who.int
WHO — 21 domains, 202 requests. fndrsp.net fires at +0 ms. Two Clarity tags, Monsido heatmaps, FundRaiseUp, Facebook SDK, UA discontinued in 2024 — all with no consent banner. An organization that publishes data-protection guidance for healthcare.
Timeline of the leak
Declared versus actual
Transfer timings
FundRaiseUp — before the page loads
Microsoft Clarity tag 1
Facebook SDK
GTM-5QFSQRT
UA analytics.js — discontinued 2024
Heatmap & session recording
Detected trackers
- Google Tag Manager (GTM-5QFSQRT)
- Google Analytics UA (www.google-analytics.com) — deprecated
- Google Analytics GA4 (G-WKG4M0MSB8)
- Microsoft Clarity (ekg7xazin3, ktuyny0n5d) — two tags
- Monsido (heatmaps + tracking)
- FundRaiseUp (fndrsp.net, fundraiseup.com)
- Facebook SDK (connect.facebook.net)
- Google Fonts (fonts.googleapis.com)
- FontAwesome CDN (use.fontawesome.com)
- Telerik Kendo CDN (kendo.cdn.telerik.com)
- Cloudflare cdnjs (cdnjs.cloudflare.com)
Indicators of GDPR non-compliance
- GDPR Art. 7 / an analogous standard for WHOfndrsp.net (+0 ms, FundRaiseUp) — the first request of the session, before the page even loads. Microsoft Clarity (+220 ms) fires immediately. GTM (+315 ms), UA (+648 ms), Facebook SDK (+240 ms) — all with no consent. No banner is present.
- AdditionallyTwo Microsoft Clarity tags (ekg7xazin3 and ktuyny0n5d) — duplication. UA, discontinued since July 2024, continues running. Monsido heatmaps (+4623 ms) — heatmap recording with no consent.
Context
The World Health Organization (WHO) is a UN specialized agency, headquartered in Geneva. It publishes data-protection guidance for healthcare and information-security standards for medical systems. As a UN agency, it enjoys immunity, sitting outside GDPR jurisdiction. The HAR was captured on the European regional office (who.int/europe). 202 requests, 21 domains.
fndrsp.net — the first request of the session
fndrsp.net belongs to FundRaiseUp, an American online-donation platform. The first request in the HAR fires at the +0 ms mark — before the browser has even started loading the page. It repeats twice more (+968 ms, +4251 ms). FundRaiseUp powers WHO’s donation widget. 15 requests to static.fundraiseup.com per session — payment infrastructure activates on every page load.
Two Microsoft Clarity tags
www.clarity.ms/tag/ekg7xazin3 and www.clarity.ms/tag/ktuyny0n5d — two separate Clarity tags on the same site. Both load with no consent. Clarity records mouse movements, clicks, and scrolling. Duplicate tags mean data for every session is sent to Microsoft twice.
Monsido — heatmaps and tracking
heatmaps.monsido.com (+4623 ms) and tracking.monsido.com (+4623 ms) — Monsido, a Danish web-analytics and accessibility platform. It loads a heatmap configuration (settings/hLJ4OK61Ms4s7WsE4AzSsQ.json) — this records visitor heatmaps. With no consent. As with EFTA’s Matomo HeatmapSessionRecording — recording user behavior requires explicit consent.
UA after retirement — the third instance in the series
UA’s analytics.js (+648 ms) loads and sends a pageview. The third instance in this series, after eua.eu and frontex.europa.eu. GA4 (G-WKG4M0MSB8) runs in parallel. Two GA counters, one of them discontinued.
Telerik Kendo — a corporate JS CDN
kendo.cdn.telerik.com/2021.1.119 — the Telerik CDN (Progress Software, USA), for Kendo UI, a corporate JavaScript UI framework. Loads kendo.all.min.js and kendo.timezones.min.js — large libraries (several MB). Visitors’ IP addresses are transmitted to Telerik/Progress Software (USA).
Legal status
WHO, as a UN agency, enjoys immunity under the Convention on the Privileges and Immunities of the Specialized Agencies (1947). GDPR technically does not apply. Nonetheless, WHO publishes guidance on protecting personal data in healthcare and calls on member states to uphold privacy principles — including in the processing of medical data.
Conclusion
WHO — 21 domains, fndrsp.net at +0 ms, two Clarity tags, Monsido heatmaps, UA discontinued in 2024, a Facebook SDK, the Telerik Kendo CDN. An organization that publishes healthcare data-protection guidance itself deploys a full stack of American trackers with no consent banner. UN immunity does not remove the ethical dimension of the question.
8805252f41be7b6fb24ea4719e0bd42aaea4629572b301545f296a5ea322d06aWhere to file: Jurisdiction determined under Art. 3(2) GDPR —
To: Jurisdiction determined under Art. 3(2) GDPR From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website who.int. 2. Circumstances I visited the website who.int and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 13 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) fndrsp.net (+0 ms, FundRaiseUp) — the first request of the session, before the page even loads. Microsoft Clarity (+220 ms) fires immediately. GTM (+315 ms), UA (+648 ms), Facebook SDK (+240 ms) — all with no consent. No banner is present. 2) Two Microsoft Clarity tags (ekg7xazin3 and ktuyny0n5d) — duplication. UA, discontinued since July 2024, continues running. Monsido heatmaps (+4623 ms) — heatmap recording with no consent. Full technical documentation is published at: https://gdpru.eu/en/audits/who-int/ 3. Provisions violated GDPR Art. 7 / an analogous standard for WHO; Additionally 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]