Policy changed — see what exactly · 2026-08-14 →
Autoscout24.it is a large car marketplace. Home-page capture: 155 requests, 27 domains — full-fledged programmatic advertising. The data about the visit spreads across two dozen external advertising companies — Google Ad Manager, Criteo, PubMatic, OpenX, ID5, RTB House, Integral Ad Science, DoubleClick. The site has an IAB-standard consent-collection platform, and in a clean session it forms a consent string that, when decoded, means «no consent for any purpose». But the advertising vendors fire anyway: they synchronise cookies, match cross-site identifiers, request ads and record impressions. One of the PubMatic requests goes out as if the GDPR rules do not apply at all. That is, the consent signal says «no», and the advertising works.
Timeline of the leak
Declared versus actual
Detected trackers
- Google Ad Manager
- Criteo
- PubMatic
- OpenX
- ID5
- RTB House
- Integral Ad Science
- DoubleClick
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — programmatic advertising fires against the explicit «consent not given» signalThe site has its own IAB-standard (TCF) consent-collection platform. In a clean session it forms a consent string, which it passes to the advertising vendors — and this string, when decoded, shows that consent is not given for any processing purpose (all purposes zeroed, special features off). That is, the signal is unambiguous: the user allowed nothing. Nevertheless, a whole set of advertising vendors fires despite this signal: Criteo and PubMatic perform cookie synchronisation, ID5 matches a cross-site advertising identifier, OpenX and RTB House connect, Google Ad Manager requests ads, DoubleClick records the impression, Integral Ad Science verifies impressions. Separately telling is that one of the PubMatic requests goes out with a flag as if the GDPR rules do not apply at all (although the user is in Italy). This is not a confusion of the consent signal — here the signal is correct and says «no», and the advertising infrastructure ignores it and still carries out identifier synchronisation and tracking. Under EU rules, storing and reading advertising identifiers requires precisely prior consent, so references to other bases do not cover this.
Context
www.autoscout24.it is a large online marketplace for the sale of new and used cars. The data controller is AutoScout24. The site is commercial: a listings catalogue, search, contacts with sellers, monetisation through advertising. Capture: 155 requests to 27 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. The site has its own IAB-standard (TCF) consent-collection platform. The technical stack is full-fledged programmatic advertising with the participation of many external vendors.
Who receives the data
Spotted here were: Criteo, PubMatic, OpenX, ID5, RTB House, Google, Integral Ad Science. This is a real-time advertising ecosystem: Google Ad Manager requests and serves ads; Criteo and PubMatic synchronise cookies; ID5 is a cross-site advertising-identifier provider, matching the user across sites; OpenX and RTB House are advertising exchanges; Integral Ad Science verifies impressions; DoubleClick records impressions. Additionally, a third-party tracking domain fires, sending an impression pixel. Here the data about the visit spreads across many independent advertising companies.
Was there a consent banner
Yes, the site has its own IAB-standard consent-collection platform. In a clean session no choice was made, and it forms a default consent string. The advertising vendors receive this string together with the requests — and when decoded it is unambiguous: consent is not given for any processing purpose. That is, the consent mechanism is not merely present — it explicitly tells the vendors «no». The problem is that the vendors do not observe this signal.
What fires before consent
Under a «no consent» signal the following fire anyway:
- identifier synchronisation by ID5, PubMatic, OpenX, Criteo, RTB House;
- Google Ad Manager ad request;
- Criteo cookie synchronisation;
- Integral Ad Science impression verification and DoubleClick impression recording;
- a third-party tracking pixel. It is fundamental that this is not a confusion of the signal, as happens when consent is mistakenly set to «given». Here the signal is correct and says «no» — and the advertising infrastructure ignores it. Identifier synchronisation and cookie-matching sets are advertising-tracking operations that under EU rules require prior consent.
The disabled GDPR flag
The PubMatic request that goes out with a flag meaning that the GDPR rules do not apply deserves separate mention. The user, meanwhile, is located in Italy, that is, under the full effect of the GDPR. Passing such a flag to an advertising vendor effectively lifts the restrictions of the European rules from it — which directly contradicts both the fact and the signal of the site’s own consent platform, which at the same time reports «no».
Conclusion
Autoscout24.it shows a typical and at the same time serious problem of programmatic advertising. The consent platform on the site exists and works correctly — it forms and passes the vendors a «no consent» signal. But two dozen advertising companies ignore this signal: they synchronise identifiers, request ads, record impressions, and one of the requests goes out as if the GDPR does not apply at all. The main takeaway for the reader: the mere presence of a correct consent platform guarantees nothing if the advertising vendors do not observe its signal — and this is verified only by a network capture with decoding of the consent string, and here the capture shows that the string says «no», and the advertising works. This is the gap between what the consent mechanism promises and what actually goes out to the advertising network.
196c38294d75df24dba8bbc2a54890b23603d57be0167b6f06b31d1f2896502eWhere to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website autoscout24.it. 2. Circumstances I visited the website autoscout24.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 20 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site has its own IAB-standard (TCF) consent-collection platform. In a clean session it forms a consent string, which it passes to the advertising vendors — and this string, when decoded, shows that consent is not given for any processing purpose (all purposes zeroed, special features off). That is, the signal is unambiguous: the user allowed nothing. Nevertheless, a whole set of advertising vendors fires despite this signal: Criteo and PubMatic perform cookie synchronisation, ID5 matches a cross-site advertising identifier, OpenX and RTB House connect, Google Ad Manager requests ads, DoubleClick records the impression, Integral Ad Science verifies impressions. Separately telling is that one of the PubMatic requests goes out with a flag as if the GDPR rules do not apply at all (although the user is in Italy). This is not a confusion of the consent signal — here the signal is correct and says «no», and the advertising infrastructure ignores it and still carries out identifier synchronisation and tracking. Under EU rules, storing and reading advertising identifiers requires precisely prior consent, so references to other bases do not cover this. Full technical documentation is published at: https://gdpru.eu/en/audits/it-autoscout24-it/ 3. Provisions violated Art. 6(1)(a) GDPR — programmatic advertising fires against the explicit «consent not given» signal 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]