Technical audit · 2026-06-15

italotreno.com

Private High-Speed Rail Operator

Italo is Italy's largest private high-speed rail operator and the first private operator on a high-speed rail network in Europe. 111 requests, 9 domains — the site is compact and at first glance tidy: there is a Didomi consent-collection platform, advertising cookies are disabled. But the main analytics is Google Analytics disguised as the site's own domain: the data goes via a subdomain of italotreno.com (physically on Microsoft Azure servers) and on to Google. And a record of the visit is sent together with a persistent visitor identifier before the person chose anything, with the analytics permission on by default. And the policy, meanwhile, promises that for the site's own cookies there is no transfer outside the EU, and calls the analytics «anonymous, equated to technical» — whereas this stream carries a unique identifier and goes to Google.

Timeline of the leak

586 ms · reviews platform before all
The very first third-party request — even before the consent platform loads — connects the Skeepers reviews widget. Later its utility data (statistics and links) are added to it.
816–983 ms · consent and Google tag systems
The Didomi consent-collection platform loads, and in parallel — Google's tag-management system (Google Tag Manager) and the Akamai performance-monitoring library.
1857 ms · the consent banner appears
The visible part of the Didomi consent banner is rendered. From this moment the user is shown a choice — but no decision is recorded in the capture: throughout the whole session the site set not a single cookie.
3122–3362 ms · more Google tags and Akamai configuration
An additional Google tag and the settings of the Akamai monitoring service load. Additionally, from the site's own domain the Akamai pixel and behavioural sensors are served — this is performance telemetry and bot protection.
4578 ms · analytics goes out before the choice
The key moment. To the address analytics.italotreno.com — that is, seemingly an own domain, but in fact Google Analytics — a page-view record goes out together with a persistent visitor identifier and the page address. The technical consent signal in the request shows: the analytics permission is on by default. At the same time an event about viewing a promotion goes out. The user, meanwhile, pressed nothing.
11–27 s · regular activity signals
The same stream continues to send Google engagement signals — repeated events at the 11th, 19th and 27th seconds, with the same visitor identifier and the same permission on by default.

Declared versus actual

+ Google Analytics — not declared
+ Didomi — not declared
+ Skeepers — not declared
+ Akamai mPulse — not declared

Detected trackers

Indicators of GDPR non-compliance

Context

www.italotreno.com is the website of Italo, Italy’s largest private high-speed rail operator and Europe’s first private operator on a high-speed network. Tickets are sold through the site, so there is flight search, payment and a promotions showcase here. The capture is compact: 111 requests to 9 domains, taken on a clean Edge browser with no VPN and no blocker. There is a Didomi consent-collection platform on the site, and advertising cookies are indeed disabled in this session. At first glance — a tidy picture. The interest is in the fact that the main analytics is hidden so as to look like «its own».

Who receives the data

Spotted here were: Google, Didomi, Skeepers, Akamai. A caveat on roles: Didomi is the consent-collection platform itself, its presence is expected and is not a complaint. Skeepers is a customer-reviews platform. Akamai is performance monitoring and bot protection. The central figure of the analysis is Google: it is precisely its analytics that is disguised as Italo’s own domain.

Yes, it is Didomi, and its visible part is rendered at around 1.9 seconds. But in this session the user pressed nothing: throughout the whole capture the site set not a single cookie, that is, the consent cookie did not appear. This is a clean first contact — and it is precisely in it that the «default» behaviour is visible.

Google Analytics disguised as an own domain

The main finding. The main analytics stream goes not to the usual Google domain, but to the address analytics.italotreno.com — that is, to a subdomain of Italo itself. But the contents of this stream leave no doubt: it is Google Analytics — the same counter and the same data format as Google’s, merely passed through the site’s own domain (physically — Microsoft Azure servers). This is a common trick: Google’s analytics is wrapped onto one’s own address so that it looks like «first-party» — this way it bypasses blockers and browser restrictions and stops «looking» like data transmission to Google. The effect is twofold. The technical one — the data reaches Google anyway. And the legal one — more on it below.

