Technical audit · 2026-05-31

seai.ie

Sustainable Energy Authority of Ireland

The Sustainable Energy Authority — a state body processing applications for housing grants and citizens' financial and medical data. 70 requests, 12 domains. DoubleClick Floodlight — an advertising remarketing pixel — activates without consent. Plus GA4, Genesys chat, and New Relic. Seven data recipients go unmentioned in the policy.

Timeline of the leak

+82 ms · before the banner
www.seai.ie/modules/contrib/google_tag/gtag.js and gtm.js — Drupal's Google Tag module loads as part of the main JS bundle.
+89 ms · before the banner
cdnjs.cloudflare.com — moment.js and moment-timezone from the Cloudflare CDN.
+113 ms · before the banner
fonts.googleapis.com — Google Fonts (Open Sans). The user's IP address is transmitted to Google's servers in the USA.
+126 ms · before the banner
www.googletagmanager.com (GTM-W4CXSS6) — the GTM container loads.
+346 ms · before the banner
www.googletagmanager.com — gtag/js GA4 G-E4HE7YKWT5 activates via GTM.
+459 ms · before the banner
www.googletagmanager.com — gtag/destination DC-9943193. DoubleClick Floodlight activates via GTM.
+519 ms · before the banner
region1.google-analytics.com/g/collect — a GA4 tracking request. USA.
+558 ms · before the banner
apps.mypurecloud.ie — the Genesys Cloud chat widget (22 requests). An American platform, on an Irish domain.
+613–660 ms · before the banner
ade.googlesyndication.com — two DoubleClick Floodlight requests: src=9943193, type=landi0, cat=seai-003. A remarketing advertising pixel on a government site.
+1582 ms · before the banner
js-agent.newrelic.com and bam.eu01.nr-data.net — the New Relic SPA agent loads and transmits session data. Two performance-monitoring requests.

Declared versus actual

Web Chat — mentioned in the policy as a means of collecting data — declared
Cookies Policy — referenced as a separate document (not supplied) — declared
+ Google Tag Manager (GTM-W4CXSS6) — not mentioned — not declared
+ Google Analytics GA4 (G-E4HE7YKWT5) — not mentioned — not declared
+ Google DoubleClick Floodlight (DC-9943193) — not mentioned — not declared
+ Genesys Cloud (apps.mypurecloud.ie) — not named specifically — not declared
+ New Relic (js-agent.newrelic.com, bam.eu01.nr-data.net) — not mentioned — not declared
+ Google Fonts (fonts.googleapis.com) — not mentioned — not declared
+ Cloudflare cdnjs — not mentioned — not declared

Transfer timings

+126 ms www.googletagmanager.com

GTM-W4CXSS6. USA.

+346 ms www.googletagmanager.com

GA4 G-E4HE7YKWT5, via GTM. USA.

+459 ms www.googletagmanager.com

DoubleClick DC-9943193, via GTM. USA.

+519 ms region1.google-analytics.com

GA4 g/collect. USA.

+558 ms apps.mypurecloud.ie

Genesys Cloud chat. 22 requests. USA/IE.

+613 ms ade.googlesyndication.com

DoubleClick Floodlight pixel. cat=seai-003. USA.

+1582 ms js-agent.newrelic.com

New Relic SPA agent. USA.

+1605 ms bam.eu01.nr-data.net

New Relic session data. EU endpoint.

Detected trackers

Indicators of GDPR non-compliance

Context

SEAI (the Sustainable Energy Authority of Ireland) is a state agency that administers energy-efficiency housing grants, processing financial data, property data, and, in certain cases, citizens’ medical data. HAR: 70 requests, 12 domains. Sensitivity: high — visitors to the site may be grant applicants submitting financial and housing data. 24 requests go to the first-party domain www.seai.ie, 9 to the CDN seaiprod.prod.acquia-sites.com — the remaining 37 go to ten external domains.

