The Ministry of Environment of Lithuania — 37 requests, 8 domains. Before consent, Google Analytics (GA4 and a legacy Universal Analytics, via GTM), Google Fonts, and Cloudflare Web Analytics load, transmitting the visitor's IP to Google (US). No consent manager fired.
Timeline of the leak
Declared versus actual
Transfer timings
GTM with UA-190913104-1 (legacy) and GA4. Google, US.
Cloudflare Web Analytics beacon.
GA4 page_view (G-VKWL5JFJFK). Google, US.
Detected trackers
- Google Analytics 4 (G-VKWL5JFJFK) + Universal Analytics (UA-190913104-1) + GTM
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com)
- Cloudflare Web Analytics (static.cloudflareinsights.com)
Indicators of GDPR non-compliance
- ePrivacy (Lithuanian implementation) + GDPR Chapter V — consent and transferBefore consent, Google Tag Manager loads with two tags — legacy Universal Analytics (UA-190913104-1, +493 ms) and GA4 (G-VKWL5JFJFK, +1092 ms) — after which, at +1229 ms, GA4 sends a page_view event (am.lrv.lt/lt/) to region1.google-analytics.com. Google Fonts (+492 ms) and Cloudflare Web Analytics (+496 ms, with a POST beacon to /cdn-cgi/rum) also load. The visitor's IP is transmitted to Google (US). No consent manager fired in the scan, zero Set-Cookie headers for the entire session, and no user choice was made.
- GDPR Art. 13(1)(e) — disclosure of recipientsA privacy policy was not provided as part of the package. The lrv.lt platform applies a consent model (necessary cookies — without consent, others — with consent), but Google Analytics, Google Fonts, and Cloudflare Web Analytics, all of which actually run, do not fall under 'necessary' and are not disclosed in the available materials.
Context
am.lrv.lt is the site of the Ministry of Environment of the Republic of Lithuania (Aplinkos ministerija), hosted on the shared government platform lrv.lt. The short domain am.lt redirects to it. The data controller is the ministry. A privacy policy was not provided as part of the package. Scan: 37 requests, 8 domains, captured in a clean browser.
Who receives data directly (before consent)
Google (US) — the GA4 page_view event, legacy Universal Analytics, and fonts; Cloudflare — RUM data via a beacon.
Declared versus actual
The government platform lrv.lt applies a consent model: necessary cookies are set automatically, others require consent. No separate policy was provided within this audit.
The scan shows a broader set of services than would be minimally necessary, and all of them fire before consent. At +493 ms, Google Tag Manager loads the legacy Universal Analytics tag (UA-190913104-1), and at +1092 ms, the GA4 tag (G-VKWL5JFJFK); at +1229 ms, GA4 sends a page_view event with the address am.lrv.lt/lt/ to region1.google-analytics.com. In parallel, Google Fonts loads at +492 ms, and Cloudflare Web Analytics at +496 ms, followed by a POST RUM beacon to /cdn-cgi/rum. All of these requests transmit the visitor’s IP address to Google (US) and Cloudflare. The session state is one of no consent: no consent manager fired, not a single cookie was set during the entire session, and no user choice was made. The presence of the legacy Universal Analytics tag, discontinued by Google in 2023, indicates a long-standing tracking configuration that has not been reviewed.
Timing relative to consent
Google Fonts, GTM, and Cloudflare Web Analytics load at +492–496 ms, and GA4 sends its event at +1229 ms. Consent was not given during the session (zero Set-Cookie headers).
What cannot be claimed from this scan
The scan covers the homepage. The GA4 client identifier is not reproduced in full in this publication. In 2026, Universal Analytics no longer performs standard data collection, but its tag loads and contacts Google’s servers. Google and Cloudflare may use edge nodes within the EU, so the conclusion regarding recipient affiliation is based on company origin. No policy was provided. Server-side processing is not visible in a browser-based scan.
Conclusion
The Ministry of Environment of Lithuania’s site loads Google Analytics before consent — both the current GA4 version with a page_view transmission and legacy Universal Analytics — as well as Google Fonts and Cloudflare Web Analytics, transmitting the visitor’s IP to Google (US) and Cloudflare. The consent manager does not hold these services back in the scan, and the lrv.lt platform declares a consent model that they bypass. Transmitting data to recipients in the US before consent and failing to disclose the services constitute a violation of the requirements on consent, disclosure of recipients, and cross-border transfer. Remediation: remove the legacy Universal Analytics tag, make GA4 subject to consent, host fonts locally, forgo external Cloudflare web analytics before consent, and publish a cookie policy with a list of recipients.
87c31f42418495ad7225e377ab2102888ec789ebd5a27ebd2021f5e26d9f208fWhere to file: State Data Protection Inspectorate (ADA) — ada.lt
To: State Data Protection Inspectorate (ADA) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website am.lrv.lt. 2. Circumstances I visited the website am.lrv.lt and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) Before consent, Google Tag Manager loads with two tags — legacy Universal Analytics (UA-190913104-1, +493 ms) and GA4 (G-VKWL5JFJFK, +1092 ms) — after which, at +1229 ms, GA4 sends a page_view event (am.lrv.lt/lt/) to region1.google-analytics.com. Google Fonts (+492 ms) and Cloudflare Web Analytics (+496 ms, with a POST beacon to /cdn-cgi/rum) also load. The visitor's IP is transmitted to Google (US). No consent manager fired in the scan, zero Set-Cookie headers for the entire session, and no user choice was made. 2) A privacy policy was not provided as part of the package. The lrv.lt platform applies a consent model (necessary cookies — without consent, others — with consent), but Google Analytics, Google Fonts, and Cloudflare Web Analytics, all of which actually run, do not fall under 'necessary' and are not disclosed in the available materials. Full technical documentation is published at: https://gdpru.eu/en/audits/lt-am-lrv-lt/ 3. Provisions violated ePrivacy (Lithuanian implementation) + GDPR Chapter V — consent and transfer; GDPR Art. 13(1)(e) — disclosure of recipients 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]