Technical audit · 2026-05-31

cro.ie

Companies Registration Office of Ireland — the state business registration authority

Ireland's state Companies Registration Office — 30 requests, 5 domains. The GA collect call goes out 26 ms before the Complianz CMP. UserWay (an accessibility widget) fires without consent. The policy explicitly excludes company register data from GDPR's scope — a correct legal position.

Timeline of the leak

+155 ms · before the banner
GA4's gtag.js (G-J5Q235KJ2S) loads.
+251 ms · before the banner
GA4 collect — visit data is transmitted to Google, USA.
+256 ms · before the banner
UserWay (cdn.userway.org) — the accessibility widget. USA.
+277 ms · banner
Complianz GDPR Premium (complianz.min.js) — the CMP is ready.

Declared versus actual

+ UserWay (cdn.userway.org) — не заявлен

Transfer timings

+155 ms www.googletagmanager.com

GA4 G-J5Q235KJ2S — gtag

+251 ms region1.google-analytics.com

GA4 collect — 26 ms before Complianz

+256 ms cdn.userway.org

UserWay accessibility widget. USA

Detected trackers

Indicators of GDPR non-compliance

Context

The Companies Registration Office (CRO) is Ireland’s state company register. It accepts incorporation documents, registers businesses, and publishes data on directors and shareholders. It is under DPC oversight. A WordPress site with the Complianz GDPR Premium plugin. Cloudflare WAF. HAR: 30 requests, 5 domains.

The privacy policy draws a clear distinction: data submitted to the CRO under the Companies Act 2014 and the Registration of Business Names Act 1963 is public by law and does not fall under the Data Protection Acts. This is a legally sound position: a public company register, by definition, contains data accessible to everyone. The policy applies only to data the user voluntarily provides when using the site (search, payment).

GA ahead of Complianz — a 26 ms gap

The GA4 collect call goes out at +251 ms. Complianz is ready at +277 ms. The gap — 26 ms — is minimal, but sufficient for the first pageview to be sent without consent. Complianz GDPR Premium supports blocking scripts until consent is given — the cookieblocker.min.css setting is already active, but GA4 is not blocked.

UserWay — an accessibility widget

cdn.userway.org is UserWay, an American accessibility widget (WCAG compliance). It adds a toolbar for people with disabilities: font, contrast, and cursor adjustments. It transmits the visitor’s IP address to the USA without consent. A European alternative would be AccessMonster (EU) or a self-hosted WCAG implementation without external JavaScript.

CSP — GA is explicitly permitted

content-security-policy: default-src 'self' https://www.google-analytics.com https://www.googletagmanager.com... — Google Analytics is explicitly listed in the CSP. This means the inclusion of GA is deliberate, not accidental.

Conclusion

The CRO is a state register with a correct legal position stated in its policy. The GA collect call precedes Complianz by 26 ms — a technical issue fixable through the plugin’s settings. UserWay firing without consent is a separate concern. Priority: block GA via the Complianz cookieblocker until consent is given.

Evidence
Original (audit)
HAR file: ie/cro-ie-2026-05-31.har
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Data Protection Commission (DPC)dataprotection.ie

To: Data Protection Commission (DPC)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website cro.ie.

2. Circumstances
I visited the website cro.ie and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 31 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) GA4's gtag.js (+155 ms) and the GA collect call (+251 ms) load before the Complianz CMP (+277 ms). Visit data is transmitted to Google (USA) 26 ms before the consent banner appears.

2) UserWay (cdn.userway.org/widget.js, +256 ms) — an American accessibility-widget service (AccessiBe Group). Loads without consent. Transmits the visitor's IP address to the USA.

Full technical documentation is published at: https://gdpru.eu/en/audits/ie-cro-ie/

3. Provisions violated
GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 6(1)

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]