Technical audit · 2026-05-31

tcd.ie

Trinity College Dublin — Ireland's Oldest University

Trinity College Dublin — a university founded in 1592, processing student data including medical and disability data. GTM loads 101 ms before OneTrust. A YouTube embed on the home page activates DoubleClick without consent. 70 requests, 14 domains.

Timeline of the leak

+2594 ms · before the banner
cdnjs.cloudflare.com — tiny-slider CSS. The Cloudflare CDN.
+2595 ms · before the banner
www.trumba.com — three events-calendar images. Trumba is an American event-scheduling service.
+2621 ms · before the banner
www.googletagmanager.com (GTM-KTX8CV) — the GTM container loads.
+2632 ms · before the banner
www.youtube.com/embed/V1ggffYdjzU — the YouTube iframe loads without consent.
+2722 ms · the banner begins loading
cdn.cookielaw.org (OneTrust otSDKStub.js) — the OneTrust CMP initializes. GTM has already been running for 101 ms; YouTube for 90 ms.
+3007–3011 ms · prior to consent
www.youtube.com — player scripts, CSS, JS (4 requests). The Roboto font, loaded via fonts.gstatic.com.
+3123–3293 ms · prior to consent
googleads.g.doubleclick.net/pagead/id — DoubleClick advertising identification (two requests). static.doubleclick.net/instream/ad_status.js.
+5457 ms and +21434 ms
www.youtube.com/youtubei/v1/log_event — YouTube logs session events. jnn-pa.googleapis.com/GenerateIT (+18476 ms) — an internal Google API. Set-Cookie is zero.

Declared versus actual

Cookies — mentioned in the policy, referencing a Cookie Register and a Cookie Policy — заявлен
YouTube — mentioned indirectly, in the description of media content — заявлен
+ Google Tag Manager (GTM-KTX8CV) — not named specifically — не заявлен
+ DoubleClick (googleads.g.doubleclick.net) — not mentioned — не заявлен
+ Trumba (www.trumba.com) — not mentioned — не заявлен
+ Cloudflare cdnjs — not mentioned — не заявлен
+ OneTrust (cdn.cookielaw.org) — not named specifically — не заявлен

Transfer timings

+2621 ms www.googletagmanager.com

GTM-KTX8CV. USA.

+2632 ms www.youtube.com

YouTube embed V1ggffYdjzU. 9 requests.

+2722 ms cdn.cookielaw.org

OneTrust otSDKStub.js. UUID 9f346210.

+2740 ms geolocation.onetrust.com

OneTrust geolocation, for banner configuration.

+3123 ms googleads.g.doubleclick.net

DoubleClick pagead/id — an advertising identifier. USA.

+3133 ms static.doubleclick.net

DoubleClick instream/ad_status.js. USA.

+18476 ms jnn-pa.googleapis.com

An internal Google API, GenerateIT. USA.

Detected trackers

Indicators of GDPR non-compliance

Context

Trinity College Dublin is Ireland’s oldest university, founded in 1592. It processes student data, including medical data, disability data, psychological counseling records, and financial information. Sensitivity: high. HAR: 70 requests, 14 domains. 28 requests go to www.tcd.ie, 8 to the CDN pxl-tcdie.terminalfour.net — the remaining 34 go to twelve external domains.

OneTrust arrives 101 ms after GTM

The loading order is critical: GTM-KTX8CV launches at +2621 ms. OneTrust begins initializing at +2722 ms. 101 ms is the window during which the GTM container is active and can fire any tags configured within it, with no restrictions imposed by the consent platform. If GTM has been configured with analytics or advertising tags set to trigger on “All Pages,” they will execute before OneTrust has any chance to block them. The HAR records exactly this scenario: YouTube and the associated DoubleClick call activate within this window.

The university’s home page embeds a YouTube video player (embed/V1ggffYdjzU). It loads at +2632 ms — without consent, before the OneTrust banner appears. YouTube is not a neutral media player: it connects to Google’s advertising infrastructure. The HAR records two requests to googleads.g.doubleclick.net/pagead/id (+3123 and +3293 ms) — this is DoubleClick advertising identification, assigning the visitor an advertising identifier. static.doubleclick.net/instream/ad_status.js loads at +3133 ms. Additionally: jnn-pa.googleapis.com/$rpc/google.internal.waa.v1.Waa/GenerateIT fires at +18476 ms — an internal Google API associated with advertising-traffic verification. All of this occurs on the site of a university that processes students’ medical data, without their consent.

Trumba — an undocumented events service

At +2595 ms, three images load from www.trumba.com. Trumba is an American SaaS service for managing event scheduling. Every request to Trumba transmits the visitor’s IP address to American servers. Trumba is not mentioned in the privacy policy.

The policy refers to external documents

The policy contains references to a Cookie Register and a Cookie Policy as separate documents. Neither was supplied in the archive. In the policy text itself, specific services — GTM, YouTube, DoubleClick, Trumba, OneTrust — are not named specifically. Under Art. 13(1)(e), a reference to an external register is acceptable provided the register is current and accessible; without reviewing the register itself, it cannot be established whether all recipients are in fact documented there.

None of the 70 requests sets a cookie via Set-Cookie. DoubleClick’s pagead/id call returned a 302 status (a redirect) with no cookie set in the HAR — nevertheless, the identification request itself did take place.

Conclusion

tcd.ie reproduces a pattern typical of university sites: YouTube without consent as the most common vector of violation, GTM ahead of the CMP, and Trumba undocumented. What sets it apart is the nature of the data involved: Trinity College processes students’ medical and disability data. This makes the violation of the consent principle on the home page not merely a legal issue but an ethical one. The fix: replace the direct YouTube embed with privacy-enhanced mode gated behind consent, or a static preview requiring a click to activate; move GTM behind OneTrust; and document Trumba in the Cookie Register.

Evidence
Original (audit)
HAR file: ie/tcd-ie-2026-05-31.har
SHA-256: fcbadbc4891ab34d4ed1e2bd2fcf58e9e8ac1d021e417ba962ad59119775e2f6
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Data Protection Commission (DPC)dataprotection.ie

To: Data Protection Commission (DPC)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website tcd.ie.

2. Circumstances
I visited the website tcd.ie and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 31 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) GTM (GTM-KTX8CV) loads at +2621 ms. OneTrust (cdn.cookielaw.org) loads at +2722 ms — 101 ms after GTM. The YouTube embed initializes at +2632 ms without consent and activates DoubleClick: googleads.g.doubleclick.net/pagead/id (+3123 ms), static.doubleclick.net/instream/ad_status.js (+3133 ms). DoubleClick — Google's advertising identification system — launches before any user interaction with the OneTrust banner.

2) A YouTube iframe (V1ggffYdjzU) is embedded on the home page and loads immediately upon opening, without waiting for consent. YouTube loads its own scripts (9 requests), activates DoubleClick to identify the visitor's advertising profile, and sends log_event calls at +5457 ms and +21434 ms. A jnn-pa.googleapis.com GenerateIT request fires at +18476 ms. All of this occurs without user consent.

3) The policy refers to a Cookie Register and a Cookie Policy as separate documents, neither of which was included in the archive. Trumba (an events-calendar management service, USA) loads images from www.trumba.com (+2595 ms) — not mentioned in the policy. Cloudflare cdnjs is not mentioned.

Full technical documentation is published at: https://gdpru.eu/en/audits/ie-tcd-ie/

3. Provisions violated
GDPR Art. 6(1), Art. 7; ePrivacy Regulations (SI 336/2011); GDPR Art. 6(1) — an embedded YouTube video without consent; GDPR Art. 13(1)(e)

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]