Podaj dalej — Pokaż Dowody
City of Łódź Office - Audit of violations on city and municipal-related services (2026)
A technical journalistic investigation documenting probable personal data protection violations on websites managed by entities associated with the City of Łódź. Tracking systems were triggered immediately upon entering the site - without user consent, sending signals to external entities. Proceedings by the Personal Data Protection Office (UODO), Office of Electronic Communications (UKE), and the prosecutor's office are underway.
Official context – response from the Deputy Mayor of the City of Łódź
On May 22, 2026, councilors Sebastian Bułak, Marcin Buchali, and Piotr Cieplucha submitted an interpellation regarding reports of possible tracking of municipal website users without informed consent, citing the audit by the Dadalo.pl editorial team and press reports. The response was provided on June 30, 2026, by the Deputy Mayor of the City of Łódź, Tomasz Piotrowski.
"The information contained in the interpellation (cited publication) initiated an internal analysis regarding the websites operated by the Office, in particular:uml.lodz.plandbip.uml.lodz.pl. We cannot rule out that the situation described on https://dadalo.pl/ took place, and the parametergcdassumed the value13l3l3l2l1l1."
The Deputy Mayor confirmed that the parameter gcd=13l3l3l2l1l1 ("not set" state) might have been present on the city's websites. As I demonstrate in the audit, this value, combined with poor implementation, means that the consent mechanism did not have time to act - tracking tags were triggered before the user made a decision to grant or deny consent, and marketing data was sent as if full consent had been given for everything.
The city declared it would take corrective actions, including removing old and inadequate tracking codes and considering conducting analytics outside the Google ecosystem. It was also announced that commissioning an external audit is under consideration.
Furthermore, the Deputy Mayor indicated that a proprietary cookie consent tool had been implemented on the uml.lodz.pl and bip.uml.lodz.pl websites. At the same time, it was reserved that commissioning an external audit of this solution is also being considered.
Due to the nature of the response and the scale of irregularities, including this "proprietary solution" implemented on the BIP, an official editorial response to the above letter will be published soon on the dadalo.pl website. Concurrently, the update of the audit in its current form and detail, along with comments for each domain, is part of this response.
Update July 7, 2026: due to re-analyzing the evidence per domain, which took me several days and allowed for a more detailed look at the problems than in March, I decided to clarify the violation scoring I write about in a more technical and detailed manner, in many cases analyzing the full payload. This changes not only the number of domain violations but also, in some cases, their severity. The ratings are currently placed in the aggregate list (domain index) and in the per-domain report.
In the original version of the report, I interpreted the value of the parameter gcd=13l3l3l2l1l1 as indicating an active, default "granted" state setting. After the city's response, in which it admits to the problem with data processing, and analysis of available data, I am clarifying this position.
Generally speaking, the network data (incl. the npa=1 flag and the absence of the gcs parameter) shows that the websites did not set anything. Instead of a forced "granted" state, we are dealing with a complete failure to configure Consent Mode at the critical moment of page loading.
Google tags were triggered in legacy mode — that is, as if the Consent Mode mechanism had not been implemented at all. The lack of a signal from Consent Mode resulted in full data processing prior to any user decision. In the text, I update the interpretation taking this knowledge into account, and on dadalo.pl I will publish my opinion regarding this practice, which I know from the industry.
Note: The technical details of the analysis refer to the state of the pages at the time of the audit (March 6–9, 2026) and do not include any subsequent modifications made by the City of Łódź Office.
This change does not weaken, but rather clarifies the assessment: the problem is not a wrongly set flag, but the lack of a functioning consent management architecture at the time tracking is initialized.
Marketing tracking evaluation variants
Evaluation based on the presence of active marketing tracking without consent. Between July 5-7, 2026, I re-analyzed the evidence and decided to modify the ratings and methodology using the more detailed information I painstakingly prepared for each domain. I believe this is currently more reliable.
| Evaluation type | Description | |
|---|---|---|
| 🔴🔴 Very negative | Active marketing tracking + no CMP + cross-controller sharing with other entities. | |
| 🔴 Negative | Active marketing tracking (GA4 / UA / Pixel) triggered without an effective consent signal. CMP present, but not integrated with Consent Mode. | |
| ⚠️ Medium | No direct marketing tracking on the domain. Legacy Facebook SDK present and indirect tracking via external widgets. No CMP. | |
| ✅ Positive | No marketing tracking (GA4 / Pixel). Consent mechanism present and integrated. |
I have established that on many municipal websites in Łódź, visitors were tracked without their knowledge and consent
My findings are confirmed by tests conducted between March 6-9, 2026
The material documents the technical scanning of 41 websites managed by, funded by, or associated with the City of Łódź Office. Each test session was sterile — an automated browser opened the page without any cookies, without browsing history, and without interacting with the consent banner.
Out of 41 technically checked addresses, 4 items were excluded from the comparative assessment for technical reasons (TLS problem, technical panels, or redirects). The aggregate indicators were thus calculated for 37 assessable domains. It is worth noting that as a result of an in-depth analysis of the source data in July 2026 and a change in the rating methodology, the weights and ratings of some domains were modified.
The result is unequivocal: on 29 out of 37 assessable domains, tracking systems (mainly Google Analytics, Google Ads, and DoubleClick) were triggered immediately upon entering the site and began sending data to external servers before the user had the opportunity to make any decision regarding consent.
In many cases, the consent banner did not perform a real blocking function. Tracking tags initialized in full mode (setting analytical and marketing cookies), and data was transmitted to Google, Meta, and DoubleClick before the consent mechanism had time to act.
On the majority of tested domains, tracking tags were triggered in a state of unconfigured Consent Mode (parameter gcd=13l3l3l2l1l1), which resulted in full data processing prior to any user interaction.
ℹ️ TCF 2.2 vs Google Consent Mode v2 – why doesn't it protect in this case?
Some websites may use the IAB TCF 2.2 (Transparency & Consent Framework), which standardizes consent collection. However, TCF only regulates the method of obtaining user consent, not the behavior of Google tags.
Google Consent Mode v2 works independently and must be correctly integrated with the CMP. In the analyzed cases, Google tags were triggered at a very early stage of page loading (already at the after_domcontentloaded stage), before the CMP banner had time to fully initialize and transmit any consent signals.
Why didn't the pingless mode (cookieless pings) work?
- Pingless (anonymous pings without full cookies) only occurs with correct Advanced Consent Mode with a default state of denied.
- On the tested domains, Google tags were triggered without effective blocking by the Consent Mode mechanism, resulting in the immediate saving of full analytical and marketing cookies (
_ga,_gcl_au,_fbp, and others). - There was no limited, anonymous pinging — full tracking occurred before any user decision.
In conclusion: even having a certified CMP compliant with TCF 2.2 does not absolve one from the obligation of correct Google Consent Mode configuration. Triggering tracking tags before effectively determining the consent state constitutes a violation of Article 6(1)(a) of the GDPR, regardless of the consent framework used.
Domain breakdown
| Domain (click to go) | Entity / Data Controller | Tracking evaluation |
|---|---|---|
| lodz.pl | Municipal Library in Łódź | 🔴 VIOLATION |
| uml.lodz.pl | City of Łódź Office – main domain | 🔴🔴 V. NEGATIVE |
| bip.uml.lodz.pl | City of Łódź Office | 🔴 VIOLATION |
| mpu.lodz.pl | Municipal Urban Planning Office in Łódź | 🔴 VIOLATION |
| zdit.uml.lodz.pl | ZDiT (Redirect) | ➖ EXCLUDED |
| cuw.uml.lodz.pl | Shared Services Center in Łódź | 🔴 VIOLATION |
| cuwdps.uml.lodz.pl | Shared Services Center for DPS in Łódź | 🔴 VIOLATION |
| lckm.uml.lodz.pl | Łódź Contact Center for Residents | 🔴 VIOLATION |
| mops.uml.lodz.pl | Municipal Social Welfare Centre in Łódź | 🔴 VIOLATION |
| mzz.lodz.pl | Municipal Nursery Complex in Łódź | 🔴 VIOLATION |
| schronisko.uml.lodz.pl | Shelter for Homeless Animals in Łódź | 🔴 VIOLATION |
| architektmiasta.uml.lodz.pl | City Architect's Office | 🔴 VIOLATION |
| rewitalizacja.uml.lodz.pl | Revitalization Portal | 🔴 VIOLATION |
| invest.lodz.pl | City of Łódź Office (Invest in Łódź) | 🔴 VIOLATION |
| li.lodz.pl | Łódź Investments Sp. z o.o. | 🔴 VIOLATION |
| zlm.lodz.pl | Municipal Premises Management | 🔴 VIOLATION |
| bip.zlm.lodz.pl | Municipal Premises Management | 🔴 VIOLATION |
| mosir.lodz.pl | Municipal Sports and Recreation Centre in Łódź | 🔴 VIOLATION |
| aquapark.lodz.pl | Aquapark Fala Sp. z o.o. | 🔴 VIOLATION |
| orientarium.lodz.pl | Orientarium Zoo Łódź | 🔴🔴 V. NEGATIVE |
| lodz.travel | Łódź Tourism Organization (ŁOT) | 🔴 VIOLATION |
| kartalodzianina.pl | Łódź Tourism Organization (ŁOT) | 🔴 VIOLATION |
| biblioteka.lodz.pl | Municipal Library in Łódź | 🔴 VIOLATION |
| capz.lodz.pl | Administrative Centre for Foster Care | 🔴 VIOLATION |
| css.samorzad.lodz.pl | Social Benefits Centre | 🔴 VIOLATION |
| botaniczny.lodz.pl | Botanical Garden in Łódź | 🔴 VIOLATION |
| strazmiejska.lodz.pl | Shelter for Homeless Animals in Łódź | 🔴 VIOLATION |
| nowa.mapa.lodz.pl | InterSIT — Łódź Geodesy Centre | ⚠️ MEDIUM |
| ads.biblioteka.lodz.pl | Municipal Library (Ad Server) | ➖ EXCLUDED |
| atlasarena.pl | MAKiS Sp. z o.o. (100% City) | ⚠️ MEDIUM |
| bip.biblioteka.lodz.pl | Municipal Library in Łódź | ⚠️ MEDIUM |
| kartaturysty.lodz.travel | Łódź Tourism Organization (ŁOT) | ✅ POSITIVE |
| lodz.praca.gov.pl | District Labour Office in Łódź | 🔴 VIOLATION |
| media.lodz.pl | Łódź Media Group / ŁOT | ⚠️ MEDIUM |
| mpk.lodz.pl | Municipal Transport Company in Łódź | 🔴 VIOLATION |
| pup-lodz.pl | District Labour Office in Łódź | ➖ EXCLUDED |
| teatr-muzyczny.lodz.pl | Musical Theatre in Łódź | ➖ EXCLUDED |
| wizyty.uml.lodz.pl | City of Łódź Office (appointment booking) | ✅ POSITIVE |
| wsparcie.uml.lodz.pl | Social Support Portal | ✅ POSITIVE |
| zzm.lodz.pl | Municipal Greenery Authority | 🔴 VIOLATION |
| makis.pl | Municipal Arena of Culture and Sports | ⚠️ MEDIUM |
Methodological note: "Excluded" means an address technically checked but incomparable with the others (e.g., TLS problem or redirect). Not all city domains were analyzed — however, the sample is large and representative enough to draw general conclusions.
Full investigative documentation for each domain — network logs in HAR format, cookie dumps, request payloads with the gcd parameter, browser trace — is available below in the sections for individual domains.
📋 Legal notice and rules of openness
This report has been prepared and published in good faith, as part of independent journalistic activity, in order to pursue the public interest. All findings presented in the material are based on my best knowledge regarding the technical analysis of tracking mechanisms and personal data processing on websites.
In connection with the findings described in this material, proceedings are underway before the competent institutions — the Personal Data Protection Office (UODO), the Office of Electronic Communications (UKE), and prosecutorial authorities. In mid-July 2026, I am supplementing the evidence and initiating further institutions to verify the resolution of the personal data processing issue.
I adopt a stance of full openness and transparency. If anyone identifies substantive or technical errors in this report, please contact me. Any justified allegation will be verified, and the report will be corrected accordingly.
Contact the editorial office: @dadalo@journa.host (Mastodon) · redakcja@dadalo.pl
Research Objective and Methodology
The panel below presents technically documented and frozen events from the scanning process of websites associated with the city of Łódź. The data is integral, timestamped, and made available for further investigative verification.
- Clean incognito sessions: Chrome 145 / Firefox 140
- Full sterility: No interaction with cookie banners. The scanner documents what the page loads before the user gives consent.
- Digital evidence: DevTools Network/Storage/Console, HAR format log exports, timestamp analysis.
- Scope of tests: March 6–9, 2026
📖 Chronology of triggering trackers without user consent
The guide below explains the chronology of cookies appearing in a sterile test session (before clicking consent on the banner). It shows the moment of creation of tracking mechanisms. This is a technical description for selected files that we publish so that anyone can falsify the theses contained in the report.
Timeline of identifiers appearing
In the analyzed evidence (the cookies_timeline.ndjson file available under the icon ⏱️ Cookies Timeline), the following sequence frequently occurs:
before_navigation:cookies: [](Clean browser session)after_domcontentloaded: Over a dozen analytical, advertising, and third-party cookies appear immediately.after_load: The set of created cookies persists in the target system's memory.after_async_window: Scripts continue to run actively, overwriting and updating identifier values (e.g.,_ga_*).
Evidentiary conclusion: Tracking mechanisms do not wait until the end of page loading and do not wait for user consent. They activate at a very early stage of rendering the page in a fully passive session.
Significance of key identifiers (Cookies)
_ga,_gid,_gat_gtag_UA_*,_ga_*— This is a strong trace of Google Analytics / Google tags._gais used to distinguish long-term users,_gididentifies short-term sessions, and_gatlimits the number of requests._gcl_au— A typical cookie associated with Google Ads / conversions. Usually appears with Google advertising campaign implementations._fbp— A Meta Pixel marketing cookie (Facebook), used to track visits, user behavior, and advertising goals across external providers.FCCDCF— Cookie associated with Google Funding Choices or the consent mechanism. A trace of platform consent collection systems.YSC,VISITOR_INFO1_LIVE,__Secure-ROLLOUT_TOKEN— Traces of the YouTube system. The presence of the partitionKey attribute often indicates that the embedding operated in a third-party context and processed viewer data.
Technical evidence of data transmission prior to consent
Since there was no pollution in the before_navigation state, and right after after_domcontentloaded the browser already possessed a full set of identifiers such as _ga, _gid, or _fbp, this indicates forced initialization of analytics and advertising prior to any conscious action by the user.
Important: Even if the CMP mechanism (e.g., Cookiebot, Klaro) wakes up with a delay and "clears" these cookies at the end of the session (in the after_async_window phase), the audit still records a violation. This is because before the CMP reacted, the browser had already managed to establish communication with target servers (e.g., Google) and transmit data to them in network requests (Payload), containing e.g., the Consent Mode parameter gcd=13l3l3l2l1l1. Deleting a cookie after the fact does not reverse the data leak that has already occurred.
The paired evidentiary chain for each domain generally confirms the pattern: (1) no cookies 🡒 (2) immediate saving without user consent in Storage memory 🡒 (3) irreversible transmission of g/collect requests with the parameter gcd=13l3l3l2l1l1 to recipients 🡒 (4) optional, delayed clearing using an improperly configured CMP banner.
What should a correct implementation look like? According to the guidelines, the system should retain only necessary technical cookies. All advertising and analytical signals should have a default denied (blocked) status. Only after explicit acceptance on the banner can the signals be updated to the granted state. In the analyzed cases, Google tags were triggered without effective limitation from the Consent Mode mechanism, which resulted in full data processing prior to any user decision. This situation can be fundamentally verified with free tools, including the Preview mode in Google Tag Manager (Consent tab).
🔬 Visualization of the violation mechanism
The diagrams below illustrate the course of the violation recorded in sterile test sessions and the contrast with the correct implementation of the consent mechanism.
📊 Evidentiary chain — sequence of violation ▼
flowchart TD
A["🧪 Sterile test session
before_navigation
cookies: empty list"] --> B["⚡ after_domcontentloaded
_ga, _gid, _fbp appear
along with other cookies"]
B --> C["🔴 Scripts launch analytics
and advertising before any
user action"]
C --> D["📡 Browser sends requests
e.g. g/collect to recipients"]
D --> E["🔑 Payload reveals
gcd=13l3l3l2l1l1
(lack of configured Consent Mode)"]
E --> F["🌐 Data reaches third
parties: Google, Meta, DoubleClick
before the user consents"]
F --> G["⏳ after_async_window
CMP may remove some cookies
if we click REJECT"]
G --> H["⚖️ Legal-technical effect:
cookie removal does not reverse
prior data transmission"]
style A fill:#0f172a,stroke:#38bdf8,color:#e2e8f0
style B fill:#1e1b4b,stroke:#f43f5e,color:#fda4af
style C fill:#4c0519,stroke:#f43f5e,color:#fda4af
style D fill:#4c0519,stroke:#f43f5e,color:#fda4af
style E fill:#431407,stroke:#f59e0b,color:#fde68a
style F fill:#4c0519,stroke:#f43f5e,color:#fda4af
style G fill:#1e1b4b,stroke:#a78bfa,color:#c4b5fd
style H fill:#0c0a09,stroke:#ef4444,color:#fca5a5
The diagram presents the evidentiary chain recorded in each scanning session. The "GRANTED" stage (step 5) is crucial — it means that the tracking system received a consent signal without the user's actual decision.
⚖️ Comparison: stated condition vs correct condition ▼
flowchart LR
subgraph X["🔴 Condition found in audit"]
direction TB
A1["Entering the site
without clicking consent"] --> A2["Immediate activation
of tracking tags"]
A2 --> A3["Cookies appear
_ga, _gid, _fbp, _gcl_au"]
A3 --> A4["Requests are sent
to Google / Meta / DoubleClick"]
A4 --> A5["Payload contains
gcd=13l3l3l2l1l1
(no effective Consent Mode)"]
A5 --> A6["CMP reacts with a delay
or only clears cookies locally
Transmission has already occurred"]
end
subgraph Y["🟢 Correct condition per GDPR"]
direction TB
B1["Entering the site
without clicking consent"] --> B2["Default consent state
= denied"]
B2 --> B3["No analytical or
advertising cookies"]
B3 --> B4["No transmission of marketing
data to recipients"]
B4 --> B5["Only after conscious
user acceptance does
status change to granted"]
end
style A1 fill:#1e1b4b,stroke:#818cf8,color:#e0e7ff
style A2 fill:#4c0519,stroke:#f43f5e,color:#fda4af
style A3 fill:#4c0519,stroke:#f43f5e,color:#fda4af
style A4 fill:#4c0519,stroke:#f43f5e,color:#fda4af
style A5 fill:#431407,stroke:#f59e0b,color:#fde68a
style A6 fill:#4c0519,stroke:#f43f5e,color:#fda4af
style B1 fill:#0f172a,stroke:#38bdf8,color:#e2e8f0
style B2 fill:#052e16,stroke:#22c55e,color:#bbf7d0
style B3 fill:#052e16,stroke:#22c55e,color:#bbf7d0
style B4 fill:#052e16,stroke:#22c55e,color:#bbf7d0
style B5 fill:#052e16,stroke:#22c55e,color:#bbf7d0
The comparison shows a fundamental difference: in the stated condition, the system immediately treats the user as someone who gave consent (GRANTED). In the correct condition, the default state is refusal (denied), and marketing data is not sent until a conscious action is taken.
📊 Analysis details, files, and ratings for each domain
On July 5-7, 2026, the report was substantively updated with additional technical detailshttps://orientarium.lodz.pl/ ŁOT Group
SCAN ID: 20260306_202023_a6417c59
ADO: ZOO Łódź sp. z o.o.
Hosting/IT: Hetzner
Technical Conclusions (Scanner)
- 🔴🔴 Active Facebook Pixel (fbevents.js + config 668887504186759 + cookie _fbp)
- 🔴🔴 Google Ads Conversion IDs: AW-10940984035 + AW-665139254 + AW-557285855
- 🔴 Dedicated GA4 G-K51BYYXXYF + GTM GTM-NVTJSXK + Crazy Egg (script.crazyegg.com)
- ⚠️ PixelYourSite (WordPress plugin) + Google Conversion Linker (_gcl_au + _gcl_ls)
- - Cookie Notice present, but does not block marketing tags before consent
- - reCAPTCHA + YouTube widgets + livebar lodz.pl/livebar/
Privacy Policy Analysis vs Tags
📄 Show Domain Assessment ▼
Conclusions and Violations
- 🔴🔴 Active Facebook Pixel — fbevents.js + config 668887504186759 loaded. Cookie _fbp is set. PixelYourSite (WordPress plugin) confirms intentional Pixel implementation.
- 🔴🔴 Google Ads Conversion + Enhanced Conversions — active IDs: AW-10940984035, AW-665139254 and AW-557285855. _gcl_au and _gcl_ls (Google Conversion Linker) present.
- 🔴 Dedicated GA4 + GTM + Crazy Egg — property G-K51BYYXXYF, container GTM-NVTJSXK and script.crazyegg.com (heatmaps and session recording).
- ⚠️ Lack of effective CMP — only Cookie Notice (WordPress plugin) is present, which does not block marketing tags before user consent. Tags fire immediately after page load.
- - reCAPTCHA + third-party widgets — reCAPTCHA v3 + YouTube widgets + livebar lodz.pl/livebar/.
Legal Context (Orientarium Zoo Łódź)
Orientarium Zoo Łódź is a modern tourist and educational attraction of the City of Łódź. The website has a commercial-recreational character (tickets, events, marketing). It does not process special categories of data within the meaning of art. 9 RODO, but as a website with advertising monetization and high traffic, it is subject to standard RODO + ePrivacy requirements.
Layer A — culture of administrator compliance. A very aggressive marketing stack (Pixel + Google Ads + GA4 + Crazy Egg) was used with a minimal consent mechanism (only Cookie Notice). This is a classic example of prioritizing monetization over compliance.
Layer B — market value of behavioral signal. High. The zoo website generates data on interests in family recreation, events and tourism — attractive for audience profiling. The full stack (Pixel + Conversion + session recording) maximizes signal value.
Summary of assessment – orientarium.lodz.pl
| Criterion | Assessment |
|---|---|
| Firing trackers before consent | 🔴🔴 Yes — Pixel + Google Ads + GA4 fired immediately |
| CMP Effectiveness | 🔴 Only Cookie Notice — does not block tags |
| Transmission to third parties | 🔴🔴 Pixel + Google Ads + Crazy Egg + shared GA |
| Facebook Pixel | 🔴🔴 Active (fbevents.js + config + _fbp) |
| Google Ads / Conversion | 🔴🔴 Active (3x AW- ID + Conversion Linker) |
| Overall assessment | 🔴🔴 Very negative — full marketing stack without effective consent |
Verdict: On orientarium.lodz.pl one of the most aggressive marketing stacks in the entire audit was implemented: active Facebook Pixel, multiple Google Ads Conversion IDs, dedicated GA4 and Crazy Egg (session recording). Cookie Notice does not block tags before user consent. This is a classic example of prioritizing monetization over privacy protection on the website of a City of Łódź tourist attraction. Violation of art. 5(3) of the ePrivacy Directive and art. 6 and 7 RODO is clear.
📸 Evidence: Page Snapshots and GDPR Documents ▼
📌 Notes from policy scan:
Cookie banner: https://orientarium.lodz.pl/assets/2025/05/Polityka-plikow-Cookies-07.2024.pdf — anomaly: two different cookie PDF versions
https://uml.lodz.pl/ ŁOT Group
SCAN ID: 20260306_201513_88503e84
ADO: Łódź City Office
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions (Scanner)
- 🔴🔴 GA4 G-30F084ZHSL + two Google Ads Conversions: AW-10940984035 + AW-790142032
- 🔴🔴 Conversion event sent on the homepage: AW-10940984035/V02uCO6r29MDEOPViOEo
- ⚠️ New CMP: Klaro.js (cookies.uml.lodz.pl) — better than cookie-box, but still ineffective against Google
- - Facebook SDK + YouTube widget + Twitter widgets + livebar lodz.pl/livebar/
- - Ad server from the Library + Google Conversion Linker (_gcl_ls)
- - Beacons with gcd=13l3l3l2l1l1 + npa=1 — tags fire before consent
Privacy Policy Analysis vs Tags
📄 Show Domain Assessment ▼
Conclusions and Violations
- 🔴🔴 GA4 + two Google Ads Conversions without consent — active beacon to G-30F084ZHSL and conversion events to AW-10940984035 and AW-790142032. Tags fire with parameters gcd=13l3l3l2l1l1 + npa=1.
- 🔴🔴 Conversion event on the homepage — conversion AW-10940984035/V02uCO6r29MDEOPViOEo was recorded and sent directly on uml.lodz.pl.
- ⚠️ New CMP: Klaro — instead of cookie-box, klaro.js + config from cookies.uml.lodz.pl appeared. This is a step in the right direction, but still does not block Google tags before consent.
