Technical audit · 2026-06-16

tudelft.nl

Website of Delft University of Technology

Tudelft.nl is the website of Delft University of Technology. Homepage scan: 59 requests, 10 domains. The configuration is exemplary. Among analytics, there is only the private Siteimprove package, running without cookies and anonymized. The remaining external services are functional: an image-delivery network, an accessibility text-to-speech tool, and a consent-collection platform. The scan shows no Google Analytics, no Facebook, no advertising, no session recording, and no third-party commercial trackers. Not a single cookie was set during the session. No violations were recorded.

Timeline of the leak

559 ms · private Siteimprove analytics
Siteimprove analytics loads — a private web-statistics package running without cookies.
560 ms · consent platform and image delivery
The consent-collection platform and an image-delivery network load. Image delivery is a functional resource for page styling.
1331 ms · accessibility text-to-speech
An accessibility page text-to-speech tool loads — an assistive feature, not tracking.
1573 ms · statistics request sent
Analytics sends a request with its own transit identifier, without a cookie. This is consistent with a cookieless, anonymized mode.
consent platform present, analytics cookieless, no cookie set
A consent-collection platform is present. The only analytics runs without cookies and is anonymized, and is therefore exempt from consent. Not a single cookie was set during the session.

Declared versus actual

Siteimprove (analytics) — заявлен

Detected trackers

Context

www.tudelft.nl is the website of Delft University of Technology (TU Delft): information on education, research, and admissions. The data controller is the university. The site is informational.

Scan: 59 requests to 10 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The site has a consent-collection platform. The technical stack is restrained.

Who receives the data

There are no third-party commercial recipients.

Among analytics, only the private Siteimprove package runs, without cookies and anonymized. The remaining external services are functional: an image-delivery network, an accessibility text-to-speech tool, and a consent-collection platform. The scan shows no Google Analytics, no advertising networks, no social media pixels, and no session recording.

Yes, the site has a consent-collection platform. That said, the only analytics runs without cookies and is anonymized, and is therefore exempt from consent. Not a single cookie was set during the entire session. The remaining external requests — image delivery and text-to-speech — relate to page functioning and accessibility.

Only cookieless analytics and functional elements. Before any interaction, private cookieless analytics, image delivery, and the text-to-speech tool fire. The scan contains no Google analytics, no advertising domains, no social plugins, and no session recording.

Conclusion

Tudelft.nl is a model of a restrained configuration for a university. The only analytics is private Siteimprove, running without cookies and anonymized, while the remaining external services are functional: image delivery and accessibility text-to-speech. There is no third-party advertising, no Google analytics, no social media pixels, and no session recording whatsoever, and no cookies are set. The key takeaway for the reader: a university can manage perfectly well with cookieless, anonymized statistics alone, and here that is achieved without a single third-party commercial tracker. No violations were recorded.

Evidence
Original (audit)
HAR file: nl/tudelft-nl-2026-06-16.har
SHA-256: 36bee3bfa22e3df69e24d772c81907c75c02686730e19e63a236abe8b06344b9
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.