A government statistics agency — the body one would expect to understand data better than anyone. HAR: 122 requests, 11 domains. Google Tag Manager loads prior to consent. Seven external CDNs are not mentioned in the privacy policy. Seven of eight external services are American companies.
Timeline of the leak
Declared versus actual
Transfer timings
Highcharts 9.3.3 — a charting library. USA.
jsDelivr — 46 requests. An open-source library CDN.
GTM with ID G-M5K0ZBH6F8. USA.
Cloudflare CDN — cookieconsent2.
jQuery CDN. USA.
DataTables CDN — 7 requests.
BootstrapCDN. Font Awesome 4.7.0.
Google Fonts — Roboto Slab + Roboto. USA.
Google Fonts font files. USA.
Detected trackers
- Google Tag Manager / Google Analytics (www.googletagmanager.com)
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com)
- jsDelivr CDN (cdn.jsdelivr.net)
- cdnjs / Cloudflare (cdnjs.cloudflare.com)
- Highcharts CDN (code.highcharts.com)
- jQuery CDN (code.jquery.com)
- BootstrapCDN / MaxCDN (maxcdn.bootstrapcdn.com)
- DataTables CDN (cdn.datatables.net)
Indicators of GDPR non-compliance
- GDPR Art. 6(1), Art. 5(1)(a)Google Tag Manager (www.googletagmanager.com) loads at +126 ms — before any user interaction with the consent banner. Google Fonts (fonts.googleapis.com, fonts.gstatic.com) loads at +154–264 ms without consent, transmitting the user's IP address to Google's servers in the USA.
- GDPR Art. 13(1)(e)The privacy policy mentions Google Analytics and one cookie from Highcharts (__cfduid). Seven external CDN domains are not mentioned in the policy: jsDelivr, cdnjs.cloudflare.com, code.highcharts.com, code.jquery.com, maxcdn.bootstrapcdn.com, cdn.datatables.net, cdn.cso.ie. Data recipients are not disclosed in full.
- GDPR Art. 5(1)(c) — data minimization46 requests to jsDelivr and 7 to cdn.datatables.net load visualization libraries (Chart.js, Leaflet, Highcharts, PapaParse, Turf.js) for every home-page visitor. These resources belong to visualization tooling and may not be required when merely browsing the home page.
Context
The CSO (Central Statistics Office) is Ireland’s state body responsible for collecting, processing, and publishing official statistics, based in Cork. HAR: 122 requests, 11 domains. Of these, 53 requests go to the first-party domain www.cso.ie, 2 to cdn.cso.ie, and 67 to nine external domains, seven of which are American.
Google Tag Manager prior to consent
At the +126 ms mark, before any user interaction with the banner, www.googletagmanager.com loads with the ID G-M5K0ZBH6F8. GTM is a container: depending on tag configuration, it can activate Google Analytics, remarketing pixels, and other scripts. The fact that GTM loads prior to consent means the user’s IP address is transmitted to Google’s servers in the USA without a legal basis under GDPR Art. 6(1).
Google Fonts without consent
At +154 ms — fonts.googleapis.com; at +264 ms — fonts.gstatic.com. Two font families load: Roboto Slab and Roboto. Each request to Google’s servers transmits the visitor’s IP address. Since the Munich court ruling (2022) and subsequent positions taken by German and Austrian supervisory authorities, connecting to Google Fonts without consent and without local hosting has been treated as a violation of Art. 6(1). Both fonts can be hosted locally — there is no technical obstacle to doing so.
Seven external CDNs outside the policy
The CSO’s privacy policy names exactly two data recipients: Google Analytics and Highcharts (with an explanation of Cloudflare’s __cfduid cookie). Seven other external domains — jsDelivr, cdnjs.cloudflare.com, code.jquery.com, maxcdn.bootstrapcdn.com, cdn.datatables.net, fonts.googleapis.com, fonts.gstatic.com — are not mentioned in the policy. Under Art. 13(1)(e), the data subject must be informed of all recipients or categories of recipients of their data. Seven unmentioned domains means seven unnamed recipients.
An architectural choice
46 requests to jsDelivr load a visualization stack: Chart.js, Leaflet, Highcharts, PapaParse, Turf.js, Moment.js, Esri Leaflet, and the CSO’s own PxWidget. These libraries power interactive infographics and maps — functionality genuinely needed on pages featuring visualizations. Loading them on the home page means that every visitor, including those who arrived simply for news or contact information, leaves a trace in the logs of nine external servers. Technically, this is a matter of lazy loading: the libraries could be included only on the pages where they are actually used.
Set-Cookie — zero
Despite all this external loading, none of the 122 requests in the HAR sets a cookie via Set-Cookie. Cookies are also absent from outgoing requests. GTM is loaded, but no cookies are recorded in the HAR — possibly because blocking is implemented at the GTM configuration level. This partially softens the picture, but does not eliminate the fact that external resources load prior to consent.
Conclusion
The CSO is a government body that works with data as its core function. The privacy policy was drafted in 2020 and does not reflect the site’s actual set of external dependencies: of nine external domains, two are mentioned. Google Tag Manager loads prior to consent. Google Fonts transmits IP addresses to servers in the USA without consent. Cookies, meanwhile, are not set — a fact worth recording. Fixing this requires three steps: move GTM behind the consent banner, host fonts locally, and update the privacy policy with a complete list of recipients.
3564c7d61ac788dbdf41e4d18efd8bcb56c949bead9106fec9a2607871fc5d42Where to file: Data Protection Commission (DPC) — dataprotection.ie
To: Data Protection Commission (DPC) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website cso.ie. 2. Circumstances I visited the website cso.ie and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 31 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) Google Tag Manager (www.googletagmanager.com) loads at +126 ms — before any user interaction with the consent banner. Google Fonts (fonts.googleapis.com, fonts.gstatic.com) loads at +154–264 ms without consent, transmitting the user's IP address to Google's servers in the USA. 2) The privacy policy mentions Google Analytics and one cookie from Highcharts (__cfduid). Seven external CDN domains are not mentioned in the policy: jsDelivr, cdnjs.cloudflare.com, code.highcharts.com, code.jquery.com, maxcdn.bootstrapcdn.com, cdn.datatables.net, cdn.cso.ie. Data recipients are not disclosed in full. 3) 46 requests to jsDelivr and 7 to cdn.datatables.net load visualization libraries (Chart.js, Leaflet, Highcharts, PapaParse, Turf.js) for every home-page visitor. These resources belong to visualization tooling and may not be required when merely browsing the home page. Full technical documentation is published at: https://gdpru.eu/en/audits/ie-cso-ie/ 3. Provisions violated GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 13(1)(e); GDPR Art. 5(1)(c) — data minimization 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]