Technical audit · 2026-05-29

e-epites.hu

Electronic Construction Portal of Hungary

The Hungarian construction administration portal (É-Építés, operated by Lechner Tudásközpont) — 174 requests, 6 domains. A Drupal 11 site with a cookiesjsr consent manager. But before this manager manages to initialize, Google Tag Manager, Google Analytics, and Hotjar (session recording) have already loaded. GA is declared in the policy; Hotjar is not declared at all. Tracker scripts fire before the consent manager, transmitting the IP address to Google (USA), Hotjar (Malta/EU), and Cloudflare (USA).

Timeline of the leak

+0 ms · portal load
Markup, scripts, and images — served from the first-party domain www.e-epites.hu (Apache, Drupal 11, PHP 8.3).
+174 ms · CDN libraries prior to consent
progress-tracker from cdn.jsdelivr.net and select2 (CSS) from cdnjs.cloudflare.com. The visitor's IP address is transmitted to jsDelivr and Cloudflare.
+273…+390 ms · GTM and Google Analytics prior to consent
The Google Tag Manager container (gtm.js, GTM-NT38F4N), followed by gtag.js for GA4 (G-G2LYMG4368). The visitor's IP address is transmitted to Google (USA).
+391…+520 ms · Hotjar prior to consent
static.hotjar.com (hotjar-3725915.js) and script.hotjar.com (modules) — a session-recording and heatmap service. The visitor's IP address is transmitted to Hotjar (Malta/EU). Not named in the policy.
+597…+687 ms · consent manager loads after the trackers
Only now does the cookiesjsr consent manager connect (js-cookie and cookiesjsr itself, from jsDelivr). GTM, GA4, and Hotjar have already loaded by this point — the manager did not manage to hold them back.
tracking profile
The site runs both Google Analytics (declared) and Hotjar (undeclared) simultaneously — statistics plus session recording. No separate GA /g/collect call appears within the capture window; the tracker scripts are, however, loaded.

Declared versus actual

The portal's cookie table — the Drupal session cookie (SSESS), the cookiesjsr consent manager's own cookie, Google Tag Manager (for loading Google Analytics), and Google Analytics cookies (statistics, _gali, user distinction) — заявлен
Operator — Lechner Tudásközpont Nonprofit Kft.; the site has an adatkezelési tájékoztató and the cookiesjsr consent manager — заявлен
+ Hotjar (static.hotjar.com, script.hotjar.com) — third-party recipient of IP address (Malta/EU), session recording, prior to consent, not named in the policy — не заявлен
+ jsDelivr (cdn.jsdelivr.net) — third-party recipient of IP address, prior to consent, not named in the policy — не заявлен
+ cdnjs / Cloudflare (cdnjs.cloudflare.com) — third-party recipient of IP address from the USA, prior to consent, not named in the policy — не заявлен

Transfer timings

+174 ms cdn.jsdelivr.net

progress-tracker, js-cookie, cookiesjsr. Operated by Prospect One, EU.

+174 ms cdnjs.cloudflare.com

select2 (css+js). Cloudflare, USA.

+273 ms www.googletagmanager.com

gtm.js (GTM-NT38F4N) and gtag.js (GA4 G-G2LYMG4368). Google, USA.

+391 ms static.hotjar.com

Hotjar id 3725915 — session recording, heatmaps. Hotjar, Malta/EU.

+520 ms script.hotjar.com

Hotjar modules. Not named in the policy.

Detected trackers

Indicators of GDPR non-compliance

Context

e-epites.hu is the official Hungarian construction administration portal (É-Építés Portál), part of the National Construction Register (Országos Építésügyi Nyilvántartás). Professional content is prepared by the responsible ministry, while operation is carried out by Lechner Tudásközpont Nonprofit Kft., a state-owned non-profit enterprise. The portal provides access to building permit information, an electronic construction log, and related registry services (some of which require registration). The site is built on Drupal 11 (Apache, PHP 8.3). Capture: 174 requests, 6 domains, recorded in a clean browser.

Google (USA) — the visitor’s IP address via Google Tag Manager and GA4. Hotjar (Malta/EU) — the visitor’s IP address via session-recording scripts. Cloudflare (USA) — the visitor’s IP address via select2 from cdnjs. jsDelivr (EU) — the visitor’s IP address via library loading.

Declared versus Actual

The portal has done something simpler sites have not: it has a genuine consent manager — the open-source cookiesjsr — and its cookie table honestly lists its own session cookie, the consent manager’s own cookie, and Google Analytics loaded via Google Tag Manager. That is, the intent to manage consent is evident, and analytics is disclosed.

