The Police of Hungary (operated by the National Police Headquarters, ORFK) — 151 requests, 6 domains. Prior to any consent, the visitor's IP address is transmitted to Google (Google Analytics in two versions and reCAPTCHA) and to Cloudflare (cdnjs). The authority's own policy, meanwhile, states directly that the site does not use cookies and does not transfer data to third parties — the capture disproves both statements.
Timeline of the leak
Declared versus actual
Transfer timings
reCAPTCHA api.js. Google, USA.
jquery-mousewheel. Cloudflare, USA.
analytics.js — Universal Analytics (deprecated). Google, USA.
reCAPTCHA runtime. Google, USA.
/j/collect — UA-41385412-1 hit sent. Google, USA.
gtag.js — GA4 (G-1B1E2T7ZMX). Google, USA.
Detected trackers
- Google Analytics (deprecated UA-41385412-1 + GA4 G-1B1E2T7ZMX) — prior to consent, not named in the policy
- Google reCAPTCHA (www.google.com/recaptcha, www.gstatic.com/recaptcha) — prior to consent, not named in the policy
- cdnjs / Cloudflare (cdnjs.cloudflare.com — jquery-mousewheel) — prior to consent, not named in the policy
Indicators of GDPR non-compliance
- GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients, cross-border transfer, and contradiction with the policyThe police's privacy notice (adatvédelmi tájékoztató) states directly that the site does not use cookies (only a session ID containing no personal data) and that personal data is not transferred to third parties. The capture disproves this: prior to consent, Google Analytics loads (the deprecated UA-41385412-1 and GA4 G-1B1E2T7ZMX, with a hit sent to www.google-analytics.com/j/collect at +601 ms), as does Google reCAPTCHA (www.google.com/recaptcha at +232 ms and the runtime from www.gstatic.com at +382 ms) and the jquery-mousewheel library from cdnjs.cloudflare.com (+343 ms). All of these transmit the visitor's IP address to third-party recipients in the USA (Google and Cloudflare). None of them is named in the policy, and the statements 'we do not use cookies' and 'we do not transfer data to third parties' directly contradict actual behavior.
- ePrivacy (Hungarian implementation) — trackers prior to consentGoogle Analytics, reCAPTCHA, and cdnjs fire at +232–640 ms, before any action by the visitor, and the UA hit is actually sent. The policy cites consent as the legal basis (GDPR Art. 6(1)(a)), implemented via continued use of the site — but the transfer of the IP address to third-party recipients in the USA occurred before any choice was made. Set-Cookie across the session is zero.
Context
police.hu is the website of the Police of Hungary (Rendőrség). The operator is the National Police Headquarters (Országos Rendőr-főkapitányság, ORFK). The site is built on Drupal 8 (nginx), with strong HSTS (preload) present. Capture: 151 requests, 6 domains, recorded in a clean browser.
Direct Recipients of Data (prior to consent)
Google (USA) — the visitor’s IP address via Google Analytics and reCAPTCHA. Cloudflare (USA) — the visitor’s IP address via the delivery of the jquery-mousewheel library from cdnjs.
Declared versus Actual
Here the discrepancy is especially stark, because the policy makes categorical and verifiable claims. The police’s privacy notice states directly that the site does not use cookies — only a session ID, containing no personal data and deleted upon logout. Technical data (the time the visit began, the IP address, browser and OS type), according to the policy’s text, is collected exclusively for traffic statistics and is not linked to other data. In a separate clause, the policy states that personal data is not transferred to third parties, except in cases mandated by law. Neither Google, Google Analytics, reCAPTCHA, nor Cloudflare is named in the policy.
The capture reveals a different picture. Prior to any consent, the site contacts several third-party recipients. At +232 ms, Google reCAPTCHA connects (api.js from www.google.com, the runtime from www.gstatic.com at +382 ms). At +343 ms, the jquery-mousewheel library loads from cdnjs.cloudflare.com. At +379 ms, the classic Universal Analytics connects (analytics.js), and at +601 ms its hit, carrying the identifier UA-41385412-1, is actually sent to www.google-analytics.com/j/collect; next, at +640 ms, GA4 loads (gtag.js, G-1B1E2T7ZMX). All of these calls transmit the visitor’s IP address to third-party recipients in the USA — Google and Cloudflare.
