Technical audit · 2026-05-29

kuria-birosag.hu

Supreme Court of Hungary

The Supreme Court of Hungary (Kúria) — 11 requests, a single domain. The capture was recorded on the portal's entry welcome page: all resources, including fonts, are hosted locally on the first-party domain, with no external calls, trackers, or cookies whatsoever. No violations have been recorded.

Timeline of the leak

+0 ms · portal load
Entry at /welcome, redirecting to /hu/welcome. Markup, stylesheets, scripts, fonts, and images — served from the first-party domain kuria-birosag.hu (Drupal, kuria_smg theme). HSTS with preload and X-Frame-Options SAMEORIGIN headers are present.
local fonts
Fonts (Adobe Garamond Pro, Bodoni MT Condensed, ttf) are served from the site's own domain, with no calls to external font services.
no consent banner required
There are no third-party resources on this page requiring consent; no cookies are set.
no third-party calls
Google, analytics, maps, advertising, font services, and session recording are absent from the capture. All calls are confined to the first-party domain.

Declared versus actual

Cookie Policy ('Tájékoztató a sütik használatáról') — cookies for functionality and statistics — declared
Google Analytics web analytics is declared, for measuring portal traffic — declared

Context

kuria-birosag.hu is the website of the Kúria, the Supreme Court of Hungary, the country’s highest judicial instance. The data controller is the Kúria. The site is built on Drupal (the kuria_smg theme). The capture was recorded on the portal’s entry welcome page: entry at /welcome, redirecting to /hu/welcome. Capture: 11 requests, a single domain, recorded in a clean browser.

Declared versus Actual

The capture reveals a fully self-sufficient entry page. All resources — markup, stylesheets, scripts, images, and fonts — load from the first-party domain kuria-birosag.hu. Fonts (Adobe Garamond Pro, Bodoni MT Condensed) are served locally from the theme directory, with no calls to external font services. There are no external domains present in the capture whatsoever: no analytics, no Google, no maps, no advertising pixels, no session recording. No cookies are set (Set-Cookie is zero). HSTS with preload and X-Frame-Options SAMEORIGIN security headers are present.

The Kúria’s Cookie Policy declares the use of Google Analytics web analytics to measure portal traffic. On this particular entry page, Google Analytics does not fire — there are no calls to it in the capture. Accordingly, on the page covered, no discrepancy between “declared” and “actual” arises: the declared analytics does not activate here, and there are no third-party calls.

All calls go to the first-party domain. There are no third-party resources on the entry page requiring consent; no cookies are set, and a consent banner is therefore unnecessary here. For the website of the highest judicial instance, this is the expected and correct behavior.

What Cannot Be Asserted from This Capture

The capture covers the portal’s entry welcome page, not its internal sections. The Kúria’s Cookie Policy declares the use of Google Analytics for traffic measurement — this analytics tool may activate on the main portal’s internal pages, which this capture does not cover. The behavior of the consent mechanism and of the declared analytics beyond the entry page cannot be assessed from this capture. Server-side processing is not visible in a browser-based capture.

Conclusion

The entry page of the Hungarian Supreme Court’s website demonstrates a configuration that is clean as captured: all resources, including fonts, are hosted locally on the first-party domain, there are no external calls whatsoever, and trackers and cookies are absent. The Google Analytics web analytics declared in the policy does not fire on this page. No violations have been recorded within the scope of this capture. The behavior of the main portal’s internal sections, where Google Analytics may activate under the policy, should be verified with a separate capture.

Evidence
Original (audit)
HAR file: hu/kuria-birosag-hu-2026-05-29.har
SHA-256: 97bd0a8c863b9faa8315dffd511b7863fa4de0529883b0bfe9e5dc5331f705f3
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.