At around 4.6 seconds this stream sends a full page-view record. In it — a persistent visitor identifier (assigned in this same session), the page address and title. And the technical consent signal accompanying the request shows: the advertising permission is off, but the analytics permission is on by default, before any user choice. Then an event about viewing a promotion goes out, and after it activity signals at the 11th, 19th and 27th seconds. Since the browser is clean and there is no consent cookie, the only consistent explanation is: the analytics permission is «on» by default, and Google Analytics collects data from the first screen without waiting for a decision.

«Anonymous and technical» — against a persistent identifier

The policy justifies this analytics’ exemption from consent directly: it classes the analytics cookies as «equated to technical ones», describing them as collection «in anonymous and aggregate form» that «does not identify the user» — and therefore «consent is not required». The whole construction rests on the word «anonymous». The capture removes this word. Google Analytics transmits a persistent visitor identifier — a stable browser marker by which one person is distinguished from another (the same one on which the count of «unique users» is built). This is neither anonymous nor aggregate data. And if so, the basis «technical cookie, no consent needed» does not stand under this specific stream: for analytics with a persistent identifier going to a third party, consent is required.

«We do not transfer outside the EU» — against Google in the USA

And here is where the disguise as an own domain strikes the policy itself. The document promises: for the site’s own cookies (Italo) no transfer outside the EU is envisaged, and for third-party ones — «see the table or the third party’s policy». Since the analytics is served from a subdomain of italotreno.com itself, it is presented as «its own» — that is, precisely the case where «there is no transfer abroad». But the contents of this «own» stream is Google Analytics, and its final recipient is Google. That is, the appearance of an own domain creates exactly the impression that the policy also fixes in words — «this is ours, it does not go abroad» — whereas in fact the data about the visit goes to Google. Promise and fact diverge, and diverge not by chance, but precisely by means of this wrapper.

Recipients not named

Neither the site’s cookie policy nor the main privacy policy names individually Google and Google Analytics, Didomi, Skeepers or Akamai. Instead — general formulas about «third parties engaged in web analytics, advertising and social networks» and a reference to «a table or the third party’s policy». The actual recipients cannot be learned from the documents themselves.

What cannot be claimed from the capture

A few honest caveats. The separate cookie table to which the policy refers I did not check by its full text — it is possible that Google and others are named in it; I record only that they are not in the body of both policies. Why exactly the analytics permission turned out to be on — a default setting or the treatment of the analytics as «technical» — cannot be said unambiguously from the capture; the fact is proven: on a clean browser without a consent cookie Google Analytics sent data with the analytics permission on. The subdomain analytics.italotreno.com is physically on Microsoft Azure servers — this is an intermediate link; the final recipient of the analytics is Google, and it is to it that the transfer-abroad question relates. Skeepers fired earliest — I note this as a fact of sequence, not as a proven transfer of a profile. Akamai with its monitoring and sensors is a performance and bot-protection function, defensible as technical, although the company itself is American and the data goes out before consent. The capture covers the home page.

Conclusion

Italo looks like a «good student»: the consent platform is in place, advertising cookies are off, the number of third parties is minimised. But the main analytics is Google Analytics wrapped onto its own subdomain (physically on Microsoft Azure servers), which sends a record of the visit with a persistent visitor identifier before the person chose anything, with the analytics permission on by default. And the policy describes this same stream in two ways incorrectly: it calls the analytics «anonymous, equated to technical» (whereas it carries a unique identifier) and promises that for the site’s own cookies there is no transfer outside the EU (whereas this is Google, going to the USA). The main takeaway for the reader: disguising a tracker as an own domain is not «privacy by default» but the reverse; it merely makes third-party transfer indistinguishable from «one’s own» by eye, and it is precisely on this indistinguishability that both of the policy’s promises rest, which the capture does not confirm.

Evidence
Original (audit)
HAR file: it/italotreno-com-2026-06-15.har
SHA-256: 676322ecc995b9ba4ef015f0ffb3c5e05a28f991233a79397308e52be48766f2
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.