Technical audit · 2026-05-29

parlament.hu

National Assembly (Parliament) of Hungary

The National Assembly (Parliament) of Hungary — 143 requests, 4 domains. The sole external recipient is Google Analytics, but in two versions at once: the deprecated Universal Analytics (UA-50664080-1) and GA4. Both send hits prior to any consent, transmitting the IP address to Google (USA). Analytics is declared in the policy, but on the basis of 'legitimate interest,' whereas analytics cookies generally require prior consent.

Timeline of the leak

+0 ms · portal load
Markup, scripts, and images — served from the first-party domain www.parlament.hu. HSTS (includeSubDomains) is present.
+414 ms · Google Tag Manager / GA4 prior to consent
gtag.js (GA4 stream G-K44KGQW81R). The visitor's IP address is transmitted to Google (USA).
+1815 ms · Universal Analytics prior to consent
analytics.js — the classic (deprecated) Universal Analytics library. The visitor's IP address is transmitted to Google (USA).
+3908…+4020 ms · analytics hits prior to consent
Calls are sent: a UA hit to www.google-analytics.com/j/collect (UA-50664080-1) and a GA4 page_view event to region1.google-analytics.com/g/collect. Both prior to any action by the visitor.
no consent mechanism holds back the analytics
Analytics fires unconditionally; the policy relies on 'legitimate interest,' which is why GA launches before any choice is made, rather than after consent.
no other trackers
Google Fonts, reCAPTCHA, Facebook, advertising pixels, and session recording are absent from the capture. The sole external recipient is Google Analytics, in two versions.

Declared versus actual

Cookie Policy (Tájékoztató a sütik használatáról) — declares Google Analytics as a third-party service, including remarketing, Google Display Network reports, and demographic/interest reports; cookies _ga, _gid, _gat — declared
Legal basis — legitimate interest (GDPR Art. 6(1)(f)), with a balancing test; the policy acknowledges the possible processing of data by external providers in unsafe third countries — declared
Operator — Országgyűlés Hivatala (the Office of the National Assembly) — declared
+ The deprecated Universal Analytics identifier (UA-50664080-1) continues to send hits — the configuration has not been brought into line with the GA4 actually in use — not declared

Transfer timings

+414 ms www.googletagmanager.com

gtag.js — GA4 (G-K44KGQW81R). Google, USA.

+1815 ms www.google-analytics.com

analytics.js — Universal Analytics (deprecated). Google, USA.

+3908 ms www.google-analytics.com

/j/collect — UA-50664080-1 hit sent. Google, USA.

+4020 ms region1.google-analytics.com

/g/collect — GA4 page_view event sent. Google, USA (EU regional endpoint).

Detected trackers

Indicators of GDPR non-compliance

Context

parlament.hu is the website of the National Assembly of Hungary (Országgyűlés), the country’s unicameral parliament. The data controller is the Office of the National Assembly (Országgyűlés Hivatala). The site is served with HSTS (includeSubDomains). Capture: 143 requests, 4 domains, recorded in a clean browser.

Google (USA) — the visitor’s IP address and viewing data via Google Analytics, in two versions (GA4 and the deprecated Universal Analytics). There are no other third-party recipients in the capture.

Declared versus Actual

Parliament’s cookie policy names Google Analytics directly as a third-party service — moreover, it lists its extended functions: remarketing, Google Display Network reports, and demographic and interest reports. That is, analytics is disclosed, and disclosed in detail. As the legal basis, the policy cites not consent but legitimate interest (GDPR Art. 6(1)(f)), for which a balancing test has been carried out; separately, the policy acknowledges in general terms that external providers may process data in countries not recognized as safe third countries.

The capture shows that analytics fires prior to any consent, and in two versions at once. At +414 ms, the GA4 container connects (gtag, stream G-K44KGQW81R); at +1815 ms, the classic Universal Analytics library (analytics.js). Both then actually send calls: at +3908 ms, a hit from the deprecated Universal Analytics (UA-50664080-1) goes to www.google-analytics.com/j/collect, and at +4020 ms, a GA4 page_view event goes to region1.google-analytics.com. This is not merely script loading: data has already been sent to Google (USA). Not a single cookie is set during the session (Set-Cookie is zero).

