The portal of Poland's public broadcaster — 168 requests, 29 hosts, 106 outbound requests. The consent banner appears at the 2150th millisecond. By this point, Google's ad server, the video advertising kit, a second Google consent platform, the tag manager, and the Gemius audience platform have all already loaded, and Funding Choices has managed to send two requests. Refusal is recorded in the session and transmitted to recipients, but data still goes out: IP address, screen resolution, window size, time zone, browser client hints. Over the course of the capture, four advertisements were shown.
Timeline of the leak
Declared versus actual
Transfer timings
The Source Sans Pro font from Google's servers.
Google's video advertising kit.
The Google Publisher Tag ad-server library.
The Google consent platform, publisher identifier in the address.
The GTM-5DVKHRB tag manager.
Two POST requests, 1.26 seconds before the consent panel appears.
Gemius audience-platform scripts.
ccm/collect, page_view, gcs=G100.
GA4 page_view: screen resolution, platform, client hints, language, page address and title.
Hits with page address, screen resolution, window size, time zone; identifier fields marked -NOCONSENT.
Two gampad/ads requests.
adview requests, followed by btr/view and pcs/activeview — tracking of four impressions.
Detected trackers
- Google Ad Manager / AdSense (securepubads.g.doubleclick.net, pagead2.googlesyndication.com, safeframe.googlesyndication.com) — 35 requests, four ads shown
- Google Funding Choices (fundingchoicesmessages.google.com) — a second consent platform, two requests before the banner appears
- Google Analytics 4 (G-LGWGNHP986) and Universal Analytics via www.googletagmanager.com (GTM-5DVKHRB)
- Gemius (tvpgapl.hit.gemius.pl) — a Polish audience-measurement platform, five requests
- Google Ad Traffic Quality (ep1/ep2.adtrafficquality.google) — traffic quality check, five requests
- AMP for ads (cdn.ampproject.org) — 15 requests
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — 17 requests
- IMA SDK (imasdk.googleapis.com) — video advertising kit
Indicators of GDPR non-compliance
- ePrivacy — Telecommunications Law, Art. 173 (in conjunction with GDPR Art. 6(1)(a))The consent banner renders at +2150 ms — the moment when the portal's own platform requests the first-screen template consents22/first-screen.html. By this point, the following have already loaded: Google fonts (+447 ms), the IMA video advertising kit (+448 ms), the Google Publisher Tag ad-server library (+448 ms), the Google Funding Choices platform (+448 ms), the GTM-5DVKHRB tag manager (+468 ms), the ad server's executable module (+815 ms), and the Gemius audience platform (+1335 ms). Funding Choices, meanwhile, manages to send two POST requests at +883 and +894 ms — 1.26 seconds before the banner appears.
- GDPR Art. 5(1)(a) — transparencyThe cookie policy states that the entity placing cookies on the user's device and accessing them is the portal's operator — TVP — and that the information contained in the cookies can only be read by the server that created them, 'that is, in this case, TVP.' Yet on the page, Google's ad server, the Gemius audience platform, and a second Google consent platform all operate independently, each from its own domain with its own requests. The claim of a sole recipient is factually incorrect.
- GDPR Art. 6(1) — processing despite a recorded refusalGoogle's requests carry a gcs=G100 marker — both storage categories denied — and Gemius transmits internal fields with a value of -NOCONSENT. In other words, the absence of consent is recorded and transmitted to recipients. Nonetheless, the requests still go out, carrying the IP address, screen resolution of 1536x864, window size, color depth, time zone, the Windows platform, x86/64 architecture, a list of browser versions, interface language, page address, and page title. Screen resolution and the set of client hints are fingerprinting parameters; the portal's own policy classifies active reading of device characteristics, including screen resolution, as a special feature requiring separate consent.
- GDPR Art. 12(1) — accessibility of control mechanismsThe section on cookie types suggests the user express consent via the settings of software installed on their device, and provides a list of browsers that includes Internet Explorer, whose support ended in 2022. The advanced-settings panel that actually works on the portal is mentioned elsewhere in the document, but in the section answering 'how to manage this,' the reader is directed to the browser.
Context
tvp.pl is the flagship portal of Telewizja Polska S.A., Poland’s public broadcaster. The company is listed in its own documents as being in liquidation; its registered address is Warsaw, ul. J.P. Woronicza 17. The Data Protection Officer is rodo@tvp.pl. The portal publishes news, programming, materials from the group’s channels, and carries advertising blocks.
Scan: 168 requests, 29 hosts. Sixty-two requests to the site’s own infrastructure, spread across ten static hosts, 106 outbound. Capture duration: 11.9 seconds; full page load completed at 4276 ms. Captured on June 16, 2026, on the homepage.
A privacy policy with a cookie policy, a list of trusted partners, and a list of the group’s sites and apps describes the processing, dated January 9, 2024.
Who receives data directly
Google (ad server, tag manager, analytics, consent platform, traffic quality check, fonts, AMP), Gemius.
