The Hungarian construction administration portal (É-Építés, operated by Lechner Tudásközpont) — 174 requests, 6 domains. A Drupal 11 site with a cookiesjsr consent manager. But before this manager manages to initialize, Google Tag Manager, Google Analytics, and Hotjar (session recording) have already loaded. GA is declared in the policy; Hotjar is not declared at all. Tracker scripts fire before the consent manager, transmitting the IP address to Google (USA), Hotjar (Malta/EU), and Cloudflare (USA).
Timeline of the leak
Declared versus actual
Transfer timings
progress-tracker, js-cookie, cookiesjsr. Operated by Prospect One, EU.
select2 (css+js). Cloudflare, USA.
gtm.js (GTM-NT38F4N) and gtag.js (GA4 G-G2LYMG4368). Google, USA.
Hotjar id 3725915 — session recording, heatmaps. Hotjar, Malta/EU.
Hotjar modules. Not named in the policy.
Detected trackers
- Hotjar (static.hotjar.com, script.hotjar.com — id 3725915, session recording and heatmaps) — prior to consent, not named in the policy
- Google Analytics 4 via Google Tag Manager (GTM-NT38F4N, gtag G-G2LYMG4368) — loads before the consent manager initializes; declared in the policy
- jsDelivr (cdn.jsdelivr.net — progress-tracker, js-cookie, cookiesjsr) — prior to consent, not named in the policy
- cdnjs / Cloudflare (cdnjs.cloudflare.com — select2) — prior to consent, not named in the policy
Indicators of GDPR non-compliance
- GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and cross-border transferPrior to consent, Hotjar loads (static.hotjar.com at +391 ms and script.hotjar.com at +520 ms — a session-recording and heatmap service), along with Google Tag Manager and GA4 (gtm.js at +273 ms, gtag.js at +390 ms), as well as libraries from jsDelivr (progress-tracker, js-cookie, cookiesjsr) and select2 from cdnjs.cloudflare.com. All of these transmit the visitor's IP address: to Hotjar (Malta/EU), to Google (USA), and to Cloudflare (USA). The portal's cookie table declares only the session cookie, the consent manager's own cookiesjsr cookie, and Google Analytics via GTM; it does not name Hotjar as a recipient at all.
- ePrivacy (Hungarian implementation) — trackers loading before the consent managerThe site has a consent manager, cookiesjsr, installed, but it loads at +597–687 ms — already after Google Tag Manager (+273 ms), GA4 (+390 ms), and Hotjar (+391–520 ms). In other words, tracker scripts connect before the mechanism intended to govern them has initialized. Set-Cookie across the entire session is zero; no user choice is recorded, but the calls to the trackers and the transfer of the IP address to their providers have already taken place.
Context
e-epites.hu is the official Hungarian construction administration portal (É-Építés Portál), part of the National Construction Register (Országos Építésügyi Nyilvántartás). Professional content is prepared by the responsible ministry, while operation is carried out by Lechner Tudásközpont Nonprofit Kft., a state-owned non-profit enterprise. The portal provides access to building permit information, an electronic construction log, and related registry services (some of which require registration). The site is built on Drupal 11 (Apache, PHP 8.3). Capture: 174 requests, 6 domains, recorded in a clean browser.
Direct Recipients of Data (prior to consent)
Google (USA) — the visitor’s IP address via Google Tag Manager and GA4. Hotjar (Malta/EU) — the visitor’s IP address via session-recording scripts. Cloudflare (USA) — the visitor’s IP address via select2 from cdnjs. jsDelivr (EU) — the visitor’s IP address via library loading.
Declared versus Actual
The portal has done something simpler sites have not: it has a genuine consent manager — the open-source cookiesjsr — and its cookie table honestly lists its own session cookie, the consent manager’s own cookie, and Google Analytics loaded via Google Tag Manager. That is, the intent to manage consent is evident, and analytics is disclosed.
The capture, however, reveals two problems. The first is the loading order. The cookiesjsr consent manager connects only at +597–687 ms, whereas Google Tag Manager loads at +273 ms, GA4 at +390 ms, and Hotjar at +391–520 ms. In other words, tracker scripts connect before the mechanism intended to govern them has initialized; by the time the consent manager starts, calls to Google and Hotjar — and with them, the visitor’s IP address — have already been sent to their providers.
