The IKI supermarket chain, Lithuania — 197 requests, 12 domains. The OneTrust consent manager is present and loads, but trackers don't wait for it: before consent, Google Analytics, Google Ads and Campaign Manager, the Meta Pixel, and the Exponea platform all fire. Data goes out to Google and Meta (US) before the user's choice.
Timeline of the leak
Declared versus actual
Transfer timings
Exponea/Bloomreach — customer data platform.
Meta/Facebook SDK. US.
GA4 page_view (G-QYC21FRZS1). US.
Google Campaign Manager DC-12036474 / Google Ads AW-693009689. US.
Detected trackers
- Google Analytics 4 (G-QYC21FRZS1)
- Google Ads (AW-693009689) + Campaign Manager/DoubleClick (DC-12036474)
- Meta / Facebook Pixel
- Exponea / Bloomreach Engagement (api.exponea.com) — CDP
- Cloudflare Web Analytics
- Adobe Typekit (fonts)
- OneTrust (cdn.cookielaw.org) — CMP (not gating)
Indicators of GDPR non-compliance
- ePrivacy (Lithuanian implementation) + GDPR Art. 6(1) — trackers before consentThe OneTrust consent manager is present and loads (otSDKStub.js at +757 ms, the banner at +1588 ms), but does not hold trackers back. Before consent, the following fire: GA4 (G-QYC21FRZS1) with first_visit, session_start, and page_view events; Google Ads (AW-693009689) and Campaign Manager/DoubleClick (DC-12036474) with page_view and Floodlight activity; the Meta/Facebook SDK; the Exponea/Bloomreach Engagement platform; Cloudflare Web Analytics. Zero Set-Cookie headers for the entire session, and no user choice was made.
- GDPR Chapter V + Art. 13(1)(e) — transfer and disclosureBefore consent, data (page_view, URL, GA4 client identifier) is transmitted to Google (US) and to Meta (US), as well as to Exponea/Bloomreach. The general privacy policy provided names neither Google, Meta, Exponea, nor Adobe Typekit; the cookie description in it is minimal, with the list of trackers relegated to a separate OneTrust mechanism.
Context
iki.lt is the site of IKI, one of the largest supermarket chains in Lithuania. The operator is IKI (Palink UAB). A general privacy policy was provided (approximately 32,000 characters), devoted to processing of customer data; the cookie description in it is minimal. Scan: 197 requests, 12 domains, captured in a clean browser.
Who receives data directly (before consent)
Google (US) — GA4, Google Ads, and Campaign Manager; Meta (US) — the Facebook SDK/Pixel; Exponea/Bloomreach — a customer data platform.
Declared versus actual
The provided policy is built on consent (the term sutikimas appears 21 times) and is devoted to processing of customer data; specific measurement and advertising tools are not named in it, and the cookie description is minimal — the list of trackers is relegated to a separate OneTrust consent mechanism.
The scan shows that the consent mechanism is present, but does not hold trackers back. OneTrust loads as expected — otSDKStub.js at +757 ms, the otBannerSdk.js banner at +1588 ms, consent configuration. Nonetheless, third-party services fire independently of it and before any choice. At +1458 ms, the Exponea/Bloomreach Engagement customer data platform loads; at +2040 ms, the Meta/Facebook SDK; at +3488–3515 ms, Google Analytics 4 (identifier G-QYC21FRZS1) with first_visit, session_start, and page_view events; and at +3571–3578 ms, Google Ads (AW-693009689) and Campaign Manager/DoubleClick (DC-12036474) with page_view events and Floodlight activity. Additionally, Cloudflare Web Analytics and Adobe Typekit fonts run. The session state, meanwhile, is one of no consent: not a single cookie was set during the entire session, and no user choice was made. Thus, advertising, analytics, and the customer data platform transmit data to Google (US), Meta (US), and Exponea before consent, and these services aren’t named in the provided policy.
Timing relative to consent
OneTrust loads at +757–1588 ms, but in parallel with it and after it, up to +3578 ms, Exponea, Meta, GA4, and Google Ads fire. Consent was not given during the session (zero Set-Cookie headers) — trackers do not wait for the choice.
What cannot be claimed from this scan
The scan covers the homepage. The GA4 client identifier is not reproduced in full in this publication. A separate cookie policy managed by OneTrust may contain a list of these services; the point of discrepancy is their firing before consent and their absence from the general policy provided. Recipients may use edge nodes within the EU, so the conclusion regarding their affiliation is based on company origin. Server-side processing is not visible in a browser-based scan.
Conclusion
The IKI supermarket chain has the OneTrust consent manager, but it does not hold trackers back: before consent, Google Analytics, Google Ads and Campaign Manager, the Meta Pixel, and the Exponea customer data platform all fire, transmitting data to Google and Meta (US). The presence of a consent manager that loads but doesn’t block is the same picture that distinguishes a non-compliant configuration from a correct one, where the stack is held back until the choice is made. Advertising and analytics firing before consent, data transfer to recipients in the US, and the absence of service disclosure in the provided policy constitute a violation of the requirements on consent, disclosure of recipients, and cross-border transfer. Remediation: configure OneTrust to genuinely block all non-technical services until consent, prevent GA4, Google Ads, Meta, and Exponea from firing before the choice, and disclose the services in use in the policy.
99e4bc4fb9cf00a980a2097ce4f0a852ab1152460a2ee33304d7b7eba2d7efa3Where to file: State Data Protection Inspectorate (ADA) — ada.lt
To: State Data Protection Inspectorate (ADA) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website iki.lt. 2. Circumstances I visited the website iki.lt and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The OneTrust consent manager is present and loads (otSDKStub.js at +757 ms, the banner at +1588 ms), but does not hold trackers back. Before consent, the following fire: GA4 (G-QYC21FRZS1) with first_visit, session_start, and page_view events; Google Ads (AW-693009689) and Campaign Manager/DoubleClick (DC-12036474) with page_view and Floodlight activity; the Meta/Facebook SDK; the Exponea/Bloomreach Engagement platform; Cloudflare Web Analytics. Zero Set-Cookie headers for the entire session, and no user choice was made. 2) Before consent, data (page_view, URL, GA4 client identifier) is transmitted to Google (US) and to Meta (US), as well as to Exponea/Bloomreach. The general privacy policy provided names neither Google, Meta, Exponea, nor Adobe Typekit; the cookie description in it is minimal, with the list of trackers relegated to a separate OneTrust mechanism. Full technical documentation is published at: https://gdpru.eu/en/audits/lt-iki-lt/ 3. Provisions violated ePrivacy (Lithuanian implementation) + GDPR Art. 6(1) — trackers before consent; GDPR Chapter V + Art. 13(1)(e) — transfer and disclosure 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]