Europe's largest C2C marketplace. OneTrust with TCF 2.0 is implemented correctly — but Google Publisher Tag and Prebid Stack initialize simultaneously with the TCF stub, before the banner appears. The IAB vendor list includes dozens of companies citing 'legitimate interest.'
Timeline of the leak
Declared versus actual
Transfer timings
OneTrust TCF stub
Google GPT — advertising infrastructure
Prebid Stack header bidding
OneTrust fully loaded
Confiant — malvertising protection
Unidentified connectioncheck
Detected trackers
- Google Publisher Tag / GPT (pagead2.googlesyndication.com)
- Prebid Stack / pbstck.com
- Confiant (cdn.confiant-integrations.net)
- OneTrust with TCF 2.0 (cdn.cookielaw.org)
- ICG-IN.COM (conn-check.icg-in.com)
Indicators of GDPR non-compliance
- GDPR Art. 6(1), Art. 5(1)(a)Google Publisher Tag (GPT, +350 ms) and Prebid Stack (+351 ms) load simultaneously with the OneTrust TCF stub (+349 ms) — before the banner appears to the user. The TCF stub is meant to block advertising infrastructure until consent is given, but GPT and Prebid initialize in parallel with it.
- GDPR Art. 7, TCF 2.0OneTrust implements IAB TCF 2.0, loading iab2V2Data.json and googleData.json — a full list of IAB vendors. The data-sharing disclosure document lists dozens of advertising vendors (Exponential Interactive, Captify, Index Exchange, Quantcast, RTB House, Trade Desk, and others), each citing 'legitimate interest' — a legal basis the EDPB has repeatedly found insufficient for advertising tracking.
- GDPR Art. 13(1)(e)conn-check.icg-in.com is not mentioned in the documentation as a recipient. pbstck.com (Prebid Stack) is mentioned indirectly via IAB TCF, but not as a named recipient in the policy.
Context
Vinted UAB is a Lithuanian C2C secondhand marketplace, the largest in Europe. It operates in 20+ countries and is headquartered in Vilnius. The lead supervisory authority is the Lithuanian VDAI. HAR: 136 requests, 16 domains. A home-page session.
TCF 2.0 — hundreds of vendors citing “legitimate interest”
Vinted implements the IAB Transparency & Consent Framework 2.0 via OneTrust. The “data sharing with companies” document lists IAB vendors: Exponential Interactive, Captify, Roq.ad, AdSpirit, Index Exchange, Quantcast, BeeswaxIO, Sovrn, Adkernel, Adikteev, RTB House, N.Rich, Trade Desk, Nexxen, Epsilon, Yahoo EMEA, Venatus, ADventori, TripleLift, ETARGET, BidTheatre, Ogury, Xandr, ShareThis, NEORY, Nexxen Group — and dozens more.
Most of them declare “legitimate interest” as the legal basis for processing data for advertising purposes. The EDPB, in Guidelines 3/2022, stated directly that legitimate interest is not an admissible basis for advertising profiling and tracking without consent.
GPT and Prebid ahead of the banner — a 1-millisecond gap
The OneTrust TCF stub (+349 ms), Google GPT (+350 ms), and Prebid Stack (+351 ms) all load within 2 milliseconds of each other. The TCF stub is a technical mechanism meant to intercept calls to window.__tcfapi and block advertising infrastructure until consent is given. Technically, this is the correct architecture: the TCF API is ready before GPT. In practice, however, GPT and Prebid initialize before the user ever sees the banner (+1791 ms).
Confiant — protecting the advertising ecosystem
cdn.confiant-integrations.net is Confiant, a malvertising protection platform used within Prebid. Confiant scans advertising creatives before display, preventing malicious code from loading via advertising networks. This is a useful security tool — but it transmits page and context data to the USA.
conn-check.icg-in.com — an unidentified domain
conn-check.icg-in.com/connectioncheck (+3625 ms) is a connection-check request to a domain mentioned neither in the policy nor in the IAB vendor list. ICG-IN may be part of the advertising infrastructure, but without explicit disclosure this constitutes a violation of Art. 13(1)(e).
Comparison with Yaga
Both are C2C secondhand marketplaces on the Estonian market. Yaga uses the Facebook Pixel and loads GTM 736 ms before Cookiebot. Vinted uses IAB TCF with hundreds of IAB vendors, GPT, and Prebid for its RTB auction. Different scales, different architectures — the same underlying problem with initialization order.
Conclusion
Vinted has invested serious effort into TCF 2.0 — a full IAB vendor list, a correctly configured OneTrust setup. But “legitimate interest” as the basis for hundreds of advertising vendors does not align with the EDPB’s position. GPT and Prebid initialize simultaneously with the TCF stub — before the banner appears. conn-check.icg-in.com is undisclosed. Transparency is present — the legal bases require reconsideration.
ea81a4952b91642f419520a60389e2d10d7fecf5edc089f33bf3bd5e25bc933cWhere to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee
Important: AKI only handles submissions in Estonian. Translate the letter before sending.
To: Estonian Data Protection Inspectorate (AKI) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website vinted.ee. 2. Circumstances I visited the website vinted.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 6 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) Google Publisher Tag (GPT, +350 ms) and Prebid Stack (+351 ms) load simultaneously with the OneTrust TCF stub (+349 ms) — before the banner appears to the user. The TCF stub is meant to block advertising infrastructure until consent is given, but GPT and Prebid initialize in parallel with it. 2) OneTrust implements IAB TCF 2.0, loading iab2V2Data.json and googleData.json — a full list of IAB vendors. The data-sharing disclosure document lists dozens of advertising vendors (Exponential Interactive, Captify, Index Exchange, Quantcast, RTB House, Trade Desk, and others), each citing 'legitimate interest' — a legal basis the EDPB has repeatedly found insufficient for advertising tracking. 3) conn-check.icg-in.com is not mentioned in the documentation as a recipient. pbstck.com (Prebid Stack) is mentioned indirectly via IAB TCF, but not as a named recipient in the policy. Full technical documentation is published at: https://gdpru.eu/en/audits/ee-vinted-ee/ 3. Provisions violated GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 7, TCF 2.0; GDPR Art. 13(1)(e) 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]