The Baltic News Service, BNS — 106 requests, 10 domains. Two Google Analytics properties, Gemius audience measurement, and Google Fonts fire before consent; the Cookie-Script consent manager loads only after trackers have already started. None of these services is named in the short policy.
Timeline of the leak
Declared versus actual
Transfer timings
Gemius — audience measurement.
Sentry — error monitoring. European ingest.
GA4 page_view (two properties). Google, US.
Detected trackers
- Google Analytics 4 (G-TMK7NHF6XW, G-EPNPX5ZP4G) + GTM
- Gemius (galv.hit.gemius.pl) — audience measurement
- Sentry (EU ingest) — error monitoring
- Google Fonts (fonts.gstatic.com)
- Cookie-Script (cdn.cookie-script.com) — CMP (loads late)
Indicators of GDPR non-compliance
- ePrivacy (Lithuanian implementation) + GDPR Art. 6(1) — trackers before consentThe Cookie-Script consent manager only loads at +1226 ms — already after trackers have started. Before it, Google Tag Manager (GTM-N8JLV9HQ, +265 ms), Gemius audience measurement (galv.hit.gemius.pl, +266 ms), Sentry, and Google Fonts fire, and at +2063–2090 ms two Google Analytics 4 properties (G-TMK7NHF6XW and G-EPNPX5ZP4G) send a page_view event. Zero Set-Cookie headers for the entire session, and no user choice was made.
- GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and transferIP and page_view event data is transmitted to Google (US) via GA4 and fonts, and audience data to Gemius. BNS's policy is short and mentions only a session cookie and aggregated IP-based statistics; neither Google Analytics, Gemius, Sentry, Cookie-Script, nor Google Fonts is named in it.
Context
bns.lt is the site of BNS (Baltic News Service), one of the leading news agencies in the Baltic states. The operator is UAB BNS. Privacy rules (privatumo taisyklės) of approximately 3,800 characters were provided, covering bns.lt and bnsplius.lt. Scan: 106 requests, 10 domains, captured in a clean browser.
Who receives data directly (before consent)
Google (US) — the GA4 page_view event and fonts; Gemius (Poland/EU) — audience measurement.
Declared versus actual
BNS’s privacy rules are short and, with respect to cookies, are limited to mentioning a session cookie that the browser deletes at the end of the session, and stating that IP is recorded to maintain visit statistics and is used only in aggregated statistical form. The policy does not name a single third-party measurement or advertising tool, nor does it describe a cookie-consent mechanism.
The scan shows a substantially broader set of services firing before consent. At +265 ms, Google Tag Manager launches (GTM-N8JLV9HQ); at +266 ms, Gemius audience measurement (galv.hit.gemius.pl); at +714 ms, Sentry error monitoring (European ingest); in parallel, Google Fonts and a library from cdnjs load. At +2063–2090 ms, two Google Analytics 4 properties (G-TMK7NHF6XW and G-EPNPX5ZP4G) send a page_view event with the address bns.lt and a client identifier. The Cookie-Script consent manager, meanwhile, only loads at +1226 ms — already after GTM, Gemius, Sentry, and fonts have started — and does not hold them back in the scan. The session state is one of no consent: not a single cookie was set during the entire session, and no user choice was made. None of these services is named in the policy.
Timing relative to consent
Trackers start from +265 ms, the consent manager only from +1226 ms, and GA4 events go out at +2063 ms. The loading order is such that consent could not technically have preceded some of the services firing; consent was in fact not given during the session (zero Set-Cookie headers).
What cannot be claimed from this scan
The scan covers the homepage. The GA4 client identifier is not reproduced in full in this publication. Gemius (infrastructure in Poland) and Sentry (European ingest) are processed within the EU; the question of cross-border transfer to the US relates primarily to Google. Recipients may use edge nodes within the EU, so the conclusion regarding their affiliation is based on company origin. Server-side processing is not visible in a browser-based scan.
Conclusion
BNS’s site launches two Google Analytics properties, Gemius audience measurement, Sentry monitoring, and Google Fonts before consent, while the Cookie-Script consent manager loads only after trackers have already started and does not hold them back. The short privacy policy mentions only a session cookie and aggregated statistics, and names none of the actual services. Analytics and audience measurement firing before consent, data transfer to Google (US), and the absence of service disclosure constitute a violation of the requirements on consent, disclosure of recipients, and cross-border transfer. Remediation: reconfigure Cookie-Script to load first and genuinely hold GTM, GA4, Gemius, Sentry, and fonts back until consent; host fonts locally; expand the policy with a list of the services actually in use.
fd5cf3eeaff56d458aa184420949537bbd0eafb175dccdc3d548a33e61eed702Where to file: State Data Protection Inspectorate (ADA) — ada.lt
To: State Data Protection Inspectorate (ADA) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website bns.lt. 2. Circumstances I visited the website bns.lt and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The Cookie-Script consent manager only loads at +1226 ms — already after trackers have started. Before it, Google Tag Manager (GTM-N8JLV9HQ, +265 ms), Gemius audience measurement (galv.hit.gemius.pl, +266 ms), Sentry, and Google Fonts fire, and at +2063–2090 ms two Google Analytics 4 properties (G-TMK7NHF6XW and G-EPNPX5ZP4G) send a page_view event. Zero Set-Cookie headers for the entire session, and no user choice was made. 2) IP and page_view event data is transmitted to Google (US) via GA4 and fonts, and audience data to Gemius. BNS's policy is short and mentions only a session cookie and aggregated IP-based statistics; neither Google Analytics, Gemius, Sentry, Cookie-Script, nor Google Fonts is named in it. Full technical documentation is published at: https://gdpru.eu/en/audits/lt-bns-lt/ 3. Provisions violated ePrivacy (Lithuanian implementation) + GDPR Art. 6(1) — trackers before consent; GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and transfer 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]