Eötvös Loránd University (ELTE, Budapest) — 58 requests, 6 domains. A Klaro consent manager is present and holds back the declared analytics (Google, Meta, and TikTok do not fire in the capture). However, a third-party accessibility widget from Skynet Technologies (USA, via Cloudflare) and search libraries from jsDelivr load prior to consent, transmitting the visitor's IP address and Referer header to third-party recipients; these services are not named in the policy.
Timeline of the leak
Declared versus actual
Transfer timings
Algolia/InstantSearch search libraries. Via Cloudflare. Visitor's IP address.
Skynet accessibility widget. Via Cloudflare, a US company.
POST widget-setting-status with Origin/Referer elte.hu. Skynet, USA.
Detected trackers
- Skynet Technologies — accessibility widget (www.skynettechnologies.com, ada.skynettechnologies.us), via Cloudflare (USA), prior to consent
- cdn.jsdelivr.net — Algolia/InstantSearch search libraries, via Cloudflare, prior to consent
Indicators of GDPR non-compliance
- GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and cross-border transferOn page load, prior to any consent, a third-party accessibility widget from Skynet Technologies connects: scripts from www.skynettechnologies.com (at +1053 ms) and a POST request to ada.skynettechnologies.us/api/widget-setting-status (at +2100 ms), transmitting the Origin and Referer header https://elte.hu/. Both domains are served via Cloudflare, and Skynet Technologies itself is based in the USA. In parallel, search libraries (algoliasearch, instantsearch) load from cdn.jsdelivr.net, also via Cloudflare. Neither the Skynet accessibility widget nor jsDelivr is named in the cookie policy: the policy lists Google, Meta, TikTok, YouTube, and others, but not these actually loaded third-party services.
Context
elte.hu is the website of Eötvös Loránd University (Eötvös Loránd Tudományegyetem, ELTE) in Budapest, one of Hungary’s largest and oldest universities. The data controller is ELTE. The site is built on Drupal 11. The cookie policy discloses cookie categories in detail and uses the Klaro consent manager. Capture: 58 requests, 6 domains, recorded in a clean browser.
Direct Recipients of Data (prior to consent)
Skynet Technologies (USA), via Cloudflare — IP address and Referer header via the accessibility widget, including a POST request. jsDelivr, via Cloudflare — visitor IP address via the loading of search libraries.
Declared versus Actual
ELTE’s cookie policy is carefully and thoroughly constructed. It divides cookies into functional (Drupal/PHP, on the basis of public interest), security (Google reCAPTCHA), analytics (Google Analytics, Google Tag Manager, HotJar), marketing (Meta Pixel, TikTok Pixel), and embedded-content categories (YouTube, Vimeo, Spotify, Facebook). The policy states directly that analytics, marketing, and embedded-content cookies are activated only after the visitor’s consent, with choice governed by the Klaro consent manager.
The capture confirms this part: the consent mechanism works. Klaro is present, and none of the declared trackers — Google Analytics, GTM, HotJar, Meta Pixel, TikTok Pixel, YouTube, reCAPTCHA — fires in a session without consent. No cookies are set (Set-Cookie is zero).
However, two third-party services bypass both this mechanism and the policy. First, at +1053 ms, a third-party accessibility widget from Skynet Technologies connects: first, scripts from www.skynettechnologies.com (the all-in-one-accessibility widget, Rubik fonts, and a set of assets), and then, at +2100 ms, a POST request to ada.skynettechnologies.us/api/widget-setting-status, transmitting the Origin and Referer header https://elte.hu/. Both domains are served via Cloudflare, and Skynet Technologies itself is based in the USA. Second, at +30 ms, JavaScript search libraries load from cdn.jsdelivr.net (algoliasearch, instantsearch.js, a Typesense adapter) — also via Cloudflare. Neither the Skynet accessibility widget nor the jsDelivr CDN is named in the cookie policy, even though the policy lists roughly a dozen other third-party services by name.
Thus, the consent manager correctly holds back the declared analytics and marketing tools, but does not hold back the transfer of the visitor’s IP address to Skynet (USA) or to jsDelivr, and the policy itself does not disclose these recipients.
Timing Relative to Consent
The search libraries from jsDelivr load at +30 ms, the Skynet accessibility widget at +1053 ms, and the POST request to ada.skynettechnologies.us at +2100 ms. All of this occurs before any choice is made by the user; the Klaro consent manager does not block these calls. No consent was given during the session (Set-Cookie is zero). At the same time, Klaro correctly holds back the trackers declared in the policy — that is, the consent mechanism works selectively and does not cover the accessibility widget or the CDN.
What Cannot Be Asserted from This Capture
The capture covers the home page in its pre-consent state. The Skynet accessibility widget is intended to assist people with disabilities and is functionally useful; nevertheless, from a data-transfer standpoint, it remains a third-party recipient based in the USA. The capture cannot determine precisely what data it collects beyond the fact of the call itself. Cloudflare may use edge nodes within the EU; the conclusion drawn therefore concerns the recipients’ corporate affiliation (US companies), not the physical location of the nodes. The behavior of the declared trackers after consent is not observed in this session. Server-side processing is not visible in a browser-based capture.
Conclusion
The website of Eötvös Loránd University has built its consent mechanism correctly: the Klaro consent manager holds back the declared analytics and marketing tools (Google, Meta, TikTok, HotJar, YouTube) until consent is given. However, two third-party services bypass it: the Skynet Technologies accessibility widget (USA, via Cloudflare), including a POST request transmitting the Origin and Referer headers, and the search libraries from jsDelivr — both load prior to consent and transmit the visitor’s IP address to third-party recipients, while remaining unnamed in an otherwise detailed cookie policy. For a university website, the transfer of the IP address to a third-party recipient in the USA prior to and outside the consent mechanism, together with the non-disclosure of these recipients in the policy, constitutes a violation of the requirements concerning disclosure of recipients and cross-border transfer. Remedy: hold back the accessibility widget until consent is given, or host it locally; host the search libraries on the university’s own infrastructure; and disclose both recipients in the policy.
a112395657e75614b22937b6f8f20749957206425e9dd83167d60b6384614ec1Where to file: Hungarian National Authority for Data Protection (NAIH) — file a complaint online →
To: Hungarian National Authority for Data Protection (NAIH) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website elte.hu. 2. Circumstances I visited the website elte.hu and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications: 1) On page load, prior to any consent, a third-party accessibility widget from Skynet Technologies connects: scripts from www.skynettechnologies.com (at +1053 ms) and a POST request to ada.skynettechnologies.us/api/widget-setting-status (at +2100 ms), transmitting the Origin and Referer header https://elte.hu/. Both domains are served via Cloudflare, and Skynet Technologies itself is based in the USA. In parallel, search libraries (algoliasearch, instantsearch) load from cdn.jsdelivr.net, also via Cloudflare. Neither the Skynet accessibility widget nor jsDelivr is named in the cookie policy: the policy lists Google, Meta, TikTok, YouTube, and others, but not these actually loaded third-party services. Full technical documentation is published at: https://gdpru.eu/en/audits/hu-elte-hu/ 3. Provisions violated GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and cross-border transfer 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]