- ⚠️ Facebook SDK + third-party widgets — Facebook SDK, YouTube widget API, Twitter widgets and iframe lodz.pl/livebar/ were loaded. Facebook Like plugin is also present.
- - Google Conversion Linker active — _gcl_ls in localStorage + _gcl_au in cookies (from previous sessions).
Legal Context (Łódź City Office – main domain)
uml.lodz.pl is the official homepage of the Łódź City Office — the most important domain in the entire municipal ecosystem. Thousands of residents visit it daily for official, informational and communication purposes. As a public entity website, it is subject to the highest standards of transparency and data processing minimization.
Layer A — culture of administrator compliance. A new CMP (Klaro) has been implemented, which is progress compared to the cookie-box. However, a full marketing stack (GA4 + two Google Ads Conversions) is still launched without an effective consent signal. This is a systemic oversight at the level of the entire institution.
Layer B — market value of behavioral signal. Very high. The Łódź City Office homepage generates data on the interests of Łódź residents (offices, services, events) — attractive for audience profiling. Conversion tracking + GA4 maximize the value of this signal.
Summary of assessment – uml.lodz.pl
| Criterion | Assessment |
|---|---|
| Firing trackers before consent | 🔴🔴 Yes — GA4 + 2× Google Ads Conversion + conversion event |
| CMP Effectiveness | ⚠️ New Klaro (better than cookie-box), but still ineffective against Google |
| Transmission to third parties | 🔴🔴 Yes — GA4 + Google Ads + Facebook SDK + livebar |
| Google Ads Conversion | 🔴🔴 Active (2 IDs + conversion event on the homepage) |
| Facebook Pixel | ✅ Inactive (only SDK + Like plugin) |
| Overall assessment | 🔴🔴 Very negative — full marketing stack on the city's main domain |
Verdict: On uml.lodz.pl (main domain of the Łódź City Office), one of the heaviest marketing stacks in the entire audit was implemented: active GA4 (G-30F084ZHSL), two Google Ads Conversion IDs (AW-10940984035 + AW-790142032) and a direct conversion event on the homepage. The new Klaro CMP is progress, but still does not block Google tags before user consent. This is a violation of the principles of minimization and legality of processing at the level of the entire public institution.
🔬 Extended Analysis: X-ray Methodology vs Scanner ▼
Methodology Note: Our automated Scanner focuses on detecting advertising, analytics and tracking infrastructure (so-called "tracking heuristics" in the context of Consent Mode and cookies). In parallel, "X-ray" (plugin from the Internet. Time to Act! foundation) was used. X-ray is based on privacy activists' methodology, for whom every connection to an external server without consent (even downloading fonts or CDN scripts) is treated as data disclosure (IP address) and a potential violation. The following comparison is a unique fusion of both perspectives.
Evidentiary Consistency
- Timeline consistency: Raw loading logic data perfectly matches network logs. Initialization of tracking packages occurs fractions of a second after DOM load, clearly proving forced script execution.
- GCD Confirmation: X-ray clearly documents the sending of the hard parameter
gcd=13l3l3l2l1l1in separate endpoints (region1.analytics.google.com,stats.g.doubleclick.net,www.google.com,www.google.pl). This fully verifies our thesis — the evidence appears in at least two independent tools. - Differences in domain visibility (Tracking vs All Connections): The Scanner reports a dozen domains (because it filters pure "tracking"). X-ray reports more, including
bunny.net(fonts),twitter.com,gr-cdn.comorgoogletagmanager.com. From a legal point of view, according to RODO activists, loading e.g. a stylesheet from a foreign server is also data transmission outside the main domain.
Deeper data flow analysis:
- Google Ads Advertising Infrastructure: Remarketing identifiers
AW-790142032andAW-10940984035detected active before user consent. Google Ads tags are not declared in the UMŁ cookie policy. - Active Meta Tracking: Connections to
connect.facebook.netandwww.facebook.comrecorded in a clean session — transmission of IP address and page URL to Meta Platforms without consent. - Cross-domain tracking lodz.pl ↔ uml.lodz.pl: Domains share GA property
G-30F084ZHSLand UAUA-25825547-40without disclosure of joint administration (art. 26 RODO) in the RODO documents of either domain. - Twitter Session Tracking: Embedded content generates
session_idreported tosyndication.twitter.combefore any intentional visitor action.
📸 Evidence: Page Snapshots and GDPR Documents ▼
📌 Notes from policy scan:
No dedicated “privacy policy"; there is a cookie policy + RODO newsletter: https://uml.lodz.pl/zobacz-rowniez/rodo-newsletter/
https://ads.biblioteka.lodz.pl/ ŁOT Group
SCAN ID: 20260306_201837_7265207d
Data Controller: Biblioteka Miejska w Łodzi
Hosting/IT: Hetzner
Technical Conclusions
- -Only technical/session cookies exist after the session.
- -The service is an administrative panel for managing campaigns and therefore does not have its own mechanism for collecting consents. However, it is on the domain list and embedded on the main library page, which is why it is part of the scan.
Privacy Policy Analysis vs Tags
No assigned containers in the journalistic table.
📄 Show Domain Assessment ▼
Audit Summary: ads.biblioteka.lodz.pl
Latest scan: 20260306_201837_7265207d
Basic information
- URL: https://ads.biblioteka.lodz.pl/
- Sterile Session Status: 🟢 CLEAN (No tracking traces before consent)
- Total Requests: 11
- Tracking Requests: 0
- Cookies Set: 1
Conclusions and Violations
- ⚠️ Only technical/session cookies exist after the session.
Data Flow (Identified Recipients)
- No identified external tracking domains in this session.
CMP Detection (Consent Management)
- No commonly known CMP tools uniquely identified in code (an untypical solution might be used).
Report generated automatically based on network traffic analysis and DOM changes in an empty browser session (Before clicking the consent button).
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Revive Adserver login panel – no public policy page
https://bip.uml.lodz.pl/
SCAN ID: 20260306_201535_2201a79b
Data Controller: Urząd Miasta Łodzi
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions
- 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
- 🔴
A custom CMP was detected (TYPO3 cookiebox from the
uml_portalpackage), which does not block the loading of trackers before the user's decision — a deceptive mechanism. There are noconsent defaultorconsent updatecommands indata_layer.json. - 🔴 Data transmitted to Google (GA4 + DoubleClick) before any decision. Facebook SDK and YouTube player_api were also loaded — without confirmed beacon calls in this measurement.
- ⚠️
GA cookies set on the apex domain
.uml.lodz.pl— analytical identity shared with the City of Łódź portal (details in expanded view). - - After the session, 9 tracking cookies remain (4× GA, 5× YouTube). Additionally, 2 F5 BIG-IP session management cookies — non-tracking.
Privacy Policy Analysis vs Tags
📄 Show Domain Assessment ▼
Audit Summary: bip.uml.lodz.pl
Latest scan: 20260306_201535_2201a79b
Conclusions and Violations
- 🔴
Tracking tags were firing immediately upon entering the site, before any user decision.
Google Analytics 4 cookies (property
G-30F084ZHSL), Universal Analytics (UA-25825547-40), and YouTube cookies were set. Facebook SDK was loaded (without confirmed beacon transmission in this measurement). - 🔴
A CMP was detected (TYPO3 cookiebox from the
uml_portalpackage), which does not block the loading of trackers before the user's decision — a deceptive mechanism. There are noconsent defaultorconsent updatecommands indata_layer.json. - 🔴
Data transmitted to Google (GA4 + DoubleClick) before consent was given. Calls to
region1.analytics.google.com/g/collectandstats.g.doubleclick.net/g/collectcontain the client ID (cid), the Consent Mode signal (gcd=13l3l3l2l1l1), the non-personalized ads flag (npa=1), and the DMA context. Thegcdconfiguration indicates a lack of an integrated consent signal — the analytical ping is sent regardless. - ⚠️
After the session, 9 tracking cookies remain (
_ga*~2 years, YouTube cookies ~2 years). Additionally, 2 F5 BIG-IP cookies (TS013f51fc,TS01619efc) function as a load balancer persistence mechanism — they do not qualify as trackers, but they reveal the architecture.
Legal Context (BIP)
bip.uml.lodz.pl is not an ordinary information page. It is the Public Information Bulletin (BIP) — a tool for executing the right of access to public information under Art. 61 of the Constitution of the Republic of Poland, operated within the regime of the Act of 6 September 2001 on Access to Public Information and the Regulation of the Ministry of Internal Affairs and Administration of 18 January 2007 on the BIP. A citizen exercising their constitutional right of access to public information cannot be subjected to commercial tracking as an unwritten condition of access. The violation is of a qualified nature — beyond the GDPR, it affects the constitutional guarantee of access to information on the activities of public authority bodies.
Overall Assessment: A domain with a special legal status (BIP), on which transmission to third parties without user consent was identified, alongside a cross-domain scope of GA cookies covering the entire UMŁ portal. The deceptive CMP mechanism (TYPO3 cookiebox present, but non-blocking) weakens the line of defense based on "lack of awareness" — there was an awareness of the obligation, but a lack of effective implementation.
Data Flow (Identified Recipients)
- Google LLC – Google Analytics 4 (property
G-30F084ZHSL, endpointregion1.analytics.google.com/g/collect), Universal Analytics (UA-25825547-40), Google Signals / DoubleClick (endpointstats.g.doubleclick.net/g/collect) - Meta Platforms Ireland Ltd. – Facebook SDK (
connect.facebook.net/pl_PL/sdk.js) loaded; beacon calls tofacebook.com/trwere not recorded in this measurement - YouTube (Google) –
player_api+ widget API, setting cookies for the.youtube.comdomain - ads.biblioteka.lodz.pl – external ad server (Revive Adserver, endpoint
/www/delivery/asyncjs.php) belonging to the Municipal Library in Łodzi — a separate data controller
CMP Detection
A custom CMP embedded in the TYPO3 template was detected (typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js). The script loads, but does not constitute an opt-in mechanism — it does not block the execution of Google Analytics, Facebook SDK, or YouTube tags before the user's decision. In data_layer.json, Google Consent Mode commands (consent default, consent update) are missing, and payloads to /g/collect contain the gcd=13l3l3l2l1l1 signal, indicating a lack of integrated CMP with the Consent Mode layer.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
BIP — no separate privacy policy
https://bip.zlm.lodz.pl/
SCAN ID: 20260306_201940_dbfda186
Data Controller: Zarząd Lokali Miejskich
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions
- 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
- 🔴
A custom CMP was detected (TYPO3 cookiebox from the
uml_portalpackage), which does not block the loading of trackers before the user's decision — a deceptive mechanism. There are noconsent defaultorconsent updatecommands indata_layer.json. - 🔴 Data transmitted to Google (GA4 + DoubleClick) before any decision. Facebook SDK, YouTube player_api, and a Twitter iframe were also loaded — without confirmed beacon calls in this measurement.
- ⚠️
GA cookies set on the apex domain
.zlm.lodz.pl— analytical identity shared with the ZLM portal (details in expanded view). - - After the session, 9 tracking cookies remain (4× GA, 5× YouTube). No F5 BIG-IP session management cookies — hosting architecture differs from bip.uml.lodz.pl.
Privacy Policy Analysis vs Tags
📄 Show Domain Assessment ▼
Audit Summary: bip.zlm.lodz.pl
Latest scan: 20260306_201940_dbfda186
Conclusions and Violations
- 🔴
Tracking tags were firing immediately upon entering the site, before any user decision. Google Analytics 4 cookies (property
G-30F084ZHSL), Universal Analytics (UA-25825547-40), and YouTube cookies were set. Facebook SDK and a Twitter iframe were loaded (without confirmed beacon transmission in this measurement). - 🔴
A CMP was detected (TYPO3 cookiebox from the
uml_portalpackage), which does not block the loading of trackers before the user's decision — a deceptive mechanism. There are noconsent defaultorconsent updatecommands indata_layer.json. - 🔴
Data transmitted to Google (GA4 + DoubleClick) before consent was given. Calls to
region1.analytics.google.com/g/collectandstats.g.doubleclick.net/g/collectcontain the client ID (cid), the Consent Mode signal (gcd=13l3l3l2l1l1), the non-personalized ads flag (npa=1), and the DMA context. Thegcdconfiguration indicates a lack of an integrated consent signal — the analytical ping is sent regardless. - 🔴
Cross-domain scope cookies GA. The cookies
_ga,_ga_30F084ZHSL,_gid, and_gat_gtag_UA_25825547_40are set on the apex domain.zlm.lodz.pl, rather than.bip.zlm.lodz.pl. This means that the user's analytical identity on the BIP is carried over between the BIP and the ZLM portal (zlm.lodz.pl) — due to thecookie_domain: autoconfiguration in gtag. This is a separate cross-domain vector from the shared container identifier (UA-25825547-40) also used by uml.lodz.pl and lodz.pl. - ⚠️
After the session, 9 tracking cookies remain (
_ga*~2 years, YouTube cookies ~2 years). Unlike bip.uml.lodz.pl, F5 BIG-IP session management cookies are missing — ZLM likely hosts its BIP on a separate infrastructure.
Legal Context (BIP)
bip.zlm.lodz.pl is not an ordinary information page. It is the Public Information Bulletin of the Municipal Housing Management (Zarząd Lokali Miejskich) in Łódź — a tool for executing the right of access to public information under Art. 61 of the Constitution of the Republic of Poland, operated within the regime of the Act of 6 September 2001 on Access to Public Information and the Regulation of the Ministry of Internal Affairs and Administration of 18 January 2007 on the BIP. A citizen exercising their constitutional right of access to public information cannot be subjected to commercial tracking as an unwritten condition of access. Additional circumstance: ZLM is a separate data controller relative to UMŁ and the Municipal Library, yet it shares the measurement layer with them (the Library's GA4 property G-30F084ZHSL, and the shared UA-25825547-40 container) — without a public declaration of joint controllership within the meaning of Art. 26 GDPR.
Overall Assessment: The pattern is technically similar to bip.uml.lodz.pl (identical Google containers, identical Consent Mode configuration, the same deceptive TYPO3 cookiebox), but additionally embeds a Twitter iframe and utilizes a different hosting architecture (no F5 layer). The fact that the BIP of another separate data controller uses the exact same measurement infrastructure as UMŁ strengthens the hypothesis of data joint controllership without a public declaration.
Data Flow (Identified Recipients)
- Google LLC – Google Analytics 4 (property
G-30F084ZHSL, endpointregion1.analytics.google.com/g/collect), Universal Analytics (UA-25825547-40), Google Signals / DoubleClick (endpointstats.g.doubleclick.net/g/collect) - Meta Platforms Ireland Ltd. – Facebook SDK (
connect.facebook.net/pl_PL/sdk.js) loaded; beacon calls tofacebook.com/trwere not recorded in this measurement - YouTube (Google) –
player_api+ widget API, setting cookies for the.youtube.comdomain - X Corp. (formerly Twitter) – iframe
platform.twitter.com/widgets/widget_iframeembedded with originbip.zlm.lodz.pland thewidgets.jsscript; no X/Twitter cookies found in the cookie jar of this measurement - ads.biblioteka.lodz.pl – external ad server (Revive Adserver, endpoint
/www/delivery/asyncjs.php) belonging to the Municipal Library in Łódź — a separate data controller
CMP Detection
A custom CMP embedded in the TYPO3 template was detected (typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js). The script loads, but does not constitute an opt-in mechanism — it does not block the execution of Google Analytics, Facebook SDK, YouTube, or the Twitter widget before the user's decision. In data_layer.json, Google Consent Mode commands (consent default, consent update) are missing, and payloads to /g/collect contain the gcd=13l3l3l2l1l1 signal, indicating a lack of integrated CMP with the Consent Mode layer.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
https://mpu.lodz.pl/
SCAN ID: 20260306_201556_b3e7d004
Data Controller: Miejska Pracownia Urbanistyczna
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions (Scanner)
- 🔴
Two GA4 properties running simultaneously without Consent Mode:
G-30F084ZHSL(Library) +G-W8F2064SGL(new) withgcd=13l3l3l2l1l1+npa=1+pscdl=noapi - 🔴
Scroll depth 90% event transmitted to
G-W8F2064SGLprior to any user decision - ⚠️
Legacy UA container
UA-25825547-40remains active concurrently with both GA4 properties - -
The
cookie-box.jsCMP (TYPO3) is present but disconnected from Google Consent Mode - -
Facebook SDK + YouTube widget API + Twitter widgets +
lodz.pl/livebar/widget - - Timeline is stable (before_navigation = 0). No retroactive cookie clearing.
Privacy Policy Analysis vs Tags
G-30F084ZHSL and UA UA-25825547-40 with other municipal domains) without a declaration of joint controllership (Art. 26 GDPR). The website belongs to an entity handling local spatial planning — data mapping tracking interest in specific spatial plots or zoning layouts requires an assessment of proportionality. The cookie-box CMP fails to convey consent signals to gtag — a classic blueprint of the uml.lodz.pl family.📄 Show Domain Assessment ▼
Conclusions and Violations
- 🔴 Dual GA4 properties tracking without Consent Mode. Pings routed concurrently to
tid=G-30F084ZHSL(Municipal Library) andtid=G-9NTNY6Z0NB(presumably dedicated to MOSiR). Both carry identical metrics parameters:gcd=13l3l3l2l1l1,npa=1,pscdl=noapi, anddma=1. The cookie-box CMP fails to integrate with Google's Consent API. - 🔴 Cross-controller + legacy UA — GA4 property
G-30F084ZHSL(owner: Municipal Library) is active onmosir.lodz.plalongside legacyUA-25825547-40and GTM containerGTM-K44FPW9. The client identifiercid=2028970183.1772824802is shared across the entire ecosystem. - 🔴 Advanced events tracked without consent — a
scrollevent with parameterep.percent_scrolled=90was recorded and routed toG-9NTNY6Z0NB(viaregion1.google-analytics.com/g/collect). Scroll depth tracking operates prior to any interaction with the CMP banner. - ⚠️ Facebook SDK without the Pixel —
connect.facebook.net/pl_PL/sdk.jsloaded (two instances). However, Pixel beacons, the_fbpcookie, andsignals/configrequests are absent. The SDK is present but inactive tracking-wise in this measurement. - ⚠️ Third-party widgets on a sports and recreation domain — YouTube player_api + widgetapi, Twitter widgets.js + iframe, and the UMŁ livebar widget (
lodz.pl/livebar/) are embedded. These components dropVISITOR_INFO1_LIVE,YSC,__Secure-YNID, and__Secure-ROLLOUT_TOKENcookies without first-party control. - ⚠️ CMP present but ineffective against Google — script path resolves to
/typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js. No consent commands exist in the data_layer. Google tags (including GTM-K44FPW9) initialize and transmit data independently of the CMP state. - ⚠️ No signals in storage + stable profile — localStorage and sessionStorage remain empty. The cookie jar timeline is identical across all stages (before_navigation = 0, no retroactive clearing). The Library's ad server
ads.biblioteka.lodz.plis active (standard infrastructure of the lodz.pl family).
Legal Context (Municipal Sports and Recreation Center in Łódź)
MOSiR executes public tasks within the scope of physical culture, sport, and recreation (Physical Culture Act of June 25, 2010). The page handles sports events, recreational facilities, membership passes, and communications with citizens — involving data of a less sensitive nature than MOPS, but remaining within a public administration framework combined with commercial monetization elements (advertisements, partnerships, service sales).
Layer A — controller's compliance culture. The cookie-box CMP (shared across the uml_portal family) was deployed, but was not integrated with Google's Consent Mode or GTM. A new GTM container GTM-K44FPW9 and a dedicated GA4 property G-9NTNY6Z0NB were appended while simultaneously preserving the shared G-30F084ZHSL asset linked to the Municipal Library — operating without transparent fulfillment of Art. 26 GDPR.
Layer B — market value of the behavioral profile. A sports and recreation domain generates structural interest data (events, venues, passes) — highly attractive for behavioral profiling and audience building within Google Ads / Meta. Routing scroll depth + page_view metrics to two parallel GA4 properties expands the signal value far outside the statutory public mandates of MOSiR.Domain assessment summary – mosir.lodz.pl
| Criterion | Assessment |
|---|---|
| Launching trackers before consent | 🔴 Yes — two GA4 properties + UA + GTM running with gcd=13l3l3l2l1l1 and pscdl=noapi; scroll depth 90% transmitted |
| CMP Effectiveness | ⚠️ Present (TYPO3 cookie-box), but disconnected from Google Consent Mode or GTM |
| Data transmission to third parties | 🔴 Yes — shared G-30F084ZHSL (Library) + YouTube/Twitter widgets + ads.biblioteka.lodz.pl |
| Cross-controller identity | 🔴 Active deployment (G-30F084ZHSL + G-9NTNY6Z0NB + UA-25825547-40) |
| Facebook Pixel | Refusal default (Only the SDK loads, dropping no beacons) |
| Overall assessment | 🔴 Severe violation — multiple GA4 properties running without a consent signal + cross-controller deployment on a domain with commercial layers |
Verdict: On mosir.lodz.pl, two parallel GA4 properties (G-30F084ZHSL and G-9NTNY6Z0NB) as well as legacy UA (UA-25825547-40) initialize with the configuration metrics gcd=13l3l3l2l1l1 + pscdl=noapi. The cookie-box CMP fails to convey consent signals. Advanced scroll depth events are tracked and dispatched before user interaction. Furthermore, cross-controller sharing occurs with the Municipal Library alongside the deployment of the Facebook SDK and YouTube/Twitter widgets. This establishes a violation of the principles of lawfulness and data minimization (Art. 5 and 6 GDPR) along with the joint controllership transparency mandates of Art. 26 GDPR. The Facebook Pixel is inactive, though the third-party tracking surface remains extensive.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
No privacy policy / GDPR links present in the footer; MOSiR BIP: https://bip.mosir.lodz.pl/
https://mosir.lodz.pl/
SCAN ID: 20260306_202001_8e86892d
Data Controller: Miejski Ośrodek Sportu i Rekreacji
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions (Scanner)
- 🔴
Two GA4 properties running simultaneously without Consent Mode:
G-30F084ZHSL(Library) +G-9NTNY6Z0NBwithgcd=13l3l3l2l1l1+npa=1+pscdl=noapi - 🔴
Cross-controller identity sharing via
G-30F084ZHSL+ legacy UA containerUA-25825547-40+ GTM containerGTM-K44FPW9on the MOSiR domain - ⚠️ Facebook SDK loaded (connect.facebook.net), but without an active Pixel (missing fbevents.js, _fbp, and signals/config)
- -
YouTube widget + Twitter widgets + UMŁ livebar (
lodz.pl/livebar/) → third-party cookies from YouTube/Twitter - - cookie-box.js CMP (TYPO3) present; ads.biblioteka.lodz.pl/asyncjs.php active; cookie timeline stable, local/sessionStorage empty
- -
Scroll depth 90% transmitted to
G-9NTNY6Z0NB(scrollevent withepn.percent_scrolled=90)
Privacy Policy Analysis vs Tags
G-30F084ZHSL (Municipal Library) on the MOSiR domain. Legacy UA + new GTM GTM-K44FPW9 operate without integration with the TYPO3 cookie-box. A sports and recreation domain featuring commercial and event elements — resulting in a higher exposure to third-party tracking than purely informational sites.📄 Show Domain Assessment ▼
Conclusions and Violations
- 🔴 Dual GA4 without Consent Mode — concurrently pinged:
tid=G-30F084ZHSL(Municipal Library) andtid=G-9NTNY6Z0NB(presumably dedicated to MOSiR). Both carry identical metrics parameters:gcd=13l3l3l2l1l1,npa=1,pscdl=noapi, anddma=1. The cookie-box CMP fails to integrate with Google's Consent API. - 🔴 Cross-controller + legacy UA — GA4 property
G-30F084ZHSL(owner: Municipal Library) is active onmosir.lodz.plalongside legacyUA-25825547-40and GTM containerGTM-K44FPW9. The client identifiercid=2028970183.1772824802is shared across the entire ecosystem. - 🔴 Advanced events tracked without consent — a
scrollevent with parameterep.percent_scrolled=90was recorded and routed toG-9NTNY6Z0NB(viaregion1.google-analytics.com/g/collect). Scroll depth tracking operates prior to any interaction with the CMP banner. - ⚠️ Facebook SDK without the Pixel —
connect.facebook.net/pl_PL/sdk.jsloaded (two instances). However, Pixel beacons, the_fbpcookie, andsignals/configrequests are absent. The SDK is present but inactive tracking-wise in this measurement. - ⚠️ Third-party widgets on a sports and recreation domain — YouTube player_api + widgetapi, Twitter widgets.js + iframe, and the UMŁ livebar widget (
lodz.pl/livebar/) are embedded. These components dropVISITOR_INFO1_LIVE,YSC,__Secure-YNID, and__Secure-ROLLOUT_TOKENcookies without first-party control. - ⚠️ CMP present but ineffective against Google — script path resolves to
/typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js. No consent commands exist in the data_layer. Google tags (including GTM-K44FPW9) initialize and transmit data independently of the CMP state. - ⚠️ No signals in storage + stable profile — localStorage and sessionStorage remain empty. The cookie jar timeline is identical across all stages (before_navigation = 0, no retroactive clearing). The Library's ad server
ads.biblioteka.lodz.plis active (standard infrastructure of the lodz.pl family).
