The Ministry of Finance of Lithuania — 28 requests, 5 domains. Before consent, Google Fonts (IP to Google, US) and Cloudflare Web Analytics with an RUM beacon load. The lrv.lt platform applies a consent model, but these third-party requests bypass it and are not named in the available materials.
Timeline of the leak
Declared versus actual
Transfer timings
Google Fonts (Public Sans). Google, US.
Cloudflare Web Analytics beacon + RUM.
Google font files. Google, US.
Detected trackers
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com)
- Cloudflare Web Analytics (static.cloudflareinsights.com)
Indicators of GDPR non-compliance
- GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and transferBefore consent, Google Fonts loads (fonts.googleapis.com/css2 and fonts.gstatic.com, the Public Sans font, +582 ms), transmitting the visitor's IP to Google (US), and Cloudflare Web Analytics (static.cloudflareinsights.com/beacon.min.js, +584 ms, with a POST beacon to /cdn-cgi/rum). The lrv.lt platform applies a consent model (necessary cookies — without consent, others — with consent), but these third-party requests do not fall under 'necessary' and are not named in the available materials.
- ePrivacy (Lithuanian implementation) — third-party resources before consentGoogle Fonts and Cloudflare Web Analytics fire at +582–584 ms, before any choice. Zero Set-Cookie headers for the entire session. The provided document is an accessibility statement, and the link to cookie settings within it leads to a non-existent page (404 error).
Context
finmin.lrv.lt is the site of the Ministry of Finance of the Republic of Lithuania (Finansų ministerija), hosted on the shared government platform lrv.lt. The short domain finmin.lt redirects to it. The data controller is the ministry. The document provided is an accessibility statement (Prieinamumo paraiška); it does not contain a separate privacy policy, and the link to cookie settings leads to a page with a 404 error. Scan: 28 requests, 5 domains, captured in a clean browser.
Who receives data directly (before consent)
Google (US) — IP via Google Fonts; Cloudflare — IP and RUM data via a beacon.
Declared versus actual
The government platform lrv.lt, on which the ministry’s site is hosted, applies a consent model: necessary cookies are set automatically without consent, while others require the user’s consent; the platform has separate cookie and privacy policies. The document provided within this audit, however, is an accessibility statement, and following the link to cookie settings within it leads to a non-existent page.
The scan shows that two third-party services fire before consent that do not fall under “necessary.” At +582 ms, Google Fonts loads (the Public Sans font from fonts.googleapis.com and fonts.gstatic.com), transmitting the visitor’s IP address to Google (US). At +584 ms, Cloudflare Web Analytics loads (static.cloudflareinsights.com/beacon.min.js), and Real User Monitoring data goes out via a POST request to /cdn-cgi/rum. The session state, meanwhile, is one of no consent: not a single cookie was set during the entire session, and no user choice was made. Both services constitute transmission of data to external recipients (Google and Cloudflare) before consent, and neither is named in the available materials.
Timing relative to consent
Google Fonts and Cloudflare Web Analytics load at +582–584 ms, at the very start of the session, before any choice. Consent was not given during the session (zero Set-Cookie headers).
What cannot be claimed from this scan
The scan covers the homepage. Google and Cloudflare may use edge nodes within the EU, so the conclusion regarding the recipients’ affiliation is based on company origin (US companies). Cloudflare Web Analytics operates without cookies; the point of discrepancy is the transmission of IP and RUM data to an external recipient before consent, and the non-disclosure of the services. A separate cookie policy for the lrv.lt platform may contain a list of services; the accessibility statement provided contains no such information, and the link to cookie settings leads to an error. Server-side processing is not visible in a browser-based scan.
Conclusion
The Ministry of Finance of Lithuania’s site transmits the visitor’s IP to Google (via Google Fonts) and to Cloudflare (via Web Analytics with an RUM beacon) before consent. The lrv.lt platform declares a consent model, but these third-party requests bypass it and are not disclosed in the materials provided; on top of that, the link to cookie settings leads to a non-existent page. Transmitting IP to external recipients in the US before consent and failing to disclose the services constitute a violation of the requirements on consent, disclosure of recipients, and cross-border transfer. Remediation: host fonts locally on the site’s own domain, forgo external Cloudflare web analytics before consent or replace it with a solution within the platform’s own perimeter, restore a working link to cookie settings, and disclose the services in use in the policy.
fc44c5c58c5edd448f0998be505176dd5483cd1ad87f5e29503f10860b37d144Where to file: State Data Protection Inspectorate (ADA) — ada.lt
To: State Data Protection Inspectorate (ADA) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website finmin.lrv.lt. 2. Circumstances I visited the website finmin.lrv.lt and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) Before consent, Google Fonts loads (fonts.googleapis.com/css2 and fonts.gstatic.com, the Public Sans font, +582 ms), transmitting the visitor's IP to Google (US), and Cloudflare Web Analytics (static.cloudflareinsights.com/beacon.min.js, +584 ms, with a POST beacon to /cdn-cgi/rum). The lrv.lt platform applies a consent model (necessary cookies — without consent, others — with consent), but these third-party requests do not fall under 'necessary' and are not named in the available materials. 2) Google Fonts and Cloudflare Web Analytics fire at +582–584 ms, before any choice. Zero Set-Cookie headers for the entire session. The provided document is an accessibility statement, and the link to cookie settings within it leads to a non-existent page (404 error). Full technical documentation is published at: https://gdpru.eu/en/audits/lt-finmin-lrv-lt/ 3. Provisions violated GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and transfer; ePrivacy (Lithuanian implementation) — third-party resources before consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]