HIQA — Ireland's health and social care quality regulator. 81 requests, 8 domains. GA4 sends a collect request before the Cookiebot banner. Campaign Monitor (12 requests) loads an email-subscription form without consent. Two GTM IDs run in parallel. Fonts and Font Awesome are hosted locally. The document in the archive is not a cookie policy.
Timeline of the leak
Declared versus actual
Transfer timings
gtag/js GA4 G-L4D89K6CE0 + GTM-T5LKDTW. USA.
Cookiebot cc.js. UUID d924c445.
GA4 g/collect. gcs=G100. USA.
Campaign Monitor iframe. 12 requests. UK.
Font Awesome 4.7.0 CSS. Cloudflare.
Detected trackers
- Google Analytics GA4 (www.googletagmanager.com, G-L4D89K6CE0)
- Google Tag Manager (www.googletagmanager.com, GTM-T5LKDTW)
- Campaign Monitor / cmemailmarketing.co.uk — an embedded subscription form
- Cookiebot CMP (consent.cookiebot.com, consentcdn.cookiebot.com)
- jsDelivr CDN (cdn.jsdelivr.net)
- Cloudflare cdnjs (cdnjs.cloudflare.com)
Indicators of GDPR non-compliance
- GDPR Art. 6(1), Art. 7; ePrivacy Regulations (SI 336/2011)GA4 (G-L4D89K6CE0, gtag/js) loads at +92 ms. GTM (GTM-T5LKDTW, gtm.js) loads simultaneously (+92 ms). GA4 sends a tracking request to region1.google-analytics.com/g/collect at +497 ms. Cookiebot's cc.js loads at +216 ms, but the banner initializes after the GA4 collect request. The user is already being tracked by GA4 before the consent banner has finished loading.
- GDPR Art. 6(1) — Campaign Monitor subscription form prior to consentAt +514 ms, cmemailmarketing.co.uk loads an embedded iframe carrying HIQA's newsletter subscription form. 12 requests go to Campaign Monitor's servers in the UK: Modernizr, jQuery, CSS, Bootstrap DatePicker, cm-canvas.js, Common.js, Form.js. Campaign Monitor is a British CRM/email-marketing platform. Visitors' personal data (IP address, user agent, fingerprint) is transmitted on every home-page load — prior to consent.
- GDPR Art. 13(1)(e)The document in the archive — the HIQA Protected Disclosures Policy — is not a cookie policy or privacy notice for the website. Specific web technical tools (GA4, GTM, Campaign Monitor) are not documented in any of the materials available.
Context
HIQA (the Health Information and Quality Authority) is Ireland’s body responsible for inspecting and regulating the quality of health and social care services: hospitals, nursing homes, and children’s residential centers. HAR: 81 requests, 8 domains. 59 requests go to www.hiqa.ie — the Roboto, Roboto Condensed, Font Awesome, and HIQA icon fonts are all hosted locally. Sensitivity: high.
Two GTM IDs in parallel
At +92 ms, two requests fire to www.googletagmanager.com: gtag/js?id=G-L4D89K6CE0 (a direct GA4 connection via gtag) and gtm.js?id=GTM-T5LKDTW (the GTM container). Drupal’s google_tag module powers both connections. Having two parallel GA4 integrations — one via gtag and one via GTM — is an unusual configuration that can lead to duplicate event submission. GA4 sends a full tracking request to region1.google-analytics.com (+497 ms) before the Cookiebot banner has finished initializing.
Campaign Monitor — 12 requests prior to consent
At +514 ms, HIQA’s home page loads an embedded iframe carrying the email-subscription form, hosted at cmemailmarketing.co.uk/su885809414/frm5. Campaign Monitor is a British CRM and email-marketing platform. The iframe loads a full web-application stack: Modernizr, jQuery, Bootstrap DatePicker, cm-canvas.js, Common.js, Form.js, spinner.gif — 12 requests in total. Each request transmits the visitor’s IP address to Campaign Monitor’s servers in the UK. The newsletter subscription form is functionality a visitor would activate voluntarily — but the iframe loads on every home-page visit, regardless of the visitor’s intent and without their consent.
The document in the archive — not a cookie policy
The ODP document provided contains the text of the “HIQA Protected Disclosures Policy” — a whistleblowing procedure. This is neither a cookie policy nor a privacy notice for the website. Whether declared practices match the site’s actual architecture cannot be assessed from the document supplied.
Architectural discipline regarding fonts
HIQA hosts all fonts locally: Roboto v29, Roboto Condensed v24 (three weights), a custom icon font (hiqa.ttf), and Font Awesome 6.x webfonts — all served from www.hiqa.ie. This is the correct approach for fonts, eliminating the transmission of IP addresses to Google. The contrast with the Cloudflare cdnjs call (+977 ms) for Font Awesome 4.7.0 is all the more notable: an older version of the very same Font Awesome loads from an external CDN.
Set-Cookie — zero
None of the 81 requests sets a cookie via Set-Cookie.
Conclusion
hiqa.ie commits violations on two fronts: analytics (GA4 firing before the Cookiebot banner) and functionality (the Campaign Monitor iframe loading on every visit without consent). For a body that inspects service quality and standards compliance in healthcare, its own site’s failure to meet GDPR standards is an institutional contradiction. Fixing Campaign Monitor requires a single step: move the iframe behind the consent banner, or replace it with a static, lazy-loaded form.
eec43542db868927ff8768402ffbb3426d5c5fc18dd718581dca878bdbc26fa2Where to file: Data Protection Commission (DPC) — dataprotection.ie
To: Data Protection Commission (DPC) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website hiqa.ie. 2. Circumstances I visited the website hiqa.ie and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 31 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) GA4 (G-L4D89K6CE0, gtag/js) loads at +92 ms. GTM (GTM-T5LKDTW, gtm.js) loads simultaneously (+92 ms). GA4 sends a tracking request to region1.google-analytics.com/g/collect at +497 ms. Cookiebot's cc.js loads at +216 ms, but the banner initializes after the GA4 collect request. The user is already being tracked by GA4 before the consent banner has finished loading. 2) At +514 ms, cmemailmarketing.co.uk loads an embedded iframe carrying HIQA's newsletter subscription form. 12 requests go to Campaign Monitor's servers in the UK: Modernizr, jQuery, CSS, Bootstrap DatePicker, cm-canvas.js, Common.js, Form.js. Campaign Monitor is a British CRM/email-marketing platform. Visitors' personal data (IP address, user agent, fingerprint) is transmitted on every home-page load — prior to consent. 3) The document in the archive — the HIQA Protected Disclosures Policy — is not a cookie policy or privacy notice for the website. Specific web technical tools (GA4, GTM, Campaign Monitor) are not documented in any of the materials available. Full technical documentation is published at: https://gdpru.eu/en/audits/ie-hiqa-ie/ 3. Provisions violated GDPR Art. 6(1), Art. 7; ePrivacy Regulations (SI 336/2011); GDPR Art. 6(1) — Campaign Monitor subscription form prior to consent; GDPR Art. 13(1)(e) 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]