Technical audit · 2026-05-31

sfi.ie

Science Foundation Ireland — Ireland's National Research Funding Agency

Science Foundation Ireland — the state agency funding STEM research. 36 requests, 6 domains. GTM loads 156 ms before the consent manager appears. The privacy policy is dated 2018 — not a single specific external service is named.

Timeline of the leak

+119 ms · before the banner
fonts.googleapis.com — two families: Source Sans Pro (7 weights) and Roboto Slab (4 weights). The user's IP address goes to Google's servers in the USA.
+119 ms · before the banner
maxcdn.bootstrapcdn.com — Font Awesome 4.7.0 CSS from MaxCDN. USA.
+152 ms · before the banner
www.googletagmanager.com (GTM-K87TNXJ) — the GTM container loads without consent.
+164–165 ms · before the banner
fonts.gstatic.com — 5 woff2 font files (Source Sans Pro + Roboto Slab). Google's servers, USA.
+165 ms · before the banner
maxcdn.bootstrapcdn.com — fontawesome-webfont.woff2. MaxCDN, USA.
+308 ms · manager initialization
unpkg.com/dept-cookie-management@0.1.6/dist/index.js — the consent management tool loads. By this point, GTM has already been running for 156 ms.

Declared versus actual

+ Google Tag Manager (GTM-K87TNXJ) — not mentioned — не заявлен
+ Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — not mentioned — не заявлен
+ BootstrapCDN / MaxCDN (maxcdn.bootstrapcdn.com) — not mentioned — не заявлен
+ unpkg.com (dept-cookie-management) — not mentioned — не заявлен

Transfer timings

+119 ms fonts.googleapis.com

Source Sans Pro + Roboto Slab. USA.

+119 ms maxcdn.bootstrapcdn.com

Font Awesome 4.7.0 CSS + woff2. USA.

+152 ms www.googletagmanager.com

GTM-K87TNXJ. USA.

+164 ms fonts.gstatic.com

5 woff2 font files. USA.

+308 ms unpkg.com

dept-cookie-management v0.1.6. An npm CDN.

Detected trackers

Indicators of GDPR non-compliance

Context

SFI (Science Foundation Ireland) is the state fund financing basic and applied STEM research, established in 2003. It administers grant programs for universities, research centers, and industry partners. HAR: 36 requests, 6 domains. 25 requests go to the first-party domain www.sfi.ie, with the remaining 11 going to five external domains.

The site uses dept-cookie-management — a JavaScript consent-management package published on npm and loaded from the unpkg.com CDN. It appears in the HAR at +308 ms. GTM-K87TNXJ loads at +152 ms. The gap is 156 ms, during which the GTM container is already initialized and capable of activating any tags configured within it. The loading order is inverted: the consent tool arrives after the tool it is supposed to control.

At +119 ms, two CSS requests fire to fonts.googleapis.com: Source Sans Pro (100, 200, 300, 400, 600, 700, 900) and Roboto Slab (100, 200, 300, 400). At +164–165 ms, five woff2 files load from fonts.gstatic.com. Each request transmits the visitor’s IP address to Google’s servers in the USA. Both font families are standard open-source fonts, available for local hosting. Google Fonts is not mentioned in the privacy policy.

BootstrapCDN and Font Awesome 4.7.0

Font Awesome 4.7.0 — a version released in 2016 — loads from maxcdn.bootstrapcdn.com (a CDN owned by MaxCDN, USA). This is another external recipient of visitors’ IP addresses, unmentioned in the policy. Like Google Fonts, the Font Awesome icons could be hosted locally.

The 2018 privacy policy

The privacy policy is dated 9 May 2018 — the date the GDPR took effect. Over the following eight years, the site changed its architecture, added a GTM container, and connected external CDNs — but the policy was never updated. It names no specific data recipient: in place of names, only categories (“analytics providers,” “search engine providers”) appear. Under Art. 13(1)(e), the data subject must be given information about specific recipients, or at least their categories — generic descriptions without names do not meet this requirement.

None of the 36 requests sets a cookie via Set-Cookie. Cookies are also absent from outgoing requests.

Conclusion

sfi.ie reproduces a pattern typical of the Irish series: GTM firing without consent, Google Fonts loading without consent, and an outdated policy naming no specific recipients. What sets it apart is an inverted loading order: the consent manager appears 156 ms after GTM, rendering the concept of consent technically meaningless. The fix is standard: move GTM behind the banner, host the fonts and Font Awesome locally, and update the policy with an actual list of recipients and a current date.

Evidence
Original (audit)
HAR file: ie/sfi-ie-2026-05-31.har
SHA-256: 96efa3f34b6601819522360c791c3bb076b3d329cb902f35e712e29126624770
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Data Protection Commission (DPC)dataprotection.ie

To: Data Protection Commission (DPC)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website sfi.ie.

2. Circumstances
I visited the website sfi.ie and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 31 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) Google Tag Manager (GTM-K87TNXJ) loads at +152 ms without consent. Google Fonts (fonts.googleapis.com) — two font families (Source Sans Pro, Roboto Slab) — loads at +119 ms, transmitting the user's IP address to Google's servers in the USA. BootstrapCDN (maxcdn.bootstrapcdn.com) loads at +119 ms. The consent management tool (unpkg.com/dept-cookie-management@0.1.6) loads at +308 ms — 189 ms after GTM launches.

2) The privacy policy is dated 9 May 2018 and names no specific external service: not GTM, not Google Analytics, not Google Fonts, not BootstrapCDN, not unpkg. Only generic categories ('analytics providers,' 'search engine providers') are mentioned, without identifying recipients.

Full technical documentation is published at: https://gdpru.eu/en/audits/ie-sfi-ie/

3. Provisions violated
GDPR Art. 6(1), Art. 7; ePrivacy Regulations (SI 336/2011); GDPR Art. 13(1)(e)

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]