Technical audit · 2026-05-29

police.hu

Police of Hungary

The Police of Hungary (operated by the National Police Headquarters, ORFK) — 151 requests, 6 domains. Prior to any consent, the visitor's IP address is transmitted to Google (Google Analytics in two versions and reCAPTCHA) and to Cloudflare (cdnjs). The authority's own policy, meanwhile, states directly that the site does not use cookies and does not transfer data to third parties — the capture disproves both statements.

Timeline of the leak

+0 ms · portal load
Markup, scripts, and images — served from the first-party domain www.police.hu (nginx, Drupal 8). Strong HSTS (preload) is present.
+232…+382 ms · reCAPTCHA and Cloudflare prior to consent
Google reCAPTCHA (api.js from www.google.com, the runtime from www.gstatic.com) and the jquery-mousewheel library from cdnjs.cloudflare.com. The visitor's IP address is transmitted to Google and Cloudflare (USA).
+379…+640 ms · Google Analytics prior to consent
The classic analytics.js (Universal Analytics), sending a UA-41385412-1 hit to www.google-analytics.com/j/collect (+601 ms), followed by gtag.js for GA4 (G-1B1E2T7ZMX). The visitor's IP address is transmitted to Google (USA).
no consent mechanism holds back the trackers
The policy cites consent 'via use of the site' as the basis, but Google Analytics, reCAPTCHA, and cdnjs fire before and independently of any choice.
no other trackers
Facebook, advertising pixels, and session recording are absent from the capture. External calls are limited to Google Analytics, reCAPTCHA, and one library from Cloudflare.

Declared versus actual

Privacy notice (adatvédelmi tájékoztató, ORFK) — states that the site does not use cookies, only a session ID containing no personal data, deleted upon logout — declared
Technical data (IP address, browser and OS type) is collected only for statistics and is not linked to other data — declared
Stated directly: personal data is not transferred to third parties (except in cases mandated by law) — declared
Operator — Országos Rendőr-főkapitányság (ORFK, National Police Headquarters); Google, Analytics, reCAPTCHA, and Cloudflare are not named in the policy — declared
+ Google Analytics (UA-41385412-1 and GA4) — third-party recipient of IP address from the USA, prior to consent, not named in the policy; contradicts the statements about the absence of cookies and data transfer — not declared
+ Google reCAPTCHA (www.google.com, www.gstatic.com) — third-party recipient of IP address from the USA, prior to consent, not named — not declared
+ cdnjs / Cloudflare (cdnjs.cloudflare.com) — third-party recipient of IP address from the USA, prior to consent, not named — not declared

Transfer timings

+232 ms www.google.com

reCAPTCHA api.js. Google, USA.

+343 ms cdnjs.cloudflare.com

jquery-mousewheel. Cloudflare, USA.

+379 ms www.google-analytics.com

analytics.js — Universal Analytics (deprecated). Google, USA.

+382 ms www.gstatic.com

reCAPTCHA runtime. Google, USA.

+601 ms www.google-analytics.com

/j/collect — UA-41385412-1 hit sent. Google, USA.

+640 ms www.googletagmanager.com

gtag.js — GA4 (G-1B1E2T7ZMX). Google, USA.

Detected trackers

Indicators of GDPR non-compliance

Context

police.hu is the website of the Police of Hungary (Rendőrség). The operator is the National Police Headquarters (Országos Rendőr-főkapitányság, ORFK). The site is built on Drupal 8 (nginx), with strong HSTS (preload) present. Capture: 151 requests, 6 domains, recorded in a clean browser.

Google (USA) — the visitor’s IP address via Google Analytics and reCAPTCHA. Cloudflare (USA) — the visitor’s IP address via the delivery of the jquery-mousewheel library from cdnjs.

Declared versus Actual

Here the discrepancy is especially stark, because the policy makes categorical and verifiable claims. The police’s privacy notice states directly that the site does not use cookies — only a session ID, containing no personal data and deleted upon logout. Technical data (the time the visit began, the IP address, browser and OS type), according to the policy’s text, is collected exclusively for traffic statistics and is not linked to other data. In a separate clause, the policy states that personal data is not transferred to third parties, except in cases mandated by law. Neither Google, Google Analytics, reCAPTCHA, nor Cloudflare is named in the policy.

