location being viewed to Google; the map key belongs to the site. Google may use edge nodes within the EU; the conclusion drawn therefore concerns the recipient’s corporate affiliation (Google, USA), not the physical location of the node. The server: aruba-proxy header indicates Aruba (EU) hosting. As of the date of review, no policy was found on the site; if one exists somewhere without a link from the site, it is not visible in the capture or on the pages reviewed. Server-side processing is not visible in a browser-based capture.
Conclusion
The website of the Dunakeszi cold storage facility, prior to any valid consent, transmits the visitor’s IP address to Google via several services at once: Google Analytics (in two variants — the deprecated Universal Analytics and GA4), an embedded Google Maps map, and Google Fonts. Meanwhile, the site has no published privacy policy whatsoever, and its sole consent mechanism — a bar stating “by continuing to use the site, we consider that you consent,” with a single “accept” button — is invalid under the GDPR, since it provides neither a free nor an unambiguous choice and discloses no recipients. The transfer of the visitor’s IP address to a third-party recipient in the USA by default, on every visit, without disclosure and outside any valid consent mechanism, constitutes a violation of the requirements concerning transparency, disclosure of recipients, and cross-border transfer. Remediation requires basic groundwork: publish a privacy policy listing the Google services in use, install a proper consent banner with an equally prominent rejection option, host the fonts locally, and connect Google Analytics and the map only after consent is given; the deprecated Universal Analytics identifier should also be removed.
5a7de4239c48b39e6451deb068eab55229bc378eb122395db96ef8af230eb817Where to file: Hungarian National Authority for Data Protection (NAIH) — file a complaint online →
To: Hungarian National Authority for Data Protection (NAIH) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website dkh.hu. 2. Circumstances I visited the website dkh.hu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site has no published privacy policy or cookie policy of any kind — only a notice bar with a single 'Elfogadom' button. Meanwhile, prior to any consent, Google Analytics loads in two variants (the deprecated Universal Analytics UA-9217572-10 and GA4 G-949F1D20QC, with a page_view event to region1.google-analytics.com), an embedded Google Maps map (maps.googleapis.com ×12, maps.gstatic.com, google.com/maps/embed), and Google Fonts (Montserrat). All of these transmit the visitor's IP address to Google (USA). No recipient is disclosed, because there is nowhere for such disclosure to appear: the site contains no transparency information regarding processing whatsoever. 2) The sole consent element is a notice stating 'by continuing to use the site, we consider that you consent,' with a single 'Elfogadom' button, with no rejection option and no settings. Google Analytics, Google Maps, and Google Fonts fire at +4245–6230 ms, prior to any interaction with the notice. Set-Cookie across the entire session is zero; there is no valid consent, yet the transfer of the IP address to Google has already taken place. Full technical documentation is published at: https://gdpru.eu/en/audits/hu-dkh-hu/ 3. Provisions violated GDPR Art. 13 + Art. 13(1)(e) + Chapter V — absence of disclosure, recipients, and cross-border transfer; ePrivacy (Hungarian implementation) — invalid consent and trackers prior to consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]