Italo is Italy's largest private high-speed rail operator and the first private operator on a high-speed rail network in Europe. 111 requests, 9 domains — the site is compact and at first glance tidy: there is a Didomi consent-collection platform, advertising cookies are disabled. But the main analytics is Google Analytics disguised as the site's own domain: the data goes via a subdomain of italotreno.com (physically on Microsoft Azure servers) and on to Google. And a record of the visit is sent together with a persistent visitor identifier before the person chose anything, with the analytics permission on by default. And the policy, meanwhile, promises that for the site's own cookies there is no transfer outside the EU, and calls the analytics «anonymous, equated to technical» — whereas this stream carries a unique identifier and goes to Google.
Timeline of the leak
Declared versus actual
Detected trackers
- Google Analytics 4 (counter ID G-KGDSYWDJH0), disguised as the site's own domain: the data goes to analytics.italotreno.com, hosted on Microsoft Azure
- Google Tag Manager — Google's tag-management system
- Didomi — consent-collection platform (sdk.privacy-center.org)
- Skeepers — customer-reviews platform
- Akamai mPulse — performance monitoring and bot protection
Indicators of GDPR non-compliance
- Art. 44 GDPR — the promise «we do not transfer data outside the EU» against a hidden Google Analytics in the USAThe site's policy explicitly promises: for the site's own cookies (Italo) no transfer outside the EU is envisaged, and for third-party ones it refers to a separate table. But the main analytics stream goes to the address analytics.italotreno.com — that is, it looks like the site's own domain. In fact this is Google Analytics: the same counter and the same format as Google's, merely passed through its own subdomain (physically — Microsoft Azure servers). Every such request transmits data about the visit to Google. It is precisely the appearance of an «own domain» that creates in the user the impression that there is no third-party transfer, let alone transfer abroad — whereas in fact this is Google, and its final recipient is located in the USA.
- Art. 6(1)(a) GDPR — analytics sent before consent, with permission on by defaultThe capture was taken on a clean browser: throughout the whole session the site set not a single cookie, that is, the Didomi consent cookie did not appear and the user chose nothing. The visible part of the consent banner is rendered at around 1.9 seconds. Nevertheless, already at 4.6 seconds Google Analytics sends a full page-view record together with a persistent visitor identifier, and the technical consent signal in this request shows: the analytics permission is on by default (while the advertising permission is off). That is, analytics tracking is allowed in advance, before any user decision, and the collection goes out immediately. Then come events about viewing promotions and regular «activity signals» at the 11th, 19th and 27th seconds.
- Art. 6(1)(a) GDPR + incorrect qualification — the analytics is declared «anonymous» and «technical», although it carries a persistent identifierThe policy justifies this analytics' exemption from consent by the fact that the analytics cookies are «equated to technical ones», collect data «in anonymous and aggregate form» and «do not identify the user», and therefore consent for them is «not required». But the capture refutes this: Google Analytics transmits a persistent visitor identifier — a stable browser marker by which one person is distinguished from another (the same one on which the count of «unique users» is built). This is neither anonymous nor aggregate data. Consequently, the basis «technical cookie, no consent needed» does not stand under this stream.
- Art. 13(1)(e) GDPR — recipients not named individuallyNeither the site's cookie policy nor the main privacy policy names specific recipients: neither Google and Google Analytics, nor Didomi, nor Skeepers, nor Akamai. The document operates with general formulas («third parties engaged in web analytics, advertising and social networks») and refers to «a table or the third party's policy». Who actually receives the data cannot be understood from the policies themselves.
Context
www.italotreno.com is the website of Italo, Italy’s largest private high-speed rail operator and Europe’s first private operator on a high-speed network. Tickets are sold through the site, so there is flight search, payment and a promotions showcase here. The capture is compact: 111 requests to 9 domains, taken on a clean Edge browser with no VPN and no blocker. There is a Didomi consent-collection platform on the site, and advertising cookies are indeed disabled in this session. At first glance — a tidy picture. The interest is in the fact that the main analytics is hidden so as to look like «its own».
