Euronics.it is an electronics and home-appliances store chain. Home-page capture: 211 requests, 26 domains — one of the most behaviourally-tracking-heavy commercial sites. There is a OneTrust consent-collection platform, but its consent check is recorded only at around the 17th second, while before it the full arsenal of behaviour tracking fires. Three session-recording and behavioural-analysis tools at once — Microsoft Clarity, Hotjar and VWO; Salesforce profiling across several services; Google Analytics with analytics allowed by default; a Google advertising tag and Klarna payment tracking. Microsoft Clarity, meanwhile, actively records the session and sends it to its servers before consent. All these tools are named in the policy, but they fire before the user's choice.
Timeline of the leak
Declared versus actual
Detected trackers
- Microsoft Clarity (session recording)
- Hotjar (session recording)
- VWO
- Salesforce (profiling)
- Google Analytics 4
- Google AdSense
- Klarna
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — session recording and profiling fire before consentThe site has a OneTrust consent-collection platform, but its consent check in this session is recorded only at around the 17th second — while before it a whole arsenal of behavioural tracking manages to fire. Microsoft Clarity records the session (movements, clicks, scrolling) and sends the data to its servers more than ten times starting from the third second. In parallel, two more behavioural-analysis tools work — Hotjar and VWO. Salesforce profiling is represented by several services at once: a customer-data platform, a personalisation service and a recommendation engine — all of them collect and transmit behavioural data. Google Analytics, meanwhile, launches with analytics allowed by default. Session recording and profiling are not de-identified statistics but individual behavioural observation requiring prior consent. Here it unfolds a dozen seconds before consent is even recorded.
Context
www.euronics.it is an electronics and home-appliances store chain. The data controller is the Euronics operator. The site is commercial: catalogue, search, cart, personal account, instalments. Capture: 211 requests to 26 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. There is a OneTrust consent-collection platform. The technical stack is one of the most behaviourally-tracking-heavy among commercial sites.
Who receives the data
Spotted here were: Microsoft, Salesforce, Google, Klarna. Microsoft receives the session recording via Clarity — the recording of movements, clicks and scrolling. Salesforce is represented by several profiling services at once: a customer-data platform, a personalisation service and a recommendation engine. Google — by analytics and an advertising tag. Klarna — by payment tracking. Additionally, two more behavioural-analysis tools work — Hotjar and VWO. That is, three session-recording and behavioural-analysis tools operate on the site simultaneously.
Was there a consent banner
Yes, the site has a OneTrust consent-collection platform, but its consent check in the session is recorded only at around the 17th second. By this moment the session recording and profiling have already fired and sent data. Meanwhile it is important: the policy itself classes the profiling cookies as non-technical, requiring consent, and equates the analytics to technical only on condition of de-identification. Session recording and profiling do not fall under de-identified analytics — this is individual behavioural observation.
What fires before consent
Before consent is recorded, the following fire:
- Microsoft Clarity — session recording with data sent more than ten times;
- Hotjar and VWO — two more behavioural-analysis tools;
- Salesforce profiling — customer-data platform, personalisation and recommendation engine;
- Google Analytics — with analytics allowed by default;
- the Google advertising tag and Klarna payment tracking. Session recording captures the user’s individual behaviour — this is not aggregate statistics, and by EU rules such observation requires prior consent. Here it unfolds a dozen seconds before consent is recorded.
Declared, but switched on before consent
It is worth noting: the site’s transparency in terms of naming recipients is better than some others’. All these tools — Clarity, Hotjar, VWO, the Salesforce services — are named in the policy. The problem is not that they are hidden, but that they fire before consent. Naming a tool does not replace a legal basis: if a service records the user’s behaviour, it must wait for consent rather than simply be mentioned in the document.
Conclusion
Euronics.it is one of the heaviest commercial cases in terms of the volume of behavioural tracking. Before consent, which is recorded only by the 17th second, three session-recording and behavioural-analysis tools, several Salesforce profiling services and Google analytics allowed by default already work on the site. Microsoft Clarity, meanwhile, really records the user’s session and sends it outward. The main takeaway for the reader: session recording and profiling are individual observation that must wait for consent, and the presence of these tools in the policy’s list changes nothing if they are switched on before the choice. Here practically the entire behavioural stack manages to fire before consent all at once.
8f1fe746a9cd30b920b27364517b00a38b2627000bcca86acfbd8b07d5cdedb3Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website euronics.it. 2. Circumstances I visited the website euronics.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 20 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site has a OneTrust consent-collection platform, but its consent check in this session is recorded only at around the 17th second — while before it a whole arsenal of behavioural tracking manages to fire. Microsoft Clarity records the session (movements, clicks, scrolling) and sends the data to its servers more than ten times starting from the third second. In parallel, two more behavioural-analysis tools work — Hotjar and VWO. Salesforce profiling is represented by several services at once: a customer-data platform, a personalisation service and a recommendation engine — all of them collect and transmit behavioural data. Google Analytics, meanwhile, launches with analytics allowed by default. Session recording and profiling are not de-identified statistics but individual behavioural observation requiring prior consent. Here it unfolds a dozen seconds before consent is even recorded. Full technical documentation is published at: https://gdpru.eu/en/audits/it-euronics-it/ 3. Provisions violated Art. 6(1)(a) GDPR — session recording and profiling fire before consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]