The capture, however, reveals two problems. The first is the loading order. The cookiesjsr consent manager connects only at +597–687 ms, whereas Google Tag Manager loads at +273 ms, GA4 at +390 ms, and Hotjar at +391–520 ms. In other words, tracker scripts connect before the mechanism intended to govern them has initialized; by the time the consent manager starts, calls to Google and Hotjar — and with them, the visitor’s IP address — have already been sent to their providers.

The second, and more serious, issue is Hotjar. This is not a statistics counter but a service for recording user sessions and building heatmaps: it captures cursor movements, clicks, scrolling, and is capable of capturing interaction with page elements. Hotjar is not mentioned anywhere in the portal’s cookie table, even though Google Analytics is named there specifically. The portal thus runs an undeclared behavioral tracker, which loads prior to consent. Additionally, the visitor’s IP address is transmitted to Cloudflare (select2 from cdnjs) and to jsDelivr during library loading — these CDNs are likewise not named in the policy.

All external calls occur at +174–687 ms. The key point is that the trackers (GTM at +273 ms, GA4 at +390 ms, Hotjar at +391–520 ms) load before the cookiesjsr consent manager (+597 ms). The consent mechanism could not, physically, have held back what had already connected before it. No valid consent is recorded during the session (Set-Cookie is zero).

What Cannot Be Asserted from This Capture

The GTM, GA4, and Hotjar scripts are loaded in the capture — this alone has already transmitted the IP address to their providers — but there is no separate GA /g/collect call within the capture window, and the HAR cannot establish whether Hotjar began actual session recording prior to consent; this depends on the consent-mode configuration, which is not visible in a browser-based capture. The fact of IP address transmission upon script loading occurred in any case. Hotjar (Hotjar Ltd, Malta; parent company Contentsquare, France) is an EU-based recipient, so the question of cross-border transfer to third countries is weaker in its case; the principal concern is non-disclosure and behavioral recording prior to consent. Google and Cloudflare are US companies. Google and Cloudflare may use edge nodes within the EU; the conclusion drawn therefore concerns the recipient’s corporate affiliation, not the location of the node. The capture was recorded in a lean form without response bodies, so the visual state of the banner cannot be reconstructed from it; the conclusion regarding order rests on the timing of the calls. Server-side processing is not visible in a browser-based capture.

Conclusion

Hungary’s construction administration portal is built more carefully than average: it has a cookiesjsr consent manager, and Google Analytics is declared in the cookie table. Nevertheless, the implementation fails in two places at once. First, the tracker scripts — Google Tag Manager, GA4, and Hotjar — load before the consent manager itself initializes, so the visitor’s IP address has already been sent to their providers prior to consent. Second, Hotjar — a session-recording service — is not disclosed in the policy at all, despite being a more sensitive behavioral tracker than the declared statistics tool. The transfer of the IP address to an undisclosed recipient (Hotjar), as well as to Google and Cloudflare, prior to actual consent, despite the presence of a consent mechanism that does not function effectively, constitutes a violation of the requirements concerning disclosure of recipients and the proper sequencing of consent. The remedy is within the operator’s control: load GTM, GA4, and Hotjar only after the consent manager initializes and only with consent given; add Hotjar (and the CDNs in use) to the cookie table as recipients; and, where possible, host the libraries locally.

Evidence
Original (audit)
HAR file: hu/e-epites-hu-2026-05-29.har
SHA-256: e4409a1fcdd4c2ef1d3893ff26e712af3bb38158be0a289a3db9cfe21afe800a
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Hungarian National Authority for Data Protection (NAIH)file a complaint online →

To: Hungarian National Authority for Data Protection (NAIH)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website e-epites.hu.

2. Circumstances
I visited the website e-epites.hu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) Prior to consent, Hotjar loads (static.hotjar.com at +391 ms and script.hotjar.com at +520 ms — a session-recording and heatmap service), along with Google Tag Manager and GA4 (gtm.js at +273 ms, gtag.js at +390 ms), as well as libraries from jsDelivr (progress-tracker, js-cookie, cookiesjsr) and select2 from cdnjs.cloudflare.com. All of these transmit the visitor's IP address: to Hotjar (Malta/EU), to Google (USA), and to Cloudflare (USA). The portal's cookie table declares only the session cookie, the consent manager's own cookiesjsr cookie, and Google Analytics via GTM; it does not name Hotjar as a recipient at all.

2) The site has a consent manager, cookiesjsr, installed, but it loads at +597–687 ms — already after Google Tag Manager (+273 ms), GA4 (+390 ms), and Hotjar (+391–520 ms). In other words, tracker scripts connect before the mechanism intended to govern them has initialized. Set-Cookie across the entire session is zero; no user choice is recorded, but the calls to the trackers and the transfer of the IP address to their providers have already taken place.

Full technical documentation is published at: https://gdpru.eu/en/audits/hu-e-epites-hu/

3. Provisions violated
GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and cross-border transfer; ePrivacy (Hungarian implementation) — trackers loading before the consent manager

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]