Uva.nl is the website of the University of Amsterdam. Homepage scan: 35 requests, 9 domains. The site has its own consent banner, but the university's own analytics system already fires before it — and not as an anonymized counter. Within the very first second, it assigns the visitor a persistent identifier and launches a session-recording and heatmap module that captures on-page behavior. Additionally, Google Analytics sends a request with analytics granted. The fact that the measurement is deployed on the university's own subdomain does not exempt it: with a persistent identifier and session recording, this is full-fledged behavioral data collection requiring consent, and it occurs before the user's choice.
Timeline of the leak
Declared versus actual
Detected trackers
- Own Matomo with session recording (before consent)
- Google Analytics 4 (analytics granted)
- Siteimprove (private analytics)
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — in-house analytics with session recording and a persistent identifier operates before consentThe site has its own consent banner, but the university's own analytics system already fires before it. And it is not configured as an anonymized counter: within the very first second, it assigns the visitor a persistent identifier and sends it to its own servers, and also launches a session-recording and heatmap module that captures the user's on-page behavior. The fact that the analytics is deployed on the university's own subdomain does not exempt it: with a persistent identifier and session recording, this is full-fledged behavioral data collection requiring consent. Additionally, Google Analytics sends a request with analytics granted. Session recording and behavioral analytics with a persistent identifier are non-technical purposes requiring consent, and here they fire before the user's choice. The site's own policy states that cookies are set after consent, when required — yet identifier-based measurement and session recording launch before it.
Context
www.uva.nl is the website of the University of Amsterdam (Universiteit van Amsterdam): information on education, research, and admissions. The data controller is the university. The site is informational, with an extension into services for students and staff.
Scan: 35 requests to 9 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The site has its own consent banner. The analytics stack includes an in-house measurement system, private analytics, and Google Analytics.
Who receives the data
Google Analytics was observed here, along with the university’s own analytics system.
The in-house measurement system is deployed on the university’s own subdomain and runs on an open-source engine. It assigns the visitor a persistent identifier and performs session recording with heatmaps. Additionally, private cookieless analytics and Google Analytics run. The scan contains no advertising networks and no social media pixels.
Was there a consent banner
Yes, the site has its own consent banner. But the in-house analytics system, with its persistent identifier and session recording, already fires before it. The site’s own policy states that cookies are set after consent, when required — yet identifier-based measurement and session recording launch before the choice.
What fires before consent
Before the user’s choice, the following fire:
- in-house analytics — assigning a persistent identifier;
- the session-recording and heatmap module — capturing behavior;
- Siteimprove private analytics (without cookies).
Private analytics is not a concern here — it is anonymized and cookieless. The key issue is the in-house measurement system: with a persistent identifier and session recording, this is full-fledged behavioral data collection, and deployment on the site’s own subdomain does not exempt it.
Why “own subdomain” is not a free pass
This point matters for understanding the issue. The fact that the analytics runs on the university’s own infrastructure is indeed better than transmitting data to a third-party service. But legally, the question isn’t whose infrastructure it is — it’s the nature of the collection. A persistent visitor identifier and session recording constitute behavioral profiling requiring consent. Launching it before consent contradicts both the rule and the site’s own policy, which promises to set cookies after consent.
Conclusion
Uva.nl is a case where the university’s own analytics is configured too aggressively. The site has a consent banner, private analytics is anonymized, and there are no advertising networks — this works in the site’s favor. But the in-house measurement system assigns a persistent identifier and performs session recording before the user’s choice, and Google Analytics operates with analytics granted. The key takeaway for the reader: hosting analytics on your own subdomain does not eliminate the consent requirement if it assigns a persistent identifier and records sessions. It would be enough to gate identifier-based measurement and session recording on consent — as has already been done for the private analytics.
762af1737a4ffc55f19fe77023e8c53b4b7edd8424b522c4d3cc6caf3ad8452fWhere to file: Dutch Data Protection Authority (AP) — autoriteitpersoonsgegevens.nl
To: Dutch Data Protection Authority (AP) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website uva.nl. 2. Circumstances I visited the website uva.nl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site has its own consent banner, but the university's own analytics system already fires before it. And it is not configured as an anonymized counter: within the very first second, it assigns the visitor a persistent identifier and sends it to its own servers, and also launches a session-recording and heatmap module that captures the user's on-page behavior. The fact that the analytics is deployed on the university's own subdomain does not exempt it: with a persistent identifier and session recording, this is full-fledged behavioral data collection requiring consent. Additionally, Google Analytics sends a request with analytics granted. Session recording and behavioral analytics with a persistent identifier are non-technical purposes requiring consent, and here they fire before the user's choice. The site's own policy states that cookies are set after consent, when required — yet identifier-based measurement and session recording launch before it. Full technical documentation is published at: https://gdpru.eu/en/audits/nl-uva-nl/ 3. Provisions violated Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — in-house analytics with session recording and a persistent identifier operates before consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]