Justeat.it is a food-delivery service (the Just Eat Takeaway group). Home-page capture: 67 requests, 10 domains — restrained. On the advertising front the site is clean: no Google Analytics, no Meta, no advertising networks, no programmatic exchanges — the Google tag manager is loaded but launched no analytics. Almost everything else is Just Eat's own infrastructure. But two collections fire before consent: the site's own event service sends data before the consent banner has loaded, and a third-party anti-fraud service fingerprints the device and checks the connection parameters. The anti-fraud is defensible — the policy describes it as fraud protection on the basis of legitimate interest — but device fingerprinting before consent remains disputed under EU rules.
Timeline of the leak
Declared versus actual
Detected trackers
- Anti-fraud fingerprinting (icg-in.com)
- Just Eat's own event tracking
- Datadog RUM
- Usabilla (surveys)
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR / ePrivacy — device fingerprinting and own tracking fire before consentThe site has its own consent banner, but in a clean session, before it and before any choice, two collections fire. First, Just Eat's own event service sends data before the consent banner has even loaded. Second, by the fourth-to-seventh second a third-party anti-fraud service connects, which fingerprints the device and checks the connection parameters (including network and web-socket checks) — these are characteristic fraud- and bot-detection techniques. The anti-fraud in itself is defensible: the site's policy explicitly describes automatic detection of fraudulent actions on the basis of legitimate interest, and fraud protection is a recognised basis. But device fingerprinting under EU rules, as a rule, requires consent unless it is strictly necessary, and its launch before the user's choice remains disputed. On the advertising front, meanwhile, everything is clean: there is no Google Analytics, no advertising networks, no social-network pixels in the capture.
Context
www.justeat.it is a food-ordering and delivery service (the Just Eat Takeaway group). The data controller is the Just Eat operator. The site is commercial: restaurant search, order placement and payment, personal account. Capture: 67 requests to 10 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. The site has its own consent banner. Most of the infrastructure is its own (Just Eat Takeaway domains).
Who receives the data
Spotted here was: a third-party anti-fraud service. The main external recipient is the anti-fraud service, which fingerprints the device and checks the connection parameters to detect fraud and bots. The rest is its own: the Just Eat event service, Datadog monitoring and the Usabilla surveys service. There are no advertising networks, no Google analytics, no social-network pixels and no programmatic exchanges in the capture.
Was there a consent banner
Yes, the site has its own consent banner. No decision was made in the session — the capture was taken in a clean session, no cookie was set during the session. Meanwhile the timing reveals a nuance: the own event service sends data before the consent banner has loaded. That is, some of the collection happens before the consent mechanism even appears.
What fires before consent
Before consent, the following fire:
- Just Eat’s own event service — sending data before the banner loads;
- the anti-fraud service — device fingerprinting and connection checking. The anti-fraud here is the least disputed part: fraud protection is recognised as a legitimate interest, and the site’s policy explicitly describes it. But device fingerprinting under EU rules, as a rule, requires consent unless it is strictly necessary, so its launch before the user’s choice remains in a disputed zone. The own event tracking before the banner appears is a separate question: if this is behaviour analytics, it should wait for consent.
What is in the site’s favour
The positive is worth noting. On the advertising front the site is clean: there are no advertising networks, no programmatic exchanges, no Google analytics and no social-network pixels in the capture, although the Google tag manager is loaded. That is, the data about the visit does not spread across advertising companies. The main external collection is the anti-fraud, which has a recognised legal basis.
Conclusion
Justeat.it is a moderate case with an on the whole restrained picture. There is no advertising tracking on the site, and this distinguishes it favourably: no Google analytics, no advertising networks, no programmatic exchanges. The main questions are narrow: the own event service sends data before the consent banner appears, and a third-party anti-fraud fingerprints the device before consent. The anti-fraud, meanwhile, is defensible by legitimate interest and described in the policy. The main takeaway for the reader: even on a site without advertising tracking, two collections started before the user’s choice remain, and if device fingerprinting is not strictly necessary, it, like the own event analytics, should be switched into consent-waiting mode.
7231a8dbae8573143aed1c6fa7262ad4997599bcc25005cf42b4f85a8773823aWhere to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website justeat.it. 2. Circumstances I visited the website justeat.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 20 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site has its own consent banner, but in a clean session, before it and before any choice, two collections fire. First, Just Eat's own event service sends data before the consent banner has even loaded. Second, by the fourth-to-seventh second a third-party anti-fraud service connects, which fingerprints the device and checks the connection parameters (including network and web-socket checks) — these are characteristic fraud- and bot-detection techniques. The anti-fraud in itself is defensible: the site's policy explicitly describes automatic detection of fraudulent actions on the basis of legitimate interest, and fraud protection is a recognised basis. But device fingerprinting under EU rules, as a rule, requires consent unless it is strictly necessary, and its launch before the user's choice remains disputed. On the advertising front, meanwhile, everything is clean: there is no Google Analytics, no advertising networks, no social-network pixels in the capture. Full technical documentation is published at: https://gdpru.eu/en/audits/it-justeat-it/ 3. Provisions violated Art. 6(1)(a) GDPR / ePrivacy — device fingerprinting and own tracking fire before consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]