Thus, two categorical claims made by the policy turn out to be false at once. The claim that the site “does not use cookies” does not square with the presence of Google Analytics and reCAPTCHA, which employ their own storage mechanisms. And the claim that data is not transferred to third parties is directly disproven by the transfer of the IP address to Google and Cloudflare on every visit. Moreover, the very statistics for which the policy collects technical data are, in fact, gathered via Google Analytics — a US third-party service not mentioned in the policy.
Timing Relative to Consent
All external calls occur at +232–640 ms, with the analytics hit actually sent, all before any action by the visitor. The policy cites consent implemented via continued use of the site as the basis — but the transfer of the IP address to third-party recipients occurs unconditionally and in advance. No consent was given during the session (Set-Cookie is zero).
What Cannot Be Asserted from This Capture
Google Analytics and reCAPTCHA set their own cookies via JavaScript, which is not reflected in the zero Set-Cookie count at the HTTP header level; nevertheless, this disproves the policy’s literal statement that no cookies are used. The identifier UA-41385412-1 belongs to the deprecated Universal Analytics; the hit is sent, but whether it is processed on Google’s side cannot be established from the capture — the fact of IP address transmission did, however, occur. reCAPTCHA on a site with forms can be regarded as a protective measure; this negates neither the transfer of the IP address to Google nor the fact that it is not disclosed in the policy. Google and Cloudflare may use edge nodes within the EU; the conclusion drawn therefore concerns the recipient’s corporate affiliation (US companies), not the location of the node. Server-side processing is not visible in a browser-based capture.
Conclusion
The website of the Police of Hungary, prior to any consent, transmits the visitor’s IP address to several third-party recipients in the USA: to Google, via Google Analytics (in two versions) and reCAPTCHA, and to Cloudflare, via a library from cdnjs. Meanwhile, the authority’s own policy states directly that the site does not use cookies and does not transfer data to third parties — the capture disproves both statements, and none of the actual recipients is named in the policy. For a national law-enforcement authority, the transfer of the IP address to undisclosed third-party recipients in the USA by default, on every visit, and contrary to the direct statements of its own policy, constitutes a violation of the requirements concerning disclosure of recipients, cross-border transfer, and the proper sequencing of consent. The remedy is within the operator’s control: host statistics on a self-managed solution (such as local Matomo) instead of Google Analytics, host the library locally, load reCAPTCHA only on pages containing forms and after consent, disable the deprecated Universal Analytics identifier, and bring the policy into line with reality.
8886cbb5d6e17221dc59babf98f27bff02b9cd8643691ad415ff07c587a36f44Where to file: Hungarian National Authority for Data Protection (NAIH) — file a complaint online →
To: Hungarian National Authority for Data Protection (NAIH) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website police.hu. 2. Circumstances I visited the website police.hu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) The police's privacy notice (adatvédelmi tájékoztató) states directly that the site does not use cookies (only a session ID containing no personal data) and that personal data is not transferred to third parties. The capture disproves this: prior to consent, Google Analytics loads (the deprecated UA-41385412-1 and GA4 G-1B1E2T7ZMX, with a hit sent to www.google-analytics.com/j/collect at +601 ms), as does Google reCAPTCHA (www.google.com/recaptcha at +232 ms and the runtime from www.gstatic.com at +382 ms) and the jquery-mousewheel library from cdnjs.cloudflare.com (+343 ms). All of these transmit the visitor's IP address to third-party recipients in the USA (Google and Cloudflare). None of them is named in the policy, and the statements 'we do not use cookies' and 'we do not transfer data to third parties' directly contradict actual behavior. 2) Google Analytics, reCAPTCHA, and cdnjs fire at +232–640 ms, before any action by the visitor, and the UA hit is actually sent. The policy cites consent as the legal basis (GDPR Art. 6(1)(a)), implemented via continued use of the site — but the transfer of the IP address to third-party recipients in the USA occurred before any choice was made. Set-Cookie across the session is zero. Full technical documentation is published at: https://gdpru.eu/en/audits/hu-police-hu/ 3. Provisions violated GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients, cross-border transfer, and contradiction with the policy; ePrivacy (Hungarian implementation) — trackers prior to consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]