Technical audit · 2026-05-29

dkh.hu

Dunakeszi Cold Storage Facility (Hungary)

Dunakeszi Hűtőház Kft. (dkh.hu), a cold storage facility — 57 requests, 10 domains. A private commercial company; a brochure-style WordPress site. The site has no published privacy policy whatsoever — only a notice bar with a single 'accept' button. Prior to any consent, the visitor's IP address is transmitted to Google via several services at once: Google Analytics (deprecated Universal Analytics and GA4), an embedded Google Maps map, and Google Fonts. All recipients are undisclosed.

Timeline of the leak

+0 ms · site load
Markup, scripts, and images — served from the first-party domain (WordPress; hosting appears to be Aruba, based on the server: aruba-proxy header). No first-party cookies are set in the capture.
+4245…+4249 ms · Google Fonts and GTM prior to consent
Google Fonts CSS (fonts.googleapis.com, Montserrat font) and the gtag.js / Google Tag Manager container. The visitor's IP address and Referer header are transmitted to Google (USA).
+5058…+5204 ms · Google Analytics prior to consent
A second gtag.js container, the classic analytics.js, and a GA4 page_view event to region1.google-analytics.com. Two identifiers operate simultaneously: the deprecated Universal Analytics (UA-9217572-10) and GA4 (G-949F1D20QC).
+4780…+6230 ms · Google Maps prior to consent
Embedded location map: google.com/maps/embed, maps.gstatic.com, and maps.googleapis.com (approximately 12 calls — map API, geometry, search, static image). The visitor's IP address is transmitted to Google (USA).
cookie notice invalid as consent
The sole element is a bar stating 'by continuing to use the site, we consider that you consent,' with an 'Elfogadom' button. There is no rejection option, no settings, and no link to a policy. External calls occur before and independently of any interaction with it.
sole recipient — Google
All external calls are directed to Google services (Analytics, Maps, Fonts). Facebook, other advertising pixels, and session recording are absent from the capture.

Declared versus actual

Cookie notice — a single line stating 'by continuing to use the site, we consider that you consent,' and a single 'Elfogadom' button — заявлен
No published privacy policy or cookie policy is present on the site as of the date of review; there are no 'Adatvédelem' / 'Süti tájékoztató' links in the navigation or footer — заявлен
+ Google Analytics (Universal Analytics UA-9217572-10 and GA4 G-949F1D20QC) — third-party recipient of IP address from the USA, prior to consent, not named — не заявлен
+ Google Maps (maps.googleapis.com, maps.gstatic.com, google.com/maps/embed) — third-party recipient of IP address from the USA, prior to consent, not named — не заявлен
+ Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — third-party recipient of IP address from the USA, prior to consent, not named — не заявлен

Transfer timings

+4245 ms fonts.googleapis.com

Google Fonts CSS (Montserrat). Google, USA.

+4249 ms www.googletagmanager.com

gtag.js — containers UA-9217572-10 and G-949F1D20QC. Google, USA.

+4780 ms www.google.com

Google Maps embed. Google, USA.

+5065 ms www.google-analytics.com

analytics.js (classic Universal Analytics). Google, USA.

+5204 ms region1.google-analytics.com

GA4 /g/collect — page_view event. EU regional endpoint.

+5768 ms maps.googleapis.com

Google Maps API (×12: geometry, search, places, static). Google, USA.

Detected trackers

Indicators of GDPR non-compliance

Context

dkh.hu is the website of Dunakeszi Hűtőház Kft. (Dunakeszi Cold Storage Facility), a private commercial enterprise providing low-temperature storage, freezing, and related logistics services for the food industry. The data controller is Dunakeszi Hűtőház Kft. The site is a brochure-style WordPress build (sections for “About Us,” “Services,” “Gallery,” “Contacts,” and a directions map); hosting, based on the server header, is Aruba. Capture: 57 requests, 10 domains, recorded in a clean browser.

Google (USA) — the visitor’s IP address, via several services at once: Google Analytics (Universal Analytics and GA4), the embedded Google Maps map, and Google Fonts. There are no other third-party recipients in the capture.

Declared versus Actual

The distinctive feature of this case is that there is effectively nothing declared at all. The site has no published privacy policy or cookie policy: there is no “Adatvédelem,” “Süti tájékoztató,” or “Adatkezelési tájékoztató” link in the navigation or footer. The sole privacy-related element is a bar at the bottom of the page stating that by continuing to use the site, the visitor expresses consent, with a single “Elfogadom” button. There is no rejection option, no settings, and no description of the services in use.

