Hungary's Data Protection Authority (NAIH) — 81 requests, 6 domains. The country's GDPR supervisory authority. There is no analytics or cookies on the site — but prior to any consent, the visitor's IP address and Referer header are transmitted to Google (Fonts and hosted jQuery) and to Cloudflare cdnjs. The authority's own cookie policy declares only technical cookies and does not name these third-party recipients.
Timeline of the leak
Declared versus actual
Transfer timings
Google Fonts CSS (Source Sans Pro). Google, USA.
Google Hosted Libraries — jQuery, jQuery UI. Google, USA.
animate.css. Served via Cloudflare, USA.
Google font files (×8). Google, USA.
Detected trackers
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — prior to consent, not named in the policy
- Google Hosted Libraries (ajax.googleapis.com — jQuery, jQuery UI) — prior to consent
- Cloudflare cdnjs (cdnjs.cloudflare.com — animate.css) — prior to consent
- jQuery CDN (code.jquery.com — jquery-migrate) — prior to consent
Indicators of GDPR non-compliance
- GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and cross-border transferOn page load, prior to any consent, Google Fonts loads (fonts.googleapis.com at +537 ms, fonts.gstatic.com ×8 at +706 ms), as do Google Hosted Libraries (ajax.googleapis.com — jQuery and jQuery UI at +544 ms), Cloudflare cdnjs (animate.css at +542 ms), and the jQuery CDN (code.jquery.com at +544 ms). Both Google loads transmit the visitor's IP address and the Referer header https://naih.hu/ to Google (USA). NAIH's own cookie policy states that the site uses exclusively technically necessary, session, and preference cookies, and that no personal data is retained in them; third-party recipients (Google, Cloudflare) are not named in the policy.
Context
naih.hu is the website of the National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH), Hungary’s GDPR supervisory authority. The data controller is NAIH. The site is served by an Apache server. Capture: 81 requests, 6 domains, recorded in a clean browser.
Direct Recipients of Data (prior to consent)
Google (USA) — the visitor’s IP address and Referer header via Google Fonts and Google-hosted jQuery. Cloudflare (USA) — the visitor’s IP address via cdnjs. The jQuery CDN — the visitor’s IP address via jquery-migrate.
Declared versus Actual
NAIH’s own cookie policy states directly and categorically: naih.hu uses exclusively cookies necessary for the site’s functioning and session maintenance, along with preference cookies that remember selected settings. The policy separately emphasizes that no personal data is retained in cookies — only an identifier reflecting acceptance of the cookie notice is stored. The policy mentions no analytics, third-party services, font providers, or CDNs.
The capture confirms part of these statements: there is no analytics (Google Analytics, Matomo) on the site, no advertising pixels, and no cookies are set during the session (Set-Cookie is zero). It does, however, reveal a different problem. At +537 ms, immediately on page load, Google Fonts connects: CSS from fonts.googleapis.com, followed by Source Sans Pro font files from fonts.gstatic.com (eight files at +706 ms). Both loads transmit the visitor’s IP address and the Referer header https://naih.hu/ to Google (USA). Almost simultaneously, at +542–545 ms, external libraries load: animate.css from Cloudflare cdnjs, jQuery and jQuery UI from Google Hosted Libraries (ajax.googleapis.com), and jquery-migrate from code.jquery.com. All of these calls transmit the visitor’s IP address to third-party recipients and occur unconditionally, before any choice is made.
Thus, although there are no cookies or analytics, the site contacts several third-party recipients in the USA prior to consent, none of which is named in the authority’s policy. For a data protection supervisory authority, this discrepancy is particularly notable: the policy declares self-sufficiency with respect to cookies, while in fact the visitor’s IP address is transmitted to Google and Cloudflare on every visit.
Timing Relative to Consent
External calls occur at +537–708 ms, all before any action by the visitor. The site has a cookie notice, but it does not hold back the loading of fonts and libraries — these calls occur outside the consent mechanism. No consent was given during the session (Set-Cookie is zero).
What Cannot Be Asserted from This Capture
The capture covers the home page in its pre-consent state. Google Fonts and Google-hosted libraries do not set cookies, so the policy’s literal statement about using only technical cookies is not formally violated; the issue is the undisclosed transfer of the IP address to third-party recipients. Google and Cloudflare may use edge nodes within the EU; the conclusion drawn therefore concerns the recipients’ corporate affiliation (US companies), not the physical location of the nodes. Server-side processing is not visible in a browser-based capture.
Conclusion
The website of Hungary’s data protection authority uses no analytics and sets no cookies, consistent with its own policy. However, prior to any consent, it transmits the visitor’s IP address and Referer header to several third-party recipients in the USA: to Google, via Google Fonts and hosted jQuery libraries, and to Cloudflare, via cdnjs. None of these recipients is named in the authority’s cookie policy, despite the policy’s claim of the site’s self-sufficiency. For a GDPR supervisory authority that itself imposes these very requirements on others, the transfer of the IP address to third-party recipients in the USA by default, on every visit, and outside any consent mechanism, constitutes a violation of the requirements concerning disclosure of recipients and cross-border transfer. The remedy is simple and entirely within the authority’s own control: host the fonts and JavaScript libraries locally on the site’s own domain — this would eliminate all external calls, making the site genuinely self-sufficient.
dedf5b6273b62c8f5bf91b7c965ef9ad12f761c2fa50692f2aa679028e662716Where to file: Hungarian National Authority for Data Protection (NAIH) — file a complaint online →
To: Hungarian National Authority for Data Protection (NAIH) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website naih.hu. 2. Circumstances I visited the website naih.hu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) On page load, prior to any consent, Google Fonts loads (fonts.googleapis.com at +537 ms, fonts.gstatic.com ×8 at +706 ms), as do Google Hosted Libraries (ajax.googleapis.com — jQuery and jQuery UI at +544 ms), Cloudflare cdnjs (animate.css at +542 ms), and the jQuery CDN (code.jquery.com at +544 ms). Both Google loads transmit the visitor's IP address and the Referer header https://naih.hu/ to Google (USA). NAIH's own cookie policy states that the site uses exclusively technically necessary, session, and preference cookies, and that no personal data is retained in them; third-party recipients (Google, Cloudflare) are not named in the policy. Full technical documentation is published at: https://gdpru.eu/en/audits/hu-naih-hu/ 3. Provisions violated GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and cross-border transfer 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]