Technical audit · 2026-06-16

judiciary.mt

Judiciary of Malta

The site of the Judiciary of Malta — 74 requests, five hosts. A consent-management plugin is installed, but the Google tag is baked into the markup at line 270 and loads before the plugin's script, while the banner's display fonts only load at the 2972nd millisecond — by which point all transmissions had already occurred. Three requests go out to Google: analytics with a client identifier, the DoubleClick advertising node, and a remarketing-audiences pixel. The policy, meanwhile, restricts third-party cookies to social-media sharing and embedded content.

Timeline of the leak

+0…+26 ms · entry
Redirect from an unsecured connection. The document is served from judiciary.mt, running WordPress with the Sydney Pro theme, the Elementor builder, and a multilingual module. The browser sent a DNT: 1 header.
+356 ms · consent banner styling
wp-content/plugins/gdpr-cookie-compliance/dist/styles/gdpr-main.css — the consent-management plugin's stylesheet.
+357 ms · counter beats the plugin
www.googletagmanager.com/gtag/js?id=G-641JJS3WVG. The initiator is parsing of the main document's markup, line 270. The call is baked into the HTML and executes unconditionally.
+387…+388 ms · banner script and logo
gdpr-cookie-compliance/dist/scripts/main.js and gdpr-logo.png — the plugin's executable part arrives 30 ms after the Google tag.
+932…+1154 ms · automated-request detection
Redirect to the internal path /cdn-cgi/challenge-platform, followed by a POST to the same path — the Cloudflare mechanism, running via the first party.
+1297 ms · data transmission to Google
region1.analytics.google.com/g/collect, a page_view event: client identifier, screen resolution of 1536x864, the Windows platform, x86/64 architecture, a list of browser versions, an interface language of ru, the address https://judiciary.mt/, and the page title in Maltese.
+1300 ms · advertising node
stats.g.doubleclick.net/g/collect with the same client identifier. An IP-truncation marker is set.
+1301 ms · remarketing audiences
www.google.ee/ads/ga-audiences with the same client identifier — a pixel for building advertising audiences.
+2972 ms · banner fonts
Two weights of the Nunito font from the consent plugin's package. The banner's display finishes rendering 1.7 seconds after all three transmissions had already occurred.

Declared versus actual

No personal information about the visitor is collected unless voluntarily provided — заявлен
Visitor information is not shared with third parties without their consent or lawful authorization — заявлен
IP address logs are kept on a limited basis, for administration and troubleshooting — заявлен
IP address logs are not used to track sessions or on-site behavior — заявлен
The site uses cookies on a limited basis — заявлен
Two types of cookies: session cookies and limited third-party cookies — заявлен
Third-party cookies are permitted only for sharing material via social media and for third-party content embedded on the site — заявлен
Cookie management — via browser settings; disabling them will not affect browsing — заявлен
Data Protection Officer — dpo.justice@gov.mt; supervisory authority — Information and Data Protection Commissioner — заявлен
+ Google Analytics 4 — not named — не заявлен
+ DoubleClick — advertising node, not named — не заявлен
+ Google remarketing-audiences pixel — not named — не заявлен
+ Client identifier, screen resolution, and browser client hints transmitted to Google — не заявлен
+ Cloudflare's automated-request detection mechanism — не заявлен

Transfer timings

+356 ms judiciary.mt

GDPR Cookie Compliance stylesheet.

+357 ms www.googletagmanager.com

gtag/js for the GA4 stream, parsed from the markup, line 270.

+387 ms judiciary.mt

The plugin's executable part — 30 ms after the Google tag.

+1297 ms region1.analytics.google.com

page_view: client identifier, screen resolution, client hints, language, page address and title.

+1300 ms stats.g.doubleclick.net

Google advertising node with the same client identifier.

+1301 ms www.google.ee

Remarketing-audiences pixel with the same client identifier.

+2972 ms judiciary.mt

The banner finishes rendering after all transmissions.

Detected trackers

Indicators of GDPR non-compliance

Context

judiciary.mt is the site of the Judiciary of Malta. It publishes information on courts and tribunals, the composition of the judiciary, court procedures, access to e-justice services, and sections on the Court of Justice of the European Union and the European Court of Human Rights. The Data Protection Officer is dpo.justice@gov.mt. The platform is WordPress with the Sydney Pro theme, the Elementor builder, a multilingual module, and an accessibility plugin; infrastructure runs behind Cloudflare.