Declared versus actual
The portal’s document is detailed — following the industry Transparency & Consent Framework standard, it lists eleven processing purposes, three special purposes, features, and special features, provides a list of well over a hundred partners in which Google Ireland and Gemius are explicitly named, and openly acknowledges the risk of transfer to third countries. In terms of content, the disclosure is far more complete than on most government sites.
The discrepancies lie in three other areas.
First: loading order. The moment the banner appears in the capture is unambiguous: at +2150 ms, the portal’s own platform requests the first-screen template consents22/first-screen.html. By this point, eight external requests had already fired. At +447 ms — Google fonts. At +448 ms, via three parallel requests — the IMA video advertising kit, the Google Publisher Tag ad-server library, and the Google Funding Choices consent platform. At +468 ms — the tag manager. At +815 ms — the ad server’s executable module. At +1335 ms — the Gemius audience platform.
Funding Choices, meanwhile, doesn’t merely load: at +883 and +894 ms, it sends two POST requests. That is, an outbound transmission occurs 1.26 seconds before the user first sees any choice.
Second: the claim of a sole recipient. The cookie policy’s very first paragraph states that the entity placing cookies on the user’s device and accessing them is the portal’s operator, TVP. Two paragraphs later, the claim is reinforced: the information contained in cookies can only be read by the server that created them, “that is, in this case, TVP.” Meanwhile, on the page, Google’s ad server, Gemius, Funding Choices, and the traffic-quality-check service all operate independently — each from its own domain, with its own requests and its own data. The partner list at the end of the document contradicts this: there, Google and Gemius are named as recipients.
Third: what goes out despite a recorded refusal. The picture here is more complex, and it’s worth unpacking.
The portal’s consent mode is configured in good faith. Both of Google’s requests carry a gcs=G100 marker — both storage categories denied. Gemius transmits internal identifier fields with a value of -NOCONSENT. In other words, the absence of consent is recorded and honestly communicated to recipients, and no persistent identifiers are written.
But the requests still go out, carrying a substantive set of data. In GA4: screen resolution of 1536x864, the Windows platform, bitness and architecture, a full list of browser versions, interface language, page address, and page title. In the request to the advertising platform: a pageview event with the page’s address. In Gemius’s hits: page address, screen resolution, window size, color depth, time zone, the same set of client hints. The IP address is transmitted in every case by the nature of the request.
It’s worth returning here to the portal’s own document. In the section on special features, it explicitly describes active reading of device characteristics — with examples such as “installed fonts or screen resolution” — as something requiring the user’s separate consent. Screen resolution goes out to three recipients before that consent is requested.
Fourth: where the portal sends users for settings. The section on cookie types answers the management question this way: the user can express consent for cookie storage via the settings of software installed on their device — and provides a list of browsers where, alongside Firefox, Safari, Chrome, and Opera, sits Internet Explorer, whose support ended in 2022. The advanced-settings panel that actually works on the portal is mentioned elsewhere in the document, but it’s precisely in the section on management that the reader is directed to the browser.
Separately, regarding consent architecture. Two platforms run simultaneously on the portal: an in-house implementation of the industry Transparency & Consent Framework v2.2, served from www.tvp.pl, and Google Funding Choices, loaded from a Google domain. Only the first is described in the documents.
Consent: what is proven and what is not
Proven: the moment the banner appears. The request for the first-screen template at +2150 ms is the platform’s own request for the panel’s content — that is, the point before which the panel could not have been shown. Everything that occurred before it occurred before the choice was presented.
Proven: eight external requests and two transmissions occurred earlier. The order can be read directly from the capture and does not depend on what the user clicked afterward: even instant consent would not have undone the fact that the ad server, the video advertising kit, the Google platform, and Gemius were loaded before the panel appeared.
Proven: no choice was made in this session. All requests to the platform’s internal API are GET-type: the vendor list, its version, consent details, purposes, templates, vendors. There is not a single request in the capture that saves a user decision. This is confirmed on the recipients’ side as well: gcs=G100 for Google and -NOCONSENT for Gemius.
Proven: an ad was shown. Two gampad/ads requests for ads, a safety-isolation safeframe, followed by four adview requests, four btr/view, and two pcs/activeview — request, display, and visibility tracking. The advertising is non-personalized: the npa=1 marker is set.
Not proven and not claimed: cookies written to the device. Set-Cookie and Cookie headers have been stripped from the published file during sanitization, and the markers in the requests point precisely to storage being denied and no persistent identifiers being written. The concern rests not on cookie writing, but on the transmission of device parameters and IP address to external recipients before and outside of consent.
Separately: the browser sent a DNT: 1 header during the capture. This had no effect on the composition or volume of the transmissions.
Limits of observation
The scan covers a single page — the homepage — in a single state: the consent panel is shown, no choice was made. The observation records browser behavior, not the internal workings of the services: server-side processing, contractual relationships with recipients, and the services’ own settings on their owners’ side are not verified by a browser-based scan. Legal assessment falls to the competent authority — the President of the Personal Data Protection Office (UODO).