Legal Context (Municipal Sports and Recreation Center in Łódź)
MOSiR executes public tasks within the scope of physical culture, sport, and recreation (Physical Culture Act of June 25, 2010). The page handles sports events, recreational facilities, membership passes, and communications with citizens — involving data of a less sensitive nature than MOPS, but remaining within a public administration framework combined with commercial monetization elements (advertisements, partnerships, service sales).
Layer A — controller's compliance culture. The cookie-box CMP (shared across the uml_portal family) was deployed, but was not integrated with Google's Consent Mode or GTM. A new GTM container GTM-K44FPW9 and a dedicated GA4 property G-9NTNY6Z0NB were appended while simultaneously preserving the shared G-30F084ZHSL asset linked to the Municipal Library — operating without transparent fulfillment of Art. 26 GDPR.
Layer B — market value of the behavioral profile. A sports and recreation domain generates structural interest data (events, venues, passes) — highly attractive for behavioral profiling and audience building within Google Ads / Meta. Routing scroll depth + page_view metrics to two parallel GA4 properties expands the signal value far outside the statutory public mandates of MOSiR.Domain assessment summary – mosir.lodz.pl
| Criterion | Assessment |
|---|---|
| Launching trackers before consent | 🔴 Yes — two GA4 properties + UA + GTM running with gcd=13l3l3l2l1l1 and pscdl=noapi; scroll depth 90% transmitted |
| CMP Effectiveness | ⚠️ Present (TYPO3 cookie-box), but disconnected from Google Consent Mode or GTM |
| Data transmission to third parties | 🔴 Yes — shared G-30F084ZHSL (Library) + YouTube/Twitter widgets + ads.biblioteka.lodz.pl |
| Cross-controller identity | 🔴 Active deployment (G-30F084ZHSL + G-9NTNY6Z0NB + UA-25825547-40) |
| Facebook Pixel | ✅ Inactive (SDK loads but drops no beacons) |
| Overall assessment | 🔴 Severe violation — multiple GA4 properties running without a consent signal + cross-controller deployment on a domain with commercial layers |
Verdict: On mosir.lodz.pl, two parallel GA4 properties (G-30F084ZHSL and G-9NTNY6Z0NB) as well as legacy UA (UA-25825547-40) initialize with the configuration metrics gcd=13l3l3l2l1l1 + pscdl=noapi. The cookie-box CMP fails to convey consent signals. Advanced scroll depth events are tracked and dispatched before user interaction. Furthermore, cross-controller sharing occurs with the Municipal Library alongside the deployment of the Facebook SDK and YouTube/Twitter widgets. This establishes a violation of the principles of lawfulness and data minimization (Art. 5 and 6 GDPR) along with the joint controllership transparency mandates of Art. 26 GDPR. The Facebook Pixel is inactive, though the third-party tracking surface remains extensive.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
No privacy policy / GDPR links present in the footer; MOSiR BIP: https://bip.mosir.lodz.pl/
https://atlasarena.pl/ ŁOT Group
SCAN ID: 20260307_072753_5e64d738
Data Controller: MAKiS sp. z o.o. (100% City owned)
Hosting/IT: IONOS-AS This is the joint network for IONOS, Fasthosts, Arsys, 1&1 Mail and Media and 1&1 Telecom. Formerly known as 1&1 Internet SE., DE
Technical Conclusions
- 🟢 Cookiebot CMP works correctly – no mass initialization of tracking tags was observed before the user's decision.
- 🟡 PixelYourSite plugin present – requires verification of its integration with Cookiebot.
- - After the session, potentially tracking cookies exist (2 pcs.).
Privacy Policy Analysis vs Tags
📄 Show Domain Assessment ▼
Audit Summary: atlasarena.pl
Latest scan: 20260307_072753_5e64d738
Conclusions and Violations
- 🟢 Cookiebot CMP works correctly – no mass initialization of tracking tags was observed before the user's decision.
- 🟡 PixelYourSite (Free) plugin present – requires verification of its integration with Cookiebot.
- 🟡
After the session, a first-party tracking cookie
gaVisitorUuidremains (valid for 2 years).
Overall Assessment: The website performs significantly better than most of the analyzed municipal domains. The Cookiebot CMP most likely effectively delays/blocks trackers until consent is given.
Data Flow (Identified Recipients)
- Google – reCAPTCHA, Google Analytics (G-RJ3LFRYX2R)
- Meta (Facebook) – Facebook Pixel (FB:1380002969841302)
- Others – an.gr-wcon.com, gr-cdn.com, Weglot, Userway
CMP Detection
Wykryto Cookiebot – it appears well-integrated and effective at blocking/delaying tags before the user's decision.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Cookiebot implemented correctly, but missing privacy links in the footer/page. The contact form includes a text stating that the privacy policy and information obligation can be found on the Makis.pl website.
https://lodz.pl/ ŁOT Group
SCAN ID: 20260306_201450_b6d79db5
Data Controller: Biblioteka Miejska w Łodzi
Hosting/IT: Hetzner
lodz.pl is a commercial publishing portal with a fully monetized Google advertising stack.
Technical Conclusions (Scanner)
- 🔴
Full Google monetization stack: AdSense (
ca-pub-6662457014686579), three Google Ads Conversion IDs (AW-790142032,AW-10940984035,AW-10886899517) — conversion pings togoogleadservices.comandgoogleads.g.doubleclick.net. All before user decision. - 🔴
Facebook Pixel active (ID
528537619394728) —fbevents.js, config load, cookie_fbp(90 days). Plus 6 iframe Facebook Like buttons for articles. - 🔴
Two GA4 properties with the same
cid=30299385:G-30F084ZHSL(Municipal Library) +G-K51BYYXXYF(own lodz.pl) + DoubleClick. Additionally, Google Tag containerGT-5DH5KDR(server-side). - ⚠️
Google Funding Choices CMP (dedicated solution for AdSense publishers) implemented, cookie
FCCDCFset, iframe__tcfapiLocator(IAB TCF v2) present. Despite this,pscdl=noapiin GA pings — Consent Mode is not integrated with the CMP layer. - -
13 cookies remain stable throughout the entire measurement cycle. New elements compared to the municipal domain family:
_gcl_au(Google Conversion Linker),_fbp(Facebook Pixel),FCCDCF(FC decision),OAIDonads.biblioteka.lodz.pl(Revive Advertiser ID, 3 years).
Privacy Policy Analysis vs Tags
pscdl=noapi). The entire stack fires prior to user decision.📄 Show Domain Assessment ▼
Conclusions and Violations
- 🔴 Publishing portal with full Google advertising monetization — unique within the domain family. Google AdSense as publisher (
ca-pub-6662457014686579, scriptpagead2.googlesyndication.com/pagead/js/adsbygoogle.js), three different Google Ads Conversion IDs (AW-790142032,AW-10940984035,AW-10886899517) with active pings towww.google.com/ccm/collect,googleadservices.com/pagead/conversion/10940984035/, andgoogleads.g.doubleclick.net/pagead/viewthroughconversion/10940984035/. All identifiers transmiten=conversion/en=page_viewevents before user decision. Cookie_gcl_au(Google Conversion Linker) is set. - 🔴 Facebook Pixel active (not just the SDK). ID
528537619394728, loaded viaconnect.facebook.net/signals/config/528537619394728+fbevents.js. Cookie_fbp=fb.1.1772824492321.199835837329971849set (90 days). Additionally, 6 iframe Facebook Like buttons are deployed for individual articles — each generating a request to Facebook with the article URL as referrer, exposing precisely which articles the user has on their screen. - 🔴 Two GA4 properties with the same cid + server-side Google Tag. GA4 ping
G-30F084ZHSL(Municipal Library, consistent across the domain family) +G-K51BYYXXYF(own lodz.pl) + shared UAUA-25825547-40, all usingcid=30299385.1772824492. DoubleClick receives pings for both GA4 properties. Additionally, the new Google Tag containerGT-5DH5KDRis active — theGT-prefix marks a newer generation of Google Tag containers (server-side data collection). - 🔴 Google Funding Choices CMP present but ineffective. lodz.pl deployed a dedicated CMP solution for AdSense publishers (
fundingchoicesmessages.google.com/i/ca-pub-6662457014686579). CookieFCCDCFcontains the CMP choice. The__tcfapiLocatoriframe confirms support for IAB TCF v2. Despite this, thepscdl=noapiparameter across all GA pings signifies "no Consent API integration" — Google Consent Mode does not receive consent signals from Funding Choices. Three compliance layers (FC + TCF v2 + Consent Mode) are implemented in parallel but remain technically decoupled. - 🔴 The Library's Revive Adserver utilizing a persistent Advertiser ID. The
OAID(OpenX Advertiser ID) cookie onads.biblioteka.lodz.plis set for 3 years (until 2027-11). Unlike other analyzed domains where only theasyncjs.phpscript was loaded, here Revive sets its own persistent identifying cookie, pinning the user inside the Library's ad server ecosystem. - ⚠️ Facebook Like button iframes expose the specific articles visited by the user. In
iframes.json, 6 embedded "Like" iframes are present, each with ahrefparameter pointing to a concrete article on lodz.pl (including pieces on Widzew Łódź, the POW renovation, historic clubs, and life-saving boxes). Each of these iframes transmits information to Facebook detailing exactly what content resides within the user's viewport — even if the user never clicks "Like". A standard flaw of embedding native Facebook Like plugins. - ⚠️ Consent Mode is "consent not set":
gcd=13l3l3l2l1l1,npa=1,dma=1. The behavioral signal feeds Google's audience models despite the non-personalized flag — the canonical pattern of this domain family, with the distinct delta that conversion signals from three Google Ads campaigns and Pixel signals are added on top here. - ⚠️ UMŁ newsletter iframe + Twitter widget embedded.
newsletter.uml.lodz.pl/site2/.../webforms_id=E(newsletter signups for the City Hall) and a Twitter iframe with origin=lodz.pl are embedded.
Assessment summary – lodz.pl
| Criterion | Assessment |
|---|---|
| Launching trackers before consent | 🔴 Severe violation |
| Google AdSense (publisher) | 🔴 Advertising monetization |
| Google Ads Conversion Tracking | 🔴 Three distinct campaigns |
| Facebook Pixel | 🔴 Active + Like button iframes |
| Effectiveness of CMP (Google Funding Choices + TCF v2) | 🔴 Deployed, ineffective (pscdl=noapi) |
| Two GA4 properties + server-side Google Tag | 🔴 Same cid routed to two separate properties |
| Revive Adserver with persistent OAID | 🔴 3 years |
| Overall assessment | 🔴 Very poor — commercial advertising stack operating without effective consent |
Verdict: The root domain of the Łódź ecosystem operates as a commercial publishing portal with a fully monetized Google advertising stack (AdSense, three Google Ads conversion tracking IDs, server-side Google Tag, two GA4 properties + DoubleClick) and an active Facebook Pixel. Three compliance layers were deployed (Google Funding Choices, IAB TCF v2, Consent Mode), yet they are not integrated with each other — the pscdl=noapi parameter across all GA pings confirms that Consent Mode fails to receive consent signals from FC/TCF. The Library's Revive Adserver sets a persistent Advertiser ID valid for 3 years. Facebook Like button iframes expose the titles of specific articles present within the user's viewport. The domain requires an independent ownership verification: who owns the AdSense account ca-pub-6662457014686579, who operates the three Google Ads campaigns, and who controls GA4 property G-K51BYYXXYF and Facebook Pixel 528537619394728 — as these metrics isolate the actual boundaries of liability for the controller/joint controllers.
🔬 Extended Analysis: Methodology Rentgen vs Scanner ▼
Methodological Note: Our automated Scanner focuses on mapping out advertising, analytical, and tracking infrastructure. In parallel, "Rentgen" was applied (a browser plugin created by the Internet. Czas działać! foundation). Rentgen relies on the methodology of privacy activists, for whom any external server connection made without explicit consent is treated as a potential data exposure. The following breakdown offers a unique fusion of both analytical horizons.
Evidentiary Consistency
- Timeline alignment: Raw data documenting the loading logic aligns perfectly with network logs. Tracking pack initialization occurs fractions of a second after the DOM loads, uniquely demonstrating early script execution prior to user decision.
- Confirmation of early tracking: Rentgen confirms early execution of tracking scripts alongside multiple connections to external endpoints (Google, Meta, Twitter/X). This anchors the thesis regarding the lack of effective tracker blocking before interaction.
- Subdomain visibility deltas: The Scanner maps tracking-specific domains. Rentgen logs a wider radius of external handshakes (including fonts, generic CDNs, etc.). From a GDPR activist standpoint, any such connection executed without consent can be interpreted as a potential data leak.
Deeper analysis of data flows:
- Expansive Advertising Infrastructure (Google Ads): Requests with triple remarketing identifiers were recorded (
tids=AW-557285855~AW-11108391222~AW-665139254) alongside AdSense integration (client=ca-pub-6662457014686579). This reflects explicit monetization of municipal portal traffic. - Active Meta Pixel: Capture of a payload carrying a
PageViewevent (Pixel ID: 528537619394728). The Pixel initializes instantly and routes metrics straight to Meta's servers. - EU Geolocation Detection: Google Analytics logs the user as residing within the GDPR jurisdiction (
_eu=EAAAAGA). - Cross-domain Referrer Leak: Embedded widgets (including the newsletter) pass sub-paths and source data out to external services.
- Twitter Session Tracking: Embedded elements generate a
session_idpassed back tosyndication.twitter.combefore any intentional user action occurs.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
The privacy policy is available at lodz.pl/polityka-prywatnosci/ — the link is visible in the service contact menu and within the consent banner when options are expanded. Note: The policy does not contain an effective date or a last updated date — preventing verification of its validity period and change log history.
https://kartaturysty.lodz.travel/ ŁOT Group
SCAN ID: 20260306_201815_708851ac
Data Controller: Łódzka Organizacja Turystyczna (ŁOT)
Hosting/IT: Autonomous System for Dataspace P.S.A., PL
Technical Conclusions
- ✅
Zero behavioral tracking in the front-end layer. No Google Analytics, no GTM, no Facebook, no YouTube, no DoubleClick, no Library ad server, no Twitter.
data_layer.jsonis empty. - ✅
Cookies are not set before the user's decision. Throughout the entire measurement cycle, only
JSESSIONIDis present — an application session cookie, not a tracker.
Privacy Policy Analysis vs Tags
📄 Show Domain Assessment ▼
Conclusions and Violations
- ✅ Zero behavioral tracking in the front-end layer.
The following do not occur in `scripts_dom.json`: Google Tag Manager, Google Analytics (analytics.js, gtag/js), Facebook SDK, Facebook Pixel, YouTube API, Twitter widgets, DoubleClick,ads.biblioteka.lodz.plad server, TYPO3 cookiebox, Klaro, or thelodz.pl/livebarwidget.data_layer.jsonis empty — completely missing any GTM measurement layer. Unlikekartalodzianina.pl(which utilizes Consent Mode v2 with cookieless pings), Karta Turysty does not conduct Google analytics at all. - ✅ Cookies are not set before the user's decision.
The measurement timeline (before_navigation→after_domcontentloaded→after_load→after_async_window) indicates the presence of onlyJSESSIONIDthroughout the entire session lifecycle — session-only (expires=-1), on thekartaturysty.lodz.travelhost, functioning as a technically necessary application session cookie. Zero trackers. - ⚠️ Google Fonts loaded remotely — the only concrete GDPR issue.
The page fetches two font families (Montserrat, Poppins) fromfonts.googleapis.com/css2(stylesheet) and corresponding WOFF2 files fromfonts.gstatic.com. Each of these requests transmits the user's IP address and HTTP headers to Google servers in the USA, without obtaining consent and without a legal basis specified in the privacy policy.
The ruling of the German Landgericht München I of 20 January 2022, case ref. 3 O 17493/20 deemed remote loading of Google Fonts a violation of Art. 6(1) GDPR — the IP address is personal data within the meaning of the CJEU Breyer judgment (C-582/14), and its transmission to Google lacks a basis in user consent, contract, or legitimate interest. Standard technical solution: hosting fonts locally on the operator's server (self-hosted webfonts). The LG München ruling is not binding for Polish courts but is widely cited in data protection doctrine across the EEA. - ⚠️ External scripts from public CDNs without an integrity signature (SRI).
The page loads:cdnjs.cloudflare.com/ajax/libs/limonte-sweetalert2/10.10.0/sweetalert2.min.jsandunpkg.com/leaflet@1.9.1/dist/leaflet.js. These are popular front-end libraries, but loaded without theintegrityattribute — presenting a supply chain risk. This is not a GDPR violation, but rather a signal concerning application security hygiene. - ⚠️ The
JSESSIONIDcookie reveals architectural details and points to a shared platform withkartalodzianina.pl.
The cookie value contains the.ktlodz_zeussuffix, which identifies the backend application server instance. The naming convention is analogous tokartalodzianina.pl, where the JSESSIONID had the suffix.lodz_atena. Both sites use the same technological stack (Java EE application server), the same assets structure (assets/n/,cmsJS/,assets/visit/), identical versions of external libraries, and the same custom cookiebar (jquery.cookiebar.js) — representing two instances of a single platform handling the city's different card products.
Scope of this measurement — what is visible and what is not
The measurement covered the kartaturysty.lodz.travel landing page without interaction — without logging in, without registration, and without utilizing card features. All conclusions above apply exclusively to the front-end layer visible to an anonymous visitor.
Outside the scope of this measurement remain:
- The data layer of registered card users (personal data of tourists, attraction usage history)
- Integrations with tourist attractions, hotels, and other card service partners
- The legal model of the PPP concession agreement and data processing clauses
- The record of processing activities of the consortium operating the city's card products
- The behavior of the service after logging in and using card features (what happens in the authorized layer)
Verdict: The kartaturysty.lodz.travel front-end is the cleanest in terms of tracking out of all the analyzed domains in the Łódź ecosystem — completely free of Google Analytics, GTM, Facebook, YouTube, Twitter, DoubleClick, and the Library ad server. Cookies in the front-end layer are restricted exclusively to the application session. The only concrete problem: Google Fonts are loaded remotely, which in light of the German LG München I ruling of 20 January 2022 (case ref. 3 O 17493/20) constitutes a GDPR violation. Technical solution: hosting fonts locally. Karta Turysty shares its technical platform with Karta Łodzianina (consistent backend instance naming convention — .ktlodz_zeus alongside .lodz_atena) — both cards are powered by the same infrastructure but possess distinctly different levels of front-end analytics deployment. The backend layer of registered user data processing and the legal model of the PPP concession agreement remain outside the scope of this measurement.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
PDF in the footer; the cookie banner mentions ŁOT as the data controller
https://media.lodz.pl/ ŁOT Group
SCAN ID: 20260306_201723_e56edb54
Data Controller: Łódź Media Group / ŁOT
Hosting/IT: CF-GDA, PL
Technical Conclusions (Scanner)
- ✅
Zero third-party trackers. No Google Analytics, no GTM, no Facebook, no YouTube, no DoubleClick, no
ads.biblioteka.lodz.pl.data_layer.jsonis empty,iframes.jsonis empty. - ✅
CookieYes CMP deployed and effective. Cookie
cookieyes-consentstored with decision:consent:no,necessary:yes, all other categories (functional, analytics, performance, advertisement):no. No tracker cookies in the timeline. - ⚠️
Adobe Typekit (
use.typekit.net,p.typekit.net) — 9 font requests loaded remotely. Analogous to the Google Fonts issue (LG München I judgment, 3 O 17493/20) — user IP transmitted to Adobe Systems without consent. - -
Stack: WordPress 6.9.1, Cookie Law Info (Lite) plugin v3.4.0, Contact Form 7 v6.1.5, custom theme
lodzmediagroup. All JS/CSS resources hosted locally on media.lodz.pl. - -
Zero cross-controller identity sharing with the municipal domain family. Zero association with the measurement ecosystem of the Library (
G-30F084ZHSL) or UMŁ (UA-25825547-40).
Privacy Policy Analysis vs Tags
📄 Show Domain Assessment ▼
Conclusions and Violations
- ✅ Zero third-party trackers in the frontend layer. The following do not occur in `scripts_dom.json`: Google Tag Manager, Google Analytics (analytics.js, gtag/js), Facebook SDK, Facebook Pixel, YouTube API, Twitter widgets, DoubleClick, ad server
ads.biblioteka.lodz.pl, Klaro.data_layer.jsonis empty.iframes.jsonis empty. The page does not conduct behavioral analytics and does not embed any external social media widgets. - ✅ CookieYes CMP implemented correctly. The
cookieyes-consentcookie stores the user choice in the following format:consent:no, necessary:yes, functional:no, analytics:no, performance:no, advertisement:no. The measurement timeline (before_navigation=0 → after_domcontentloaded=1 → after_load=1 → after_async_window=1) confirms that only the CMP decision cookie is present throughout the session lifecycle. No analytical, advertising, functional, or performance cookies are dropped before consent. Plugin: Cookie Law Info Lite v3.4.0 (wp-content/plugins/cookie-law-info). - ⚠️ Adobe Typekit — remote font loading. The site fetches fonts from
use.typekit.net(7 font files with hashesaf/134b52,af/22b56a,af/3756a3,af/783f34,af/87e50a,af/b02074,af/cc7dab) and CSS files (use.typekit.net/pqs4jjt.css,p.typekit.net/p.css). Adobe Typekit is a service provided by Adobe Systems Inc. (USA) — creating an identical legal issue to Google Fonts according to the LG München I judgment of January 20, 2022 (case ref. 3 O 17493/20): user IP address is transmitted to a provider based outside the EEA without a valid legal basis. Solution: self-hosted webfonts or utilizing open-source fonts available locally. - ⚠️ Technical stack (for administrator's information). WordPress 6.9.1, jQuery, Contact Form 7 plugin v6.1.5, custom theme
lodzmediagroup. All JS/CSS scripts are hosted locally onmedia.lodz.pl. Nolocal_storageorsession_storageusage outside standardwpEmojiSettingsSupports.
Scope of this measurement — what is visible and what is not
The measurement covered the media.lodz.pl landing page without interaction. All conclusions apply exclusively to the frontend layer visible to an anonymous visitor.
Outside the scope of this measurement remain:
- The data processing layer within the CRM/newsletter databases of Łódź Media Group — a publicly declared base of roughly 174k email addresses and 170k phone numbers coupled with ad targeting capabilities.
- The legal basis for building and maintaining these databases — a question explicitly raised in the councillors' interpellation of May 22, 2026 (item 12).
- Agreements between the City of Łódź, the Municipal Library, ŁMG, and ŁOT regarding the use of data from lodz.pl portal users and the łódź.pl application for advertising and marketing purposes.
- Potential activity of analytics and profiling tools inside authenticated subpages of media.lodz.pl (if any exist).
Domain assessment summary – media.lodz.pl
| Criterion | Assessment |
|---|---|
| Launching trackers before consent | ✅ Compliant |
| Google Analytics / GTM | ✅ None |
| Facebook, YouTube, Twitter, DoubleClick | ✅ None |
| Library ad server | ✅ None |
| Cross-controller identity sharing with the municipal domain family | ✅ None |
| CMP Effectiveness (CookieYes) | ✅ Functional (decision propagated) |
| Adobe Typekit | ⚠️ Remote, IP transmission to Adobe (USA) |
| Backend layer (ŁMG CRM/newsletter databases) | ❓ Outside frontend measurement scope |
| Overall frontend layer assessment | ✅ Compliant, with one qualification (Adobe Typekit) |
Verdict: The frontend of media.lodz.pl (Łódź Media Group) is surprisingly clean regarding tracking — alongside kartaturysty.lodz.travel, it stands as one of the two domains in the analyzed Łódź ecosystem featuring a correctly working CMP and zero data transmission to third parties before user consent. This can be explained in an obvious way. Only potential clients utilizing the Media Group and ŁOT offer access this page, eliminating the need for advanced tracking typical for external portals where client bases and remarketing paths are built. The CookieYes cookie records the user choice, and no analytical or advertising cookies are deployed. The sole qualification: remote loading of Adobe Typekit fonts — analogous to the Google Fonts issue (LG München I judgment, case ref. 3 O 17493/20), with a straightforward technical resolution (local hosting). Crucial addendum: the "compliant" rating applies strictly to the frontend layer of the landing page without interaction. The actual subject of investigation regarding Łódź Media Group — the CRM/newsletter databases publicly declared in the commercial offer of ŁMG (approx. 174k emails, 170k phone numbers, ad targeting) and agreements with the City/Library regarding data exploitation from the lodz.pl portal and the łódź.pl app — resides in the backend/CRM/documentary layer, outside the capabilities of a frontend audit. Item 12 of the councillors' interpellation of May 22, 2026, concerns precisely this area.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Both links in the footer
https://biblioteka.lodz.pl/ ŁOT Group
SCAN ID: 20260306_201857_a94f04b6
Data Controller: Biblioteka Miejska w Łodzi
Hosting/IT: CF-KRK, PL
Technical Conclusions
- 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
- 🔴
No visible CMP mechanism. There are no
consent defaultorconsent updatecommands indata_layer.json. - 🔴 Data was transmitted to Google Analytics and Facebook Pixel before consent was given.
