University of Vienna — 34 requests, 4 domains, all univie.ac.at. Matomo is self-hosted on proprietary subdomains — good. But it fires without explicit consent, and HeatmapSessionRecording captures user behavior on the page.
Timeline of the leak
Declared versus actual
Transfer timings
The primary Matomo instance. Self-hosted.
Two parallel tracking pings, no cookies in the HAR.
HeatmapSessionRecording configs — user session recording activated.
Detected trackers
- Matomo (self-hosted, two instances)
- Matomo HeatmapSessionRecording
Indicators of GDPR non-compliance
- GDPR Art. 6(1)(a), TKG § 165Matomo fires 6650 ms after the page loads. Consent scripts load at +628 ms, but there is no sign in the HAR that a banner was shown and consent obtained before the tracker fired. HeatmapSessionRecording is activated — this records users' sessions.
Context
Universität Wien is Austria’s largest university, founded in 1365, with around 90,000 students. HAR: 34 requests, 4 domains.
Proprietary infrastructure
34 requests, all to univie.ac.at subdomains. Zero external services — no Google, no Meta, no CDN. Inter and Source Serif 4 fonts are hosted locally. Matomo is deployed on two proprietary subdomains: matomo.univie.ac.at and startmatomo.univie.ac.at.
Matomo without explicit consent
Consent scripts load at +628 ms, but Matomo fires at +6650 ms with no visible consent banner in the HAR. The privacy policy (October 2022) describes general data-processing bases but does not name Matomo specifically and does not state a specific legal basis for the site’s web analytics. Two parallel tracker instances — possibly an A/B configuration or a migration in progress — increase the volume of data collected.
HeatmapSessionRecording
Both Matomo instances activate the HeatmapSessionRecording plugin — a tool for recording users’ mouse movements, clicks, and scrolling. This goes beyond simple visit analytics: it captures the specific behavior of an individual visitor on the page. This is not mentioned in the privacy policy.
Conclusion
Architecturally, this is exemplary: zero external dependencies, everything self-hosted. But Matomo with HeatmapSessionRecording fires before the user could have expressed consent, and the 2022 privacy policy reflects neither the tool itself nor the session recording.
02b2080b5a21de55902c9918cc0738a6a9bef5f0850ee139419538c1cb9a4027Where to file: Datenschutzbehörde (DSB) — file a complaint online →
To: Datenschutzbehörde (DSB) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website univie.ac.at. 2. Circumstances I visited the website univie.ac.at and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 26 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) Matomo fires 6650 ms after the page loads. Consent scripts load at +628 ms, but there is no sign in the HAR that a banner was shown and consent obtained before the tracker fired. HeatmapSessionRecording is activated — this records users' sessions. Full technical documentation is published at: https://gdpru.eu/en/audits/at-univie-ac-at/ 3. Provisions violated GDPR Art. 6(1)(a), TKG § 165 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]