Technical audit · 2026-06-16

www.tvp.pl

Portal of the public broadcaster 'Polish Television'

The portal of Poland's public broadcaster — 168 requests, 29 hosts, 106 outbound requests. The consent banner appears at the 2150th millisecond. By this point, Google's ad server, the video advertising kit, a second Google consent platform, the tag manager, and the Gemius audience platform have all already loaded, and Funding Choices has managed to send two requests. Refusal is recorded in the session and transmitted to recipients, but data still goes out: IP address, screen resolution, window size, time zone, browser client hints. Over the course of the capture, four advertisements were shown.

Timeline of the leak

+0…+213 ms · entering the portal
Two redirects, from tvp.pl to www.tvp.pl. The document is served from the site's own infrastructure, with static content distributed across ten hosts, s.tvp.pl through s10.tvp.pl. The browser sent a DNT: 1 header.
+446 ms · own consent platform
www.tvp.pl/files/portale-v4/polityka-prywatnosci/cmp/tcf22/tvp-tcfapi.js — a TCF v2.2 interface, developed by the portal. The file dates from December 5, 2023.
+447…+468 ms · advertising stack before the banner
fonts.googleapis.com — the Source Sans Pro font. imasdk.googleapis.com/gpt_proxy.js — the video advertising kit. securepubads.g.doubleclick.net/tag/js/gpt.js — the Google Publisher Tag ad-server library. fundingchoicesmessages.google.com — the Google consent platform for publisher pub-3844631381653775. www.googletagmanager.com/gtm.js?id=GTM-5DVKHRB — the tag manager.
+815…+944 ms · Funding Choices transmits data
The ad server's executable module pubads_impl.js, followed by two POST requests to fundingchoicesmessages.google.com and loading of its message. All of this occurs 1.2 seconds before the portal's banner appears.
+1294…+1969 ms · the consent platform gathers configuration
polityka-prywatnosci.tvp.pl/shared/consent_api.php — the vendor list, the list version, TVP's consent details, the list of purposes. In the same interval, at +1335 ms, Gemius loads: pp_gemius.js and gemius.js.
+2746…+4143 ms · analytics despite a recorded refusal
gtag/js for the GA4 stream G-LGWGNHP986, and analytics.js. Then a POST to pagead2.googlesyndication.com/ccm/collect with a page_view event, and a POST to region1.google-analytics.com/g/collect. Both carry a gcs=G100 marker — both storage categories denied; the requests still go out, carrying screen resolution, platform, architecture, a list of browser versions, language, and page address.
+6562…+6564 ms · Gemius hits
rexdot.js and redot.js on tvpgapl.hit.gemius.pl. Internal identifier fields are transmitted with a value of -NOCONSENT, but alongside them go the page address, screen resolution, window size, color depth, time zone, and browser client hints.
+6679…+7251 ms · ad requested and shown
Two gampad/ads requests to the ad server, a safeframe safety-isolation frame, an ad-traffic-quality check via ep1/ep2.adtrafficquality.google, and loading of AMP libraries for advertising. From +7251 ms, adview requests occur — ad impressions.
+9088…+11926 ms · impression tracking
Four btr/view requests and two pcs/activeview requests — recording of views and ad visibility. The final traffic-quality-check request occurs at +11926 ms.

Declared versus actual

The entity placing cookies and accessing them is the portal's operator, TVP — заявлен
The content of cookies can only be read by the server that created them, 'that is, in this case, TVP' — заявлен
Google Ireland Ltd and Gemius S.A. — appear in the list of trusted partners, alongside a hundred other companies — заявлен
Eleven processing purposes under the TCF standard, three special purposes, three features, and two special features — described in detail — заявлен
Active reading of device characteristics, including screen resolution — a special feature requiring separate consent — заявлен
Transfer of data to the US and other third countries — the risk is acknowledged, legal basis Article 49(1)(a) — заявлен
Consent management — via the advanced-settings panel, and in the section on cookie types — via browser settings — заявлен
Consent given on one TVP site applies across nine sites and seven apps of the group — заявлен
Document version dated January 9, 2024; the broadcaster is listed as being in liquidation — заявлен
+ Google Funding Choices — a second consent platform, operating in parallel with the portal's own — не заявлен
+ Loading order: the advertising and audience-measurement stack before the banner appears — не заявлен
+ Transmission of device parameters despite a recorded refusal — не заявлен
+ Google traffic-quality checks and AMP advertising libraries — не заявлен

Transfer timings

+447 ms fonts.googleapis.com

The Source Sans Pro font from Google's servers.