- - After the session, potentially tracking cookies exist (6 pcs.).
Privacy Policy Analysis vs Tags
📄 Show Domain Assessment ▼
Audit Summary: biblioteka.lodz.pl
Latest scan: 20260306_201857_a94f04b6
Conclusions and Violations
- 🔴
Tracking tags were firing immediately upon entering the site, before any user decision.
Google Analytics cookies (
_ga*,_gid) and Facebook cookies (_fbp) appeared. - 🔴
No visible CMP mechanism. There are no
consent defaultorconsent updatecommands indata_layer.json. - 🔴 Data was transmitted to Google Analytics and Facebook Pixel before consent was given.
- ⚠️
Persistent tracking cookies remain after the session (
_ga*,_fbp).
Overall Assessment: One of the worst analyzed websites. Lack of CMP + immediate firing of Google and Facebook tags.
Data Flow (Identified Recipients)
- Google – Google Analytics 4 (G-4XLLVG2B8P, G-VTQKC3GTDX), Universal Analytics (UA-218462078-1)
- Meta (Facebook) – Facebook Pixel (FB:357593604940620)
- Userway – accessibility widget
CMP Detection
No consent management mechanism (CMP) was detected. The website does not block tags before the user's decision.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Cookie banner links to: https://biblioteka.lodz.pl/assets/policies/COOKIES.pdf — both are PDFs
https://lodz.travel/ ŁOT Group
SCAN ID: 20260306_201751_fdf84108
Data Controller: Łódzka Organizacja Turystyczna (ŁOT)
Hosting/IT: Hetzner
lodz.travel is a commercial tourism portal with a fully monetized Google advertising stack.
Technical Conclusions (Scanner)
- 🔴
Full Google monetization stack: AdSense (
ca-pub-6662457014686579), four Google Ads Conversion IDs (AW-790142032,AW-10940984035,AW-10886899517,AW-665139254) with activeen=conversionpings togoogleadservices.com,googleads.g.doubleclick.net,www.google.com/pagead/1p-conversion/, andwww.google.pl/pagead/1p-conversion/. All before user decision. - 🔴
Facebook Pixel active (ID
710762686030917) —fbevents.js, config load. Different Pixel ID than on lodz.pl (where it was528537619394728). - 🔴
Two GA4 properties with the same
cid=1694443646:G-5TZ8847RTL(own lodz.travel) +G-30F084ZHSL(Municipal Library) + shared UA containerUA-25825547-40+ DoubleClick. GTM containerGTM-P5KSMXV. - 🔴
A
conversionevent defined in thedata_layer:send_to: AW-10940984035/V02uCO6r29MDEOPViOEo— a specific Google Ads campaign label triggered immediately upon entering the page. - 🔴
Two CMPs deployed simultaneously: the TYPO3 cookiebox from the
uml_portalpackage and Klaro fromcookies.uml.lodz.pl. Neither of them blocks trackers.pscdl=noapiacross all pings — Consent Mode is not integrated. - -
9 cookies remain stable throughout the cycle.
_gcl_lspresent in localStorage (Google Conversion Linker). Thegoogle_auto_fc_cmp_settingkey in localStorage suggests active Google Funding Choices.
Privacy Policy Analysis vs Tags
pscdl=noapi). The entire stack fires prior to user decision. The domain is managed by the Łódź Tourist Organization — using a separate FB Pixel account from lodz.pl, but sharing the exact same AdSense publisher ID and three out of four AW conversion IDs found on lodz.pl.📄 Show Domain Assessment ▼
Conclusions and Violations
- 🔴 Tourism portal with a full Google advertising monetization stack. AdSense (
ca-pub-6662457014686579) — the exact same publisher property utilized on lodz.pl. Four Google Ads Conversion IDs execute active pings:AW-790142032,AW-10940984035,AW-10886899517, andAW-665139254. Target endpoints:www.google.com/ccm/collect,www.googleadservices.com/pagead/conversion/[ID]/,googleads.g.doubleclick.net/pagead/viewthroughconversion/[ID]/,www.google.com/pagead/1p-conversion/[ID]/, andwww.google.pl/pagead/1p-conversion/[ID]/. Aconversionevent anchored to specific labelAW-10940984035/V02uCO6r29MDEOPViOEotriggers immediately upon page entry. - 🔴 Facebook Pixel active with ID
710762686030917. Loads configuration details viaconnect.facebook.net/signals/config/710762686030917+fbevents.js. This represents a distinct Pixel from lodz.pl (528537619394728) — indicating that lodz.travel operates its own independent Meta advertising account, separate from lodz.pl. - 🔴 Two GA4 properties sharing the identical cid + shared UA + DoubleClick + GTM. Pings routed to
region1.analytics.google.com/g/collectconnect both propertyG-5TZ8847RTL(dedicated to lodz.travel) and propertyG-30F084ZHSL(Municipal Library), both binding to client ID1694443646.1772824674. DoubleClickstats.g.doubleclick.net/g/collectprocesses pings for both properties. Shared UA containerUA-25825547-40is active. GTM container resolves toGTM-P5KSMXV. - 🔴 Two CMPs deployed in parallel — neither exerts any blocking effect. The custom TYPO3 cookiebox from the
uml_portalpackage (typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js) and Klaro from the central infrastructurecookies.uml.lodz.pl(klaro.js,embed.js, and its configuration file) both load successfully, yet all Google and Meta tags fire prior to any user interaction. The presence ofpscdl=noapiacross all GA and Ads pings proves that Consent Mode receives no input from either CMP layer. Additionally, localStorage logsgoogle_auto_fc_cmp_setting=[1]— confirming active Google Funding Choices for AdSense. - 🔴 AdSense iframe embedded within the DOM. Analysis of
iframes.jsonreveals the presence ofaswift_0— an AdSense advertising iframe carrying a full array of contextual parameters (resolution, viewport dimensions, user-agent hints, correlator tokens). The portal serves Google ads as a publisher. - 🔴 The Library's ad server + lodz.pl livebar are embedded. The script
ads.biblioteka.lodz.pl/www/delivery/asyncjs.phpis loaded. Thelodz.pl/livebar/iframe (the Municipal Library information widget) is present. - ⚠️ Consent Mode is "consent not set":
gcd=13l3l3l2l1l1,npa=1,dma=1,pscdl=noapi. The tracking payload feeds Google's audience modeling layers despite the non-personalized flag. This matching configuration follows the exact blueprint of theuml_portalfamily. - ⚠️ Twitter widgets + YouTube API. Scripts
platform.twitter.com/widgets.jsloads an iframe with an origin onlodz.travel. The YouTube integrations includewidgetapi.js+player_api, setting YouTube cookies bound to partitionKeyhttps://lodz.travel. - ⚠️ Cross-controller identity sharing. The exact same client identifier (
cid) is pushed in parallel to a GA4 property owned by the Municipal Library (G-30F084ZHSL) and to the dedicated GA4 property of lodz.travel (G-5TZ8847RTL). The domain is managed by the Łódź Tourist Organization (under Art. 26 GDPR — operating without a public declaration of joint controllership). - ⚠️ Shared components with lodz.pl: Shares the exact same AdSense publisher ID (
ca-pub-6662457014686579) and three out of four Google Ads Conversion IDs (AW-790142032,AW-10940984035,AW-10886899517). Exclusively deployed on lodz.travel: conversion trackerAW-665139254, dedicated GA4 propertyG-5TZ8847RTL, and a unique Facebook Pixel ID710762686030917.
Assessment summary – lodz.travel
| Criterion | Assessment |
|---|---|
| Launching trackers before consent | 🔴 Severe violation |
| Google AdSense (publisher) | 🔴 Active (identical publisher ID to lodz.pl) |
| Google Ads Conversion Tracking | 🔴 Four active tracking campaigns executing pings |
| Facebook Pixel | 🔴 Active (dedicated ID, independent of lodz.pl) |
| Effectiveness of CMPs (TYPO3 cookiebox + Klaro + FC) | 🔴 Three distinct layers, none are functional (pscdl=noapi) |
| Two GA4 properties with matching cid | 🔴 Cross-controller identity sharing |
| The Library's ad server | 🔴 ads.biblioteka.lodz.pl successfully loaded |
| Overall assessment | 🔴 Very poor — commercial tourism portal with active advertising monetization |
Verdict: The tourist portal lodz.travel (managed by the Łódź Tourist Organization) deploys a complete Google advertising monetization stack that fires prior to any user choice: AdSense (sharing the identical publisher property ca-pub-6662457014686579 found on lodz.pl), four Google Ads Conversion IDs (three shared with lodz.pl plus a dedicated tracker AW-665139254), a dedicated GA4 property G-5TZ8847RTL alongside the Library's property G-30F084ZHSL sharing the same client identifier (cid), a dedicated Facebook Pixel 710762686030917, and GTM container GTM-P5KSMXV. Three compliance layers (the TYPO3 cookiebox, Klaro, and Google Funding Choices) are running in parallel but remain technically decoupled from the Google Consent Mode layer, as evidenced by the pscdl=noapi parameter present across all tracking requests. An AdSense marketing iframe is parsed into the DOM immediately upon first entry. Despite the independent legal personality of the Tourist Organization relative to the Municipal Library, the two portals share an interconnected technical tracking infrastructure (AdSense and three conversion IDs) without a public joint controllership declaration under Art. 26 GDPR.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Privacy policy present in the last data chunk; missing a separate dedicated GDPR information clause
https://cuw.uml.lodz.pl/
SCAN ID: 20260306_201639_2d114b5e
Data Controller: Centrum Usług Wspólnych w Łodzi
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions
- 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
- 🔴
A custom CMP was detected (TYPO3 cookiebox from the
uml_portalpackage), which does not block the loading of trackers before the user's decision — a deceptive mechanism. - 🔴
Data transmitted to Google (GA4
G-30F084ZHSL+ DoubleClick) before any decision. Facebook SDK, YouTube player_api, a Twitter iframe, and the Municipal Library ad server script (ads.biblioteka.lodz.pl) were also loaded. - ⚠️
GA cookies set on the apex domain
.uml.lodz.pl— analytical identity shared with uml.lodz.pl and bip.uml.lodz.pl (details in expanded view). - 🔴
Google Consent Mode: the
gcd=13l3l3l2l1l1parameter in all/g/collectcalls indicates a lack of an integrated consent signal. Thenpa=1flag forces non-personalized ads, butcid,sid, andpage_vieware transmitted nevertheless — the signal fueling Google's audience models is sent regardless. - - After the session, 8 tracking cookies remain (4× GA, 4× YouTube). No Facebook Pixel, no second Analytics container.
Privacy Policy Analysis vs Tags
.uml.lodz.pl scope with uml.lodz.pl and bip.uml.lodz.pl) without a declaration of joint controllership (Art. 26 GDPR). An entity handling debt collection and European fund settlements itself lacking basic cookie hygiene — a matter of compliance culture for a controller accessing sensitive financial data.📄 Show Domain Assessment ▼
Conclusions and Violations
- 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
After theafter_domcontentloadedstage, Google Analytics cookies (_ga,_ga_30F084ZHSL,_gid,_gat_gtag_UA_25825547_40) and YouTube cookies were automatically set. The following scripts were loaded:google-analytics.com/analytics.js,googletagmanager.com/gtag/js(G-30F084ZHSL + UA-25825547-40),connect.facebook.net/sdk.js,youtube.com/player_api,platform.twitter.com/widgets.js,ads.biblioteka.lodz.pl/www/delivery/asyncjs.php. - 🔴 A custom consent management mechanism (CMP) was implemented, which does not block trackers before the user's decision.
A custom CMP is present on the page:typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js. The mechanism loads, but does not provide an effective opt-in — tracking scripts launch without blocking. There are noconsent defaultorconsent updatecommands indata_layer.json. Unlikecss.samorzad.lodz.pl, Klaro from the central central infrastructurecookies.uml.lodz.plhas not been deployed here. - 🔴 Data was transmitted to third parties before consent was given.
Confirmed requests:
• Google Analytics 4 (G-30F084ZHSL, belonging to the Municipal Library) →region1.analytics.google.com/g/collect(page_view, cid=86646066)
• Universal Analytics (UA-25825547-40) — cookie_gat_gtag_UA_25825547_40set (throttle token after ping)
• DoubleClick →stats.g.doubleclick.net/g/collect(same cid)
• Facebook SDK (without Pixel — nofbevents.js, no_fbpcookie)
• YouTube (player_api + widgetapi)
• Twitter widgets (iframe with origin=cuw.uml.lodz.pl)
•ads.biblioteka.lodz.pl— Municipal Library Revive Adserver (separate data controller)
Unlike domains from thelodz.plfamily, thelodz.pl/livebarwidget was not detected on CUW. - 🔴 Cross-subdomain scope cookies GA — the strongest vector of this domain.
The cookies_ga,_ga_30F084ZHSL,_gid, and_gat_gtag_UA_25825547_40are set on the apex domain.uml.lodz.pl, rather than.cuw.uml.lodz.pl. This means that CUW shares its analytical identity with the main city portal (uml.lodz.pl) and the office's Public Information Bulletin (bip.uml.lodz.pl) — the measurement identifies the same user across three formally separate services of different data controllers. Thecookie_domain: autoconfiguration in gtag results in a shared measurement namespace for the entire*.uml.lodz.plfamily. - ⚠️ YouTube cookies are partitioned (CHIPS), but with an anomaly.
They contain"partitionKey": "https://uml.lodz.pl"(notcuw.uml.lodz.pl) and"_crHasCrossSiteAncestor": true. A recurring feature of measurements across the*.uml.lodz.plsubdomains. - ⚠️ Consent Mode parameters indicate a lack of an integrated consent signal.
The parameters visible in requests are:gcd=13l3l3l2l1l1,npa=1,dma=1,dma_cps=a. The configuration indicates "consent not set" while simultaneously forcing non-personalized ads — despite this, the client ID (cid), session ID (sid), andpage_viewevent are transmitted. Thenpa=1flag limits personalized displays, but does not turn off the provisioning of Google's audience models — the behavioral signal enters the system regardless.
Legal and Market Context (Shared Services Center)
cuw.uml.lodz.pl is the website of the Shared Services Center (Centrum Usług Wspólnych) in Łódź — a budgetary unit established by resolution of the City Council on 30 March 2016, executing centralized administrative, HR-payroll, accounting, and financial services for municipal units: the Board of Roads and Transport, the Municipal Investment Center, the Municipal Greenery Board, the Municipal Urban Planning Studio, and the Animal Shelter. Within its scope of duties: conducting commissioned debt collection tasks for municipal receivables and settling projects co-financed by European funds (the Department for Project Settlements was transferred in 2018 from the UMŁ Revitalization Bureau).
Layer A — controller's compliance culture. CUW has access to the financial data of citizens subjected to municipal debt collection, as well as data of beneficiaries and partners in European fund settlements. An entity with such a mandate should represent an elevated standard of compliance hygiene across all its systems — including its own website. Actual implementation: a deceptive TYPO3 cookiebox, transmission of the client identifier to Google, DoubleClick, Facebook, and the Municipal Library ad server before any user decision. The argument here concerns not the protection of an individual visitor, but the consistency of practices of an institution entrusted with a mandate to manage sensitive financial data.
Layer B — market value of the behavioral profile. Behavioral data from the domain of a unit settling European funds represents valuable advertising inventory for sectors serving EU beneficiaries: consulting firms writing applications, law firms specializing in subsidy law, providers of project management software, banks offering bridge loans and factoring products, and audit firms. The transmission of cid to GA4 and DoubleClick feeds Google's audience building models, which are then bought by advertisers from these sectors. The npa=1 flag limits personalized display, but does not disable the use of the signal to build remarketing segments and lookalike audiences. The general EU Regulation No. 2021/1060 for the 2021-2027 perspective contains its own provisions on processing beneficiary data — exporting their behavioral profile to the Google advertising system without a legal basis goes beyond the processing purposes specified in grant agreements.
Separate circumstance: the cross-subdomain scope cookies on .uml.lodz.pl mean that the measurement identifies the same user across three formally distinct services of different data controllers — CUW, the main UMŁ portal, and the office's BIP. Joint data controllership within the meaning of Art. 26 GDPR exists without a public declaration between the units.
Assessment summary – cuw.uml.lodz.pl
| Criterion | Assessment | Comment |
|---|---|---|
| Launching trackers before consent | 🔴 Severe violation | Confirmed by cookies_timeline + payloads |
| Effectiveness of implemented CMP | 🔴 Low / deceptive | Custom TYPO3 cookie-box does not block tags (Klaro missing) |
| Data transmission to third parties | 🔴 Yes | Google (GA4 + UA + DoubleClick), Meta SDK, YouTube, Twitter, ads.biblioteka.lodz.pl |
| Consent Mode Parameters | ⚠️ Consent not set + npa=1 | Signal fuels audience models despite non-personalized flag |
| Cross-subdomain scope | 🔴 Yes — across the entire .uml.lodz.pl family | Shared identity with uml.lodz.pl and bip.uml.lodz.pl |
| YouTube cookies | ⚠️ Partitioned (CHIPS) | partitionKey https://uml.lodz.pl |
| Controller's compliance culture | 🔴 Inconsistent | Debt collection and EU settlements unit lacking cookie hygiene |
| Market value of the profile | ⚠️ EU consulting / banking sector | Audience segment valuable for advertisers serving beneficiaries |
| Overall assessment | 🔴 Poor | Full tracking stack on the domain of an entity with a sensitive mandate |
Verdict: A deceptive CMP (TYPO3 cookiebox) has been implemented on the cuw.uml.lodz.pl website, which does not block the loading of trackers before the user's decision. The exact same client identity (cid) is transmitted in parallel to a GA4 property belonging to the Municipal Library and to DoubleClick, while cross-subdomain scope cookies on .uml.lodz.pl identify the user across three formally separate services — CUW, UMŁ, and the office's BIP. The unit handles the collection of municipal receivables and settlements of European funds — a mandate requiring an elevated standard of compliance, which the deployed technical configuration fails to meet. The behavioral signal from the domain handling EU settlements represents valuable advertising inventory for the consulting and banking sectors serving beneficiaries of European funds — exported to the Google Ads system without a public legal basis and without a joint controllership declaration under Art. 26 GDPR.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Debt collection clauses separately: https://cuw.uml.lodz.pl/windykacja/klauzula-informacyjna-windykacja/
https://kartalodzianina.pl/ ŁOT Group
SCAN ID: 20260306_201700_53607701
Data Controller: Łódzka Organizacja Turystyczna (ŁOT)
Hosting/IT: Autonomous System for Dataspace P.S.A., PL
Technical Conclusions
- ✅
Consent Mode v2 implemented correctly —
ad_storage,analytics_storage,ad_user_data,ad_personalizationaredeniedby default. This is the first analyzed domain in the Łódź ecosystem with a correct implementation. - ✅
Cookies are not set before the user's decision. Throughout the entire measurement cycle (before → dom → load → async), only
JSESSIONIDis present — an application session cookie, not a tracker. - ✅
No Facebook SDK/Pixel, no YouTube API, no Twitter widgets, no DoubleClick, no
ads.biblioteka.lodz.plad server. A fundamentally simpler front-end configuration than municipal domains. - ⚠️
Consent Mode in advanced mode — despite being
denied, two cookieless pings (page_view,scroll 90%) with session metadata are sent toregion1.google-analytics.com/g/collect. Details in the expanded view. - ⚠️
GA4 property
G-ZX3TE0H6N6— dedicated to this service, outside the Municipal Library property family. The administrator of this property and the legal basis for data collection (even cookieless) must be specified in the consortium's record of processing activities. - -
External scripts from public CDNs without an integrity signature (SRI):
sweetalert2from cdnjs,leafletfrom unpkg. A front-end security hygiene signal, not a GDPR layer.
Privacy Policy Analysis vs Tags
📄 Show Domain Assessment ▼
Conclusions and Violations
- ✅ Consent Mode v2 implemented correctly in the GTM layer.
Indata_layer.json, commands are present that are missing from all analyzed municipal entity domains:
•consent defaultwithad_storage: denied,ad_user_data: denied,ad_personalization: denied,analytics_storage: denied
•consent updatemaintaining the same state (the user did not click consent during the measurement)
Cookies are not set before the user's decision. Throughout the entire measurement cycle (stagesbefore_navigation,after_domcontentloaded,after_load,after_async_window), onlyJSESSIONIDis present in the cookie jar — an application session cookie (session-only, expires=-1), not a tracker. - ✅ No third-party trackers on the front-end layer.
The following do not occur in `scripts_dom.json`: Facebook SDK, Facebook Pixel (fbevents.js), YouTube API (player_api,widgetapi), Twitter widgets, DoubleClick,ads.biblioteka.lodz.plad server, TYPO3 cookiebox, Klaro fromcookies.uml.lodz.pl, or thelodz.pl/livebarwidget. A fundamentally simpler configuration than domains in theuml_portalandinvest_in_lodzfamilies. A custom cookiebar (assets/n/js/jquery.cookiebar.js) is present — an operator mechanism, not a deceptive packaged solution. - ⚠️ Consent Mode in advanced mode — cookieless pings to Google despite being
denied.
Two calls toregion1.google-analytics.com/g/collectare confirmed inpayloads.ndjson:
•en=page_view:tid=G-ZX3TE0H6N6,cid=1646069836.1772824623(session-only, without a persistent cookie),gcs=G100,gcd=13p3p3p2p5l1,npa=1,pscdl=denied
•en=scrollwithepn.percent_scrolled=90: analogous parameters,gcd=13q3q3q2q5l1
Google Consent Mode v2 in advanced mode assumes that tags load despite the lack of consent, but send "cookieless pings" without a persistent identifier. However, the pings contain basic data: URL, page title (dt=Karta Łodzianina), screen resolution, browser and platform version (uafvl), language, event type, and scroll depth. The IP address is visible to Google from the transport layer. In light of the CJEU Breyer ruling (C-582/14), the IP address + user-agent constitute personal data. The legal interpretation of the advanced mode has been questioned by the CNIL (France) and the Belgian DPA — a doctrinal controversy, not an obvious violation. - ⚠️ GA4 property
G-ZX3TE0H6N6— dedicated, outside the Library property family.
Unlike all analyzed municipal entity domains (which send data toG-30F084ZHSLbelonging to the Municipal Library), Karta Łodzianina uses its own GA4 property. There is no cross-controller data flow with the Library or theuml_portalfamily. Open question: who is the controller of propertyG-ZX3TE0H6N6— the PPP consortium as the operator, the City of Łódź as the concession grantor, or is it joint controllership? Behavioral data (even in the form of cookieless pings) reaches this property and is processed in Google Analytics by the entity administering the account — a proper resolution of this question should stem from the PPP concession agreement and the records of processing activities of both parties. - ⚠️ External scripts from public CDNs without an integrity signature (SRI).
The page loads:cdnjs.cloudflare.com/ajax/libs/limonte-sweetalert2/10.10.0/sweetalert2.min.js(alerts library) andunpkg.com/unpkg.com/leaflet@1.9.1/dist/leaflet.js(maps library). Both are popular, commonly used front-end libraries, but loaded without theintegrityattribute (Subresource Integrity). Supply chain risk in the front-end layer. The mere fact of hosting on a CDN does not constitute a GDPR violation — it is a signal in the application security hygiene layer. - ⚠️ The
JSESSIONIDcookie reveals an architectural detail.
The cookie value contains the.lodz_atenasuffix, which identifies the backend application server instance (a classic Java EE signature). This is not a tracker or a GDPR violation — it is an informational element about the system architecture, potentially useful for analyzing the backend data processing layer, outside the scope of the front-end scanner.
Scope of this measurement — what is visible and what is not
The measurement covered the kartalodzianina.pl landing page without interaction — without logging in, without registration, without using card features. All conclusions above apply exclusively to the front-end layer visible to an anonymous visitor.
Outside the scope of this measurement remain:
- The data layer of registered card users (personal data, service usage history)
- Integrations with card service partners (municipal transport, discount services, cultural services)
- The legal model of the PPP concession agreement and data processing clauses
- The record of processing activities of the consortium and the City of Łódź as potential joint controllers
- The behavior of the service after clicking "Accept" (what tag stack deploys after consent)
These layers require a documentary analysis of the concession agreement, access to the records of processing activities, and measurements after user interaction — outside the scope of the anonymous front-end measurement scanner.
Comparison with municipal entity domains
In the context of the comparison with the rest of the analyzed domains of the Łódź ecosystem (aquapark, botaniczny, BIPs, CSS, CUW, CUWDPS, invest, capz, samorzad), the front-end of kartalodzianina.pl is clearly better implemented in terms of consent and tracking hygiene:
| Element | Municipal entity domains | kartalodzianina.pl |
|---|---|---|
| Consent Mode v2 | ❌ No consent commands in data_layer | ✅ Correctly implemented (denied default) |
| Cookies before consent | ❌ 8-11 trackers immediately | ✅ Only JSESSIONID |
| Facebook SDK/Pixel | ⚠️ Loaded (SDK; Pixel on aquapark) | ✅ None |
| YouTube API | ⚠️ Loaded, YouTube cookies | ✅ None |
| Twitter widgets | ⚠️ Loaded, iframe | ✅ None |
| ads.biblioteka.lodz.pl | ❌ Loaded | ✅ None |
📄 Show Domain Assessment ▼
Audit Summary: kartalodzianina.pl
Latest scan: 20260306_201700_53607701
Basic information
- URL: https://kartalodzianina.pl/
- Sterile Session Status: 🔴 VIOLATION (Tracking/cookie traces before consent)
- Total Requests: 101
- Tracking Requests: 2
- Cookies Set: 1
Conclusions and Violations
- ⚠️ Detected gcd parameter in tracking requests.
