City of Łódź Office - Audit of violations on city and municipal-related services (2026)

A technical journalistic investigation documenting probable personal data protection violations on websites managed by entities associated with the City of Łódź. Tracking systems were triggered immediately upon entering the site - without user consent, sending signals to external entities. Proceedings by the Personal Data Protection Office (UODO), Office of Electronic Communications (UKE), and the prosecutor's office are underway.

Official context – response from the Deputy Mayor of the City of Łódź

On May 22, 2026, councilors Sebastian Bułak, Marcin Buchali, and Piotr Cieplucha submitted an interpellation regarding reports of possible tracking of municipal website users without informed consent, citing the audit by the Dadalo.pl editorial team and press reports. The response was provided on June 30, 2026, by the Deputy Mayor of the City of Łódź, Tomasz Piotrowski.

"The information contained in the interpellation (cited publication) initiated an internal analysis regarding the websites operated by the Office, in particular: uml.lodz.pl and bip.uml.lodz.pl. We cannot rule out that the situation described on https://dadalo.pl/ took place, and the parameter gcd assumed the value 13l3l3l2l1l1."

The Deputy Mayor confirmed that the parameter gcd=13l3l3l2l1l1 ("not set" state) might have been present on the city's websites. As I demonstrate in the audit, this value, combined with poor implementation, means that the consent mechanism did not have time to act - tracking tags were triggered before the user made a decision to grant or deny consent, and marketing data was sent as if full consent had been given for everything.

The city declared it would take corrective actions, including removing old and inadequate tracking codes and considering conducting analytics outside the Google ecosystem. It was also announced that commissioning an external audit is under consideration.

Furthermore, the Deputy Mayor indicated that a proprietary cookie consent tool had been implemented on the uml.lodz.pl and bip.uml.lodz.pl websites. At the same time, it was reserved that commissioning an external audit of this solution is also being considered.

Due to the nature of the response and the scale of irregularities, including this "proprietary solution" implemented on the BIP, an official editorial response to the above letter will be published soon on the dadalo.pl website. Concurrently, the update of the audit in its current form and detail, along with comments for each domain, is part of this response.

Source: Response from the Deputy Mayor of the City of Łódź, Tomasz Piotrowski, to the councilors' interpellation of May 22, 2026 (letter dated June 30, 2026).
Technical interpretation update July 4-7, 2026

Update July 7, 2026: due to re-analyzing the evidence per domain, which took me several days and allowed for a more detailed look at the problems than in March, I decided to clarify the violation scoring I write about in a more technical and detailed manner, in many cases analyzing the full payload. This changes not only the number of domain violations but also, in some cases, their severity. The ratings are currently placed in the aggregate list (domain index) and in the per-domain report.

In the original version of the report, I interpreted the value of the parameter gcd=13l3l3l2l1l1 as indicating an active, default "granted" state setting. After the city's response, in which it admits to the problem with data processing, and analysis of available data, I am clarifying this position.

Generally speaking, the network data (incl. the npa=1 flag and the absence of the gcs parameter) shows that the websites did not set anything. Instead of a forced "granted" state, we are dealing with a complete failure to configure Consent Mode at the critical moment of page loading.

Google tags were triggered in legacy mode — that is, as if the Consent Mode mechanism had not been implemented at all. The lack of a signal from Consent Mode resulted in full data processing prior to any user decision. In the text, I update the interpretation taking this knowledge into account, and on dadalo.pl I will publish my opinion regarding this practice, which I know from the industry.

Note: The technical details of the analysis refer to the state of the pages at the time of the audit (March 6–9, 2026) and do not include any subsequent modifications made by the City of Łódź Office.

This change does not weaken, but rather clarifies the assessment: the problem is not a wrongly set flag, but the lack of a functioning consent management architecture at the time tracking is initialized.

Marketing tracking evaluation variants

Evaluation based on the presence of active marketing tracking without consent. Between July 5-7, 2026, I re-analyzed the evidence and decided to modify the ratings and methodology using the more detailed information I painstakingly prepared for each domain. I believe this is currently more reliable.

Evaluation typeDescription
🔴🔴 Very negativeActive marketing tracking + no CMP + cross-controller sharing with other entities.
🔴 NegativeActive marketing tracking (GA4 / UA / Pixel) triggered without an effective consent signal. CMP present, but not integrated with Consent Mode.
⚠️ MediumNo direct marketing tracking on the domain. Legacy Facebook SDK present and indirect tracking via external widgets. No CMP.
PositiveNo marketing tracking (GA4 / Pixel). Consent mechanism present and integrated.
🔴

I have established that on many municipal websites in Łódź, visitors were tracked without their knowledge and consent

My findings are confirmed by tests conducted between March 6-9, 2026

The material documents the technical scanning of 41 websites managed by, funded by, or associated with the City of Łódź Office. Each test session was sterile — an automated browser opened the page without any cookies, without browsing history, and without interacting with the consent banner.

Out of 41 technically checked addresses, 4 items were excluded from the comparative assessment for technical reasons (TLS problem, technical panels, or redirects). The aggregate indicators were thus calculated for 37 assessable domains. It is worth noting that as a result of an in-depth analysis of the source data in July 2026 and a change in the rating methodology, the weights and ratings of some domains were modified.

The result is unequivocal: on 29 out of 37 assessable domains, tracking systems (mainly Google Analytics, Google Ads, and DoubleClick) were triggered immediately upon entering the site and began sending data to external servers before the user had the opportunity to make any decision regarding consent.

In many cases, the consent banner did not perform a real blocking function. Tracking tags initialized in full mode (setting analytical and marketing cookies), and data was transmitted to Google, Meta, and DoubleClick before the consent mechanism had time to act.

On the majority of tested domains, tracking tags were triggered in a state of unconfigured Consent Mode (parameter gcd=13l3l3l2l1l1), which resulted in full data processing prior to any user interaction.

ℹ️ TCF 2.2 vs Google Consent Mode v2 – why doesn't it protect in this case?

Some websites may use the IAB TCF 2.2 (Transparency & Consent Framework), which standardizes consent collection. However, TCF only regulates the method of obtaining user consent, not the behavior of Google tags.

Google Consent Mode v2 works independently and must be correctly integrated with the CMP. In the analyzed cases, Google tags were triggered at a very early stage of page loading (already at the after_domcontentloaded stage), before the CMP banner had time to fully initialize and transmit any consent signals.

Why didn't the pingless mode (cookieless pings) work?

  • Pingless (anonymous pings without full cookies) only occurs with correct Advanced Consent Mode with a default state of denied.
  • On the tested domains, Google tags were triggered without effective blocking by the Consent Mode mechanism, resulting in the immediate saving of full analytical and marketing cookies (_ga, _gcl_au, _fbp, and others).
  • There was no limited, anonymous pinging — full tracking occurred before any user decision.

In conclusion: even having a certified CMP compliant with TCF 2.2 does not absolve one from the obligation of correct Google Consent Mode configuration. Triggering tracking tags before effectively determining the consent state constitutes a violation of Article 6(1)(a) of the GDPR, regardless of the consent framework used.

Domain breakdown

Domain (click to go)Entity / Data ControllerTracking evaluation
lodz.plMunicipal Library in Łódź🔴 VIOLATION
uml.lodz.plCity of Łódź Office – main domain🔴🔴 V. NEGATIVE
bip.uml.lodz.plCity of Łódź Office🔴 VIOLATION
mpu.lodz.plMunicipal Urban Planning Office in Łódź🔴 VIOLATION
zdit.uml.lodz.plZDiT (Redirect)➖ EXCLUDED
cuw.uml.lodz.plShared Services Center in Łódź🔴 VIOLATION
cuwdps.uml.lodz.plShared Services Center for DPS in Łódź🔴 VIOLATION
lckm.uml.lodz.plŁódź Contact Center for Residents🔴 VIOLATION
mops.uml.lodz.plMunicipal Social Welfare Centre in Łódź🔴 VIOLATION
mzz.lodz.plMunicipal Nursery Complex in Łódź🔴 VIOLATION
schronisko.uml.lodz.plShelter for Homeless Animals in Łódź🔴 VIOLATION
architektmiasta.uml.lodz.plCity Architect's Office🔴 VIOLATION
rewitalizacja.uml.lodz.plRevitalization Portal🔴 VIOLATION
invest.lodz.plCity of Łódź Office (Invest in Łódź)🔴 VIOLATION
li.lodz.plŁódź Investments Sp. z o.o.🔴 VIOLATION
zlm.lodz.plMunicipal Premises Management🔴 VIOLATION
bip.zlm.lodz.plMunicipal Premises Management🔴 VIOLATION
mosir.lodz.plMunicipal Sports and Recreation Centre in Łódź🔴 VIOLATION
aquapark.lodz.plAquapark Fala Sp. z o.o.🔴 VIOLATION
orientarium.lodz.plOrientarium Zoo Łódź🔴🔴 V. NEGATIVE
lodz.travelŁódź Tourism Organization (ŁOT)🔴 VIOLATION
kartalodzianina.plŁódź Tourism Organization (ŁOT)🔴 VIOLATION
biblioteka.lodz.plMunicipal Library in Łódź🔴 VIOLATION
capz.lodz.plAdministrative Centre for Foster Care🔴 VIOLATION
css.samorzad.lodz.plSocial Benefits Centre🔴 VIOLATION
botaniczny.lodz.plBotanical Garden in Łódź🔴 VIOLATION
strazmiejska.lodz.plShelter for Homeless Animals in Łódź🔴 VIOLATION
nowa.mapa.lodz.plInterSIT — Łódź Geodesy Centre⚠️ MEDIUM
ads.biblioteka.lodz.plMunicipal Library (Ad Server)➖ EXCLUDED
atlasarena.plMAKiS Sp. z o.o. (100% City)⚠️ MEDIUM
bip.biblioteka.lodz.plMunicipal Library in Łódź⚠️ MEDIUM
kartaturysty.lodz.travelŁódź Tourism Organization (ŁOT)✅ POSITIVE
lodz.praca.gov.plDistrict Labour Office in Łódź🔴 VIOLATION
media.lodz.plŁódź Media Group / ŁOT⚠️ MEDIUM
mpk.lodz.plMunicipal Transport Company in Łódź🔴 VIOLATION
pup-lodz.plDistrict Labour Office in Łódź➖ EXCLUDED
teatr-muzyczny.lodz.plMusical Theatre in Łódź➖ EXCLUDED
wizyty.uml.lodz.plCity of Łódź Office (appointment booking)✅ POSITIVE
wsparcie.uml.lodz.plSocial Support Portal✅ POSITIVE
zzm.lodz.plMunicipal Greenery Authority🔴 VIOLATION
makis.plMunicipal Arena of Culture and Sports⚠️ MEDIUM

Methodological note: "Excluded" means an address technically checked but incomparable with the others (e.g., TLS problem or redirect). Not all city domains were analyzed — however, the sample is large and representative enough to draw general conclusions.

📁

Full investigative documentation for each domain — network logs in HAR format, cookie dumps, request payloads with the gcd parameter, browser trace — is available below in the sections for individual domains.

📋 Legal notice and rules of openness

This report has been prepared and published in good faith, as part of independent journalistic activity, in order to pursue the public interest. All findings presented in the material are based on my best knowledge regarding the technical analysis of tracking mechanisms and personal data processing on websites.

In connection with the findings described in this material, proceedings are underway before the competent institutions — the Personal Data Protection Office (UODO), the Office of Electronic Communications (UKE), and prosecutorial authorities. In mid-July 2026, I am supplementing the evidence and initiating further institutions to verify the resolution of the personal data processing issue.

I adopt a stance of full openness and transparency. If anyone identifies substantive or technical errors in this report, please contact me. Any justified allegation will be verified, and the report will be corrected accordingly.

Contact the editorial office: @dadalo@journa.host (Mastodon) · redakcja@dadalo.pl

Research Objective and Methodology

The panel below presents technically documented and frozen events from the scanning process of websites associated with the city of Łódź. The data is integral, timestamped, and made available for further investigative verification.

  • Clean incognito sessions: Chrome 145 / Firefox 140
  • Full sterility: No interaction with cookie banners. The scanner documents what the page loads before the user gives consent.
  • Digital evidence: DevTools Network/Storage/Console, HAR format log exports, timestamp analysis.
  • Scope of tests: March 6–9, 2026

📖 Chronology of triggering trackers without user consent

The guide below explains the chronology of cookies appearing in a sterile test session (before clicking consent on the banner). It shows the moment of creation of tracking mechanisms. This is a technical description for selected files that we publish so that anyone can falsify the theses contained in the report.

Timeline of identifiers appearing

In the analyzed evidence (the cookies_timeline.ndjson file available under the icon ⏱️ Cookies Timeline), the following sequence frequently occurs:

  • before_navigation: cookies: [] (Clean browser session)
  • after_domcontentloaded: Over a dozen analytical, advertising, and third-party cookies appear immediately.
  • after_load: The set of created cookies persists in the target system's memory.
  • after_async_window: Scripts continue to run actively, overwriting and updating identifier values (e.g., _ga_*).

Evidentiary conclusion: Tracking mechanisms do not wait until the end of page loading and do not wait for user consent. They activate at a very early stage of rendering the page in a fully passive session.

Significance of key identifiers (Cookies)

  • _ga, _gid, _gat_gtag_UA_*, _ga_* — This is a strong trace of Google Analytics / Google tags. _ga is used to distinguish long-term users, _gid identifies short-term sessions, and _gat limits the number of requests.
  • _gcl_au — A typical cookie associated with Google Ads / conversions. Usually appears with Google advertising campaign implementations.
  • _fbp — A Meta Pixel marketing cookie (Facebook), used to track visits, user behavior, and advertising goals across external providers.
  • FCCDCF — Cookie associated with Google Funding Choices or the consent mechanism. A trace of platform consent collection systems.
  • YSC, VISITOR_INFO1_LIVE, __Secure-ROLLOUT_TOKEN — Traces of the YouTube system. The presence of the partitionKey attribute often indicates that the embedding operated in a third-party context and processed viewer data.

Technical evidence of data transmission prior to consent

Since there was no pollution in the before_navigation state, and right after after_domcontentloaded the browser already possessed a full set of identifiers such as _ga, _gid, or _fbp, this indicates forced initialization of analytics and advertising prior to any conscious action by the user.

Important: Even if the CMP mechanism (e.g., Cookiebot, Klaro) wakes up with a delay and "clears" these cookies at the end of the session (in the after_async_window phase), the audit still records a violation. This is because before the CMP reacted, the browser had already managed to establish communication with target servers (e.g., Google) and transmit data to them in network requests (Payload), containing e.g., the Consent Mode parameter gcd=13l3l3l2l1l1. Deleting a cookie after the fact does not reverse the data leak that has already occurred.

The paired evidentiary chain for each domain generally confirms the pattern: (1) no cookies 🡒 (2) immediate saving without user consent in Storage memory 🡒 (3) irreversible transmission of g/collect requests with the parameter gcd=13l3l3l2l1l1 to recipients 🡒 (4) optional, delayed clearing using an improperly configured CMP banner.

What should a correct implementation look like? According to the guidelines, the system should retain only necessary technical cookies. All advertising and analytical signals should have a default denied (blocked) status. Only after explicit acceptance on the banner can the signals be updated to the granted state. In the analyzed cases, Google tags were triggered without effective limitation from the Consent Mode mechanism, which resulted in full data processing prior to any user decision. This situation can be fundamentally verified with free tools, including the Preview mode in Google Tag Manager (Consent tab).

🔬 Visualization of the violation mechanism

The diagrams below illustrate the course of the violation recorded in sterile test sessions and the contrast with the correct implementation of the consent mechanism.

📊 Evidentiary chain — sequence of violation

flowchart TD
    A["🧪 Sterile test session
before_navigation
cookies: empty list"] --> B["⚡ after_domcontentloaded
_ga, _gid, _fbp appear
along with other cookies"] B --> C["🔴 Scripts launch analytics
and advertising before any
user action"] C --> D["📡 Browser sends requests
e.g. g/collect to recipients"] D --> E["🔑 Payload reveals
gcd=13l3l3l2l1l1
(lack of configured Consent Mode)"] E --> F["🌐 Data reaches third
parties: Google, Meta, DoubleClick
before the user consents"] F --> G["⏳ after_async_window
CMP may remove some cookies
if we click REJECT"] G --> H["⚖️ Legal-technical effect:
cookie removal does not reverse
prior data transmission"] style A fill:#0f172a,stroke:#38bdf8,color:#e2e8f0 style B fill:#1e1b4b,stroke:#f43f5e,color:#fda4af style C fill:#4c0519,stroke:#f43f5e,color:#fda4af style D fill:#4c0519,stroke:#f43f5e,color:#fda4af style E fill:#431407,stroke:#f59e0b,color:#fde68a style F fill:#4c0519,stroke:#f43f5e,color:#fda4af style G fill:#1e1b4b,stroke:#a78bfa,color:#c4b5fd style H fill:#0c0a09,stroke:#ef4444,color:#fca5a5

The diagram presents the evidentiary chain recorded in each scanning session. The "GRANTED" stage (step 5) is crucial — it means that the tracking system received a consent signal without the user's actual decision.

⚖️ Comparison: stated condition vs correct condition

flowchart LR
    subgraph X["🔴 Condition found in audit"]
        direction TB
        A1["Entering the site
without clicking consent"] --> A2["Immediate activation
of tracking tags"] A2 --> A3["Cookies appear
_ga, _gid, _fbp, _gcl_au"] A3 --> A4["Requests are sent
to Google / Meta / DoubleClick"] A4 --> A5["Payload contains
gcd=13l3l3l2l1l1
(no effective Consent Mode)"] A5 --> A6["CMP reacts with a delay
or only clears cookies locally
Transmission has already occurred"] end subgraph Y["🟢 Correct condition per GDPR"] direction TB B1["Entering the site
without clicking consent"] --> B2["Default consent state
= denied"] B2 --> B3["No analytical or
advertising cookies"] B3 --> B4["No transmission of marketing
data to recipients"] B4 --> B5["Only after conscious
user acceptance does
status change to granted"] end style A1 fill:#1e1b4b,stroke:#818cf8,color:#e0e7ff style A2 fill:#4c0519,stroke:#f43f5e,color:#fda4af style A3 fill:#4c0519,stroke:#f43f5e,color:#fda4af style A4 fill:#4c0519,stroke:#f43f5e,color:#fda4af style A5 fill:#431407,stroke:#f59e0b,color:#fde68a style A6 fill:#4c0519,stroke:#f43f5e,color:#fda4af style B1 fill:#0f172a,stroke:#38bdf8,color:#e2e8f0 style B2 fill:#052e16,stroke:#22c55e,color:#bbf7d0 style B3 fill:#052e16,stroke:#22c55e,color:#bbf7d0 style B4 fill:#052e16,stroke:#22c55e,color:#bbf7d0 style B5 fill:#052e16,stroke:#22c55e,color:#bbf7d0

The comparison shows a fundamental difference: in the stated condition, the system immediately treats the user as someone who gave consent (GRANTED). In the correct condition, the default state is refusal (denied), and marketing data is not sent until a conscious action is taken.

📊 Analysis details, files, and ratings for each domain

On July 5-7, 2026, the report was substantively updated with additional technical details
B. NEGATIVE

https://orientarium.lodz.pl/ ŁOT Group

SCAN ID: 20260306_202023_a6417c59

ADO: ZOO Łódź sp. z o.o.

Hosting/IT: Hetzner

Requests21
Cookies10

Technical Conclusions (Scanner)

  • 🔴🔴 Active Facebook Pixel (fbevents.js + config 668887504186759 + cookie _fbp)
  • 🔴🔴 Google Ads Conversion IDs: AW-10940984035 + AW-665139254 + AW-557285855
  • 🔴 Dedicated GA4 G-K51BYYXXYF + GTM GTM-NVTJSXK + Crazy Egg (script.crazyegg.com)
  • ⚠️ PixelYourSite (WordPress plugin) + Google Conversion Linker (_gcl_au + _gcl_ls)
  • - Cookie Notice present, but does not block marketing tags before consent
  • - reCAPTCHA + YouTube widgets + livebar lodz.pl/livebar/

Privacy Policy Analysis vs Tags

Identified Container IDs:
G-K51BYYXXYF AW-10940984035 AW-665139254 AW-557285855 FB Pixel 668887504186759
Privacy Policy Assessment: Aggressive marketing stack (Pixel + Google Ads + GA4 + session recording) on the zoo website without an effective consent mechanism. Cookie Notice does not block tags before user interaction.
📄 Show Domain Assessment

Conclusions and Violations

  • 🔴🔴 Active Facebook Pixelfbevents.js + config 668887504186759 loaded. Cookie _fbp is set. PixelYourSite (WordPress plugin) confirms intentional Pixel implementation.
  • 🔴🔴 Google Ads Conversion + Enhanced Conversions — active IDs: AW-10940984035, AW-665139254 and AW-557285855. _gcl_au and _gcl_ls (Google Conversion Linker) present.
  • 🔴 Dedicated GA4 + GTM + Crazy Egg — property G-K51BYYXXYF, container GTM-NVTJSXK and script.crazyegg.com (heatmaps and session recording).
  • ⚠️ Lack of effective CMP — only Cookie Notice (WordPress plugin) is present, which does not block marketing tags before user consent. Tags fire immediately after page load.
  • - reCAPTCHA + third-party widgets — reCAPTCHA v3 + YouTube widgets + livebar lodz.pl/livebar/.

Legal Context (Orientarium Zoo Łódź)

Orientarium Zoo Łódź is a modern tourist and educational attraction of the City of Łódź. The website has a commercial-recreational character (tickets, events, marketing). It does not process special categories of data within the meaning of art. 9 RODO, but as a website with advertising monetization and high traffic, it is subject to standard RODO + ePrivacy requirements.

Layer A — culture of administrator compliance. A very aggressive marketing stack (Pixel + Google Ads + GA4 + Crazy Egg) was used with a minimal consent mechanism (only Cookie Notice). This is a classic example of prioritizing monetization over compliance.

Layer B — market value of behavioral signal. High. The zoo website generates data on interests in family recreation, events and tourism — attractive for audience profiling. The full stack (Pixel + Conversion + session recording) maximizes signal value.

Summary of assessment – orientarium.lodz.pl

CriterionAssessment
Firing trackers before consent🔴🔴 Yes — Pixel + Google Ads + GA4 fired immediately
CMP Effectiveness🔴 Only Cookie Notice — does not block tags
Transmission to third parties🔴🔴 Pixel + Google Ads + Crazy Egg + shared GA
Facebook Pixel🔴🔴 Active (fbevents.js + config + _fbp)
Google Ads / Conversion🔴🔴 Active (3x AW- ID + Conversion Linker)
Overall assessment🔴🔴 Very negative — full marketing stack without effective consent

Verdict: On orientarium.lodz.pl one of the most aggressive marketing stacks in the entire audit was implemented: active Facebook Pixel, multiple Google Ads Conversion IDs, dedicated GA4 and Crazy Egg (session recording). Cookie Notice does not block tags before user consent. This is a classic example of prioritizing monetization over privacy protection on the website of a City of Łódź tourist attraction. Violation of art. 5(3) of the ePrivacy Directive and art. 6 and 7 RODO is clear.

📸 Evidence: Page Snapshots and GDPR Documents
📌 Notes from policy scan:

Cookie banner: https://orientarium.lodz.pl/assets/2025/05/Polityka-plikow-Cookies-07.2024.pdf — anomaly: two different cookie PDF versions

📁 Show Hard Evidence (HAR, Cookies, Trace)
B. NEGATIVE

https://uml.lodz.pl/ ŁOT Group

SCAN ID: 20260306_201513_88503e84

ADO: Łódź City Office

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests15
Cookies8

Technical Conclusions (Scanner)

  • 🔴🔴 GA4 G-30F084ZHSL + two Google Ads Conversions: AW-10940984035 + AW-790142032
  • 🔴🔴 Conversion event sent on the homepage: AW-10940984035/V02uCO6r29MDEOPViOEo
  • ⚠️ New CMP: Klaro.js (cookies.uml.lodz.pl) — better than cookie-box, but still ineffective against Google
  • - Facebook SDK + YouTube widget + Twitter widgets + livebar lodz.pl/livebar/
  • - Ad server from the Library + Google Conversion Linker (_gcl_ls)
  • - Beacons with gcd=13l3l3l2l1l1 + npa=1 — tags fire before consent

Privacy Policy Analysis vs Tags

Identified Container IDs:
G-30F084ZHSL AW-10940984035 AW-790142032 UA-25825547-40
Privacy Policy Assessment: Main domain of the Łódź City Office with a full marketing stack (GA4 + 2× Google Ads Conversion + conversion event). New Klaro CMP, but still ineffective against Google.
📄 Show Domain Assessment

Conclusions and Violations

  • 🔴🔴 GA4 + two Google Ads Conversions without consent — active beacon to G-30F084ZHSL and conversion events to AW-10940984035 and AW-790142032. Tags fire with parameters gcd=13l3l3l2l1l1 + npa=1.
  • 🔴🔴 Conversion event on the homepage — conversion AW-10940984035/V02uCO6r29MDEOPViOEo was recorded and sent directly on uml.lodz.pl.
  • ⚠️ New CMP: Klaro — instead of cookie-box, klaro.js + config from cookies.uml.lodz.pl appeared. This is a step in the right direction, but still does not block Google tags before consent.
  • ⚠️ Facebook SDK + third-party widgets — Facebook SDK, YouTube widget API, Twitter widgets and iframe lodz.pl/livebar/ were loaded. Facebook Like plugin is also present.
  • - Google Conversion Linker active_gcl_ls in localStorage + _gcl_au in cookies (from previous sessions).

Legal Context (Łódź City Office – main domain)

uml.lodz.pl is the official homepage of the Łódź City Office — the most important domain in the entire municipal ecosystem. Thousands of residents visit it daily for official, informational and communication purposes. As a public entity website, it is subject to the highest standards of transparency and data processing minimization.

Layer A — culture of administrator compliance. A new CMP (Klaro) has been implemented, which is progress compared to the cookie-box. However, a full marketing stack (GA4 + two Google Ads Conversions) is still launched without an effective consent signal. This is a systemic oversight at the level of the entire institution.

Layer B — market value of behavioral signal. Very high. The Łódź City Office homepage generates data on the interests of Łódź residents (offices, services, events) — attractive for audience profiling. Conversion tracking + GA4 maximize the value of this signal.

