The website of Italy's largest news agency. 266 requests, 75 domains — the record-holder of the series for the number of third parties. The consent architecture here is mature: the heavy advertising honestly waits for the moment of consent, and before it Google works in an anonymised denied mode. But checking the consent string reveals: on this site a refusal is recorded — and even so, after it the advertising exchanges merge the user's identifiers. Scale in itself is not a violation, but this is.
Timeline of the leak
Declared versus actual
Detected trackers
- Google Ads/Analytics (GTM, GA4 in denied mode, Google Ad Manager)
- RTB exchanges and identifier synchronisation (Criteo, Rubicon/Magnite, PubMatic, OpenX, The Trade Desk, Outbrain, Casale Media, Teads, a-mx, etc.)
- comScore
- Nielsen/Audicom (anonymous volumetrics — matches the policy)
- Iubenda (consent banner)
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — identifier synchronisation under a «no consent» signalAll requests to the advertising exchanges carry the same machine consent string (IAB format), and on decoding, not a single processing purpose is allowed in it — that is, a refusal is recorded. Nevertheless, after the moment this decision is recorded (+14026 ms), 59 advertising requests fire, among which is not only the display of ads but also direct synchronisation of the user's identifiers across platforms (The Trade Desk, Outbrain, PubMatic, Criteo, a-mx). Meanwhile ANSA's own policy classifies profiling as processing based on consent. Merging identifiers under a refusal signal lacks the very basis the document itself names.
Context
www.ansa.it is the website of ANSA, Italy’s largest news agency. Access follows a «pay or consent» model: either accept cookies and profiling, or take out a paid subscription without tracking. The policy describes this in detail. The capture shows 266 requests to 75 domains — the record-holder of the whole series for the number of third parties. ANSA itself is correctly named as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. This site is a good lesson that the number of domains in itself proves nothing yet: here one must look not at «how many» but at «when and under what consent». And on careful checking the picture turns out to be dual.
Was there a consent banner
There is a banner — the Iubenda system, and it is built in layers: first the initial screen, then detailed settings. The consent decision is recorded by a separate request at +14026 ms. It is around this moment that the whole plot unfolds.
What is done right
First about the strong side, because it exists. Before the consent decision, only the libraries of the advertising systems load on the site — code, not the data collection itself. Google’s measurements at this time go in the anonymised denied mode: pings without user identification. No real ad auctions and no identifier synchronisations occur before the decision. This is noticeably better than the advertising blog from the same series, where the first synchronisation went out already in the first second, without waiting for anything. The audience measurement via the Audicom system deserves separate praise: the policy promises that it is fully anonymous and transmits no identifiers — and the capture confirms this, the identifier field in the corresponding request is empty. Here word and deed coincide.
But the consent is a «refusal» — and the exchanges fired anyway
And now what overturns the first favourable impression, and for the sake of which it was worth digging deeper. I decoded that very machine consent string that all requests to the exchanges carry. Throughout the session it is a single one, and in it not a single processing purpose is allowed. In other words, on this visit a refusal is recorded. And despite this, immediately after the decision moment some fifty advertising requests fire. Some of them are the display of ads, which under a refusal can still be conducted in a non-personalised, contextual form. But among them there is also something else — direct synchronisation of the user’s identifiers between advertising platforms: The Trade Desk, Outbrain, PubMatic, Criteo and others merge their markers in order to recognise the visitor on different sites. This is no longer contextual advertising, but precisely the building of a cross-site profile — something that should not happen under a refusal. All the more so since ANSA’s own policy explicitly classifies profiling as processing based on consent. There is no consent — yet the merging of identifiers is under way.
Why this is nonetheless milder than the advertising blog
For the sake of proportion. Unlike the blog with WordAds, here the consent architecture really does work by timing: the heavy advertising waited for the decision moment rather than pushing in during the first second, and before that Google honestly held to the denied mode. That is, the mechanism is not absent — it exists and half performs its task. The problem is in the other half: after the recorded refusal the advertising stack did not stop, but carries out identifier synchronisation as if consent had been obtained. This is serious, but it is a failure in an otherwise well-thought-out system, not its total absence.
What cannot be claimed from the capture
Here there are more caveats than usual, and they matter. The body of the request with the consent decision is hidden in the export, so I cannot quote verbatim «pressed refuse» or «continued without accepting» — but the result is unambiguous: the final consent string denies everything. In it I decoded specifically the consent by purpose; the separate «legitimate interest» signal, on which some vendors may rely for certain operations, I did not analyse — so not every one of these requests is automatically unlawful, but identifier synchronisation does not fall under a refusal. The comScore measurer’s library loaded early, but I will not undertake to confirm from this capture that it transmitted data before consent. And I will note separately: this analysis revises the initial favourable assessment — it was precisely the decoding of the consent string that revealed what was not visible from the domain list and timing alone.
Conclusion
Scale is deceptive in both directions. Seventy-five third parties do not in themselves make a site a violator — and the consent architecture here is mature, the advertising waits for the decision, the audience measurer is honestly anonymous. But strict checking reveals the underside: on the visit a refusal is recorded, and the advertising exchanges after it nonetheless merge the user’s identifiers — without the consent-based basis the policy itself names. The main takeaway for the reader: even a properly configured consent mechanism can let tracking through if the advertising stack does not respect the pressed «refuse» button — and this can be caught only by decoding the consent signal itself, not by counting domains.
91ada1c5fe2e1171e8ddd8ef6f7a2e596e1790365f7ba7068f5956794c08dd41Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website ansa.it. 2. Circumstances I visited the website ansa.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) All requests to the advertising exchanges carry the same machine consent string (IAB format), and on decoding, not a single processing purpose is allowed in it — that is, a refusal is recorded. Nevertheless, after the moment this decision is recorded (+14026 ms), 59 advertising requests fire, among which is not only the display of ads but also direct synchronisation of the user's identifiers across platforms (The Trade Desk, Outbrain, PubMatic, Criteo, a-mx). Meanwhile ANSA's own policy classifies profiling as processing based on consent. Merging identifiers under a refusal signal lacks the very basis the document itself names. Full technical documentation is published at: https://gdpru.eu/en/audits/it-ansa-it/ 3. Provisions violated Art. 6(1)(a) GDPR — identifier synchronisation under a «no consent» signal 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]