- • Detected CMP elements: consent.
- ⚠️ After the session, potentially tracking cookies exist (1 pc.).
Data Flow (Identified Recipients)
External services receiving data in this session:
- region1.google-analytics.com
CMP Detection (Consent Management)
- Mechanisms/variables suggesting the use of were detected: consent
Report generated automatically based on network traffic analysis and DOM changes in an empty browser session (Before clicking the consent button).
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Cookie banner without a link to the policy.
https://zlm.lodz.pl/
SCAN ID: 20260306_201918_010ea978
ADO: Municipal Premises Authority
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions (Scanner)
- 🔴 GA4 G-30F084ZHSL (Library) + legacy UA UA-25825547-40 with gcd=13l3l3l2l1l1 + npa=1
- 🔴 CMP cookie-box.js present, but not integrated with Google Consent Mode
- ⚠️ Facebook SDK + YouTube widget + Twitter widgets + livebar lodz.pl/livebar/
- - Ad server from the Municipal Library (ads.biblioteka.lodz.pl)
- - CSP errors when loading images from GTM / livebar (do not block tracking)
- - Stable timeline. GA cookies set immediately after DOMContentLoaded.
Privacy Policy Analysis vs Tags
📸 Evidence: Page Snapshots and GDPR Documents ▼
📌 Notes from policy scan:
Footer links lead to ZLM BIP
https://zdit.uml.lodz.pl/
SCAN ID: 20260306_201618_f1dbf1a2
ADO: Roads and Transport Authority
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions
- ⚠️Redirect to uml.lodz.pl with full tracking stack.
Privacy Policy Analysis vs Tags
connect.facebook.net recorded in data flow. CMP (Klaro) configured incorrectly — gcd=13l3l3l2l1l1 detected before user decision (art. 6 sec. 1 lit. a RODO).📸 Evidence: Page Snapshots and GDPR Documents ▼
📌 Notes from policy scan:
BIP page privacy policy/RODO in the footer. Redirects to uml.lodz.pl
No archived snapshots for this domain.
https://aquapark.lodz.pl/ ŁOT Group
SCAN ID: 20260309_103954_565488af
Data Controller: Aquapark Fala sp. z o.o.
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions
- 🔴 An extensive tracking stack launched immediately upon entry — GA4 (two properties), Universal Analytics, DoubleClick, Facebook Pixel, and GTM with active scroll tracking.
- 🔴
A custom CMP was detected (TYPO3 cookiebox from the
uml_portalpackage), which does not block the loading of trackers before the user's decision — a deceptive mechanism. - 🔴
The same client ID (
cid) transmitted in parallel to two GA4 properties belonging to different controllers — the Municipal Library (G-30F084ZHSL) and the aquapark (G-N60T196VLF). Cross-controller identity sharing without a public legal basis. - 🔴
Facebook Pixel initialized (config Pixel ID
1232725160738501downloaded,_fbpcookie set,fbevents.jslibrary loaded). Thefacebook.com/trbeacon was not recorded in the measurement window — Pixel ready to transmit events. - 🔴
Municipal Library ad server (
ads.biblioteka.lodz.pl, Revive Adserver, endpoint/www/delivery/asyncjs.php) loaded on a commercial site of a municipal facility — request to a separate data controller's domain. - 🔴
Google Consent Mode: the
gcd=13l3l3l2l1l1parameter in all/g/collectcalls indicates a lack of an integrated consent signal. Thenpa=1flag (non-personalized ads) is present, butcid,sid,page_view, and thescrollevent with theepn.percent_scrolled=90parameter are transmitted nevertheless. - -
After the session, 11 tracking cookies remain (6× GA/GTM, 4× YouTube, 1× Facebook Pixel
_fbp) + 1 F5 BIG-IP session management cookie (not a tracker).
Privacy Policy Analysis vs Tags
https://aquapark.lodz.pl/typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js available on Github in 2014 and updated on 31.01.2016, which in my opinion is far from current legal and technical requirements. The same TYPO3 package (uml_portal) with the same cache-buster version that we have on botaniczny, bip.uml, and bip.zlm, as well as other services with a similar mechanism.📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Both links in the footer
https://mpk.lodz.pl/ ŁOT Group
SCAN ID: 20260309_103954_7e7bd54e
Data Controller: MPK Łódź sp. z o.o. (100% City owned)
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions
- 🔴 Total absence of a CMP — scripts_dom.json does not contain any consent mechanism (missing cookie-box.js, klaro.js, Funding Choices, CookieYes). Third-party code is loaded unconditionally.
- 🔴
Facebook legacy SDK (
connect.facebook.net/pl_PL/all.js) loaded directly on mpk.lodz.pl. Initialization confirmed in sessionStorage (fbssls_). - ⚠️
YouTube + Google Analytics loaded indirectly via the
lodz.pl/livebar/iframe (UMŁ widget). Inside the livebar context: YouTube widget API + gtag.js (UA-25825547-40 and G-30F084ZHSL). - -
YouTube cookies (
VISITOR_INFO1_LIVE,YSC,__Secure-ROLLOUT_TOKEN) appear with mpk.lodz.pl as thepartitionKey— a side effect of the livebar widget. - -
First-party elements:
JSESSIONID(session) + custom cookiescrlPgrCrntPgId4CckNmsnews(scroll progress). Timeline is stable, before_navigation = 0. - - No direct YouTube embeds on mpk.lodz.pl. No direct GA beacons detected on the main domain within this measurement.
Privacy Policy Analysis vs Tags
lodz.pl/livebar/ widget (administered by the Municipal Library). The violation of Art. 173 of the Telecommunications Law is explicit.📄 Show Domain Assessment ▼
Conclusions and Violations
- 🔴 Total absence of a CMP — no cookie consent mechanism was detected in `scripts_dom.json`. Missing cookie-box.js, klaro.js, Funding Choices, CookieYes, and Drupal EU Cookie Compliance. Third-party components (Facebook SDK) are loaded unconditionally on every visit.
- 🔴 Uncontrolled Facebook legacy SDK — the script
connect.facebook.net/pl_PL/all.jsis loaded directly on `mpk.lodz.pl` (two instances). The SDK initializes itself (confirmed in sessionStorage viafbssls_with an "unknown" status). There is no active Pixel, but loading the SDK itself requires consent. - ⚠️ Indirect tracking via the livebar widget — the iframe
https://lodz.pl/livebar/(UMŁ) injects the YouTube widget API, gtag.js with containerUA-25825547-40, and containerG-30F084ZHSLinto the page. YouTube cookies appear with mpk.lodz.pl as thepartitionKey, despite the lack of a direct YouTube embed on the main domain. - ⚠️ Legacy Universal Analytics inside the widget context —
analytics.jsand the gtag script for UA-25825547-40 are loaded inside the livebar frame. No direct GA beacons were captured on the root mpk.lodz.pl domain. - ⚠️ First-party infrastructure —
JSESSIONID(application session) and the custom cookiescrlPgrCrntPgId4CckNmsnews=1(internal tracking for news scroll progress). Both are first-party and non-profiling. - ⚠️ Limitations of previous capture path — the `payloads.ndjson` file was incomplete. The comprehensive picture (YouTube widget API + gtag inside livebar) was successfully re-constructed only through `requests.ndjson` and `responses.ndjson`.
Legal Context (Municipal Transport Company in Łódź)
MPK Łódź Sp. z o.o. operates as a municipal public transport company governed by the Act on Public Collective Transport. The website fulfills an informational and service function and is heavily visited by minors (students). It does not process special categories of data within the meaning of Art. 9 GDPR, but as a public entity, it is held to high standards of transparency.
Layer A — controller's compliance culture. No CMP has been implemented on the page, despite embedding the legacy Facebook SDK and a livebar widget that introduces additional third-party cookies and scripts. This is not a configuration error — it represents a complete lack of a base consent layer.
Layer B — market value of the signal. Low on the MPK side (as it lacks its own GA4 or AdSense containers). The primary beneficiary of the tracking remains the livebar widget (YouTube + Municipal Library GA). However, this does not exempt the administrator from the obligation to secure consent before embedding such elements.
Domain assessment summary – mpk.lodz.pl
| Criterion | Assessment |
|---|---|
| Launching trackers before consent | 🔴 Yes — Facebook SDK directly + livebar tracking without a CMP |
| Presence / effectiveness of a CMP | 🔴 CMP does not exist |
| Transmission to third parties | ⚠️ Indirect (via lodz.pl/livebar widget) + direct Facebook SDK |
| Facebook Pixel / SDK | ⚠️ Legacy SDK loaded, no active Pixel beacons found |
| YouTube / GA | ⚠️ Indirectly via livebar (UA-25825547-40 + G-30F084ZHSL) |
| Overall assessment | 🔴 Severe violation — missing CMP layer paired with the legacy Facebook SDK on a public transit website |
Verdict: One of the clearest structural breaches in the audit is documented on mpk.lodz.pl — a complete absence of a cookie consent mechanism combined with loading the legacy Facebook SDK directly on the domain. Supplementary tracking assets (the YouTube widget API and Google Analytics) are funneled indirectly via the embedded lodz.pl/livebar/ widget. While there is no direct YouTube embed or dedicated GA4 container mapped directly to the root domain, this does not mitigate the weight of the violation of Art. 173 of the Telecommunications Law. MPK Łódź Sp. z o.o. distributes digital content that drops third-party cookies without providing any possibility for the user to register consent preferences.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Detected in incognito mode: a banner is visible alongside an extensive "RODO w MPK" (GDPR at MPK) section parsed onto the homepage.
https://www.makis.pl/ ŁOT Group
SCAN ID: 20260309_103954_f4656360
Data Controller: Miejska Arena Kultury i Sportu Sp z o.o. (100% City owned)
Hosting/IT: IONOS-AS This is the joint network for IONOS, Fasthosts, Arsys, 1&1 Mail and Media and 1&1 Telecom. Formerly known as 1&1 Internet SE., DE
Technical Conclusions (Scanner)
- ✅ Cookiebot CMP active and configured
- ✅ Legacy UA tracker UA-22415839-4 loaded with type="text/plain" (blocked by CMP)
- - Accessibility tool: Userway (cdn.userway.org)
- - No GA4, Facebook Pixel, Google Ads, or Crazy Egg
- - Cookies: session-only first-party (ba6ac1318ea3a0a881974ef325909922) only
- - No active marketing beacons in payloads
Privacy Policy Analysis vs Tags
📄 Show Domain Assessment ▼
Conclusions and Violations
- ✅ Cookiebot CMP works — Cookiebot scripts (`consent.cookiebot.com`) and the consent iframe are loaded. This represents one of the rare audit cases where a CMP is genuinely active.
- ✅ Legacy UA blocked — the gtag/js?id=UA-22415839-4 tag carries a type="text/plain" attribute, meaning Cookiebot strictly blocks it before user consent.
- ⚠️ GA4 Absent — the site relies on the deprecated Universal Analytics tracking container (UA-22415839-4). No GA4 deployment was detected.
- ✅ No Pixel / Ads / session recording — Facebook SDK (outside potential embeds), Google Ads, or session recording suites are completely absent.
- - Userway (accessibility) — accessibility widget loaded. This functions as a helper tool rather than a marketing tracker (persisting preferences in localStorage).
Legal Context (Municipal Culture and Sports Arena)
makis.pl operates as the landing page of the municipal company responsible for handling sports and cultural venues within Łódź (arenas, ice rinks, major events). Visitors are primarily individuals checking out sports schedules, cultural events, or ticketing information — contextually far less sensitive than benefits portals or shelters.
Layer A — controller's compliance culture. The best performing infrastructure across the reviewed municipal domains. They utilize a professional CMP platform (Cookiebot) and effectively block processing tags prior to consent. This represents an exemplary standard relative to the rest of the uml.lodz.pl ecosystem.
Layer B — market value of the behavioral profile. Low/moderate. Data tracking structural interest in sports matches or cultural events carries a very bounded commercial value.
Audit summary – www.makis.pl
| Criterion | Assessment |
|---|---|
| Launching trackers before consent | ✅ None — UA is blocked by Cookiebot |
| CMP Effectiveness | ✅ Cookiebot active and blocking |
| Modern tracking (GA4 / Pixel / Ads) | ✅ None |
| Third-party elements | ⚠️ Only Userway (accessibility) + Cookiebot |
| Overall assessment | ✅ Positive / Medium — one of the best domains identified in the audit |
Verdict: A significantly better practice was applied on www.makis.pl than on the majority of municipal domains. They use Cookiebot as a CMP, which effectively blocks legacy UA before the user's choice. No GA4, Facebook Pixel, or Google Ads deployments were detected. The only supplementary tool remains Userway (accessibility). This serves as a benchmark for correct tracking hygiene in a municipal corporation.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
The cookie banner redirects to: https://makis.pl/polityka-prywatnosci — same page
https://pup-lodz.pl/
ADO: Poviat Labour Office in Łódź
Domain disabled from analysis
The pup-lodz.pl page is a technical redirect leading to the lodz.praca.gov.pl service. The audit report is available at the target domain.
https://lodz.praca.gov.pl/
SCAN ID: 20260309_104016_c5852ac5
Data Controller: Powiatowy Urząd Pracy w Łodzi
Hosting/IT: TM, PL
Technical Conclusions (Scanner)
- 🔴
GA4 ping executed to
www.google-analytics.com/j/collectprior to user decision:tid=G-07E8YF01RN,cid=698957334. - 🔴
Complete absence of Google Consent Mode in any shape or form — missing all parameters such as
gcd,npa,dma, orpscdl. The website completely fails to signal any consent state. - 🔴
Hybrid UA/GA4 configuration: cookies are initialized in the Universal Analytics format (
_ga=GA1.3.*,_gid,_gat), while routing metrics to a GA4 property (G-07E8YF01RN) via the legacy legacy endpoint/j/collectusing theanalytics.jslibrary. Unfinished migration more than 2.5 years after UA's sunset (July 2023). - 🔴
Embedded Google Maps (2 iframes for PUP branches) — 15 requests for vector map tiles executed to
www.google.com/maps/vt. The user's IP address is transmitted to Google during the rendering of every single tile. - 🔴
Google Translate widget (
translate.google.com/translate_a/element.js) and Google Fonts (fonts.gstatic.com) present — additional IP address transmissions to Google without valid user consent. - ⚠️
GA cookies set with a scope on
.praca.gov.pl— the analytical identity escapes the boundaries of this specific page, propagating across the parent domain. - -
8 cookies remain stable throughout the entire measurement cycle. Infrastructure: Liferay CMS (
LFR_SESSION_STATE_10206) + F5 BIG-IP (BIGipServerPool_Wortal-new, clusterwortal-77bccd544c-g2xhq).data_layer.jsonis empty — GTM is absent. - -
Methodological note: the
scripts_dom.jsonfile was missing from the upload — the full roster of loaded scripts remains unconfirmed; conclusions are anchored in raw network payloads.
Privacy Policy Analysis vs Tags
📄 Show Domain Assessment ▼
Conclusions and Violations
- 🔴 GA4 ping executed before user decision. Call routed to
www.google-analytics.com/j/collectcontainingtid=G-07E8YF01RN,cid=698957334.173049222,dl=https://lodz.praca.gov.pl/, andvp=1440x2200. Cookies_ga,_gid, and_gatare set following theafter_domcontentloadedstage. - 🔴 Complete absence of Google Consent Mode. The GA4 payload completely lacks parameters like
gcd,npa,dma,pscdl, orgcs. The page signals neither consent nor refusal — representing a classic pre-Consent Mode technical setup. Unlike the municipal domains of Łódź (which at minimum dispatchgcd=13l3l3l2l1l1as a fallback "consent not set"), lodz.praca.gov.pl contains no signaling whatsoever. - 🔴 Hybrid UA/GA4 layout — unfinished migration. Initializes cookies using the older Universal Analytics formatting architecture (
_ga=GA1.3.698957334,_gid=GA1.3.1484994928,_gat=1) paired with a GA4 measurement property (prefixG-), hitting the legacy/j/collectendpoint via the oldanalytics.jslibrary. Google fully deprecated Universal Analytics on July 1, 2023 — this configuration has been left unmigrated for more than 2.5 years. - 🔴 Embedded Google Maps — 15 vector tile requests. Two embedded map iframes (District Labor Office in Łódź + District Labor Office No. 2) execute 15 parallel tile requests to
www.google.com/maps/vt— every map tile request transmits the user's IP address, user-agent string, and specific browser details straight to Google. Executed without user consent and without a clear legal basis articulated in the privacy policy. - 🔴 Google Translate widget and Google Fonts — additional IP tracking. The active translation script (
translate.google.com/translate_a/element.js+translate.googleapis.com+www.gstatic.com/_/translate_http/) leaks user IP addresses to Google immediately upon loading. Google Fonts calls tofonts.gstatic.comtrigger an identical data transmission — paralleling the legal doctrine of the German Landgericht München I ruling of 20 January 2022 (case ref. 3 O 17493/20), which found remote embedding of Google Fonts to stand as a violation of Art. 6(1) GDPR. Technical correction for both: local hosting. - ⚠️ GA cookies set with a scope on
.praca.gov.pl— cross-domain escape. The cookies_ga,_gid, and_gatare broad-scoped to the apex domain.praca.gov.pl, rather than being restricted tolodz.praca.gov.pl. This means the analytical tracking signature of the Łódź PUP visitor is propagated across the entire government parent domain — extending beyond the local liability scope of this specific page controller. - ⚠️ Methodological note — missing
scripts_dom.jsonpayload file. The comprehensive structural breakdown of all active DOM-loaded scripts could not be verified due to a missing upload log. Technical deductions have been successfully extracted frompayloads.ndjson,cookies_timeline.ndjson,cookies.json,data_layer.json,iframes.json,local_storage.json, andsession_storage.json. Final verification of supplementary scripts would require appending the missing file or executing an updated scan path.
Legal Context (District Labor Office in Łódź)
lodz.praca.gov.pl acts as the digital infrastructure for the local District Labor Office (PUP) in Łódź, performing statutory public administration duties dictated by the Act of 20 April 2004 on Employment Promotion and Labor Market Institutions. The target audience interacting with this portal comprises unemployed individuals, citizens facing career transition, individuals seeking vocational activation tracks (internships, specialized training, business startup grants), and employers lodging job listings. Interacting with a PUP domain inherently exposes vulnerable livelihood circumstances governed by the heightened protection parameters of Art. 9 GDPR — social situation tracking (unemployment indicators), alongside sensitive health indicators (disabled citizens registering with a PUP utilize separate specialized support and funding tracks).
The controller of a public institution serving economically and socially vulnerable populations in 2026 — years after the global rollout of the GDPR and long after the mandatory integration of Google Consent Mode v2 — continues to deploy an obsolete pre-consent tracking profile, making zero attempts to register or respect user preferences. This is exacerbated by three supplementary background scripts (Maps, Translate, Fonts) executing data handshakes to Google, despite standard open-source technical alternatives existing that allow local hosting or connection stripping.
Assessment summary – lodz.praca.gov.pl
| Criterion | Assessment |
|---|---|
| Launching trackers before consent | 🔴 Severe violation |
| Google Consent Mode | 🔴 Absent in any shape or form |
| GA Configuration (UA/GA4) | 🔴 Hybrid, unfinished migration post-UA deprecation |
| Google Maps embedded | 🔴 15 tile requests leaking IP to Google |
| Google Translate + Google Fonts | 🔴 Remotely hosted, automated IP leakage |
| Cookies scope | ⚠️ Apex domain propagation to .praca.gov.pl |
| Third-party scripts (Facebook, Twitter, YouTube, DoubleClick) | ✅ None detected |
| Commercial Advertising Monetization | ✅ Absent (No AdSense, Ads, or Meta Pixel tracking) |
| Regulatory / Subject Context | 🔴 Heightened sensitivity (Art. 9 GDPR + Employment Promotion Act) |
| Overall assessment | 🔴 Poor (Total lack of Consent Mode + sensitive user context) |
Verdict: The portal of the District Labor Office in Łódź executes GA4 behavioral tracking (property G-07E8YF01RN) without any integration of Google Consent Mode — completely omitting metrics such as gcd, npa, dma, or pscdl inside its out-going payloads. The hybrid UA/GA4 technical structure connecting through the legacy /j/collect endpoint proves that the data layer was never properly zmigrated following the global retirement of Universal Analytics in July 2023. User IP addresses are automatically passed to Google via three peripheral integrations (Google Maps tile requests, Google Translate widget initialization, and remote Google Fonts stylesheets). The targeted user base is covered by the strict privacy boundaries of Art. 9 GDPR and the Act on Employment Promotion and Labor Market Institutions.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Link located in the "Urząd" (Office) service menu
https://architektmiasta.uml.lodz.pl/
SCAN ID: 20260309_104021_61f1f764
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions
- 🔴
Tracking tags were firing immediately upon entering the site, before any user decision.
After the
after_domcontentloadedstage, Google Analytics and YouTube cookies appeared. - ⚠️
Klaro CMP was detected, however, it did not effectively block tags before user interaction.
There are no
consent defaultorconsent updatecommands indata_layer.json. - ⚠️ Data was transmitted to third parties (Google, Meta, YouTube, Twitter) before consent was given.
- - After the session, potentially tracking cookies exist (11 pcs.).
Privacy Policy Analysis vs Tags
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Detected in incognito: The banner only redirects to uml.lodz.pl, no dedicated GDPR link in the footer
https://teatr-muzyczny.lodz.pl/
SCAN ID: 20260309_104016_fff92000
ADO: Musical Theatre in Łódź
Hosting/IT: TARRCI-AS, PL
Technical Conclusions
- ⚠️Position disabled from comparative evaluation due to TLS issue / unavailability of the input domain, preventing the full sterile session test under conditions comparable to other domains.
Privacy Policy Analysis vs Tags
No verifiable containers.
📸 Evidence: Page Snapshots and GDPR Documents ▼
📌 Notes from policy scan:
TLS Error — untrusted certificate. Page unavailable.
https://bip.biblioteka.lodz.pl/
SCAN ID: 20260309_104042_b2ce5a56
Data Controller: Biblioteka Miejska w Łodzi
Hosting/IT: CF-KRK, PL
Technical Conclusions
- -After the session, potentially tracking cookies exist (1 pc.).
Privacy Policy Analysis vs Tags
No assigned containers in the journalistic table.
📄 Show Domain Assessment ▼
Audit Summary: bip.biblioteka.lodz.pl
Conclusions
- 🟢
No tracking tags are fired before the user's decision. After
after_domcontentloaded, only a single Joomla session cookie was set. - 🟢 No external tracking scripts or trackers present. All scripts are first-party (Joomla + govarticle template).
- 🟢 No data transmission to third parties. All requests are first-party.
- 🟢 No need for a CMP – the page does not load any trackers requiring consent.
Overall Assessment: The website performs exemplarily in terms of privacy. It stands as an example of a well-designed public administration webpage.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Link in the service menu
https://capz.lodz.pl/
SCAN ID: 20260309_104044_19fa3625
ADO: Administrative Center for Substitute Care
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions
- 🔴 Tracking tags fired immediately upon entering the page, before any user decision.
- 🔴
Own CMP detected (cookiebox TYPO3 from the
uml_portalpackage), which does not block the loading of trackers before the user's decision — a sham mechanism. - 🔴
Data transmitted to Google (GA4
G-30F084ZHSL+ DoubleClick) before any decision. Facebook SDK, YouTube player_api and Twitter iframe were also loaded. Municipal Library ad server (ads.biblioteka.lodz.pl) andlodz.pl/livebarwidget embedded on the page. - 🔴
Google Consent Mode: parameter
gcd=13l3l3l2l1l1in all/g/collectcalls indicates lack of integrated consent signal. Flagnpa=1forces non-personalized ads, butcid,sidandpage_vieware still transmitted. - - After the session, 8 tracking cookies remain (4× GA, 4× YouTube). No Facebook Pixel — only Facebook SDK loaded.
Privacy Policy Analysis vs Tags
gcd=13l3l3l2l1l1 sent before consent is given (art. 6 sec. 1 lit. a RODO).📄 Show Domain Assessment ▼
Audit Summary: bip.biblioteka.lodz.pl
Conclusions and Violations
- 🔴 Tracking tags fired immediately upon entering the page, before any user decision.
After theafter_domcontentloadedstage, Google Analytics cookies (_ga,_ga_30F084ZHSL,_gid,_gat_gtag_UA_25825547_40) and YouTube cookies were automatically set. At the same time, the following scripts were loaded:google-analytics.com/analytics.js,googletagmanager.com/gtag/js(G-30F084ZHSL + UA-25825547-40),connect.facebook.net/sdk.js,youtube.com/player_api,platform.twitter.com/widgets.js. - 🔴 An own consent management mechanism (CMP) was implemented that does not block trackers before the user's decision.