Summary of assessment – uml.lodz.pl

CriterionAssessment
Firing trackers before consent🔴🔴 Yes — GA4 + 2× Google Ads Conversion + conversion event
CMP Effectiveness⚠️ New Klaro (better than cookie-box), but still ineffective against Google
Transmission to third parties🔴🔴 Yes — GA4 + Google Ads + Facebook SDK + livebar
Google Ads Conversion🔴🔴 Active (2 IDs + conversion event on the homepage)
Facebook Pixel✅ Inactive (only SDK + Like plugin)
Overall assessment🔴🔴 Very negative — full marketing stack on the city's main domain

Verdict: On uml.lodz.pl (main domain of the Łódź City Office), one of the heaviest marketing stacks in the entire audit was implemented: active GA4 (G-30F084ZHSL), two Google Ads Conversion IDs (AW-10940984035 + AW-790142032) and a direct conversion event on the homepage. The new Klaro CMP is progress, but still does not block Google tags before user consent. This is a violation of the principles of minimization and legality of processing at the level of the entire public institution.

🔬 Extended Analysis: X-ray Methodology vs Scanner

Methodology Note: Our automated Scanner focuses on detecting advertising, analytics and tracking infrastructure (so-called "tracking heuristics" in the context of Consent Mode and cookies). In parallel, "X-ray" (plugin from the Internet. Time to Act! foundation) was used. X-ray is based on privacy activists' methodology, for whom every connection to an external server without consent (even downloading fonts or CDN scripts) is treated as data disclosure (IP address) and a potential violation. The following comparison is a unique fusion of both perspectives.

Evidentiary Consistency

  1. Timeline consistency: Raw loading logic data perfectly matches network logs. Initialization of tracking packages occurs fractions of a second after DOM load, clearly proving forced script execution.
  2. GCD Confirmation: X-ray clearly documents the sending of the hard parameter gcd=13l3l3l2l1l1 in separate endpoints (region1.analytics.google.com, stats.g.doubleclick.net, www.google.com, www.google.pl). This fully verifies our thesis — the evidence appears in at least two independent tools.
  3. Differences in domain visibility (Tracking vs All Connections): The Scanner reports a dozen domains (because it filters pure "tracking"). X-ray reports more, including bunny.net (fonts), twitter.com, gr-cdn.com or googletagmanager.com. From a legal point of view, according to RODO activists, loading e.g. a stylesheet from a foreign server is also data transmission outside the main domain.

Deeper data flow analysis:

  • Google Ads Advertising Infrastructure: Remarketing identifiers AW-790142032 and AW-10940984035 detected active before user consent. Google Ads tags are not declared in the UMŁ cookie policy.
  • Active Meta Tracking: Connections to connect.facebook.net and www.facebook.com recorded in a clean session — transmission of IP address and page URL to Meta Platforms without consent.
  • Cross-domain tracking lodz.pl ↔ uml.lodz.pl: Domains share GA property G-30F084ZHSL and UA UA-25825547-40 without disclosure of joint administration (art. 26 RODO) in the RODO documents of either domain.
  • Twitter Session Tracking: Embedded content generates session_id reported to syndication.twitter.com before any intentional visitor action.
📸 Evidence: Page Snapshots and GDPR Documents
📁 Show Hard Evidence (HAR, Cookies, Trace)
EXCLUDED

https://ads.biblioteka.lodz.pl/ ŁOT Group

SCAN ID: 20260306_201837_7265207d

Data Controller: Biblioteka Miejska w Łodzi

Hosting/IT: Hetzner

Requests0
Cookies1

Technical Conclusions

  • -Only technical/session cookies exist after the session.
  • -The service is an administrative panel for managing campaigns and therefore does not have its own mechanism for collecting consents. However, it is on the domain list and embedded on the main library page, which is why it is part of the scan.

Privacy Policy Analysis vs Tags

No assigned containers in the journalistic table.

Privacy Policy Assessment: The privacy policy correctly declares the use of identified tools (tracking codes) or no explicit concealment was found (Full Compliance of the declaration with the actual state).
📄 Show Domain Assessment

Audit Summary: ads.biblioteka.lodz.pl

Latest scan: 20260306_201837_7265207d

Basic information

  • URL: https://ads.biblioteka.lodz.pl/
  • Sterile Session Status: 🟢 CLEAN (No tracking traces before consent)
  • Total Requests: 11
  • Tracking Requests: 0
  • Cookies Set: 1

Conclusions and Violations

  • ⚠️ Only technical/session cookies exist after the session.

Data Flow (Identified Recipients)

  • No identified external tracking domains in this session.

CMP Detection (Consent Management)

  • No commonly known CMP tools uniquely identified in code (an untypical solution might be used).

Report generated automatically based on network traffic analysis and DOM changes in an empty browser session (Before clicking the consent button).

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

Revive Adserver login panel – no public policy page

📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://bip.uml.lodz.pl/

SCAN ID: 20260306_201535_2201a79b

Data Controller: Urząd Miasta Łodzi

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests6
Cookies11

Technical Conclusions

  • 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
  • 🔴 A custom CMP was detected (TYPO3 cookiebox from the uml_portal package), which does not block the loading of trackers before the user's decision — a deceptive mechanism. There are no consent default or consent update commands in data_layer.json.
  • 🔴 Data transmitted to Google (GA4 + DoubleClick) before any decision. Facebook SDK and YouTube player_api were also loaded — without confirmed beacon calls in this measurement.
  • ⚠️ GA cookies set on the apex domain .uml.lodz.pl — analytical identity shared with the City of Łódź portal (details in expanded view).
  • - After the session, 9 tracking cookies remain (4× GA, 5× YouTube). Additionally, 2 F5 BIG-IP session management cookies — non-tracking.

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
UA-25825547-40 G-30F084ZHSL
Policy Assessment: The policy declares Google Analytics and Facebook, however, a custom CMP (TYPO3 cookiebox) was implemented on the bip.uml.lodz.pl website, which does not block the loading of tags before the user's decision. Google Analytics tags, Facebook SDK, and YouTube were firing immediately after the page loaded, before any user interaction. No declaration of DoubleClick in the privacy policy.
📄 Show Domain Assessment

Audit Summary: bip.uml.lodz.pl

Latest scan: 20260306_201535_2201a79b

Conclusions and Violations

  • 🔴 Tracking tags were firing immediately upon entering the site, before any user decision. Google Analytics 4 cookies (property G-30F084ZHSL), Universal Analytics (UA-25825547-40), and YouTube cookies were set. Facebook SDK was loaded (without confirmed beacon transmission in this measurement).
  • 🔴 A CMP was detected (TYPO3 cookiebox from the uml_portal package), which does not block the loading of trackers before the user's decision — a deceptive mechanism. There are no consent default or consent update commands in data_layer.json.
  • 🔴 Data transmitted to Google (GA4 + DoubleClick) before consent was given. Calls to region1.analytics.google.com/g/collect and stats.g.doubleclick.net/g/collect contain the client ID (cid), the Consent Mode signal (gcd=13l3l3l2l1l1), the non-personalized ads flag (npa=1), and the DMA context. The gcd configuration indicates a lack of an integrated consent signal — the analytical ping is sent regardless.
  • ⚠️ After the session, 9 tracking cookies remain (_ga* ~2 years, YouTube cookies ~2 years). Additionally, 2 F5 BIG-IP cookies (TS013f51fc, TS01619efc) function as a load balancer persistence mechanism — they do not qualify as trackers, but they reveal the architecture.

Legal Context (BIP)

bip.uml.lodz.pl is not an ordinary information page. It is the Public Information Bulletin (BIP) — a tool for executing the right of access to public information under Art. 61 of the Constitution of the Republic of Poland, operated within the regime of the Act of 6 September 2001 on Access to Public Information and the Regulation of the Ministry of Internal Affairs and Administration of 18 January 2007 on the BIP. A citizen exercising their constitutional right of access to public information cannot be subjected to commercial tracking as an unwritten condition of access. The violation is of a qualified nature — beyond the GDPR, it affects the constitutional guarantee of access to information on the activities of public authority bodies.

Overall Assessment: A domain with a special legal status (BIP), on which transmission to third parties without user consent was identified, alongside a cross-domain scope of GA cookies covering the entire UMŁ portal. The deceptive CMP mechanism (TYPO3 cookiebox present, but non-blocking) weakens the line of defense based on "lack of awareness" — there was an awareness of the obligation, but a lack of effective implementation.

Data Flow (Identified Recipients)

  • Google LLC – Google Analytics 4 (property G-30F084ZHSL, endpoint region1.analytics.google.com/g/collect), Universal Analytics (UA-25825547-40), Google Signals / DoubleClick (endpoint stats.g.doubleclick.net/g/collect)
  • Meta Platforms Ireland Ltd. – Facebook SDK (connect.facebook.net/pl_PL/sdk.js) loaded; beacon calls to facebook.com/tr were not recorded in this measurement
  • YouTube (Google)player_api + widget API, setting cookies for the .youtube.com domain
  • ads.biblioteka.lodz.pl – external ad server (Revive Adserver, endpoint /www/delivery/asyncjs.php) belonging to the Municipal Library in Łodzi — a separate data controller

CMP Detection

A custom CMP embedded in the TYPO3 template was detected (typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js). The script loads, but does not constitute an opt-in mechanism — it does not block the execution of Google Analytics, Facebook SDK, or YouTube tags before the user's decision. In data_layer.json, Google Consent Mode commands (consent default, consent update) are missing, and payloads to /g/collect contain the gcd=13l3l3l2l1l1 signal, indicating a lack of integrated CMP with the Consent Mode layer.

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

BIP — no separate privacy policy

📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://bip.zlm.lodz.pl/

SCAN ID: 20260306_201940_dbfda186

Data Controller: Zarząd Lokali Miejskich

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests6
Cookies9

Technical Conclusions

  • 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
  • 🔴 A custom CMP was detected (TYPO3 cookiebox from the uml_portal package), which does not block the loading of trackers before the user's decision — a deceptive mechanism. There are no consent default or consent update commands in data_layer.json.
  • 🔴 Data transmitted to Google (GA4 + DoubleClick) before any decision. Facebook SDK, YouTube player_api, and a Twitter iframe were also loaded — without confirmed beacon calls in this measurement.
  • ⚠️ GA cookies set on the apex domain .zlm.lodz.pl — analytical identity shared with the ZLM portal (details in expanded view).
  • - After the session, 9 tracking cookies remain (4× GA, 5× YouTube). No F5 BIG-IP session management cookies — hosting architecture differs from bip.uml.lodz.pl.

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
UA-25825547-40 G-30F084ZHSL
Policy Assessment: Active cross-domain tracking (shared UA-25825547-40 container with uml.lodz.pl and lodz.pl) without a declaration of joint controllership (Art. 26 GDPR). Google and Facebook tags were firing before user interaction.
📄 Show Domain Assessment

Audit Summary: bip.zlm.lodz.pl

Latest scan: 20260306_201940_dbfda186

Conclusions and Violations

  • 🔴 Tracking tags were firing immediately upon entering the site, before any user decision. Google Analytics 4 cookies (property G-30F084ZHSL), Universal Analytics (UA-25825547-40), and YouTube cookies were set. Facebook SDK and a Twitter iframe were loaded (without confirmed beacon transmission in this measurement).
  • 🔴 A CMP was detected (TYPO3 cookiebox from the uml_portal package), which does not block the loading of trackers before the user's decision — a deceptive mechanism. There are no consent default or consent update commands in data_layer.json.
  • 🔴 Data transmitted to Google (GA4 + DoubleClick) before consent was given. Calls to region1.analytics.google.com/g/collect and stats.g.doubleclick.net/g/collect contain the client ID (cid), the Consent Mode signal (gcd=13l3l3l2l1l1), the non-personalized ads flag (npa=1), and the DMA context. The gcd configuration indicates a lack of an integrated consent signal — the analytical ping is sent regardless.
  • 🔴 Cross-domain scope cookies GA. The cookies _ga, _ga_30F084ZHSL, _gid, and _gat_gtag_UA_25825547_40 are set on the apex domain .zlm.lodz.pl, rather than .bip.zlm.lodz.pl. This means that the user's analytical identity on the BIP is carried over between the BIP and the ZLM portal (zlm.lodz.pl) — due to the cookie_domain: auto configuration in gtag. This is a separate cross-domain vector from the shared container identifier (UA-25825547-40) also used by uml.lodz.pl and lodz.pl.
  • ⚠️ After the session, 9 tracking cookies remain (_ga* ~2 years, YouTube cookies ~2 years). Unlike bip.uml.lodz.pl, F5 BIG-IP session management cookies are missing — ZLM likely hosts its BIP on a separate infrastructure.

Legal Context (BIP)

bip.zlm.lodz.pl is not an ordinary information page. It is the Public Information Bulletin of the Municipal Housing Management (Zarząd Lokali Miejskich) in Łódź — a tool for executing the right of access to public information under Art. 61 of the Constitution of the Republic of Poland, operated within the regime of the Act of 6 September 2001 on Access to Public Information and the Regulation of the Ministry of Internal Affairs and Administration of 18 January 2007 on the BIP. A citizen exercising their constitutional right of access to public information cannot be subjected to commercial tracking as an unwritten condition of access. Additional circumstance: ZLM is a separate data controller relative to UMŁ and the Municipal Library, yet it shares the measurement layer with them (the Library's GA4 property G-30F084ZHSL, and the shared UA-25825547-40 container) — without a public declaration of joint controllership within the meaning of Art. 26 GDPR.

Overall Assessment: The pattern is technically similar to bip.uml.lodz.pl (identical Google containers, identical Consent Mode configuration, the same deceptive TYPO3 cookiebox), but additionally embeds a Twitter iframe and utilizes a different hosting architecture (no F5 layer). The fact that the BIP of another separate data controller uses the exact same measurement infrastructure as UMŁ strengthens the hypothesis of data joint controllership without a public declaration.

Data Flow (Identified Recipients)

  • Google LLC – Google Analytics 4 (property G-30F084ZHSL, endpoint region1.analytics.google.com/g/collect), Universal Analytics (UA-25825547-40), Google Signals / DoubleClick (endpoint stats.g.doubleclick.net/g/collect)
  • Meta Platforms Ireland Ltd. – Facebook SDK (connect.facebook.net/pl_PL/sdk.js) loaded; beacon calls to facebook.com/tr were not recorded in this measurement
  • YouTube (Google)player_api + widget API, setting cookies for the .youtube.com domain
  • X Corp. (formerly Twitter) – iframe platform.twitter.com/widgets/widget_iframe embedded with origin bip.zlm.lodz.pl and the widgets.js script; no X/Twitter cookies found in the cookie jar of this measurement
  • ads.biblioteka.lodz.pl – external ad server (Revive Adserver, endpoint /www/delivery/asyncjs.php) belonging to the Municipal Library in Łódź — a separate data controller

CMP Detection

A custom CMP embedded in the TYPO3 template was detected (typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js). The script loads, but does not constitute an opt-in mechanism — it does not block the execution of Google Analytics, Facebook SDK, YouTube, or the Twitter widget before the user's decision. In data_layer.json, Google Consent Mode commands (consent default, consent update) are missing, and payloads to /g/collect contain the gcd=13l3l3l2l1l1 signal, indicating a lack of integrated CMP with the Consent Mode layer.

📸 Evidence: Snapshots of Pages and GDPR Documents
📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://mpu.lodz.pl/

SCAN ID: 20260306_201556_b3e7d004

Data Controller: Miejska Pracownia Urbanistyczna

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests10
Cookies10

Technical Conclusions (Scanner)

  • 🔴 Two GA4 properties running simultaneously without Consent Mode: G-30F084ZHSL (Library) + G-W8F2064SGL (new) with gcd=13l3l3l2l1l1 + npa=1 + pscdl=noapi
  • 🔴 Scroll depth 90% event transmitted to G-W8F2064SGL prior to any user decision
  • ⚠️ Legacy UA container UA-25825547-40 remains active concurrently with both GA4 properties
  • - The cookie-box.js CMP (TYPO3) is present but disconnected from Google Consent Mode
  • - Facebook SDK + YouTube widget API + Twitter widgets + lodz.pl/livebar/ widget
  • - Timeline is stable (before_navigation = 0). No retroactive cookie clearing.

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
G-W8F2064SGL G-30F084ZHSL UA-25825547-40
Policy Assessment: Active cross-domain tracking (shared GA4 G-30F084ZHSL and UA UA-25825547-40 with other municipal domains) without a declaration of joint controllership (Art. 26 GDPR). The website belongs to an entity handling local spatial planning — data mapping tracking interest in specific spatial plots or zoning layouts requires an assessment of proportionality. The cookie-box CMP fails to convey consent signals to gtag — a classic blueprint of the uml.lodz.pl family.
📄 Show Domain Assessment

Conclusions and Violations

  • 🔴 Dual GA4 properties tracking without Consent Mode. Pings routed concurrently to tid=G-30F084ZHSL (Municipal Library) and tid=G-9NTNY6Z0NB (presumably dedicated to MOSiR). Both carry identical metrics parameters: gcd=13l3l3l2l1l1, npa=1, pscdl=noapi, and dma=1. The cookie-box CMP fails to integrate with Google's Consent API.
  • 🔴 Cross-controller + legacy UA — GA4 property G-30F084ZHSL (owner: Municipal Library) is active on mosir.lodz.pl alongside legacy UA-25825547-40 and GTM container GTM-K44FPW9. The client identifier cid=2028970183.1772824802 is shared across the entire ecosystem.
  • 🔴 Advanced events tracked without consent — a scroll event with parameter ep.percent_scrolled=90 was recorded and routed to G-9NTNY6Z0NB (via region1.google-analytics.com/g/collect). Scroll depth tracking operates prior to any interaction with the CMP banner.
  • ⚠️ Facebook SDK without the Pixelconnect.facebook.net/pl_PL/sdk.js loaded (two instances). However, Pixel beacons, the _fbp cookie, and signals/config requests are absent. The SDK is present but inactive tracking-wise in this measurement.
  • ⚠️ Third-party widgets on a sports and recreation domain — YouTube player_api + widgetapi, Twitter widgets.js + iframe, and the UMŁ livebar widget (lodz.pl/livebar/) are embedded. These components drop VISITOR_INFO1_LIVE, YSC, __Secure-YNID, and __Secure-ROLLOUT_TOKEN cookies without first-party control.
  • ⚠️ CMP present but ineffective against Google — script path resolves to /typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js. No consent commands exist in the data_layer. Google tags (including GTM-K44FPW9) initialize and transmit data independently of the CMP state.
  • ⚠️ No signals in storage + stable profile — localStorage and sessionStorage remain empty. The cookie jar timeline is identical across all stages (before_navigation = 0, no retroactive clearing). The Library's ad server ads.biblioteka.lodz.pl is active (standard infrastructure of the lodz.pl family).

Legal Context (Municipal Sports and Recreation Center in Łódź)

MOSiR executes public tasks within the scope of physical culture, sport, and recreation (Physical Culture Act of June 25, 2010). The page handles sports events, recreational facilities, membership passes, and communications with citizens — involving data of a less sensitive nature than MOPS, but remaining within a public administration framework combined with commercial monetization elements (advertisements, partnerships, service sales).

Layer A — controller's compliance culture. The cookie-box CMP (shared across the uml_portal family) was deployed, but was not integrated with Google's Consent Mode or GTM. A new GTM container GTM-K44FPW9 and a dedicated GA4 property G-9NTNY6Z0NB were appended while simultaneously preserving the shared G-30F084ZHSL asset linked to the Municipal Library — operating without transparent fulfillment of Art. 26 GDPR.

Layer B — market value of the behavioral profile. A sports and recreation domain generates structural interest data (events, venues, passes) — highly attractive for behavioral profiling and audience building within Google Ads / Meta. Routing scroll depth + page_view metrics to two parallel GA4 properties expands the signal value far outside the statutory public mandates of MOSiR.

Domain assessment summary – mosir.lodz.pl

CriterionAssessment
Launching trackers before consent🔴 Yes — two GA4 properties + UA + GTM running with gcd=13l3l3l2l1l1 and pscdl=noapi; scroll depth 90% transmitted
CMP Effectiveness⚠️ Present (TYPO3 cookie-box), but disconnected from Google Consent Mode or GTM
Data transmission to third parties🔴 Yes — shared G-30F084ZHSL (Library) + YouTube/Twitter widgets + ads.biblioteka.lodz.pl
Cross-controller identity🔴 Active deployment (G-30F084ZHSL + G-9NTNY6Z0NB + UA-25825547-40)
Facebook PixelRefusal default (Only the SDK loads, dropping no beacons)
Overall assessment🔴 Severe violation — multiple GA4 properties running without a consent signal + cross-controller deployment on a domain with commercial layers

Verdict: On mosir.lodz.pl, two parallel GA4 properties (G-30F084ZHSL and G-9NTNY6Z0NB) as well as legacy UA (UA-25825547-40) initialize with the configuration metrics gcd=13l3l3l2l1l1 + pscdl=noapi. The cookie-box CMP fails to convey consent signals. Advanced scroll depth events are tracked and dispatched before user interaction. Furthermore, cross-controller sharing occurs with the Municipal Library alongside the deployment of the Facebook SDK and YouTube/Twitter widgets. This establishes a violation of the principles of lawfulness and data minimization (Art. 5 and 6 GDPR) along with the joint controllership transparency mandates of Art. 26 GDPR. The Facebook Pixel is inactive, though the third-party tracking surface remains extensive.

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

No privacy policy / GDPR links present in the footer; MOSiR BIP: https://bip.mosir.lodz.pl/

📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://mosir.lodz.pl/

SCAN ID: 20260306_202001_8e86892d

Data Controller: Miejski Ośrodek Sportu i Rekreacji

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests10
Cookies10

Technical Conclusions (Scanner)

  • 🔴 Two GA4 properties running simultaneously without Consent Mode: G-30F084ZHSL (Library) + G-9NTNY6Z0NB with gcd=13l3l3l2l1l1 + npa=1 + pscdl=noapi
  • 🔴 Cross-controller identity sharing via G-30F084ZHSL + legacy UA container UA-25825547-40 + GTM container GTM-K44FPW9 on the MOSiR domain
  • ⚠️ Facebook SDK loaded (connect.facebook.net), but without an active Pixel (missing fbevents.js, _fbp, and signals/config)
  • - YouTube widget + Twitter widgets + UMŁ livebar (lodz.pl/livebar/) → third-party cookies from YouTube/Twitter
  • - cookie-box.js CMP (TYPO3) present; ads.biblioteka.lodz.pl/asyncjs.php active; cookie timeline stable, local/sessionStorage empty
  • - Scroll depth 90% transmitted to G-9NTNY6Z0NB (scroll event with epn.percent_scrolled=90)

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
G-30F084ZHSL G-9NTNY6Z0NB UA-25825547-40 GTM-K44FPW9
Policy Assessment: Lack of transparent joint controllership (Art. 26 GDPR) regarding the use of shared property G-30F084ZHSL (Municipal Library) on the MOSiR domain. Legacy UA + new GTM GTM-K44FPW9 operate without integration with the TYPO3 cookie-box. A sports and recreation domain featuring commercial and event elements — resulting in a higher exposure to third-party tracking than purely informational sites.
📄 Show Domain Assessment

Conclusions and Violations

  • 🔴 Dual GA4 without Consent Mode — concurrently pinged: tid=G-30F084ZHSL (Municipal Library) and tid=G-9NTNY6Z0NB (presumably dedicated to MOSiR). Both carry identical metrics parameters: gcd=13l3l3l2l1l1, npa=1, pscdl=noapi, and dma=1. The cookie-box CMP fails to integrate with Google's Consent API.
  • 🔴 Cross-controller + legacy UA — GA4 property G-30F084ZHSL (owner: Municipal Library) is active on mosir.lodz.pl alongside legacy UA-25825547-40 and GTM container GTM-K44FPW9. The client identifier cid=2028970183.1772824802 is shared across the entire ecosystem.
  • 🔴 Advanced events tracked without consent — a scroll event with parameter ep.percent_scrolled=90 was recorded and routed to G-9NTNY6Z0NB (via region1.google-analytics.com/g/collect). Scroll depth tracking operates prior to any interaction with the CMP banner.
  • ⚠️ Facebook SDK without the Pixelconnect.facebook.net/pl_PL/sdk.js loaded (two instances). However, Pixel beacons, the _fbp cookie, and signals/config requests are absent. The SDK is present but inactive tracking-wise in this measurement.
  • ⚠️ Third-party widgets on a sports and recreation domain — YouTube player_api + widgetapi, Twitter widgets.js + iframe, and the UMŁ livebar widget (lodz.pl/livebar/) are embedded. These components drop VISITOR_INFO1_LIVE, YSC, __Secure-YNID, and __Secure-ROLLOUT_TOKEN cookies without first-party control.
  • ⚠️ CMP present but ineffective against Google — script path resolves to /typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js. No consent commands exist in the data_layer. Google tags (including GTM-K44FPW9) initialize and transmit data independently of the CMP state.
  • ⚠️ No signals in storage + stable profile — localStorage and sessionStorage remain empty. The cookie jar timeline is identical across all stages (before_navigation = 0, no retroactive clearing). The Library's ad server ads.biblioteka.lodz.pl is active (standard infrastructure of the lodz.pl family).

Legal Context (Municipal Sports and Recreation Center in Łódź)

MOSiR executes public tasks within the scope of physical culture, sport, and recreation (Physical Culture Act of June 25, 2010). The page handles sports events, recreational facilities, membership passes, and communications with citizens — involving data of a less sensitive nature than MOPS, but remaining within a public administration framework combined with commercial monetization elements (advertisements, partnerships, service sales).

Layer A — controller's compliance culture. The cookie-box CMP (shared across the uml_portal family) was deployed, but was not integrated with Google's Consent Mode or GTM. A new GTM container GTM-K44FPW9 and a dedicated GA4 property G-9NTNY6Z0NB were appended while simultaneously preserving the shared G-30F084ZHSL asset linked to the Municipal Library — operating without transparent fulfillment of Art. 26 GDPR.

Layer B — market value of the behavioral profile. A sports and recreation domain generates structural interest data (events, venues, passes) — highly attractive for behavioral profiling and audience building within Google Ads / Meta. Routing scroll depth + page_view metrics to two parallel GA4 properties expands the signal value far outside the statutory public mandates of MOSiR.

