courts.ie
The Courts Service of Ireland — 32 requests, 7 domains. GTM and Hotjar load simultaneously, before the site's own cookie manager. Hotjar records visitor behavior on the courts service's site without consent.
Timeline of the leak
Declared versus actual
Transfer timings
GTM-5GT3G58P
Hotjar session recording — without consent
GA4 collect
Detected trackers
- Google Tag Manager (GTM-5GT3G58P)
- Google Analytics GA4 (G-QZ4BZPW2JP)
- Hotjar (hotjar-3260934)
- Google Fonts (fonts.googleapis.com) — Material Symbols
Indicators of GDPR non-compliance
- GDPR Art. 6(1), Art. 5(1)(a)GTM (+210 ms) and Hotjar (+210 ms) load simultaneously — 15 ms before the site's own cookies-manager.js (+195 ms). Initialization order: trackers before the CMP. The GA collect call goes out at +5351 ms, unblocked.
- GDPR Art. 6(1)(a) — HotjarHotjar records mouse movements, clicks, and scrolling (session recording and heatmaps). It activates without consent, simultaneously with GTM. For the website of a court service, this is a sensitive category of visitor.
Context
The Courts Service of Ireland is the state body responsible for the operation of Ireland’s courts. It manages court registers, publishes rulings, and provides information on hearings. It is under the oversight of Ireland’s DPC. HAR: 32 requests, 7 domains.
Hotjar on the courts service’s site
static.hotjar.com/c/hotjar-3260934.js (+210 ms) — Hotjar, an American session-recording and heatmap service. It loads without consent, simultaneously with GTM. Hotjar records every visitor’s mouse movements, clicks, and scrolling. For a site visited by people looking into court cases, hearing lists, and registers, this represents a sensitive category of behavioral data being transmitted to the USA without consent.
The site’s own cookies-manager — does not block
courts.ie/ResourcePackages/cookies-manager/cookies-manager.js (+195 ms) — the site’s own cookie-management implementation. It loads before GTM and Hotjar (+195 ms versus +210 ms), but does not block their initialization. This is the same architectural problem seen at firmenbuch.at and auftrag.at — a CMP is present but does not stop trackers until consent is given.
The policy — current, with some nuances
The privacy policy mentions: YouTube in privacy-enhanced mode (cookies set only upon a click), and the right to access, rectify, object to, and erase data. The section on court records is clear: data from court proceedings falls under the control of the courts themselves (not the Courts Service), governed by Section 158 of the Data Protection Act 2018. Hotjar is not mentioned in the policy.
Conclusion
The Courts Service has its own cookie manager, but it does not block trackers. GTM and Hotjar load without consent. For a government body within the judicial system, running Hotjar without consent is an undesirable choice. Blocking trackers until consent is given via correct configuration of the cookies-manager, along with removing Hotjar or placing it behind the consent barrier, is the fix.
Where to file: Data Protection Commission (DPC) — dataprotection.ie
To: Data Protection Commission (DPC) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website courts.ie. 2. Circumstances I visited the website courts.ie and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 31 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) GTM (+210 ms) and Hotjar (+210 ms) load simultaneously — 15 ms before the site's own cookies-manager.js (+195 ms). Initialization order: trackers before the CMP. The GA collect call goes out at +5351 ms, unblocked. 2) Hotjar records mouse movements, clicks, and scrolling (session recording and heatmaps). It activates without consent, simultaneously with GTM. For the website of a court service, this is a sensitive category of visitor. Full technical documentation is published at: https://gdpru.eu/en/audits/ie-courts-ie/ 3. Provisions violated GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 6(1)(a) — Hotjar 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]