Technical audit · 2026-05-31

hiqa.ie

HIQA — Health Information and Quality Authority of Ireland

HIQA — Ireland's health and social care quality regulator. 81 requests, 8 domains. GA4 sends a collect request before the Cookiebot banner. Campaign Monitor (12 requests) loads an email-subscription form without consent. Two GTM IDs run in parallel. Fonts and Font Awesome are hosted locally. The document in the archive is not a cookie policy.

Timeline of the leak

+67 ms · before the banner
consent.cookiebot.com/uc.js — the Cookiebot SDK. Simultaneously, Drupal's GTM/gtag module begins loading.
+92 ms · before the banner
www.googletagmanager.com/gtag/js?id=G-L4D89K6CE0 — the GA4 script loads. In parallel: www.googletagmanager.com/gtm.js?id=GTM-T5LKDTW — the GTM container.
+214–219 ms · Cookiebot
consentcdn.cookiebot.com — configuration.js, settings.json, bc-v4.min.html, cc.js. The Cookiebot banner initializes.
+497 ms · prior to consent
region1.google-analytics.com/g/collect — a GA4 tracking request: tid=G-L4D89K6CE0, gtm=45je65r2v883400750. Data is transmitted to the USA.
+514 ms · prior to consent
cmemailmarketing.co.uk — 12 requests: the Campaign Monitor iframe carrying the subscription form loads in full. jQuery, Bootstrap DatePicker, cm-canvas.js, Form.js.
+977 ms · prior to consent
cdnjs.cloudflare.com — Font Awesome 4.7.0 CSS. The Cloudflare CDN.

Declared versus actual

+ Google Analytics GA4 (G-L4D89K6CE0) — not mentioned in the document supplied — не заявлен
+ Google Tag Manager (GTM-T5LKDTW) — not mentioned — не заявлен
+ Campaign Monitor (cmemailmarketing.co.uk) — not mentioned — не заявлен
+ Cookiebot — not mentioned — не заявлен
+ jsDelivr, Cloudflare cdnjs — not mentioned — не заявлен

Transfer timings

+92 ms www.googletagmanager.com

gtag/js GA4 G-L4D89K6CE0 + GTM-T5LKDTW. USA.

+216 ms consent.cookiebot.com

Cookiebot cc.js. UUID d924c445.

+497 ms region1.google-analytics.com

GA4 g/collect. gcs=G100. USA.

+514 ms cmemailmarketing.co.uk

Campaign Monitor iframe. 12 requests. UK.

+977 ms cdnjs.cloudflare.com

Font Awesome 4.7.0 CSS. Cloudflare.

Detected trackers

Indicators of GDPR non-compliance

Context

HIQA (the Health Information and Quality Authority) is Ireland’s body responsible for inspecting and regulating the quality of health and social care services: hospitals, nursing homes, and children’s residential centers. HAR: 81 requests, 8 domains. 59 requests go to www.hiqa.ie — the Roboto, Roboto Condensed, Font Awesome, and HIQA icon fonts are all hosted locally. Sensitivity: high.

Two GTM IDs in parallel

At +92 ms, two requests fire to www.googletagmanager.com: gtag/js?id=G-L4D89K6CE0 (a direct GA4 connection via gtag) and gtm.js?id=GTM-T5LKDTW (the GTM container). Drupal’s google_tag module powers both connections. Having two parallel GA4 integrations — one via gtag and one via GTM — is an unusual configuration that can lead to duplicate event submission. GA4 sends a full tracking request to region1.google-analytics.com (+497 ms) before the Cookiebot banner has finished initializing.

At +514 ms, HIQA’s home page loads an embedded iframe carrying the email-subscription form, hosted at cmemailmarketing.co.uk/su885809414/frm5. Campaign Monitor is a British CRM and email-marketing platform. The iframe loads a full web-application stack: Modernizr, jQuery, Bootstrap DatePicker, cm-canvas.js, Common.js, Form.js, spinner.gif — 12 requests in total. Each request transmits the visitor’s IP address to Campaign Monitor’s servers in the UK. The newsletter subscription form is functionality a visitor would activate voluntarily — but the iframe loads on every home-page visit, regardless of the visitor’s intent and without their consent.

The ODP document provided contains the text of the “HIQA Protected Disclosures Policy” — a whistleblowing procedure. This is neither a cookie policy nor a privacy notice for the website. Whether declared practices match the site’s actual architecture cannot be assessed from the document supplied.

Architectural discipline regarding fonts

HIQA hosts all fonts locally: Roboto v29, Roboto Condensed v24 (three weights), a custom icon font (hiqa.ttf), and Font Awesome 6.x webfonts — all served from www.hiqa.ie. This is the correct approach for fonts, eliminating the transmission of IP addresses to Google. The contrast with the Cloudflare cdnjs call (+977 ms) for Font Awesome 4.7.0 is all the more notable: an older version of the very same Font Awesome loads from an external CDN.

None of the 81 requests sets a cookie via Set-Cookie.

Conclusion

hiqa.ie commits violations on two fronts: analytics (GA4 firing before the Cookiebot banner) and functionality (the Campaign Monitor iframe loading on every visit without consent). For a body that inspects service quality and standards compliance in healthcare, its own site’s failure to meet GDPR standards is an institutional contradiction. Fixing Campaign Monitor requires a single step: move the iframe behind the consent banner, or replace it with a static, lazy-loaded form.

Evidence
Original (audit)
HAR file: ie/hiqa-ie-2026-05-31.har
SHA-256: eec43542db868927ff8768402ffbb3426d5c5fc18dd718581dca878bdbc26fa2
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Data Protection Commission (DPC)dataprotection.ie

To: Data Protection Commission (DPC)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website hiqa.ie.

2. Circumstances
I visited the website hiqa.ie and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 31 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) GA4 (G-L4D89K6CE0, gtag/js) loads at +92 ms. GTM (GTM-T5LKDTW, gtm.js) loads simultaneously (+92 ms). GA4 sends a tracking request to region1.google-analytics.com/g/collect at +497 ms. Cookiebot's cc.js loads at +216 ms, but the banner initializes after the GA4 collect request. The user is already being tracked by GA4 before the consent banner has finished loading.

2) At +514 ms, cmemailmarketing.co.uk loads an embedded iframe carrying HIQA's newsletter subscription form. 12 requests go to Campaign Monitor's servers in the UK: Modernizr, jQuery, CSS, Bootstrap DatePicker, cm-canvas.js, Common.js, Form.js. Campaign Monitor is a British CRM/email-marketing platform. Visitors' personal data (IP address, user agent, fingerprint) is transmitted on every home-page load — prior to consent.

3) The document in the archive — the HIQA Protected Disclosures Policy — is not a cookie policy or privacy notice for the website. Specific web technical tools (GA4, GTM, Campaign Monitor) are not documented in any of the materials available.

Full technical documentation is published at: https://gdpru.eu/en/audits/ie-hiqa-ie/

3. Provisions violated
GDPR Art. 6(1), Art. 7; ePrivacy Regulations (SI 336/2011); GDPR Art. 6(1) — Campaign Monitor subscription form prior to consent; GDPR Art. 13(1)(e)

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]