I find it problematic that the university requires any cookie consent whatsoever in the first place. They are a public institution (Körperschaft des öffentlichen Rechts), not even a "company" but state-owned, and they run basically a static website and shouldn't have a need for cookies. Any "member" area (students and faculty) would require an account anyway, where you can and have to ask for all kinds of consent during signup anyway.
I get the Danish company doesn't want to run a CDN (with DDoS mitigations and all that) on their own, and it's a real problem that the EU economy snoozed when it came to creating competitors to Akamai, Cloudflare, AWS/GCP/Azure. There is a sliver of hope that court decisions like this will create a "demand" for such platforms within the EU, and that finally some companies with some "investment" money to spare (we still have plenty "rich" companies) will fund that. Or maybe at least the US providers will find way to create EU "subsidiaries" which are actually legally shielded from US (and other non-EU) law.