Technical audit · 2026-06-15

bns.lt

Baltic News Service

The Baltic News Service, BNS — 106 requests, 10 domains. Two Google Analytics properties, Gemius audience measurement, and Google Fonts fire before consent; the Cookie-Script consent manager loads only after trackers have already started. None of these services is named in the short policy.

Timeline of the leak

+254 ms · fonts and libraries
fonts.googleapis.com (Google Fonts) and cdnjs.cloudflare.com — fonts and a library.
+265 ms · GTM and Gemius
www.googletagmanager.com/gtm.js (GTM-N8JLV9HQ) and galv.hit.gemius.pl/xgemius.min.js — the tag container and Gemius audience measurement.
+714 ms · Sentry
o4507460727930880.ingest.de.sentry.io — Sentry error monitoring (European ingest).
+1226 ms · consent manager (delayed)
cdn.cookie-script.com — Cookie-Script loads only after trackers have already started, and does not hold them back.
+2063–2090 ms · GA4 page_view before consent
region1.google-analytics.com/g/collect — a page_view event for two properties (G-TMK7NHF6XW, G-EPNPX5ZP4G) goes out to Google (US).

Declared versus actual

Short policy: session cookie and aggregated IP-based statistics — заявлен
Specific services (GA4, Gemius, Sentry, Cookie-Script, Google Fonts) are not named — заявлен
+ GA4 (G-TMK7NHF6XW, G-EPNPX5ZP4G) — page_view before consent, not named — не заявлен
+ Gemius (galv.hit.gemius.pl) — audience measurement before consent, not named — не заявлен
+ Google Fonts, Sentry — before consent, not named — не заявлен
+ The Cookie-Script CMP loads after trackers have already started — не заявлен

Transfer timings

+266 ms galv.hit.gemius.pl

Gemius — audience measurement.

+714 ms ingest.de.sentry.io

Sentry — error monitoring. European ingest.

+2063 ms region1.google-analytics.com

GA4 page_view (two properties). Google, US.

Detected trackers

Indicators of GDPR non-compliance

Context

bns.lt is the site of BNS (Baltic News Service), one of the leading news agencies in the Baltic states. The operator is UAB BNS. Privacy rules (privatumo taisyklės) of approximately 3,800 characters were provided, covering bns.lt and bnsplius.lt. Scan: 106 requests, 10 domains, captured in a clean browser.

Google (US) — the GA4 page_view event and fonts; Gemius (Poland/EU) — audience measurement.

Declared versus actual

BNS’s privacy rules are short and, with respect to cookies, are limited to mentioning a session cookie that the browser deletes at the end of the session, and stating that IP is recorded to maintain visit statistics and is used only in aggregated statistical form. The policy does not name a single third-party measurement or advertising tool, nor does it describe a cookie-consent mechanism.

The scan shows a substantially broader set of services firing before consent. At +265 ms, Google Tag Manager launches (GTM-N8JLV9HQ); at +266 ms, Gemius audience measurement (galv.hit.gemius.pl); at +714 ms, Sentry error monitoring (European ingest); in parallel, Google Fonts and a library from cdnjs load. At +2063–2090 ms, two Google Analytics 4 properties (G-TMK7NHF6XW and G-EPNPX5ZP4G) send a page_view event with the address bns.lt and a client identifier. The Cookie-Script consent manager, meanwhile, only loads at +1226 ms — already after GTM, Gemius, Sentry, and fonts have started — and does not hold them back in the scan. The session state is one of no consent: not a single cookie was set during the entire session, and no user choice was made. None of these services is named in the policy.

Trackers start from +265 ms, the consent manager only from +1226 ms, and GA4 events go out at +2063 ms. The loading order is such that consent could not technically have preceded some of the services firing; consent was in fact not given during the session (zero Set-Cookie headers).

What cannot be claimed from this scan

The scan covers the homepage. The GA4 client identifier is not reproduced in full in this publication. Gemius (infrastructure in Poland) and Sentry (European ingest) are processed within the EU; the question of cross-border transfer to the US relates primarily to Google. Recipients may use edge nodes within the EU, so the conclusion regarding their affiliation is based on company origin. Server-side processing is not visible in a browser-based scan.

Conclusion

BNS’s site launches two Google Analytics properties, Gemius audience measurement, Sentry monitoring, and Google Fonts before consent, while the Cookie-Script consent manager loads only after trackers have already started and does not hold them back. The short privacy policy mentions only a session cookie and aggregated statistics, and names none of the actual services. Analytics and audience measurement firing before consent, data transfer to Google (US), and the absence of service disclosure constitute a violation of the requirements on consent, disclosure of recipients, and cross-border transfer. Remediation: reconfigure Cookie-Script to load first and genuinely hold GTM, GA4, Gemius, Sentry, and fonts back until consent; host fonts locally; expand the policy with a list of the services actually in use.

Evidence
Original (audit)
HAR file: lt/bns-lt-2026-06-15.har
SHA-256: fd5cf3eeaff56d458aa184420949537bbd0eafb175dccdc3d548a33e61eed702
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: State Data Protection Inspectorate (ADA)ada.lt

To: State Data Protection Inspectorate (ADA)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website bns.lt.

2. Circumstances
I visited the website bns.lt and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The Cookie-Script consent manager only loads at +1226 ms — already after trackers have started. Before it, Google Tag Manager (GTM-N8JLV9HQ, +265 ms), Gemius audience measurement (galv.hit.gemius.pl, +266 ms), Sentry, and Google Fonts fire, and at +2063–2090 ms two Google Analytics 4 properties (G-TMK7NHF6XW and G-EPNPX5ZP4G) send a page_view event. Zero Set-Cookie headers for the entire session, and no user choice was made.

2) IP and page_view event data is transmitted to Google (US) via GA4 and fonts, and audience data to Gemius. BNS's policy is short and mentions only a session cookie and aggregated IP-based statistics; neither Google Analytics, Gemius, Sentry, Cookie-Script, nor Google Fonts is named in it.

Full technical documentation is published at: https://gdpru.eu/en/audits/lt-bns-lt/

3. Provisions violated
ePrivacy (Lithuanian implementation) + GDPR Art. 6(1) — trackers before consent; GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and transfer

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]