The National Media and Infocommunications Authority of Hungary (NMHH) — 76 requests, 7 domains. The national media and telecommunications regulator. The site has a consent banner, and Google Analytics is declared in the policy (with IP masking). But prior to any consent, the visitor's IP address and Referer header are transmitted to Google via Google Fonts, hosted jQuery, and GTM/Analytics itself, as well as to Infogram (an embed loader). Google Fonts, hosted jQuery, and Infogram are not named in the policy; GA4 sends page_view and scroll events before any interaction with the banner.
Timeline of the leak
Declared versus actual
Transfer timings
Google Fonts CSS (Inter, Arsenal). Google, USA.
Google Hosted Libraries — jQuery 1.12.4. Google, USA.
gtag.js — the GTM container, initializes GA4. Google, USA.
Google font files (×4). Google, USA.
Infogram embed loader. A Prezi subsidiary.
GA4 /g/collect — page_view and scroll, two streams. EU regional endpoint.
Detected trackers
- Google Analytics 4 (GTM/gtag, streams G-D5LQSMBZTF and G-9TVCG3TVNV) — prior to consent; declared in the policy, with IP masking
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — prior to consent, not named in the policy
- Google Hosted Libraries (ajax.googleapis.com — jQuery 1.12.4) — prior to consent, not named in the policy
- Infogram (e.infogram.com — embed loader, a Prezi subsidiary) — prior to consent, not named in the policy
Indicators of GDPR non-compliance
- GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and cross-border transferOn page load, prior to any consent, Google Fonts loads (fonts.googleapis.com at +296 ms, Inter and Arsenal font files from fonts.gstatic.com at +832–926 ms), as do Google-hosted jQuery 1.12.4 (ajax.googleapis.com at +297 ms) and the Infogram embed loader (e.infogram.com at +900 ms). All of these transmit the visitor's IP address — and the Google loads additionally transmit the Referer header https://nmhh.hu/ — to third-party recipients: Google (USA) and Infogram (a Prezi subsidiary). NMHH's cookie policy names only Google Analytics (with IP masking) and Hotjar; it does not name Google Fonts, hosted jQuery, or Infogram as recipients.
- ePrivacy (Hungarian implementation) — analytics and third-party resources prior to consentThe site has a consent banner ('Accept All' / 'Reject' / 'Details and settings'), but external resources and Google Analytics fire before any interaction with it. GA4 (gtag.js at +300 ms) sends page_view (+1569 ms) and scroll (+6571 ms) events to region1.google-analytics.com across two streams — before the visitor has made a choice. Set-Cookie across the entire session is zero; no consent is recorded, yet the transfer of data to third-party recipients has already taken place.
Context
nmhh.hu is the website of the National Media and Infocommunications Authority of Hungary (Nemzeti Média- és Hírközlési Hatóság, NMHH), the country’s media and electronic communications regulator. The data controller is NMHH. The site is served by an Apache/2.4.58 server (Ubuntu). Capture: 76 requests, 7 domains, recorded in a clean browser.
Direct Recipients of Data (prior to consent)
Google (USA) — the visitor’s IP address and Referer header via Google Fonts, hosted jQuery, and the GTM/Google Analytics container. Infogram (a Prezi subsidiary) — the visitor’s IP address via the embed loader.
Declared versus Actual
NMHH has a functioning consent framework: a banner with “accept all,” “reject,” and “details and settings” buttons, and a separate cookie policy, “Tájékoztató a sütikről.” The policy names Google Analytics directly, explaining that GA cookies are used by default with IP masking and are classified within the base layer, with non-anonymized statistics enabled only upon explicit consent. Hotjar is additionally mentioned — temporarily, from 19.07.2024, for user-experience research.
The capture confirms the presence of Google Analytics and clarifies its behavior: the GTM container (gtag.js) loads at +300 ms, and at +1569 and +6571 ms GA4 sends page_view and scroll events to the regional (EU) endpoint region1.google-analytics.com across two streams at once (G-D5LQSMBZTF and G-9TVCG3TVNV), carrying a client identifier and device/browser metadata. All of this occurs before any interaction with the consent banner (Set-Cookie across the session is zero). That is, the analytics tool is declared, but it is dispatched without prior consent — a separate, legally contestable point under the Hungarian implementation of ePrivacy.