The site has its own CMP:typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js. The mechanism loads but does not constitute an effective opt-in — Google, Facebook, YouTube and Twitter tracking scripts fire without blocking. Indata_layer.jsonthere are noconsent defaultorconsent updatecommands. - 🔴 Data was transmitted to third parties before consent was given.
Confirmed requests:
• Google Analytics 4 (G-30F084ZHSL) →region1.analytics.google.com/g/collect(page_view, cid=1213265501)
• Universal Analytics (UA-25825547-40)
• DoubleClick →stats.g.doubleclick.net/g/collect(same cid)
• Facebook SDK (no Pixel — nofbevents.js, no_fbpcookie)
• YouTube (player_api + widget)
• Twitter widgets (iframe with origin=capz.lodz.pl)
•ads.biblioteka.lodz.pl(Revive Adserver belonging to the Municipal Library — a separate data controller)
•lodz.pl/livebar.js(livebar widget). - ⚠️ YouTube cookies are partitioned (CHIPS).
They contain"partitionKey": "https://capz.lodz.pl"and"_crHasCrossSiteAncestor": true. They are isolated per top-level origin — they do not enable classic cross-site tracking, but still constitute data collected without user consent. - ⚠️ Consent Mode parameters indicate lack of integrated consent signal.
In requests the following parameters are visible:gcd=13l3l3l2l1l1,npa=1,dma=1,dma_cps=a. The configuration indicates „consent not set” with simultaneous forcing of non-personalized ads — nevertheless client identifier (cid), session identifier (sid) andpage_viewevent are transmitted. - ⚠️ Sharing of measurement infrastructure.
The site uses GA4 propertyG-30F084ZHSL(belonging to a different controller than CAPZ) and a shared UA-25825547-40 container — both present on other municipal domains. Additionally, it loads a script fromads.biblioteka.lodz.pl, transmitting a request to an external ad server without a public declaration of joint administration.
Summary of assessment – capz.lodz.pl
| Criterion | Assessment | Comment |
|---|---|---|
| Firing trackers before consent | 🔴 Serious violation | Confirmed by cookies_timeline + payloads |
| Effectiveness of implemented CMP | 🔴 Low / sham | Own TYPO3 cookie-box does not block tags |
| Transmission of data to third parties | 🔴 Yes | Google (incl. DoubleClick), Meta, YouTube, Twitter, ads.biblioteka.lodz.pl |
| Consent Mode parameters | ⚠️ Consent not set | gcd=13l3l3l2l1l1 + npa=1 |
| YouTube cookies | ⚠️ Partitioned (CHIPS) | Isolated per top-level origin |
| Shared measurement infrastructure | ⚠️ Yes | Shared GA4 (belonging to another controller) + UA + Library ad server |
| Overall assessment | 🔴 Poor | Sham CMP with full stack of Google + Meta + YouTube + Twitter trackers |
Verdict:
On the website capz.lodz.pl an own CMP (cookie-box from the uml_portal package) was implemented that does not block the loading of trackers before the user's decision. The same client identifier (cid) is transmitted in parallel to GA4 property G-30F084ZHSL (belonging to a different data controller than CAPZ) and to DoubleClick. The site transmits data to Google, Meta, YouTube, Twitter and the external ad server of the Municipal Library without effective consent and without a public declaration of joint administration under art. 26 RODO.
📸 Evidence: Page Snapshots and GDPR Documents ▼
📌 Notes from policy scan:
"Data Protection" link in the menu
https://botaniczny.lodz.pl/
SCAN ID: 20260309_104043_d3c46fd7
Data Controller: Ogród Botaniczny w Łodzi
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions
- 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
- 🔴 A custom CMP (TYPO3 cookiebox) was implemented, but it is ineffective – Google, Facebook, and YouTube tags load without restriction.
- 🔴 Data was transmitted to Google, Meta, YouTube, Twitter, and DoubleClick before consent was given.
- ⚠️
Google Consent Mode parameters indicate "consent not set" (
gcd=13l3l3l2l1l1,npa=1). - - After the session, potentially tracking cookies exist (9 pcs.).
Privacy Policy Analysis vs Tags
ads.biblioteka.lodz.pl).📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
GDPR ZZM (Zarząd Zieleni Miejskiej); CCTV clause: https://zzm.lodz.pl/files/public/uploads/RODO/KLAUZULA_INFORMACYJNA__MONITORING_ZZM.pdf
https://cuwdps.uml.lodz.pl/
SCAN ID: 20260309_104106_41c1beb1
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions
- 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
- 🔴
A custom CMP was detected (TYPO3 cookiebox from the
uml_portalpackage), which does not block the loading of trackers before the user's decision — a deceptive mechanism. - 🔴
Data transmitted to Google (GA4
G-30F084ZHSL+ DoubleClick) before any decision. Facebook SDK, YouTube player_api, a Twitter iframe, and the Municipal Library ad server script (ads.biblioteka.lodz.pl) were also loaded. - ⚠️
GA cookies set on the apex domain
.uml.lodz.pl— analytical identity shared with uml.lodz.pl, bip.uml.lodz.pl, and cuw.uml.lodz.pl (details in expanded view). - 🔴
Google Consent Mode: the
gcd=13l3l3l2l1l1parameter in all/g/collectcalls indicates a lack of an integrated consent signal. Thenpa=1flag forces non-personalized ads, butcid,sid, andpage_vieware transmitted nevertheless — the signal fueling Google's audience models is sent regardless. - - After the session, 9 tracking cookies remain (4× GA, 5× YouTube) + 1 F5 BIG-IP session management cookie (not a tracker). The hosting architecture is identical to bip.uml.lodz.pl.
Privacy Policy Analysis vs Tags
.uml.lodz.pl scope) without a declaration of joint controllership (Art. 26 GDPR). The website belongs to an entity handling Care Homes (DPS) — the mere fact of a visit reveals life circumstances qualifying under the special protection regime of Art. 9 GDPR (care for a senior, a person with a disability, or a mental illness).📄 Show Domain Assessment ▼
Conclusions and Violations
- 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
After theafter_domcontentloadedstage, Google Analytics cookies (_ga,_ga_30F084ZHSL,_gid,_gat_gtag_UA_25825547_40) and YouTube cookies were automatically set. The following scripts were loaded:google-analytics.com/analytics.js,googletagmanager.com/gtag/js(G-30F084ZHSL + UA-25825547-40),connect.facebook.net/sdk.js,youtube.com/player_api,platform.twitter.com/widgets.js,ads.biblioteka.lodz.pl/www/delivery/asyncjs.php. - 🔴 A custom consent management mechanism (CMP) was implemented, which does not block trackers before the user's decision.
A custom CMP is present on the page:typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js. The mechanism loads, but does not provide an effective opt-in — tracking scripts run without blocking. There are noconsent defaultorconsent updatecommands indata_layer.json. Unlikecss.samorzad.lodz.pl, Klaro from the central central infrastructurecookies.uml.lodz.plhas not been deployed here. - 🔴 Data was transmitted to third parties before consent was given.
Confirmed requests:
• Google Analytics 4 (G-30F084ZHSL, belonging to the Municipal Library) →region1.analytics.google.com/g/collect(page_view, cid=993688511)
• Universal Analytics (UA-25825547-40) — cookie_gat_gtag_UA_25825547_40set
• DoubleClick →stats.g.doubleclick.net/g/collect(same cid)
• Facebook SDK (without Pixel — nofbevents.js, no_fbpcookie)
• YouTube (player_api + widgetapi)
• Twitter widgets (iframe with origin=cuwdps.uml.lodz.pl)
•ads.biblioteka.lodz.pl— Municipal Library Revive Adserver (separate data controller) - 🔴 Cross-subdomain scope cookies GA — the strongest vector of this domain.
The cookies_ga,_ga_30F084ZHSL,_gid, and_gat_gtag_UA_25825547_40are set on the apex domain.uml.lodz.pl, rather than.cuwdps.uml.lodz.pl. This means that CUWDPS shares its analytical identity with the main city portal (uml.lodz.pl), the office's Public Information Bulletin (bip.uml.lodz.pl), and the Shared Services Center (cuw.uml.lodz.pl) — the measurement identifies the same user across four formally distinct services of different municipal units, despite these entities handling entirely different thematic areas (social care benefits vs. roads, transport, investments). - ⚠️ YouTube cookies are partitioned (CHIPS), but with an anomaly.
They contain"partitionKey": "https://uml.lodz.pl"(notcuwdps.uml.lodz.pl) and"_crHasCrossSiteAncestor": true. A recurring feature of measurements across the*.uml.lodz.plsubdomains. - ⚠️ Consent Mode parameters indicate a lack of an integrated consent signal.
The parameters visible in requests are:gcd=13l3l3l2l1l1,npa=1,dma=1,dma_cps=a. The configuration indicates "consent not set" while simultaneously forcing non-personalized ads — despite this, the client ID (cid), session ID (sid), andpage_viewevent are transmitted. Thenpa=1flag limits personalized displays, but does not turn off the provisioning of Google's audience models — the behavioral signal enters the system regardless.
Legal and Market Context (Shared Services Center for Care Homes)
cuwdps.uml.lodz.pl is the website of the Shared Services Center for Care Homes (Centrum Usług Wspólnych Domów Pomocy Społecznej) in Łódź — a budgetary unit of the City of Łódź providing shared operational management for municipal Care Homes (DPS). DPS are round-the-clock care institutions for elderly individuals requiring support, persons with intellectual disabilities, individuals with mental illnesses, and the chronically somatically ill. The mere fact of visiting this domain indirectly reveals life circumstances qualified under the special protection regime of Art. 9 GDPR — health data in the context of eligibility for institutional care requires medical certificates, disability ratings, or psychiatric diagnoses.
The legal framework encompasses: the Act of 12 March 2004 on Social Assistance (eligibility, placement, and operation procedures for care homes), the Act of 19 August 1994 on Mental Health Protection (for care homes admitting individuals with mental illnesses), and the Regulation of the Minister of Family and Social Policy on Care Homes. A controller operating in this domain is obliged to maintain strict discretion regarding individuals applying for placement in a care home, their families, and the residents of the facilities.
Layer A — controller's compliance culture. CUWDPS is a unit managing round-the-clock care facilities where some of the most vulnerable social groups reside — seniors in health crises, individuals with intellectual disabilities, and people with mental illnesses. An entity with such a mandate should represent an elevated standard of compliance hygiene across all its digital systems. Actual implementation: a deceptive TYPO3 cookiebox, transmission of the client identifier to Google, DoubleClick, Facebook, and the Municipal Library ad server before any user decision. The technical tracking configuration is identical to that of a commercial municipal aquapark — the controller does not differentiate the risk profile between a pool visitor and a family looking for a care home placement for an aging mother.
Layer B — market value of the behavioral profile. The segment "users linked to organizing institutional care for relatives" represents a highly valuable advertising inventory for the silver economy sectors: private care homes (in direct commercial competition with public facilities), agencies offering home care as an alternative to residential placement, medical and rehabilitation supply stores, law firms specializing in inheritance and guardianship law, health insurance providers for seniors, and funeral homes. The transmission of cid to GA4 and DoubleClick feeds Google's audience building models, which are subsequently bought by advertisers from these sectors. The fact that the signal originates from the domain of a public care unit means that a commercial competitor to the public care home can purchase the profile of a family currently applying for placement in a public facility. The city unintentionally supplies the remarketing market with segments from which its direct commercial competitors profit.
Assessment summary – cuwdps.uml.lodz.pl
| Criterion | Assessment | Comment |
|---|---|---|
| Launching trackers before consent | 🔴 Severe violation | Confirmed by cookies_timeline + payloads |
| Effectiveness of implemented CMP | 🔴 Low / deceptive | Custom TYPO3 cookie-box does not block tags (Klaro missing) |
| Data transmission to third parties | 🔴 Yes | Google (GA4 + UA + DoubleClick), Meta SDK, YouTube, Twitter, ads.biblioteka.lodz.pl |
| Consent Mode Parameters | ⚠️ Consent not set + npa=1 | Signal fuels audience models despite non-personalized flag |
| Cross-subdomain scope | 🔴 Yes — across the entire .uml.lodz.pl family | Shared identity with uml.lodz.pl, bip.uml.lodz.pl, cuw.uml.lodz.pl |
| YouTube cookies | ⚠️ Partitioned (CHIPS) | partitionKey https://uml.lodz.pl |
| Legal Context | 🔴 Elevated regime | Art. 9 GDPR + Act on Social Assistance + Act on Mental Health Protection |
| Market value of the profile | 🔴 Silver economy sector | Audience segment valuable for commercial competitors of public care homes |
| Overall assessment | 🔴 Qualified violation | The most vulnerable visitor population within the analyzed family of domains |
Verdict: A deceptive CMP (TYPO3 cookiebox) has been implemented on the cuwdps.uml.lodz.pl website, which does not block the loading of trackers before the user's decision. The exact same client identity (cid) is transmitted in parallel to a GA4 property belonging to the Municipal Library and to DoubleClick, while cross-subdomain scope cookies on .uml.lodz.pl identify the user across four formally distinct services — CUWDPS, UMŁ, CUW, and the office's BIP. The unit handles the administration of round-the-clock care facilities housing highly vulnerable groups — a mandate requiring an elevated standard of compliance, which the deployed technical configuration fails to meet. The behavioral signal from a domain handling public residential care settlements represents valuable advertising inventory for the commercial silver economy sector — exported to the Google Ads system without a public legal basis and without a joint controllership declaration under Art. 26 GDPR.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Detected in incognito: Banner links return 404 errors. A dedicated GDPR page is available in the menu.
https://css.samorzad.lodz.pl/
SCAN ID: 20260309_104105_22f6777d
Data Controller: Centrum Świadczeń Socjalnych w Łodzi
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions
- 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
- 🔴
Two simultaneous CMP mechanisms were detected: a custom TYPO3 cookiebox (
uml_portal) and Klaro hosted on the central domaincookies.uml.lodz.pl. Neither of them blocks the loading of trackers before the user's decision. - 🔴
Data transmitted to Google (GA4
G-30F084ZHSL+ DoubleClick) before any decision. Facebook SDK, YouTube player_api, a Twitter iframe, the Municipal Library ad server script (ads.biblioteka.lodz.pl), and thelodz.pl/livebarwidget were also loaded. - 🔴
Three simultaneous Google Analytics containers: GA4
G-30F084ZHSL(belonging to another controller), Universal AnalyticsUA-25825547-40(shared), andUA-178238957-1(dedicated to samorzad). Two simultaneous UAconfigcommands found in thedata_layer. - 🔴
Google Consent Mode: the
gcd=13l3l3l2l1l1parameter in all/g/collectcalls indicates a lack of an integrated consent signal. Thenpa=1flag forces non-personalized ads, butcid,sid, andpage_vieware transmitted nevertheless. - -
After the session, 10 tracking cookies remain (6× GA/UA, 4× YouTube). No Facebook Pixel found — only Facebook SDK loaded. GA cookies are set on the apex domain
.samorzad.lodz.pl— cross-subdomain identity persistence.
Privacy Policy Analysis vs Tags
📄 Show Domain Assessment ▼
Conclusions and Violations
- 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
After theafter_domcontentloadedstage, Google Analytics cookies (_ga,_ga_30F084ZHSL,_gid,_gat_gtag_UA_25825547_40,_gat_gtag_UA_178238957_1) and YouTube cookies were automatically set. The following scripts were loaded:google-analytics.com/analytics.js,googletagmanager.com/gtag/js(G-30F084ZHSL + UA-25825547-40 + UA-178238957-1),connect.facebook.net/sdk.js,youtube.com/player_api,platform.twitter.com/widgets.js,ads.biblioteka.lodz.pl/www/delivery/asyncjs.php,lodz.pl/livebar.js. - 🔴 Two simultaneous CMP mechanisms were implemented — neither of them blocks trackers.
Two consent management systems are present simultaneously on the website:
• a custom TYPO3 cookiebox from theuml_portalpackage (typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js),
• Klaro CMP hosted on the central infrastructure of UMŁ:cookies.uml.lodz.pl/klaro.js,cookies.uml.lodz.pl/cookie_config/config-c0e0b1f8065c1e3d26d050bac5180c66.js,cookies.uml.lodz.pl/embed.js.
Klaro is a professional, serious compliance solution — choosing this tool suggests a conscious decision to unify the consent system across municipal portals. However, in practice, both mechanisms load without any blocking effect: Google, Facebook, YouTube, and Twitter tracking scripts launch before any user decision. Indata_layer.json, there are noconsent defaultorconsent updatecommands. The mere fact of deploying Klaro alongside the TYPO3 cookiebox demonstrates that the administrator was aware of the legal obligation — yet the implementation ended with simply loading the script. - 🔴 Data was transmitted to third parties before consent was given.
Confirmed requests:
• Google Analytics 4 (G-30F084ZHSL) →region1.analytics.google.com/g/collect(page_view, cid=1402779805)
• Universal Analytics (UA-25825547-40) — cookie_gat_gtag_UA_25825547_40set (throttle token after ping)
• Universal Analytics (UA-178238957-1) — cookie_gat_gtag_UA_178238957_1set
• DoubleClick →stats.g.doubleclick.net/g/collect(same cid)
• Facebook SDK (without Pixel — nofbevents.js, no_fbpcookie)
• YouTube (player_api + widgetapi)
• Twitter widgets (iframe with origin=css.samorzad.lodz.pl)
•ads.biblioteka.lodz.pl— Municipal Library Revive Adserver (separate data controller)
•lodz.pl/livebar.js— livebar widget
The exact same client identity (cid=1402779805) is transmitted in parallel to a GA4 property belonging to a different controller (the Library) and to DoubleClick. - 🔴 Three simultaneous Google Analytics containers.
Two simultaneousconfigcommands are visible indata_layer.json:UA-25825547-40andUA-178238957-1. GA4 propertyG-30F084ZHSLis added on top of that. This is the first analyzed domain from theuml_portalfamily with three simultaneous Google measurement identifiers. UA-178238957-1 appears to be dedicated to the samorząd portal, but its coexistence with the shared UA-25825547-40 results in a duplicate stream of identical data to two different properties. - ⚠️ YouTube cookies are partitioned (CHIPS).
They contain"partitionKey": "https://samorzad.lodz.pl"and"_crHasCrossSiteAncestor": true. They are isolated per top-level origin — they do not allow classic cross-site tracking, but still represent data collected without user consent. - ⚠️ Consent Mode parameters indicate a lack of an integrated consent signal.
The parameters visible in requests are:gcd=13l3l3l2l1l1,npa=1,dma=1,dma_cps=a. The configuration indicates "consent not set" while simultaneously forcing non-personalized ads — despite this, the client ID (cid), session ID (sid), andpage_viewevent are transmitted. Neither the TYPO3 cookiebox nor Klaro integrates with the Google Consent Mode layer. - ⚠️ Cross-subdomain scope cookies GA.
The cookies_ga,_ga_30F084ZHSL,_gid,_gat_gtag_UA_25825547_40, and_gat_gtag_UA_178238957_1are set on the apex domain.samorzad.lodz.pl, rather than.css.samorzad.lodz.pl. This means that the analytical identity of the Social Benefits Center user is continued across all subdomains of the samorząd portal.
Legal Context (Social Benefits Center)
css.samorzad.lodz.pl is the website of the Social Benefits Center in Łódź — a unit performing social assistance tasks based on the Act of 12 March 2004 on Social Assistance as well as family and upbringing benefits. Visitors to this site are most frequently beneficiaries of social assistance or individuals applying for benefits — families in difficult economic situations, seniors, people with disabilities, and individuals seeking help for victims of domestic violence.
The mere fact of visiting this domain indirectly reveals the life circumstances of the user, which are qualified under the special protection regime of Art. 9 GDPR (data concerning health in the context of benefits for people with disabilities, data concerning social situation). The transmission of the client ID (cid) to three Google Analytics containers, DoubleClick, Facebook SDK, the Municipal Library ad server, and the Twitter widget without effective user consent fails to meet the proportionality standard of Art. 5(1)(c) GDPR. Additionally, the controller is obliged to maintain strict discretion regarding beneficiaries of social assistance.
The technical configuration of tracking on css.samorzad.lodz.pl is identical to the configuration of a commercial municipal venue (aquapark.lodz.pl) — the same Google identifiers, the same gcd=13l3l3l2l1l1, the same deceptive cookiebox, the same Library ad server. The controller does not differentiate the risk profile between a pool visitor and an individual searching for information on benefits for a victim of domestic violence.
Assessment summary – css.samorzad.lodz.pl
| Criterion | Assessment | Comment |
|---|---|---|
| Launching trackers before consent | 🔴 Severe violation | Confirmed by cookies_timeline + payloads |
| Effectiveness of implemented CMPs | 🔴 Low / deceptive | Two simultaneous CMPs (TYPO3 cookiebox + Klaro), neither blocks tags |
| Data transmission to third parties | 🔴 Yes | Google (3 containers + DoubleClick), Meta, YouTube, Twitter, ads.biblioteka.lodz.pl, livebar |
| Consent Mode Parameters | ⚠️ Consent not set | gcd=13l3l3l2l1l1 + npa=1 |
| Legal Context | 🔴 Elevated regime | Art. 9 GDPR + Act on Social Assistance of 12 March 2004 |
| YouTube cookies | ⚠️ Partitioned (CHIPS) | Isolated per top-level origin |
| Cross-subdomain scope | 🔴 Yes | GA cookies on .samorzad.lodz.pl |
| Overall assessment | 🔴 Qualified violation | Sensitive subjective context with a full stack of Google + Meta + YouTube + Twitter trackers |
Verdict: Two simultaneous CMP mechanisms have been implemented on the css.samorzad.lodz.pl website (the TYPO3 cookiebox from the uml_portal package and Klaro hosted on the central infrastructure cookies.uml.lodz.pl) — neither blocks the loading of trackers before the user's decision. The exact same client identifier is transmitted in parallel to three Google Analytics containers (including a GA4 property belonging to a separate data controller — the Municipal Library) and to DoubleClick. The technical configuration is identical to that of a commercial municipal facility (aquapark.lodz.pl), despite the domain serving beneficiaries of social assistance — a life circumstance covered by the elevated protection regime of Art. 9 GDPR and the special duty of discretion under the Act on Social Assistance.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Cookies + GDPR links in the footer
https://invest.lodz.pl/
SCAN ID: 20260309_104106_fb027515
Data Controller: Urząd Miasta Łodzi (Invest in Łódź)
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions
- 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
- 🔴
Two simultaneous CMP mechanisms were detected: a custom TYPO3 cookiebox (from the
invest_in_lodzpackage) and Klaro hosted on the central infrastructurecookies.uml.lodz.pl. Neither of them blocks the loading of trackers before the user's decision. - 🔴
Data transmitted to Google (GA4
G-30F084ZHSL+ DoubleClick) before any decision. Facebook SDK, YouTube player_api, a Twitter iframe, and the Municipal Library ad server script (ads.biblioteka.lodz.pl) were also loaded. The newsletter form collects email addresses into thenewsletter.uml.lodz.pldatabase. - ⚠️
Detected loading of the
countUp.jsscript from theinorganik.github.iodomain (GitHub Pages) — without a Subresource Integrity (SRI) signature. Supply chain risk for a public municipal site. - 🔴
Google Consent Mode: the
gcd=13l3l3l2l1l1parameter in all/g/collectcalls indicates a lack of an integrated consent signal. Thenpa=1flag limits personalized display, but the behavioral signal enters Google's audience models regardless. - -
After the session, 6 tracking cookies remain (2× GA, 4× YouTube) — unusually fewer than on other municipal domains; no classic
_gaand_giddespiteanalytics.jsbeing loaded. Client identification occurs via_ga_30F084ZHSLand thecidparameter in the ping.
Privacy Policy Analysis vs Tags
📄 Show Domain Assessment ▼
Conclusions and Violations
- 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
After theafter_domcontentloadedstage, Google Analytics cookies (_ga_30F084ZHSL,_gat_gtag_UA_25825547_40) and YouTube cookies were automatically set. The following scripts were loaded:google-analytics.com/analytics.js,googletagmanager.com/gtag/js(G-30F084ZHSL + UA-25825547-40),connect.facebook.net/sdk.js,youtube.com/player_api,platform.twitter.com/widgets.js,ads.biblioteka.lodz.pl/www/delivery/asyncjs.php. An unusually low number of GA cookies (missing classic_gaand_giddespiteanalytics.jsbeing loaded) — the gtag configuration likely limits some storage, yet client identification still occurs through_ga_30F084ZHSLand thecidparameter in the ping. - 🔴 Two simultaneous CMP mechanisms were implemented — neither of them blocks trackers.
Two consent management systems are present simultaneously on the website:
• a custom TYPO3 cookiebox from theinvest_in_lodzpackage (typo3conf/ext/invest_in_lodz/Resources/Public/Vendors/cookie-box/cookiebox.js) — a different package than the one in theuml_portalfamily, but an identical deceptive implementation,
• Klaro CMP hosted on the central infrastructure of UMŁ:cookies.uml.lodz.pl/klaro.js,cookies.uml.lodz.pl/embed.js, and the configuration filecookies.uml.lodz.pl/cookie_config/config-c287af79d1bade7fe699eb8513f8c534.js.
