Technical audit · 2026-05-29

naih.hu

Data Protection Authority of Hungary

Hungary's Data Protection Authority (NAIH) — 81 requests, 6 domains. The country's GDPR supervisory authority. There is no analytics or cookies on the site — but prior to any consent, the visitor's IP address and Referer header are transmitted to Google (Fonts and hosted jQuery) and to Cloudflare cdnjs. The authority's own cookie policy declares only technical cookies and does not name these third-party recipients.

Timeline of the leak

+0 ms · portal load
Markup and some scripts and images — served from the first-party domain naih.hu (Apache). HSTS is present.
+537 ms · Google Fonts prior to consent
fonts.googleapis.com (CSS), followed by fonts.gstatic.com (Source Sans Pro font files, ×8 at +706 ms). The visitor's IP address and the Referer header https://naih.hu/ are transmitted to Google (USA).
+542…+545 ms · external libraries prior to consent
cdnjs.cloudflare.com (animate.css, Cloudflare), ajax.googleapis.com (jQuery 3.7.1 and jQuery UI, Google), and code.jquery.com (jquery-migrate). The visitor's IP address is transmitted to third-party recipients.
the consent banner does not hold back the external resources
The site has a cookie notice, but calls to Google and Cloudflare occur before and independently of any choice; the consent mechanism does not block them.
no analytics
Google Analytics, Matomo, advertising pixels, and session recording are absent from the capture. External calls are limited to fonts and libraries from the Google, Cloudflare, and jQuery CDNs.

Declared versus actual

NAIH's Cookie Policy ('Süti tájékoztató') — exclusively technically necessary, session, and preference cookies — declared
Declared: no personal data is retained in cookies; only an identifier reflecting acceptance of the cookie notice is stored — declared
+ Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — third-party recipient of IP address from the USA, prior to consent, not named in the policy — not declared
+ Google Hosted Libraries (ajax.googleapis.com) — third-party recipient of IP address from the USA, prior to consent, not named — not declared
+ Cloudflare cdnjs and the jQuery CDN — third-party recipients of IP address, prior to consent, not named — not declared

Transfer timings

+537 ms fonts.googleapis.com

Google Fonts CSS (Source Sans Pro). Google, USA.

+544 ms ajax.googleapis.com

Google Hosted Libraries — jQuery, jQuery UI. Google, USA.

+542 ms cdnjs.cloudflare.com

animate.css. Served via Cloudflare, USA.

+706 ms fonts.gstatic.com

Google font files (×8). Google, USA.

Detected trackers

Indicators of GDPR non-compliance

Context

naih.hu is the website of the National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH), Hungary’s GDPR supervisory authority. The data controller is NAIH. The site is served by an Apache server. Capture: 81 requests, 6 domains, recorded in a clean browser.

Google (USA) — the visitor’s IP address and Referer header via Google Fonts and Google-hosted jQuery. Cloudflare (USA) — the visitor’s IP address via cdnjs. The jQuery CDN — the visitor’s IP address via jquery-migrate.

Declared versus Actual

NAIH’s own cookie policy states directly and categorically: naih.hu uses exclusively cookies necessary for the site’s functioning and session maintenance, along with preference cookies that remember selected settings. The policy separately emphasizes that no personal data is retained in cookies — only an identifier reflecting acceptance of the cookie notice is stored. The policy mentions no analytics, third-party services, font providers, or CDNs.

The capture confirms part of these statements: there is no analytics (Google Analytics, Matomo) on the site, no advertising pixels, and no cookies are set during the session (Set-Cookie is zero). It does, however, reveal a different problem. At +537 ms, immediately on page load, Google Fonts connects: CSS from fonts.googleapis.com, followed by Source Sans Pro font files from fonts.gstatic.com (eight files at +706 ms). Both loads transmit the visitor’s IP address and the Referer header https://naih.hu/ to Google (USA). Almost simultaneously, at +542–545 ms, external libraries load: animate.css from Cloudflare cdnjs, jQuery and jQuery UI from Google Hosted Libraries (ajax.googleapis.com), and jquery-migrate from code.jquery.com. All of these calls transmit the visitor’s IP address to third-party recipients and occur unconditionally, before any choice is made.

Thus, although there are no cookies or analytics, the site contacts several third-party recipients in the USA prior to consent, none of which is named in the authority’s policy. For a data protection supervisory authority, this discrepancy is particularly notable: the policy declares self-sufficiency with respect to cookies, while in fact the visitor’s IP address is transmitted to Google and Cloudflare on every visit.

External calls occur at +537–708 ms, all before any action by the visitor. The site has a cookie notice, but it does not hold back the loading of fonts and libraries — these calls occur outside the consent mechanism. No consent was given during the session (Set-Cookie is zero).

What Cannot Be Asserted from This Capture

The capture covers the home page in its pre-consent state. Google Fonts and Google-hosted libraries do not set cookies, so the policy’s literal statement about using only technical cookies is not formally violated; the issue is the undisclosed transfer of the IP address to third-party recipients. Google and Cloudflare may use edge nodes within the EU; the conclusion drawn therefore concerns the recipients’ corporate affiliation (US companies), not the physical location of the nodes. Server-side processing is not visible in a browser-based capture.

Conclusion

The website of Hungary’s data protection authority uses no analytics and sets no cookies, consistent with its own policy. However, prior to any consent, it transmits the visitor’s IP address and Referer header to several third-party recipients in the USA: to Google, via Google Fonts and hosted jQuery libraries, and to Cloudflare, via cdnjs. None of these recipients is named in the authority’s cookie policy, despite the policy’s claim of the site’s self-sufficiency. For a GDPR supervisory authority that itself imposes these very requirements on others, the transfer of the IP address to third-party recipients in the USA by default, on every visit, and outside any consent mechanism, constitutes a violation of the requirements concerning disclosure of recipients and cross-border transfer. The remedy is simple and entirely within the authority’s own control: host the fonts and JavaScript libraries locally on the site’s own domain — this would eliminate all external calls, making the site genuinely self-sufficient.

Evidence
Original (audit)
HAR file: hu/naih-hu-2026-05-29.har
SHA-256: dedf5b6273b62c8f5bf91b7c965ef9ad12f761c2fa50692f2aa679028e662716
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Hungarian National Authority for Data Protection (NAIH)file a complaint online →

To: Hungarian National Authority for Data Protection (NAIH)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website naih.hu.

2. Circumstances
I visited the website naih.hu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) On page load, prior to any consent, Google Fonts loads (fonts.googleapis.com at +537 ms, fonts.gstatic.com ×8 at +706 ms), as do Google Hosted Libraries (ajax.googleapis.com — jQuery and jQuery UI at +544 ms), Cloudflare cdnjs (animate.css at +542 ms), and the jQuery CDN (code.jquery.com at +544 ms). Both Google loads transmit the visitor's IP address and the Referer header https://naih.hu/ to Google (USA). NAIH's own cookie policy states that the site uses exclusively technically necessary, session, and preference cookies, and that no personal data is retained in them; third-party recipients (Google, Cloudflare) are not named in the policy.

Full technical documentation is published at: https://gdpru.eu/en/audits/hu-naih-hu/

3. Provisions violated
GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and cross-border transfer

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]