The website of Immobiliare.it — Italy's largest real-estate portal. 113 requests, 23 domains. The Didomi consent banner is present, but the advertising-retargeting stack — Google with remarketing, Meta, RTB House, the Segment customer-data platform — fires from the first second, before any consent decision, synchronising the visitor's identifiers.
Timeline of the leak
Declared versus actual
Detected trackers
- Google (DoubleClick, remarketing audience 1p-user-list, analytics via a first-party gateway)
- Meta / Facebook Pixel
- RTB House (creativecdn.com) — retargeting with identifier synchronisation
- Segment — customer-data platform
- DataDome — anti-bot
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — the advertising and retargeting stack before consentThe Didomi consent banner loads first (+727 ms), but there is no recorded «accepted/declined» decision in the capture, while the whole marketing stack fires immediately after. Facebook sends a view event (+1365 ms), Google — a measurement and the building of a remarketing audience (rmkt/collect and 1p-user-list, +1537–1860 ms), RTB House — retargeting tags and identifier synchronisation via redirects (+1348–2218 ms), the Segment customer-data platform — its own requests. That is, the banner is present, but the trackers do not depend on it and merge the visitor's identifiers across platforms without consent.
- Art. 13(1)(e) GDPR — recipients not named in the main documentThe policy describes profiling and marketing as processing purposes, but does not name specific recipients — Google, Meta, RTB House, Segment, DataDome — in the main document. The cookie details are moved to separate documentation, which did not make it into the export.
Context
www.immobiliare.it is the website of Immobiliare.it, Italy’s largest portal for searching for and renting real estate. People come here to look for housing — and this is an intention that says a lot about a person’s financial plans and life situation. The capture shows 113 requests to 23 domains. The company itself is correctly named as the data controller, and the Didomi consent-management system is installed on the site. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. The case is typical of a large commercial site: there is a consent banner, but it works rather for show.
Who receives the data
Spotted here were: Google, Meta, RTB House, Segment, DataDome.
Was there a consent banner
The banner is present — the Didomi system, and it loads first, before the main stack. But that is where its role ends: there is no recorded user decision — «accepted» or «declined» — in the capture, while the whole advertising and retargeting set fires immediately after, without depending on the banner in any way. That is, its one and only task — to hold back the trackers until the user’s choice — the banner does not perform.
The advertising and retargeting stack before consent
From the very first seconds a serious set switches on. Facebook receives a view event. Google not only takes a measurement but also builds a remarketing audience — that is, adds the visitor to a list by which it will later show them advertising on other sites. RTB House, a specialised retargeting platform, loads its tags and, through a chain of redirects, synchronises the visitor’s identifier — merges its marker with the markers of other participants in the advertising market. The Segment customer-data platform gathers events into a single profile. And all of this is before any consent.
Interest in housing goes to advertising
It is worth naming exactly what leaks here. On a real-estate portal, the visitor’s behaviour — which listings they view, in which district, in which price category — is a direct signal about their intentions and budget. And this signal, from the first second, goes to Google’s remarketing and RTB House’s retargeting. In other words, the housing search is turned into an advertising profile even before the person chose anything in the consent banner.
The policy describes purposes, but not recipients
The document is arranged in detail and names profiling and marketing among the processing purposes — that is, the mere fact of advertising activity is not hidden. But the specific data recipients — Google, Meta, RTB House, Segment, DataDome — the main document does not name, moving the cookie details to separate documentation. So the visitor will not learn from the main policy which advertising networks their data spreads to.
What cannot be claimed from the capture
A few honest caveats. There is no recorded consent decision in the capture — this is an automatic capture, and to a live user the banner is of course shown; but the fundamental point is that the trackers fire independently of it. Identifier synchronisation I determine from the characteristic redirects between the advertising domains, not from saved cookies. I did not export the separate cookie documentation — the recipients may be named there. The DataDome anti-bot protection also performs a legitimate fraud-protection function. The capture covers the home page.
Conclusion
The country’s largest real-estate portal carries a full-fledged advertising-retargeting stack — Google remarketing, Meta, RTB House’s specialised retargeting, the Segment customer-data platform — and it all fires from the first second, synchronising the visitor’s identifiers across platforms, while the Didomi consent banner is present but holds nothing back. The specific recipients are not named in the main document. The main takeaway for the reader: on a housing-search site your interest in real estate becomes an advertising profile immediately on entry — the consent banner is here, but it asks supposedly later and supposedly about nothing.
Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website immobiliare.it. 2. Circumstances I visited the website immobiliare.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The Didomi consent banner loads first (+727 ms), but there is no recorded «accepted/declined» decision in the capture, while the whole marketing stack fires immediately after. Facebook sends a view event (+1365 ms), Google — a measurement and the building of a remarketing audience (rmkt/collect and 1p-user-list, +1537–1860 ms), RTB House — retargeting tags and identifier synchronisation via redirects (+1348–2218 ms), the Segment customer-data platform — its own requests. That is, the banner is present, but the trackers do not depend on it and merge the visitor's identifiers across platforms without consent. 2) The policy describes profiling and marketing as processing purposes, but does not name specific recipients — Google, Meta, RTB House, Segment, DataDome — in the main document. The cookie details are moved to separate documentation, which did not make it into the export. Full technical documentation is published at: https://gdpru.eu/en/audits/it-immobiliare-it/ 3. Provisions violated Art. 6(1)(a) GDPR — the advertising and retargeting stack before consent; Art. 13(1)(e) GDPR — recipients not named in the main document 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]