The National Directorate-General for Aliens Policing of Hungary (OIF, formerly the Office of Immigration and Nationality) — 54 requests, 8 domains. An immigration authority whose audience includes foreign nationals, refugees, and asylum seekers. There is no analytics, some fonts have been switched to privacy-oriented Bunny Fonts, and the banner promises to load statistics/marketing only after consent. But prior to any consent, the visitor's IP address is transmitted to Google (reCAPTCHA and Google Fonts), to Bunny (Slovenia), and to unpkg. The policy states directly that visit data is not transferred to third parties — even though these recipients are not named in it.
Timeline of the leak
Declared versus actual
Transfer timings
Bunny Fonts (Nunito). BunnyWay, Slovenia (EU).
Swiper 12.2.0 (css+js). CDN, Cloudflare infrastructure.
reCAPTCHA api.js. Google, USA.
Google Fonts CSS (Lora). Google, USA.
Google font files (Lora, ×2). Google, USA.
reCAPTCHA runtime. Google, USA.
Detected trackers
- Google reCAPTCHA (www.google.com/recaptcha, www.gstatic.com/recaptcha) — prior to consent, not named in the policy
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com — Lora) — prior to consent, not named in the policy
- Bunny Fonts (fonts.bunny.net — Nunito) — prior to consent; third-party recipient of IP address (BunnyWay, Slovenia)
- unpkg (unpkg.com — Swiper 12.2.0) — prior to consent, not named in the policy
Indicators of GDPR non-compliance
- GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and cross-border transferOn page load, prior to any consent, Google reCAPTCHA loads (www.google.com/recaptcha/api.js at +783 ms and the runtime from www.gstatic.com at +1540 ms), as does Google Fonts (fonts.googleapis.com at +989 ms, Lora font files from fonts.gstatic.com at +1155–1226 ms), Bunny Fonts (fonts.bunny.net — the Nunito font at +781 ms), and the Swiper 12.2.0 library from unpkg (unpkg.com at +782–958 ms). All of these transmit the visitor's IP address to third-party recipients — to Google (USA) via reCAPTCHA and Google Fonts, to Bunny (Slovenia), and to unpkg. The Directorate-General's own privacy notice (adatvédelmi tájékoztató) states directly that data arising from visiting the site is not transferred to third parties (except for lawfully mandated targeted requests from authorities). Neither Google, Bunny, nor unpkg is named in the policy.
- ePrivacy (Hungarian implementation) — third-party resources prior to consentThe site's banner states that statistical and marketing cookies load only after the 'accept' button is clicked. However, Google reCAPTCHA, Google Fonts, Bunny Fonts, and unpkg fire at +781–1540 ms, before any interaction with the banner, transmitting the visitor's IP address to third-party recipients. Set-Cookie across the entire session is zero; there is no consent, yet the transfer of the IP address has already taken place. For an authority whose audience includes foreign nationals, refugees, and asylum seekers, this is particularly sensitive.
Context
oif.gov.hu is the website of the National Directorate-General for Aliens Policing of Hungary (Országos Idegenrendészeti Főigazgatóság, OIF), the immigration control authority responsible for residence permits, registration of foreign nationals, and asylum and protection matters. Until 2019, the authority was known as the Office of Immigration and Nationality (Bevándorlási és Menekültügyi Hivatal), corresponding to the former domain bmbah.hu. The data controller is OIF. The site is served by an Apache/2.4.62 server (Debian). Capture: 54 requests, 8 domains, recorded in a clean browser.
Direct Recipients of Data (prior to consent)
Google (USA) — the visitor’s IP address via reCAPTCHA and Google Fonts. Bunny (Slovenia) — the visitor’s IP address via Bunny Fonts. unpkg — the visitor’s IP address via the loading of the Swiper library.
Declared versus Actual
Here the discrepancy is especially stark, because the authority makes a direct promise. OIF’s privacy notice states that the Directorate-General does not transfer data arising in connection with visiting the site to third parties — except for lawfully mandated targeted requests from authorities. The consent banner, in turn, promises that statistical and marketing cookies will load only after the visitor clicks “accept.” That is, on paper, the site is closed to third-party transfer and operates on a prior-consent model.
The capture reveals otherwise. At +781 ms, before any interaction with the banner, several external recipients connect at once. Some fonts have indeed been switched to privacy-oriented Bunny Fonts (fonts.bunny.net, the Nunito font) — a deliberate step in favor of privacy. But at the same time, Google reCAPTCHA loads (api.js from www.google.com, the runtime from www.gstatic.com at +1540 ms), along with Google Fonts (the Lora font from fonts.googleapis.com and fonts.gstatic.com at +989–1226 ms) and the Swiper 12.2.0 library from unpkg. All of these calls transmit the visitor’s IP address to third-party recipients: to Google (USA) via reCAPTCHA and Google Fonts, to Bunny (Slovenia) via Nunito, and to unpkg via Swiper. None of them is named in the policy, and the fact of the IP address transfer itself directly contradicts the statement that no data is transferred to third parties.