Scan: 74 requests, five hosts. Seventy requests to the site’s own domain, four to Google. Capture duration: 2.97 seconds; full page load completed at 1454 ms. Captured on June 16, 2026, on the homepage.

A single document, combining the privacy policy and the cookie policy, describes the processing.

Who receives data directly

Google (analytics, DoubleClick, remarketing audiences).

Declared versus actual

The document is phrased in terms of restrictions — and the scan disproves each one of them.

First restriction: third-party cookies only for two purposes. The cookie policy states directly: use of third-party cookies on this site is restricted and permitted only for sharing material via social media and for third-party content embedded on the pages. This is an exhaustive two-item list.

In fact, at +1297 ms, a Google Analytics event goes out; at +1300 ms, a request to the advertising node stats.g.doubleclick.net; at +1301 ms, a request to the pixel www.google.ee/ads/ga-audiences. The latter serves to build advertising audiences for subsequent ad targeting. All three carry the same client identifier. Neither social-media sharing nor embedded content is involved here.

For a judicial-branch website, the presence of advertising infrastructure by itself requires explanation. The documents contain none — they don’t even mention analytics.

Second restriction: nothing collected without voluntary provision. The document opens with a commitment not to collect any personal information about the visitor unless they provide it themselves. The GA4 request contains a client identifier, screen resolution of 1536x864, the Windows platform, bitness and architecture, a full list of browser versions, interface language, the page address, and its title. None of this was voluntarily provided by the visitor.

Third restriction: no transfer to third parties without consent. It is stated that information collected from the visitor is not shared with third parties except with their consent or under lawful authorization. Three requests to Google occurred without any user choice.

Fourth restriction: IP address logs are not used for tracking. A separate point states that logs are kept on a limited basis, for administration and troubleshooting, and are not used to track sessions or on-site behavior. Formally, this is a statement about server logs, and with respect to those it may be accurate. But a reader reaching this point receives an unambiguous message: their movements on the site are not being tracked. Event-based analytics with a persistent identifier and transmission to advertising infrastructure contradicts that message.

A consent plugin is installed — and bypassed. The GDPR Cookie Compliance plugin runs on the site: its stylesheet is requested at +356 ms, its script at +387 ms, its logo at +388 ms. The Google tag, meanwhile, is written directly into the homepage markup at line 270 and is requested at +357 ms — that is, thirty milliseconds before the executable part of the plugin that was supposed to manage it.

Another marker is telling. The banner’s display fonts — two weights of Nunito from the same plugin’s package — only load at +2972 ms. A font is requested by the browser when the text it needs to render appears. All three transmissions had already occurred 1.7 seconds earlier.

The identifier was created during the capture itself. No caveat about an earlier visit is needed here: the request carries markers of a first visit, a new visitor, and a session start, and the timestamp embedded within the identifier falls one second after the capture’s first request. The identifier came into being before the scan’s own eyes.

Separately, it’s worth noting: the requests carry markers of non-personalized advertising and IP-address truncation. This limits the advertising component, but does not eliminate either the transmission itself or the fact that the advertising nodes received a persistent visitor identifier.

Proven: the plugin is installed, but it does not control the counter’s loading. The initiator of the request to the tag manager is recorded as parsing of the main document’s markup, with a line number given. The tag sits directly in the HTML, executes during parsing, and has no condition preceding it. The plugin’s script arrives after it.

Proven: no choice was made in this session. Across all 74 requests, there is not a single request recording a user decision.

Proven: the identifier was created on the first visit, during the capture. Markers of a first visit and a session start are set in the request itself, and the timestamp embedded in the identifier falls in the second second of the capture.

Proven: the banner finished rendering after the transmissions. The plugin’s fonts were requested at +2972 ms; all three transmissions occurred in the 1297–1301 ms interval.

Not proven and not required: whether the visitor saw the banner and at what point. Response bodies have been stripped from the published file, so the page’s visual state cannot be reconstructed from it. This is immaterial to the conclusion: the counter’s loading does not depend on the plugin regardless.

Separately: the browser sent a DNT: 1 header during the capture. This had no effect on the composition or volume of the transmissions.

Limits of observation

The scan covers a single page — the homepage — in a single state. The observation records browser behavior, not the internal workings of the services: server-side processing, contractual relationships with recipients, and the services’ own settings on their owners’ side are not verified by a browser-based scan. Legal assessment falls to the competent authority — the Information and Data Protection Commissioner, referenced by the document itself.