Who receives the data
Spotted here were: Google, Didomi, Skeepers, Akamai. A caveat on roles: Didomi is the consent-collection platform itself, its presence is expected and is not a complaint. Skeepers is a customer-reviews platform. Akamai is performance monitoring and bot protection. The central figure of the analysis is Google: it is precisely its analytics that is disguised as Italo’s own domain.
Was there a consent banner
Yes, it is Didomi, and its visible part is rendered at around 1.9 seconds. But in this session the user pressed nothing: throughout the whole capture the site set not a single cookie, that is, the consent cookie did not appear. This is a clean first contact — and it is precisely in it that the «default» behaviour is visible.
Google Analytics disguised as an own domain
The main finding. The main analytics stream goes not to the usual Google domain, but to the address analytics.italotreno.com — that is, to a subdomain of Italo itself. But the contents of this stream leave no doubt: it is Google Analytics — the same counter and the same data format as Google’s, merely passed through the site’s own domain (physically — Microsoft Azure servers). This is a common trick: Google’s analytics is wrapped onto one’s own address so that it looks like «first-party» — this way it bypasses blockers and browser restrictions and stops «looking» like data transmission to Google. The effect is twofold. The technical one — the data reaches Google anyway. And the legal one — more on it below.
The analytics went out before consent, with permission on by default
At around 4.6 seconds this stream sends a full page-view record. In it — a persistent visitor identifier (assigned in this same session), the page address and title. And the technical consent signal accompanying the request shows: the advertising permission is off, but the analytics permission is on by default, before any user choice. Then an event about viewing a promotion goes out, and after it activity signals at the 11th, 19th and 27th seconds. Since the browser is clean and there is no consent cookie, the only consistent explanation is: the analytics permission is «on» by default, and Google Analytics collects data from the first screen without waiting for a decision.
«Anonymous and technical» — against a persistent identifier
The policy justifies this analytics’ exemption from consent directly: it classes the analytics cookies as «equated to technical ones», describing them as collection «in anonymous and aggregate form» that «does not identify the user» — and therefore «consent is not required». The whole construction rests on the word «anonymous». The capture removes this word. Google Analytics transmits a persistent visitor identifier — a stable browser marker by which one person is distinguished from another (the same one on which the count of «unique users» is built). This is neither anonymous nor aggregate data. And if so, the basis «technical cookie, no consent needed» does not stand under this specific stream: for analytics with a persistent identifier going to a third party, consent is required.
«We do not transfer outside the EU» — against Google in the USA
And here is where the disguise as an own domain strikes the policy itself. The document promises: for the site’s own cookies (Italo) no transfer outside the EU is envisaged, and for third-party ones — «see the table or the third party’s policy». Since the analytics is served from a subdomain of italotreno.com itself, it is presented as «its own» — that is, precisely the case where «there is no transfer abroad». But the contents of this «own» stream is Google Analytics, and its final recipient is Google. That is, the appearance of an own domain creates exactly the impression that the policy also fixes in words — «this is ours, it does not go abroad» — whereas in fact the data about the visit goes to Google. Promise and fact diverge, and diverge not by chance, but precisely by means of this wrapper.
Recipients not named
Neither the site’s cookie policy nor the main privacy policy names individually Google and Google Analytics, Didomi, Skeepers or Akamai. Instead — general formulas about «third parties engaged in web analytics, advertising and social networks» and a reference to «a table or the third party’s policy». The actual recipients cannot be learned from the documents themselves.