Domain assessment summary – mosir.lodz.pl

CriterionAssessment
Launching trackers before consent🔴 Yes — two GA4 properties + UA + GTM running with gcd=13l3l3l2l1l1 and pscdl=noapi; scroll depth 90% transmitted
CMP Effectiveness⚠️ Present (TYPO3 cookie-box), but disconnected from Google Consent Mode or GTM
Data transmission to third parties🔴 Yes — shared G-30F084ZHSL (Library) + YouTube/Twitter widgets + ads.biblioteka.lodz.pl
Cross-controller identity🔴 Active deployment (G-30F084ZHSL + G-9NTNY6Z0NB + UA-25825547-40)
Facebook Pixel✅ Inactive (SDK loads but drops no beacons)
Overall assessment🔴 Severe violation — multiple GA4 properties running without a consent signal + cross-controller deployment on a domain with commercial layers

Verdict: On mosir.lodz.pl, two parallel GA4 properties (G-30F084ZHSL and G-9NTNY6Z0NB) as well as legacy UA (UA-25825547-40) initialize with the configuration metrics gcd=13l3l3l2l1l1 + pscdl=noapi. The cookie-box CMP fails to convey consent signals. Advanced scroll depth events are tracked and dispatched before user interaction. Furthermore, cross-controller sharing occurs with the Municipal Library alongside the deployment of the Facebook SDK and YouTube/Twitter widgets. This establishes a violation of the principles of lawfulness and data minimization (Art. 5 and 6 GDPR) along with the joint controllership transparency mandates of Art. 26 GDPR. The Facebook Pixel is inactive, though the third-party tracking surface remains extensive.

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

No privacy policy / GDPR links present in the footer; MOSiR BIP: https://bip.mosir.lodz.pl/

📁 Show Hard Evidence (HAR, Cookies, Trace)
MEDIUM

https://atlasarena.pl/ ŁOT Group

SCAN ID: 20260307_072753_5e64d738

Data Controller: MAKiS sp. z o.o. (100% City owned)

Hosting/IT: IONOS-AS This is the joint network for IONOS, Fasthosts, Arsys, 1&1 Mail and Media and 1&1 Telecom. Formerly known as 1&1 Internet SE., DE

Requests4
Cookies2

Technical Conclusions

  • 🟢 Cookiebot CMP works correctly – no mass initialization of tracking tags was observed before the user's decision.
  • 🟡 PixelYourSite plugin present – requires verification of its integration with Cookiebot.
  • - After the session, potentially tracking cookies exist (2 pcs.).

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
G-RJ3LFRYX2R FB:1380002969841302
Privacy Policy Assessment: The privacy policy correctly declares the use of the identified tracking tools. No explicit concealment was found.
📄 Show Domain Assessment

Audit Summary: atlasarena.pl

Latest scan: 20260307_072753_5e64d738

Conclusions and Violations

  • 🟢 Cookiebot CMP works correctly – no mass initialization of tracking tags was observed before the user's decision.
  • 🟡 PixelYourSite (Free) plugin present – requires verification of its integration with Cookiebot.
  • 🟡 After the session, a first-party tracking cookie gaVisitorUuid remains (valid for 2 years).

Overall Assessment: The website performs significantly better than most of the analyzed municipal domains. The Cookiebot CMP most likely effectively delays/blocks trackers until consent is given.

Data Flow (Identified Recipients)

  • Google – reCAPTCHA, Google Analytics (G-RJ3LFRYX2R)
  • Meta (Facebook) – Facebook Pixel (FB:1380002969841302)
  • Others – an.gr-wcon.com, gr-cdn.com, Weglot, Userway

CMP Detection

Wykryto Cookiebot – it appears well-integrated and effective at blocking/delaying tags before the user's decision.

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

Cookiebot implemented correctly, but missing privacy links in the footer/page. The contact form includes a text stating that the privacy policy and information obligation can be found on the Makis.pl website.

https://atlasarena.pl/ Archived: 2026-03-05 21:01
🔍 View Snapshot
📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://lodz.pl/ ŁOT Group

SCAN ID: 20260306_201450_b6d79db5

Data Controller: Biblioteka Miejska w Łodzi

Hosting/IT: Hetzner

lodz.pl is a commercial publishing portal with a fully monetized Google advertising stack.

Requests30
Cookies13

Technical Conclusions (Scanner)

  • 🔴 Full Google monetization stack: AdSense (ca-pub-6662457014686579), three Google Ads Conversion IDs (AW-790142032, AW-10940984035, AW-10886899517) — conversion pings to googleadservices.com and googleads.g.doubleclick.net. All before user decision.
  • 🔴 Facebook Pixel active (ID 528537619394728) — fbevents.js, config load, cookie _fbp (90 days). Plus 6 iframe Facebook Like buttons for articles.
  • 🔴 Two GA4 properties with the same cid=30299385: G-30F084ZHSL (Municipal Library) + G-K51BYYXXYF (own lodz.pl) + DoubleClick. Additionally, Google Tag container GT-5DH5KDR (server-side).
  • ⚠️ Google Funding Choices CMP (dedicated solution for AdSense publishers) implemented, cookie FCCDCF set, iframe __tcfapiLocator (IAB TCF v2) present. Despite this, pscdl=noapi in GA pings — Consent Mode is not integrated with the CMP layer.
  • - 13 cookies remain stable throughout the entire measurement cycle. New elements compared to the municipal domain family: _gcl_au (Google Conversion Linker), _fbp (Facebook Pixel), FCCDCF (FC decision), OAID on ads.biblioteka.lodz.pl (Revive Advertiser ID, 3 years).

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
UA-25825547-40 G-30F084ZHSL G-K51BYYXXYF GT-5DH5KDR AdSense: ca-pub-6662457014686579 AW-790142032 AW-10940984035 AW-10886899517 FB Pixel: 528537619394728
Policy Assessment: The root domain is a commercial publishing portal using Google AdSense monetization — featuring a full performance marketing stack (3× Google Ads conversion tracking, Facebook Pixel, Revive Adserver). Deployed Google Funding Choices (CMP for AdSense publishers) and TCF v2 fail to integrate with Consent Mode (pscdl=noapi). The entire stack fires prior to user decision.
📄 Show Domain Assessment

Conclusions and Violations

  • 🔴 Publishing portal with full Google advertising monetization — unique within the domain family. Google AdSense as publisher (ca-pub-6662457014686579, script pagead2.googlesyndication.com/pagead/js/adsbygoogle.js), three different Google Ads Conversion IDs (AW-790142032, AW-10940984035, AW-10886899517) with active pings to www.google.com/ccm/collect, googleadservices.com/pagead/conversion/10940984035/, and googleads.g.doubleclick.net/pagead/viewthroughconversion/10940984035/. All identifiers transmit en=conversion/en=page_view events before user decision. Cookie _gcl_au (Google Conversion Linker) is set.
  • 🔴 Facebook Pixel active (not just the SDK). ID 528537619394728, loaded via connect.facebook.net/signals/config/528537619394728 + fbevents.js. Cookie _fbp=fb.1.1772824492321.199835837329971849 set (90 days). Additionally, 6 iframe Facebook Like buttons are deployed for individual articles — each generating a request to Facebook with the article URL as referrer, exposing precisely which articles the user has on their screen.
  • 🔴 Two GA4 properties with the same cid + server-side Google Tag. GA4 ping G-30F084ZHSL (Municipal Library, consistent across the domain family) + G-K51BYYXXYF (own lodz.pl) + shared UA UA-25825547-40, all using cid=30299385.1772824492. DoubleClick receives pings for both GA4 properties. Additionally, the new Google Tag container GT-5DH5KDR is active — the GT- prefix marks a newer generation of Google Tag containers (server-side data collection).
  • 🔴 Google Funding Choices CMP present but ineffective. lodz.pl deployed a dedicated CMP solution for AdSense publishers (fundingchoicesmessages.google.com/i/ca-pub-6662457014686579). Cookie FCCDCF contains the CMP choice. The __tcfapiLocator iframe confirms support for IAB TCF v2. Despite this, the pscdl=noapi parameter across all GA pings signifies "no Consent API integration" — Google Consent Mode does not receive consent signals from Funding Choices. Three compliance layers (FC + TCF v2 + Consent Mode) are implemented in parallel but remain technically decoupled.
  • 🔴 The Library's Revive Adserver utilizing a persistent Advertiser ID. The OAID (OpenX Advertiser ID) cookie on ads.biblioteka.lodz.pl is set for 3 years (until 2027-11). Unlike other analyzed domains where only the asyncjs.php script was loaded, here Revive sets its own persistent identifying cookie, pinning the user inside the Library's ad server ecosystem.
  • ⚠️ Facebook Like button iframes expose the specific articles visited by the user. In iframes.json, 6 embedded "Like" iframes are present, each with a href parameter pointing to a concrete article on lodz.pl (including pieces on Widzew Łódź, the POW renovation, historic clubs, and life-saving boxes). Each of these iframes transmits information to Facebook detailing exactly what content resides within the user's viewport — even if the user never clicks "Like". A standard flaw of embedding native Facebook Like plugins.
  • ⚠️ Consent Mode is "consent not set": gcd=13l3l3l2l1l1, npa=1, dma=1. The behavioral signal feeds Google's audience models despite the non-personalized flag — the canonical pattern of this domain family, with the distinct delta that conversion signals from three Google Ads campaigns and Pixel signals are added on top here.
  • ⚠️ UMŁ newsletter iframe + Twitter widget embedded. newsletter.uml.lodz.pl/site2/.../webforms_id=E (newsletter signups for the City Hall) and a Twitter iframe with origin=lodz.pl are embedded.

Assessment summary – lodz.pl

CriterionAssessment
Launching trackers before consent🔴 Severe violation
Google AdSense (publisher)🔴 Advertising monetization
Google Ads Conversion Tracking🔴 Three distinct campaigns
Facebook Pixel🔴 Active + Like button iframes
Effectiveness of CMP (Google Funding Choices + TCF v2)🔴 Deployed, ineffective (pscdl=noapi)
Two GA4 properties + server-side Google Tag🔴 Same cid routed to two separate properties
Revive Adserver with persistent OAID🔴 3 years
Overall assessment🔴 Very poor — commercial advertising stack operating without effective consent

Verdict: The root domain of the Łódź ecosystem operates as a commercial publishing portal with a fully monetized Google advertising stack (AdSense, three Google Ads conversion tracking IDs, server-side Google Tag, two GA4 properties + DoubleClick) and an active Facebook Pixel. Three compliance layers were deployed (Google Funding Choices, IAB TCF v2, Consent Mode), yet they are not integrated with each other — the pscdl=noapi parameter across all GA pings confirms that Consent Mode fails to receive consent signals from FC/TCF. The Library's Revive Adserver sets a persistent Advertiser ID valid for 3 years. Facebook Like button iframes expose the titles of specific articles present within the user's viewport. The domain requires an independent ownership verification: who owns the AdSense account ca-pub-6662457014686579, who operates the three Google Ads campaigns, and who controls GA4 property G-K51BYYXXYF and Facebook Pixel 528537619394728 — as these metrics isolate the actual boundaries of liability for the controller/joint controllers.

🔬 Extended Analysis: Methodology Rentgen vs Scanner

Methodological Note: Our automated Scanner focuses on mapping out advertising, analytical, and tracking infrastructure. In parallel, "Rentgen" was applied (a browser plugin created by the Internet. Czas działać! foundation). Rentgen relies on the methodology of privacy activists, for whom any external server connection made without explicit consent is treated as a potential data exposure. The following breakdown offers a unique fusion of both analytical horizons.

Evidentiary Consistency

  1. Timeline alignment: Raw data documenting the loading logic aligns perfectly with network logs. Tracking pack initialization occurs fractions of a second after the DOM loads, uniquely demonstrating early script execution prior to user decision.
  2. Confirmation of early tracking: Rentgen confirms early execution of tracking scripts alongside multiple connections to external endpoints (Google, Meta, Twitter/X). This anchors the thesis regarding the lack of effective tracker blocking before interaction.
  3. Subdomain visibility deltas: The Scanner maps tracking-specific domains. Rentgen logs a wider radius of external handshakes (including fonts, generic CDNs, etc.). From a GDPR activist standpoint, any such connection executed without consent can be interpreted as a potential data leak.

Deeper analysis of data flows:

  • Expansive Advertising Infrastructure (Google Ads): Requests with triple remarketing identifiers were recorded (tids=AW-557285855~AW-11108391222~AW-665139254) alongside AdSense integration (client=ca-pub-6662457014686579). This reflects explicit monetization of municipal portal traffic.
  • Active Meta Pixel: Capture of a payload carrying a PageView event (Pixel ID: 528537619394728). The Pixel initializes instantly and routes metrics straight to Meta's servers.
  • EU Geolocation Detection: Google Analytics logs the user as residing within the GDPR jurisdiction (_eu=EAAAAGA).
  • Cross-domain Referrer Leak: Embedded widgets (including the newsletter) pass sub-paths and source data out to external services.
  • Twitter Session Tracking: Embedded elements generate a session_id passed back to syndication.twitter.com before any intentional user action occurs.
📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

The privacy policy is available at lodz.pl/polityka-prywatnosci/ — the link is visible in the service contact menu and within the consent banner when options are expanded. Note: The policy does not contain an effective date or a last updated date — preventing verification of its validity period and change log history.

https://lodz.pl/ Archived: 2026-03-05 21:01
🔍 View Snapshot
https://lodz.pl/polityka-prywatnosci/ Privacy Policy — Data Controller: Biblioteka Miejska w Łodzi · missing effective date
🔍 View Snapshot
📁 Show Hard Evidence (HAR, Cookies, Trace)
POSITIVE

https://kartaturysty.lodz.travel/ ŁOT Group

SCAN ID: 20260306_201815_708851ac

Data Controller: Łódzka Organizacja Turystyczna (ŁOT)

Hosting/IT: Autonomous System for Dataspace P.S.A., PL

Requests0
Cookies1

Technical Conclusions

  • Zero behavioral tracking in the front-end layer. No Google Analytics, no GTM, no Facebook, no YouTube, no DoubleClick, no Library ad server, no Twitter. data_layer.json is empty.
  • Cookies are not set before the user's decision. Throughout the entire measurement cycle, only JSESSIONID is present — an application session cookie, not a tracker.

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
None — the website does not conduct behavioral analytics
Policy Assessment: The Karta Turysty front-end is the cleanest across the entire analyzed family of domains in the Łódź ecosystem — no Google Analytics, no GTM, no third-party trackers. The only external signal is remote Google Fonts, the solution to which is local hosting. The layer of actual data processing for registered card users is outside this measurement — it concerns the PPP consortium's back-end.
📄 Show Domain Assessment

Conclusions and Violations

  • Zero behavioral tracking in the front-end layer.
    The following do not occur in `scripts_dom.json`: Google Tag Manager, Google Analytics (analytics.js, gtag/js), Facebook SDK, Facebook Pixel, YouTube API, Twitter widgets, DoubleClick, ads.biblioteka.lodz.pl ad server, TYPO3 cookiebox, Klaro, or the lodz.pl/livebar widget. data_layer.json is empty — completely missing any GTM measurement layer. Unlike kartalodzianina.pl (which utilizes Consent Mode v2 with cookieless pings), Karta Turysty does not conduct Google analytics at all.
  • Cookies are not set before the user's decision.
    The measurement timeline (before_navigationafter_domcontentloadedafter_loadafter_async_window) indicates the presence of only JSESSIONID throughout the entire session lifecycle — session-only (expires=-1), on the kartaturysty.lodz.travel host, functioning as a technically necessary application session cookie. Zero trackers.
  • ⚠️ Google Fonts loaded remotely — the only concrete GDPR issue.
    The page fetches two font families (Montserrat, Poppins) from fonts.googleapis.com/css2 (stylesheet) and corresponding WOFF2 files from fonts.gstatic.com. Each of these requests transmits the user's IP address and HTTP headers to Google servers in the USA, without obtaining consent and without a legal basis specified in the privacy policy.

    The ruling of the German Landgericht München I of 20 January 2022, case ref. 3 O 17493/20 deemed remote loading of Google Fonts a violation of Art. 6(1) GDPR — the IP address is personal data within the meaning of the CJEU Breyer judgment (C-582/14), and its transmission to Google lacks a basis in user consent, contract, or legitimate interest. Standard technical solution: hosting fonts locally on the operator's server (self-hosted webfonts). The LG München ruling is not binding for Polish courts but is widely cited in data protection doctrine across the EEA.
  • ⚠️ External scripts from public CDNs without an integrity signature (SRI).
    The page loads: cdnjs.cloudflare.com/ajax/libs/limonte-sweetalert2/10.10.0/sweetalert2.min.js and unpkg.com/leaflet@1.9.1/dist/leaflet.js. These are popular front-end libraries, but loaded without the integrity attribute — presenting a supply chain risk. This is not a GDPR violation, but rather a signal concerning application security hygiene.
  • ⚠️ The JSESSIONID cookie reveals architectural details and points to a shared platform with kartalodzianina.pl.
    The cookie value contains the .ktlodz_zeus suffix, which identifies the backend application server instance. The naming convention is analogous to kartalodzianina.pl, where the JSESSIONID had the suffix .lodz_atena. Both sites use the same technological stack (Java EE application server), the same assets structure (assets/n/, cmsJS/, assets/visit/), identical versions of external libraries, and the same custom cookiebar (jquery.cookiebar.js) — representing two instances of a single platform handling the city's different card products.

Scope of this measurement — what is visible and what is not

The measurement covered the kartaturysty.lodz.travel landing page without interaction — without logging in, without registration, and without utilizing card features. All conclusions above apply exclusively to the front-end layer visible to an anonymous visitor.

Outside the scope of this measurement remain:

  • The data layer of registered card users (personal data of tourists, attraction usage history)
  • Integrations with tourist attractions, hotels, and other card service partners
  • The legal model of the PPP concession agreement and data processing clauses
  • The record of processing activities of the consortium operating the city's card products
  • The behavior of the service after logging in and using card features (what happens in the authorized layer)

Verdict: The kartaturysty.lodz.travel front-end is the cleanest in terms of tracking out of all the analyzed domains in the Łódź ecosystem — completely free of Google Analytics, GTM, Facebook, YouTube, Twitter, DoubleClick, and the Library ad server. Cookies in the front-end layer are restricted exclusively to the application session. The only concrete problem: Google Fonts are loaded remotely, which in light of the German LG München I ruling of 20 January 2022 (case ref. 3 O 17493/20) constitutes a GDPR violation. Technical solution: hosting fonts locally. Karta Turysty shares its technical platform with Karta Łodzianina (consistent backend instance naming convention — .ktlodz_zeus alongside .lodz_atena) — both cards are powered by the same infrastructure but possess distinctly different levels of front-end analytics deployment. The backend layer of registered user data processing and the legal model of the PPP concession agreement remain outside the scope of this measurement.

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

PDF in the footer; the cookie banner mentions ŁOT as the data controller

📁 Show Hard Evidence (HAR, Cookies, Trace)
MEDIUM

https://media.lodz.pl/ ŁOT Group

SCAN ID: 20260306_201723_e56edb54

Data Controller: Łódź Media Group / ŁOT

Hosting/IT: CF-GDA, PL

Requests0
Cookies1

Technical Conclusions (Scanner)

  • Zero third-party trackers. No Google Analytics, no GTM, no Facebook, no YouTube, no DoubleClick, no ads.biblioteka.lodz.pl. data_layer.json is empty, iframes.json is empty.
  • CookieYes CMP deployed and effective. Cookie cookieyes-consent stored with decision: consent:no, necessary:yes, all other categories (functional, analytics, performance, advertisement): no. No tracker cookies in the timeline.
  • ⚠️ Adobe Typekit (use.typekit.net, p.typekit.net) — 9 font requests loaded remotely. Analogous to the Google Fonts issue (LG München I judgment, 3 O 17493/20) — user IP transmitted to Adobe Systems without consent.
  • - Stack: WordPress 6.9.1, Cookie Law Info (Lite) plugin v3.4.0, Contact Form 7 v6.1.5, custom theme lodzmediagroup. All JS/CSS resources hosted locally on media.lodz.pl.
  • - Zero cross-controller identity sharing with the municipal domain family. Zero association with the measurement ecosystem of the Library (G-30F084ZHSL) or UMŁ (UA-25825547-40).

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
None — the website does not conduct behavioral analytics
Policy Assessment: Along with kartaturysty.lodz.travel, the frontend of media.lodz.pl (Łódź Media Group) has the cleanest tracking layer among the entire analyzed family of Łódź domains. CookieYes CMP functions correctly — user decision is propagated, no analytical/advertising cookies are dropped prior to consent. The only issue remains the remote loading of Adobe Typekit fonts. The layer of actual data processing on the ŁMG side (declared database of 174k emails, 170k phone numbers) falls outside the frontend measurement scope — it concerns the backend and CRM/newsletter systems of the operator.
📄 Show Domain Assessment

Conclusions and Violations

  • Zero third-party trackers in the frontend layer. The following do not occur in `scripts_dom.json`: Google Tag Manager, Google Analytics (analytics.js, gtag/js), Facebook SDK, Facebook Pixel, YouTube API, Twitter widgets, DoubleClick, ad server ads.biblioteka.lodz.pl, Klaro. data_layer.json is empty. iframes.json is empty. The page does not conduct behavioral analytics and does not embed any external social media widgets.
  • CookieYes CMP implemented correctly. The cookieyes-consent cookie stores the user choice in the following format: consent:no, necessary:yes, functional:no, analytics:no, performance:no, advertisement:no. The measurement timeline (before_navigation=0 → after_domcontentloaded=1 → after_load=1 → after_async_window=1) confirms that only the CMP decision cookie is present throughout the session lifecycle. No analytical, advertising, functional, or performance cookies are dropped before consent. Plugin: Cookie Law Info Lite v3.4.0 (wp-content/plugins/cookie-law-info).
  • ⚠️ Adobe Typekit — remote font loading. The site fetches fonts from use.typekit.net (7 font files with hashes af/134b52, af/22b56a, af/3756a3, af/783f34, af/87e50a, af/b02074, af/cc7dab) and CSS files (use.typekit.net/pqs4jjt.css, p.typekit.net/p.css). Adobe Typekit is a service provided by Adobe Systems Inc. (USA) — creating an identical legal issue to Google Fonts according to the LG München I judgment of January 20, 2022 (case ref. 3 O 17493/20): user IP address is transmitted to a provider based outside the EEA without a valid legal basis. Solution: self-hosted webfonts or utilizing open-source fonts available locally.
  • ⚠️ Technical stack (for administrator's information). WordPress 6.9.1, jQuery, Contact Form 7 plugin v6.1.5, custom theme lodzmediagroup. All JS/CSS scripts are hosted locally on media.lodz.pl. No local_storage or session_storage usage outside standard wpEmojiSettingsSupports.

Scope of this measurement — what is visible and what is not

The measurement covered the media.lodz.pl landing page without interaction. All conclusions apply exclusively to the frontend layer visible to an anonymous visitor.

Outside the scope of this measurement remain:

  • The data processing layer within the CRM/newsletter databases of Łódź Media Group — a publicly declared base of roughly 174k email addresses and 170k phone numbers coupled with ad targeting capabilities.
  • The legal basis for building and maintaining these databases — a question explicitly raised in the councillors' interpellation of May 22, 2026 (item 12).
  • Agreements between the City of Łódź, the Municipal Library, ŁMG, and ŁOT regarding the use of data from lodz.pl portal users and the łódź.pl application for advertising and marketing purposes.
  • Potential activity of analytics and profiling tools inside authenticated subpages of media.lodz.pl (if any exist).

Domain assessment summary – media.lodz.pl

CriterionAssessment
Launching trackers before consent✅ Compliant
Google Analytics / GTM✅ None
Facebook, YouTube, Twitter, DoubleClick✅ None
Library ad server✅ None
Cross-controller identity sharing with the municipal domain family✅ None
CMP Effectiveness (CookieYes)✅ Functional (decision propagated)
Adobe Typekit⚠️ Remote, IP transmission to Adobe (USA)
Backend layer (ŁMG CRM/newsletter databases)❓ Outside frontend measurement scope
Overall frontend layer assessment✅ Compliant, with one qualification (Adobe Typekit)

Verdict: The frontend of media.lodz.pl (Łódź Media Group) is surprisingly clean regarding tracking — alongside kartaturysty.lodz.travel, it stands as one of the two domains in the analyzed Łódź ecosystem featuring a correctly working CMP and zero data transmission to third parties before user consent. This can be explained in an obvious way. Only potential clients utilizing the Media Group and ŁOT offer access this page, eliminating the need for advanced tracking typical for external portals where client bases and remarketing paths are built. The CookieYes cookie records the user choice, and no analytical or advertising cookies are deployed. The sole qualification: remote loading of Adobe Typekit fonts — analogous to the Google Fonts issue (LG München I judgment, case ref. 3 O 17493/20), with a straightforward technical resolution (local hosting). Crucial addendum: the "compliant" rating applies strictly to the frontend layer of the landing page without interaction. The actual subject of investigation regarding Łódź Media Group — the CRM/newsletter databases publicly declared in the commercial offer of ŁMG (approx. 174k emails, 170k phone numbers, ad targeting) and agreements with the City/Library regarding data exploitation from the lodz.pl portal and the łódź.pl app — resides in the backend/CRM/documentary layer, outside the capabilities of a frontend audit. Item 12 of the councillors' interpellation of May 22, 2026, concerns precisely this area.

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

Both links in the footer

📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://biblioteka.lodz.pl/ ŁOT Group

SCAN ID: 20260306_201857_a94f04b6

Data Controller: Biblioteka Miejska w Łodzi

Hosting/IT: CF-KRK, PL

Requests11
Cookies6

Technical Conclusions

  • 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
  • 🔴 No visible CMP mechanism. There are no consent default or consent update commands in data_layer.json.
  • 🔴 Data was transmitted to Google Analytics and Facebook Pixel before consent was given.
  • - After the session, potentially tracking cookies exist (6 pcs.).

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
G-4XLLVG2B8P FB:357593604940620
Policy Assessment: The policy declares analytical and marketing tools, however, no consent management mechanism (CMP) was detected on the website. Google Analytics and Facebook Pixel tags were firing before user interaction.
📄 Show Domain Assessment

Audit Summary: biblioteka.lodz.pl

Latest scan: 20260306_201857_a94f04b6

Conclusions and Violations

  • 🔴 Tracking tags were firing immediately upon entering the site, before any user decision. Google Analytics cookies (_ga*, _gid) and Facebook cookies (_fbp) appeared.
  • 🔴 No visible CMP mechanism. There are no consent default or consent update commands in data_layer.json.
  • 🔴 Data was transmitted to Google Analytics and Facebook Pixel before consent was given.
  • ⚠️ Persistent tracking cookies remain after the session (_ga*, _fbp).