The file is published stripped of personal data: cookie headers, response bodies, the tab header, and the analytics session identifier have been removed. The set of cookies on a device cannot be reconstructed from the published file, and no conclusion in this analysis relies on it. The fact that the analytics identifier was created rests on something else and is verified directly: the identifier, along with its timestamp and first-visit markers, was transmitted to Google in three requests visible in the file.

The conclusion about the moment the banner finished rendering rests on the loading time of its fonts and is indirect: a font is requested when the text appears, but the exact moment an element appears cannot be established from a browser capture. The analysis’s main argument is not built on this, but on the loading order of the tag versus the plugin’s script.

A social-login plugin installed on the site did not fire in the scan; its presence in the resource list does not mean data was transmitted in this session.

Identification of services relies on domains and address patterns: Google — via googletagmanager.com, analytics.google.com, stats.g.doubleclick.net, and the ads/ga-audiences path; the consent plugin — via the path wp-content/plugins/gdpr-cookie-compliance with a version indicated; the Cloudflare mechanism — via the internal path /cdn-cgi/challenge-platform.

Conclusion

The Judiciary of Malta’s site promises the visitor four things: not to collect anything about them without their willing consent, not to share anything with third parties without their consent, not to use logs to track behavior, and to allow third-party cookies only for two purposes — social-media sharing and embedded content. The scan disproves all four.

1.3 seconds after the homepage opens, three consecutive requests go out to Google: analytics with a client identifier, screen resolution, and a full set of browser client hints; the DoubleClick advertising node; and a pixel for building remarketing audiences. The identifier was created during the capture itself, on the first visit. A consent-management plugin is present on the site, but the Google tag is written into the markup at line 270 and loads thirty milliseconds before the plugin’s executable part, while the fonts for rendering the banner only load at the 2972nd millisecond — by which point everything had already been sent.

The presence of advertising infrastructure on a judicial body’s website is a circumstance requiring separate explanation; the documents contain none, since they don’t mention analytics or advertising at all.

Remediation: remove the counter tag from the markup and place its loading under the control of the already-installed plugin; disconnect the link to Google’s advertising infrastructure, or, if deemed necessary, disclose it in the policy with its purposes and legal basis; list all recipients along with the fields transmitted; and bring the statements about the absence of collection, transfer, and tracking in line with the site’s actual behavior.

Evidence
Original (audit)
HAR file: mt/judiciary-mt-2026-06-16.har
SHA-256: 32021ff7acd339474989b95f499e698289f6a60d1740f432223d5f1609f7ddbd
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Office of the Information and Data Protection Commissioner (IDPC)idpc.org.mt

To: Office of the Information and Data Protection Commissioner (IDPC)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website judiciary.mt.

2. Circumstances
I visited the website judiciary.mt and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The cookie policy limits third-party cookies to an exhaustive list: their use on the site is restricted and permitted only for sharing material via social media and for third-party content embedded on the pages. In fact, at +1300 ms a request goes to the advertising node stats.g.doubleclick.net, and at +1301 ms to the remarketing-audiences pixel www.google.ee/ads/ga-audiences, both carrying the same client identifier as the analytics call. Neither Google Analytics nor the advertising nodes are named in the documents, and the disclosed restriction does not cover them.

2) A consent-management plugin is installed on the site: its stylesheet is requested at +356 ms, its script at +387 ms, its logo at +388 ms. The Google tag, meanwhile, is written into the homepage markup at line 270 and is requested at +357 ms — before the plugin's script. The client identifier is created during the capture itself: the timestamp embedded within it falls one second after the first request, and the request carries markers of a first visit, a new visitor, and a session start. The banner's display fonts only load at +2972 ms, that is, after all three transmissions had already occurred.

3) The policy opens with a commitment not to collect any personal information about the visitor unless voluntarily provided, and contains two independent statements: that visitor information is not shared with third parties without their consent or lawful authorization, and that IP address logs are not used to track sessions or on-site behavior. The GA4 request transmits to Google a client identifier, screen resolution of 1536x864, the Windows platform, x86/64 architecture, a list of browser versions, interface language, the page address, and the page title; the two subsequent requests transmit the same identifier to the advertising infrastructure.

Full technical documentation is published at: https://gdpru.eu/en/audits/mt-judiciary-mt/

3. Provisions violated
GDPR Art. 5(1)(a) and Art. 13(1)(e) — transparency and disclosure of recipients; ePrivacy — S.L. 586.01, reg. 5 (in conjunction with GDPR Art. 6(1)(a)); GDPR Art. 5(1)(a) — statements contradicted by the scan

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]