Technical audit · 2026-06-15

immobiliare.it

Italy's Largest Real-Estate Portal

The website of Immobiliare.it — Italy's largest real-estate portal. 113 requests, 23 domains. The Didomi consent banner is present, but the advertising-retargeting stack — Google with remarketing, Meta, RTB House, the Segment customer-data platform — fires from the first second, before any consent decision, synchronising the visitor's identifiers.

Timeline of the leak

+727–1064 ms · consent-banner load
First the Didomi consent-management system loads. But, as seen further on, it does not wait for the user's decision.
+1171–1365 ms · CDP, retargeting and Facebook right after the banner
The Segment customer-data platform (+1171 ms), the RTB House retargeting tags (+1348 ms) and the Facebook view event (+1365 ms) load almost simultaneously with the banner, without depending on it in any way.
+1493–1860 ms · Google analytics and remarketing audience
The Google measurement goes out via a first-party gateway (+1493 ms), then the DoubleClick advertising conversion and the building of a Google remarketing audience activate (rmkt/collect and 1p-user-list, +1537–1860 ms) — the visitor is added to an advertising audience.
+2045–2587 ms · identifier synchronisation and anti-bot
Identifier-synchronisation redirects between DoubleClick and RTB House (+2045–2218 ms) — merging of the visitor's markers across platforms. Then the DataDome anti-bot protection connects. Not a single Set-Cookie throughout the entire session — the synchronisation goes via redirects.

Declared versus actual

+ Google (DoubleClick, remarketing) — не заявлен
+ Meta / Facebook Pixel — не заявлен
+ RTB House — не заявлен
+ Segment — не заявлен
+ DataDome — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.immobiliare.it is the website of Immobiliare.it, Italy’s largest portal for searching for and renting real estate. People come here to look for housing — and this is an intention that says a lot about a person’s financial plans and life situation. The capture shows 113 requests to 23 domains. The company itself is correctly named as the data controller, and the Didomi consent-management system is installed on the site. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. The case is typical of a large commercial site: there is a consent banner, but it works rather for show.

Who receives the data

Spotted here were: Google, Meta, RTB House, Segment, DataDome.

The banner is present — the Didomi system, and it loads first, before the main stack. But that is where its role ends: there is no recorded user decision — «accepted» or «declined» — in the capture, while the whole advertising and retargeting set fires immediately after, without depending on the banner in any way. That is, its one and only task — to hold back the trackers until the user’s choice — the banner does not perform.

From the very first seconds a serious set switches on. Facebook receives a view event. Google not only takes a measurement but also builds a remarketing audience — that is, adds the visitor to a list by which it will later show them advertising on other sites. RTB House, a specialised retargeting platform, loads its tags and, through a chain of redirects, synchronises the visitor’s identifier — merges its marker with the markers of other participants in the advertising market. The Segment customer-data platform gathers events into a single profile. And all of this is before any consent.

Interest in housing goes to advertising

It is worth naming exactly what leaks here. On a real-estate portal, the visitor’s behaviour — which listings they view, in which district, in which price category — is a direct signal about their intentions and budget. And this signal, from the first second, goes to Google’s remarketing and RTB House’s retargeting. In other words, the housing search is turned into an advertising profile even before the person chose anything in the consent banner.

The policy describes purposes, but not recipients

The document is arranged in detail and names profiling and marketing among the processing purposes — that is, the mere fact of advertising activity is not hidden. But the specific data recipients — Google, Meta, RTB House, Segment, DataDome — the main document does not name, moving the cookie details to separate documentation. So the visitor will not learn from the main policy which advertising networks their data spreads to.

What cannot be claimed from the capture

A few honest caveats. There is no recorded consent decision in the capture — this is an automatic capture, and to a live user the banner is of course shown; but the fundamental point is that the trackers fire independently of it. Identifier synchronisation I determine from the characteristic redirects between the advertising domains, not from saved cookies. I did not export the separate cookie documentation — the recipients may be named there. The DataDome anti-bot protection also performs a legitimate fraud-protection function. The capture covers the home page.

Conclusion

The country’s largest real-estate portal carries a full-fledged advertising-retargeting stack — Google remarketing, Meta, RTB House’s specialised retargeting, the Segment customer-data platform — and it all fires from the first second, synchronising the visitor’s identifiers across platforms, while the Didomi consent banner is present but holds nothing back. The specific recipients are not named in the main document. The main takeaway for the reader: on a housing-search site your interest in real estate becomes an advertising profile immediately on entry — the consent banner is here, but it asks supposedly later and supposedly about nothing.

Evidence
Original (audit)
HAR file: it/immobiliare-it-2026-06-15.har
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website immobiliare.it.

2. Circumstances
I visited the website immobiliare.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The Didomi consent banner loads first (+727 ms), but there is no recorded «accepted/declined» decision in the capture, while the whole marketing stack fires immediately after. Facebook sends a view event (+1365 ms), Google — a measurement and the building of a remarketing audience (rmkt/collect and 1p-user-list, +1537–1860 ms), RTB House — retargeting tags and identifier synchronisation via redirects (+1348–2218 ms), the Segment customer-data platform — its own requests. That is, the banner is present, but the trackers do not depend on it and merge the visitor's identifiers across platforms without consent.

2) The policy describes profiling and marketing as processing purposes, but does not name specific recipients — Google, Meta, RTB House, Segment, DataDome — in the main document. The cookie details are moved to separate documentation, which did not make it into the export.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-immobiliare-it/

3. Provisions violated
Art. 6(1)(a) GDPR — the advertising and retargeting stack before consent; Art. 13(1)(e) GDPR — recipients not named in the main document

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]