Technical audit · 2026-05-29

elte.hu

Eötvös Loránd University

Eötvös Loránd University (ELTE, Budapest) — 58 requests, 6 domains. A Klaro consent manager is present and holds back the declared analytics (Google, Meta, and TikTok do not fire in the capture). However, a third-party accessibility widget from Skynet Technologies (USA, via Cloudflare) and search libraries from jsDelivr load prior to consent, transmitting the visitor's IP address and Referer header to third-party recipients; these services are not named in the policy.

Timeline of the leak

+0 ms · portal load
Markup, stylesheets, scripts, and images — served from the first-party domain elte.hu (Drupal 11, Apache). Some images are served from www.elte.hu.
+30 ms · search libraries prior to consent
cdn.jsdelivr.net — algoliasearch, instantsearch.js, typesense-instantsearch-adapter. Served via Cloudflare. The visitor's IP address is transmitted to a third-party recipient.
+586 ms · first-party search
typesense.elte.hu/multi_search — a search backend on the university's own infrastructure (Apache/Ubuntu).
+1053 ms · Skynet accessibility widget prior to consent
www.skynettechnologies.com — accessibility widget scripts (all-in-one-accessibility), Rubik fonts, and assets. Served via Cloudflare, a US company.
Klaro consent manager present
The site uses the Klaro consent manager (cookies klaro, klaro_consent). Declared analytics and marketing tools are held back by it — they do not fire in the capture.
declared trackers do not fire
Google Analytics, Google Tag Manager, HotJar, Meta Pixel, TikTok Pixel, YouTube, and reCAPTCHA are not activated in the capture — held back by the consent manager pending consent.

Declared versus actual

Klaro consent manager (cookies klaro, klaro_consent) — governs visitor choice — заявлен
Functional cookies (SESS*, PHPSESSID) — Drupal/PHP, on the basis of public interest — заявлен
Google reCAPTCHA — security; Google Analytics, GTM, HotJar — analytics with consent; Meta Pixel, TikTok Pixel — marketing with consent; YouTube, Vimeo, Spotify, Facebook — embedded content with consent — заявлен
Declared: analytics, marketing, and embedded-content cookies are activated only after consent — заявлен
+ Skynet Technologies (www.skynettechnologies.com, ada.skynettechnologies.us) — accessibility widget, third-party recipient of IP address from the USA, prior to consent, not named in the policy — не заявлен
+ cdn.jsdelivr.net — third-party CDN for search libraries, prior to consent, not named in the policy — не заявлен

Transfer timings

+30 ms cdn.jsdelivr.net

Algolia/InstantSearch search libraries. Via Cloudflare. Visitor's IP address.

+1053 ms www.skynettechnologies.com

Skynet accessibility widget. Via Cloudflare, a US company.

+2100 ms ada.skynettechnologies.us

POST widget-setting-status with Origin/Referer elte.hu. Skynet, USA.

Detected trackers

Indicators of GDPR non-compliance

Context

elte.hu is the website of Eötvös Loránd University (Eötvös Loránd Tudományegyetem, ELTE) in Budapest, one of Hungary’s largest and oldest universities. The data controller is ELTE. The site is built on Drupal 11. The cookie policy discloses cookie categories in detail and uses the Klaro consent manager. Capture: 58 requests, 6 domains, recorded in a clean browser.

Skynet Technologies (USA), via Cloudflare — IP address and Referer header via the accessibility widget, including a POST request. jsDelivr, via Cloudflare — visitor IP address via the loading of search libraries.

Declared versus Actual

ELTE’s cookie policy is carefully and thoroughly constructed. It divides cookies into functional (Drupal/PHP, on the basis of public interest), security (Google reCAPTCHA), analytics (Google Analytics, Google Tag Manager, HotJar), marketing (Meta Pixel, TikTok Pixel), and embedded-content categories (YouTube, Vimeo, Spotify, Facebook). The policy states directly that analytics, marketing, and embedded-content cookies are activated only after the visitor’s consent, with choice governed by the Klaro consent manager.

The capture confirms this part: the consent mechanism works. Klaro is present, and none of the declared trackers — Google Analytics, GTM, HotJar, Meta Pixel, TikTok Pixel, YouTube, reCAPTCHA — fires in a session without consent. No cookies are set (Set-Cookie is zero).