For this authority, the context makes the finding weightier. Its visitors are foreign nationals, refugees, and asylum seekers; for many of them, the default disclosure of an IP address to a US recipient carries quite different risks than it would for an ordinary visit to a government site. At the same time, there is no analytics (Google Analytics, Matomo) on the site at all, and no cookies are set during the session (Set-Cookie is zero) — meaning the issue lies specifically in the undisclosed transfer of the IP address to third-party recipients, not in tracking cookies.
Timing Relative to Consent
All external calls occur at +781–1540 ms, before any action by the visitor. The site has a consent banner that declares a consent model, but it does not hold back the loading of fonts, reCAPTCHA, or the CDN library — these calls occur outside the consent mechanism. No consent was given during the session (Set-Cookie is zero).
What Cannot Be Asserted from This Capture
The calls to bmbah.hu at the start of the capture are redirects from the authority’s former domain to the current oif.gov.hu, not a third-party tracker; the capture simply began at the old address. Bunny Fonts (operated by BunnyWay, Slovenia) is positioned as a privacy-oriented alternative to Google Fonts that does not log IP addresses for tracking purposes; of all the external recipients, it is therefore the least concerning — but formally it remains a third-party contact not named in the policy. Google may use edge nodes within the EU; for reCAPTCHA and Google Fonts, the conclusion drawn therefore concerns the recipient’s corporate affiliation (Google, USA), not the physical location of the node. unpkg is served through Cloudflare infrastructure — the conclusion concerns the recipient operator, not a specific node. reCAPTCHA is present in the form of api.js; the form to which it is attached is not necessarily visible in the home-page capture — the library is preloaded. Server-side processing is not visible in a browser-based capture.
Conclusion
The website of Hungary’s immigration authority has taken a step toward privacy — some fonts have been switched to Bunny Fonts, there is no analytics, and the banner declares a prior-consent model. Nevertheless, prior to any consent, the site transmits the visitor’s IP address to several third-party recipients: to Google, via reCAPTCHA and the remaining Google Fonts, to Bunny (Slovenia), and to unpkg. None of them is named in the policy, and the authority’s own privacy notice states directly that visit data is not transferred to third parties — which contradicts the site’s actual behavior. For an authority working with foreign nationals, refugees, and asylum seekers, the transfer of the IP address to undisclosed third-party recipients by default, on every visit, and outside any consent mechanism, constitutes a violation of the requirements concerning disclosure of recipients and cross-border transfer, compounded by the heightened sensitivity of the audience. The remedy is largely within the authority’s own control: complete the work already begun — switch the remaining Google Fonts to locally hosted fonts or to the same Bunny service, host Swiper locally, and load reCAPTCHA only on pages containing forms and only after consent; this would leave practically no external calls prior to the visitor’s choice.
28ff2c75c22226d73664b8593ca0d9746a19c85ed6e2caac290a2354ea1a3363Where to file: Hungarian National Authority for Data Protection (NAIH) — file a complaint online →
To: Hungarian National Authority for Data Protection (NAIH) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website oif.gov.hu. 2. Circumstances I visited the website oif.gov.hu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) On page load, prior to any consent, Google reCAPTCHA loads (www.google.com/recaptcha/api.js at +783 ms and the runtime from www.gstatic.com at +1540 ms), as does Google Fonts (fonts.googleapis.com at +989 ms, Lora font files from fonts.gstatic.com at +1155–1226 ms), Bunny Fonts (fonts.bunny.net — the Nunito font at +781 ms), and the Swiper 12.2.0 library from unpkg (unpkg.com at +782–958 ms). All of these transmit the visitor's IP address to third-party recipients — to Google (USA) via reCAPTCHA and Google Fonts, to Bunny (Slovenia), and to unpkg. The Directorate-General's own privacy notice (adatvédelmi tájékoztató) states directly that data arising from visiting the site is not transferred to third parties (except for lawfully mandated targeted requests from authorities). Neither Google, Bunny, nor unpkg is named in the policy. 2) The site's banner states that statistical and marketing cookies load only after the 'accept' button is clicked. However, Google reCAPTCHA, Google Fonts, Bunny Fonts, and unpkg fire at +781–1540 ms, before any interaction with the banner, transmitting the visitor's IP address to third-party recipients. Set-Cookie across the entire session is zero; there is no consent, yet the transfer of the IP address has already taken place. For an authority whose audience includes foreign nationals, refugees, and asylum seekers, this is particularly sensitive. Full technical documentation is published at: https://gdpru.eu/en/audits/hu-oif-gov-hu/ 3. Provisions violated GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and cross-border transfer; ePrivacy (Hungarian implementation) — third-party resources prior to consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]