sfi.ie
Science Foundation Ireland — the state agency funding STEM research. 36 requests, 6 domains. GTM loads 156 ms before the consent manager appears. The privacy policy is dated 2018 — not a single specific external service is named.
Timeline of the leak
Declared versus actual
Transfer timings
Source Sans Pro + Roboto Slab. USA.
Font Awesome 4.7.0 CSS + woff2. USA.
GTM-K87TNXJ. USA.
5 woff2 font files. USA.
dept-cookie-management v0.1.6. An npm CDN.
Detected trackers
- Google Tag Manager (www.googletagmanager.com, GTM-K87TNXJ)
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com)
- BootstrapCDN / MaxCDN (maxcdn.bootstrapcdn.com)
- unpkg CDN (unpkg.com)
Indicators of GDPR non-compliance
- GDPR Art. 6(1), Art. 7; ePrivacy Regulations (SI 336/2011)Google Tag Manager (GTM-K87TNXJ) loads at +152 ms without consent. Google Fonts (fonts.googleapis.com) — two font families (Source Sans Pro, Roboto Slab) — loads at +119 ms, transmitting the user's IP address to Google's servers in the USA. BootstrapCDN (maxcdn.bootstrapcdn.com) loads at +119 ms. The consent management tool (unpkg.com/dept-cookie-management@0.1.6) loads at +308 ms — 189 ms after GTM launches.
- GDPR Art. 13(1)(e)The privacy policy is dated 9 May 2018 and names no specific external service: not GTM, not Google Analytics, not Google Fonts, not BootstrapCDN, not unpkg. Only generic categories ('analytics providers,' 'search engine providers') are mentioned, without identifying recipients.
Context
SFI (Science Foundation Ireland) is the state fund financing basic and applied STEM research, established in 2003. It administers grant programs for universities, research centers, and industry partners. HAR: 36 requests, 6 domains. 25 requests go to the first-party domain www.sfi.ie, with the remaining 11 going to five external domains.
The consent manager loads after GTM
The site uses dept-cookie-management — a JavaScript consent-management package published on npm and loaded from the unpkg.com CDN. It appears in the HAR at +308 ms. GTM-K87TNXJ loads at +152 ms. The gap is 156 ms, during which the GTM container is already initialized and capable of activating any tags configured within it. The loading order is inverted: the consent tool arrives after the tool it is supposed to control.
Google Fonts — 7 files prior to consent
At +119 ms, two CSS requests fire to fonts.googleapis.com: Source Sans Pro (100, 200, 300, 400, 600, 700, 900) and Roboto Slab (100, 200, 300, 400). At +164–165 ms, five woff2 files load from fonts.gstatic.com. Each request transmits the visitor’s IP address to Google’s servers in the USA. Both font families are standard open-source fonts, available for local hosting. Google Fonts is not mentioned in the privacy policy.
BootstrapCDN and Font Awesome 4.7.0
Font Awesome 4.7.0 — a version released in 2016 — loads from maxcdn.bootstrapcdn.com (a CDN owned by MaxCDN, USA). This is another external recipient of visitors’ IP addresses, unmentioned in the policy. Like Google Fonts, the Font Awesome icons could be hosted locally.
The 2018 privacy policy
The privacy policy is dated 9 May 2018 — the date the GDPR took effect. Over the following eight years, the site changed its architecture, added a GTM container, and connected external CDNs — but the policy was never updated. It names no specific data recipient: in place of names, only categories (“analytics providers,” “search engine providers”) appear. Under Art. 13(1)(e), the data subject must be given information about specific recipients, or at least their categories — generic descriptions without names do not meet this requirement.
Set-Cookie — zero
None of the 36 requests sets a cookie via Set-Cookie. Cookies are also absent from outgoing requests.
Conclusion
sfi.ie reproduces a pattern typical of the Irish series: GTM firing without consent, Google Fonts loading without consent, and an outdated policy naming no specific recipients. What sets it apart is an inverted loading order: the consent manager appears 156 ms after GTM, rendering the concept of consent technically meaningless. The fix is standard: move GTM behind the banner, host the fonts and Font Awesome locally, and update the policy with an actual list of recipients and a current date.
96efa3f34b6601819522360c791c3bb076b3d329cb902f35e712e29126624770Where to file: Data Protection Commission (DPC) — dataprotection.ie
To: Data Protection Commission (DPC)
From: [Your name], [contact email]
1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website sfi.ie.
2. Circumstances
I visited the website sfi.ie and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 31 May 2026 (open methodology, reproducible measurements) documents the following indications:
1) Google Tag Manager (GTM-K87TNXJ) loads at +152 ms without consent. Google Fonts (fonts.googleapis.com) — two font families (Source Sans Pro, Roboto Slab) — loads at +119 ms, transmitting the user's IP address to Google's servers in the USA. BootstrapCDN (maxcdn.bootstrapcdn.com) loads at +119 ms. The consent management tool (unpkg.com/dept-cookie-management@0.1.6) loads at +308 ms — 189 ms after GTM launches.
2) The privacy policy is dated 9 May 2018 and names no specific external service: not GTM, not Google Analytics, not Google Fonts, not BootstrapCDN, not unpkg. Only generic categories ('analytics providers,' 'search engine providers') are mentioned, without identifying recipients.
Full technical documentation is published at: https://gdpru.eu/en/audits/ie-sfi-ie/
3. Provisions violated
GDPR Art. 6(1), Art. 7; ePrivacy Regulations (SI 336/2011); GDPR Art. 13(1)(e)
4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.
5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.
[Date] [Signature / name]