gov.ie — the main portal of the Irish government. 15 requests, 3 domains — all Irish. No Google, no GTM, no advertising networks. Fonts, icons, and CSS are all local, served from assets.gov.ie. The sole external tracker is a government-run Matomo instance. It activates without a consent banner.
Timeline of the leak
Declared versus actual
Transfer timings
Matomo JS tr4ck3rj. A government-run domain. idsite=1.
Matomo PHP tr4ck3rp. Tracking request. Cookieless.
Detected trackers
- A government-run Matomo instance (track.analytics.services.gov.ie)
Indicators of GDPR non-compliance
- GDPR Art. 7; ePrivacy Regulations (SI 336/2011) — cookieless tracking without consenttrack.analytics.services.gov.ie/tr4ck3rj loads at +76 ms and sends a tracking request to /tr4ck3rp at +123 ms — on the very first page load, with no consent banner and no user interaction whatsoever. The policy declares cookieless tracking with no PII. Nevertheless, the mere fact that visit data (IP address, user agent, URL, timestamps) is transmitted to an external server occurs prior to consent. The ePrivacy Regulations apply not only to cookies but to any access to, or storage of information on, a user's terminal equipment.
- GDPR Art. 5(1)(a) — transparencyThe policy warns that Matomo 'may capture and store any PII entered using the search feature on gov.ie. This can occur if users include names, email addresses, or other personal data in their search queries.' This is honest risk disclosure, rare among the sites reviewed in this series. However, the presence of this risk in the absence of a banner or opt-in mechanism compounds the violation: the user cannot opt out of analytics before interacting with the site.
Context
gov.ie is the central information portal of the Government of Ireland, run by the Department of Public Expenditure, Infrastructure, Public Service Reform and Digitalisation. HAR: 15 requests, 3 domains. 12 requests go to assets.gov.ie (the government’s CDN for static resources), 1 to www.gov.ie, and 2 to track.analytics.services.gov.ie.
Architectural discipline
gov.ie demonstrates a government architecture built with privacy requirements in mind: the Lato and Material Symbols fonts are hosted on assets.gov.ie, not on Google Fonts. Design-system CSS, all JS modules, and icons are hosted locally. There is no Google Tag Manager, no Google Analytics, no Facebook, and no third-party library CDN. The sole external connection is a government-run Matomo instance on the domain analytics.services.gov.ie.
Matomo without a banner — a systemic choice
The privacy policy describes Matomo honestly and in detail: cookieless tracking, no PII in standard requests, IP anonymization. This is considerably better than most sites in the Irish series, where analytics goes unmentioned entirely. But Matomo launches on the very first page load — there is no banner, no opt-in mechanism, and no way to decline before tracking begins.
This is the same model seen at revenue.ie and the OGCIO: government infrastructure, a cookieless mode, conscientious documentation — but activation prior to consent. Cookieless tracking does not exempt a site from the requirements of the ePrivacy Regulations: the directive and its Irish implementation (SI 336/2011) apply to any access to, or storage of information on, a user’s terminal equipment, regardless of whether cookies are used.
Disclosure of the PII risk in search
One paragraph of the policy deserves particular attention: Matomo “may capture and store any PII entered using the search feature on gov.ie. This can occur if users include names, email addresses, or other personal data in their search queries. We advise users not to enter personal or sensitive information into the search bar.” This is a rare case of a government body honestly warning about a specific risk of personal-data capture via an analytics tool. This kind of transparency is worth noting. At the same time, it makes the absence of an opt-in mechanism more conspicuous: the user is warned of the risk but has no technical means of protecting themselves from it.
Set-Cookie — zero
None of the 15 requests sets a cookie via Set-Cookie. Matomo operates in a fully cookieless mode — consistent with the declared policy.
Conclusion
gov.ie, the country’s main government portal, embodies a state approach to privacy architecture: local resources, self-hosted analytics infrastructure, and an honest and detailed policy. The sole violation — the absence of an opt-in mechanism for Matomo — is procedural in nature and reflects a systemic choice made across the entire gov.ie platform. Of all the Irish government sites reviewed in this series, gov.ie comes closest to a correct architecture: one step remains — adding a consent banner ahead of the Matomo request.
617f9e13b7eda3cc02fe6ab131229fc4d8d5b37fc7783d2b3917c981b4c15387Where to file: Data Protection Commission (DPC) — dataprotection.ie
To: Data Protection Commission (DPC) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website gov.ie. 2. Circumstances I visited the website gov.ie and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 31 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) track.analytics.services.gov.ie/tr4ck3rj loads at +76 ms and sends a tracking request to /tr4ck3rp at +123 ms — on the very first page load, with no consent banner and no user interaction whatsoever. The policy declares cookieless tracking with no PII. Nevertheless, the mere fact that visit data (IP address, user agent, URL, timestamps) is transmitted to an external server occurs prior to consent. The ePrivacy Regulations apply not only to cookies but to any access to, or storage of information on, a user's terminal equipment. 2) The policy warns that Matomo 'may capture and store any PII entered using the search feature on gov.ie. This can occur if users include names, email addresses, or other personal data in their search queries.' This is honest risk disclosure, rare among the sites reviewed in this series. However, the presence of this risk in the absence of a banner or opt-in mechanism compounds the violation: the user cannot opt out of analytics before interacting with the site. Full technical documentation is published at: https://gdpru.eu/en/audits/ie-gov-ie/ 3. Provisions violated GDPR Art. 7; ePrivacy Regulations (SI 336/2011) — cookieless tracking without consent; GDPR Art. 5(1)(a) — transparency 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]