Policy changed — see what exactly · 2026-07-11 →
The Supreme Court of Hungary (Kúria) — 11 requests, a single domain. The capture was recorded on the portal's entry welcome page: all resources, including fonts, are hosted locally on the first-party domain, with no external calls, trackers, or cookies whatsoever. No violations have been recorded.
Timeline of the leak
Declared versus actual
Context
kuria-birosag.hu is the website of the Kúria, the Supreme Court of Hungary, the country’s highest judicial instance. The data controller is the Kúria. The site is built on Drupal (the kuria_smg theme). The capture was recorded on the portal’s entry welcome page: entry at /welcome, redirecting to /hu/welcome. Capture: 11 requests, a single domain, recorded in a clean browser.
Declared versus Actual
The capture reveals a fully self-sufficient entry page. All resources — markup, stylesheets, scripts, images, and fonts — load from the first-party domain kuria-birosag.hu. Fonts (Adobe Garamond Pro, Bodoni MT Condensed) are served locally from the theme directory, with no calls to external font services. There are no external domains present in the capture whatsoever: no analytics, no Google, no maps, no advertising pixels, no session recording. No cookies are set (Set-Cookie is zero). HSTS with preload and X-Frame-Options SAMEORIGIN security headers are present.
The Kúria’s Cookie Policy declares the use of Google Analytics web analytics to measure portal traffic. On this particular entry page, Google Analytics does not fire — there are no calls to it in the capture. Accordingly, on the page covered, no discrepancy between “declared” and “actual” arises: the declared analytics does not activate here, and there are no third-party calls.
Timing Relative to Consent
All calls go to the first-party domain. There are no third-party resources on the entry page requiring consent; no cookies are set, and a consent banner is therefore unnecessary here. For the website of the highest judicial instance, this is the expected and correct behavior.
What Cannot Be Asserted from This Capture
The capture covers the portal’s entry welcome page, not its internal sections. The Kúria’s Cookie Policy declares the use of Google Analytics for traffic measurement — this analytics tool may activate on the main portal’s internal pages, which this capture does not cover. The behavior of the consent mechanism and of the declared analytics beyond the entry page cannot be assessed from this capture. Server-side processing is not visible in a browser-based capture.
Conclusion
The entry page of the Hungarian Supreme Court’s website demonstrates a configuration that is clean as captured: all resources, including fonts, are hosted locally on the first-party domain, there are no external calls whatsoever, and trackers and cookies are absent. The Google Analytics web analytics declared in the policy does not fire on this page. No violations have been recorded within the scope of this capture. The behavior of the main portal’s internal sections, where Google Analytics may activate under the policy, should be verified with a separate capture.
97bd0a8c863b9faa8315dffd511b7863fa4de0529883b0bfe9e5dc5331f705f3