The capture reveals a different picture. Prior to any consent, the site contacts several third-party recipients. At +232 ms, Google reCAPTCHA connects (api.js from www.google.com, the runtime from www.gstatic.com at +382 ms). At +343 ms, the jquery-mousewheel library loads from cdnjs.cloudflare.com. At +379 ms, the classic Universal Analytics connects (analytics.js), and at +601 ms its hit, carrying the identifier UA-41385412-1, is actually sent to www.google-analytics.com/j/collect; next, at +640 ms, GA4 loads (gtag.js, G-1B1E2T7ZMX). All of these calls transmit the visitor’s IP address to third-party recipients in the USA — Google and Cloudflare.

Thus, two categorical claims made by the policy turn out to be false at once. The claim that the site “does not use cookies” does not square with the presence of Google Analytics and reCAPTCHA, which employ their own storage mechanisms. And the claim that data is not transferred to third parties is directly disproven by the transfer of the IP address to Google and Cloudflare on every visit. Moreover, the very statistics for which the policy collects technical data are, in fact, gathered via Google Analytics — a US third-party service not mentioned in the policy.

All external calls occur at +232–640 ms, with the analytics hit actually sent, all before any action by the visitor. The policy cites consent implemented via continued use of the site as the basis — but the transfer of the IP address to third-party recipients occurs unconditionally and in advance. No consent was given during the session (Set-Cookie is zero).

What Cannot Be Asserted from This Capture

Google Analytics and reCAPTCHA set their own cookies via JavaScript, which is not reflected in the zero Set-Cookie count at the HTTP header level; nevertheless, this disproves the policy’s literal statement that no cookies are used. The identifier UA-41385412-1 belongs to the deprecated Universal Analytics; the hit is sent, but whether it is processed on Google’s side cannot be established from the capture — the fact of IP address transmission did, however, occur. reCAPTCHA on a site with forms can be regarded as a protective measure; this negates neither the transfer of the IP address to Google nor the fact that it is not disclosed in the policy. Google and Cloudflare may use edge nodes within the EU; the conclusion drawn therefore concerns the recipient’s corporate affiliation (US companies), not the location of the node. Server-side processing is not visible in a browser-based capture.

Conclusion

The website of the Police of Hungary, prior to any consent, transmits the visitor’s IP address to several third-party recipients in the USA: to Google, via Google Analytics (in two versions) and reCAPTCHA, and to Cloudflare, via a library from cdnjs. Meanwhile, the authority’s own policy states directly that the site does not use cookies and does not transfer data to third parties — the capture disproves both statements, and none of the actual recipients is named in the policy. For a national law-enforcement authority, the transfer of the IP address to undisclosed third-party recipients in the USA by default, on every visit, and contrary to the direct statements of its own policy, constitutes a violation of the requirements concerning disclosure of recipients, cross-border transfer, and the proper sequencing of consent. The remedy is within the operator’s control: host statistics on a self-managed solution (such as local Matomo) instead of Google Analytics, host the library locally, load reCAPTCHA only on pages containing forms and after consent, disable the deprecated Universal Analytics identifier, and bring the policy into line with reality.

Evidence
Original (audit)
HAR file: hu/police-hu-2026-05-29.har
SHA-256: 8886cbb5d6e17221dc59babf98f27bff02b9cd8643691ad415ff07c587a36f44
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Hungarian National Authority for Data Protection (NAIH)file a complaint online →

To: Hungarian National Authority for Data Protection (NAIH)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website police.hu.

2. Circumstances
I visited the website police.hu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) The police's privacy notice (adatvédelmi tájékoztató) states directly that the site does not use cookies (only a session ID containing no personal data) and that personal data is not transferred to third parties. The capture disproves this: prior to consent, Google Analytics loads (the deprecated UA-41385412-1 and GA4 G-1B1E2T7ZMX, with a hit sent to www.google-analytics.com/j/collect at +601 ms), as does Google reCAPTCHA (www.google.com/recaptcha at +232 ms and the runtime from www.gstatic.com at +382 ms) and the jquery-mousewheel library from cdnjs.cloudflare.com (+343 ms). All of these transmit the visitor's IP address to third-party recipients in the USA (Google and Cloudflare). None of them is named in the policy, and the statements 'we do not use cookies' and 'we do not transfer data to third parties' directly contradict actual behavior.

2) Google Analytics, reCAPTCHA, and cdnjs fire at +232–640 ms, before any action by the visitor, and the UA hit is actually sent. The policy cites consent as the legal basis (GDPR Art. 6(1)(a)), implemented via continued use of the site — but the transfer of the IP address to third-party recipients in the USA occurred before any choice was made. Set-Cookie across the session is zero.

Full technical documentation is published at: https://gdpru.eu/en/audits/hu-police-hu/

3. Provisions violated
GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients, cross-border transfer, and contradiction with the policy; ePrivacy (Hungarian implementation) — trackers prior to consent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]