Overall Assessment: One of the worst analyzed websites. Lack of CMP + immediate firing of Google and Facebook tags.

Data Flow (Identified Recipients)

  • Google – Google Analytics 4 (G-4XLLVG2B8P, G-VTQKC3GTDX), Universal Analytics (UA-218462078-1)
  • Meta (Facebook) – Facebook Pixel (FB:357593604940620)
  • Userway – accessibility widget

CMP Detection

No consent management mechanism (CMP) was detected. The website does not block tags before the user's decision.

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

Cookie banner links to: https://biblioteka.lodz.pl/assets/policies/COOKIES.pdf — both are PDFs

📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://lodz.travel/ ŁOT Group

SCAN ID: 20260306_201751_fdf84108

Data Controller: Łódzka Organizacja Turystyczna (ŁOT)

Hosting/IT: Hetzner

lodz.travel is a commercial tourism portal with a fully monetized Google advertising stack.

Requests38
Cookies9

Technical Conclusions (Scanner)

  • 🔴 Full Google monetization stack: AdSense (ca-pub-6662457014686579), four Google Ads Conversion IDs (AW-790142032, AW-10940984035, AW-10886899517, AW-665139254) with active en=conversion pings to googleadservices.com, googleads.g.doubleclick.net, www.google.com/pagead/1p-conversion/, and www.google.pl/pagead/1p-conversion/. All before user decision.
  • 🔴 Facebook Pixel active (ID 710762686030917) — fbevents.js, config load. Different Pixel ID than on lodz.pl (where it was 528537619394728).
  • 🔴 Two GA4 properties with the same cid=1694443646: G-5TZ8847RTL (own lodz.travel) + G-30F084ZHSL (Municipal Library) + shared UA container UA-25825547-40 + DoubleClick. GTM container GTM-P5KSMXV.
  • 🔴 A conversion event defined in the data_layer: send_to: AW-10940984035/V02uCO6r29MDEOPViOEo — a specific Google Ads campaign label triggered immediately upon entering the page.
  • 🔴 Two CMPs deployed simultaneously: the TYPO3 cookiebox from the uml_portal package and Klaro from cookies.uml.lodz.pl. Neither of them blocks trackers. pscdl=noapi across all pings — Consent Mode is not integrated.
  • - 9 cookies remain stable throughout the cycle. _gcl_ls present in localStorage (Google Conversion Linker). The google_auto_fc_cmp_setting key in localStorage suggests active Google Funding Choices.

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
UA-25825547-40 G-30F084ZHSL G-5TZ8847RTL GTM-P5KSMXV AdSense: ca-pub-6662457014686579 AW-790142032 AW-10940984035 AW-10886899517 AW-665139254 FB Pixel: 710762686030917
Policy Assessment: Tourism portal featuring a full Google advertising monetization stack — AdSense, four Google Ads Conversion IDs, Facebook Pixel, two GA4 properties + DoubleClick + GTM. Two CMPs (TYPO3 cookiebox + Klaro) fail to integrate with Consent Mode (pscdl=noapi). The entire stack fires prior to user decision. The domain is managed by the Łódź Tourist Organization — using a separate FB Pixel account from lodz.pl, but sharing the exact same AdSense publisher ID and three out of four AW conversion IDs found on lodz.pl.
📄 Show Domain Assessment

Conclusions and Violations

  • 🔴 Tourism portal with a full Google advertising monetization stack. AdSense (ca-pub-6662457014686579) — the exact same publisher property utilized on lodz.pl. Four Google Ads Conversion IDs execute active pings: AW-790142032, AW-10940984035, AW-10886899517, and AW-665139254. Target endpoints: www.google.com/ccm/collect, www.googleadservices.com/pagead/conversion/[ID]/, googleads.g.doubleclick.net/pagead/viewthroughconversion/[ID]/, www.google.com/pagead/1p-conversion/[ID]/, and www.google.pl/pagead/1p-conversion/[ID]/. A conversion event anchored to specific label AW-10940984035/V02uCO6r29MDEOPViOEo triggers immediately upon page entry.
  • 🔴 Facebook Pixel active with ID 710762686030917. Loads configuration details via connect.facebook.net/signals/config/710762686030917 + fbevents.js. This represents a distinct Pixel from lodz.pl (528537619394728) — indicating that lodz.travel operates its own independent Meta advertising account, separate from lodz.pl.
  • 🔴 Two GA4 properties sharing the identical cid + shared UA + DoubleClick + GTM. Pings routed to region1.analytics.google.com/g/collect connect both property G-5TZ8847RTL (dedicated to lodz.travel) and property G-30F084ZHSL (Municipal Library), both binding to client ID 1694443646.1772824674. DoubleClick stats.g.doubleclick.net/g/collect processes pings for both properties. Shared UA container UA-25825547-40 is active. GTM container resolves to GTM-P5KSMXV.
  • 🔴 Two CMPs deployed in parallel — neither exerts any blocking effect. The custom TYPO3 cookiebox from the uml_portal package (typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js) and Klaro from the central infrastructure cookies.uml.lodz.pl (klaro.js, embed.js, and its configuration file) both load successfully, yet all Google and Meta tags fire prior to any user interaction. The presence of pscdl=noapi across all GA and Ads pings proves that Consent Mode receives no input from either CMP layer. Additionally, localStorage logs google_auto_fc_cmp_setting=[1] — confirming active Google Funding Choices for AdSense.
  • 🔴 AdSense iframe embedded within the DOM. Analysis of iframes.json reveals the presence of aswift_0 — an AdSense advertising iframe carrying a full array of contextual parameters (resolution, viewport dimensions, user-agent hints, correlator tokens). The portal serves Google ads as a publisher.
  • 🔴 The Library's ad server + lodz.pl livebar are embedded. The script ads.biblioteka.lodz.pl/www/delivery/asyncjs.php is loaded. The lodz.pl/livebar/ iframe (the Municipal Library information widget) is present.
  • ⚠️ Consent Mode is "consent not set": gcd=13l3l3l2l1l1, npa=1, dma=1, pscdl=noapi. The tracking payload feeds Google's audience modeling layers despite the non-personalized flag. This matching configuration follows the exact blueprint of the uml_portal family.
  • ⚠️ Twitter widgets + YouTube API. Scripts platform.twitter.com/widgets.js loads an iframe with an origin on lodz.travel. The YouTube integrations include widgetapi.js + player_api, setting YouTube cookies bound to partitionKey https://lodz.travel.
  • ⚠️ Cross-controller identity sharing. The exact same client identifier (cid) is pushed in parallel to a GA4 property owned by the Municipal Library (G-30F084ZHSL) and to the dedicated GA4 property of lodz.travel (G-5TZ8847RTL). The domain is managed by the Łódź Tourist Organization (under Art. 26 GDPR — operating without a public declaration of joint controllership).
  • ⚠️ Shared components with lodz.pl: Shares the exact same AdSense publisher ID (ca-pub-6662457014686579) and three out of four Google Ads Conversion IDs (AW-790142032, AW-10940984035, AW-10886899517). Exclusively deployed on lodz.travel: conversion tracker AW-665139254, dedicated GA4 property G-5TZ8847RTL, and a unique Facebook Pixel ID 710762686030917.

Assessment summary – lodz.travel

CriterionAssessment
Launching trackers before consent🔴 Severe violation
Google AdSense (publisher)🔴 Active (identical publisher ID to lodz.pl)
Google Ads Conversion Tracking🔴 Four active tracking campaigns executing pings
Facebook Pixel🔴 Active (dedicated ID, independent of lodz.pl)
Effectiveness of CMPs (TYPO3 cookiebox + Klaro + FC)🔴 Three distinct layers, none are functional (pscdl=noapi)
Two GA4 properties with matching cid🔴 Cross-controller identity sharing
The Library's ad server🔴 ads.biblioteka.lodz.pl successfully loaded
Overall assessment🔴 Very poor — commercial tourism portal with active advertising monetization

Verdict: The tourist portal lodz.travel (managed by the Łódź Tourist Organization) deploys a complete Google advertising monetization stack that fires prior to any user choice: AdSense (sharing the identical publisher property ca-pub-6662457014686579 found on lodz.pl), four Google Ads Conversion IDs (three shared with lodz.pl plus a dedicated tracker AW-665139254), a dedicated GA4 property G-5TZ8847RTL alongside the Library's property G-30F084ZHSL sharing the same client identifier (cid), a dedicated Facebook Pixel 710762686030917, and GTM container GTM-P5KSMXV. Three compliance layers (the TYPO3 cookiebox, Klaro, and Google Funding Choices) are running in parallel but remain technically decoupled from the Google Consent Mode layer, as evidenced by the pscdl=noapi parameter present across all tracking requests. An AdSense marketing iframe is parsed into the DOM immediately upon first entry. Despite the independent legal personality of the Tourist Organization relative to the Municipal Library, the two portals share an interconnected technical tracking infrastructure (AdSense and three conversion IDs) without a public joint controllership declaration under Art. 26 GDPR.

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

Privacy policy present in the last data chunk; missing a separate dedicated GDPR information clause

https://lodz.travel/ Archived: 2026-03-05 21:01
🔍 View Snapshot
📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://cuw.uml.lodz.pl/

SCAN ID: 20260306_201639_2d114b5e

Data Controller: Centrum Usług Wspólnych w Łodzi

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests6
Cookies8

Technical Conclusions

  • 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
  • 🔴 A custom CMP was detected (TYPO3 cookiebox from the uml_portal package), which does not block the loading of trackers before the user's decision — a deceptive mechanism.
  • 🔴 Data transmitted to Google (GA4 G-30F084ZHSL + DoubleClick) before any decision. Facebook SDK, YouTube player_api, a Twitter iframe, and the Municipal Library ad server script (ads.biblioteka.lodz.pl) were also loaded.
  • ⚠️ GA cookies set on the apex domain .uml.lodz.pl — analytical identity shared with uml.lodz.pl and bip.uml.lodz.pl (details in expanded view).
  • 🔴 Google Consent Mode: the gcd=13l3l3l2l1l1 parameter in all /g/collect calls indicates a lack of an integrated consent signal. The npa=1 flag forces non-personalized ads, but cid, sid, and page_view are transmitted nevertheless — the signal fueling Google's audience models is sent regardless.
  • - After the session, 8 tracking cookies remain (4× GA, 4× YouTube). No Facebook Pixel, no second Analytics container.

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
UA-25825547-40 G-30F084ZHSL
Policy Assessment: Active cross-subdomain tracking (shared .uml.lodz.pl scope with uml.lodz.pl and bip.uml.lodz.pl) without a declaration of joint controllership (Art. 26 GDPR). An entity handling debt collection and European fund settlements itself lacking basic cookie hygiene — a matter of compliance culture for a controller accessing sensitive financial data.
📄 Show Domain Assessment

Conclusions and Violations

  • 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
    After the after_domcontentloaded stage, Google Analytics cookies (_ga, _ga_30F084ZHSL, _gid, _gat_gtag_UA_25825547_40) and YouTube cookies were automatically set. The following scripts were loaded: google-analytics.com/analytics.js, googletagmanager.com/gtag/js (G-30F084ZHSL + UA-25825547-40), connect.facebook.net/sdk.js, youtube.com/player_api, platform.twitter.com/widgets.js, ads.biblioteka.lodz.pl/www/delivery/asyncjs.php.
  • 🔴 A custom consent management mechanism (CMP) was implemented, which does not block trackers before the user's decision.
    A custom CMP is present on the page: typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js. The mechanism loads, but does not provide an effective opt-in — tracking scripts launch without blocking. There are no consent default or consent update commands in data_layer.json. Unlike css.samorzad.lodz.pl, Klaro from the central central infrastructure cookies.uml.lodz.pl has not been deployed here.
  • 🔴 Data was transmitted to third parties before consent was given.
    Confirmed requests:
    • Google Analytics 4 (G-30F084ZHSL, belonging to the Municipal Library) → region1.analytics.google.com/g/collect (page_view, cid=86646066)
    • Universal Analytics (UA-25825547-40) — cookie _gat_gtag_UA_25825547_40 set (throttle token after ping)
    • DoubleClick → stats.g.doubleclick.net/g/collect (same cid)
    • Facebook SDK (without Pixel — no fbevents.js, no _fbp cookie)
    • YouTube (player_api + widgetapi)
    • Twitter widgets (iframe with origin=cuw.uml.lodz.pl)
    ads.biblioteka.lodz.pl — Municipal Library Revive Adserver (separate data controller)
    Unlike domains from the lodz.pl family, the lodz.pl/livebar widget was not detected on CUW.
  • 🔴 Cross-subdomain scope cookies GA — the strongest vector of this domain.
    The cookies _ga, _ga_30F084ZHSL, _gid, and _gat_gtag_UA_25825547_40 are set on the apex domain .uml.lodz.pl, rather than .cuw.uml.lodz.pl. This means that CUW shares its analytical identity with the main city portal (uml.lodz.pl) and the office's Public Information Bulletin (bip.uml.lodz.pl) — the measurement identifies the same user across three formally separate services of different data controllers. The cookie_domain: auto configuration in gtag results in a shared measurement namespace for the entire *.uml.lodz.pl family.
  • ⚠️ YouTube cookies are partitioned (CHIPS), but with an anomaly.
    They contain "partitionKey": "https://uml.lodz.pl" (not cuw.uml.lodz.pl) and "_crHasCrossSiteAncestor": true. A recurring feature of measurements across the *.uml.lodz.pl subdomains.
  • ⚠️ Consent Mode parameters indicate a lack of an integrated consent signal.
    The parameters visible in requests are: gcd=13l3l3l2l1l1, npa=1, dma=1, dma_cps=a. The configuration indicates "consent not set" while simultaneously forcing non-personalized ads — despite this, the client ID (cid), session ID (sid), and page_view event are transmitted. The npa=1 flag limits personalized displays, but does not turn off the provisioning of Google's audience models — the behavioral signal enters the system regardless.

Legal and Market Context (Shared Services Center)

cuw.uml.lodz.pl is the website of the Shared Services Center (Centrum Usług Wspólnych) in Łódź — a budgetary unit established by resolution of the City Council on 30 March 2016, executing centralized administrative, HR-payroll, accounting, and financial services for municipal units: the Board of Roads and Transport, the Municipal Investment Center, the Municipal Greenery Board, the Municipal Urban Planning Studio, and the Animal Shelter. Within its scope of duties: conducting commissioned debt collection tasks for municipal receivables and settling projects co-financed by European funds (the Department for Project Settlements was transferred in 2018 from the UMŁ Revitalization Bureau).

Layer A — controller's compliance culture. CUW has access to the financial data of citizens subjected to municipal debt collection, as well as data of beneficiaries and partners in European fund settlements. An entity with such a mandate should represent an elevated standard of compliance hygiene across all its systems — including its own website. Actual implementation: a deceptive TYPO3 cookiebox, transmission of the client identifier to Google, DoubleClick, Facebook, and the Municipal Library ad server before any user decision. The argument here concerns not the protection of an individual visitor, but the consistency of practices of an institution entrusted with a mandate to manage sensitive financial data.

Layer B — market value of the behavioral profile. Behavioral data from the domain of a unit settling European funds represents valuable advertising inventory for sectors serving EU beneficiaries: consulting firms writing applications, law firms specializing in subsidy law, providers of project management software, banks offering bridge loans and factoring products, and audit firms. The transmission of cid to GA4 and DoubleClick feeds Google's audience building models, which are then bought by advertisers from these sectors. The npa=1 flag limits personalized display, but does not disable the use of the signal to build remarketing segments and lookalike audiences. The general EU Regulation No. 2021/1060 for the 2021-2027 perspective contains its own provisions on processing beneficiary data — exporting their behavioral profile to the Google advertising system without a legal basis goes beyond the processing purposes specified in grant agreements.

Separate circumstance: the cross-subdomain scope cookies on .uml.lodz.pl mean that the measurement identifies the same user across three formally distinct services of different data controllers — CUW, the main UMŁ portal, and the office's BIP. Joint data controllership within the meaning of Art. 26 GDPR exists without a public declaration between the units.

Assessment summary – cuw.uml.lodz.pl

CriterionAssessmentComment
Launching trackers before consent🔴 Severe violationConfirmed by cookies_timeline + payloads
Effectiveness of implemented CMP🔴 Low / deceptiveCustom TYPO3 cookie-box does not block tags (Klaro missing)
Data transmission to third parties🔴 YesGoogle (GA4 + UA + DoubleClick), Meta SDK, YouTube, Twitter, ads.biblioteka.lodz.pl
Consent Mode Parameters⚠️ Consent not set + npa=1Signal fuels audience models despite non-personalized flag
Cross-subdomain scope🔴 Yes — across the entire .uml.lodz.pl familyShared identity with uml.lodz.pl and bip.uml.lodz.pl
YouTube cookies⚠️ Partitioned (CHIPS)partitionKey https://uml.lodz.pl
Controller's compliance culture🔴 InconsistentDebt collection and EU settlements unit lacking cookie hygiene
Market value of the profile⚠️ EU consulting / banking sectorAudience segment valuable for advertisers serving beneficiaries
Overall assessment🔴 PoorFull tracking stack on the domain of an entity with a sensitive mandate

Verdict: A deceptive CMP (TYPO3 cookiebox) has been implemented on the cuw.uml.lodz.pl website, which does not block the loading of trackers before the user's decision. The exact same client identity (cid) is transmitted in parallel to a GA4 property belonging to the Municipal Library and to DoubleClick, while cross-subdomain scope cookies on .uml.lodz.pl identify the user across three formally separate services — CUW, UMŁ, and the office's BIP. The unit handles the collection of municipal receivables and settlements of European funds — a mandate requiring an elevated standard of compliance, which the deployed technical configuration fails to meet. The behavioral signal from the domain handling EU settlements represents valuable advertising inventory for the consulting and banking sectors serving beneficiaries of European funds — exported to the Google Ads system without a public legal basis and without a joint controllership declaration under Art. 26 GDPR.

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

Debt collection clauses separately: https://cuw.uml.lodz.pl/windykacja/klauzula-informacyjna-windykacja/

📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://kartalodzianina.pl/ ŁOT Group

SCAN ID: 20260306_201700_53607701

Data Controller: Łódzka Organizacja Turystyczna (ŁOT)

Hosting/IT: Autonomous System for Dataspace P.S.A., PL

Requests2
Cookies1

Technical Conclusions

  • Consent Mode v2 implemented correctly — ad_storage, analytics_storage, ad_user_data, ad_personalization are denied by default. This is the first analyzed domain in the Łódź ecosystem with a correct implementation.
  • Cookies are not set before the user's decision. Throughout the entire measurement cycle (before → dom → load → async), only JSESSIONID is present — an application session cookie, not a tracker.
  • No Facebook SDK/Pixel, no YouTube API, no Twitter widgets, no DoubleClick, no ads.biblioteka.lodz.pl ad server. A fundamentally simpler front-end configuration than municipal domains.
  • ⚠️ Consent Mode in advanced mode — despite being denied, two cookieless pings (page_view, scroll 90%) with session metadata are sent to region1.google-analytics.com/g/collect. Details in the expanded view.
  • ⚠️ GA4 property G-ZX3TE0H6N6 — dedicated to this service, outside the Municipal Library property family. The administrator of this property and the legal basis for data collection (even cookieless) must be specified in the consortium's record of processing activities.
  • - External scripts from public CDNs without an integrity signature (SRI): sweetalert2 from cdnjs, leaflet from unpkg. A front-end security hygiene signal, not a GDPR layer.

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
G-ZX3TE0H6N6
Policy Assessment: The front-end of Karta Łodzianina is technically better implemented than the pages of Łódź municipal entities — Consent Mode v2 works, cookies are not dispatched before consent, and there are no third-party trackers. The layer of actual processing of citizens' data (registration, card usage history, integrations with service partners) is outside this measurement — it concerns the consortium's back-end and requires an analysis of the PPP concession layer.
📄 Show Domain Assessment

Conclusions and Violations

  • Consent Mode v2 implemented correctly in the GTM layer.
    In data_layer.json, commands are present that are missing from all analyzed municipal entity domains:
    consent default with ad_storage: denied, ad_user_data: denied, ad_personalization: denied, analytics_storage: denied
    consent update maintaining the same state (the user did not click consent during the measurement)
    Cookies are not set before the user's decision. Throughout the entire measurement cycle (stages before_navigation, after_domcontentloaded, after_load, after_async_window), only JSESSIONID is present in the cookie jar — an application session cookie (session-only, expires=-1), not a tracker.
  • No third-party trackers on the front-end layer.
    The following do not occur in `scripts_dom.json`: Facebook SDK, Facebook Pixel (fbevents.js), YouTube API (player_api, widgetapi), Twitter widgets, DoubleClick, ads.biblioteka.lodz.pl ad server, TYPO3 cookiebox, Klaro from cookies.uml.lodz.pl, or the lodz.pl/livebar widget. A fundamentally simpler configuration than domains in the uml_portal and invest_in_lodz families. A custom cookiebar (assets/n/js/jquery.cookiebar.js) is present — an operator mechanism, not a deceptive packaged solution.
  • ⚠️ Consent Mode in advanced mode — cookieless pings to Google despite being denied.
    Two calls to region1.google-analytics.com/g/collect are confirmed in payloads.ndjson:
    en=page_view: tid=G-ZX3TE0H6N6, cid=1646069836.1772824623 (session-only, without a persistent cookie), gcs=G100, gcd=13p3p3p2p5l1, npa=1, pscdl=denied
    en=scroll with epn.percent_scrolled=90: analogous parameters, gcd=13q3q3q2q5l1
    Google Consent Mode v2 in advanced mode assumes that tags load despite the lack of consent, but send "cookieless pings" without a persistent identifier. However, the pings contain basic data: URL, page title (dt=Karta Łodzianina), screen resolution, browser and platform version (uafvl), language, event type, and scroll depth. The IP address is visible to Google from the transport layer. In light of the CJEU Breyer ruling (C-582/14), the IP address + user-agent constitute personal data. The legal interpretation of the advanced mode has been questioned by the CNIL (France) and the Belgian DPA — a doctrinal controversy, not an obvious violation.
  • ⚠️ GA4 property G-ZX3TE0H6N6 — dedicated, outside the Library property family.
    Unlike all analyzed municipal entity domains (which send data to G-30F084ZHSL belonging to the Municipal Library), Karta Łodzianina uses its own GA4 property. There is no cross-controller data flow with the Library or the uml_portal family. Open question: who is the controller of property G-ZX3TE0H6N6 — the PPP consortium as the operator, the City of Łódź as the concession grantor, or is it joint controllership? Behavioral data (even in the form of cookieless pings) reaches this property and is processed in Google Analytics by the entity administering the account — a proper resolution of this question should stem from the PPP concession agreement and the records of processing activities of both parties.
  • ⚠️ External scripts from public CDNs without an integrity signature (SRI).
    The page loads: cdnjs.cloudflare.com/ajax/libs/limonte-sweetalert2/10.10.0/sweetalert2.min.js (alerts library) and unpkg.com/unpkg.com/leaflet@1.9.1/dist/leaflet.js (maps library). Both are popular, commonly used front-end libraries, but loaded without the integrity attribute (Subresource Integrity). Supply chain risk in the front-end layer. The mere fact of hosting on a CDN does not constitute a GDPR violation — it is a signal in the application security hygiene layer.
  • ⚠️ The JSESSIONID cookie reveals an architectural detail.
    The cookie value contains the .lodz_atena suffix, which identifies the backend application server instance (a classic Java EE signature). This is not a tracker or a GDPR violation — it is an informational element about the system architecture, potentially useful for analyzing the backend data processing layer, outside the scope of the front-end scanner.

Scope of this measurement — what is visible and what is not

The measurement covered the kartalodzianina.pl landing page without interaction — without logging in, without registration, without using card features. All conclusions above apply exclusively to the front-end layer visible to an anonymous visitor.

Outside the scope of this measurement remain:

  • The data layer of registered card users (personal data, service usage history)
  • Integrations with card service partners (municipal transport, discount services, cultural services)
  • The legal model of the PPP concession agreement and data processing clauses
  • The record of processing activities of the consortium and the City of Łódź as potential joint controllers
  • The behavior of the service after clicking "Accept" (what tag stack deploys after consent)

These layers require a documentary analysis of the concession agreement, access to the records of processing activities, and measurements after user interaction — outside the scope of the anonymous front-end measurement scanner.

Comparison with municipal entity domains

In the context of the comparison with the rest of the analyzed domains of the Łódź ecosystem (aquapark, botaniczny, BIPs, CSS, CUW, CUWDPS, invest, capz, samorzad), the front-end of kartalodzianina.pl is clearly better implemented in terms of consent and tracking hygiene:

ElementMunicipal entity domainskartalodzianina.pl
Consent Mode v2❌ No consent commands in data_layer✅ Correctly implemented (denied default)
Cookies before consent❌ 8-11 trackers immediately✅ Only JSESSIONID
Facebook SDK/Pixel⚠️ Loaded (SDK; Pixel on aquapark)✅ None
YouTube API⚠️ Loaded, YouTube cookies✅ None
Twitter widgets⚠️ Loaded, iframe✅ None
ads.biblioteka.lodz.pl❌ Loaded✅ None
📄 Show Domain Assessment

Audit Summary: kartalodzianina.pl

Latest scan: 20260306_201700_53607701

Basic information

  • URL: https://kartalodzianina.pl/
  • Sterile Session Status: 🔴 VIOLATION (Tracking/cookie traces before consent)
  • Total Requests: 101
  • Tracking Requests: 2
  • Cookies Set: 1

Conclusions and Violations

  • ⚠️ Detected gcd parameter in tracking requests.
  • • Detected CMP elements: consent.
  • ⚠️ After the session, potentially tracking cookies exist (1 pc.).

Data Flow (Identified Recipients)

External services receiving data in this session: - region1.google-analytics.com

CMP Detection (Consent Management)

  • Mechanisms/variables suggesting the use of were detected: consent

Report generated automatically based on network traffic analysis and DOM changes in an empty browser session (Before clicking the consent button).

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

Cookie banner without a link to the policy.

📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://zlm.lodz.pl/

SCAN ID: 20260306_201918_010ea978

ADO: Municipal Premises Authority

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests8
Cookies9

Technical Conclusions (Scanner)

  • 🔴 GA4 G-30F084ZHSL (Library) + legacy UA UA-25825547-40 with gcd=13l3l3l2l1l1 + npa=1
  • 🔴 CMP cookie-box.js present, but not integrated with Google Consent Mode
  • ⚠️ Facebook SDK + YouTube widget + Twitter widgets + livebar lodz.pl/livebar/
  • - Ad server from the Municipal Library (ads.biblioteka.lodz.pl)
  • - CSP errors when loading images from GTM / livebar (do not block tracking)
  • - Stable timeline. GA cookies set immediately after DOMContentLoaded.

Privacy Policy Analysis vs Tags

Identified Container IDs:
G-30F084ZHSL UA-25825547-40
Privacy Policy Assessment: Cross-controller sharing of Municipal Library GA4 on the Municipal Premises Authority website. cookie-box CMP does not transmit consent signal. Typical pattern for uml_portal domains.
📸 Evidence: Page Snapshots and GDPR Documents
📌 Notes from policy scan:

Footer links lead to ZLM BIP

https://zlm.lodz.pl/ Archived: 2026-03-05 21:01
🔍 View Snapshot
📁 Show Hard Evidence (HAR, Cookies, Trace)
DISABLED

https://zdit.uml.lodz.pl/

SCAN ID: 20260306_201618_f1dbf1a2

ADO: Roads and Transport Authority

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests12
Cookies8

Technical Conclusions

  • ⚠️Redirect to uml.lodz.pl with full tracking stack.

Privacy Policy Analysis vs Tags

Identified Container IDs:
G-30F084ZHSL UA-25825547-40 AW-790142032 AW-10940984035
Privacy Policy Assessment: Google Ads detected (AW-790142032, AW-10940984035) active before consent. Cross-domain (G-30F084ZHSL, UA-25825547-40 shared with uml.lodz.pl) without declaration of joint administration (art. 26 RODO). Connection to connect.facebook.net recorded in data flow. CMP (Klaro) configured incorrectly — gcd=13l3l3l2l1l1 detected before user decision (art. 6 sec. 1 lit. a RODO).
📸 Evidence: Page Snapshots and GDPR Documents
📌 Notes from policy scan:

BIP page privacy policy/RODO in the footer. Redirects to uml.lodz.pl

No archived snapshots for this domain.

📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://aquapark.lodz.pl/ ŁOT Group

SCAN ID: 20260309_103954_565488af

Data Controller: Aquapark Fala sp. z o.o.

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests15
Cookies12

Technical Conclusions

  • 🔴 An extensive tracking stack launched immediately upon entry — GA4 (two properties), Universal Analytics, DoubleClick, Facebook Pixel, and GTM with active scroll tracking.
  • 🔴 A custom CMP was detected (TYPO3 cookiebox from the uml_portal package), which does not block the loading of trackers before the user's decision — a deceptive mechanism.
  • 🔴 The same client ID (cid) transmitted in parallel to two GA4 properties belonging to different controllers — the Municipal Library (G-30F084ZHSL) and the aquapark (G-N60T196VLF). Cross-controller identity sharing without a public legal basis.
  • 🔴 Facebook Pixel initialized (config Pixel ID 1232725160738501 downloaded, _fbp cookie set, fbevents.js library loaded). The facebook.com/tr beacon was not recorded in the measurement window — Pixel ready to transmit events.
  • 🔴 Municipal Library ad server (ads.biblioteka.lodz.pl, Revive Adserver, endpoint /www/delivery/asyncjs.php) loaded on a commercial site of a municipal facility — request to a separate data controller's domain.
  • 🔴 Google Consent Mode: the gcd=13l3l3l2l1l1 parameter in all /g/collect calls indicates a lack of an integrated consent signal. The npa=1 flag (non-personalized ads) is present, but cid, sid, page_view, and the scroll event with the epn.percent_scrolled=90 parameter are transmitted nevertheless.
  • - After the session, 11 tracking cookies remain (6× GA/GTM, 4× YouTube, 1× Facebook Pixel _fbp) + 1 F5 BIG-IP session management cookie (not a tracker).

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
GTM-T843X8ZC UA-25825547-40 G-30F084ZHSL G-N60T196VLF FB:1232725160738501
Policy Assessment: Active cross-domain tracking (shared GTM/GA4 with uml.lodz.pl). No declaration of joint controllership (Art. 26 GDPR). Tags were firing without a visible Consent Mode mechanism, which at the time of the audit was implemented by the script: https://aquapark.lodz.pl/typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js available on Github in 2014 and updated on 31.01.2016, which in my opinion is far from current legal and technical requirements. The same TYPO3 package (uml_portal) with the same cache-buster version that we have on botaniczny, bip.uml, and bip.zlm, as well as other services with a similar mechanism.
📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

Both links in the footer

📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://mpk.lodz.pl/ ŁOT Group

SCAN ID: 20260309_103954_7e7bd54e

Data Controller: MPK Łódź sp. z o.o. (100% City owned)

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests5
Cookies6

Technical Conclusions

  • 🔴 Total absence of a CMP — scripts_dom.json does not contain any consent mechanism (missing cookie-box.js, klaro.js, Funding Choices, CookieYes). Third-party code is loaded unconditionally.
  • 🔴 Facebook legacy SDK (connect.facebook.net/pl_PL/all.js) loaded directly on mpk.lodz.pl. Initialization confirmed in sessionStorage (fbssls_).
  • ⚠️ YouTube + Google Analytics loaded indirectly via the lodz.pl/livebar/ iframe (UMŁ widget). Inside the livebar context: YouTube widget API + gtag.js (UA-25825547-40 and G-30F084ZHSL).
  • - YouTube cookies (VISITOR_INFO1_LIVE, YSC, __Secure-ROLLOUT_TOKEN) appear with mpk.lodz.pl as the partitionKey — a side effect of the livebar widget.
  • - First-party elements: JSESSIONID (session) + custom cookie scrlPgrCrntPgId4CckNmsnews (scroll progress). Timeline is stable, before_navigation = 0.
  • - No direct YouTube embeds on mpk.lodz.pl. No direct GA beacons detected on the main domain within this measurement.

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
Facebook all.js (legacy) UA-25825547-40 (in livebar) G-30F084ZHSL (in livebar)
Policy Assessment: Absence of a CMP on the MPK Łódź Sp. z o.o. website while simultaneously loading the legacy Facebook SDK directly on the domain. Additional tracking (YouTube + GA) is injected indirectly via the lodz.pl/livebar/ widget (administered by the Municipal Library). The violation of Art. 173 of the Telecommunications Law is explicit.
📄 Show Domain Assessment

Conclusions and Violations

  • 🔴 Total absence of a CMP — no cookie consent mechanism was detected in `scripts_dom.json`. Missing cookie-box.js, klaro.js, Funding Choices, CookieYes, and Drupal EU Cookie Compliance. Third-party components (Facebook SDK) are loaded unconditionally on every visit.
  • 🔴 Uncontrolled Facebook legacy SDK — the script connect.facebook.net/pl_PL/all.js is loaded directly on `mpk.lodz.pl` (two instances). The SDK initializes itself (confirmed in sessionStorage via fbssls_ with an "unknown" status). There is no active Pixel, but loading the SDK itself requires consent.
  • ⚠️ Indirect tracking via the livebar widget — the iframe https://lodz.pl/livebar/ (UMŁ) injects the YouTube widget API, gtag.js with container UA-25825547-40, and container G-30F084ZHSL into the page. YouTube cookies appear with mpk.lodz.pl as the partitionKey, despite the lack of a direct YouTube embed on the main domain.
  • ⚠️ Legacy Universal Analytics inside the widget contextanalytics.js and the gtag script for UA-25825547-40 are loaded inside the livebar frame. No direct GA beacons were captured on the root mpk.lodz.pl domain.
  • ⚠️ First-party infrastructureJSESSIONID (application session) and the custom cookie scrlPgrCrntPgId4CckNmsnews=1 (internal tracking for news scroll progress). Both are first-party and non-profiling.
  • ⚠️ Limitations of previous capture path — the `payloads.ndjson` file was incomplete. The comprehensive picture (YouTube widget API + gtag inside livebar) was successfully re-constructed only through `requests.ndjson` and `responses.ndjson`.

Legal Context (Municipal Transport Company in Łódź)

MPK Łódź Sp. z o.o. operates as a municipal public transport company governed by the Act on Public Collective Transport. The website fulfills an informational and service function and is heavily visited by minors (students). It does not process special categories of data within the meaning of Art. 9 GDPR, but as a public entity, it is held to high standards of transparency.

Layer A — controller's compliance culture. No CMP has been implemented on the page, despite embedding the legacy Facebook SDK and a livebar widget that introduces additional third-party cookies and scripts. This is not a configuration error — it represents a complete lack of a base consent layer.

Layer B — market value of the signal. Low on the MPK side (as it lacks its own GA4 or AdSense containers). The primary beneficiary of the tracking remains the livebar widget (YouTube + Municipal Library GA). However, this does not exempt the administrator from the obligation to secure consent before embedding such elements.

Domain assessment summary – mpk.lodz.pl

CriterionAssessment
Launching trackers before consent🔴 Yes — Facebook SDK directly + livebar tracking without a CMP
Presence / effectiveness of a CMP🔴 CMP does not exist
Transmission to third parties⚠️ Indirect (via lodz.pl/livebar widget) + direct Facebook SDK
Facebook Pixel / SDK⚠️ Legacy SDK loaded, no active Pixel beacons found
YouTube / GA⚠️ Indirectly via livebar (UA-25825547-40 + G-30F084ZHSL)
Overall assessment🔴 Severe violation — missing CMP layer paired with the legacy Facebook SDK on a public transit website

Verdict: One of the clearest structural breaches in the audit is documented on mpk.lodz.pl — a complete absence of a cookie consent mechanism combined with loading the legacy Facebook SDK directly on the domain. Supplementary tracking assets (the YouTube widget API and Google Analytics) are funneled indirectly via the embedded lodz.pl/livebar/ widget. While there is no direct YouTube embed or dedicated GA4 container mapped directly to the root domain, this does not mitigate the weight of the violation of Art. 173 of the Telecommunications Law. MPK Łódź Sp. z o.o. distributes digital content that drops third-party cookies without providing any possibility for the user to register consent preferences.

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

Detected in incognito mode: a banner is visible alongside an extensive "RODO w MPK" (GDPR at MPK) section parsed onto the homepage.

📁 Show Hard Evidence (HAR, Cookies, Trace)
MEDIUM

https://www.makis.pl/ ŁOT Group

SCAN ID: 20260309_103954_f4656360

Data Controller: Miejska Arena Kultury i Sportu Sp z o.o. (100% City owned)

Hosting/IT: IONOS-AS This is the joint network for IONOS, Fasthosts, Arsys, 1&1 Mail and Media and 1&1 Telecom. Formerly known as 1&1 Internet SE., DE

Requests0
Cookies1

Technical Conclusions (Scanner)

  • Cookiebot CMP active and configured
  • Legacy UA tracker UA-22415839-4 loaded with type="text/plain" (blocked by CMP)
  • - Accessibility tool: Userway (cdn.userway.org)
  • - No GA4, Facebook Pixel, Google Ads, or Crazy Egg
  • - Cookies: session-only first-party (ba6ac1318ea3a0a881974ef325909922) only
  • - No active marketing beacons in payloads

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
UA-22415839-4
Privacy Policy Assessment: Cookiebot CMP active. UA is blocked prior to user consent. Modern marketing tracking (GA4 / Pixel / Ads) is absent. The factual status performs significantly better than across the majority of the uml.lodz.pl domains.
📄 Show Domain Assessment

Conclusions and Violations

  • Cookiebot CMP works — Cookiebot scripts (`consent.cookiebot.com`) and the consent iframe are loaded. This represents one of the rare audit cases where a CMP is genuinely active.
  • Legacy UA blocked — the gtag/js?id=UA-22415839-4 tag carries a type="text/plain" attribute, meaning Cookiebot strictly blocks it before user consent.
  • ⚠️ GA4 Absent — the site relies on the deprecated Universal Analytics tracking container (UA-22415839-4). No GA4 deployment was detected.
  • No Pixel / Ads / session recording — Facebook SDK (outside potential embeds), Google Ads, or session recording suites are completely absent.
  • - Userway (accessibility) — accessibility widget loaded. This functions as a helper tool rather than a marketing tracker (persisting preferences in localStorage).

Legal Context (Municipal Culture and Sports Arena)

makis.pl operates as the landing page of the municipal company responsible for handling sports and cultural venues within Łódź (arenas, ice rinks, major events). Visitors are primarily individuals checking out sports schedules, cultural events, or ticketing information — contextually far less sensitive than benefits portals or shelters.

Layer A — controller's compliance culture. The best performing infrastructure across the reviewed municipal domains. They utilize a professional CMP platform (Cookiebot) and effectively block processing tags prior to consent. This represents an exemplary standard relative to the rest of the uml.lodz.pl ecosystem.

Layer B — market value of the behavioral profile. Low/moderate. Data tracking structural interest in sports matches or cultural events carries a very bounded commercial value.

Audit summary – www.makis.pl

CriterionAssessment
Launching trackers before consent✅ None — UA is blocked by Cookiebot
CMP Effectiveness✅ Cookiebot active and blocking
Modern tracking (GA4 / Pixel / Ads)✅ None
Third-party elements⚠️ Only Userway (accessibility) + Cookiebot
Overall assessment✅ Positive / Medium — one of the best domains identified in the audit

Verdict: A significantly better practice was applied on www.makis.pl than on the majority of municipal domains. They use Cookiebot as a CMP, which effectively blocks legacy UA before the user's choice. No GA4, Facebook Pixel, or Google Ads deployments were detected. The only supplementary tool remains Userway (accessibility). This serves as a benchmark for correct tracking hygiene in a municipal corporation.

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

The cookie banner redirects to: https://makis.pl/polityka-prywatnosci — same page

📁 Show Hard Evidence (HAR, Cookies, Trace)
DISABLED

https://pup-lodz.pl/

ADO: Poviat Labour Office in Łódź

Domain disabled from analysis

The pup-lodz.pl page is a technical redirect leading to the lodz.praca.gov.pl service. The audit report is available at the target domain.

VIOLATION

https://lodz.praca.gov.pl/

SCAN ID: 20260309_104016_c5852ac5

Data Controller: Powiatowy Urząd Pracy w Łodzi

Hosting/IT: TM, PL

Requests24
Cookies8

Technical Conclusions (Scanner)

  • 🔴 GA4 ping executed to www.google-analytics.com/j/collect prior to user decision: tid=G-07E8YF01RN, cid=698957334.
  • 🔴 Complete absence of Google Consent Mode in any shape or form — missing all parameters such as gcd, npa, dma, or pscdl. The website completely fails to signal any consent state.
  • 🔴 Hybrid UA/GA4 configuration: cookies are initialized in the Universal Analytics format (_ga=GA1.3.*, _gid, _gat), while routing metrics to a GA4 property (G-07E8YF01RN) via the legacy legacy endpoint /j/collect using the analytics.js library. Unfinished migration more than 2.5 years after UA's sunset (July 2023).
  • 🔴 Embedded Google Maps (2 iframes for PUP branches) — 15 requests for vector map tiles executed to www.google.com/maps/vt. The user's IP address is transmitted to Google during the rendering of every single tile.
  • 🔴 Google Translate widget (translate.google.com/translate_a/element.js) and Google Fonts (fonts.gstatic.com) present — additional IP address transmissions to Google without valid user consent.
  • ⚠️ GA cookies set with a scope on .praca.gov.pl — the analytical identity escapes the boundaries of this specific page, propagating across the parent domain.
  • - 8 cookies remain stable throughout the entire measurement cycle. Infrastructure: Liferay CMS (LFR_SESSION_STATE_10206) + F5 BIG-IP (BIGipServerPool_Wortal-new, cluster wortal-77bccd544c-g2xhq). data_layer.json is empty — GTM is absent.
  • - Methodological note: the scripts_dom.json file was missing from the upload — the full roster of loaded scripts remains unconfirmed; conclusions are anchored in raw network payloads.

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
G-07E8YF01RN
Policy Assessment: Website of the District Labor Office (PUP) in Łódź — complete lack of any Google Consent Mode implementation, with automatic transmission of client identifiers and user IP addresses to Google via GA4, Google Maps, Translate, and Fonts prior to any user choice. The visiting population (unemployed individuals, job seekers) falls under an elevated protection regime governed by Art. 9 GDPR and the Act of 20 April 2004 on Employment Promotion and Labor Market Institutions.
📄 Show Domain Assessment

Conclusions and Violations

  • 🔴 GA4 ping executed before user decision. Call routed to www.google-analytics.com/j/collect containing tid=G-07E8YF01RN, cid=698957334.173049222, dl=https://lodz.praca.gov.pl/, and vp=1440x2200. Cookies _ga, _gid, and _gat are set following the after_domcontentloaded stage.
  • 🔴 Complete absence of Google Consent Mode. The GA4 payload completely lacks parameters like gcd, npa, dma, pscdl, or gcs. The page signals neither consent nor refusal — representing a classic pre-Consent Mode technical setup. Unlike the municipal domains of Łódź (which at minimum dispatch gcd=13l3l3l2l1l1 as a fallback "consent not set"), lodz.praca.gov.pl contains no signaling whatsoever.
  • 🔴 Hybrid UA/GA4 layout — unfinished migration. Initializes cookies using the older Universal Analytics formatting architecture (_ga=GA1.3.698957334, _gid=GA1.3.1484994928, _gat=1) paired with a GA4 measurement property (prefix G-), hitting the legacy /j/collect endpoint via the old analytics.js library. Google fully deprecated Universal Analytics on July 1, 2023 — this configuration has been left unmigrated for more than 2.5 years.
  • 🔴 Embedded Google Maps — 15 vector tile requests. Two embedded map iframes (District Labor Office in Łódź + District Labor Office No. 2) execute 15 parallel tile requests to www.google.com/maps/vt — every map tile request transmits the user's IP address, user-agent string, and specific browser details straight to Google. Executed without user consent and without a clear legal basis articulated in the privacy policy.
  • 🔴 Google Translate widget and Google Fonts — additional IP tracking. The active translation script (translate.google.com/translate_a/element.js + translate.googleapis.com + www.gstatic.com/_/translate_http/) leaks user IP addresses to Google immediately upon loading. Google Fonts calls to fonts.gstatic.com trigger an identical data transmission — paralleling the legal doctrine of the German Landgericht München I ruling of 20 January 2022 (case ref. 3 O 17493/20), which found remote embedding of Google Fonts to stand as a violation of Art. 6(1) GDPR. Technical correction for both: local hosting.
  • ⚠️ GA cookies set with a scope on .praca.gov.pl — cross-domain escape. The cookies _ga, _gid, and _gat are broad-scoped to the apex domain .praca.gov.pl, rather than being restricted to lodz.praca.gov.pl. This means the analytical tracking signature of the Łódź PUP visitor is propagated across the entire government parent domain — extending beyond the local liability scope of this specific page controller.
  • ⚠️ Methodological note — missing scripts_dom.json payload file. The comprehensive structural breakdown of all active DOM-loaded scripts could not be verified due to a missing upload log. Technical deductions have been successfully extracted from payloads.ndjson, cookies_timeline.ndjson, cookies.json, data_layer.json, iframes.json, local_storage.json, and session_storage.json. Final verification of supplementary scripts would require appending the missing file or executing an updated scan path.

Legal Context (District Labor Office in Łódź)

lodz.praca.gov.pl acts as the digital infrastructure for the local District Labor Office (PUP) in Łódź, performing statutory public administration duties dictated by the Act of 20 April 2004 on Employment Promotion and Labor Market Institutions. The target audience interacting with this portal comprises unemployed individuals, citizens facing career transition, individuals seeking vocational activation tracks (internships, specialized training, business startup grants), and employers lodging job listings. Interacting with a PUP domain inherently exposes vulnerable livelihood circumstances governed by the heightened protection parameters of Art. 9 GDPR — social situation tracking (unemployment indicators), alongside sensitive health indicators (disabled citizens registering with a PUP utilize separate specialized support and funding tracks).

The controller of a public institution serving economically and socially vulnerable populations in 2026 — years after the global rollout of the GDPR and long after the mandatory integration of Google Consent Mode v2 — continues to deploy an obsolete pre-consent tracking profile, making zero attempts to register or respect user preferences. This is exacerbated by three supplementary background scripts (Maps, Translate, Fonts) executing data handshakes to Google, despite standard open-source technical alternatives existing that allow local hosting or connection stripping.

Assessment summary – lodz.praca.gov.pl

CriterionAssessment
Launching trackers before consent🔴 Severe violation
Google Consent Mode🔴 Absent in any shape or form
GA Configuration (UA/GA4)🔴 Hybrid, unfinished migration post-UA deprecation
Google Maps embedded🔴 15 tile requests leaking IP to Google
Google Translate + Google Fonts🔴 Remotely hosted, automated IP leakage
Cookies scope⚠️ Apex domain propagation to .praca.gov.pl
Third-party scripts (Facebook, Twitter, YouTube, DoubleClick)✅ None detected
Commercial Advertising Monetization✅ Absent (No AdSense, Ads, or Meta Pixel tracking)
Regulatory / Subject Context🔴 Heightened sensitivity (Art. 9 GDPR + Employment Promotion Act)
Overall assessment🔴 Poor (Total lack of Consent Mode + sensitive user context)

Verdict: The portal of the District Labor Office in Łódź executes GA4 behavioral tracking (property G-07E8YF01RN) without any integration of Google Consent Mode — completely omitting metrics such as gcd, npa, dma, or pscdl inside its out-going payloads. The hybrid UA/GA4 technical structure connecting through the legacy /j/collect endpoint proves that the data layer was never properly zmigrated following the global retirement of Universal Analytics in July 2023. User IP addresses are automatically passed to Google via three peripheral integrations (Google Maps tile requests, Google Translate widget initialization, and remote Google Fonts stylesheets). The targeted user base is covered by the strict privacy boundaries of Art. 9 GDPR and the Act on Employment Promotion and Labor Market Institutions.

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

Link located in the "Urząd" (Office) service menu

📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://architektmiasta.uml.lodz.pl/

SCAN ID: 20260309_104021_61f1f764

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests6
Cookies11

Technical Conclusions

  • 🔴 Tracking tags were firing immediately upon entering the site, before any user decision. After the after_domcontentloaded stage, Google Analytics and YouTube cookies appeared.
  • ⚠️ Klaro CMP was detected, however, it did not effectively block tags before user interaction. There are no consent default or consent update commands in data_layer.json.
  • ⚠️ Data was transmitted to third parties (Google, Meta, YouTube, Twitter) before consent was given.
  • - After the session, potentially tracking cookies exist (11 pcs.).

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
UA-25825547-40
Policy Assessment: Active cross-domain tracking (shared UA-25825547-40 container with uml.lodz.pl and lodz.pl) without a declaration of joint controllership (Art. 26 GDPR). Google and Facebook tags were firing before interaction with the consent mechanism.
📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

Detected in incognito: The banner only redirects to uml.lodz.pl, no dedicated GDPR link in the footer

📁 Show Hard Evidence (HAR, Cookies, Trace)
DISABLED

https://teatr-muzyczny.lodz.pl/

SCAN ID: 20260309_104016_fff92000

ADO: Musical Theatre in Łódź

Hosting/IT: TARRCI-AS, PL

Requests0
Cookies0

Technical Conclusions

  • ⚠️Position disabled from comparative evaluation due to TLS issue / unavailability of the input domain, preventing the full sterile session test under conditions comparable to other domains.

Privacy Policy Analysis vs Tags

No verifiable containers.

Privacy Policy Assessment: Result inconclusive — domain DISABLED FROM ASSESSMENT.
📸 Evidence: Page Snapshots and GDPR Documents
📌 Notes from policy scan:

TLS Error — untrusted certificate. Page unavailable.

📁 Show Hard Evidence (HAR, Cookies, Trace)
MEDIUM

https://bip.biblioteka.lodz.pl/

SCAN ID: 20260309_104042_b2ce5a56

Data Controller: Biblioteka Miejska w Łodzi

Hosting/IT: CF-KRK, PL

Requests0
Cookies1

Technical Conclusions

  • -After the session, potentially tracking cookies exist (1 pc.).

Privacy Policy Analysis vs Tags

No assigned containers in the journalistic table.

Privacy Policy Assessment: The privacy policy correctly declares the use of identified tools (tracking codes) or no explicit concealment was found (Full Compliance of the declaration with the actual state).
📄 Show Domain Assessment

Audit Summary: bip.biblioteka.lodz.pl

Conclusions

  • 🟢 No tracking tags are fired before the user's decision. After after_domcontentloaded, only a single Joomla session cookie was set.
  • 🟢 No external tracking scripts or trackers present. All scripts are first-party (Joomla + govarticle template).
  • 🟢 No data transmission to third parties. All requests are first-party.
  • 🟢 No need for a CMP – the page does not load any trackers requiring consent.

Overall Assessment: The website performs exemplarily in terms of privacy. It stands as an example of a well-designed public administration webpage.

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

Link in the service menu

📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://capz.lodz.pl/

SCAN ID: 20260309_104044_19fa3625

ADO: Administrative Center for Substitute Care

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests8
Cookies8

Technical Conclusions

  • 🔴 Tracking tags fired immediately upon entering the page, before any user decision.
  • 🔴 Own CMP detected (cookiebox TYPO3 from the uml_portal package), which does not block the loading of trackers before the user's decision — a sham mechanism.
  • 🔴 Data transmitted to Google (GA4 G-30F084ZHSL + DoubleClick) before any decision. Facebook SDK, YouTube player_api and Twitter iframe were also loaded. Municipal Library ad server (ads.biblioteka.lodz.pl) and lodz.pl/livebar widget embedded on the page.
  • 🔴 Google Consent Mode: parameter gcd=13l3l3l2l1l1 in all /g/collect calls indicates lack of integrated consent signal. Flag npa=1 forces non-personalized ads, but cid, sid and page_view are still transmitted.
  • - After the session, 8 tracking cookies remain (4× GA, 4× YouTube). No Facebook Pixel — only Facebook SDK loaded.

