Technical audit · 2026-06-15

comune.milano.it

City of Milan

The website of the city of Milan, the country's largest municipality. 169 requests, 17 domains. On the city hall's site a full Adobe advertising-audience stack works, plus Pendo product analytics — this is audience profiling, not basic statistics. The stack starts before the consent banner even appears on the screen, while the official policy promises «technical cookies only» and «no transfer outside the EEA» — both promises do not match the fact.

Timeline of the leak

+902 ms · stack load
In parallel, in the same millisecond, the Adobe Launch tag system (assets.adobedtm.com) and the OneTrust consent-banner stub load.
+1378 ms · Adobe audiences, before the banner
A request to Adobe's advertising-audience-building system (dpm.demdex.net/id) for a visitor identifier. The banner is not yet shown.
+1384 ms · Adobe measurer
The Adobe Analytics library (AppMeasurement) and the activity-map module load.
+1411 ms · government analytics
The Web Analytics Italia government analytics script loads.
+1634 ms · geolocation (not consent)
A request to geolocation.onetrust.com determines the user's region in order to choose the banner rules. This is not the recording of consent.
+1752 ms · Adobe advertising synchronisation, before the banner
Adobe's advertising platform (cm.everesttech.net) performs a redirect to synchronise identifiers between sites, and Adobe's audience domain (comunedimilano.demdex.net) loads the destination for matching the markers. The banner is still not rendered.
+1806 ms · the banner only begins to render
Only now does the visual part of the OneTrust banner load — when Adobe's advertising requests have already been sent. The banner's configuration and interface finish loading by +2050 ms.
+1867 ms · government-analytics measurement
Web Analytics Italia sends a visit measurement (idsite=1975).
+1976 ms · real Adobe Analytics hit
A full visit measurement goes out to Adobe Analytics (comunedimilano.d3.sc.omtrdc.net).
+2083 ms · Adobe server-side collection
A request to the Adobe Experience Cloud server node (adobedc.demdex.net/interact) — collection of data about the visit on Adobe's side.
+2150 ms · partner synchronisation
Adobe's audience system performs identifier synchronisation with an external data partner (dpm.demdex.net, dpid=411) — that very merging of markers between different participants in the advertising market.
+2239 ms · Pendo product analytics
Pendo loads and initialises — a user-behaviour-analysis service (a US company).
+2729 ms · reCAPTCHA
Google reCAPTCHA loads for the forms. Not a single Set-Cookie throughout the entire session was recorded in the export.

Declared versus actual

Web Analytics Italia (mentioned in the general notice as anonymous statistics) — заявлен
+ Adobe Audience Manager — не заявлен
+ Adobe Advertising Cloud / Everest Tech — не заявлен
+ Adobe Analytics — не заявлен
+ Adobe Experience Cloud — не заявлен
+ Pendo — не заявлен
+ demdex partner synchronisation (dpid=411) — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.comune.milano.it is the official website of the municipality of Milan, Italy’s largest city-commune. Through it citizens access city services: school meals, social services, tax documents, the «resident’s personal account». The capture shows 169 requests to 17 domains. The municipality itself is correctly named as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. This is one of the most serious government cases in the series — and the seriousness is not in the number of domains but in their nature: on the city hall’s site there works not basic statistics, but a full-fledged advertising-audience machine.

Who receives the data

Spotted here were: Adobe, Pendo, Google.

There is a OneTrust banner on the site, but by the moment it only begins to render on the screen (+1806 ms), Adobe’s advertising machine has already fired. The request at +1634 ms, easily mistaken for consent, is merely region geolocation to choose the banner rules. And the «accepted» or «declined» event itself is not present in the capture at all. That is, the visitor has not yet seen any choice, while their identifier is already being requested from the advertising-audience system and synchronised between sites.

Adobe’s advertising machine — what it is and when it fired

Here it is important to explain what exactly is on the site, because this is not the usual counter. The advertising-audience-building system gathers visitors into segments for targeting. The identifier-synchronisation advertising platform is needed to recognise the same person on different sites, exchanging their markers with other participants in the advertising market. This is exactly what happens here: at +1378 ms an audience identifier is requested, at +1752 ms cross-site synchronisation goes on, and at +2150 ms the visitor’s marker is merged with an external data partner. In parallel, Adobe analytics and its server-side collection work, and after them Pendo product analytics. All of this is advertising and behavioural-profiling tools, not technical means of running the site.

