Policy changed — see what exactly · 2026-07-23 →
The website of the city of Milan, the country's largest municipality. 169 requests, 17 domains. On the city hall's site a full Adobe advertising-audience stack works, plus Pendo product analytics — this is audience profiling, not basic statistics. The stack starts before the consent banner even appears on the screen, while the official policy promises «technical cookies only» and «no transfer outside the EEA» — both promises do not match the fact.
Timeline of the leak
Declared versus actual
Detected trackers
- Adobe Audience Manager (dpm.demdex.net, comunedimilano.demdex.net) — building advertising audiences
- Adobe Advertising Cloud / Everest Tech (cm.everesttech.net) — cross-site identifier synchronisation
- Adobe Analytics (comunedimilano.d3.sc.omtrdc.net)
- Adobe Experience Cloud (adobedc.demdex.net)
- Adobe Launch (assets.adobedtm.com)
- Pendo (data.eu.pendo.io, cdn.eu.pendo.io)
- Web Analytics Italia / Matomo (ingestion.webanalytics.italia.it, idsite=1975)
- Google reCAPTCHA
- OneTrust (consent banner)
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — the advertising stack starts before the banner, without consentAdobe's advertising-audience-building system requests an identifier at +1378 ms, and Adobe's advertising synchronisation at +1752 ms. Both of these happen BEFORE the consent banner is even rendered on the screen (+1806 ms). The request at +1634 ms is not consent, but region geolocation. The «accepted/declined» event itself is not present in the capture at all, while real collection continues further: an Adobe Analytics hit (+1976 ms), Adobe server-side collection (+2083 ms), partner identifier synchronisation (+2150 ms), Pendo product analytics (+2239 ms). There is no consent-waiting mode whatsoever.
- Art. 13(1)(e) GDPR — the policy states «technical cookies only»The portal's official cookie notice states verbatim that only technical cookies are collected and that personal data is not transferred to third parties. In fact, Adobe's advertising-audience infrastructure (audience building and cross-site identifier synchronisation) and Pendo product analytics work — these are not technical cookies, and they transmit the visitor's data to third-party companies. Neither Adobe nor Pendo is named in the notice.
- Art. 44 GDPR — declared «we do not transfer outside the EEA»The site-access notice explicitly states that data is not transferred to third countries outside the EU/EEA. Yet the recipients — Adobe and Pendo — are American companies, and the requests to their services transmit the visitor's data across the ocean.
Context
www.comune.milano.it is the official website of the municipality of Milan, Italy’s largest city-commune. Through it citizens access city services: school meals, social services, tax documents, the «resident’s personal account». The capture shows 169 requests to 17 domains. The municipality itself is correctly named as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. This is one of the most serious government cases in the series — and the seriousness is not in the number of domains but in their nature: on the city hall’s site there works not basic statistics, but a full-fledged advertising-audience machine.
Who receives the data
Spotted here were: Adobe, Pendo, Google.
Was there a consent banner
There is a OneTrust banner on the site, but by the moment it only begins to render on the screen (+1806 ms), Adobe’s advertising machine has already fired. The request at +1634 ms, easily mistaken for consent, is merely region geolocation to choose the banner rules. And the «accepted» or «declined» event itself is not present in the capture at all. That is, the visitor has not yet seen any choice, while their identifier is already being requested from the advertising-audience system and synchronised between sites.
Adobe’s advertising machine — what it is and when it fired
Here it is important to explain what exactly is on the site, because this is not the usual counter. The advertising-audience-building system gathers visitors into segments for targeting. The identifier-synchronisation advertising platform is needed to recognise the same person on different sites, exchanging their markers with other participants in the advertising market. This is exactly what happens here: at +1378 ms an audience identifier is requested, at +1752 ms cross-site synchronisation goes on, and at +2150 ms the visitor’s marker is merged with an external data partner. In parallel, Adobe analytics and its server-side collection work, and after them Pendo product analytics. All of this is advertising and behavioural-profiling tools, not technical means of running the site.