However, two third-party services bypass both this mechanism and the policy. First, at +1053 ms, a third-party accessibility widget from Skynet Technologies connects: first, scripts from www.skynettechnologies.com (the all-in-one-accessibility widget, Rubik fonts, and a set of assets), and then, at +2100 ms, a POST request to ada.skynettechnologies.us/api/widget-setting-status, transmitting the Origin and Referer header https://elte.hu/. Both domains are served via Cloudflare, and Skynet Technologies itself is based in the USA. Second, at +30 ms, JavaScript search libraries load from cdn.jsdelivr.net (algoliasearch, instantsearch.js, a Typesense adapter) — also via Cloudflare. Neither the Skynet accessibility widget nor the jsDelivr CDN is named in the cookie policy, even though the policy lists roughly a dozen other third-party services by name.

Thus, the consent manager correctly holds back the declared analytics and marketing tools, but does not hold back the transfer of the visitor’s IP address to Skynet (USA) or to jsDelivr, and the policy itself does not disclose these recipients.

The search libraries from jsDelivr load at +30 ms, the Skynet accessibility widget at +1053 ms, and the POST request to ada.skynettechnologies.us at +2100 ms. All of this occurs before any choice is made by the user; the Klaro consent manager does not block these calls. No consent was given during the session (Set-Cookie is zero). At the same time, Klaro correctly holds back the trackers declared in the policy — that is, the consent mechanism works selectively and does not cover the accessibility widget or the CDN.

What Cannot Be Asserted from This Capture

The capture covers the home page in its pre-consent state. The Skynet accessibility widget is intended to assist people with disabilities and is functionally useful; nevertheless, from a data-transfer standpoint, it remains a third-party recipient based in the USA. The capture cannot determine precisely what data it collects beyond the fact of the call itself. Cloudflare may use edge nodes within the EU; the conclusion drawn therefore concerns the recipients’ corporate affiliation (US companies), not the physical location of the nodes. The behavior of the declared trackers after consent is not observed in this session. Server-side processing is not visible in a browser-based capture.

Conclusion

The website of Eötvös Loránd University has built its consent mechanism correctly: the Klaro consent manager holds back the declared analytics and marketing tools (Google, Meta, TikTok, HotJar, YouTube) until consent is given. However, two third-party services bypass it: the Skynet Technologies accessibility widget (USA, via Cloudflare), including a POST request transmitting the Origin and Referer headers, and the search libraries from jsDelivr — both load prior to consent and transmit the visitor’s IP address to third-party recipients, while remaining unnamed in an otherwise detailed cookie policy. For a university website, the transfer of the IP address to a third-party recipient in the USA prior to and outside the consent mechanism, together with the non-disclosure of these recipients in the policy, constitutes a violation of the requirements concerning disclosure of recipients and cross-border transfer. Remedy: hold back the accessibility widget until consent is given, or host it locally; host the search libraries on the university’s own infrastructure; and disclose both recipients in the policy.

Evidence
Original (audit)
HAR file: hu/elte-hu-2026-05-29.har
SHA-256: a112395657e75614b22937b6f8f20749957206425e9dd83167d60b6384614ec1
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Hungarian National Authority for Data Protection (NAIH)file a complaint online →

To: Hungarian National Authority for Data Protection (NAIH)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website elte.hu.

2. Circumstances
I visited the website elte.hu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) On page load, prior to any consent, a third-party accessibility widget from Skynet Technologies connects: scripts from www.skynettechnologies.com (at +1053 ms) and a POST request to ada.skynettechnologies.us/api/widget-setting-status (at +2100 ms), transmitting the Origin and Referer header https://elte.hu/. Both domains are served via Cloudflare, and Skynet Technologies itself is based in the USA. In parallel, search libraries (algoliasearch, instantsearch) load from cdn.jsdelivr.net, also via Cloudflare. Neither the Skynet accessibility widget nor jsDelivr is named in the cookie policy: the policy lists Google, Meta, TikTok, YouTube, and others, but not these actually loaded third-party services.

Full technical documentation is published at: https://gdpru.eu/en/audits/hu-elte-hu/

3. Provisions violated
GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and cross-border transfer

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]