Klaro is a professional compliance solution, and its presence demonstrates an awareness of the legal obligation. In practice, however, both mechanisms load without any blocking effect — Google, Facebook, YouTube, and Twitter scripts launch before any user decision. Indata_layer.json, there are noconsent defaultorconsent updatecommands. - 🔴 Data was transmitted to third parties before consent was given.
Confirmed requests:
• Google Analytics 4 (G-30F084ZHSL, belonging to the Municipal Library) →region1.analytics.google.com/g/collect(page_view, cid=2057842702)
• Universal Analytics (UA-25825547-40) — cookie_gat_gtag_UA_25825547_40set
• DoubleClick →stats.g.doubleclick.net/g/collect(same cid)
• Facebook SDK (without Pixel — nofbevents.js, no_fbpcookie)
• YouTube (player_api + widgetapi)
• Twitter widgets (iframe with origin=invest.lodz.pl)
•ads.biblioteka.lodz.pl— Municipal Library Revive Adserver (separate data controller)
•newsletter.uml.lodz.pl— a form collecting email addresses (webforms_id=5) embedded as an iframe. - ⚠️ External script from GitHub Pages without an integrity signature — supply chain risk.
The site loads thecountUp.jslibrary directly frominorganik.github.io/countUp.js/dist/countUp.umd.js— GitHub Pages developer infrastructure, with no SLA and nointegrity(Subresource Integrity) attribute. A public municipal page should host its own copies of external scripts or verify them with an SRI hash. The counter animation script itself does not constitute a tracker, but responsibility for front-end security requires a higher standard than inline loading from a developer's private account. - ⚠️ Consent Mode indicates a lack of an integrated consent signal.
Parameters:gcd=13l3l3l2l1l1,npa=1,dma=1,dma_cps=a. A "consent not set" configuration with simultaneous forcing of non-personalized ads — despite this, the client ID (cid), session ID (sid), andpage_viewevent are transmitted. Thenpa=1flag limits personalized display, but does not turn off the provisioning of Google's audience models. Neither the invest_in_lodz cookiebox nor Klaro integrates with the Google Consent Mode layer. - ⚠️ YouTube partitioned cookies (CHIPS) — proper isolation.
__Secure-ROLLOUT_TOKENcontains"partitionKey": "https://invest.lodz.pl"— matching the top-frame origin, unlike domains from the*.uml.lodz.plfamily where the partitionKey was set to the parent. The GDPR violation remains (cookies collected without consent), but the classic cross-site tracking vector is closed by CHIPS isolation.
Legal and Market Context (Invest in Łódź)
invest.lodz.pl is the portal of the Investor Service Bureau of the City of Łódź — a promotional site targeted at domestic and foreign investors considering locating in Łódź. Visitor population: heads of international corporate expansion departments, investment and private equity funds, commercial real estate developers, M&A advisors, tax advisors handling expansion (including under the regime of the Act of 10 May 2018 on Supporting New Investments), and lawyers specializing in foreign investments and business relocation agencies.
Layer A — Legal. Unlike domains serving social assistance (CSS, CUWDPS), invest.lodz.pl does not fall under the elevated regime of Art. 9 GDPR. The standard violations concern Art. 5(1)(c) GDPR (data minimization principle), Art. 6 GDPR (lack of a legal basis for data transmission to third parties before consent), and Art. 26 GDPR (lack of a joint controllership declaration with the Municipal Library for GA4 property G-30F084ZHSL). The newsletter form collecting email addresses into the newsletter.uml.lodz.pl database requires separate analysis regarding marketing communication consents (Art. 10 of the Act of 18 July 2002 on Providing Services by Electronic Means, Art. 172 of the Telecommunications Law).
Layer B — Business (auto-sabotage of the site's purpose). The "corporate real estate decision makers" and "international expansion planners" segment is among the most expensive B2B segments in advertising networks — the acquisition costs for such a user in Google Ads are measured in hundreds of PLN per conversion. invest.lodz.pl transmits the visitor's identifier (cid) to a GA4 property managed by the Municipal Library and to DoubleClick — the signal enters Google's audience building models. The resulting audience segments are available to all advertisers using Google Ads, including direct competitors of cities running parallel investment promotions (Wrocław, Poznań, Kraków, Katowice, Gdańsk). The city pays to promote the "Invest in Łódź" brand, acquires a lead, and simultaneously hands over its profile to the remarketing market, where competitors can redirect their own location offers to them. The GDPR vector complements the city's brand strategy vector here — both layers lead to the exact same conclusion, just from a different angle.
Layer C — Supply Chain.⚠️⚠️⚠️⚠️⚠️ Loading the countUp.js script from a developper's private account on GitHub Pages, without SRI, is inconsistent with the operational standard of a public administration webpage. In the event of a compromise of the inorganik/countUp.js repository, the script on invest.lodz.pl could be replaced with any alternative — with the ability to execute within the context of the invest.lodz.pl origin, access newsletter forms, or intercept email addresses. This is not a theoretical risk — supply chain attacks on commonly used JavaScript libraries occur regularly (event-stream 2018, ua-parser-js 2021, popular npm packages).
Assessment summary – invest.lodz.pl
| Criterion | Assessment | Comment |
|---|---|---|
| Launching trackers before consent | 🔴 Severe violation | Confirmed by cookies_timeline + payloads |
| Effectiveness of implemented CMPs | 🔴 Low / deceptive | Two simultaneous CMPs (invest_in_lodz cookiebox + Klaro), neither blocks tags |
| Data transmission to third parties | 🔴 Yes | Google (GA4 + UA + DoubleClick), Meta SDK, YouTube, Twitter, ads.biblioteka.lodz.pl, newsletter.uml.lodz.pl |
| Consent Mode Parameters | ⚠️ Consent not set + npa=1 | Signal fuels audience models despite non-personalized flag |
| YouTube cookies | ⚠️ Partitioned (CHIPS) | partitionKey https://invest.lodz.pl — proper isolation |
| Supply chain risk | ⚠️ Script from GitHub Pages without SRI | countUp.js from inorganik.github.io |
| Auto-sabotaż celu strony | 🔴 Yes | Investor profiles available to competing cities through Google Ads |
| Newsletter form | ⚠️ Embedded iframe | Collects emails into the newsletter.uml.lodz.pl database |
| Overall assessment | 🔴 Poor (dual layer) | GDPR violation + auto-sabotage of the city's promotional strategy |
Verdict: Two simultaneous CMP mechanisms have been implemented on the invest.lodz.pl website (the TYPO3 cookiebox from the dedicated invest_in_lodz package and Klaro hosted on the central infrastructure cookies.uml.lodz.pl) — neither blocks the loading of trackers before the user's decision. The exact same client identity (cid) is transmitted in parallel to a GA4 property belonging to the Municipal Library and to DoubleClick. A promotional portal targeted at foreign investors transmits profiles of M&A and corporate real estate decision-makers to the Google Ads system — an audience segment highly valuable for competing cities conducting similar investment promotions. The GDPR violation superimposes onto the sabotage of the site's business objective. Additional risk: the countUp.js script is loaded from GitHub Pages without a Subresource Integrity (SRI) signature — a public municipal website should not import scripts from developer accounts without verification.
https://lckm.uml.lodz.pl/
SCAN ID: 20260309_104127_b6560cd6
Data Controller: Łódzkie Centrum Kontaktu z Mieszkańcami
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL (Drupal stack differing from the standard UMŁ TYPO3 deployment, different contractor)
Technical Conclusions (Scanner)
- 🔴
Pings to two GA4 properties (own
G-FFBHTEJ4R4+ the Library'sG-30F084ZHSL) and DoubleClick with the samecid— before any user decision. - 🔴
Drupal EU Cookie Compliance v10.2.4 implemented — the mechanism sets GA cookies and then removes them retroactively (visible in timeline: 9 cookies after DOM → 5 after load). However, pings with the
cidwere already sent earlier. The CMP functions deceptively. - ⚠️
GTM configuration with an unreplaced placeholder: the
ep.page_placeholder=PLACEHOLDER_page_locationparameter lands as a value transmitted to Google. Indication of an unverified deployment. - 🔴
GA cookies set on the apex domain
.uml.lodz.pl— analytical identity shared with uml.lodz.pl, bip.uml.lodz.pl, cuw.uml.lodz.pl, cuwdps.uml.lodz.pl. - -
Consent Mode:
gcd=13l3l3l2l1l1,npa=1. No Facebook SDK, no Twitter, noads.biblioteka.lodz.pl. YouTube cookies present indirectly via thelodz.pl/livebariframe.
Privacy Policy Analysis vs Tags
cid to its own LCKM GA4 and the Municipal Library GA4) without a joint controllership declaration (Art. 26 GDPR). Retroactive CMP — cookies deleted after the fact, but pings containing the client identifier are already transmitted.📄 Show Domain Assessment ▼
Conclusions and Violations
- 🔴 Retroactive cookie clearing — deceptive mechanism. Drupal EU Cookie Compliance v10.2.4 (+ custom mod) sets GA cookies (
_ga,_ga_FFBHTEJ4R4,_ga_30F084ZHSL) and subsequently deletes them between theafter_domcontentloadedandafter_loadstages. Pings toregion1.google-analytics.com/g/collectandstats.g.doubleclick.net/g/collectwithcid=1220176430were dispatched prior to the clearing. Technical effect: the client identifier is transmitted to Google despite a deceptive "no GA cookies" configuration. - 🔴 Two GA4 properties with the same cid. The dedicated property
G-FFBHTEJ4R4(LCKM) andG-30F084ZHSL(belonging to the Municipal Library) receive the exact same client identifier in concurrent calls. Cross-controller identity sharing occurs without a joint controllership declaration within the meaning of Art. 26 GDPR. DoubleClick (stats.g.doubleclick.net/g/collect) also receives the samecid. - 🔴 Cross-subdomain scope cookies GA on
.uml.lodz.pl. The same analytical identity is shared across theuml.lodz.pl,bip.uml.lodz.pl,cuw.uml.lodz.pl, andcuwdps.uml.lodz.pldomain family. The measurement identifies the identical user across five formally distinct municipal services. - ⚠️ Unverified GTM configuration — placeholder inside an event parameter value. The parameter
ep.page_placeholder=PLACEHOLDER_page_locationis transmitted to Google within every/g/collectcall. The developer copied a configuration template and failed to substitute the placeholder with the actual dynamic URL retrieval function. A clear sign that the deployment was not verified post-launch. Additionally,developer_id.dMDhkMTis present withindata_layer.json— a Google Analytics developer ID assigned to integration agencies, indicating the implementation was executed by an external vendor. - ⚠️ Consent Mode: lack of an integrated consent signal. The parameters
gcd=13l3l3l2l1l1,npa=1,dma=1are present. A "consent not set" state with non-personalized ads — despite this,cid,sid, andpage_vieware transmitted. EU Cookie Compliance does not integrate with the Google Consent Mode layer. - ⚠️ Livebar iframe acting as an indirect source of YouTube cookies. No direct YouTube scripts occur within
scripts_dom.json, but the cookie jar contains__Secure-YNID,YSC,VISITOR_INFO1_LIVE,__Secure-ROLLOUT_TOKEN, andVISITOR_PRIVACY_METADATA— originating from thelodz.pl/livebar/iframe, which internally embeds YouTube elements. The partitionKey resolves tohttps://uml.lodz.pl(notlckm.uml.lodz.pl) — a recurring feature of this domain family.
Assessment summary – lckm.uml.lodz.pl
| Criterion | Assessment |
|---|---|
| Launching trackers before consent | 🔴 Severe violation |
| Effectiveness of CMP (Drupal EU Cookie Compliance) | 🔴 Retroactive clearing — deceptive |
| Cross-controller identity sharing | 🔴 Two GA4 properties with the same cid |
| Cross-subdomain scope | 🔴 Entire .uml.lodz.pl family |
| Configuration Hygiene | ⚠️ Unreplaced placeholder |
| Third-party (Facebook, Twitter, ads.biblioteka) | ✅ None |
| Overall assessment | 🔴 Poor (Drupal with a deceptive CMP) |
Verdict: LCKM is the first domain of the *.uml.lodz.pl family built on Drupal — running the EU Cookie Compliance v10.2.4 module, which instead of blocking GA cookies, sets them and clears them retroactively. Pings containing the cid reach two GA4 properties (the dedicated LCKM one and the Municipal Library one) as well as DoubleClick before the clearing mechanism can execute. The GTM configuration contains an unreplaced placeholder, and the implementation was performed by an external vendor (indicated by the visible developer_id).
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Only cookies policy present; missing GDPR information clause
https://li.lodz.pl/
SCAN ID: 20260309_104127_03e9a4c1
Data Controller: Łódzkie Inwestycje sp. z o.o.
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions (Scanner)
- 🔴
Tracking tags were firing immediately upon entry, before the user's decision. Pings to GA4 property
G-30F084ZHSL(Municipal Library) + shared UA containerUA-25825547-40+ DoubleClick — all sharing the identicalcid=94267638. - 🔴
The TYPO3 cookiebox (
uml_portalpackage) does not block tracker initialization — a deceptive mechanism. Klaro is absent. - 🔴
Recipients: Google (GA4 + UA + DoubleClick), Facebook SDK, YouTube, Twitter iframe,
ads.biblioteka.lodz.pl,lodz.pl/livebar.js. Consent Mode showsgcd=13l3l3l2l1l1,npa=1. - -
9 tracking cookies remain (4× GA, 5× YouTube). Cross-domain scope on
.li.lodz.pl(internal). YouTube partitionKeyhttps://li.lodz.pl— correctly set.
Privacy Policy Analysis vs Tags
📄 Show Domain Assessment ▼
Conclusions and Violations
- 🔴 Tracking tags initialized before consent. GA cookies (
_ga,_ga_30F084ZHSL,_gid,_gat_gtag_UA_25825547_40) and YouTube cookies are set afterafter_domcontentloaded. Payloads hit:region1.google-analytics.com/g/collect(G-30F084ZHSL Library),region1.analytics.google.com/g/collect(UA-25825547-40), andstats.g.doubleclick.net/g/collect— all matching oncid=94267638. - 🔴 Deceptive TYPO3 Cookiebox.
typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.jsloads but fails to block tag execution. Noconsentcommands exist in the data_layer. Klaro is absent. - 🔴 Cross-controller identity sharing. The exact same
cidis transmitted to GA4G-30F084ZHSL(Municipal Library) and to the shared UA-25825547-40 container (municipal domain family). Łódzkie Inwestycje operates as a limited liability company — meaning it is a distinct legal entity and an independent data controller relative to both the City of Łódź and the Municipal Library. There is no public declaration of joint controllership (Art. 26 GDPR) or a data processing agreement (Art. 28 GDPR). - 🔴 Third-party recipients without consent: Google (GA4 + UA + DoubleClick), Meta (Facebook SDK, without Pixel), YouTube (player_api + widgetapi), Twitter (widgets.js + iframe with origin=li.lodz.pl),
ads.biblioteka.lodz.pl(the Library's Revive Adserver), andlodz.pl/livebar.js. - ⚠️ Consent Mode is "consent not set":
gcd=13l3l3l2l1l1,npa=1,dma=1. The behavioral signal feeds Google's audience modeling infrastructure despite the non-personalized ads flag. - ⚠️ Public Procurement Context (PZP). The website provides details regarding public procurement procedures with links redirecting to the BIP. Contractors interacting within public bidding tracks are subject to the duties outlined in the Act of 11 September 2019 — Public Procurement Law; exporting their
cidto Google/DoubleClick stretches far outside the processing boundaries established for public tenders.
Assessment summary – li.lodz.pl
| Criterion | Assessment |
|---|---|
| Launching trackers before consent | 🔴 Severe violation |
| Effectiveness of CMP (cookiebox TYPO3) | 🔴 Deceptive |
| Cross-controller identity sharing | 🔴 Limited company uses the Library's property |
| Transmission to third-parties | 🔴 Full uml_portal family stack |
| Consent Mode | ⚠️ Consent not set + npa=1 |
| Legal Context | ⚠️ Public Procurement Law + distinct legal personality |
| Overall assessment | 🔴 Poor |
Verdict: Follows the standard pattern of the uml_portal family (deceptive cookiebox, full third-party stack, identical cid pushed to two separate Google containers + DoubleClick). Critical legal parameter: Łódzkie Inwestycje is a limited liability company — an entirely separate legal person from the City of Łódź and the Municipal Library. Shared use of this measurement infrastructure (the Library's GA4 property, shared UA container) occurs without a public joint controllership declaration under Art. 26 GDPR or a data processing agreement under Art. 28 GDPR. The visiting population includes economic operators involved in public procurement tracks — bringing an additional regulatory intersection with the Public Procurement Law (PZP).
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
"Klauzula Informacyjna" (Information Clause) link in the footer
https://mops.uml.lodz.pl/
SCAN ID: 20260309_104129_ee8767e9
Data Controller: Miejski Ośrodek Pomocy Społecznej
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions (Scanner)
- 🔴
GA4 (G-30F084ZHSL) and UA (UA-25825547-40) initialized with
gcd=13l3l3l2l1l1+npa=1+pscdl=noapi— lack of Consent Mode integration with cookie-box - 🔴
Cross-controller: GA4 property
G-30F084ZHSL(Municipal Library) active on MOPS subdomain (social assistance) - ⚠️
Facebook SDK (
connect.facebook.net/pl_PL/sdk.js) loaded, but without an active Pixel (missingfbevents.js,_fbp, andsignals/configcalls) - -
YouTube widget API + Twitter widgets.js +
lodz.pl/livebar/iframe → third-party cookies (VISITOR_INFO1_LIVE, YSC) without first-party control - -
CMP:
cookie-box.js(TYPO3 uml_portal) present; F5 BIG-IP (TS01a62d2a, TS01619efc) — load balancer infrastructure - - Cookie timeline stable (before_navigation = 0, no retroactive clearing); localStorage/sessionStorage empty
Privacy Policy Analysis vs Tags
G-30F084ZHSL on the MOPS subdomain. The domain processes special categories of data belonging to social assistance clients (Art. 9 GDPR + Social Assistance Act of March 12, 2004). The cookie-box CMP does not pass signals to gtag — a classic blueprint of the uml.lodz.pl family.📄 Show Domain Assessment ▼
Conclusions and Violations
- 🔴 Lack of integrated Consent Mode — the GA4 beacon routed to
region1.analytics.google.com/g/collectcontainsgcd=13l3l3l2l1l1(all "l" characters = signal not set),npa=1,pscdl=noapi, anddma=1. The page signals neither consent nor refusal — a classic pre-Consent Mode setup. Unlike the municipal domains of Łódź (which at minimum dispatchgcd=13l3l3l2l1l1as a fallback "consent not set"), lodz.praca.gov.pl contains no signaling whatsoever. - 🔴 Cross-controller identity sharing — GA4 property
G-30F084ZHSL(owned by the Municipal Library in Łódź) is configured and actively pinged onmops.uml.lodz.pl. The client identifiercid=1271838583.1773049290is shared across the entire lodz.pl/uml.lodz.pl ecosystem. This establishes a violation of Art. 26 GDPR (joint controllership operating without transparency). - 🔴 Legacy UA remains active — container
UA-25825547-40(the shared tracking container for the municipal family) is loaded concurrently with GA4 via gtag.js. Universal Analytics was retired by Google in 2023, yet it still generates network events and drops_gid/_gat_gtag_UA_25825547_40cookies. - ⚠️ Facebook SDK without the Pixel — two instances of
connect.facebook.net/pl_PL/sdk.jswere detected (including one utilizing the xfbml=1 parameter). However,fbevents.js, the_fbpcookie, andsignals/config/<ID>requests are missing. The SDK itself does not perform active tracking in this setup, but it expands the front-end attack surface and facilitates dropping a tracking pixel in the future without modifying the CMP. - ⚠️ Third-party widgets on a social assistance domain — the page embeds the YouTube player_api + widgetapi, the Twitter widgets.js script + iframe, and the UMŁ livebar widget (
lodz.pl/livebar/). These components dropVISITOR_INFO1_LIVE,YSC, and__Secure-ROLLOUT_TOKENcookies, enabling profiling beyond the control of the MOPS administrator. - ⚠️ CMP is technically present but ineffective against Google — the script
/typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js(TYPO3) loads successfully but lacksconsent default/consent updateintegration with the data_layer. Tracking payloads confirm that Google tags initialize before any interaction with the banner. - ⚠️ No tracking data stored in storage — localStorage and sessionStorage remain empty (missing variables like
_fbp,_gcl_ls, orgoogle_auto_fc_cmp_setting). The cookie timeline is stable — indicating zero retroactive cleaning anomalies.
Legal Context (Municipal Social Assistance Center in Łódź)
MOPS acts as an organizational unit for social welfare, executing the statutory local government tasks outlined in the Social Assistance Act of 12 March 2004. The portal serves citizens navigating difficult life situations — processing special categories of data concerning health, financial status, family stability, or dependencies under the strict protective scope of Art. 9 GDPR. The mops.uml.lodz.pl domain is bound to an elevated data protection standard.
Layer A — controller's compliance culture. The administrator (MOPS / UMŁ) deployed the cookie-box CMP but failed to tie it to Google's Consent Mode or block tag execution before consent is obtained. Furthermore, a GA4 property belonging to an independent third party (the Municipal Library) is actively leveraged without a transparent joint controllership arrangement under Art. 26 GDPR. This represents a systemic structural flaw rather than an isolated front-end accident.
Layer B — market value of the behavioral profile. Behavioral metrics reflecting social welfare clients (individuals seeking financial or logistical assistance) represent a high-risk profile targeted for the classification of vulnerable demographic groups (poverty, structural exclusion, health crises). Exposing this signal via a shared GA4 asset heightens the risk of secondary exploitation beyond the statutory public mandate of MOPS.
Assessment summary – mops.uml.lodz.pl
| Criterion | Assessment |
|---|---|
| Launching trackers before consent | 🔴 Yes — GA4/UA running with gcd=13l3l3l2l1l1 and pscdl=noapi |
| CMP Effectiveness | ⚠️ Present (cookie-box), but disconnected from Google Consent Mode |
| Data transmission to third parties | 🔴 Yes — shared GA4 property of the Library + YouTube/Twitter SDK/iframes |
| Cross-controller identity | 🔴 Active deployment (G-30F084ZHSL on MOPS) |
| Facebook Pixel | ✅ Inactive (SDK loads but drops no beacons or _fbp cookie) |
| Overall assessment | 🔴 Severe violation — Google tracking tags launch without an effective consent flag on a domain handling special categories of personal data |
Verdict: On mops.uml.lodz.pl, Google Analytics 4 (G-30F084ZHSL) and legacy Universal Analytics (UA-25825547-40) initialize with the configuration metrics gcd=13l3l3l2l1l1 + pscdl=noapi prior to any user choice. The cookie-box CMP fails to communicate consent signals to Google. Additionally, cross-controller sharing occurs with the Municipal Library on a social assistance subdomain processing special categories of personal data under Art. 9 GDPR. This violates the core principles of data minimization and lawfulness of processing (Art. 5 and 6 GDPR) along with the structural joint controllership transparency mandates of Art. 26 GDPR. The Facebook Pixel is inactive, though loading the SDK on this specific domain warrants an independent risk assessment.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Detected in incognito: The cookie banner routes to UMŁ. A dedicated GDPR page maps the DPO and specific information clauses.
https://mzz.lodz.pl/
SCAN ID: 20260309_104148_f5fd6c65
Data Controller: Miejski Zespół Żłobków
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions (Scanner)
- 🔴
GA4
G-30F084ZHSL(Municipal Library) + legacy UAUA-25825547-40running withgcd=13l3l3l2l1l1+npa=1+pscdl=noapi— lack of Consent Mode integration with cookie-box - 🔴
The
cookie-box.jsCMP is present but disconnected from Google Consent Mode — tracking tags fire prior to user consent - ⚠️
Facebook SDK + YouTube widget API + Twitter widgets +
lodz.pl/livebar/iframe - -
F5 BIG-IP cookie (
TS014e08b6) — load balancer infrastructure - - Timeline is stable (before_navigation = 0). No retroactive cookie clearing.
- -
No dedicated GA4 property found for the nursery center — only shared
G-30F084ZHSL+ legacy UA
Privacy Policy Analysis vs Tags
G-30F084ZHSL property (Municipal Library) functions cross-controller. The cookie-box CMP fails to convey consent signals to Google.📄 Show Domain Assessment ▼
Conclusions and Violations
- 🔴 GA4 + legacy UA running without Consent Mode — active beacon to
G-30F084ZHSLcarrying the configuration metricsgcd=13l3l3l2l1l1,npa=1, andpscdl=noapi. Thecookie-box.jsCMP completely fails to map consent status out to Google's Consent API. - 🔴 Cross-controller sharing on a nursery domain — a GA4 property owned and controlled by the Municipal Library (
G-30F084ZHSL) is actively deployed on the Miejski Zespół Żłobków interface. Operates without a transparent joint controllership arrangement under Art. 26 GDPR. - ⚠️ Facebook SDK + third-party widgets —
connect.facebook.net/pl_PL/sdk.js, the YouTube widget API, and the Twitter widgets.js library are initialized. Thelodz.pl/livebar/iframe is also parsed into the front-end layout. - - CMP is technically present but ineffective against Google —
cookie-box.js(TYPO3) is executed, yet Google tracking tags initialize and route data regardless of user preferences. - - Infrastructure layer — the F5 BIG-IP cookie (
TS014e08b6) is correctly classified as a persistent load balancing asset. The cookie jar lifecycle remains stable.
