Rai.it is the website of RAI, Italian public broadcasting. Home-page capture: 159 requests, 11 domains. For a media portal the picture is restrained: there is no commercial advertising-and-analytics layer — no Google Analytics, no Meta, no advertising, no social plugins, not a single cookie was set during the session. RAI's analytics is its own and goes to a European cloud region. But there is one problem: the Nielsen audience-measurement system activates before consent — it loads the SDK, sends measurement requests and assigns a persistent unique identifier, although there is a consent banner on the site and the policy promises to process data only after prior consent. For a public broadcaster, audience measurement is a lawful function acknowledged in the policy, but an identifier assigned before consent is a violation in essence.
Timeline of the leak
Declared versus actual
Detected trackers
- Nielsen (audience measurement)
- RAI analytics on Azure
- Google Fonts
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — audience measurement with a persistent identifier fires before consentThe site has its own consent banner (a CMP based on OIL, the TCF v2 standard), and the policy itself explicitly promises to process personal data only after prior consent. Nevertheless, in a clean session, before any user decision, the Nielsen audience-measurement system activates: its SDK loads, measurement requests are sent and — crucially — a persistent unique identifier is assigned (via the nuid subdomain). This is not de-identified aggregate statistics, but cross-site audience measurement with a stable identifier, which by the rules requires prior consent. Here, however, it fires before consent, despite the presence of the platform for collecting it. In the site's favour let us note: audience measurement for a public broadcaster is a legitimate function, and the policy itself acknowledges participation in such measurements (Auditel); apart from Nielsen there is no advertising-and-analytics layer — no Google Analytics, no Meta, no advertising, no social plugins, and the own analytics is sent to a European cloud region. But an audience identifier assigned before consent remains a violation in essence.
Context
www.rai.it is the official website of RAI, Italian public broadcasting. The data controller is RAI. This is a media portal: news, programmes, links to the RaiPlay (video) and RaiPlay Sound (audio) platforms. As a public broadcaster, RAI has a lawful audience-measurement function (participation in the Auditel system). Capture: 159 requests to 11 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. There is its own consent banner (a CMP based on OIL, the TCF v2 standard). There is no commercial advertising-and-analytics layer in the capture.
Who receives the data
Spotted here was: Nielsen. Nielsen (via the imrworldwide.com domains) is an audience-measurement system: it loads its SDK, sends measurement requests and assigns the visitor a persistent unique identifier. Besides it, RAI’s own analytics is sent to the Azure cloud bus in a European region — this is first-party, EU-hosted processing, nothing goes to advertising third parties. The fonts are loaded from Google Fonts. Importantly, to be honest: there is no Google Analytics, no Meta, no advertising networks, no social-network pixels and no third-party exchanges in the capture. By a media portal’s standards this is a very restrained set.
Was there a consent banner
Yes, RAI has its own consent banner (a CMP based on OIL, the TCF v2 standard), it loads in the very first hundreds of milliseconds. No «accept/decline» decision was made in this visit — the capture was taken in a clean session. The policy itself explicitly promises to process personal data only after prior consent. And it is precisely against this backdrop that the mismatch is visible: consent is not given, the banner has not yet been passed, while the Nielsen audience measurement already fires and assigns an identifier.
What fires before consent
Before any user decision, the following manage to fire:
- the Nielsen audience-measurement system — SDK load, measurement requests and assignment of a persistent unique identifier;
- RAI’s own analytics on the Azure cloud (European region, first-party — the least problematic);
- the loading of Google Fonts. The key point is Nielsen. De-identified aggregate statistics can work without consent, but here the audience is measured with a stable unique identifier, and that is no longer an aggregate. Such measurement falls under the rules on prior consent — and it fires before consent.
On the acknowledgement in the policy
Worth noting separately for precision. RAI’s policy acknowledges participation in audience measurement — it mentions the Auditel measurements of television viewing, whose technology partner is precisely Nielsen. That is, the function itself is not hidden. But the technical recipients by name (Nielsen, the analytics cloud) are not named in the provided policy text — their detailing is moved to a separate Cookie Policy, which was not examined in this check. So we leave the question of naming the recipients open, and formulate the main complaint on timing: the audience identifier is assigned before consent, which the policy declares obligatory.
Conclusion
Rai.it is a predominantly restrained case for media with one substantial caveat. The positive is real: there is no commercial advertising-and-analytics layer — no Google Analytics, no Meta, no advertising, no social plugins; cookies are not set; the own analytics stays in a European cloud region; and a consent banner is provided. But the Nielsen audience-measurement system activates before consent and assigns the visitor a persistent unique identifier — and this is not a de-identified aggregate, and consent for it is required in advance, all the more so since the policy itself promises prior consent. The main takeaway for the reader: even for a public broadcaster, where audience measurement is a lawful function, it should wait for consent and be transparent about the recipients. It would be enough to place the audience measurement behind the consent banner — the infrastructure for this is already on the site.
fc14943352d991f6b20461e33bb2bd98900642813c646701c09ed752f1b6a41aWhere to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website rai.it. 2. Circumstances I visited the website rai.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site has its own consent banner (a CMP based on OIL, the TCF v2 standard), and the policy itself explicitly promises to process personal data only after prior consent. Nevertheless, in a clean session, before any user decision, the Nielsen audience-measurement system activates: its SDK loads, measurement requests are sent and — crucially — a persistent unique identifier is assigned (via the nuid subdomain). This is not de-identified aggregate statistics, but cross-site audience measurement with a stable identifier, which by the rules requires prior consent. Here, however, it fires before consent, despite the presence of the platform for collecting it. In the site's favour let us note: audience measurement for a public broadcaster is a legitimate function, and the policy itself acknowledges participation in such measurements (Auditel); apart from Nielsen there is no advertising-and-analytics layer — no Google Analytics, no Meta, no advertising, no social plugins, and the own analytics is sent to a European cloud region. But an audience identifier assigned before consent remains a violation in essence. Full technical documentation is published at: https://gdpru.eu/en/audits/it-rai-it/ 3. Provisions violated Art. 6(1)(a) GDPR — audience measurement with a persistent identifier fires before consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]