The main discrepancy, however, lies elsewhere than Analytics. The capture reveals three third-party recipients that the policy does not name at all. At +296 ms, Google Fonts connects (CSS from fonts.googleapis.com, followed by Inter and Arsenal font files from fonts.gstatic.com at +832–926 ms). Almost simultaneously, at +297 ms, jQuery 1.12.4 loads from Google Hosted Libraries (ajax.googleapis.com). Both loads transmit the visitor’s IP address and the Referer header https://nmhh.hu/ to Google (USA). At +900 ms, the Infogram embed loader connects (e.infogram.com), transmitting the visitor’s IP address to Infogram, a Prezi subsidiary. Neither Google Fonts, hosted jQuery, nor Infogram is mentioned in the cookie policy, even though the policy names its recipients specifically (Google Analytics, Hotjar).
Timing Relative to Consent
All external calls occur at +296–926 ms, and the Analytics calls at +1569–6580 ms, all before any action by the visitor. The site has a consent banner, but it holds back neither the loading of fonts and libraries nor the initialization of GA4 — these calls occur outside the consent mechanism. No consent was given during the session (Set-Cookie is zero).
What Cannot Be Asserted from This Capture
GA4, by its operating configuration, applies IP anonymization and, in this capture, communicates with the EU regional endpoint (region1), with the npa=1 parameter indicating a non-personalized mode; for Google Analytics, therefore, the issue is not non-disclosure (it is declared) but dispatch prior to consent. The GA client identifier is intentionally not reproduced in this card. Google may use edge nodes within the EU, so for Google Fonts and hosted jQuery, the conclusion drawn concerns the recipient’s corporate affiliation (a US company), not the physical location of the node. Infogram is a Prezi subsidiary: the corporate group is managed from the USA (San Francisco/Oakland), while development has historically been based in Latvia (EU); the conclusion drawn concerns the recipient’s corporate affiliation, not the specific jurisdiction of processing. Hotjar, declared in the policy, is not observed in this capture (it is temporary and may have expired) — no conclusion about it can be drawn from this snapshot. The capture covers the home page in its pre-consent state; server-side processing is not visible in a browser-based capture.
Conclusion
The website of Hungary’s media and infocommunications regulator is carefully built: it has a consent banner and a cookie policy, and Google Analytics is declared within it, with IP masking stated. Nevertheless, prior to any consent, the site transmits the visitor’s IP address and Referer header to several third-party recipients not named in the policy: to Google, via Google Fonts and hosted jQuery, and to Infogram (Prezi), via the embed loader. In parallel, Google Analytics sends page_view and scroll events before any interaction with the banner. For a national regulator, the transfer of the IP address to undisclosed third-party recipients by default, on every visit, and outside any consent mechanism, constitutes a violation of the requirements concerning disclosure of recipients and cross-border transfer. The remedy lies largely within the authority’s own control: host the fonts and JavaScript libraries locally on the site’s own domain, and enable the Infogram embed and the initialization of Analytics only after consent is given — this would eliminate all external calls prior to the visitor’s choice.
55cc5d638902db4e97c2d44b86bbdb0d07b33c8ddaf9d2754f85d1382677f413Where to file: Hungarian National Authority for Data Protection (NAIH) — file a complaint online →
To: Hungarian National Authority for Data Protection (NAIH)
From: [Your name], [contact email]
1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website nmhh.hu.
2. Circumstances
I visited the website nmhh.hu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications:
1) On page load, prior to any consent, Google Fonts loads (fonts.googleapis.com at +296 ms, Inter and Arsenal font files from fonts.gstatic.com at +832–926 ms), as do Google-hosted jQuery 1.12.4 (ajax.googleapis.com at +297 ms) and the Infogram embed loader (e.infogram.com at +900 ms). All of these transmit the visitor's IP address — and the Google loads additionally transmit the Referer header https://nmhh.hu/ — to third-party recipients: Google (USA) and Infogram (a Prezi subsidiary). NMHH's cookie policy names only Google Analytics (with IP masking) and Hotjar; it does not name Google Fonts, hosted jQuery, or Infogram as recipients.
2) The site has a consent banner ('Accept All' / 'Reject' / 'Details and settings'), but external resources and Google Analytics fire before any interaction with it. GA4 (gtag.js at +300 ms) sends page_view (+1569 ms) and scroll (+6571 ms) events to region1.google-analytics.com across two streams — before the visitor has made a choice. Set-Cookie across the entire session is zero; no consent is recorded, yet the transfer of data to third-party recipients has already taken place.
Full technical documentation is published at: https://gdpru.eu/en/audits/hu-nmhh-hu/
3. Provisions violated
GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and cross-border transfer; ePrivacy (Hungarian implementation) — analytics and third-party resources prior to consent
4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.
5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.
[Date] [Signature / name]