DoubleClick Floodlight on a government site

At +459 ms, gtag/destination?id=DC-9943193 activates via GTM — DoubleClick Floodlight, a Google Ads conversion-tracking tool. At +613 and +660 ms, two pixel requests fire to ade.googlesyndication.com, carrying the parameters src=9943193, type=landi0, cat=seai-003. Floodlight is a remarketing advertising tool: it tags site visitors for subsequent targeted advertising across Google’s network. The parameter npa=1 (Non-Personalized Ads) is present in the request, but the transfer of data to Google’s advertising servers occurs regardless of it. The use of a remarketing advertising pixel on the home page of a state body that processes housing-grant applications, without user consent, is the most serious violation in this HAR.

The Genesys Cloud chat widget (an American company, a customer-engagement platform) generates 22 requests to apps.mypurecloud.ie and api-cdn.mypurecloud.ie on the very first page load, without consent. The policy mentions a “Web Chat function” as a means of collecting personal data, but does not name Genesys as the platform, nor does it explain that the chat widget initializes for every visitor upon page load, regardless of whether the user intends to use it.

At +1582 ms, js-agent.newrelic.com/nr-spa-1.301.0.min.js loads — the New Relic performance-monitoring agent. At +1605 and +2302 ms, requests fire to bam.eu01.nr-data.net, carrying the identifier NRJS-63ad9662344bba3672e, transaction data, and timestamps. New Relic collects technical data about browser and session performance. It is not mentioned in the privacy policy.

None of the 70 requests sets a cookie via Set-Cookie. The trackers operate via fingerprinting and request parameters. This does not reduce the volume of data transmitted, but it does make it less visible to standard cookie audits.

Conclusion

seai.ie processes citizens’ applications for housing grants — a context demanding a high standard of data protection. The actual architecture includes a remarketing advertising pixel (DoubleClick Floodlight), dual analytics (GTM + GA4), a chat platform (Genesys), performance monitoring (New Relic), and Google Fonts — all firing without consent and undisclosed in the policy. The privacy policy (January 2026) refers to a separate Cookie Policy, which was not included in the archive. Seven external data recipients go unmentioned in the documentation available.

Evidence
Original (audit)
HAR file: ie/seai-ie-2026-05-31.har
SHA-256: ccb72e6fded036aed30dfbdc8cdd3e85782fa219e5235eee8990fac53fe59abd
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Data Protection Commission (DPC)dataprotection.ie

To: Data Protection Commission (DPC)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website seai.ie.

2. Circumstances
I visited the website seai.ie and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 31 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) GTM (GTM-W4CXSS6) loads at +126 ms without consent. Via GTM, the following activate: GA4 (G-E4HE7YKWT5, +346 ms), and DoubleClick Floodlight (DC-9943193, +459 ms) — a remarketing advertising pixel. GA4 sends a full tracking request (+519 ms), and DoubleClick sends two pixel requests to ade.googlesyndication.com (+613, +660 ms). All of this occurs prior to consent.

2) DoubleClick Floodlight (DC-9943193, cat=seai-003) is a Google Ads conversion-tracking and remarketing tool. It activates without consent on the home page of a state body. The parameter npa=1 (Non-Personalized Ads) is present in the request, but the transfer of data to ade.googlesyndication.com occurs regardless of this flag.

3) The Genesys Cloud chat widget (apps.mypurecloud.ie, 22 requests) and New Relic APM (js-agent.newrelic.com, bam.eu01.nr-data.net, 3 requests) load without consent. Genesys is an American company (part of the Salesforce ecosystem). New Relic is an American performance-monitoring company that transmits session data to bam.eu01.nr-data.net.

4) The privacy policy (January 2026) mentions Web Chat and refers to a Cookies Policy, but names none of the external services by name: GTM, GA4, DoubleClick, Genesys, New Relic, Cloudflare cdnjs, and Google Fonts are all undisclosed in the policy. Seven data recipients are undocumented.

Full technical documentation is published at: https://gdpru.eu/en/audits/ie-seai-ie/

3. Provisions violated
GDPR Art. 6(1), Art. 7; ePrivacy Regulations (SI 336/2011); GDPR Art. 6(1) — advertising remarketing on a government energy site; GDPR Art. 6(1); GDPR Art. 13(1)(e)

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]