MediaWorld (controller Mediamarket S.p.A., part of the European MediaMarktSaturn group) is Italy's largest consumer-electronics retail chain. 178 requests, only 6 domains, and this is the most restrained site in the series: there are no heavy trackers before consent here. No data transmission to Google Analytics, no advertising pixels, no third-party exchanges fired in the session. Before consent only the SpeedCurve third-party speed-measurement service fires (USA, at the 155th millisecond), the loading of Google tag systems and the assignment of an own visitor identifier. The case is borderline and mild, but formally there are requests to third-party services before consent here.
Timeline of the leak
Declared versus actual
Detected trackers
- SpeedCurve (cdn.speedcurve.com, beacon.speedcurve.com)
- Google Tag Manager — Google's tag-management system
- Own persistent visitor identifier
- The site's own stream of utility events to an internal address
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — a third-party speed-measurement service works before consentIn a clean session, the very first of everything third-party to load is SpeedCurve — an external tool that measures page-load speed and records errors. It launches at the 155th millisecond, before the site's own consent mechanism manages to load, and later, at around the sixth second, sends a utility message to its servers. SpeedCurve is a third-party company with servers in the USA, and its launch and requests happen before any user cookie decision. The collection of such performance data is often justified by technical necessity, but in fact it is a third-party recipient firing before consent.
- Art. 6(1)(a) GDPR — loading of Google tag systems before consentIn the first seconds of the visit, before the user's choice, the site reaches out to a Google domain and loads four Google Tag Manager containers — the system through which analytics and advertising tags are usually connected. This request itself transmits the visitor's address and page information to Google. An important caveat in the site's favour: it did not go further than this — not a single data transmission to Google Analytics, advertising networks or social-network pixels was recorded in this session. That is, before consent only the infrastructure for tags loaded, but the tags themselves collected no data.
- Art. 13(1)(e) GDPR — the third-party service SpeedCurve is not named in the policyThe data controller is Mediamarket S.p.A. (Verano Brianza). The cookie policy names Google Analytics and describes in general terms the third-party cookies for advertising, personalisation and statistics, referring to third-party sites. However, the SpeedCurve service, which actually fires on the site, is not mentioned in it — that is, one of the actually working third-party recipients is absent from the document.
Context
www.mediaworld.it is the Italian website of the MediaWorld chain, the country’s largest consumer-electronics-and-appliances retail chain, part of the European MediaMarktSaturn group. The data controller is the company Mediamarket S.p.A. with a sole member, registered address Verano Brianza. This is an online store with a catalogue, cart and order placement. Capture: 178 requests to only 6 domains, taken on a clean Edge browser with no VPN and no blocker. Half of these domains are the group’s own resources. There are essentially two third-party services: Google’s tag system and the SpeedCurve speed-measurement service. The site’s consent-collection mechanism is its own, built-in, rather than a third-party platform. Against the general backdrop of the series, this is the tidiest site.
Who receives the data
Spotted here were: SpeedCurve, Google. An important caveat: heavy advertising-and-analytics recipients — data transmissions to Google Analytics, advertising networks, social-network pixels — were not recorded at all in this session. Google is present only as the loading of tag systems from its domain, and SpeedCurve as a third-party speed-measurement tool. The only thing that outwardly resembles a «social network» — the Facebook icon — is just an image from the site’s own storage, not a tracking pixel.
Was there a consent banner
Yes, and the mechanism here is its own — the consent-collection module loads at the 555th millisecond, there is no third-party consent platform. Consent itself was not given in this session: the capture was taken in a clean visit, before the user’s choice, and it is precisely this that allows one to see what fires «by default». The data controller is Mediamarket S.p.A. (Verano Brianza). The cookie policy names Google Analytics and describes in general terms the third-party cookies for advertising, personalisation and statistics; the SpeedCurve service is not mentioned in it.
What fires before consent
The picture is mild, and therein lies its value for the series — as a contrary example. Little fires before consent:
- the SpeedCurve third-party speed-measurement service — even before the site’s own consent mechanism, and later sends a utility message to its servers;
- the loading of four Google tag systems from its domain;
- the assignment of the site’s own persistent identifier to the visitor;
- the site’s own utility telemetry (its content is hidden in the export). The key and honest point: it does not go further than this. Not a single data transmission to Google Analytics, advertising networks, DoubleClick or social networks was recorded in the session. That is, before consent only the infrastructure loaded — speed measurement and tag systems — but the collection itself by advertising and analytics tags did not happen. This behaviour is noticeably closer to what it should be than the other sites in the series.
Conclusion
MediaWorld stands out against the backdrop of the series in that the heavy advertising-and-analytics layer is not launched before consent here: there are no transmissions to Google Analytics, no advertising pixels, no third-party exchanges — the Google tag systems loaded, but collected no data with them. What does fire before consent is the SpeedCurve third-party speed-measurement service (USA, at the 155th millisecond, before the own consent mechanism) and the assignment of an own identifier to the visitor. The main takeaway for the reader: this is an example of relatively restrained behaviour, where the complaints are pinpoint — a third-party service firing before consent and not named in the policy, and the loading of tag systems from a Google domain before the user’s choice — rather than mass data collection without a basis. It is precisely such sites that show a restrained configuration is technically possible.
727c9863f2a8aa83ea8fff4ea943370ffb57cf15b2de67d950d1d1cdc0d042a3Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website mediaworld.it. 2. Circumstances I visited the website mediaworld.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) In a clean session, the very first of everything third-party to load is SpeedCurve — an external tool that measures page-load speed and records errors. It launches at the 155th millisecond, before the site's own consent mechanism manages to load, and later, at around the sixth second, sends a utility message to its servers. SpeedCurve is a third-party company with servers in the USA, and its launch and requests happen before any user cookie decision. The collection of such performance data is often justified by technical necessity, but in fact it is a third-party recipient firing before consent. 2) In the first seconds of the visit, before the user's choice, the site reaches out to a Google domain and loads four Google Tag Manager containers — the system through which analytics and advertising tags are usually connected. This request itself transmits the visitor's address and page information to Google. An important caveat in the site's favour: it did not go further than this — not a single data transmission to Google Analytics, advertising networks or social-network pixels was recorded in this session. That is, before consent only the infrastructure for tags loaded, but the tags themselves collected no data. 3) The data controller is Mediamarket S.p.A. (Verano Brianza). The cookie policy names Google Analytics and describes in general terms the third-party cookies for advertising, personalisation and statistics, referring to third-party sites. However, the SpeedCurve service, which actually fires on the site, is not mentioned in it — that is, one of the actually working third-party recipients is absent from the document. Full technical documentation is published at: https://gdpru.eu/en/audits/it-mediaworld-it/ 3. Provisions violated Art. 6(1)(a) GDPR — a third-party speed-measurement service works before consent; Art. 6(1)(a) GDPR — loading of Google tag systems before consent; Art. 13(1)(e) GDPR — the third-party service SpeedCurve is not named in the policy 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]