Legal Context (Municipal Nursery Center in Łódź)
Miejski Zespół Żłobków w Łodzi operates as an organizational unit of the City of Łódź, handling early child care for toddlers aged 0–3. The website handles informational and enrolment/recruitment processes and is heavily frequented by parents of young children. While it does not structurally harvest special categories of data within the strict definitions of Art. 9 GDPR, the specific demographic profile (early childhood care logistics) demands an elevated standard of compliance and privacy safeguarding.
Layer A — controller's compliance culture. The administrator deployed the standard package cookie-box CMP but left it disconnected from Google's Consent Mode infrastructure. A shared GA4 analytics asset belonging to an external entity (the Municipal Library) is integrated without transparent fulfillment of Art. 26 GDPR. This reflects a systemic operational oversight on a site handling early childhood care resources.
Layer B — market value of the behavioral profile. A nursery-focused domain maps behavioral trends reflecting parental care structures and early registration paths — a segment targeted for commercial family-focused profiling. Distributing this signal out via a shared GA4 asset expands exposure to secondary data exploitation far outside the statutory public remit of the nursery center.
Assessment summary – mzz.lodz.pl
| Criterion | Assessment |
|---|---|
| Launching trackers before consent | 🔴 Yes — GA4 + UA running with gcd=13l3l3l2l1l1 and pscdl=noapi |
| CMP Effectiveness | ⚠️ Present (cookie-box), but disconnected from Google Consent Mode |
| Data transmission to third parties | 🔴 Yes — shared G-30F084ZHSL property + YouTube/Twitter widgets + livebar widget |
| Cross-controller identity | 🔴 Active deployment (G-30F084ZHSL running on the nursery portal) |
| Facebook Pixel | ✅ Inactive (Only the SDK loads, dropping no beacons) |
| Overall assessment | 🔴 Severe violation — tracking tags initialize without an effective consent signal on a public nursery domain |
Verdict: On mzz.lodz.pl, Google Analytics 4 (G-30F084ZHSL) and legacy Universal Analytics (UA-25825547-40) initialize with the configuration metrics gcd=13l3l3l2l1l1 + pscdl=noapi prior to any user choice. The cookie-box CMP fails to convey consent signals to Google. Furthermore, cross-controller data sharing occurs with the Municipal Library on an early childhood domain. This violates the core principles of data minimization and lawfulness of processing (Art. 5 and 6 GDPR) along with the structural joint controllership transparency mandates of Art. 26 GDPR. The early childhood context accentuates the gravity of the tracking setup.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Detected in incognito mode: the cookie banner routes to UMŁ. A dedicated GDPR page lists the DPO and specific information clauses.
https://rewitalizacja.uml.lodz.pl/
SCAN ID: 20260309_104150_9c36cb31
ADO: Revitalization Office of the Łódź City Office
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions (Scanner)
- ❌ Consent Mode is NOT configured — gcd=13l3l3l2l2l1 (all “l” = consent not set). No gcs parameter and pscdl=noapi. Identical to domains rated 🔴.
- ❌ npa=0 is hardcoded in the tag — allow_ad_personalization_signals: true + allow_display_features: true in data_layer.json (config G-1EC6G25418). Does not come from CMP or user decision.
- ❌ Cookies before consent — after_domcontentloaded, before_navigation=0: _ga (valid until April 2027), _gid, _gat, _ga_1EC6G25418. Pattern identical to 🔴 rated domains.
- ⚠️ Legacy UA fires full pageview before consent — /j/collect tid=UA-113466830-1, status 200. Response body contains „2,cG-1EC6G25418” (dual-tagging, is_legacy_loaded: true).
- ⚠️ Additional third-party trackers — platform.twitter.com/widgets.js + two instances of connect.facebook.net (SDK), rufous-sandbox iframe (Twitter telemetry/scribe).
- ✅ Dedicated GA4 property G-1EC6G25418 (not shared with other UMŁ domains)
- ✅ No Facebook Pixel, Google Ads Conversion, Crazy Egg or session recording
Privacy Policy Analysis vs Tags
📄 Show Domain Assessment ▼
Conclusions and Violations
- ❌ Lack of effective Consent Mode — GA4 beacon to region1.google-analytics.com/g/collect carries gcd=13l3l3l2l2l1. All letter positions are “l” = consent not set. No gcs and pscdl=noapi. In data_layer.json there is no consent default or consent update command.
- ❌ npa=0 does not come from CMP — in data_layer.json it is clearly visible: allow_ad_personalization_signals: true and allow_display_features: true in the config command for G-1EC6G25418. This is a static implementation flag. In a sterile session (without interaction) ad personalization is explicitly allowed.
- ❌ Cookies set before consent — timeline: before_navigation = 0 → after_domcontentloaded = full set _ga, _gid, _gat, _ga_1EC6G25418. _ga valid until April 2027 (cookie_expires: 63072000).
- ❌ Legacy UA fires pageview before consent — /j/collect?tid=UA-113466830-1 status 200. Response body contains „2,cG-1EC6G25418” — confirmation of dual-tagging (is_legacy_loaded: true).
- ⚠️ Additional third-party trackers — platform.twitter.com/widgets.js + two instances of connect.facebook.net (SDK, no Pixel), rufous-sandbox iframe (Twitter telemetry/scribe/analytics).
- ✅ Dedicated GA4 property — G-1EC6G25418 (no allegation of data sharing under art. 26 RODO, unlike G-30F084ZHSL).
- ✅ Lack of aggressive marketing tracking — no Facebook Pixel, Google Ads Conversion ID or Crazy Egg / session recording detected.
Legal Context (Revitalization Portal)
The Revitalization Portal is a dedicated website for the Łódź revitalization project (financed, among others, from EU funds). It has an informational and communication character. It does not process special categories of data and does not conduct aggressive advertising monetization.
Layer A — culture of administrator compliance. Poor. cookie-box.js CMP is loaded, but does not transmit a real consent signal to Google (no Consent Mode integration, all-l type gcd, hardcoded npa=0). Analytical tracking (GA4 + legacy UA) and additional scripts are launched before any user decision — exactly the same as in negatively rated domains.
Layer B — market value of behavioral signal. Low. The site has an informational character (revitalization, maps, documents). It does not generate attractive data for advertising audience profiling.
Summary of assessment – rewitalizacja.uml.lodz.pl
| Criterion | Assessment |
|---|---|
| Firing trackers before consent | ❌ Cookies (_ga*) and GA4/UA beacon set after DOMContentLoaded, before_navigation=0 |
| CMP Effectiveness | ❌ Present (cookie-box.js), but not integrated with Consent Mode (no consent update, gcd=13l3l3l2l2l1) |
| Transmission to third parties | ⚠️ GA4 + legacy UA + Twitter widgets + FB SDK + rufous-sandbox |
| Facebook Pixel | ✅ Inactive (only SDK, no Pixel config and _fbp) |
| Google Ads / Conversion | ✅ None |
| Overall assessment | ❌ Negative / Violation — tracking without effective consent signal (identical to shelter and zzm) |
Verdict: On rewitalizacja.uml.lodz.pl a dedicated GA4 property (G-1EC6G25418) was implemented and there is no Pixel or Google Ads Conversion — these are real positives compared to some other UMŁ domains. However, the violation mechanism is identical: full analytical cookies + GA4/UA beacon + legacy UA launched before consent, cookie-box CMP without Consent Mode integration (all-l gcd, hardcoded npa=0, no consent commands in dataLayer) and additional Twitter and Facebook SDK trackers. According to the legend from July 7, it qualifies directly for 🔴 VIOLATION.
📸 Evidence: Page Snapshots and GDPR Documents ▼
📌 Notes from policy scan:
Detected in incognito: local cookies and dedicated RODO page in the menu.
https://nowa.mapa.lodz.pl/
SCAN ID: 20260309_104149_87917d65
Data Controller: InterSIT — Łódzki Ośrodek Geodezji
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions
- ⚠️The
gcdparameter was detected in tracking requests, signaling incomplete Consent Mode integration. - ⚠️A
gcdstring was dispatched without an accompanyinggcsvalue in a subset of telemetry requests. - -After the session, 5 potentially tracking cookies remain persistent within the cookie jar.
Privacy Policy Analysis vs Tags
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Link located in the footer
https://schronisko.uml.lodz.pl/
SCAN ID: 20260309_104209_93f8cd81
Data Controller: Schronisko dla Zwierząt w Łodzi
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions (Scanner)
- 🔴
GA4
G-30F084ZHSL(Municipal Library) + legacy UAUA-25825547-40running withgcd=13l3l3l2l1l1+npa=1+pscdl=noapi— lack of Consent Mode integration with cookie-box - 🔴
The
cookie-box.jsCMP is present but disconnected from Google Consent Mode — tracking tags fire prior to user consent - ⚠️
Facebook SDK + YouTube widget API + Twitter widgets +
lodz.pl/livebar/iframe - -
F5 BIG-IP cookie (
TS014e08b6) — persistent load balancing cookie correctly classified - - Timeline is stable (before_navigation = 0). No retroactive cookie clearing detected.
- -
No dedicated GA4 property found for the shelter portal — running only shared
G-30F084ZHSL+ legacy UA
Privacy Policy Analysis vs Tags
📄 Show Domain Assessment ▼
Conclusions and Violations
- 🔴 The Library's GA4 property running without Consent Mode — an active beacon to
G-30F084ZHSLtransmits the configuration metricsgcd=13l3l3l2l1l1,npa=1, andpscdl=noapi. Thecookie-box.jsCMP completely fails to map consent status out to Google's Consent API, making the implementation deceptive. - 🔴 Cross-controller data sharing on the shelter domain — a GA4 property owned and controlled by the Municipal Library is actively deployed on the animal shelter portal. This operates without a transparent joint controllership arrangement or disclosure under Art. 26 GDPR.
- ⚠️ Facebook SDK + third-party widgets —
connect.facebook.net/pl_PL/sdk.js, the YouTube widget API, and the Twitter widgets.js library are initialized. Thelodz.pl/livebar/iframe is also parsed into the frontend layout, leaking traffic metadata. - ⚠️ Legacy UA remains active — container
UA-25825547-40is configured and executed concurrently alongside GA4 layers despite its universal deprecation. - ⚠️ The Library's ad server — active injection of
ads.biblioteka.lodz.pl/www/delivery/asyncjs.phploads third-party components from an external platform without prior consent filters.
Legal Context (Animal Shelter in Łódź)
The Animal Shelter in Łódź is a municipal unit executing localized public care and animal control mandates. The portal serves a strong community adoption and informational focus. While it does not structurally process special categories of data under Art. 9 GDPR, public units interfacing with civic engagement parameters are bound to clean compliance baselines and operational transparency.
Layer A — controller's compliance culture. The administrator deployed the framework's default cookie-box CMP but left it disconnected from Google's Consent Mode infrastructure. A shared analytics container belonging to an external entity (the Municipal Library) is embedded without a joint controllership layout. This maps as an unverified deployment sequence typical of the uml_portal ecosystem.
Layer B — market value of the behavioral profile. Moderate. The domain maps interest segments focusing on domestic pet adoption, veterinary visibility paths, and local community assistance. Exposing these telemetry hits to a shared framework increases vulnerability to unintended commercial profiling.
Domain assessment summary – schronisko.uml.lodz.pl
| Criterion | Assessment |
|---|---|
| Launching trackers before consent | 🔴 Yes — GA4 + UA running with gcd=13l3l3l2l1l1 and pscdl=noapi |
| CMP Effectiveness | ⚠️ Present (cookie-box), but disconnected from Google Consent Mode |
| Data transmission to third parties | 🔴 Yes — shared G-30F084ZHSL property + YouTube/Twitter widgets + livebar widget |
| Cross-controller identity | 🔴 Active deployment (G-30F084ZHSL running on the shelter portal) |
| Facebook Pixel | ✅ Inactive (Only the SDK loads, dropping no beacons) |
| Overall assessment | 🔴 Negative — tracking tags initialize without an effective consent signal on a public municipal domain |
Verdict: On schronisko.uml.lodz.pl, Google Analytics 4 (G-30F084ZHSL) and legacy Universal Analytics (UA-25825547-40) initialize with the configuration metrics gcd=13l3l3l2l1l1 + pscdl=noapi prior to any user choice. The cookie-box CMP fails to convey consent signals to Google. Furthermore, cross-controller data sharing occurs with the Municipal Library on a local public sector site, establishing a breach of data minimization and lawfulness of processing (Arts. 5 and 6 GDPR) along with the structural joint controllership mandates of Art. 26 GDPR.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Detected in incognito mode: the cookie banner routes to UMŁ central targets, but the shelter's BIP endpoint hosts standalone information clauses.
https://wizyty.uml.lodz.pl/
SCAN ID: 20260309_104213_8cf5c6dd
ADO: Łódź City Office (visit reservation)
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions
- ✅ No marketing tracking. Only session and infrastructural cookies present (PHPSESSID + F5 BIG-IP).
Assessment
📸 Evidence: Page Snapshots and GDPR Documents ▼
📌 Notes from policy scan:
Detected in incognito: policies are linked only in the "Book a visit" step in the form (they redirect to the UMŁ BIP).
https://strazmiejska.lodz.pl/
SCAN ID: 20260309_104212_8ebcd5a3
Data Controller: Straż Miejska w Łodzi (Municipal Police)
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions (Scanner)
- 🔴
GA4
G-30F084ZHSL(Municipal Library) + legacy UAUA-25825547-40running withgcd=13l3l3l2l1l1+npa=1+pscdl=noapi— lack of Consent Mode integration with cookie-box - 🔴
The
cookie-box.jsCMP is present but disconnected from Google Consent Mode — tracking tags fire prior to user consent - ⚠️
Facebook SDK + YouTube widget API + Twitter widgets +
lodz.pl/livebar/iframe - -
F5 BIG-IP cookie (
TS01619efc) — infrastructure load balancer cookie - -
The Municipal Library's ad server link (
ads.biblioteka.lodz.pl) is active - - Cookie timeline is stable (before_navigation = 0). No retroactive cookie clearing detected.
Privacy Policy Analysis vs Tags
uml_portal domain family.📄 Show Domain Assessment ▼
Conclusions and Violations
- 🔴 The Library's GA4 property running without Consent Mode — an active beacon to
G-30F084ZHSLtransmits the configuration metricsgcd=13l3l3l2l1l1,npa=1, andpscdl=noapi. Thecookie-box.jsCMP completely fails to map consent status out to Google's Consent API. - 🔴 Cross-controller data sharing on the Municipal Police domain — a GA4 property owned and controlled by the Municipal Library is actively deployed on the Straż Miejska portal. This operates without a transparent joint controllership arrangement or disclosure under Art. 26 GDPR.
- ⚠️ Facebook SDK + third-party widgets —
connect.facebook.net/pl_PL/sdk.js, the YouTube widget API, and the Twitter widgets.js library are initialized. Thelodz.pl/livebar/iframe is also parsed into the frontend layout. - ⚠️ Legacy UA remains active — container
UA-25825547-40is configured and executed concurrently alongside GA4 layers despite its universal deprecation. - ⚠️ The Library's ad server — active injection of
ads.biblioteka.lodz.pl/www/delivery/asyncjs.phploads components from an external platform without prior consent filters.
Legal Context (Straż Miejska w Łodzi — Municipal Police)
Straż Miejska w Łodzi is a public order enforcement unit executing localized municipal policing, intervention tracking, and civic safety reporting. The portal serves an important community security and informational focus. Frequented by citizens filing local complaints or tracking civic enforcement status, this public framework demands rigorous compliance baseline parameters and absolute operational transparency regarding tracking scripts.
Layer A — controller's compliance culture. The administrator deployed the standard package cookie-box CMP but left it completely disconnected from Google's Consent Mode infrastructure. A shared analytics container belonging to an external entity (the Municipal Library) is embedded without a joint controllership layout. This maps as an unverified deployment sequence typical of the uml_portal ecosystem.
Layer B — market value of the behavioral profile. Moderate. The domain maps interest segments focusing on local safety enforcement tracking, citation information, and localized intervention queries. Exposing these telemetry hits to a shared framework increases vulnerability to unintended commercial profiling.
Assessment summary – strazmiejska.lodz.pl
| Criterion | Assessment |
|---|---|
| Launching trackers before consent | 🔴 Yes — GA4 + UA running with gcd=13l3l3l2l1l1 and pscdl=noapi |
| CMP Effectiveness | ⚠️ Present (cookie-box), but disconnected from Google Consent Mode |
| Data transmission to third parties | 🔴 Yes — shared G-30F084ZHSL property + YouTube/Twitter widgets + livebar widget |
| Cross-controller identity | 🔴 Active deployment (G-30F084ZHSL running on the Municipal Police portal) |
| Facebook Pixel | ✅ Inactive (Only the SDK loads, dropping no beacons) |
| Overall assessment | 🔴 Negative — tracking tags initialize without an effective consent signal on a public municipal domain |
Verdict: On strazmiejska.lodz.pl, Google Analytics 4 (G-30F084ZHSL) and legacy Universal Analytics (UA-25825547-40) initialize with the configuration metrics gcd=13l3l3l2l1l1 + pscdl=noapi prior to any user choice. The cookie-box CMP fails to convey consent signals to Google. Furthermore, cross-controller data sharing occurs with the Municipal Library on a local public safety site, establishing a breach of data minimization and lawfulness of processing (Arts. 5 and 6 GDPR) along with the structural joint controllership mandates of Art. 26 GDPR.
📸 Evidence: Snapshots of Pages and GDPR Documents ▼
📌 Notes from policy scan:
Nothing on the homepage. There is a GDPR page listed on the BIP, but the active cookie banner links directly to a 404 error page.
https://wsparcie.uml.lodz.pl/
SCAN ID: 20260309_104231_a18b770e
ADO: Łódź City Office Social Support Portal
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions (Scanner)
- ✅ No GA4, UA, Facebook Pixel, Google Ads or other marketing trackers
- - Only lodz.pl/livebar/ + YouTube cookies (with partitionKey) present
- - Cookies: ASP.NET_SessionId (httpOnly), XSRF-TOKEN, F5 BIG-IP
- - Data Layer empty — no GTM / gtag
- - No CMP (not required due to absence of marketing trackers)
Privacy Policy Analysis vs Tags
📄 Show Domain Assessment ▼
Conclusions and Violations
- ✅ No marketing tracking — no GA4, legacy UA, Facebook Pixel or Google Ads detected. Data Layer is empty.
- ⚠️ Livebar + YouTube — lodz.pl/livebar.js and YouTube cookies (with partitionKey) loaded. These are the only third-party elements.
- - Standard application cookies — ASP.NET_SessionId (httpOnly) + XSRF-TOKEN + F5 BIG-IP. No GA / _fbp / _gcl_au cookies.
- - No CMP — not required because no marketing trackers requiring consent were launched.
Legal Context (Social Support Portal)
The domain wsparcie.uml.lodz.pl is a resident account portal for social benefits, life situation self-diagnosis and register of non-governmental organization services. It processes data on residents' material, family and health situation — including data that may belong to special categories (art. 9 RODO).
Layer A — culture of administrator compliance. Very good in terms of marketing tracking. No GA4 or Pixel launched on a portal with sensitive data. The only third-party is the municipal livebar.
Layer B — market value of behavioral signal. Low. The portal is purely service-oriented (benefits, applications, self-diagnosis). This data has very limited commercial value and should not be marketing-profiled.
Summary of assessment – wsparcie.uml.lodz.pl
| Criterion | Assessment |
|---|---|
| Firing trackers before consent | ✅ No — no GA4 / UA / Pixel / Ads |
| Presence of third-party | ⚠️ Only livebar + YouTube cookies |
| Marketing cookies | ✅ None (_ga, _fbp, _gcl_au etc.) |
| Processing context | ⚠️ Data on social benefits (possible special data) |
| Overall assessment | ✅ Positive — no marketing violations |
Verdict: On wsparcie.uml.lodz.pl no marketing trackers were found (no GA4, UA, Pixel, Google Ads). Only the municipal livebar generating YouTube cookies is present. In the context of a social benefits portal, this is one of the cleanest domains in the entire audit in terms of marketing data processing.
📸 Evidence: Page Snapshots and GDPR Documents ▼
📌 Notes from policy scan:
Detected in incognito: cookie pop-up implemented, dedicated links to social support policies in the footer.
https://zzm.lodz.pl/
SCAN ID: 20260309_104233_104a4b29
ADO: Municipal Greenery Authority in Łódź
Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL
Technical Conclusions (Scanner)
- 🔴 GA4 G-30F084ZHSL (Library) + legacy UA UA-25825547-40 with gcd=13l3l3l2l1l1 + npa=1
- 🔴 CMP cookie-box.js present, but not integrated with Google Consent Mode
- ⚠️ Facebook SDK + YouTube widget + Twitter widgets + livebar lodz.pl/livebar/
- - Ad server from the Municipal Library (ads.biblioteka.lodz.pl)
- - Stable timeline. GA cookies set immediately after DOMContentLoaded.
Privacy Policy Analysis vs Tags
📄 Show Domain Assessment ▼
Conclusions and Violations
- 🔴 Library GA4 without Consent Mode — active beacon to G-30F084ZHSL with parameters gcd=13l3l3l2l1l1, npa=1 and pscdl=noapi. CMP cookie-box.js does not integrate with Google Consent API.
- 🔴 Cross-controller sharing — GA4 property belonging to the Municipal Library is actively used on the Municipal Greenery Authority website. Lack of transparent joint administration (art. 26 RODO).
- ⚠️ Facebook SDK + third-party widgets — connect.facebook.net/pl_PL/sdk.js, YouTube widget API, Twitter widgets.js and iframe lodz.pl/livebar/ loaded.
- - Legacy UA still active — UA-25825547-40 configured in parallel with GA4.
- - Ad server from the Library — active ads.biblioteka.lodz.pl/www/delivery/asyncjs.php.
Legal Context (Municipal Greenery Authority)
The Municipal Greenery Authority in Łódź is a unit responsible for maintaining urban greenery, parks, squares, tree stands and recreational areas. Visitors to the website are mainly residents interested in greenery, outdoor events and environmental protection.
Layer A — culture of administrator compliance. cookie-box CMP implemented, but not integrated with Google Consent Mode. Shared GA4 property of the Municipal Library launched without transparent joint administration. This is a systemic oversight repeating across many municipal units.
Layer B — market value of behavioral signal. Low/moderate. Data on interest in urban greenery and recreation has limited commercial value.
Summary of assessment – zzm.lodz.pl
| Criterion | Assessment |
|---|---|
| Firing trackers before consent | 🔴 Yes — GA4 + UA with gcd=13l3l3l2l1l1 and pscdl=noapi |
| CMP Effectiveness | ⚠️ Present (cookie-box), but not integrated with Consent Mode |
| Transmission to third parties | 🔴 Yes — shared G-30F084ZHSL + YouTube/Twitter + livebar |
| Cross-controller identity | 🔴 Active (G-30F084ZHSL on ZZM domain) |
| Facebook Pixel | ✅ Inactive (only SDK) |
| Overall assessment | 🔴 Negative — active marketing tracking without effective consent |
Verdict: On zzm.lodz.pl activation of GA4 (G-30F084ZHSL) and legacy UA (UA-25825547-40) with parameters gcd=13l3l3l2l1l1 + pscdl=noapi was confirmed. cookie-box CMP does not transmit consent signal. Additionally, there is cross-controller sharing with the Municipal Library on the Municipal Greenery Authority domain. This constitutes a violation of the principles of lawfulness and minimization of processing (art. 5 and 6 RODO) and joint administration requirements (art. 26 RODO).
📸 Evidence: Page Snapshots and GDPR Documents ▼
📌 Notes from policy scan:
RODO ZZM PDF; monitoring clause: https://zzm.lodz.pl/files/public/uploads/RODO/KLAUZULA_INFORMACYJNA__MONITORING_ZZM.pdf
Google Tag Assistant – official Consent Mode debugging tool
Do you want to check for yourself whether any of the domains in the report actually send data to Google before obtaining consent? Use the official Google tool:
• the exact moment of triggering Google Analytics, Google Ads, DoubleClick, etc.
• what data is passed to Google servers
• whether Consent Mode is correctly implemented
This is a completely objective Google tool. Anyone can independently verify and falsify the report results.
Most importantly, this tool is used by digital marketing specialists to check how and if tags work, so there is no possibility that someone allegedly implemented something wrong or made a mistake. Especially on the scale of over a dozen domains actively monetized with traffic in the millions. It is also worth mentioning that Google has no interest in falsifying results, as this would harm its own interests. It is a reliable tool.