Privacy Policy Analysis vs Tags

Identified Container IDs:
UA-25825547-40 G-30F084ZHSL
Privacy Policy Assessment: Active cross-domain tracking (shared GA4/UA with other municipal domains) without declaration of joint administration (art. 26 RODO) in the privacy policy. Parameter gcd=13l3l3l2l1l1 sent before consent is given (art. 6 sec. 1 lit. a RODO).
📄 Show Domain Assessment

Audit Summary: bip.biblioteka.lodz.pl

Conclusions and Violations

  • 🔴 Tracking tags fired immediately upon entering the page, before any user decision.
    After the after_domcontentloaded stage, Google Analytics cookies (_ga, _ga_30F084ZHSL, _gid, _gat_gtag_UA_25825547_40) and YouTube cookies were automatically set. At the same time, the following scripts were loaded: google-analytics.com/analytics.js, googletagmanager.com/gtag/js (G-30F084ZHSL + UA-25825547-40), connect.facebook.net/sdk.js, youtube.com/player_api, platform.twitter.com/widgets.js.
  • 🔴 An own consent management mechanism (CMP) was implemented that does not block trackers before the user's decision.
    The site has its own CMP: typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js. The mechanism loads but does not constitute an effective opt-in — Google, Facebook, YouTube and Twitter tracking scripts fire without blocking. In data_layer.json there are no consent default or consent update commands.
  • 🔴 Data was transmitted to third parties before consent was given.
    Confirmed requests:
    • Google Analytics 4 (G-30F084ZHSL) → region1.analytics.google.com/g/collect (page_view, cid=1213265501)
    • Universal Analytics (UA-25825547-40)
    • DoubleClick → stats.g.doubleclick.net/g/collect (same cid)
    • Facebook SDK (no Pixel — no fbevents.js, no _fbp cookie)
    • YouTube (player_api + widget)
    • Twitter widgets (iframe with origin=capz.lodz.pl)
    ads.biblioteka.lodz.pl (Revive Adserver belonging to the Municipal Library — a separate data controller)
    lodz.pl/livebar.js (livebar widget).
  • ⚠️ YouTube cookies are partitioned (CHIPS).
    They contain "partitionKey": "https://capz.lodz.pl" and "_crHasCrossSiteAncestor": true. They are isolated per top-level origin — they do not enable classic cross-site tracking, but still constitute data collected without user consent.
  • ⚠️ Consent Mode parameters indicate lack of integrated consent signal.
    In requests the following parameters are visible: gcd=13l3l3l2l1l1, npa=1, dma=1, dma_cps=a. The configuration indicates „consent not set” with simultaneous forcing of non-personalized ads — nevertheless client identifier (cid), session identifier (sid) and page_view event are transmitted.
  • ⚠️ Sharing of measurement infrastructure.
    The site uses GA4 property G-30F084ZHSL (belonging to a different controller than CAPZ) and a shared UA-25825547-40 container — both present on other municipal domains. Additionally, it loads a script from ads.biblioteka.lodz.pl, transmitting a request to an external ad server without a public declaration of joint administration.

Summary of assessment – capz.lodz.pl

CriterionAssessmentComment
Firing trackers before consent🔴 Serious violationConfirmed by cookies_timeline + payloads
Effectiveness of implemented CMP🔴 Low / shamOwn TYPO3 cookie-box does not block tags
Transmission of data to third parties🔴 YesGoogle (incl. DoubleClick), Meta, YouTube, Twitter, ads.biblioteka.lodz.pl
Consent Mode parameters⚠️ Consent not setgcd=13l3l3l2l1l1 + npa=1
YouTube cookies⚠️ Partitioned (CHIPS)Isolated per top-level origin
Shared measurement infrastructure⚠️ YesShared GA4 (belonging to another controller) + UA + Library ad server
Overall assessment🔴 PoorSham CMP with full stack of Google + Meta + YouTube + Twitter trackers
---

Verdict:
On the website capz.lodz.pl an own CMP (cookie-box from the uml_portal package) was implemented that does not block the loading of trackers before the user's decision. The same client identifier (cid) is transmitted in parallel to GA4 property G-30F084ZHSL (belonging to a different data controller than CAPZ) and to DoubleClick. The site transmits data to Google, Meta, YouTube, Twitter and the external ad server of the Municipal Library without effective consent and without a public declaration of joint administration under art. 26 RODO.

📸 Evidence: Page Snapshots and GDPR Documents
📌 Notes from policy scan:

"Data Protection" link in the menu

https://capz.lodz.pl/ Archived: 2026-03-05 21:01
🔍 View Snapshot
📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://botaniczny.lodz.pl/

SCAN ID: 20260309_104043_d3c46fd7

Data Controller: Ogród Botaniczny w Łodzi

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests9
Cookies9

Technical Conclusions

  • 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
  • 🔴 A custom CMP (TYPO3 cookiebox) was implemented, but it is ineffective – Google, Facebook, and YouTube tags load without restriction.
  • 🔴 Data was transmitted to Google, Meta, YouTube, Twitter, and DoubleClick before consent was given.
  • ⚠️ Google Consent Mode parameters indicate "consent not set" (gcd=13l3l3l2l1l1, npa=1).
  • - After the session, potentially tracking cookies exist (9 pcs.).

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
UA-25825547-40
Policy Assessment: Active cross-domain tracking (shared G-30F084ZHSL GA4 and UA-25825547-40 with other uml.lodz.pl domains). A custom CMP was implemented, but it is ineffective. No declaration of DoubleClick and YouTube. Shared infrastructure with the Municipal Library (the same GA4 + script from ads.biblioteka.lodz.pl).
📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

GDPR ZZM (Zarząd Zieleni Miejskiej); CCTV clause: https://zzm.lodz.pl/files/public/uploads/RODO/KLAUZULA_INFORMACYJNA__MONITORING_ZZM.pdf

📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://cuwdps.uml.lodz.pl/

SCAN ID: 20260309_104106_41c1beb1

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests6
Cookies10

Technical Conclusions

  • 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
  • 🔴 A custom CMP was detected (TYPO3 cookiebox from the uml_portal package), which does not block the loading of trackers before the user's decision — a deceptive mechanism.
  • 🔴 Data transmitted to Google (GA4 G-30F084ZHSL + DoubleClick) before any decision. Facebook SDK, YouTube player_api, a Twitter iframe, and the Municipal Library ad server script (ads.biblioteka.lodz.pl) were also loaded.
  • ⚠️ GA cookies set on the apex domain .uml.lodz.pl — analytical identity shared with uml.lodz.pl, bip.uml.lodz.pl, and cuw.uml.lodz.pl (details in expanded view).
  • 🔴 Google Consent Mode: the gcd=13l3l3l2l1l1 parameter in all /g/collect calls indicates a lack of an integrated consent signal. The npa=1 flag forces non-personalized ads, but cid, sid, and page_view are transmitted nevertheless — the signal fueling Google's audience models is sent regardless.
  • - After the session, 9 tracking cookies remain (4× GA, 5× YouTube) + 1 F5 BIG-IP session management cookie (not a tracker). The hosting architecture is identical to bip.uml.lodz.pl.

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
UA-25825547-40 G-30F084ZHSL
Policy Assessment: Active cross-domain tracking (shared .uml.lodz.pl scope) without a declaration of joint controllership (Art. 26 GDPR). The website belongs to an entity handling Care Homes (DPS) — the mere fact of a visit reveals life circumstances qualifying under the special protection regime of Art. 9 GDPR (care for a senior, a person with a disability, or a mental illness).
📄 Show Domain Assessment

Conclusions and Violations

  • 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
    After the after_domcontentloaded stage, Google Analytics cookies (_ga, _ga_30F084ZHSL, _gid, _gat_gtag_UA_25825547_40) and YouTube cookies were automatically set. The following scripts were loaded: google-analytics.com/analytics.js, googletagmanager.com/gtag/js (G-30F084ZHSL + UA-25825547-40), connect.facebook.net/sdk.js, youtube.com/player_api, platform.twitter.com/widgets.js, ads.biblioteka.lodz.pl/www/delivery/asyncjs.php.
  • 🔴 A custom consent management mechanism (CMP) was implemented, which does not block trackers before the user's decision.
    A custom CMP is present on the page: typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js. The mechanism loads, but does not provide an effective opt-in — tracking scripts run without blocking. There are no consent default or consent update commands in data_layer.json. Unlike css.samorzad.lodz.pl, Klaro from the central central infrastructure cookies.uml.lodz.pl has not been deployed here.
  • 🔴 Data was transmitted to third parties before consent was given.
    Confirmed requests:
    • Google Analytics 4 (G-30F084ZHSL, belonging to the Municipal Library) → region1.analytics.google.com/g/collect (page_view, cid=993688511)
    • Universal Analytics (UA-25825547-40) — cookie _gat_gtag_UA_25825547_40 set
    • DoubleClick → stats.g.doubleclick.net/g/collect (same cid)
    • Facebook SDK (without Pixel — no fbevents.js, no _fbp cookie)
    • YouTube (player_api + widgetapi)
    • Twitter widgets (iframe with origin=cuwdps.uml.lodz.pl)
    ads.biblioteka.lodz.pl — Municipal Library Revive Adserver (separate data controller)
  • 🔴 Cross-subdomain scope cookies GA — the strongest vector of this domain.
    The cookies _ga, _ga_30F084ZHSL, _gid, and _gat_gtag_UA_25825547_40 are set on the apex domain .uml.lodz.pl, rather than .cuwdps.uml.lodz.pl. This means that CUWDPS shares its analytical identity with the main city portal (uml.lodz.pl), the office's Public Information Bulletin (bip.uml.lodz.pl), and the Shared Services Center (cuw.uml.lodz.pl) — the measurement identifies the same user across four formally distinct services of different municipal units, despite these entities handling entirely different thematic areas (social care benefits vs. roads, transport, investments).
  • ⚠️ YouTube cookies are partitioned (CHIPS), but with an anomaly.
    They contain "partitionKey": "https://uml.lodz.pl" (not cuwdps.uml.lodz.pl) and "_crHasCrossSiteAncestor": true. A recurring feature of measurements across the *.uml.lodz.pl subdomains.
  • ⚠️ Consent Mode parameters indicate a lack of an integrated consent signal.
    The parameters visible in requests are: gcd=13l3l3l2l1l1, npa=1, dma=1, dma_cps=a. The configuration indicates "consent not set" while simultaneously forcing non-personalized ads — despite this, the client ID (cid), session ID (sid), and page_view event are transmitted. The npa=1 flag limits personalized displays, but does not turn off the provisioning of Google's audience models — the behavioral signal enters the system regardless.

Legal and Market Context (Shared Services Center for Care Homes)

cuwdps.uml.lodz.pl is the website of the Shared Services Center for Care Homes (Centrum Usług Wspólnych Domów Pomocy Społecznej) in Łódź — a budgetary unit of the City of Łódź providing shared operational management for municipal Care Homes (DPS). DPS are round-the-clock care institutions for elderly individuals requiring support, persons with intellectual disabilities, individuals with mental illnesses, and the chronically somatically ill. The mere fact of visiting this domain indirectly reveals life circumstances qualified under the special protection regime of Art. 9 GDPR — health data in the context of eligibility for institutional care requires medical certificates, disability ratings, or psychiatric diagnoses.

The legal framework encompasses: the Act of 12 March 2004 on Social Assistance (eligibility, placement, and operation procedures for care homes), the Act of 19 August 1994 on Mental Health Protection (for care homes admitting individuals with mental illnesses), and the Regulation of the Minister of Family and Social Policy on Care Homes. A controller operating in this domain is obliged to maintain strict discretion regarding individuals applying for placement in a care home, their families, and the residents of the facilities.

Layer A — controller's compliance culture. CUWDPS is a unit managing round-the-clock care facilities where some of the most vulnerable social groups reside — seniors in health crises, individuals with intellectual disabilities, and people with mental illnesses. An entity with such a mandate should represent an elevated standard of compliance hygiene across all its digital systems. Actual implementation: a deceptive TYPO3 cookiebox, transmission of the client identifier to Google, DoubleClick, Facebook, and the Municipal Library ad server before any user decision. The technical tracking configuration is identical to that of a commercial municipal aquapark — the controller does not differentiate the risk profile between a pool visitor and a family looking for a care home placement for an aging mother.

Layer B — market value of the behavioral profile. The segment "users linked to organizing institutional care for relatives" represents a highly valuable advertising inventory for the silver economy sectors: private care homes (in direct commercial competition with public facilities), agencies offering home care as an alternative to residential placement, medical and rehabilitation supply stores, law firms specializing in inheritance and guardianship law, health insurance providers for seniors, and funeral homes. The transmission of cid to GA4 and DoubleClick feeds Google's audience building models, which are subsequently bought by advertisers from these sectors. The fact that the signal originates from the domain of a public care unit means that a commercial competitor to the public care home can purchase the profile of a family currently applying for placement in a public facility. The city unintentionally supplies the remarketing market with segments from which its direct commercial competitors profit.

Assessment summary – cuwdps.uml.lodz.pl

CriterionAssessmentComment
Launching trackers before consent🔴 Severe violationConfirmed by cookies_timeline + payloads
Effectiveness of implemented CMP🔴 Low / deceptiveCustom TYPO3 cookie-box does not block tags (Klaro missing)
Data transmission to third parties🔴 YesGoogle (GA4 + UA + DoubleClick), Meta SDK, YouTube, Twitter, ads.biblioteka.lodz.pl
Consent Mode Parameters⚠️ Consent not set + npa=1Signal fuels audience models despite non-personalized flag
Cross-subdomain scope🔴 Yes — across the entire .uml.lodz.pl familyShared identity with uml.lodz.pl, bip.uml.lodz.pl, cuw.uml.lodz.pl
YouTube cookies⚠️ Partitioned (CHIPS)partitionKey https://uml.lodz.pl
Legal Context🔴 Elevated regimeArt. 9 GDPR + Act on Social Assistance + Act on Mental Health Protection
Market value of the profile🔴 Silver economy sectorAudience segment valuable for commercial competitors of public care homes
Overall assessment🔴 Qualified violationThe most vulnerable visitor population within the analyzed family of domains

Verdict: A deceptive CMP (TYPO3 cookiebox) has been implemented on the cuwdps.uml.lodz.pl website, which does not block the loading of trackers before the user's decision. The exact same client identity (cid) is transmitted in parallel to a GA4 property belonging to the Municipal Library and to DoubleClick, while cross-subdomain scope cookies on .uml.lodz.pl identify the user across four formally distinct services — CUWDPS, UMŁ, CUW, and the office's BIP. The unit handles the administration of round-the-clock care facilities housing highly vulnerable groups — a mandate requiring an elevated standard of compliance, which the deployed technical configuration fails to meet. The behavioral signal from a domain handling public residential care settlements represents valuable advertising inventory for the commercial silver economy sector — exported to the Google Ads system without a public legal basis and without a joint controllership declaration under Art. 26 GDPR.

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

Detected in incognito: Banner links return 404 errors. A dedicated GDPR page is available in the menu.

📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://css.samorzad.lodz.pl/

SCAN ID: 20260309_104105_22f6777d

Data Controller: Centrum Świadczeń Socjalnych w Łodzi

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests8
Cookies10

Technical Conclusions

  • 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
  • 🔴 Two simultaneous CMP mechanisms were detected: a custom TYPO3 cookiebox (uml_portal) and Klaro hosted on the central domain cookies.uml.lodz.pl. Neither of them blocks the loading of trackers before the user's decision.
  • 🔴 Data transmitted to Google (GA4 G-30F084ZHSL + DoubleClick) before any decision. Facebook SDK, YouTube player_api, a Twitter iframe, the Municipal Library ad server script (ads.biblioteka.lodz.pl), and the lodz.pl/livebar widget were also loaded.
  • 🔴 Three simultaneous Google Analytics containers: GA4 G-30F084ZHSL (belonging to another controller), Universal Analytics UA-25825547-40 (shared), and UA-178238957-1 (dedicated to samorzad). Two simultaneous UA config commands found in the data_layer.
  • 🔴 Google Consent Mode: the gcd=13l3l3l2l1l1 parameter in all /g/collect calls indicates a lack of an integrated consent signal. The npa=1 flag forces non-personalized ads, but cid, sid, and page_view are transmitted nevertheless.
  • - After the session, 10 tracking cookies remain (6× GA/UA, 4× YouTube). No Facebook Pixel found — only Facebook SDK loaded. GA cookies are set on the apex domain .samorzad.lodz.pl — cross-subdomain identity persistence.

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
UA-25825547-40 UA-178238957-1 G-30F084ZHSL
Policy Assessment: Active cross-domain tracking (shared GA4/UA with other municipal domains) without a declaration of joint controllership (Art. 26 GDPR). The website processes individual data in the context of social benefits — lack of a proportionality analysis within the meaning of Art. 5(1)(c) GDPR and the special regime of Art. 9 GDPR.
📄 Show Domain Assessment

Conclusions and Violations

  • 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
    After the after_domcontentloaded stage, Google Analytics cookies (_ga, _ga_30F084ZHSL, _gid, _gat_gtag_UA_25825547_40, _gat_gtag_UA_178238957_1) and YouTube cookies were automatically set. The following scripts were loaded: google-analytics.com/analytics.js, googletagmanager.com/gtag/js (G-30F084ZHSL + UA-25825547-40 + UA-178238957-1), connect.facebook.net/sdk.js, youtube.com/player_api, platform.twitter.com/widgets.js, ads.biblioteka.lodz.pl/www/delivery/asyncjs.php, lodz.pl/livebar.js.
  • 🔴 Two simultaneous CMP mechanisms were implemented — neither of them blocks trackers.
    Two consent management systems are present simultaneously on the website:
    • a custom TYPO3 cookiebox from the uml_portal package (typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js),
    • Klaro CMP hosted on the central infrastructure of UMŁ: cookies.uml.lodz.pl/klaro.js, cookies.uml.lodz.pl/cookie_config/config-c0e0b1f8065c1e3d26d050bac5180c66.js, cookies.uml.lodz.pl/embed.js.
    Klaro is a professional, serious compliance solution — choosing this tool suggests a conscious decision to unify the consent system across municipal portals. However, in practice, both mechanisms load without any blocking effect: Google, Facebook, YouTube, and Twitter tracking scripts launch before any user decision. In data_layer.json, there are no consent default or consent update commands. The mere fact of deploying Klaro alongside the TYPO3 cookiebox demonstrates that the administrator was aware of the legal obligation — yet the implementation ended with simply loading the script.
  • 🔴 Data was transmitted to third parties before consent was given.
    Confirmed requests:
    • Google Analytics 4 (G-30F084ZHSL) → region1.analytics.google.com/g/collect (page_view, cid=1402779805)
    • Universal Analytics (UA-25825547-40) — cookie _gat_gtag_UA_25825547_40 set (throttle token after ping)
    • Universal Analytics (UA-178238957-1) — cookie _gat_gtag_UA_178238957_1 set
    • DoubleClick → stats.g.doubleclick.net/g/collect (same cid)
    • Facebook SDK (without Pixel — no fbevents.js, no _fbp cookie)
    • YouTube (player_api + widgetapi)
    • Twitter widgets (iframe with origin=css.samorzad.lodz.pl)
    ads.biblioteka.lodz.pl — Municipal Library Revive Adserver (separate data controller)
    lodz.pl/livebar.js — livebar widget
    The exact same client identity (cid=1402779805) is transmitted in parallel to a GA4 property belonging to a different controller (the Library) and to DoubleClick.
  • 🔴 Three simultaneous Google Analytics containers.
    Two simultaneous config commands are visible in data_layer.json: UA-25825547-40 and UA-178238957-1. GA4 property G-30F084ZHSL is added on top of that. This is the first analyzed domain from the uml_portal family with three simultaneous Google measurement identifiers. UA-178238957-1 appears to be dedicated to the samorząd portal, but its coexistence with the shared UA-25825547-40 results in a duplicate stream of identical data to two different properties.
  • ⚠️ YouTube cookies are partitioned (CHIPS).
    They contain "partitionKey": "https://samorzad.lodz.pl" and "_crHasCrossSiteAncestor": true. They are isolated per top-level origin — they do not allow classic cross-site tracking, but still represent data collected without user consent.
  • ⚠️ Consent Mode parameters indicate a lack of an integrated consent signal.
    The parameters visible in requests are: gcd=13l3l3l2l1l1, npa=1, dma=1, dma_cps=a. The configuration indicates "consent not set" while simultaneously forcing non-personalized ads — despite this, the client ID (cid), session ID (sid), and page_view event are transmitted. Neither the TYPO3 cookiebox nor Klaro integrates with the Google Consent Mode layer.
  • ⚠️ Cross-subdomain scope cookies GA.
    The cookies _ga, _ga_30F084ZHSL, _gid, _gat_gtag_UA_25825547_40, and _gat_gtag_UA_178238957_1 are set on the apex domain .samorzad.lodz.pl, rather than .css.samorzad.lodz.pl. This means that the analytical identity of the Social Benefits Center user is continued across all subdomains of the samorząd portal.

Legal Context (Social Benefits Center)

css.samorzad.lodz.pl is the website of the Social Benefits Center in Łódź — a unit performing social assistance tasks based on the Act of 12 March 2004 on Social Assistance as well as family and upbringing benefits. Visitors to this site are most frequently beneficiaries of social assistance or individuals applying for benefits — families in difficult economic situations, seniors, people with disabilities, and individuals seeking help for victims of domestic violence.

The mere fact of visiting this domain indirectly reveals the life circumstances of the user, which are qualified under the special protection regime of Art. 9 GDPR (data concerning health in the context of benefits for people with disabilities, data concerning social situation). The transmission of the client ID (cid) to three Google Analytics containers, DoubleClick, Facebook SDK, the Municipal Library ad server, and the Twitter widget without effective user consent fails to meet the proportionality standard of Art. 5(1)(c) GDPR. Additionally, the controller is obliged to maintain strict discretion regarding beneficiaries of social assistance.

The technical configuration of tracking on css.samorzad.lodz.pl is identical to the configuration of a commercial municipal venue (aquapark.lodz.pl) — the same Google identifiers, the same gcd=13l3l3l2l1l1, the same deceptive cookiebox, the same Library ad server. The controller does not differentiate the risk profile between a pool visitor and an individual searching for information on benefits for a victim of domestic violence.

Assessment summary – css.samorzad.lodz.pl

CriterionAssessmentComment
Launching trackers before consent🔴 Severe violationConfirmed by cookies_timeline + payloads
Effectiveness of implemented CMPs🔴 Low / deceptiveTwo simultaneous CMPs (TYPO3 cookiebox + Klaro), neither blocks tags
Data transmission to third parties🔴 YesGoogle (3 containers + DoubleClick), Meta, YouTube, Twitter, ads.biblioteka.lodz.pl, livebar
Consent Mode Parameters⚠️ Consent not setgcd=13l3l3l2l1l1 + npa=1
Legal Context🔴 Elevated regimeArt. 9 GDPR + Act on Social Assistance of 12 March 2004
YouTube cookies⚠️ Partitioned (CHIPS)Isolated per top-level origin
Cross-subdomain scope🔴 YesGA cookies on .samorzad.lodz.pl
Overall assessment🔴 Qualified violationSensitive subjective context with a full stack of Google + Meta + YouTube + Twitter trackers

Verdict: Two simultaneous CMP mechanisms have been implemented on the css.samorzad.lodz.pl website (the TYPO3 cookiebox from the uml_portal package and Klaro hosted on the central infrastructure cookies.uml.lodz.pl) — neither blocks the loading of trackers before the user's decision. The exact same client identifier is transmitted in parallel to three Google Analytics containers (including a GA4 property belonging to a separate data controller — the Municipal Library) and to DoubleClick. The technical configuration is identical to that of a commercial municipal facility (aquapark.lodz.pl), despite the domain serving beneficiaries of social assistance — a life circumstance covered by the elevated protection regime of Art. 9 GDPR and the special duty of discretion under the Act on Social Assistance.

📸 Evidence: Snapshots of Pages and GDPR Documents
📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://invest.lodz.pl/

SCAN ID: 20260309_104106_fb027515

Data Controller: Urząd Miasta Łodzi (Invest in Łódź)

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests6
Cookies6

Technical Conclusions

  • 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
  • 🔴 Two simultaneous CMP mechanisms were detected: a custom TYPO3 cookiebox (from the invest_in_lodz package) and Klaro hosted on the central infrastructure cookies.uml.lodz.pl. Neither of them blocks the loading of trackers before the user's decision.
  • 🔴 Data transmitted to Google (GA4 G-30F084ZHSL + DoubleClick) before any decision. Facebook SDK, YouTube player_api, a Twitter iframe, and the Municipal Library ad server script (ads.biblioteka.lodz.pl) were also loaded. The newsletter form collects email addresses into the newsletter.uml.lodz.pl database.
  • ⚠️ Detected loading of the countUp.js script from the inorganik.github.io domain (GitHub Pages) — without a Subresource Integrity (SRI) signature. Supply chain risk for a public municipal site.
  • 🔴 Google Consent Mode: the gcd=13l3l3l2l1l1 parameter in all /g/collect calls indicates a lack of an integrated consent signal. The npa=1 flag limits personalized display, but the behavioral signal enters Google's audience models regardless.
  • - After the session, 6 tracking cookies remain (2× GA, 4× YouTube) — unusually fewer than on other municipal domains; no classic _ga and _gid despite analytics.js being loaded. Client identification occurs via _ga_30F084ZHSL and the cid parameter in the ping.

