Tecnomat (a building-materials and DIY store chain, the Adeo group) is the heaviest site in the series for tracking: 539 requests, 69 domains. Consent is collected on OneTrust, the banner is on the screen — but not pressed. And even so, in the first seconds a full advertising-and-analytics storm launches: Google (GA4, Ads, DoubleClick), the Meta pixel with a page view, Criteo, Adobe Audience Manager, Hotjar session recording and dozens of programmatic exchanges. Google Consent Mode is set to «granted» from the start in all requests, the «denied» state does not appear once — that is, the site by default considers consent given, without waiting for the user, against the text of its own banner (without acceptance — only technical tools). In addition, the consent interface is built as a dark pattern: to accept is one click, to refuse there is no equivalent button. And even the extremely detailed cookie policy of ~60 recipients does not cover all who actually fired.
Timeline of the leak
Declared versus actual
Detected trackers
- Meta / Facebook
- Criteo
- Adobe Audience Manager
- Hotjar
- Programmatic exchanges (RTB)
- OneTrust
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — the advertising-and-analytics layer works without consent, «granted» by defaultIn a clean session the OneTrust consent banner is shown but not pressed — the user made no choice. Despite this, in the very first seconds the whole advertising-and-analytics layer launches: Google (GA4, Ads, DoubleClick), the Meta advertising pixel with a page-view event, Criteo, Adobe Audience Manager and dozens of programmatic exchanges. The Google Consent Mode signal, meanwhile, is immediately «granted» in all requests (both for advertising and for analytics) — there is not a single request in the «denied» state in the capture at all. This means the site set consent to the «given» position by default, without waiting for the user's decision. There is no OneTrust record of an «accept» press either. Thereby processing for advertising and profiling goes on without a legal basis. A direct contradiction: the banner's own text promises that without acceptance only technical tools will work, while the own cookie policy classes advertising and analytics cookies as those requiring consent.
- Art. 4(11), 7(3) GDPR — a dark pattern in the consent interfaceConsent is not free and equal. On the banner's first layer a bright «Accetta tutti i cookie» button is visible, but there is no equivalent «reject all» button next to it — only «Impostazioni cookie» and an X. On the second layer (the preference centre) there is an «Allow all», but again no simple one-click «reject all»: refusal requires manually toggling the categories. Consent is given in one click, refusal in several actions. This asymmetry is a typical impermissible design pattern under the EDPB's guidelines on deceptive design and Garante's position: refusing should be as easy as consenting.
- Art. 13(1)(e) GDPR — some actual recipients are not named even in the detailed policyThe cookie policy lists about sixty third-party recipients — a very long list. Nevertheless, a number of services that actually fired in the capture are absent from it: the third-party Hotjar session recording, the Taboola and Outbrain native advertising networks, the Rubicon (Magnite), TripleLift, Yieldlab, BidSwitch, Teads advertising exchanges, the Zemanta advertising platform, the Microsoft Bing conversion tracking and the adtech domain vzbl.eu. That is, even a seemingly exhaustive sheet of recipients does not cover the actual set — especially telling is the absence of Hotjar, which records the user's behaviour on the page.
Context
www.tecnomat.it is the Italian website of the Tecnomat chain (formerly Bricoman), a large retailer of building materials and DIY goods, part of the Adeo group (the same group as Leroy Merlin). The controller is Tecnomat / the corresponding legal entity of the group. This is a commercial online store with a catalogue, store selection, cart and payment. Capture: 539 requests to 69 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. There is a OneTrust consent-collection platform with an auto-blocking module. This is the heaviest site in the series by the number of third-party recipients — a full-fledged programmatic advertising stack.
Who receives the data
Spotted here were: Google, Meta / Facebook, Criteo, Adobe Audience Manager, Microsoft (Bing / Xandr), PubMatic, Index Exchange, Rubicon / Magnite, Taboola, Outbrain, Adform, Hotjar, ID5, TripleLift, Teads — and this is not the full list, but the most noticeable of the dozens. The layer divides into several roles: web analytics (GA4), advertising profiling and retargeting (Criteo, Meta, Google Ads), identifier merging across platforms (Adobe Audience Manager, ID5, Neustar), programmatic exchanges and RTB synchronisations (PubMatic, Index Exchange, Rubicon, Adform, Xandr, Smart AdServer, 360yield, TripleLift, Yieldlab, BidSwitch and others), native advertising (Taboola, Outbrain) and, separately, third-party recording of the user’s behaviour on the page (Hotjar).