The discrepancy here lies not in disclosure but in two other things. First, the legal basis: the policy relies on legitimate interest, whereas under the ePrivacy rules, analytics cookies generally require prior consent — meaning that launching analytics before any choice by the visitor is problematic. Second, the configuration is outdated: alongside GA4, Universal Analytics — a version Google has discontinued — continues to run and send hits.

Analytics fires at +414–4020 ms, with hits actually sent, all before any action by the visitor. There is no mechanism holding back analytics until consent — the policy relies on legitimate interest instead. No consent was given during the session (Set-Cookie is zero).

What Cannot Be Asserted from This Capture

The GA calls were actually sent (HTTP 200 and 204 status codes), meaning the data has left; the client identifiers carried in these calls are intentionally not reproduced in this card. The identifier UA-50664080-1 belongs to Universal Analytics, processing for which Google has discontinued; the hit is nevertheless still sent, but the capture cannot establish whether it is processed on Google’s side — the fact of IP address transmission did, however, occur. GA4 communicates with an EU regional endpoint (region1), but Google is a US company. Google may use edge nodes within the EU; the conclusion drawn therefore concerns the recipient’s corporate affiliation, not the location of the node. The question of whether legitimate interest is an acceptable basis for analytics is a legal one; this card records the discrepancy itself (analytics prior to consent) rather than rendering a legal verdict. Server-side processing is not visible in a browser-based capture.

Conclusion

The website of Hungary’s parliament transmits visitor data to Google Analytics, in two versions at once — the deprecated Universal Analytics and GA4 — prior to any consent, transferring the IP address to Google (USA) on every visit. Analytics is disclosed in the cookie policy, including its advertising-related functions, but it relies on legitimate interest, whereas analytics cookies generally require prior consent under the ePrivacy rules; as a result, analytics launches before the visitor makes a choice. Additionally, the configuration is outdated: alongside GA4, the discontinued Universal Analytics continues to run. Launching analytics and transferring data to a third-party recipient in the USA prior to consent constitutes a violation of the requirements concerning the proper sequencing of consent and cross-border transfer. The remedy is within the operator’s control: launch Google Analytics only after explicit consent via a fully functioning consent mechanism, disable the deprecated Universal Analytics identifier, and retain a single, current counter.

Evidence
Original (audit)
HAR file: hu/parlament-hu-2026-05-29.har
SHA-256: 131e817b4cda0e9a97a3582c768a835097e67c10256ab9c94f32ea6d45259daa
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Hungarian National Authority for Data Protection (NAIH)file a complaint online →

To: Hungarian National Authority for Data Protection (NAIH)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website parlament.hu.

2. Circumstances
I visited the website parlament.hu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) Prior to any consent, Google Analytics fires in two versions at once: the GA4 container (gtag G-K44KGQW81R at +414 ms), sending a page_view event to region1.google-analytics.com (+4020 ms), and the deprecated Universal Analytics (analytics.js at +1815 ms), sending a UA-50664080-1 hit to www.google-analytics.com/j/collect (+3908 ms). These are calls actually sent, not merely libraries loaded. The cookie policy declares Google Analytics, but on the legal basis of 'legitimate interest' (GDPR Art. 6(1)(f)), with a balancing test. Under the ePrivacy rules, analytics cookies generally require prior consent rather than legitimate interest; here, however, analytics launches before any choice is made by the visitor. Set-Cookie across the session is zero.

2) Both GA calls transmit the visitor's IP address and viewing data to Google (USA). The cookie policy acknowledges in general terms that external providers may process data in countries not recognized as safe third countries, but the transfer occurs by default, prior to consent.

Full technical documentation is published at: https://gdpru.eu/en/audits/hu-parlament-hu/

3. Provisions violated
ePrivacy (Hungarian implementation) — analytics prior to consent, on the basis of legitimate interest; GDPR Chapter V — cross-border transfer

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]