The second, and more serious, issue is Hotjar. This is not a statistics counter but a service for recording user sessions and building heatmaps: it captures cursor movements, clicks, scrolling, and is capable of capturing interaction with page elements. Hotjar is not mentioned anywhere in the portal’s cookie table, even though Google Analytics is named there specifically. The portal thus runs an undeclared behavioral tracker, which loads prior to consent. Additionally, the visitor’s IP address is transmitted to Cloudflare (select2 from cdnjs) and to jsDelivr during library loading — these CDNs are likewise not named in the policy.
Timing Relative to Consent
All external calls occur at +174–687 ms. The key point is that the trackers (GTM at +273 ms, GA4 at +390 ms, Hotjar at +391–520 ms) load before the cookiesjsr consent manager (+597 ms). The consent mechanism could not, physically, have held back what had already connected before it. No valid consent is recorded during the session (Set-Cookie is zero).
What Cannot Be Asserted from This Capture
The GTM, GA4, and Hotjar scripts are loaded in the capture — this alone has already transmitted the IP address to their providers — but there is no separate GA /g/collect call within the capture window, and the HAR cannot establish whether Hotjar began actual session recording prior to consent; this depends on the consent-mode configuration, which is not visible in a browser-based capture. The fact of IP address transmission upon script loading occurred in any case. Hotjar (Hotjar Ltd, Malta; parent company Contentsquare, France) is an EU-based recipient, so the question of cross-border transfer to third countries is weaker in its case; the principal concern is non-disclosure and behavioral recording prior to consent. Google and Cloudflare are US companies. Google and Cloudflare may use edge nodes within the EU; the conclusion drawn therefore concerns the recipient’s corporate affiliation, not the location of the node. The capture was recorded in a lean form without response bodies, so the visual state of the banner cannot be reconstructed from it; the conclusion regarding order rests on the timing of the calls. Server-side processing is not visible in a browser-based capture.
Conclusion
Hungary’s construction administration portal is built more carefully than average: it has a cookiesjsr consent manager, and Google Analytics is declared in the cookie table. Nevertheless, the implementation fails in two places at once. First, the tracker scripts — Google Tag Manager, GA4, and Hotjar — load before the consent manager itself initializes, so the visitor’s IP address has already been sent to their providers prior to consent. Second, Hotjar — a session-recording service — is not disclosed in the policy at all, despite being a more sensitive behavioral tracker than the declared statistics tool. The transfer of the IP address to an undisclosed recipient (Hotjar), as well as to Google and Cloudflare, prior to actual consent, despite the presence of a consent mechanism that does not function effectively, constitutes a violation of the requirements concerning disclosure of recipients and the proper sequencing of consent. The remedy is within the operator’s control: load GTM, GA4, and Hotjar only after the consent manager initializes and only with consent given; add Hotjar (and the CDNs in use) to the cookie table as recipients; and, where possible, host the libraries locally.
e4409a1fcdd4c2ef1d3893ff26e712af3bb38158be0a289a3db9cfe21afe800aWhere to file: Hungarian National Authority for Data Protection (NAIH) — file a complaint online →
To: Hungarian National Authority for Data Protection (NAIH) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website e-epites.hu. 2. Circumstances I visited the website e-epites.hu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) Prior to consent, Hotjar loads (static.hotjar.com at +391 ms and script.hotjar.com at +520 ms — a session-recording and heatmap service), along with Google Tag Manager and GA4 (gtm.js at +273 ms, gtag.js at +390 ms), as well as libraries from jsDelivr (progress-tracker, js-cookie, cookiesjsr) and select2 from cdnjs.cloudflare.com. All of these transmit the visitor's IP address: to Hotjar (Malta/EU), to Google (USA), and to Cloudflare (USA). The portal's cookie table declares only the session cookie, the consent manager's own cookiesjsr cookie, and Google Analytics via GTM; it does not name Hotjar as a recipient at all. 2) The site has a consent manager, cookiesjsr, installed, but it loads at +597–687 ms — already after Google Tag Manager (+273 ms), GA4 (+390 ms), and Hotjar (+391–520 ms). In other words, tracker scripts connect before the mechanism intended to govern them has initialized. Set-Cookie across the entire session is zero; no user choice is recorded, but the calls to the trackers and the transfer of the IP address to their providers have already taken place. Full technical documentation is published at: https://gdpru.eu/en/audits/hu-e-epites-hu/ 3. Provisions violated GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and cross-border transfer; ePrivacy (Hungarian implementation) — trackers loading before the consent manager 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]