Technical audit · 2026-06-20

euronics.it

Electronics and Home Appliances Store

Euronics.it is an electronics and home-appliances store chain. Home-page capture: 211 requests, 26 domains — one of the most behaviourally-tracking-heavy commercial sites. There is a OneTrust consent-collection platform, but its consent check is recorded only at around the 17th second, while before it the full arsenal of behaviour tracking fires. Three session-recording and behavioural-analysis tools at once — Microsoft Clarity, Hotjar and VWO; Salesforce profiling across several services; Google Analytics with analytics allowed by default; a Google advertising tag and Klarna payment tracking. Microsoft Clarity, meanwhile, actively records the session and sends it to its servers before consent. All these tools are named in the policy, but they fire before the user's choice.

Timeline of the leak

980–985 ms · Salesforce profiling and payment
Salesforce's profiling services start: the customer-data platform and the personalisation service, as well as the Klarna payment service's tracking and Google's A/B-testing tool. All of this before consent.
1077–2496 ms · Salesforce recommendation engine
The Salesforce recommendation engine (Einstein) connects and requests personalised selections based on behaviour. Profiling unfolds before consent.
1554 ms · VWO behavioural analysis
The VWO tool sends a behavioural beacon. This is analysis of the user's actions on the page, before consent.
2626 ms · OneTrust consent platform
The OneTrust consent-collection platform loads. A consent mechanism is provided — which means that what fires before the choice happens before consent.
2671–2674 ms · Hotjar and Microsoft Clarity session recording
Two session-recording tools launch — Hotjar and Microsoft Clarity. They record the user's behaviour on the page: movements, clicks, scrolling.
2674 ms onward · Clarity records and sends the session
Microsoft Clarity sends the session-recording data to its servers — more than ten times over the course of the session. That is, the user's behaviour is really recorded and goes outward, before consent.
3874–3989 ms · Google Analytics and advertising tag
Google Analytics sends a view with analytics allowed by default, and the Google advertising tag sends a utility ping (in non-personalised mode).
around 17 seconds · consent check
The OneTrust platform records the consent check only at around the 17th second — that is, the session recording and profiling have long fired by this moment. No cookie was set via the headers during the session.

Declared versus actual

Microsoft Clarity — заявлен
Hotjar — заявлен
VWO — заявлен
Salesforce iGoDigital — заявлен
Salesforce Einstein — заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.euronics.it is an electronics and home-appliances store chain. The data controller is the Euronics operator. The site is commercial: catalogue, search, cart, personal account, instalments. Capture: 211 requests to 26 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. There is a OneTrust consent-collection platform. The technical stack is one of the most behaviourally-tracking-heavy among commercial sites.

Who receives the data

Spotted here were: Microsoft, Salesforce, Google, Klarna. Microsoft receives the session recording via Clarity — the recording of movements, clicks and scrolling. Salesforce is represented by several profiling services at once: a customer-data platform, a personalisation service and a recommendation engine. Google — by analytics and an advertising tag. Klarna — by payment tracking. Additionally, two more behavioural-analysis tools work — Hotjar and VWO. That is, three session-recording and behavioural-analysis tools operate on the site simultaneously.

Yes, the site has a OneTrust consent-collection platform, but its consent check in the session is recorded only at around the 17th second. By this moment the session recording and profiling have already fired and sent data. Meanwhile it is important: the policy itself classes the profiling cookies as non-technical, requiring consent, and equates the analytics to technical only on condition of de-identification. Session recording and profiling do not fall under de-identified analytics — this is individual behavioural observation.

Before consent is recorded, the following fire:

  • Microsoft Clarity — session recording with data sent more than ten times;
  • Hotjar and VWO — two more behavioural-analysis tools;
  • Salesforce profiling — customer-data platform, personalisation and recommendation engine;
  • Google Analytics — with analytics allowed by default;
  • the Google advertising tag and Klarna payment tracking. Session recording captures the user’s individual behaviour — this is not aggregate statistics, and by EU rules such observation requires prior consent. Here it unfolds a dozen seconds before consent is recorded.

It is worth noting: the site’s transparency in terms of naming recipients is better than some others’. All these tools — Clarity, Hotjar, VWO, the Salesforce services — are named in the policy. The problem is not that they are hidden, but that they fire before consent. Naming a tool does not replace a legal basis: if a service records the user’s behaviour, it must wait for consent rather than simply be mentioned in the document.

Conclusion

Euronics.it is one of the heaviest commercial cases in terms of the volume of behavioural tracking. Before consent, which is recorded only by the 17th second, three session-recording and behavioural-analysis tools, several Salesforce profiling services and Google analytics allowed by default already work on the site. Microsoft Clarity, meanwhile, really records the user’s session and sends it outward. The main takeaway for the reader: session recording and profiling are individual observation that must wait for consent, and the presence of these tools in the policy’s list changes nothing if they are switched on before the choice. Here practically the entire behavioural stack manages to fire before consent all at once.

Evidence
Original (audit)
HAR file: it/euronics-it-2026-06-20.har
SHA-256: 8f1fe746a9cd30b920b27364517b00a38b2627000bcca86acfbd8b07d5cdedb3
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website euronics.it.

2. Circumstances
I visited the website euronics.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 20 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site has a OneTrust consent-collection platform, but its consent check in this session is recorded only at around the 17th second — while before it a whole arsenal of behavioural tracking manages to fire. Microsoft Clarity records the session (movements, clicks, scrolling) and sends the data to its servers more than ten times starting from the third second. In parallel, two more behavioural-analysis tools work — Hotjar and VWO. Salesforce profiling is represented by several services at once: a customer-data platform, a personalisation service and a recommendation engine — all of them collect and transmit behavioural data. Google Analytics, meanwhile, launches with analytics allowed by default. Session recording and profiling are not de-identified statistics but individual behavioural observation requiring prior consent. Here it unfolds a dozen seconds before consent is even recorded.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-euronics-it/

3. Provisions violated
Art. 6(1)(a) GDPR — session recording and profiling fire before consent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]