The policy promises «technical cookies only» — and this is not so

The portal’s official cookie notice is worded unambiguously: only technical cookies are collected, and personal data is not transferred to third parties. Comparison with the capture shows the opposite. Adobe’s advertising-audience infrastructure and Pendo analytics are not technical cookies, and they do precisely transmit the visitor’s data to third-party companies, and before consent at that. Neither Adobe nor Pendo is named in the notice. The gap between «technical only, we transfer to no one» and the actual advertising synchronisation with an external partner is not a minor inaccuracy, but a contradiction in essence.

«We do not transfer outside the EEA» — while the recipients are in the USA

The second categorical phrase that the capture refutes. The site-access notice explicitly states that data is not transferred outside the EU and the European Economic Area. But the main recipients here — Adobe and Pendo — are American companies, and every request to their services takes the visitor’s data across the ocean. The promise about the EEA borders and the actual transfer to the USA are incompatible.

What cannot be claimed from the capture

A few honest caveats. The consent event is not present in the capture — this is an automatic capture, and to a live visitor the banner is of course shown; but the fundamental point is that Adobe’s advertising requests go out before the banner is even rendered, that is, they do not depend on the user’s choice. Cookie-setting on Adobe’s side is not directly visible in the lightweight export — on the identifier synchronisation I judge from the characteristic redirects between its domains. The official cookie notice I read from the available publication rather than exporting in full, but the wording about «exclusively technical cookies» in it is unambiguous. The capture covers the public home page; the «personal account» services behind login are not engaged here.

Conclusion

This is one of the heaviest government cases in the series. The website of the country’s largest city, through which citizens turn to city services, carries a full-fledged Adobe advertising-audience machine — with segment building, cross-site identifier synchronisation and the merging of the visitor’s marker with an external data partner — as well as Pendo product analytics. All of this starts before the consent banner appears. And all of this against the backdrop of an official policy that promises «technical cookies only», «no transfer to third parties» and «nothing outside the EEA». Not one of the three promises withstands comparison with the capture. The main takeaway for the reader: here a municipal site, which citizens trust out of necessity rather than choice, behaves like a commercial advertising platform — and does so silently, in defiance of its own assurances.

Evidence
Original (audit)
HAR file: it/www-comune-milano-it-2026-06-15.har
SHA-256: 5b4a9de877bac72343bbf85c40b03b7f9b36dc85e26a6b59c2d25dfbe0defb73
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website comune.milano.it.

2. Circumstances
I visited the website comune.milano.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) Adobe's advertising-audience-building system requests an identifier at +1378 ms, and Adobe's advertising synchronisation at +1752 ms. Both of these happen BEFORE the consent banner is even rendered on the screen (+1806 ms). The request at +1634 ms is not consent, but region geolocation. The «accepted/declined» event itself is not present in the capture at all, while real collection continues further: an Adobe Analytics hit (+1976 ms), Adobe server-side collection (+2083 ms), partner identifier synchronisation (+2150 ms), Pendo product analytics (+2239 ms). There is no consent-waiting mode whatsoever.

2) The portal's official cookie notice states verbatim that only technical cookies are collected and that personal data is not transferred to third parties. In fact, Adobe's advertising-audience infrastructure (audience building and cross-site identifier synchronisation) and Pendo product analytics work — these are not technical cookies, and they transmit the visitor's data to third-party companies. Neither Adobe nor Pendo is named in the notice.

3) The site-access notice explicitly states that data is not transferred to third countries outside the EU/EEA. Yet the recipients — Adobe and Pendo — are American companies, and the requests to their services transmit the visitor's data across the ocean.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-comune-milano-it/

3. Provisions violated
Art. 6(1)(a) GDPR — the advertising stack starts before the banner, without consent; Art. 13(1)(e) GDPR — the policy states «technical cookies only»; Art. 44 GDPR — declared «we do not transfer outside the EEA»

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]