+448 ms imasdk.googleapis.com

Google's video advertising kit.

+448 ms securepubads.g.doubleclick.net

The Google Publisher Tag ad-server library.

+448 ms fundingchoicesmessages.google.com

The Google consent platform, publisher identifier in the address.

+468 ms www.googletagmanager.com

The GTM-5DVKHRB tag manager.

+883 and +894 ms fundingchoicesmessages.google.com

Two POST requests, 1.26 seconds before the consent panel appears.

+1335 ms tvpgapl.hit.gemius.pl

Gemius audience-platform scripts.

+3115 ms pagead2.googlesyndication.com

ccm/collect, page_view, gcs=G100.

+4143 ms region1.google-analytics.com

GA4 page_view: screen resolution, platform, client hints, language, page address and title.

+6562 ms tvpgapl.hit.gemius.pl

Hits with page address, screen resolution, window size, time zone; identifier fields marked -NOCONSENT.

+6679 ms pagead2.googlesyndication.com

Two gampad/ads requests.

+7251 ms pagead2.googlesyndication.com

adview requests, followed by btr/view and pcs/activeview — tracking of four impressions.

Detected trackers

Indicators of GDPR non-compliance

Context

tvp.pl is the flagship portal of Telewizja Polska S.A., Poland’s public broadcaster. The company is listed in its own documents as being in liquidation; its registered address is Warsaw, ul. J.P. Woronicza 17. The Data Protection Officer is rodo@tvp.pl. The portal publishes news, programming, materials from the group’s channels, and carries advertising blocks.

Scan: 168 requests, 29 hosts. Sixty-two requests to the site’s own infrastructure, spread across ten static hosts, 106 outbound. Capture duration: 11.9 seconds; full page load completed at 4276 ms. Captured on June 16, 2026, on the homepage.

A privacy policy with a cookie policy, a list of trusted partners, and a list of the group’s sites and apps describes the processing, dated January 9, 2024.

Who receives data directly

Google (ad server, tag manager, analytics, consent platform, traffic quality check, fonts, AMP), Gemius.

Declared versus actual

The portal’s document is detailed — following the industry Transparency & Consent Framework standard, it lists eleven processing purposes, three special purposes, features, and special features, provides a list of well over a hundred partners in which Google Ireland and Gemius are explicitly named, and openly acknowledges the risk of transfer to third countries. In terms of content, the disclosure is far more complete than on most government sites.

The discrepancies lie in three other areas.

First: loading order. The moment the banner appears in the capture is unambiguous: at +2150 ms, the portal’s own platform requests the first-screen template consents22/first-screen.html. By this point, eight external requests had already fired. At +447 ms — Google fonts. At +448 ms, via three parallel requests — the IMA video advertising kit, the Google Publisher Tag ad-server library, and the Google Funding Choices consent platform. At +468 ms — the tag manager. At +815 ms — the ad server’s executable module. At +1335 ms — the Gemius audience platform.

Funding Choices, meanwhile, doesn’t merely load: at +883 and +894 ms, it sends two POST requests. That is, an outbound transmission occurs 1.26 seconds before the user first sees any choice.

Second: the claim of a sole recipient. The cookie policy’s very first paragraph states that the entity placing cookies on the user’s device and accessing them is the portal’s operator, TVP. Two paragraphs later, the claim is reinforced: the information contained in cookies can only be read by the server that created them, “that is, in this case, TVP.” Meanwhile, on the page, Google’s ad server, Gemius, Funding Choices, and the traffic-quality-check service all operate independently — each from its own domain, with its own requests and its own data. The partner list at the end of the document contradicts this: there, Google and Gemius are named as recipients.

Third: what goes out despite a recorded refusal. The picture here is more complex, and it’s worth unpacking.

