Technical audit · 2026-06-15

mediaworld.it

Consumer Electronics and Appliances Retail Chain

MediaWorld (controller Mediamarket S.p.A., part of the European MediaMarktSaturn group) is Italy's largest consumer-electronics retail chain. 178 requests, only 6 domains, and this is the most restrained site in the series: there are no heavy trackers before consent here. No data transmission to Google Analytics, no advertising pixels, no third-party exchanges fired in the session. Before consent only the SpeedCurve third-party speed-measurement service fires (USA, at the 155th millisecond), the loading of Google tag systems and the assignment of an own visitor identifier. The case is borderline and mild, but formally there are requests to third-party services before consent here.

Timeline of the leak

155 ms · speed-measurement service before all
The very first of the third-party to load is SpeedCurve — an external tool that measures page-load speed. It starts before the site's own consent mechanism has loaded. SpeedCurve's servers are located in the USA.
555 ms · own consent mechanism
The site's own modules responsible for consent collection load. The mechanism here is its own, built-in, rather than a third-party consent platform.
1218 ms · assignment of an identifier to the visitor
The site, via its own address, assigns the visitor a persistent identifier. This happens before the user has made a cookie choice.
1248 ms onward · four Google tag systems
The site reaches out to a Google domain and in the first seconds loads four tag-management system (Google Tag Manager) containers. This request transmits the visitor's address and page information to Google — but no further data transmissions by the tags (to analytics or advertising) followed in the session.
5260 ms · own utility telemetry
A stream of utility messages to the site's own internal address begins. This is its own event telemetry; the content of the messages is redacted in the export, so what exactly is in them cannot be established.
6545 ms · message to the SpeedCurve service
A utility message goes out to SpeedCurve's servers — that is, the third-party service not only loaded but also sent data, still without a recorded user consent decision.

Declared versus actual

+ SpeedCurve — не заявлен
+ Google Tag Manager — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.mediaworld.it is the Italian website of the MediaWorld chain, the country’s largest consumer-electronics-and-appliances retail chain, part of the European MediaMarktSaturn group. The data controller is the company Mediamarket S.p.A. with a sole member, registered address Verano Brianza. This is an online store with a catalogue, cart and order placement. Capture: 178 requests to only 6 domains, taken on a clean Edge browser with no VPN and no blocker. Half of these domains are the group’s own resources. There are essentially two third-party services: Google’s tag system and the SpeedCurve speed-measurement service. The site’s consent-collection mechanism is its own, built-in, rather than a third-party platform. Against the general backdrop of the series, this is the tidiest site.

Who receives the data

Spotted here were: SpeedCurve, Google. An important caveat: heavy advertising-and-analytics recipients — data transmissions to Google Analytics, advertising networks, social-network pixels — were not recorded at all in this session. Google is present only as the loading of tag systems from its domain, and SpeedCurve as a third-party speed-measurement tool. The only thing that outwardly resembles a «social network» — the Facebook icon — is just an image from the site’s own storage, not a tracking pixel.

Yes, and the mechanism here is its own — the consent-collection module loads at the 555th millisecond, there is no third-party consent platform. Consent itself was not given in this session: the capture was taken in a clean visit, before the user’s choice, and it is precisely this that allows one to see what fires «by default». The data controller is Mediamarket S.p.A. (Verano Brianza). The cookie policy names Google Analytics and describes in general terms the third-party cookies for advertising, personalisation and statistics; the SpeedCurve service is not mentioned in it.

The picture is mild, and therein lies its value for the series — as a contrary example. Little fires before consent:

  • the SpeedCurve third-party speed-measurement service — even before the site’s own consent mechanism, and later sends a utility message to its servers;
  • the loading of four Google tag systems from its domain;
  • the assignment of the site’s own persistent identifier to the visitor;
  • the site’s own utility telemetry (its content is hidden in the export). The key and honest point: it does not go further than this. Not a single data transmission to Google Analytics, advertising networks, DoubleClick or social networks was recorded in the session. That is, before consent only the infrastructure loaded — speed measurement and tag systems — but the collection itself by advertising and analytics tags did not happen. This behaviour is noticeably closer to what it should be than the other sites in the series.

Conclusion

MediaWorld stands out against the backdrop of the series in that the heavy advertising-and-analytics layer is not launched before consent here: there are no transmissions to Google Analytics, no advertising pixels, no third-party exchanges — the Google tag systems loaded, but collected no data with them. What does fire before consent is the SpeedCurve third-party speed-measurement service (USA, at the 155th millisecond, before the own consent mechanism) and the assignment of an own identifier to the visitor. The main takeaway for the reader: this is an example of relatively restrained behaviour, where the complaints are pinpoint — a third-party service firing before consent and not named in the policy, and the loading of tag systems from a Google domain before the user’s choice — rather than mass data collection without a basis. It is precisely such sites that show a restrained configuration is technically possible.

Evidence
Original (audit)
HAR file: it/mediaworld-it-2026-06-15.har
SHA-256: 727c9863f2a8aa83ea8fff4ea943370ffb57cf15b2de67d950d1d1cdc0d042a3
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website mediaworld.it.

2. Circumstances
I visited the website mediaworld.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) In a clean session, the very first of everything third-party to load is SpeedCurve — an external tool that measures page-load speed and records errors. It launches at the 155th millisecond, before the site's own consent mechanism manages to load, and later, at around the sixth second, sends a utility message to its servers. SpeedCurve is a third-party company with servers in the USA, and its launch and requests happen before any user cookie decision. The collection of such performance data is often justified by technical necessity, but in fact it is a third-party recipient firing before consent.

2) In the first seconds of the visit, before the user's choice, the site reaches out to a Google domain and loads four Google Tag Manager containers — the system through which analytics and advertising tags are usually connected. This request itself transmits the visitor's address and page information to Google. An important caveat in the site's favour: it did not go further than this — not a single data transmission to Google Analytics, advertising networks or social-network pixels was recorded in this session. That is, before consent only the infrastructure for tags loaded, but the tags themselves collected no data.

3) The data controller is Mediamarket S.p.A. (Verano Brianza). The cookie policy names Google Analytics and describes in general terms the third-party cookies for advertising, personalisation and statistics, referring to third-party sites. However, the SpeedCurve service, which actually fires on the site, is not mentioned in it — that is, one of the actually working third-party recipients is absent from the document.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-mediaworld-it/

3. Provisions violated
Art. 6(1)(a) GDPR — a third-party speed-measurement service works before consent; Art. 6(1)(a) GDPR — loading of Google tag systems before consent; Art. 13(1)(e) GDPR — the third-party service SpeedCurve is not named in the policy

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]