The policy promises «technical cookies only» — and this is not so
The portal’s official cookie notice is worded unambiguously: only technical cookies are collected, and personal data is not transferred to third parties. Comparison with the capture shows the opposite. Adobe’s advertising-audience infrastructure and Pendo analytics are not technical cookies, and they do precisely transmit the visitor’s data to third-party companies, and before consent at that. Neither Adobe nor Pendo is named in the notice. The gap between «technical only, we transfer to no one» and the actual advertising synchronisation with an external partner is not a minor inaccuracy, but a contradiction in essence.
«We do not transfer outside the EEA» — while the recipients are in the USA
The second categorical phrase that the capture refutes. The site-access notice explicitly states that data is not transferred outside the EU and the European Economic Area. But the main recipients here — Adobe and Pendo — are American companies, and every request to their services takes the visitor’s data across the ocean. The promise about the EEA borders and the actual transfer to the USA are incompatible.
What cannot be claimed from the capture
A few honest caveats. The consent event is not present in the capture — this is an automatic capture, and to a live visitor the banner is of course shown; but the fundamental point is that Adobe’s advertising requests go out before the banner is even rendered, that is, they do not depend on the user’s choice. Cookie-setting on Adobe’s side is not directly visible in the lightweight export — on the identifier synchronisation I judge from the characteristic redirects between its domains. The official cookie notice I read from the available publication rather than exporting in full, but the wording about «exclusively technical cookies» in it is unambiguous. The capture covers the public home page; the «personal account» services behind login are not engaged here.
Conclusion
This is one of the heaviest government cases in the series. The website of the country’s largest city, through which citizens turn to city services, carries a full-fledged Adobe advertising-audience machine — with segment building, cross-site identifier synchronisation and the merging of the visitor’s marker with an external data partner — as well as Pendo product analytics. All of this starts before the consent banner appears. And all of this against the backdrop of an official policy that promises «technical cookies only», «no transfer to third parties» and «nothing outside the EEA». Not one of the three promises withstands comparison with the capture. The main takeaway for the reader: here a municipal site, which citizens trust out of necessity rather than choice, behaves like a commercial advertising platform — and does so silently, in defiance of its own assurances.
5b4a9de877bac72343bbf85c40b03b7f9b36dc85e26a6b59c2d25dfbe0defb73Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website comune.milano.it. 2. Circumstances I visited the website comune.milano.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) Adobe's advertising-audience-building system requests an identifier at +1378 ms, and Adobe's advertising synchronisation at +1752 ms. Both of these happen BEFORE the consent banner is even rendered on the screen (+1806 ms). The request at +1634 ms is not consent, but region geolocation. The «accepted/declined» event itself is not present in the capture at all, while real collection continues further: an Adobe Analytics hit (+1976 ms), Adobe server-side collection (+2083 ms), partner identifier synchronisation (+2150 ms), Pendo product analytics (+2239 ms). There is no consent-waiting mode whatsoever. 2) The portal's official cookie notice states verbatim that only technical cookies are collected and that personal data is not transferred to third parties. In fact, Adobe's advertising-audience infrastructure (audience building and cross-site identifier synchronisation) and Pendo product analytics work — these are not technical cookies, and they transmit the visitor's data to third-party companies. Neither Adobe nor Pendo is named in the notice. 3) The site-access notice explicitly states that data is not transferred to third countries outside the EU/EEA. Yet the recipients — Adobe and Pendo — are American companies, and the requests to their services transmit the visitor's data across the ocean. Full technical documentation is published at: https://gdpru.eu/en/audits/it-comune-milano-it/ 3. Provisions violated Art. 6(1)(a) GDPR — the advertising stack starts before the banner, without consent; Art. 13(1)(e) GDPR — the policy states «technical cookies only»; Art. 44 GDPR — declared «we do not transfer outside the EEA» 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]