Privacy & cookies.
This site sets no cookies for ordinary visitors and collects no personal data about them. Here is exactly what that means, where the two exceptions are, and what happens if any of it changes.
The short version
By default this site runs no analytics, sets no tracking cookies, and collects no personal data about you. There is no tracking script, no advertising pixel, no embedded video, and no third-party font. You can read every page without sending anything to anyone but the web server that hosts it.
That is why you may not have been shown a cookie banner. Under the GDPR and the Dutch Telecommunications Act, consent is required for non-essential cookies, and when there are none, there is nothing to consent to. A banner appears only in the one situation where the law requires it, described below.
What the server sees
Like any web server, the host records standard technical request data, your IP address, the page requested, the time, and your browser’s user-agent string, in its access logs. This is necessary to deliver the page and to keep the service secure and available. The legal basis is legitimate interest (GDPR Article 6(1)(f)). These logs are kept by the hosting provider under Erasmus University Rotterdam’s agreement with them, and are not used to profile you. They are retained only as long as they are needed for security and availability, and are rotated and deleted by the provider on that basis rather than kept indefinitely; the retention period set in that agreement is the one that applies. Ask privacy@eur.nl if you need the current figure.
Fonts and images are served from here
The typefaces (Source Serif 4, Inter, IBM Plex Mono) are stored on this server and delivered with the page. They are not loaded from Google Fonts, so no request, and no IP address, is sent to Google when you open a page. Photographs are likewise hosted here.
Links to other sites
Pages link out to eur.nl, to LinkedIn, Instagram and Facebook, and to published research. Following a link is a request you make, and those sites apply their own privacy policies. Nothing is sent to them until you click.
If you did see a cookie banner
The site operator can switch on Google Analytics 4 to count visits. When, and only when, that is enabled, a consent banner appears before anything loads. It works like this:
- Nothing is sent to Google until you choose “Allow analytics”. The analytics script is not even downloaded first; consent defaults to “denied” (Google Consent Mode v2).
- Declining is one click, equal to accepting, and the site works identically either way.
- Your choice is stored in one first-party cookie (
ese_consent, 6 months) so we do not ask again. It identifies nobody and tracks nothing. Only after you accept does Google Analytics set its own cookies:_gaand_ga_*(2 years), and in some configurations_gid(24 hours), which hold a random ID used to distinguish visitors. Google may transfer analytics data to the United States. The transfer runs on the EU–US Data Privacy Framework, the European Commission’s adequacy decision of July 2023, under which Google LLC is self-certified; that decision was upheld by the EU General Court in September 2025 and is under appeal at the Court of Justice, so the basis could change. Google Analytics 4 does not store IP addresses: your address is used to derive an approximate location and is then discarded by Google on collection. That is Google’s behaviour, not a setting we can enforce. - Changed your mind after accepting? Withdraw your consent with one click here, the consent and analytics cookies are deleted immediately, the banner returns, and analytics stays off until you accept again.
The test behind this design is simple: anything that stores or reads information on your device, beyond what is strictly necessary to deliver the page, needs your consent first. Anything that does not, does not. A planned newsletter is not active, if it goes live it will run on a mail platform approved by Erasmus University Rotterdam, on consent you give explicitly, with an unsubscribe link in every message. If this site is ever doing something not described on this page, that is a mistake, please tell us.
While the site is closed to the public
Before launch this site shows a holding page to everyone except people who enter a shared preview password. Two things follow from that, and both involve your data.
A cookie if you enter the password. Getting the password right sets one first-party cookie, ese_preview, so you are not asked again on every page. It is a session cookie: it is deleted when you close your browser. It is marked HttpOnly and SameSite=Lax, and contains a one-way hash, not the password, and nothing that identifies you.
A short-lived record of your IP address if you get the password wrong. To stop the password being guessed automatically, failed attempts are counted per IP address. What is stored is a hash of the address and a number. The record expires fifteen minutes after the most recent failed attempt, so repeated guessing keeps it alive until the guessing stops; it is then deleted automatically. A correct password erases it, unless the address is already locked out, in which case the lock stands until it expires. It is never used for anything else and never leaves the server.
This page stays readable without the password, deliberately: a privacy statement you cannot reach is no statement at all.
This section applies only while the holding page is switched on. When the site is open to the public no password form is shown, no ese_preview cookie is issued and no attempt counter is written. The mechanism stays in the theme so the site can be closed again for maintenance, and it behaves the same way if it is.
Photographs, names and quotations
This site publishes photographs in which people are recognisable, and it names people: staff, guest speakers, and the authors of research we report on. Photographs come from Erasmus University’s own press image bank or from the Marketing Science @ESE channel, and are credited where a credit is given. Names, roles and quotations are taken from published sources, and each one is linked to the page it came from.
The legal basis is legitimate interest (GDPR Article 6(1)(f)): informing prospective students about the programme and the people who teach it. If you are recognisable in a photograph here, or named in one of these articles, and you would rather not be, write to the address below and the image or the mention will be removed. You do not have to give a reason, and nothing else about you is processed as a result of asking.
How artificial intelligence is used on this site
Some of the photographs on this site have been edited using artificial intelligence. That applies to the two photographs of students on the home page, to the two in the article about block 1, and to the photograph of the Marketing Take-Off session at the head of the article about Take-Off. The editing adjusts a real photograph, it does not invent the scene, although in each case the Erasmus School of Economics clothing the students are wearing was put there by the edit: these are photographs of Campus Woudestein from Erasmus University’s press image bank, credited to their photographer. The EU Artificial Intelligence Act sets transparency obligations for artificially generated or manipulated images, and rather than argue about whether a particular edit crosses that threshold we would rather simply tell you, because you are entitled to know which pictures have been altered before you judge a place by them.
The articles on this site are drafted with the help of a large language model and then checked, corrected and edited by a person before publication. Every factual claim carries a visible source link so you can verify it against the original rather than trusting either the model or us. Where an article reports research, the finding is taken from the published paper; where it describes a course, it is taken from the EUR course catalogue or the official study schedule. If you find a claim on this site that its own source does not support, please tell us and we will correct or remove it.
No artificial intelligence is used to make decisions about you. There is no profiling, no automated decision-making within the meaning of Article 22 of the GDPR, and nothing on this site scores, ranks or assesses a visitor. No personal data from visitors is entered into an AI system: the models used in drafting see published sources and our own text, not server logs, not messages you send us, and not anything identifying you.
Your rights, and who is responsible
The data controller is Erasmus University Rotterdam (Burgemeester Oudlaan 50, 3062 PA Rotterdam). This page describes only this site. The university’s full privacy regime governs and takes precedence:
- EUR Privacy Statement
- EUR Data Protection Officer, the DPO can be reached at fg@eur.nl; privacy questions and complaints go to privacy@eur.nl.
You have the right to access, rectify, erase, restrict and object to the processing of your personal data, and the right to receive it in a portable form. Where processing rests on your consent, as analytics does, you may withdraw that consent at any time without giving a reason, and withdrawing it does not affect what was lawful before. You may also lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
Last reviewed 10 September 2026.
