Technical audit · 2026-06-16

uva.nl

Website of the University of Amsterdam

Uva.nl is the website of the University of Amsterdam. Homepage scan: 35 requests, 9 domains. The site has its own consent banner, but the university's own analytics system already fires before it — and not as an anonymized counter. Within the very first second, it assigns the visitor a persistent identifier and launches a session-recording and heatmap module that captures on-page behavior. Additionally, Google Analytics sends a request with analytics granted. The fact that the measurement is deployed on the university's own subdomain does not exempt it: with a persistent identifier and session recording, this is full-fledged behavioral data collection requiring consent, and it occurs before the user's choice.

Timeline of the leak

171 ms · own consent banner
The university's own consent banner loads. Since a consent mechanism exists, anything that fires before the choice occurs before consent.
194–320 ms · in-house analytics with a persistent identifier
The university's own analytics system sends a pageview and assigns the visitor a persistent identifier. This is not an anonymized counter but measurement with a persistent identifier, and it occurs before consent.
417 ms · session recording and heatmaps
A session-recording and heatmap module launches — capturing the user's on-page behavior. Before consent.
833 ms · private analytics
Siteimprove private analytics loads, running without cookies. This part is set up in a restrained manner.
6067 ms · Google Analytics with analytics granted
Google Analytics sends a pageview with an 'analytics granted' signal. The advertising portion, meanwhile, is declined.
banner present, but measurement and session recording had already fired before the choice
The site's own consent banner is present, but identifier-based measurement and session recording had already fired by this point. No cookies were set via headers during the session.

Declared versus actual

Siteimprove (private analytics) — заявлен
+ Session recording (own Matomo) — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.uva.nl is the website of the University of Amsterdam (Universiteit van Amsterdam): information on education, research, and admissions. The data controller is the university. The site is informational, with an extension into services for students and staff.

Scan: 35 requests to 9 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The site has its own consent banner. The analytics stack includes an in-house measurement system, private analytics, and Google Analytics.

Who receives the data

Google Analytics was observed here, along with the university’s own analytics system.

The in-house measurement system is deployed on the university’s own subdomain and runs on an open-source engine. It assigns the visitor a persistent identifier and performs session recording with heatmaps. Additionally, private cookieless analytics and Google Analytics run. The scan contains no advertising networks and no social media pixels.

Yes, the site has its own consent banner. But the in-house analytics system, with its persistent identifier and session recording, already fires before it. The site’s own policy states that cookies are set after consent, when required — yet identifier-based measurement and session recording launch before the choice.

Before the user’s choice, the following fire:

  • in-house analytics — assigning a persistent identifier;
  • the session-recording and heatmap module — capturing behavior;
  • Siteimprove private analytics (without cookies).

Private analytics is not a concern here — it is anonymized and cookieless. The key issue is the in-house measurement system: with a persistent identifier and session recording, this is full-fledged behavioral data collection, and deployment on the site’s own subdomain does not exempt it.

Why “own subdomain” is not a free pass

This point matters for understanding the issue. The fact that the analytics runs on the university’s own infrastructure is indeed better than transmitting data to a third-party service. But legally, the question isn’t whose infrastructure it is — it’s the nature of the collection. A persistent visitor identifier and session recording constitute behavioral profiling requiring consent. Launching it before consent contradicts both the rule and the site’s own policy, which promises to set cookies after consent.

Conclusion

Uva.nl is a case where the university’s own analytics is configured too aggressively. The site has a consent banner, private analytics is anonymized, and there are no advertising networks — this works in the site’s favor. But the in-house measurement system assigns a persistent identifier and performs session recording before the user’s choice, and Google Analytics operates with analytics granted. The key takeaway for the reader: hosting analytics on your own subdomain does not eliminate the consent requirement if it assigns a persistent identifier and records sessions. It would be enough to gate identifier-based measurement and session recording on consent — as has already been done for the private analytics.

Evidence
Original (audit)
HAR file: nl/uva-nl-2026-06-16.har
SHA-256: 762af1737a4ffc55f19fe77023e8c53b4b7edd8424b522c4d3cc6caf3ad8452f
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Dutch Data Protection Authority (AP)autoriteitpersoonsgegevens.nl

To: Dutch Data Protection Authority (AP)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website uva.nl.

2. Circumstances
I visited the website uva.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site has its own consent banner, but the university's own analytics system already fires before it. And it is not configured as an anonymized counter: within the very first second, it assigns the visitor a persistent identifier and sends it to its own servers, and also launches a session-recording and heatmap module that captures the user's on-page behavior. The fact that the analytics is deployed on the university's own subdomain does not exempt it: with a persistent identifier and session recording, this is full-fledged behavioral data collection requiring consent. Additionally, Google Analytics sends a request with analytics granted. Session recording and behavioral analytics with a persistent identifier are non-technical purposes requiring consent, and here they fire before the user's choice. The site's own policy states that cookies are set after consent, when required — yet identifier-based measurement and session recording launch before it.

Full technical documentation is published at: https://gdpru.eu/en/audits/nl-uva-nl/

3. Provisions violated
Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — in-house analytics with session recording and a persistent identifier operates before consent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]