Anyone who clicks on a link in the UM newsletter or other e-mails such as the announcement of the Foundation Day, does not go directly to that specific website, but first makes a stop-over on the UM server. That is where there is a programme running that uses a unique code embedded in every single e-mail sent, takes a note of which employee or student clicked on which link, and so who finds which information interesting. But also at that time and from which IP-address the user accesses the site and via which provider.
With these tracking links, the UM gathers information from students and employees without them being aware of it, says third-year student of Econometrics Peter van Mill, skilful with computers and partial to his privacy. “I expect these kind of marketing tricks from businesses, but not from a university. This is not right from a privacy point of view. I want to be able to read the newsletters without the university monitoring which links I click on.”
Trust
Spokesperson Koen Augustijn states that the university works with Tripolis, a programme that indeed registers who clicks on what links. However, for the university it is not about an individual’s choices, says Augustijn, but about “the number of clicks to assess whether actual use is being made of the available content”.
With regard to the tracking links, the UM informs its students and employees in the privacy statement on its website, the spokesperson said. This states: “In order to be able to measure the efficiency and relevance of the above-mentioned newsletters, statistics are collected with respect to the interaction of the recipients with the information sent.”
Aside from the unclear phrasing, the question is whether such a statement suffices. The Dutch Data Protection Authority (DDPA) reported when asked: “As soon as tracking links yield data that can be redirected to an IP or e-mail address, explicit permission from the user is required.”
Why is there no option to not be followed, Van Mill wondered? “The UM claims that it does not monitor individuals, but there is no way of checking whether that is true. You just have to put your trust in the university keeping its word. And suppose that individual data is not looked at, is it generated and stored? Who can get at it?”
Anonymised
Then there are the cookies. As is the case on so many websites, students and employees also encounter them on the UM website. On the first visit, a pop-up window appears from which you can choose: allow all cookies, customize, use necessary cookies only. But anyone who chooses the ‘necessary’, Van Mill says, still receives five analytic cookies, plus one for Google Analytics, which - among others - records which pages you visit, and how long.
How necessary is that?
The UM states that it doesn’t use any other analytic cookies than Google Analytics. Augustijn: “We did an extra check last week. This showed that on a website associated with the UM, five analytic cookies were placed. This has since then been adapted.”
To use Google Analytics, the UM does not need permission, because they anonymize the data. In doing so, the university meets the privacy requirements, says Augustijn.
AutoDelete
To place analytical cookies, the Dutch Data Protection Authority states in its reaction, “you don’t usually need to ask for permission, if the website only uses those cookies themselves to count visitors and in doing so does not (further) process the personal data. Using analytical cookies, you gain better insight into the functioning of your website.”
Van Mill: “You can consider these cookies as being useful, but as far as I am concerned, they are not necessary. The same applies here: why does the university not allow people to choose whether or not to accept the cookies.”
Another possibility: download free files, or browser extensions, which continuously get rid of these cookies from your computer. Van Mill recommends, among others, AutoDelete.