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
UA-25825547-40 G-30F084ZHSL
Policy Assessment: Active tracking (shared GA4/UA with other municipal domains) without a declaration of joint controllership (Art. 26 GDPR). A promotional site for investors — visitor profiles (M&A / corporate real estate decision makers) are transmitted to Google Ads, where they can be purchased by competing cities running alternative investment campaigns.
📄 Show Domain Assessment

Conclusions and Violations

  • 🔴 Tracking tags were firing immediately upon entering the site, before any user decision.
    After the after_domcontentloaded stage, Google Analytics cookies (_ga_30F084ZHSL, _gat_gtag_UA_25825547_40) and YouTube cookies were automatically set. The following scripts were loaded: google-analytics.com/analytics.js, googletagmanager.com/gtag/js (G-30F084ZHSL + UA-25825547-40), connect.facebook.net/sdk.js, youtube.com/player_api, platform.twitter.com/widgets.js, ads.biblioteka.lodz.pl/www/delivery/asyncjs.php. An unusually low number of GA cookies (missing classic _ga and _gid despite analytics.js being loaded) — the gtag configuration likely limits some storage, yet client identification still occurs through _ga_30F084ZHSL and the cid parameter in the ping.
  • 🔴 Two simultaneous CMP mechanisms were implemented — neither of them blocks trackers.
    Two consent management systems are present simultaneously on the website:
    • a custom TYPO3 cookiebox from the invest_in_lodz package (typo3conf/ext/invest_in_lodz/Resources/Public/Vendors/cookie-box/cookiebox.js) — a different package than the one in the uml_portal family, but an identical deceptive implementation,
    • Klaro CMP hosted on the central infrastructure of UMŁ: cookies.uml.lodz.pl/klaro.js, cookies.uml.lodz.pl/embed.js, and the configuration file cookies.uml.lodz.pl/cookie_config/config-c287af79d1bade7fe699eb8513f8c534.js.
    Klaro is a professional compliance solution, and its presence demonstrates an awareness of the legal obligation. In practice, however, both mechanisms load without any blocking effect — Google, Facebook, YouTube, and Twitter scripts launch before any user decision. In data_layer.json, there are no consent default or consent update commands.
  • 🔴 Data was transmitted to third parties before consent was given.
    Confirmed requests:
    • Google Analytics 4 (G-30F084ZHSL, belonging to the Municipal Library) → region1.analytics.google.com/g/collect (page_view, cid=2057842702)
    • Universal Analytics (UA-25825547-40) — cookie _gat_gtag_UA_25825547_40 set
    • DoubleClick → stats.g.doubleclick.net/g/collect (same cid)
    • Facebook SDK (without Pixel — no fbevents.js, no _fbp cookie)
    • YouTube (player_api + widgetapi)
    • Twitter widgets (iframe with origin=invest.lodz.pl)
    ads.biblioteka.lodz.pl — Municipal Library Revive Adserver (separate data controller)
    newsletter.uml.lodz.pl — a form collecting email addresses (webforms_id=5) embedded as an iframe.
  • ⚠️ External script from GitHub Pages without an integrity signature — supply chain risk.
    The site loads the countUp.js library directly from inorganik.github.io/countUp.js/dist/countUp.umd.js — GitHub Pages developer infrastructure, with no SLA and no integrity (Subresource Integrity) attribute. A public municipal page should host its own copies of external scripts or verify them with an SRI hash. The counter animation script itself does not constitute a tracker, but responsibility for front-end security requires a higher standard than inline loading from a developer's private account.
  • ⚠️ Consent Mode indicates a lack of an integrated consent signal.
    Parameters: gcd=13l3l3l2l1l1, npa=1, dma=1, dma_cps=a. A "consent not set" configuration with simultaneous forcing of non-personalized ads — despite this, the client ID (cid), session ID (sid), and page_view event are transmitted. The npa=1 flag limits personalized display, but does not turn off the provisioning of Google's audience models. Neither the invest_in_lodz cookiebox nor Klaro integrates with the Google Consent Mode layer.
  • ⚠️ YouTube partitioned cookies (CHIPS) — proper isolation.
    __Secure-ROLLOUT_TOKEN contains "partitionKey": "https://invest.lodz.pl" — matching the top-frame origin, unlike domains from the *.uml.lodz.pl family where the partitionKey was set to the parent. The GDPR violation remains (cookies collected without consent), but the classic cross-site tracking vector is closed by CHIPS isolation.

Legal and Market Context (Invest in Łódź)

invest.lodz.pl is the portal of the Investor Service Bureau of the City of Łódź — a promotional site targeted at domestic and foreign investors considering locating in Łódź. Visitor population: heads of international corporate expansion departments, investment and private equity funds, commercial real estate developers, M&A advisors, tax advisors handling expansion (including under the regime of the Act of 10 May 2018 on Supporting New Investments), and lawyers specializing in foreign investments and business relocation agencies.

Layer A — Legal. Unlike domains serving social assistance (CSS, CUWDPS), invest.lodz.pl does not fall under the elevated regime of Art. 9 GDPR. The standard violations concern Art. 5(1)(c) GDPR (data minimization principle), Art. 6 GDPR (lack of a legal basis for data transmission to third parties before consent), and Art. 26 GDPR (lack of a joint controllership declaration with the Municipal Library for GA4 property G-30F084ZHSL). The newsletter form collecting email addresses into the newsletter.uml.lodz.pl database requires separate analysis regarding marketing communication consents (Art. 10 of the Act of 18 July 2002 on Providing Services by Electronic Means, Art. 172 of the Telecommunications Law).

Layer B — Business (auto-sabotage of the site's purpose). The "corporate real estate decision makers" and "international expansion planners" segment is among the most expensive B2B segments in advertising networks — the acquisition costs for such a user in Google Ads are measured in hundreds of PLN per conversion. invest.lodz.pl transmits the visitor's identifier (cid) to a GA4 property managed by the Municipal Library and to DoubleClick — the signal enters Google's audience building models. The resulting audience segments are available to all advertisers using Google Ads, including direct competitors of cities running parallel investment promotions (Wrocław, Poznań, Kraków, Katowice, Gdańsk). The city pays to promote the "Invest in Łódź" brand, acquires a lead, and simultaneously hands over its profile to the remarketing market, where competitors can redirect their own location offers to them. The GDPR vector complements the city's brand strategy vector here — both layers lead to the exact same conclusion, just from a different angle.

Layer C — Supply Chain.⚠️⚠️⚠️⚠️⚠️ Loading the countUp.js script from a developper's private account on GitHub Pages, without SRI, is inconsistent with the operational standard of a public administration webpage. In the event of a compromise of the inorganik/countUp.js repository, the script on invest.lodz.pl could be replaced with any alternative — with the ability to execute within the context of the invest.lodz.pl origin, access newsletter forms, or intercept email addresses. This is not a theoretical risk — supply chain attacks on commonly used JavaScript libraries occur regularly (event-stream 2018, ua-parser-js 2021, popular npm packages).

Assessment summary – invest.lodz.pl

CriterionAssessmentComment
Launching trackers before consent🔴 Severe violationConfirmed by cookies_timeline + payloads
Effectiveness of implemented CMPs🔴 Low / deceptiveTwo simultaneous CMPs (invest_in_lodz cookiebox + Klaro), neither blocks tags
Data transmission to third parties🔴 YesGoogle (GA4 + UA + DoubleClick), Meta SDK, YouTube, Twitter, ads.biblioteka.lodz.pl, newsletter.uml.lodz.pl
Consent Mode Parameters⚠️ Consent not set + npa=1Signal fuels audience models despite non-personalized flag
YouTube cookies⚠️ Partitioned (CHIPS)partitionKey https://invest.lodz.pl — proper isolation
Supply chain risk⚠️ Script from GitHub Pages without SRIcountUp.js from inorganik.github.io
Auto-sabotaż celu strony🔴 YesInvestor profiles available to competing cities through Google Ads
Newsletter form⚠️ Embedded iframeCollects emails into the newsletter.uml.lodz.pl database
Overall assessment🔴 Poor (dual layer)GDPR violation + auto-sabotage of the city's promotional strategy

Verdict: Two simultaneous CMP mechanisms have been implemented on the invest.lodz.pl website (the TYPO3 cookiebox from the dedicated invest_in_lodz package and Klaro hosted on the central infrastructure cookies.uml.lodz.pl) — neither blocks the loading of trackers before the user's decision. The exact same client identity (cid) is transmitted in parallel to a GA4 property belonging to the Municipal Library and to DoubleClick. A promotional portal targeted at foreign investors transmits profiles of M&A and corporate real estate decision-makers to the Google Ads system — an audience segment highly valuable for competing cities conducting similar investment promotions. The GDPR violation superimposes onto the sabotage of the site's business objective. Additional risk: the countUp.js script is loaded from GitHub Pages without a Subresource Integrity (SRI) signature — a public municipal website should not import scripts from developer accounts without verification.

VIOLATION

https://lckm.uml.lodz.pl/

SCAN ID: 20260309_104127_b6560cd6

Data Controller: Łódzkie Centrum Kontaktu z Mieszkańcami

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL (Drupal stack differing from the standard UMŁ TYPO3 deployment, different contractor)

Requests5
Cookies5

Technical Conclusions (Scanner)

  • 🔴 Pings to two GA4 properties (own G-FFBHTEJ4R4 + the Library's G-30F084ZHSL) and DoubleClick with the same cid — before any user decision.
  • 🔴 Drupal EU Cookie Compliance v10.2.4 implemented — the mechanism sets GA cookies and then removes them retroactively (visible in timeline: 9 cookies after DOM → 5 after load). However, pings with the cid were already sent earlier. The CMP functions deceptively.
  • ⚠️ GTM configuration with an unreplaced placeholder: the ep.page_placeholder=PLACEHOLDER_page_location parameter lands as a value transmitted to Google. Indication of an unverified deployment.
  • 🔴 GA cookies set on the apex domain .uml.lodz.pl — analytical identity shared with uml.lodz.pl, bip.uml.lodz.pl, cuw.uml.lodz.pl, cuwdps.uml.lodz.pl.
  • - Consent Mode: gcd=13l3l3l2l1l1, npa=1. No Facebook SDK, no Twitter, no ads.biblioteka.lodz.pl. YouTube cookies present indirectly via the lodz.pl/livebar iframe.

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
G-FFBHTEJ4R4 G-30F084ZHSL
Policy Assessment: Cross-controller identity sharing (the same cid to its own LCKM GA4 and the Municipal Library GA4) without a joint controllership declaration (Art. 26 GDPR). Retroactive CMP — cookies deleted after the fact, but pings containing the client identifier are already transmitted.
📄 Show Domain Assessment

Conclusions and Violations

  • 🔴 Retroactive cookie clearing — deceptive mechanism. Drupal EU Cookie Compliance v10.2.4 (+ custom mod) sets GA cookies (_ga, _ga_FFBHTEJ4R4, _ga_30F084ZHSL) and subsequently deletes them between the after_domcontentloaded and after_load stages. Pings to region1.google-analytics.com/g/collect and stats.g.doubleclick.net/g/collect with cid=1220176430 were dispatched prior to the clearing. Technical effect: the client identifier is transmitted to Google despite a deceptive "no GA cookies" configuration.
  • 🔴 Two GA4 properties with the same cid. The dedicated property G-FFBHTEJ4R4 (LCKM) and G-30F084ZHSL (belonging to the Municipal Library) receive the exact same client identifier in concurrent calls. Cross-controller identity sharing occurs without a joint controllership declaration within the meaning of Art. 26 GDPR. DoubleClick (stats.g.doubleclick.net/g/collect) also receives the same cid.
  • 🔴 Cross-subdomain scope cookies GA on .uml.lodz.pl. The same analytical identity is shared across the uml.lodz.pl, bip.uml.lodz.pl, cuw.uml.lodz.pl, and cuwdps.uml.lodz.pl domain family. The measurement identifies the identical user across five formally distinct municipal services.
  • ⚠️ Unverified GTM configuration — placeholder inside an event parameter value. The parameter ep.page_placeholder=PLACEHOLDER_page_location is transmitted to Google within every /g/collect call. The developer copied a configuration template and failed to substitute the placeholder with the actual dynamic URL retrieval function. A clear sign that the deployment was not verified post-launch. Additionally, developer_id.dMDhkMT is present within data_layer.json — a Google Analytics developer ID assigned to integration agencies, indicating the implementation was executed by an external vendor.
  • ⚠️ Consent Mode: lack of an integrated consent signal. The parameters gcd=13l3l3l2l1l1, npa=1, dma=1 are present. A "consent not set" state with non-personalized ads — despite this, cid, sid, and page_view are transmitted. EU Cookie Compliance does not integrate with the Google Consent Mode layer.
  • ⚠️ Livebar iframe acting as an indirect source of YouTube cookies. No direct YouTube scripts occur within scripts_dom.json, but the cookie jar contains __Secure-YNID, YSC, VISITOR_INFO1_LIVE, __Secure-ROLLOUT_TOKEN, and VISITOR_PRIVACY_METADATA — originating from the lodz.pl/livebar/ iframe, which internally embeds YouTube elements. The partitionKey resolves to https://uml.lodz.pl (not lckm.uml.lodz.pl) — a recurring feature of this domain family.

Assessment summary – lckm.uml.lodz.pl

CriterionAssessment
Launching trackers before consent🔴 Severe violation
Effectiveness of CMP (Drupal EU Cookie Compliance)🔴 Retroactive clearing — deceptive
Cross-controller identity sharing🔴 Two GA4 properties with the same cid
Cross-subdomain scope🔴 Entire .uml.lodz.pl family
Configuration Hygiene⚠️ Unreplaced placeholder
Third-party (Facebook, Twitter, ads.biblioteka)✅ None
Overall assessment🔴 Poor (Drupal with a deceptive CMP)

Verdict: LCKM is the first domain of the *.uml.lodz.pl family built on Drupal — running the EU Cookie Compliance v10.2.4 module, which instead of blocking GA cookies, sets them and clears them retroactively. Pings containing the cid reach two GA4 properties (the dedicated LCKM one and the Municipal Library one) as well as DoubleClick before the clearing mechanism can execute. The GTM configuration contains an unreplaced placeholder, and the implementation was performed by an external vendor (indicated by the visible developer_id).

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

Only cookies policy present; missing GDPR information clause

📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://li.lodz.pl/

SCAN ID: 20260309_104127_03e9a4c1

Data Controller: Łódzkie Inwestycje sp. z o.o.

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests8
Cookies9

Technical Conclusions (Scanner)

  • 🔴 Tracking tags were firing immediately upon entry, before the user's decision. Pings to GA4 property G-30F084ZHSL (Municipal Library) + shared UA container UA-25825547-40 + DoubleClick — all sharing the identical cid=94267638.
  • 🔴 The TYPO3 cookiebox (uml_portal package) does not block tracker initialization — a deceptive mechanism. Klaro is absent.
  • 🔴 Recipients: Google (GA4 + UA + DoubleClick), Facebook SDK, YouTube, Twitter iframe, ads.biblioteka.lodz.pl, lodz.pl/livebar.js. Consent Mode shows gcd=13l3l3l2l1l1, npa=1.
  • - 9 tracking cookies remain (4× GA, 5× YouTube). Cross-domain scope on .li.lodz.pl (internal). YouTube partitionKey https://li.lodz.pl — correctly set.

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
UA-25825547-40 G-30F084ZHSL
Policy Assessment: A municipal limited liability company uses the GA4 property of the Municipal Library and the shared UA container of municipal entities — establishing cross-controller identity sharing between distinct legal entities without a public data processing/joint controllership agreement (Art. 26/28 GDPR). Standard GDPR violations combined with a Public Procurement Law vector for tender information.
📄 Show Domain Assessment

Conclusions and Violations

  • 🔴 Tracking tags initialized before consent. GA cookies (_ga, _ga_30F084ZHSL, _gid, _gat_gtag_UA_25825547_40) and YouTube cookies are set after after_domcontentloaded. Payloads hit: region1.google-analytics.com/g/collect (G-30F084ZHSL Library), region1.analytics.google.com/g/collect (UA-25825547-40), and stats.g.doubleclick.net/g/collect — all matching on cid=94267638.
  • 🔴 Deceptive TYPO3 Cookiebox. typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js loads but fails to block tag execution. No consent commands exist in the data_layer. Klaro is absent.
  • 🔴 Cross-controller identity sharing. The exact same cid is transmitted to GA4 G-30F084ZHSL (Municipal Library) and to the shared UA-25825547-40 container (municipal domain family). Łódzkie Inwestycje operates as a limited liability company — meaning it is a distinct legal entity and an independent data controller relative to both the City of Łódź and the Municipal Library. There is no public declaration of joint controllership (Art. 26 GDPR) or a data processing agreement (Art. 28 GDPR).
  • 🔴 Third-party recipients without consent: Google (GA4 + UA + DoubleClick), Meta (Facebook SDK, without Pixel), YouTube (player_api + widgetapi), Twitter (widgets.js + iframe with origin=li.lodz.pl), ads.biblioteka.lodz.pl (the Library's Revive Adserver), and lodz.pl/livebar.js.
  • ⚠️ Consent Mode is "consent not set": gcd=13l3l3l2l1l1, npa=1, dma=1. The behavioral signal feeds Google's audience modeling infrastructure despite the non-personalized ads flag.
  • ⚠️ Public Procurement Context (PZP). The website provides details regarding public procurement procedures with links redirecting to the BIP. Contractors interacting within public bidding tracks are subject to the duties outlined in the Act of 11 September 2019 — Public Procurement Law; exporting their cid to Google/DoubleClick stretches far outside the processing boundaries established for public tenders.

Assessment summary – li.lodz.pl

CriterionAssessment
Launching trackers before consent🔴 Severe violation
Effectiveness of CMP (cookiebox TYPO3)🔴 Deceptive
Cross-controller identity sharing🔴 Limited company uses the Library's property
Transmission to third-parties🔴 Full uml_portal family stack
Consent Mode⚠️ Consent not set + npa=1
Legal Context⚠️ Public Procurement Law + distinct legal personality
Overall assessment🔴 Poor

Verdict: Follows the standard pattern of the uml_portal family (deceptive cookiebox, full third-party stack, identical cid pushed to two separate Google containers + DoubleClick). Critical legal parameter: Łódzkie Inwestycje is a limited liability company — an entirely separate legal person from the City of Łódź and the Municipal Library. Shared use of this measurement infrastructure (the Library's GA4 property, shared UA container) occurs without a public joint controllership declaration under Art. 26 GDPR or a data processing agreement under Art. 28 GDPR. The visiting population includes economic operators involved in public procurement tracks — bringing an additional regulatory intersection with the Public Procurement Law (PZP).

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

"Klauzula Informacyjna" (Information Clause) link in the footer

📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://mops.uml.lodz.pl/

SCAN ID: 20260309_104129_ee8767e9

Data Controller: Miejski Ośrodek Pomocy Społecznej

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests8
Cookies10

Technical Conclusions (Scanner)

  • 🔴 GA4 (G-30F084ZHSL) and UA (UA-25825547-40) initialized with gcd=13l3l3l2l1l1 + npa=1 + pscdl=noapi — lack of Consent Mode integration with cookie-box
  • 🔴 Cross-controller: GA4 property G-30F084ZHSL (Municipal Library) active on MOPS subdomain (social assistance)
  • ⚠️ Facebook SDK (connect.facebook.net/pl_PL/sdk.js) loaded, but without an active Pixel (missing fbevents.js, _fbp, and signals/config calls)
  • - YouTube widget API + Twitter widgets.js + lodz.pl/livebar/ iframe → third-party cookies (VISITOR_INFO1_LIVE, YSC) without first-party control
  • - CMP: cookie-box.js (TYPO3 uml_portal) present; F5 BIG-IP (TS01a62d2a, TS01619efc) — load balancer infrastructure
  • - Cookie timeline stable (before_navigation = 0, no retroactive clearing); localStorage/sessionStorage empty

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
G-30F084ZHSL UA-25825547-40
Policy Assessment: No mention of joint controllership (Art. 26 GDPR) with the Municipal Library regarding the use of GA4 property G-30F084ZHSL on the MOPS subdomain. The domain processes special categories of data belonging to social assistance clients (Art. 9 GDPR + Social Assistance Act of March 12, 2004). The cookie-box CMP does not pass signals to gtag — a classic blueprint of the uml.lodz.pl family.
📄 Show Domain Assessment

Conclusions and Violations

  • 🔴 Lack of integrated Consent Mode — the GA4 beacon routed to region1.analytics.google.com/g/collect contains gcd=13l3l3l2l1l1 (all "l" characters = signal not set), npa=1, pscdl=noapi, and dma=1. The page signals neither consent nor refusal — a classic pre-Consent Mode setup. Unlike the municipal domains of Łódź (which at minimum dispatch gcd=13l3l3l2l1l1 as a fallback "consent not set"), lodz.praca.gov.pl contains no signaling whatsoever.
  • 🔴 Cross-controller identity sharing — GA4 property G-30F084ZHSL (owned by the Municipal Library in Łódź) is configured and actively pinged on mops.uml.lodz.pl. The client identifier cid=1271838583.1773049290 is shared across the entire lodz.pl/uml.lodz.pl ecosystem. This establishes a violation of Art. 26 GDPR (joint controllership operating without transparency).
  • 🔴 Legacy UA remains active — container UA-25825547-40 (the shared tracking container for the municipal family) is loaded concurrently with GA4 via gtag.js. Universal Analytics was retired by Google in 2023, yet it still generates network events and drops _gid / _gat_gtag_UA_25825547_40 cookies.
  • ⚠️ Facebook SDK without the Pixel — two instances of connect.facebook.net/pl_PL/sdk.js were detected (including one utilizing the xfbml=1 parameter). However, fbevents.js, the _fbp cookie, and signals/config/<ID> requests are missing. The SDK itself does not perform active tracking in this setup, but it expands the front-end attack surface and facilitates dropping a tracking pixel in the future without modifying the CMP.
  • ⚠️ Third-party widgets on a social assistance domain — the page embeds the YouTube player_api + widgetapi, the Twitter widgets.js script + iframe, and the UMŁ livebar widget (lodz.pl/livebar/). These components drop VISITOR_INFO1_LIVE, YSC, and __Secure-ROLLOUT_TOKEN cookies, enabling profiling beyond the control of the MOPS administrator.
  • ⚠️ CMP is technically present but ineffective against Google — the script /typo3conf/ext/uml_portal/Resources/Public/Vendors/cookie-box/cookiebox.js (TYPO3) loads successfully but lacks consent default / consent update integration with the data_layer. Tracking payloads confirm that Google tags initialize before any interaction with the banner.
  • ⚠️ No tracking data stored in storage — localStorage and sessionStorage remain empty (missing variables like _fbp, _gcl_ls, or google_auto_fc_cmp_setting). The cookie timeline is stable — indicating zero retroactive cleaning anomalies.

Legal Context (Municipal Social Assistance Center in Łódź)

MOPS acts as an organizational unit for social welfare, executing the statutory local government tasks outlined in the Social Assistance Act of 12 March 2004. The portal serves citizens navigating difficult life situations — processing special categories of data concerning health, financial status, family stability, or dependencies under the strict protective scope of Art. 9 GDPR. The mops.uml.lodz.pl domain is bound to an elevated data protection standard.

Layer A — controller's compliance culture. The administrator (MOPS / UMŁ) deployed the cookie-box CMP but failed to tie it to Google's Consent Mode or block tag execution before consent is obtained. Furthermore, a GA4 property belonging to an independent third party (the Municipal Library) is actively leveraged without a transparent joint controllership arrangement under Art. 26 GDPR. This represents a systemic structural flaw rather than an isolated front-end accident.

Layer B — market value of the behavioral profile. Behavioral metrics reflecting social welfare clients (individuals seeking financial or logistical assistance) represent a high-risk profile targeted for the classification of vulnerable demographic groups (poverty, structural exclusion, health crises). Exposing this signal via a shared GA4 asset heightens the risk of secondary exploitation beyond the statutory public mandate of MOPS.

Assessment summary – mops.uml.lodz.pl

CriterionAssessment
Launching trackers before consent🔴 Yes — GA4/UA running with gcd=13l3l3l2l1l1 and pscdl=noapi
CMP Effectiveness⚠️ Present (cookie-box), but disconnected from Google Consent Mode
Data transmission to third parties🔴 Yes — shared GA4 property of the Library + YouTube/Twitter SDK/iframes
Cross-controller identity🔴 Active deployment (G-30F084ZHSL on MOPS)
Facebook Pixel✅ Inactive (SDK loads but drops no beacons or _fbp cookie)
Overall assessment🔴 Severe violation — Google tracking tags launch without an effective consent flag on a domain handling special categories of personal data

Verdict: On mops.uml.lodz.pl, Google Analytics 4 (G-30F084ZHSL) and legacy Universal Analytics (UA-25825547-40) initialize with the configuration metrics gcd=13l3l3l2l1l1 + pscdl=noapi prior to any user choice. The cookie-box CMP fails to communicate consent signals to Google. Additionally, cross-controller sharing occurs with the Municipal Library on a social assistance subdomain processing special categories of personal data under Art. 9 GDPR. This violates the core principles of data minimization and lawfulness of processing (Art. 5 and 6 GDPR) along with the structural joint controllership transparency mandates of Art. 26 GDPR. The Facebook Pixel is inactive, though loading the SDK on this specific domain warrants an independent risk assessment.

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

Detected in incognito: The cookie banner routes to UMŁ. A dedicated GDPR page maps the DPO and specific information clauses.

📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://mzz.lodz.pl/

SCAN ID: 20260309_104148_f5fd6c65

Data Controller: Miejski Zespół Żłobków

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests8
Cookies10

Technical Conclusions (Scanner)

  • 🔴 GA4 G-30F084ZHSL (Municipal Library) + legacy UA UA-25825547-40 running with gcd=13l3l3l2l1l1 + npa=1 + pscdl=noapi — lack of Consent Mode integration with cookie-box
  • 🔴 The cookie-box.js CMP is present but disconnected from Google Consent Mode — tracking tags fire prior to user consent
  • ⚠️ Facebook SDK + YouTube widget API + Twitter widgets + lodz.pl/livebar/ iframe
  • - F5 BIG-IP cookie (TS014e08b6) — load balancer infrastructure
  • - Timeline is stable (before_navigation = 0). No retroactive cookie clearing.
  • - No dedicated GA4 property found for the nursery center — only shared G-30F084ZHSL + legacy UA

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
G-30F084ZHSL UA-25825547-40
Policy Assessment: Active marketing tracking on the nursery portal (an entity managing care for the youngest children) operating without valid consent. The G-30F084ZHSL property (Municipal Library) functions cross-controller. The cookie-box CMP fails to convey consent signals to Google.
📄 Show Domain Assessment

Conclusions and Violations

  • 🔴 GA4 + legacy UA running without Consent Mode — active beacon to G-30F084ZHSL carrying the configuration metrics gcd=13l3l3l2l1l1, npa=1, and pscdl=noapi. The cookie-box.js CMP completely fails to map consent status out to Google's Consent API.
  • 🔴 Cross-controller sharing on a nursery domain — a GA4 property owned and controlled by the Municipal Library (G-30F084ZHSL) is actively deployed on the Miejski Zespół Żłobków interface. Operates without a transparent joint controllership arrangement under Art. 26 GDPR.
  • ⚠️ Facebook SDK + third-party widgetsconnect.facebook.net/pl_PL/sdk.js, the YouTube widget API, and the Twitter widgets.js library are initialized. The lodz.pl/livebar/ iframe is also parsed into the front-end layout.
  • - CMP is technically present but ineffective against Googlecookie-box.js (TYPO3) is executed, yet Google tracking tags initialize and route data regardless of user preferences.
  • - Infrastructure layer — the F5 BIG-IP cookie (TS014e08b6) is correctly classified as a persistent load balancing asset. The cookie jar lifecycle remains stable.

