Technical audit · 2026-05-29

nmhh.hu

National Media and Infocommunications Authority of Hungary

The National Media and Infocommunications Authority of Hungary (NMHH) — 76 requests, 7 domains. The national media and telecommunications regulator. The site has a consent banner, and Google Analytics is declared in the policy (with IP masking). But prior to any consent, the visitor's IP address and Referer header are transmitted to Google via Google Fonts, hosted jQuery, and GTM/Analytics itself, as well as to Infogram (an embed loader). Google Fonts, hosted jQuery, and Infogram are not named in the policy; GA4 sends page_view and scroll events before any interaction with the banner.

Timeline of the leak

+0 ms · portal load
An http→https redirect (307), followed by markup, scripts, and images served from the first-party domain nmhh.hu (Apache/2.4.58, Ubuntu).
+296…+300 ms · Google and GTM prior to consent
Google Fonts CSS (fonts.googleapis.com), Google-hosted jQuery 1.12.4 (ajax.googleapis.com), and gtag.js — the Google Tag Manager container initializing Google Analytics (googletagmanager.com). The visitor's IP address and the Referer header https://nmhh.hu/ are transmitted to Google (USA).
+832…+926 ms · font files prior to consent
Inter and Arsenal font files from fonts.gstatic.com (×4). The visitor's IP address is transmitted to Google (USA).
+900 ms · Infogram prior to consent
e.infogram.com — the Infogram embed loader (a data-visualization service, a Prezi subsidiary). The visitor's IP address is transmitted to a third-party recipient.
the consent banner does not hold back the resources
The site has a banner ('Accept All' / 'Reject' / 'Details and settings'), but calls to Google, Infogram, and the loading of Google Analytics occur before and independently of any interaction with it; the consent mechanism does not block them.
+1569…+6580 ms · Google Analytics prior to consent
GA4 sends page_view (+1569 ms) and scroll (+6571 ms) events to region1.google-analytics.com across two streams (G-D5LQSMBZTF and G-9TVCG3TVNV), carrying a client identifier and device/browser metadata. Advertising pixels and session recording are absent from the capture.

Declared versus actual

Consent banner — 'Összes elfogadása' (accept all), 'Elutasítom' (reject), 'Részletek és beállítások' (details) — declared
Cookie Policy ('Tájékoztató a sütikről') — first-party session cookies + Google Analytics with IP masking by default (in the base layer) + Hotjar (temporary, from 19.07.2024, for up to 30 days) — declared
A separate newsletter notice (the file supplied) covers only newsletter subscription, processed by Neosoft; it does not mention cookies or trackers — declared
+ Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — third-party recipient of IP address from the USA, prior to consent, not named in the policy — not declared
+ Google Hosted Libraries (ajax.googleapis.com) — third-party recipient of IP address from the USA, prior to consent, not named in the policy — not declared
+ Infogram (e.infogram.com) — third-party recipient of IP address, prior to consent, not named in the policy — not declared

Transfer timings

+296 ms fonts.googleapis.com

Google Fonts CSS (Inter, Arsenal). Google, USA.

+297 ms ajax.googleapis.com

Google Hosted Libraries — jQuery 1.12.4. Google, USA.

+300 ms www.googletagmanager.com

gtag.js — the GTM container, initializes GA4. Google, USA.

+832 ms fonts.gstatic.com

Google font files (×4). Google, USA.

+900 ms e.infogram.com

Infogram embed loader. A Prezi subsidiary.

+1569 ms region1.google-analytics.com

GA4 /g/collect — page_view and scroll, two streams. EU regional endpoint.

Detected trackers

Indicators of GDPR non-compliance

Context

nmhh.hu is the website of the National Media and Infocommunications Authority of Hungary (Nemzeti Média- és Hírközlési Hatóság, NMHH), the country’s media and electronic communications regulator. The data controller is NMHH. The site is served by an Apache/2.4.58 server (Ubuntu). Capture: 76 requests, 7 domains, recorded in a clean browser.

Google (USA) — the visitor’s IP address and Referer header via Google Fonts, hosted jQuery, and the GTM/Google Analytics container. Infogram (a Prezi subsidiary) — the visitor’s IP address via the embed loader.

Declared versus Actual

NMHH has a functioning consent framework: a banner with “accept all,” “reject,” and “details and settings” buttons, and a separate cookie policy, “Tájékoztató a sütikről.” The policy names Google Analytics directly, explaining that GA cookies are used by default with IP masking and are classified within the base layer, with non-anonymized statistics enabled only upon explicit consent. Hotjar is additionally mentioned — temporarily, from 19.07.2024, for user-experience research.

The capture confirms the presence of Google Analytics and clarifies its behavior: the GTM container (gtag.js) loads at +300 ms, and at +1569 and +6571 ms GA4 sends page_view and scroll events to the regional (EU) endpoint region1.google-analytics.com across two streams at once (G-D5LQSMBZTF and G-9TVCG3TVNV), carrying a client identifier and device/browser metadata. All of this occurs before any interaction with the consent banner (Set-Cookie across the session is zero). That is, the analytics tool is declared, but it is dispatched without prior consent — a separate, legally contestable point under the Hungarian implementation of ePrivacy.