The capture shows that, meanwhile, the site actively communicates with Google. Prior to any action by the visitor, Google Fonts (the Montserrat font) loads, along with two Google Tag Manager containers and Google Analytics in two variants at once: the deprecated Universal Analytics (identifier UA-9217572-10, the classic analytics.js) and the current GA4 (G-949F1D20QC), which sends a page_view event to region1.google-analytics.com. In addition to analytics, the contacts page embeds a Google Maps map — approximately twelve calls to maps.googleapis.com, plus maps.gstatic.com and google.com/maps/embed. All of these calls transmit the visitor’s IP address to Google (USA).

The discrepancy here is thus absolute: the site discloses no recipient, because there is nowhere for such disclosure to appear — the site contains no transparency information regarding processing whatsoever, and its sole consent mechanism is invalid. Meanwhile, the visitor’s data actually leaves for Google on every visit.

External calls occur at +4245–6230 ms. The timing is late (the page takes several seconds to fully execute), but this changes nothing in principle: all calls occur before any interaction with the cookie notice, and the notice itself does not hold them back. No valid consent was given during the session (Set-Cookie is zero).

What Cannot Be Asserted from This Capture

The identifier UA-9217572-10 belongs to Universal Analytics, processing for which Google has discontinued; the container and analytics.js nevertheless still load, so the capture cannot establish that data within UA continues to be processed on Google’s side — but the fact of the IP address being transmitted to Google upon loading these resources did occur. GA4 communicates with an EU regional endpoint (region1) and sends a page_view event. The embedded Google Maps map transmits the visitor’s IP address and the fact of the location being viewed to Google; the map key belongs to the site. Google may use edge nodes within the EU; the conclusion drawn therefore concerns the recipient’s corporate affiliation (Google, USA), not the physical location of the node. The server: aruba-proxy header indicates Aruba (EU) hosting. As of the date of review, no policy was found on the site; if one exists somewhere without a link from the site, it is not visible in the capture or on the pages reviewed. Server-side processing is not visible in a browser-based capture.

Conclusion

The website of the Dunakeszi cold storage facility, prior to any valid consent, transmits the visitor’s IP address to Google via several services at once: Google Analytics (in two variants — the deprecated Universal Analytics and GA4), an embedded Google Maps map, and Google Fonts. Meanwhile, the site has no published privacy policy whatsoever, and its sole consent mechanism — a bar stating “by continuing to use the site, we consider that you consent,” with a single “accept” button — is invalid under the GDPR, since it provides neither a free nor an unambiguous choice and discloses no recipients. The transfer of the visitor’s IP address to a third-party recipient in the USA by default, on every visit, without disclosure and outside any valid consent mechanism, constitutes a violation of the requirements concerning transparency, disclosure of recipients, and cross-border transfer. Remediation requires basic groundwork: publish a privacy policy listing the Google services in use, install a proper consent banner with an equally prominent rejection option, host the fonts locally, and connect Google Analytics and the map only after consent is given; the deprecated Universal Analytics identifier should also be removed.

Evidence
Original (audit)
HAR file: hu/dkh-hu-2026-05-29.har
SHA-256: 5a7de4239c48b39e6451deb068eab55229bc378eb122395db96ef8af230eb817
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Hungarian National Authority for Data Protection (NAIH)file a complaint online →

To: Hungarian National Authority for Data Protection (NAIH)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website dkh.hu.

2. Circumstances
I visited the website dkh.hu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site has no published privacy policy or cookie policy of any kind — only a notice bar with a single 'Elfogadom' button. Meanwhile, prior to any consent, Google Analytics loads in two variants (the deprecated Universal Analytics UA-9217572-10 and GA4 G-949F1D20QC, with a page_view event to region1.google-analytics.com), an embedded Google Maps map (maps.googleapis.com ×12, maps.gstatic.com, google.com/maps/embed), and Google Fonts (Montserrat). All of these transmit the visitor's IP address to Google (USA). No recipient is disclosed, because there is nowhere for such disclosure to appear: the site contains no transparency information regarding processing whatsoever.

2) The sole consent element is a notice stating 'by continuing to use the site, we consider that you consent,' with a single 'Elfogadom' button, with no rejection option and no settings. Google Analytics, Google Maps, and Google Fonts fire at +4245–6230 ms, prior to any interaction with the notice. Set-Cookie across the entire session is zero; there is no valid consent, yet the transfer of the IP address to Google has already taken place.

Full technical documentation is published at: https://gdpru.eu/en/audits/hu-dkh-hu/

3. Provisions violated
GDPR Art. 13 + Art. 13(1)(e) + Chapter V — absence of disclosure, recipients, and cross-border transfer; ePrivacy (Hungarian implementation) — invalid consent and trackers prior to consent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]