Technical audit · 2026-06-20

amazon.it

Amazon Marketplace in Italy

Amazon.it is the Italian version of the Amazon marketplace. Home-page capture: 264 requests, 9 domains. Here there is a fundamental difference from commercial sites with a scattering of third-party trackers: almost everything is first-party, Amazon's own domains. No Google Analytics, no Meta, no third-party advertising networks: Amazon has no need of others, because it is itself a huge advertising-and-analytics ecosystem. But it does not become cleaner for that. Even before the privacy-settings banner loads, Amazon's own logging service sends events with a session identifier; then Amazon's behavioural telemetry and advertising exchange fire — and ad targeting is on by default. The data, meanwhile, does not leave outward — it stays with Amazon — but processing for advertising and analytics begins before consent, and it is precisely for placing advertising trackers before consent that Amazon has already been fined in the EU.

Timeline of the leak

177 ms · Amazon logging before the banner
Amazon's own logging service (fls-eu) sends events with a session identifier. This happens even before the privacy-settings banner loads.
1521 ms · privacy-settings banner
Amazon's privacy-settings banner loads. That is, by the time it appears the logging has already fired — before any user choice.
2089 ms · behavioural telemetry
Amazon's own behavioural telemetry fires — page-interaction events. This data stays within Amazon's infrastructure, but is collected before consent.
2642 ms · Amazon advertising exchange, targeting by default
Amazon's advertising exchange is called. The request parameter means that opting out of ad targeting is off by default — that is, interest-based advertising is on from the start, without consent.
4622–5302 ms · experiment and profiling pixels
Utility pixels for A/B experiments and profiling on Amazon's infrastructure fire. Still before consent.
there is a banner, but consent does not precede collection
A privacy-settings banner is present on the site, but Amazon's own analytics, logging and advertising exchange start before the user's choice. No cookie was set via the headers during the session — identification goes through the proprietary telemetry services.

Detected trackers

Indicators of GDPR non-compliance

Context

www.amazon.it is the Italian version of the Amazon marketplace, one of the country’s largest commercial sites. The data controller is Amazon (the European division). The site is a full-fledged store with search, recommendations, product advertising, a personal account and the Prime programme. Capture: 264 requests to 9 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. There is a privacy-settings banner on the site. A fundamental peculiarity: almost all the domains are Amazon’s own domains.

Who receives the data

There are no external, third-party recipients — and this is the key difference of Amazon from other commercial sites. On most commercial platforms the data spreads across dozens of outside companies — Google, Meta, advertising exchanges. With Amazon it is otherwise: it is self-sufficient. The logging (fls-eu), behavioural telemetry (unagi), advertising exchange (amazon-adsystem) and experiment pixels — all of these are Amazon’s own services. The data does not go to Google or Meta, it stays within Amazon’s ecosystem. But Amazon is itself one of the largest advertising platforms in the world, so «everything in-house» here does not mean «not for advertising».

Yes, there is a privacy-settings banner on the site; it loads at around 1.5 seconds. No decision was made in this visit — the capture was taken in a clean session. And it is precisely the timing that reveals the problem: Amazon’s own logging service sends events with a session identifier already at the 177th millisecond — that is, before the banner even loaded. And the advertising exchange is called with targeting on by default.

Before the user’s choice, the following manage to fire:

  • Amazon logging (fls-eu) with a session identifier — before the banner loads;
  • Amazon behavioural telemetry (page-interaction events);
  • Amazon advertising exchange with ad targeting on by default;
  • A/B-experiment and profiling pixels. There is no third-party leak here, but there is processing for advertising and analytics before consent. Under EU rules, non-technical trackers — analytics and advertising — require consent before they run; if they start on page load and the banner appears later, the consent is already invalid.

Why «first-party» is not an indulgence

This is an important point for understanding. The fact that Amazon does not pass data to Google or Meta is indeed better than a scattering of third-party trackers. But legally the question is not to whom the data goes, but on what basis it is collected. Ad targeting and behavioural analytics are non-technical purposes requiring consent. Targeting on by default (opt-out off from the start) and logging before the banner mean that processing for these purposes begins without consent. It is precisely for placing advertising trackers before obtaining consent on its European platform that Amazon has already received a large fine from the French regulator — that is, this is not a theoretical quibble, but exactly the practice that the regulator found to be a violation.

Conclusion

Amazon.it is an exemplary case of how a closed ecosystem does not equal privacy. There are no third-party trackers here, and the data does not spread across outside companies — but that is because Amazon is itself both the analytics and the advertising exchange. Its own logging with a session identifier starts before the banner, behavioural telemetry and ad targeting are on before consent and by default. The main takeaway for the reader: the absence of third-party recipients does not cancel the requirement of consent — advertising and analytics, even entirely first-party, must wait for the user’s choice, and targeting on by default directly contradicts this requirement. And this is not an abstraction: it is precisely for collecting advertising trackers before consent that Amazon has already been fined in the EU.

Evidence
Original (audit)
HAR file: it/amazon-it-2026-06-20.har
SHA-256: b6e5942b73b169951c9a0654540de7791141c1615ecc643d687d0e995f63319d
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website amazon.it.

2. Circumstances
I visited the website amazon.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 20 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) There is a privacy-settings banner on the site, but in a clean session, before it even loads and without any user decision, Amazon's own logging service (fls-eu) is already sending events with a session identifier — at the 177th millisecond, whereas the banner loads only at around 1.5 seconds. Then Amazon's behavioural telemetry fires (page-interaction events) and Amazon's advertising exchange is called, and with a parameter meaning that opting out of ad targeting is off by default — that is, interest-based advertising is on from the start, before consent. Additionally, experiment and profiling pixels fire. The peculiarity of Amazon is that all of this is first-party: the data does not go to Google, Meta or any other external recipients, but stays within Amazon's own ecosystem. But Amazon is itself a major advertising platform, and processing for analytics and advertising before consent, with targeting on by default, is exactly what the French regulator has already fined Amazon for: placing advertising trackers before obtaining consent is incompatible with EU requirements.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-amazon-it/

3. Provisions violated
Art. 6(1)(a) GDPR — Amazon's own analytics and advertising work before consent, targeting on by default

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]