What cannot be claimed from the capture
A few honest caveats. The separate cookie table to which the policy refers I did not check by its full text — it is possible that Google and others are named in it; I record only that they are not in the body of both policies. Why exactly the analytics permission turned out to be on — a default setting or the treatment of the analytics as «technical» — cannot be said unambiguously from the capture; the fact is proven: on a clean browser without a consent cookie Google Analytics sent data with the analytics permission on. The subdomain analytics.italotreno.com is physically on Microsoft Azure servers — this is an intermediate link; the final recipient of the analytics is Google, and it is to it that the transfer-abroad question relates. Skeepers fired earliest — I note this as a fact of sequence, not as a proven transfer of a profile. Akamai with its monitoring and sensors is a performance and bot-protection function, defensible as technical, although the company itself is American and the data goes out before consent. The capture covers the home page.
Conclusion
Italo looks like a «good student»: the consent platform is in place, advertising cookies are off, the number of third parties is minimised. But the main analytics is Google Analytics wrapped onto its own subdomain (physically on Microsoft Azure servers), which sends a record of the visit with a persistent visitor identifier before the person chose anything, with the analytics permission on by default. And the policy describes this same stream in two ways incorrectly: it calls the analytics «anonymous, equated to technical» (whereas it carries a unique identifier) and promises that for the site’s own cookies there is no transfer outside the EU (whereas this is Google, going to the USA). The main takeaway for the reader: disguising a tracker as an own domain is not «privacy by default» but the reverse; it merely makes third-party transfer indistinguishable from «one’s own» by eye, and it is precisely on this indistinguishability that both of the policy’s promises rest, which the capture does not confirm.
676322ecc995b9ba4ef015f0ffb3c5e05a28f991233a79397308e52be48766f2Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website italotreno.com. 2. Circumstances I visited the website italotreno.com and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site's policy explicitly promises: for the site's own cookies (Italo) no transfer outside the EU is envisaged, and for third-party ones it refers to a separate table. But the main analytics stream goes to the address analytics.italotreno.com — that is, it looks like the site's own domain. In fact this is Google Analytics: the same counter and the same format as Google's, merely passed through its own subdomain (physically — Microsoft Azure servers). Every such request transmits data about the visit to Google. It is precisely the appearance of an «own domain» that creates in the user the impression that there is no third-party transfer, let alone transfer abroad — whereas in fact this is Google, and its final recipient is located in the USA. 2) The capture was taken on a clean browser: throughout the whole session the site set not a single cookie, that is, the Didomi consent cookie did not appear and the user chose nothing. The visible part of the consent banner is rendered at around 1.9 seconds. Nevertheless, already at 4.6 seconds Google Analytics sends a full page-view record together with a persistent visitor identifier, and the technical consent signal in this request shows: the analytics permission is on by default (while the advertising permission is off). That is, analytics tracking is allowed in advance, before any user decision, and the collection goes out immediately. Then come events about viewing promotions and regular «activity signals» at the 11th, 19th and 27th seconds. 3) The policy justifies this analytics' exemption from consent by the fact that the analytics cookies are «equated to technical ones», collect data «in anonymous and aggregate form» and «do not identify the user», and therefore consent for them is «not required». But the capture refutes this: Google Analytics transmits a persistent visitor identifier — a stable browser marker by which one person is distinguished from another (the same one on which the count of «unique users» is built). This is neither anonymous nor aggregate data. Consequently, the basis «technical cookie, no consent needed» does not stand under this stream. 4) Neither the site's cookie policy nor the main privacy policy names specific recipients: neither Google and Google Analytics, nor Didomi, nor Skeepers, nor Akamai. The document operates with general formulas («third parties engaged in web analytics, advertising and social networks») and refers to «a table or the third party's policy». Who actually receives the data cannot be understood from the policies themselves. Full technical documentation is published at: https://gdpru.eu/en/audits/it-italotreno-com-it/ 3. Provisions violated Art. 44 GDPR — the promise «we do not transfer data outside the EU» against a hidden Google Analytics in the USA; Art. 6(1)(a) GDPR — analytics sent before consent, with permission on by default; Art. 6(1)(a) GDPR + incorrect qualification — the analytics is declared «anonymous» and «technical», although it carries a persistent identifier; Art. 13(1)(e) GDPR — recipients not named individually 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]