Technical audit · 2026-06-20

autoscout24.it

Car Marketplace

Autoscout24.it is a large car marketplace. Home-page capture: 155 requests, 27 domains — full-fledged programmatic advertising. The data about the visit spreads across two dozen external advertising companies — Google Ad Manager, Criteo, PubMatic, OpenX, ID5, RTB House, Integral Ad Science, DoubleClick. The site has an IAB-standard consent-collection platform, and in a clean session it forms a consent string that, when decoded, means «no consent for any purpose». But the advertising vendors fire anyway: they synchronise cookies, match cross-site identifiers, request ads and record impressions. One of the PubMatic requests goes out as if the GDPR rules do not apply at all. That is, the consent signal says «no», and the advertising works.

Timeline of the leak

287–868 ms · consent platform (TCF)
AutoScout24's own IAB-standard consent-collection platform loads. In a clean session it forms a consent string that, when decoded, means: consent is not given for any purpose.
1055–1080 ms · tag system and DoubleClick
Google Tag Manager and the DoubleClick advertising domain connect — Google's tag manager and advertising infrastructure.
1526–1531 ms · advertising-identifier synchronisation
Almost simultaneously ID5, PubMatic, OpenX, Criteo and RTB House connect — the advertising vendors begin identifier synchronisation. The consent signal, meanwhile, is «no».
1709 ms · Google Ad Manager ad request
Google Ad Manager requests ads. The request goes out with the attached consent string, which means the absence of consent.
1885 ms · Criteo cookie synchronisation
Criteo performs cookie synchronisation via its synchroniser frame — matching of the advertising identifier, still without consent.
2524 ms · PubMatic with the GDPR flag disabled
PubMatic performs a cookie-matching set, and the request goes out with a flag as if the GDPR rules do not apply — although the user is located in Italy.
there is a banner, consent not given — the advertising works
The consent platform is present on the site and forms a «no consent» signal, but the advertising vendors ignore it and carry out identifier synchronisation and tracking. No cookie was set via the headers during the session — the matching goes through the advertising requests themselves.

Declared versus actual

ID5 — заявлен
+ Criteo — не заявлен
+ PubMatic — не заявлен
+ OpenX — не заявлен
+ RTB House — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.autoscout24.it is a large online marketplace for the sale of new and used cars. The data controller is AutoScout24. The site is commercial: a listings catalogue, search, contacts with sellers, monetisation through advertising. Capture: 155 requests to 27 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. The site has its own IAB-standard (TCF) consent-collection platform. The technical stack is full-fledged programmatic advertising with the participation of many external vendors.

Who receives the data

Spotted here were: Criteo, PubMatic, OpenX, ID5, RTB House, Google, Integral Ad Science. This is a real-time advertising ecosystem: Google Ad Manager requests and serves ads; Criteo and PubMatic synchronise cookies; ID5 is a cross-site advertising-identifier provider, matching the user across sites; OpenX and RTB House are advertising exchanges; Integral Ad Science verifies impressions; DoubleClick records impressions. Additionally, a third-party tracking domain fires, sending an impression pixel. Here the data about the visit spreads across many independent advertising companies.

Yes, the site has its own IAB-standard consent-collection platform. In a clean session no choice was made, and it forms a default consent string. The advertising vendors receive this string together with the requests — and when decoded it is unambiguous: consent is not given for any processing purpose. That is, the consent mechanism is not merely present — it explicitly tells the vendors «no». The problem is that the vendors do not observe this signal.

Under a «no consent» signal the following fire anyway:

  • identifier synchronisation by ID5, PubMatic, OpenX, Criteo, RTB House;
  • Google Ad Manager ad request;
  • Criteo cookie synchronisation;
  • Integral Ad Science impression verification and DoubleClick impression recording;
  • a third-party tracking pixel. It is fundamental that this is not a confusion of the signal, as happens when consent is mistakenly set to «given». Here the signal is correct and says «no» — and the advertising infrastructure ignores it. Identifier synchronisation and cookie-matching sets are advertising-tracking operations that under EU rules require prior consent.

The disabled GDPR flag

The PubMatic request that goes out with a flag meaning that the GDPR rules do not apply deserves separate mention. The user, meanwhile, is located in Italy, that is, under the full effect of the GDPR. Passing such a flag to an advertising vendor effectively lifts the restrictions of the European rules from it — which directly contradicts both the fact and the signal of the site’s own consent platform, which at the same time reports «no».

Conclusion

Autoscout24.it shows a typical and at the same time serious problem of programmatic advertising. The consent platform on the site exists and works correctly — it forms and passes the vendors a «no consent» signal. But two dozen advertising companies ignore this signal: they synchronise identifiers, request ads, record impressions, and one of the requests goes out as if the GDPR does not apply at all. The main takeaway for the reader: the mere presence of a correct consent platform guarantees nothing if the advertising vendors do not observe its signal — and this is verified only by a network capture with decoding of the consent string, and here the capture shows that the string says «no», and the advertising works. This is the gap between what the consent mechanism promises and what actually goes out to the advertising network.

Evidence
Original (audit)
HAR file: it/autoscout24-it-2026-06-20.har
SHA-256: 196c38294d75df24dba8bbc2a54890b23603d57be0167b6f06b31d1f2896502e
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website autoscout24.it.

2. Circumstances
I visited the website autoscout24.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 20 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site has its own IAB-standard (TCF) consent-collection platform. In a clean session it forms a consent string, which it passes to the advertising vendors — and this string, when decoded, shows that consent is not given for any processing purpose (all purposes zeroed, special features off). That is, the signal is unambiguous: the user allowed nothing. Nevertheless, a whole set of advertising vendors fires despite this signal: Criteo and PubMatic perform cookie synchronisation, ID5 matches a cross-site advertising identifier, OpenX and RTB House connect, Google Ad Manager requests ads, DoubleClick records the impression, Integral Ad Science verifies impressions. Separately telling is that one of the PubMatic requests goes out with a flag as if the GDPR rules do not apply at all (although the user is in Italy). This is not a confusion of the consent signal — here the signal is correct and says «no», and the advertising infrastructure ignores it and still carries out identifier synchronisation and tracking. Under EU rules, storing and reading advertising identifiers requires precisely prior consent, so references to other bases do not cover this.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-autoscout24-it/

3. Provisions violated
Art. 6(1)(a) GDPR — programmatic advertising fires against the explicit «consent not given» signal

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]