The file is published stripped of personal data: Cookie headers in requests, response bodies, the page title, and the analytics session identifier have been removed. Full device and site identifiers are not reproduced in this analysis. The set of cookies on a device cannot be reconstructed from the published file, and no conclusion in this analysis relies on it: all statements rest on request addresses, their order, and the parameters visible in the file.
The portal’s behavior once consent is given is not part of this scan. What ads and from which advertisers were shown was not analyzed from the capture — only the fact of a request, display, and tracking of four ads with a non-personalized-advertising marker is recorded.
Identification of services relies on domains and address patterns: Google — via doubleclick.net, googlesyndication.com, googletagmanager.com, google-analytics.com, fundingchoicesmessages.google.com, adtrafficquality.google, imasdk.googleapis.com, ampproject.org, and fonts.gstatic.com; Gemius — via hit.gemius.pl and its hit pattern; the in-house consent platform — via the paths cmp/tcf22 and consent_api.php on the portal’s domains.
Conclusion
Poland’s public broadcaster discloses its advertising setup more thoroughly than most: purposes are listed per the industry standard, Google is named, Gemius is named, the risk of transfer to third countries is openly acknowledged. Where implementation departs from this description is in the sequence of events. The consent panel appears at the 2150th millisecond, while Google’s ad server, the video advertising kit, the tag manager, the Gemius audience platform, and a second, nowhere-described Google consent platform all load earlier — with the latter managing to send two requests 1.26 seconds before the user first sees any choice.
Beyond that, the portal behaves more honestly than many: the refusal is recorded and transmitted to recipients, no persistent identifiers are written, and the advertising shown is non-personalized. But transmissions still occur — IP address, screen resolution, window size, time zone, platform, architecture, a list of browser versions, language, and page address go out to Google and Gemius. The portal’s own policy classifies screen resolution among the characteristics whose reading requires separate consent.
And against this backdrop, the policy states that only TVP’s server places and reads cookies, while the section on managing settings sends the user to their browser, listing Internet Explorer among the options.
Remediation: move the loading of the ad server, the video advertising kit, the tag manager, and the audience platform under the control of the consent panel, so that none of them starts before the choice is presented; prevent Google Funding Choices requests before that point, or drop the second platform altogether; eliminate or minimize the transmission of device parameters despite a recorded refusal; correct the policy’s claim that only TVP places and reads cookies; rewrite the section on managing settings so it leads to the advanced-settings panel, and remove the outdated instructions.
78ed8c7fc4e0e9ca39adf5cbdb638269ddda1937762fd1568908a4f2da6037aaWhere to file: Personal Data Protection Office (UODO) — uodo.gov.pl
To: Personal Data Protection Office (UODO) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website www.tvp.pl. 2. Circumstances I visited the website www.tvp.pl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The consent banner renders at +2150 ms — the moment when the portal's own platform requests the first-screen template consents22/first-screen.html. By this point, the following have already loaded: Google fonts (+447 ms), the IMA video advertising kit (+448 ms), the Google Publisher Tag ad-server library (+448 ms), the Google Funding Choices platform (+448 ms), the GTM-5DVKHRB tag manager (+468 ms), the ad server's executable module (+815 ms), and the Gemius audience platform (+1335 ms). Funding Choices, meanwhile, manages to send two POST requests at +883 and +894 ms — 1.26 seconds before the banner appears. 2) The cookie policy states that the entity placing cookies on the user's device and accessing them is the portal's operator — TVP — and that the information contained in the cookies can only be read by the server that created them, 'that is, in this case, TVP.' Yet on the page, Google's ad server, the Gemius audience platform, and a second Google consent platform all operate independently, each from its own domain with its own requests. The claim of a sole recipient is factually incorrect. 3) Google's requests carry a gcs=G100 marker — both storage categories denied — and Gemius transmits internal fields with a value of -NOCONSENT. In other words, the absence of consent is recorded and transmitted to recipients. Nonetheless, the requests still go out, carrying the IP address, screen resolution of 1536x864, window size, color depth, time zone, the Windows platform, x86/64 architecture, a list of browser versions, interface language, page address, and page title. Screen resolution and the set of client hints are fingerprinting parameters; the portal's own policy classifies active reading of device characteristics, including screen resolution, as a special feature requiring separate consent. 4) The section on cookie types suggests the user express consent via the settings of software installed on their device, and provides a list of browsers that includes Internet Explorer, whose support ended in 2022. The advanced-settings panel that actually works on the portal is mentioned elsewhere in the document, but in the section answering 'how to manage this,' the reader is directed to the browser. Full technical documentation is published at: https://gdpru.eu/en/audits/pl-tvp-pl/ 3. Provisions violated ePrivacy — Telecommunications Law, Art. 173 (in conjunction with GDPR Art. 6(1)(a)); GDPR Art. 5(1)(a) — transparency; GDPR Art. 6(1) — processing despite a recorded refusal; GDPR Art. 12(1) — accessibility of control mechanisms 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]