Technical audit · 2026-06-15

finmin.lrv.lt

Ministry of Finance of Lithuania

The Ministry of Finance of Lithuania — 28 requests, 5 domains. Before consent, Google Fonts (IP to Google, US) and Cloudflare Web Analytics with an RUM beacon load. The lrv.lt platform applies a consent model, but these third-party requests bypass it and are not named in the available materials.

Timeline of the leak

+0 ms · redirect
finmin.lt redirects to finmin.lrv.lt (the ministry's own domain on the lrv.lt platform).
+582 ms · Google Fonts before consent
fonts.googleapis.com/css2 and fonts.gstatic.com — the Public Sans font. The visitor's IP goes out to Google (US).
+584 ms · Cloudflare Analytics before consent
static.cloudflareinsights.com/beacon.min.js — Cloudflare Web Analytics; RUM data goes out via a POST request to /cdn-cgi/rum.
documentation incomplete
An accessibility statement was provided; the link to cookie settings leads to a 404 page.

Declared versus actual

The lrv.lt platform applies a consent model (necessary cookies — automatic, others — with consent) — заявлен
A Slapukų policy and a Privatumo policy exist on the platform — заявлен
+ Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — IP to Google (US), before consent, not named in the available materials — не заявлен
+ Cloudflare Web Analytics (static.cloudflareinsights.com) — before consent, not named — не заявлен
+ The provided document is an accessibility statement; the link to cookie settings leads to a 404 — не заявлен

Transfer timings

+582 ms fonts.googleapis.com

Google Fonts (Public Sans). Google, US.

+584 ms static.cloudflareinsights.com

Cloudflare Web Analytics beacon + RUM.

+651 ms fonts.gstatic.com

Google font files. Google, US.

Detected trackers

Indicators of GDPR non-compliance

Context

finmin.lrv.lt is the site of the Ministry of Finance of the Republic of Lithuania (Finansų ministerija), hosted on the shared government platform lrv.lt. The short domain finmin.lt redirects to it. The data controller is the ministry. The document provided is an accessibility statement (Prieinamumo paraiška); it does not contain a separate privacy policy, and the link to cookie settings leads to a page with a 404 error. Scan: 28 requests, 5 domains, captured in a clean browser.

Google (US) — IP via Google Fonts; Cloudflare — IP and RUM data via a beacon.

Declared versus actual

The government platform lrv.lt, on which the ministry’s site is hosted, applies a consent model: necessary cookies are set automatically without consent, while others require the user’s consent; the platform has separate cookie and privacy policies. The document provided within this audit, however, is an accessibility statement, and following the link to cookie settings within it leads to a non-existent page.

The scan shows that two third-party services fire before consent that do not fall under “necessary.” At +582 ms, Google Fonts loads (the Public Sans font from fonts.googleapis.com and fonts.gstatic.com), transmitting the visitor’s IP address to Google (US). At +584 ms, Cloudflare Web Analytics loads (static.cloudflareinsights.com/beacon.min.js), and Real User Monitoring data goes out via a POST request to /cdn-cgi/rum. The session state, meanwhile, is one of no consent: not a single cookie was set during the entire session, and no user choice was made. Both services constitute transmission of data to external recipients (Google and Cloudflare) before consent, and neither is named in the available materials.

Google Fonts and Cloudflare Web Analytics load at +582–584 ms, at the very start of the session, before any choice. Consent was not given during the session (zero Set-Cookie headers).

What cannot be claimed from this scan

The scan covers the homepage. Google and Cloudflare may use edge nodes within the EU, so the conclusion regarding the recipients’ affiliation is based on company origin (US companies). Cloudflare Web Analytics operates without cookies; the point of discrepancy is the transmission of IP and RUM data to an external recipient before consent, and the non-disclosure of the services. A separate cookie policy for the lrv.lt platform may contain a list of services; the accessibility statement provided contains no such information, and the link to cookie settings leads to an error. Server-side processing is not visible in a browser-based scan.

Conclusion

The Ministry of Finance of Lithuania’s site transmits the visitor’s IP to Google (via Google Fonts) and to Cloudflare (via Web Analytics with an RUM beacon) before consent. The lrv.lt platform declares a consent model, but these third-party requests bypass it and are not disclosed in the materials provided; on top of that, the link to cookie settings leads to a non-existent page. Transmitting IP to external recipients in the US before consent and failing to disclose the services constitute a violation of the requirements on consent, disclosure of recipients, and cross-border transfer. Remediation: host fonts locally on the site’s own domain, forgo external Cloudflare web analytics before consent or replace it with a solution within the platform’s own perimeter, restore a working link to cookie settings, and disclose the services in use in the policy.

Evidence
Original (audit)
HAR file: lt/finmin-lrv-lt-2026-06-15.har
SHA-256: fc44c5c58c5edd448f0998be505176dd5483cd1ad87f5e29503f10860b37d144
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: State Data Protection Inspectorate (ADA)ada.lt

To: State Data Protection Inspectorate (ADA)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website finmin.lrv.lt.

2. Circumstances
I visited the website finmin.lrv.lt and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) Before consent, Google Fonts loads (fonts.googleapis.com/css2 and fonts.gstatic.com, the Public Sans font, +582 ms), transmitting the visitor's IP to Google (US), and Cloudflare Web Analytics (static.cloudflareinsights.com/beacon.min.js, +584 ms, with a POST beacon to /cdn-cgi/rum). The lrv.lt platform applies a consent model (necessary cookies — without consent, others — with consent), but these third-party requests do not fall under 'necessary' and are not named in the available materials.

2) Google Fonts and Cloudflare Web Analytics fire at +582–584 ms, before any choice. Zero Set-Cookie headers for the entire session. The provided document is an accessibility statement, and the link to cookie settings within it leads to a non-existent page (404 error).

Full technical documentation is published at: https://gdpru.eu/en/audits/lt-finmin-lrv-lt/

3. Provisions violated
GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and transfer; ePrivacy (Lithuanian implementation) — third-party resources before consent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]