The portal’s consent mode is configured in good faith. Both of Google’s requests carry a gcs=G100 marker — both storage categories denied. Gemius transmits internal identifier fields with a value of -NOCONSENT. In other words, the absence of consent is recorded and honestly communicated to recipients, and no persistent identifiers are written.

But the requests still go out, carrying a substantive set of data. In GA4: screen resolution of 1536x864, the Windows platform, bitness and architecture, a full list of browser versions, interface language, page address, and page title. In the request to the advertising platform: a pageview event with the page’s address. In Gemius’s hits: page address, screen resolution, window size, color depth, time zone, the same set of client hints. The IP address is transmitted in every case by the nature of the request.

It’s worth returning here to the portal’s own document. In the section on special features, it explicitly describes active reading of device characteristics — with examples such as “installed fonts or screen resolution” — as something requiring the user’s separate consent. Screen resolution goes out to three recipients before that consent is requested.

Fourth: where the portal sends users for settings. The section on cookie types answers the management question this way: the user can express consent for cookie storage via the settings of software installed on their device — and provides a list of browsers where, alongside Firefox, Safari, Chrome, and Opera, sits Internet Explorer, whose support ended in 2022. The advanced-settings panel that actually works on the portal is mentioned elsewhere in the document, but it’s precisely in the section on management that the reader is directed to the browser.

Separately, regarding consent architecture. Two platforms run simultaneously on the portal: an in-house implementation of the industry Transparency & Consent Framework v2.2, served from www.tvp.pl, and Google Funding Choices, loaded from a Google domain. Only the first is described in the documents.

Proven: the moment the banner appears. The request for the first-screen template at +2150 ms is the platform’s own request for the panel’s content — that is, the point before which the panel could not have been shown. Everything that occurred before it occurred before the choice was presented.

Proven: eight external requests and two transmissions occurred earlier. The order can be read directly from the capture and does not depend on what the user clicked afterward: even instant consent would not have undone the fact that the ad server, the video advertising kit, the Google platform, and Gemius were loaded before the panel appeared.

Proven: no choice was made in this session. All requests to the platform’s internal API are GET-type: the vendor list, its version, consent details, purposes, templates, vendors. There is not a single request in the capture that saves a user decision. This is confirmed on the recipients’ side as well: gcs=G100 for Google and -NOCONSENT for Gemius.

Proven: an ad was shown. Two gampad/ads requests for ads, a safety-isolation safeframe, followed by four adview requests, four btr/view, and two pcs/activeview — request, display, and visibility tracking. The advertising is non-personalized: the npa=1 marker is set.

Not proven and not claimed: cookies written to the device. Set-Cookie and Cookie headers have been stripped from the published file during sanitization, and the markers in the requests point precisely to storage being denied and no persistent identifiers being written. The concern rests not on cookie writing, but on the transmission of device parameters and IP address to external recipients before and outside of consent.

Separately: the browser sent a DNT: 1 header during the capture. This had no effect on the composition or volume of the transmissions.

Limits of observation

The scan covers a single page — the homepage — in a single state: the consent panel is shown, no choice was made. The observation records browser behavior, not the internal workings of the services: server-side processing, contractual relationships with recipients, and the services’ own settings on their owners’ side are not verified by a browser-based scan. Legal assessment falls to the competent authority — the President of the Personal Data Protection Office (UODO).

The file is published stripped of personal data: Cookie headers in requests, response bodies, the page title, and the analytics session identifier have been removed. Full device and site identifiers are not reproduced in this analysis. The set of cookies on a device cannot be reconstructed from the published file, and no conclusion in this analysis relies on it: all statements rest on request addresses, their order, and the parameters visible in the file.

The portal’s behavior once consent is given is not part of this scan. What ads and from which advertisers were shown was not analyzed from the capture — only the fact of a request, display, and tracking of four ads with a non-personalized-advertising marker is recorded.

Identification of services relies on domains and address patterns: Google — via doubleclick.net, googlesyndication.com, googletagmanager.com, google-analytics.com, fundingchoicesmessages.google.com, adtrafficquality.google, imasdk.googleapis.com, ampproject.org, and fonts.gstatic.com; Gemius — via hit.gemius.pl and its hit pattern; the in-house consent platform — via the paths cmp/tcf22 and consent_api.php on the portal’s domains.