The main discrepancy, however, lies elsewhere than Analytics. The capture reveals three third-party recipients that the policy does not name at all. At +296 ms, Google Fonts connects (CSS from fonts.googleapis.com, followed by Inter and Arsenal font files from fonts.gstatic.com at +832–926 ms). Almost simultaneously, at +297 ms, jQuery 1.12.4 loads from Google Hosted Libraries (ajax.googleapis.com). Both loads transmit the visitor’s IP address and the Referer header https://nmhh.hu/ to Google (USA). At +900 ms, the Infogram embed loader connects (e.infogram.com), transmitting the visitor’s IP address to Infogram, a Prezi subsidiary. Neither Google Fonts, hosted jQuery, nor Infogram is mentioned in the cookie policy, even though the policy names its recipients specifically (Google Analytics, Hotjar).

All external calls occur at +296–926 ms, and the Analytics calls at +1569–6580 ms, all before any action by the visitor. The site has a consent banner, but it holds back neither the loading of fonts and libraries nor the initialization of GA4 — these calls occur outside the consent mechanism. No consent was given during the session (Set-Cookie is zero).

What Cannot Be Asserted from This Capture

GA4, by its operating configuration, applies IP anonymization and, in this capture, communicates with the EU regional endpoint (region1), with the npa=1 parameter indicating a non-personalized mode; for Google Analytics, therefore, the issue is not non-disclosure (it is declared) but dispatch prior to consent. The GA client identifier is intentionally not reproduced in this card. Google may use edge nodes within the EU, so for Google Fonts and hosted jQuery, the conclusion drawn concerns the recipient’s corporate affiliation (a US company), not the physical location of the node. Infogram is a Prezi subsidiary: the corporate group is managed from the USA (San Francisco/Oakland), while development has historically been based in Latvia (EU); the conclusion drawn concerns the recipient’s corporate affiliation, not the specific jurisdiction of processing. Hotjar, declared in the policy, is not observed in this capture (it is temporary and may have expired) — no conclusion about it can be drawn from this snapshot. The capture covers the home page in its pre-consent state; server-side processing is not visible in a browser-based capture.

Conclusion

The website of Hungary’s media and infocommunications regulator is carefully built: it has a consent banner and a cookie policy, and Google Analytics is declared within it, with IP masking stated. Nevertheless, prior to any consent, the site transmits the visitor’s IP address and Referer header to several third-party recipients not named in the policy: to Google, via Google Fonts and hosted jQuery, and to Infogram (Prezi), via the embed loader. In parallel, Google Analytics sends page_view and scroll events before any interaction with the banner. For a national regulator, the transfer of the IP address to undisclosed third-party recipients by default, on every visit, and outside any consent mechanism, constitutes a violation of the requirements concerning disclosure of recipients and cross-border transfer. The remedy lies largely within the authority’s own control: host the fonts and JavaScript libraries locally on the site’s own domain, and enable the Infogram embed and the initialization of Analytics only after consent is given — this would eliminate all external calls prior to the visitor’s choice.

Evidence
Original (audit)
HAR file: hu/nmhh-hu-2026-05-29.har
SHA-256: 55cc5d638902db4e97c2d44b86bbdb0d07b33c8ddaf9d2754f85d1382677f413
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Hungarian National Authority for Data Protection (NAIH)file a complaint online →

To: Hungarian National Authority for Data Protection (NAIH)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website nmhh.hu.

2. Circumstances
I visited the website nmhh.hu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) On page load, prior to any consent, Google Fonts loads (fonts.googleapis.com at +296 ms, Inter and Arsenal font files from fonts.gstatic.com at +832–926 ms), as do Google-hosted jQuery 1.12.4 (ajax.googleapis.com at +297 ms) and the Infogram embed loader (e.infogram.com at +900 ms). All of these transmit the visitor's IP address — and the Google loads additionally transmit the Referer header https://nmhh.hu/ — to third-party recipients: Google (USA) and Infogram (a Prezi subsidiary). NMHH's cookie policy names only Google Analytics (with IP masking) and Hotjar; it does not name Google Fonts, hosted jQuery, or Infogram as recipients.

2) The site has a consent banner ('Accept All' / 'Reject' / 'Details and settings'), but external resources and Google Analytics fire before any interaction with it. GA4 (gtag.js at +300 ms) sends page_view (+1569 ms) and scroll (+6571 ms) events to region1.google-analytics.com across two streams — before the visitor has made a choice. Set-Cookie across the entire session is zero; no consent is recorded, yet the transfer of data to third-party recipients has already taken place.

Full technical documentation is published at: https://gdpru.eu/en/audits/hu-nmhh-hu/

3. Provisions violated
GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and cross-border transfer; ePrivacy (Hungarian implementation) — analytics and third-party resources prior to consent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]