Legal Context (Municipal Nursery Center in Łódź)

Miejski Zespół Żłobków w Łodzi operates as an organizational unit of the City of Łódź, handling early child care for toddlers aged 0–3. The website handles informational and enrolment/recruitment processes and is heavily frequented by parents of young children. While it does not structurally harvest special categories of data within the strict definitions of Art. 9 GDPR, the specific demographic profile (early childhood care logistics) demands an elevated standard of compliance and privacy safeguarding.

Layer A — controller's compliance culture. The administrator deployed the standard package cookie-box CMP but left it disconnected from Google's Consent Mode infrastructure. A shared GA4 analytics asset belonging to an external entity (the Municipal Library) is integrated without transparent fulfillment of Art. 26 GDPR. This reflects a systemic operational oversight on a site handling early childhood care resources.

Layer B — market value of the behavioral profile. A nursery-focused domain maps behavioral trends reflecting parental care structures and early registration paths — a segment targeted for commercial family-focused profiling. Distributing this signal out via a shared GA4 asset expands exposure to secondary data exploitation far outside the statutory public remit of the nursery center.

Assessment summary – mzz.lodz.pl

CriterionAssessment
Launching trackers before consent🔴 Yes — GA4 + UA running with gcd=13l3l3l2l1l1 and pscdl=noapi
CMP Effectiveness⚠️ Present (cookie-box), but disconnected from Google Consent Mode
Data transmission to third parties🔴 Yes — shared G-30F084ZHSL property + YouTube/Twitter widgets + livebar widget
Cross-controller identity🔴 Active deployment (G-30F084ZHSL running on the nursery portal)
Facebook Pixel✅ Inactive (Only the SDK loads, dropping no beacons)
Overall assessment🔴 Severe violation — tracking tags initialize without an effective consent signal on a public nursery domain

Verdict: On mzz.lodz.pl, Google Analytics 4 (G-30F084ZHSL) and legacy Universal Analytics (UA-25825547-40) initialize with the configuration metrics gcd=13l3l3l2l1l1 + pscdl=noapi prior to any user choice. The cookie-box CMP fails to convey consent signals to Google. Furthermore, cross-controller data sharing occurs with the Municipal Library on an early childhood domain. This violates the core principles of data minimization and lawfulness of processing (Art. 5 and 6 GDPR) along with the structural joint controllership transparency mandates of Art. 26 GDPR. The early childhood context accentuates the gravity of the tracking setup.

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

Detected in incognito mode: the cookie banner routes to UMŁ. A dedicated GDPR page lists the DPO and specific information clauses.

📁 Show Hard Evidence (HAR, Cookies, Trace)
🔴 VIOLATION

https://rewitalizacja.uml.lodz.pl/

SCAN ID: 20260309_104150_9c36cb31

ADO: Revitalization Office of the Łódź City Office

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests 6
Cookies 4

Technical Conclusions (Scanner)

  • Consent Mode is NOT configured — gcd=13l3l3l2l2l1 (all “l” = consent not set). No gcs parameter and pscdl=noapi. Identical to domains rated 🔴.
  • npa=0 is hardcoded in the tag — allow_ad_personalization_signals: true + allow_display_features: true in data_layer.json (config G-1EC6G25418). Does not come from CMP or user decision.
  • Cookies before consent — after_domcontentloaded, before_navigation=0: _ga (valid until April 2027), _gid, _gat, _ga_1EC6G25418. Pattern identical to 🔴 rated domains.
  • ⚠️ Legacy UA fires full pageview before consent — /j/collect tid=UA-113466830-1, status 200. Response body contains „2,cG-1EC6G25418” (dual-tagging, is_legacy_loaded: true).
  • ⚠️ Additional third-party trackers — platform.twitter.com/widgets.js + two instances of connect.facebook.net (SDK), rufous-sandbox iframe (Twitter telemetry/scribe).
  • Dedicated GA4 property G-1EC6G25418 (not shared with other UMŁ domains)
  • No Facebook Pixel, Google Ads Conversion, Crazy Egg or session recording

Privacy Policy Analysis vs Tags

Identified Container IDs:
G-1EC6G25418 UA-113466830-1
Privacy Policy Assessment: Violation of the principles of data minimization and lawfulness of processing. GA4 + legacy UA tracking launched without an effective consent signal. CMP cookie-box.js present, but not integrated with Consent Mode (no consent default / consent update commands in dataLayer). npa=0 is hardcoded, does not result from user decision. Additional Twitter scripts and Facebook SDK.
📄 Show Domain Assessment

Conclusions and Violations

  • Lack of effective Consent Mode — GA4 beacon to region1.google-analytics.com/g/collect carries gcd=13l3l3l2l2l1. All letter positions are “l” = consent not set. No gcs and pscdl=noapi. In data_layer.json there is no consent default or consent update command.
  • npa=0 does not come from CMP — in data_layer.json it is clearly visible: allow_ad_personalization_signals: true and allow_display_features: true in the config command for G-1EC6G25418. This is a static implementation flag. In a sterile session (without interaction) ad personalization is explicitly allowed.
  • Cookies set before consent — timeline: before_navigation = 0after_domcontentloaded = full set _ga, _gid, _gat, _ga_1EC6G25418. _ga valid until April 2027 (cookie_expires: 63072000).
  • Legacy UA fires pageview before consent/j/collect?tid=UA-113466830-1 status 200. Response body contains „2,cG-1EC6G25418” — confirmation of dual-tagging (is_legacy_loaded: true).
  • ⚠️ Additional third-party trackersplatform.twitter.com/widgets.js + two instances of connect.facebook.net (SDK, no Pixel), rufous-sandbox iframe (Twitter telemetry/scribe/analytics).
  • Dedicated GA4 propertyG-1EC6G25418 (no allegation of data sharing under art. 26 RODO, unlike G-30F084ZHSL).
  • Lack of aggressive marketing tracking — no Facebook Pixel, Google Ads Conversion ID or Crazy Egg / session recording detected.

Legal Context (Revitalization Portal)

The Revitalization Portal is a dedicated website for the Łódź revitalization project (financed, among others, from EU funds). It has an informational and communication character. It does not process special categories of data and does not conduct aggressive advertising monetization.

Layer A — culture of administrator compliance. Poor. cookie-box.js CMP is loaded, but does not transmit a real consent signal to Google (no Consent Mode integration, all-l type gcd, hardcoded npa=0). Analytical tracking (GA4 + legacy UA) and additional scripts are launched before any user decision — exactly the same as in negatively rated domains.

Layer B — market value of behavioral signal. Low. The site has an informational character (revitalization, maps, documents). It does not generate attractive data for advertising audience profiling.

Summary of assessment – rewitalizacja.uml.lodz.pl

CriterionAssessment
Firing trackers before consent❌ Cookies (_ga*) and GA4/UA beacon set after DOMContentLoaded, before_navigation=0
CMP Effectiveness❌ Present (cookie-box.js), but not integrated with Consent Mode (no consent update, gcd=13l3l3l2l2l1)
Transmission to third parties⚠️ GA4 + legacy UA + Twitter widgets + FB SDK + rufous-sandbox
Facebook Pixel✅ Inactive (only SDK, no Pixel config and _fbp)
Google Ads / Conversion✅ None
Overall assessment❌ Negative / Violation — tracking without effective consent signal (identical to shelter and zzm)

Verdict: On rewitalizacja.uml.lodz.pl a dedicated GA4 property (G-1EC6G25418) was implemented and there is no Pixel or Google Ads Conversion — these are real positives compared to some other UMŁ domains. However, the violation mechanism is identical: full analytical cookies + GA4/UA beacon + legacy UA launched before consent, cookie-box CMP without Consent Mode integration (all-l gcd, hardcoded npa=0, no consent commands in dataLayer) and additional Twitter and Facebook SDK trackers. According to the legend from July 7, it qualifies directly for 🔴 VIOLATION.

📸 Evidence: Page Snapshots and GDPR Documents
📌 Notes from policy scan:

Detected in incognito: local cookies and dedicated RODO page in the menu.

📁 Show Hard Evidence (HAR, Cookies, Trace)
MEDIUM

https://nowa.mapa.lodz.pl/

SCAN ID: 20260309_104149_87917d65

Data Controller: InterSIT — Łódzki Ośrodek Geodezji

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests2
Cookies6

Technical Conclusions

  • ⚠️The gcd parameter was detected in tracking requests, signaling incomplete Consent Mode integration.
  • ⚠️A gcd string was dispatched without an accompanying gcs value in a subset of telemetry requests.
  • -After the session, 5 potentially tracking cookies remain persistent within the cookie jar.

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
G-JQ5N1LX76Z
Privacy Policy Assessment: The privacy policy accurately declares the use of the identified tracking codes, or no deliberate concealment was found (Full Alignment between public declarations and factual implementation).
📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

Link located in the footer

📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://schronisko.uml.lodz.pl/

SCAN ID: 20260309_104209_93f8cd81

Data Controller: Schronisko dla Zwierząt w Łodzi

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests8
Cookies9

Technical Conclusions (Scanner)

  • 🔴 GA4 G-30F084ZHSL (Municipal Library) + legacy UA UA-25825547-40 running with gcd=13l3l3l2l1l1 + npa=1 + pscdl=noapi — lack of Consent Mode integration with cookie-box
  • 🔴 The cookie-box.js CMP is present but disconnected from Google Consent Mode — tracking tags fire prior to user consent
  • ⚠️ Facebook SDK + YouTube widget API + Twitter widgets + lodz.pl/livebar/ iframe
  • - F5 BIG-IP cookie (TS014e08b6) — persistent load balancing cookie correctly classified
  • - Timeline is stable (before_navigation = 0). No retroactive cookie clearing detected.
  • - No dedicated GA4 property found for the shelter portal — running only shared G-30F084ZHSL + legacy UA

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
G-30F084ZHSL UA-25825547-40
Policy Assessment: Cross-controller sharing of the Municipal Library's GA4 property occurs on the animal shelter portal. The cookie-box CMP fails to convey consent signals to Google. Follows the standard blueprint of the uml_portal domain family.
📄 Show Domain Assessment

Conclusions and Violations

  • 🔴 The Library's GA4 property running without Consent Mode — an active beacon to G-30F084ZHSL transmits the configuration metrics gcd=13l3l3l2l1l1, npa=1, and pscdl=noapi. The cookie-box.js CMP completely fails to map consent status out to Google's Consent API, making the implementation deceptive.
  • 🔴 Cross-controller data sharing on the shelter domain — a GA4 property owned and controlled by the Municipal Library is actively deployed on the animal shelter portal. This operates without a transparent joint controllership arrangement or disclosure under Art. 26 GDPR.
  • ⚠️ Facebook SDK + third-party widgetsconnect.facebook.net/pl_PL/sdk.js, the YouTube widget API, and the Twitter widgets.js library are initialized. The lodz.pl/livebar/ iframe is also parsed into the frontend layout, leaking traffic metadata.
  • ⚠️ Legacy UA remains active — container UA-25825547-40 is configured and executed concurrently alongside GA4 layers despite its universal deprecation.
  • ⚠️ The Library's ad server — active injection of ads.biblioteka.lodz.pl/www/delivery/asyncjs.php loads third-party components from an external platform without prior consent filters.

Legal Context (Animal Shelter in Łódź)

The Animal Shelter in Łódź is a municipal unit executing localized public care and animal control mandates. The portal serves a strong community adoption and informational focus. While it does not structurally process special categories of data under Art. 9 GDPR, public units interfacing with civic engagement parameters are bound to clean compliance baselines and operational transparency.

Layer A — controller's compliance culture. The administrator deployed the framework's default cookie-box CMP but left it disconnected from Google's Consent Mode infrastructure. A shared analytics container belonging to an external entity (the Municipal Library) is embedded without a joint controllership layout. This maps as an unverified deployment sequence typical of the uml_portal ecosystem.

Layer B — market value of the behavioral profile. Moderate. The domain maps interest segments focusing on domestic pet adoption, veterinary visibility paths, and local community assistance. Exposing these telemetry hits to a shared framework increases vulnerability to unintended commercial profiling.

Domain assessment summary – schronisko.uml.lodz.pl

CriterionAssessment
Launching trackers before consent🔴 Yes — GA4 + UA running with gcd=13l3l3l2l1l1 and pscdl=noapi
CMP Effectiveness⚠️ Present (cookie-box), but disconnected from Google Consent Mode
Data transmission to third parties🔴 Yes — shared G-30F084ZHSL property + YouTube/Twitter widgets + livebar widget
Cross-controller identity🔴 Active deployment (G-30F084ZHSL running on the shelter portal)
Facebook Pixel✅ Inactive (Only the SDK loads, dropping no beacons)
Overall assessment🔴 Negative — tracking tags initialize without an effective consent signal on a public municipal domain

Verdict: On schronisko.uml.lodz.pl, Google Analytics 4 (G-30F084ZHSL) and legacy Universal Analytics (UA-25825547-40) initialize with the configuration metrics gcd=13l3l3l2l1l1 + pscdl=noapi prior to any user choice. The cookie-box CMP fails to convey consent signals to Google. Furthermore, cross-controller data sharing occurs with the Municipal Library on a local public sector site, establishing a breach of data minimization and lawfulness of processing (Arts. 5 and 6 GDPR) along with the structural joint controllership mandates of Art. 26 GDPR.

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

Detected in incognito mode: the cookie banner routes to UMŁ central targets, but the shelter's BIP endpoint hosts standalone information clauses.

📁 Show Hard Evidence (HAR, Cookies, Trace)
POSITIVE

https://wizyty.uml.lodz.pl/

SCAN ID: 20260309_104213_8cf5c6dd

ADO: Łódź City Office (visit reservation)

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests0
Cookies2

Technical Conclusions

  • No marketing tracking. Only session and infrastructural cookies present (PHPSESSID + F5 BIG-IP).

Assessment

Assessment: Clean domain — no violations found in the area of marketing tracking.
📸 Evidence: Page Snapshots and GDPR Documents
📌 Notes from policy scan:

Detected in incognito: policies are linked only in the "Book a visit" step in the form (they redirect to the UMŁ BIP).

📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://strazmiejska.lodz.pl/

SCAN ID: 20260309_104212_8ebcd5a3

Data Controller: Straż Miejska w Łodzi (Municipal Police)

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests14
Cookies9

Technical Conclusions (Scanner)

  • 🔴 GA4 G-30F084ZHSL (Municipal Library) + legacy UA UA-25825547-40 running with gcd=13l3l3l2l1l1 + npa=1 + pscdl=noapi — lack of Consent Mode integration with cookie-box
  • 🔴 The cookie-box.js CMP is present but disconnected from Google Consent Mode — tracking tags fire prior to user consent
  • ⚠️ Facebook SDK + YouTube widget API + Twitter widgets + lodz.pl/livebar/ iframe
  • - F5 BIG-IP cookie (TS01619efc) — infrastructure load balancer cookie
  • - The Municipal Library's ad server link (ads.biblioteka.lodz.pl) is active
  • - Cookie timeline is stable (before_navigation = 0). No retroactive cookie clearing detected.

Privacy Policy Analysis vs Tags

Identified Container Identifiers:
G-30F084ZHSL UA-25825547-40
Policy Assessment: Cross-controller sharing of the Municipal Library's GA4 property occurs on the Municipal Police portal. The cookie-box CMP fails to convey consent signals to Google. Follows the standard template pattern of the uml_portal domain family.
📄 Show Domain Assessment

Conclusions and Violations

  • 🔴 The Library's GA4 property running without Consent Mode — an active beacon to G-30F084ZHSL transmits the configuration metrics gcd=13l3l3l2l1l1, npa=1, and pscdl=noapi. The cookie-box.js CMP completely fails to map consent status out to Google's Consent API.
  • 🔴 Cross-controller data sharing on the Municipal Police domain — a GA4 property owned and controlled by the Municipal Library is actively deployed on the Straż Miejska portal. This operates without a transparent joint controllership arrangement or disclosure under Art. 26 GDPR.
  • ⚠️ Facebook SDK + third-party widgetsconnect.facebook.net/pl_PL/sdk.js, the YouTube widget API, and the Twitter widgets.js library are initialized. The lodz.pl/livebar/ iframe is also parsed into the frontend layout.
  • ⚠️ Legacy UA remains active — container UA-25825547-40 is configured and executed concurrently alongside GA4 layers despite its universal deprecation.
  • ⚠️ The Library's ad server — active injection of ads.biblioteka.lodz.pl/www/delivery/asyncjs.php loads components from an external platform without prior consent filters.

Legal Context (Straż Miejska w Łodzi — Municipal Police)

Straż Miejska w Łodzi is a public order enforcement unit executing localized municipal policing, intervention tracking, and civic safety reporting. The portal serves an important community security and informational focus. Frequented by citizens filing local complaints or tracking civic enforcement status, this public framework demands rigorous compliance baseline parameters and absolute operational transparency regarding tracking scripts.

Layer A — controller's compliance culture. The administrator deployed the standard package cookie-box CMP but left it completely disconnected from Google's Consent Mode infrastructure. A shared analytics container belonging to an external entity (the Municipal Library) is embedded without a joint controllership layout. This maps as an unverified deployment sequence typical of the uml_portal ecosystem.

Layer B — market value of the behavioral profile. Moderate. The domain maps interest segments focusing on local safety enforcement tracking, citation information, and localized intervention queries. Exposing these telemetry hits to a shared framework increases vulnerability to unintended commercial profiling.

Assessment summary – strazmiejska.lodz.pl

CriterionAssessment
Launching trackers before consent🔴 Yes — GA4 + UA running with gcd=13l3l3l2l1l1 and pscdl=noapi
CMP Effectiveness⚠️ Present (cookie-box), but disconnected from Google Consent Mode
Data transmission to third parties🔴 Yes — shared G-30F084ZHSL property + YouTube/Twitter widgets + livebar widget
Cross-controller identity🔴 Active deployment (G-30F084ZHSL running on the Municipal Police portal)
Facebook Pixel✅ Inactive (Only the SDK loads, dropping no beacons)
Overall assessment🔴 Negative — tracking tags initialize without an effective consent signal on a public municipal domain

Verdict: On strazmiejska.lodz.pl, Google Analytics 4 (G-30F084ZHSL) and legacy Universal Analytics (UA-25825547-40) initialize with the configuration metrics gcd=13l3l3l2l1l1 + pscdl=noapi prior to any user choice. The cookie-box CMP fails to convey consent signals to Google. Furthermore, cross-controller data sharing occurs with the Municipal Library on a local public safety site, establishing a breach of data minimization and lawfulness of processing (Arts. 5 and 6 GDPR) along with the structural joint controllership mandates of Art. 26 GDPR.

📸 Evidence: Snapshots of Pages and GDPR Documents
📌 Notes from policy scan:

Nothing on the homepage. There is a GDPR page listed on the BIP, but the active cookie banner links directly to a 404 error page.

📁 Show Hard Evidence (HAR, Cookies, Trace)
POSITIVE

https://wsparcie.uml.lodz.pl/

SCAN ID: 20260309_104231_a18b770e

ADO: Łódź City Office Social Support Portal

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests2
Cookies7

Technical Conclusions (Scanner)

  • No GA4, UA, Facebook Pixel, Google Ads or other marketing trackers
  • - Only lodz.pl/livebar/ + YouTube cookies (with partitionKey) present
  • - Cookies: ASP.NET_SessionId (httpOnly), XSRF-TOKEN, F5 BIG-IP
  • - Data Layer empty — no GTM / gtag
  • - No CMP (not required due to absence of marketing trackers)

Privacy Policy Analysis vs Tags

Identified Container IDs:
No GA4 / UA / Google Ads / Pixel
Privacy Policy Assessment: No marketing tracking identified. Only municipal livebar + YouTube embed (likely from livebar) present. Actual state consistent with no violations in the area of marketing data processing.
📄 Show Domain Assessment

Conclusions and Violations

  • No marketing tracking — no GA4, legacy UA, Facebook Pixel or Google Ads detected. Data Layer is empty.
  • ⚠️ Livebar + YouTubelodz.pl/livebar.js and YouTube cookies (with partitionKey) loaded. These are the only third-party elements.
  • - Standard application cookiesASP.NET_SessionId (httpOnly) + XSRF-TOKEN + F5 BIG-IP. No GA / _fbp / _gcl_au cookies.
  • - No CMP — not required because no marketing trackers requiring consent were launched.

Legal Context (Social Support Portal)

The domain wsparcie.uml.lodz.pl is a resident account portal for social benefits, life situation self-diagnosis and register of non-governmental organization services. It processes data on residents' material, family and health situation — including data that may belong to special categories (art. 9 RODO).

Layer A — culture of administrator compliance. Very good in terms of marketing tracking. No GA4 or Pixel launched on a portal with sensitive data. The only third-party is the municipal livebar.

Layer B — market value of behavioral signal. Low. The portal is purely service-oriented (benefits, applications, self-diagnosis). This data has very limited commercial value and should not be marketing-profiled.

Summary of assessment – wsparcie.uml.lodz.pl

CriterionAssessment
Firing trackers before consent✅ No — no GA4 / UA / Pixel / Ads
Presence of third-party⚠️ Only livebar + YouTube cookies
Marketing cookies✅ None (_ga, _fbp, _gcl_au etc.)
Processing context⚠️ Data on social benefits (possible special data)
Overall assessment✅ Positive — no marketing violations

Verdict: On wsparcie.uml.lodz.pl no marketing trackers were found (no GA4, UA, Pixel, Google Ads). Only the municipal livebar generating YouTube cookies is present. In the context of a social benefits portal, this is one of the cleanest domains in the entire audit in terms of marketing data processing.

📸 Evidence: Page Snapshots and GDPR Documents
📌 Notes from policy scan:

Detected in incognito: cookie pop-up implemented, dedicated links to social support policies in the footer.

📁 Show Hard Evidence (HAR, Cookies, Trace)
VIOLATION

https://zzm.lodz.pl/

SCAN ID: 20260309_104233_104a4b29

ADO: Municipal Greenery Authority in Łódź

Hosting/IT: LODMAN-AS2 Metropolitan Area Network LODMAN, PL

Requests8
Cookies9

Technical Conclusions (Scanner)

  • 🔴 GA4 G-30F084ZHSL (Library) + legacy UA UA-25825547-40 with gcd=13l3l3l2l1l1 + npa=1
  • 🔴 CMP cookie-box.js present, but not integrated with Google Consent Mode
  • ⚠️ Facebook SDK + YouTube widget + Twitter widgets + livebar lodz.pl/livebar/
  • - Ad server from the Municipal Library (ads.biblioteka.lodz.pl)
  • - Stable timeline. GA cookies set immediately after DOMContentLoaded.

Privacy Policy Analysis vs Tags

Identified Container IDs:
G-30F084ZHSL UA-25825547-40
Privacy Policy Assessment: Cross-controller sharing of Municipal Library GA4 on the Municipal Greenery Authority website. cookie-box CMP does not transmit consent signal. Typical pattern for uml_portal domains.
📄 Show Domain Assessment

Conclusions and Violations

  • 🔴 Library GA4 without Consent Mode — active beacon to G-30F084ZHSL with parameters gcd=13l3l3l2l1l1, npa=1 and pscdl=noapi. CMP cookie-box.js does not integrate with Google Consent API.
  • 🔴 Cross-controller sharing — GA4 property belonging to the Municipal Library is actively used on the Municipal Greenery Authority website. Lack of transparent joint administration (art. 26 RODO).
  • ⚠️ Facebook SDK + third-party widgetsconnect.facebook.net/pl_PL/sdk.js, YouTube widget API, Twitter widgets.js and iframe lodz.pl/livebar/ loaded.
  • - Legacy UA still activeUA-25825547-40 configured in parallel with GA4.
  • - Ad server from the Library — active ads.biblioteka.lodz.pl/www/delivery/asyncjs.php.

Legal Context (Municipal Greenery Authority)

The Municipal Greenery Authority in Łódź is a unit responsible for maintaining urban greenery, parks, squares, tree stands and recreational areas. Visitors to the website are mainly residents interested in greenery, outdoor events and environmental protection.

Layer A — culture of administrator compliance. cookie-box CMP implemented, but not integrated with Google Consent Mode. Shared GA4 property of the Municipal Library launched without transparent joint administration. This is a systemic oversight repeating across many municipal units.

Layer B — market value of behavioral signal. Low/moderate. Data on interest in urban greenery and recreation has limited commercial value.

Summary of assessment – zzm.lodz.pl

CriterionAssessment
Firing trackers before consent🔴 Yes — GA4 + UA with gcd=13l3l3l2l1l1 and pscdl=noapi
CMP Effectiveness⚠️ Present (cookie-box), but not integrated with Consent Mode
Transmission to third parties🔴 Yes — shared G-30F084ZHSL + YouTube/Twitter + livebar
Cross-controller identity🔴 Active (G-30F084ZHSL on ZZM domain)
Facebook Pixel✅ Inactive (only SDK)
Overall assessment🔴 Negative — active marketing tracking without effective consent

Verdict: On zzm.lodz.pl activation of GA4 (G-30F084ZHSL) and legacy UA (UA-25825547-40) with parameters gcd=13l3l3l2l1l1 + pscdl=noapi was confirmed. cookie-box CMP does not transmit consent signal. Additionally, there is cross-controller sharing with the Municipal Library on the Municipal Greenery Authority domain. This constitutes a violation of the principles of lawfulness and minimization of processing (art. 5 and 6 RODO) and joint administration requirements (art. 26 RODO).

📸 Evidence: Page Snapshots and GDPR Documents
📌 Notes from policy scan:

RODO ZZM PDF; monitoring clause: https://zzm.lodz.pl/files/public/uploads/RODO/KLAUZULA_INFORMACYJNA__MONITORING_ZZM.pdf

📁 Show Hard Evidence (HAR, Cookies, Trace)
🔍
Independent verification tool

Google Tag Assistant – official Consent Mode debugging tool

Do you want to check for yourself whether any of the domains in the report actually send data to Google before obtaining consent? Use the official Google tool:

The tool allows you to see in real time: • consent status (granted / denied) for each tag
• the exact moment of triggering Google Analytics, Google Ads, DoubleClick, etc.
• what data is passed to Google servers
• whether Consent Mode is correctly implemented

This is a completely objective Google tool. Anyone can independently verify and falsify the report results.
Most importantly, this tool is used by digital marketing specialists to check how and if tags work, so there is no possibility that someone allegedly implemented something wrong or made a mistake. Especially on the scale of over a dozen domains actively monetized with traffic in the millions. It is also worth mentioning that Google has no interest in falsifying results, as this would harm its own interests. It is a reliable tool.