Conclusion

Poland’s public broadcaster discloses its advertising setup more thoroughly than most: purposes are listed per the industry standard, Google is named, Gemius is named, the risk of transfer to third countries is openly acknowledged. Where implementation departs from this description is in the sequence of events. The consent panel appears at the 2150th millisecond, while Google’s ad server, the video advertising kit, the tag manager, the Gemius audience platform, and a second, nowhere-described Google consent platform all load earlier — with the latter managing to send two requests 1.26 seconds before the user first sees any choice.

Beyond that, the portal behaves more honestly than many: the refusal is recorded and transmitted to recipients, no persistent identifiers are written, and the advertising shown is non-personalized. But transmissions still occur — IP address, screen resolution, window size, time zone, platform, architecture, a list of browser versions, language, and page address go out to Google and Gemius. The portal’s own policy classifies screen resolution among the characteristics whose reading requires separate consent.

And against this backdrop, the policy states that only TVP’s server places and reads cookies, while the section on managing settings sends the user to their browser, listing Internet Explorer among the options.

Remediation: move the loading of the ad server, the video advertising kit, the tag manager, and the audience platform under the control of the consent panel, so that none of them starts before the choice is presented; prevent Google Funding Choices requests before that point, or drop the second platform altogether; eliminate or minimize the transmission of device parameters despite a recorded refusal; correct the policy’s claim that only TVP places and reads cookies; rewrite the section on managing settings so it leads to the advanced-settings panel, and remove the outdated instructions.

Evidence
Original (audit)
HAR file: pl/tvp-pl-2026-06-16.har
SHA-256: 78ed8c7fc4e0e9ca39adf5cbdb638269ddda1937762fd1568908a4f2da6037aa
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Personal Data Protection Office (UODO)uodo.gov.pl

To: Personal Data Protection Office (UODO)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website www.tvp.pl.

2. Circumstances
I visited the website www.tvp.pl and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The consent banner renders at +2150 ms — the moment when the portal's own platform requests the first-screen template consents22/first-screen.html. By this point, the following have already loaded: Google fonts (+447 ms), the IMA video advertising kit (+448 ms), the Google Publisher Tag ad-server library (+448 ms), the Google Funding Choices platform (+448 ms), the GTM-5DVKHRB tag manager (+468 ms), the ad server's executable module (+815 ms), and the Gemius audience platform (+1335 ms). Funding Choices, meanwhile, manages to send two POST requests at +883 and +894 ms — 1.26 seconds before the banner appears.

2) The cookie policy states that the entity placing cookies on the user's device and accessing them is the portal's operator — TVP — and that the information contained in the cookies can only be read by the server that created them, 'that is, in this case, TVP.' Yet on the page, Google's ad server, the Gemius audience platform, and a second Google consent platform all operate independently, each from its own domain with its own requests. The claim of a sole recipient is factually incorrect.

3) Google's requests carry a gcs=G100 marker — both storage categories denied — and Gemius transmits internal fields with a value of -NOCONSENT. In other words, the absence of consent is recorded and transmitted to recipients. Nonetheless, the requests still go out, carrying the IP address, screen resolution of 1536x864, window size, color depth, time zone, the Windows platform, x86/64 architecture, a list of browser versions, interface language, page address, and page title. Screen resolution and the set of client hints are fingerprinting parameters; the portal's own policy classifies active reading of device characteristics, including screen resolution, as a special feature requiring separate consent.

4) The section on cookie types suggests the user express consent via the settings of software installed on their device, and provides a list of browsers that includes Internet Explorer, whose support ended in 2022. The advanced-settings panel that actually works on the portal is mentioned elsewhere in the document, but in the section answering 'how to manage this,' the reader is directed to the browser.

Full technical documentation is published at: https://gdpru.eu/en/audits/pl-tvp-pl/

3. Provisions violated
ePrivacy — Telecommunications Law, Art. 173 (in conjunction with GDPR Art. 6(1)(a)); GDPR Art. 5(1)(a) — transparency; GDPR Art. 6(1) — processing despite a recorded refusal; GDPR Art. 12(1) — accessibility of control mechanisms

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]