Was there a consent banner
Yes — the OneTrust banner is shown. But therein lies the point: it is not pressed, while the advertising-and-analytics layer works anyway. The proof is in the site’s own signals. Google Consent Mode in every request immediately transmits the «granted» state (consent given for advertising and analytics). Under a normal configuration, before the click «denied» would be transmitted, and after pressing «accept» — a transition to «granted». In the capture the «denied» state does not appear once, and there is no OneTrust record of an «accept» press either. So the site set consent to «given» by default, without waiting for the user’s decision. This directly contradicts two of the platform’s own documents. The banner’s text promises: without acceptance only technical tools work. The cookie policy classes advertising and analytics cookies as categories for which consent is required. In fact, both are ignored.
The consent dark pattern
A separate problem is the choice interface itself. On the banner’s first layer the «accept all cookies» button is brightly highlighted, but there is no equivalent «reject all» button next to it — only «settings» and an X. On the second layer, in the preference centre, there is an «allow all» button, but again no simple one-click refusal: to refuse, one must manually toggle the categories. Consent is one move, refusal is several. Such asymmetry is recognised as an impermissible design technique: refusing should be as easy as consenting.
Recipients beyond the list
The site’s cookie policy is very detailed — it lists about sixty third-party recipients. But even it does not cover all who actually fired. In the capture the following appeared, but are absent from the policy: the third-party Hotjar session recording, the Taboola and Outbrain native networks, the Rubicon (Magnite), TripleLift, Yieldlab, BidSwitch, Teads advertising exchanges, the Zemanta platform, the Microsoft Bing conversion tracking and the adtech domain vzbl.eu. Especially telling is the absence of Hotjar — a tool that records the user’s behaviour on the page. It is separately worth noting how to reach this policy at all: the page is served only after the site obtains access to geolocation or a store selection. That is, the mandatory information about trackers is hidden behind an additional condition.
Conclusion
Tecnomat is the extreme pole of the series and its telling counter-example. Here it is not «a few trackers slipped through before the banner» — here an advertising-and-analytics storm of dozens of recipients works in fact without consent: Google Consent Mode is set to «granted» by default, the «refused» state does not appear once, there was no «accept» press, while the banner meanwhile hangs on the screen promising the opposite. On top of this — a dark pattern where refusing is harder than consenting, and a detailed policy that still does not name all the actually working recipients, including the Hotjar session recording. The main takeaway for the reader: the presence of a banner, a consent platform and a multi-page policy means nothing in itself — it is verified only by a network capture, and here it shows that consent is simulated by default, refusal is made difficult, and the actual list of recipients is broader than declared.
eb18200553dfba01837edf164373abaeace910d9fc2316a4ee6b6d39211765e9Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website tecnomat.it. 2. Circumstances I visited the website tecnomat.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) In a clean session the OneTrust consent banner is shown but not pressed — the user made no choice. Despite this, in the very first seconds the whole advertising-and-analytics layer launches: Google (GA4, Ads, DoubleClick), the Meta advertising pixel with a page-view event, Criteo, Adobe Audience Manager and dozens of programmatic exchanges. The Google Consent Mode signal, meanwhile, is immediately «granted» in all requests (both for advertising and for analytics) — there is not a single request in the «denied» state in the capture at all. This means the site set consent to the «given» position by default, without waiting for the user's decision. There is no OneTrust record of an «accept» press either. Thereby processing for advertising and profiling goes on without a legal basis. A direct contradiction: the banner's own text promises that without acceptance only technical tools will work, while the own cookie policy classes advertising and analytics cookies as those requiring consent. 2) Consent is not free and equal. On the banner's first layer a bright «Accetta tutti i cookie» button is visible, but there is no equivalent «reject all» button next to it — only «Impostazioni cookie» and an X. On the second layer (the preference centre) there is an «Allow all», but again no simple one-click «reject all»: refusal requires manually toggling the categories. Consent is given in one click, refusal in several actions. This asymmetry is a typical impermissible design pattern under the EDPB's guidelines on deceptive design and Garante's position: refusing should be as easy as consenting. 3) The cookie policy lists about sixty third-party recipients — a very long list. Nevertheless, a number of services that actually fired in the capture are absent from it: the third-party Hotjar session recording, the Taboola and Outbrain native advertising networks, the Rubicon (Magnite), TripleLift, Yieldlab, BidSwitch, Teads advertising exchanges, the Zemanta advertising platform, the Microsoft Bing conversion tracking and the adtech domain vzbl.eu. That is, even a seemingly exhaustive sheet of recipients does not cover the actual set — especially telling is the absence of Hotjar, which records the user's behaviour on the page. Full technical documentation is published at: https://gdpru.eu/en/audits/it-tecnomat-it/ 3. Provisions violated Art. 6(1)(a) GDPR — the advertising-and-analytics layer works without consent, «granted» by default; Art. 4(11), 7(3) GDPR — a dark pattern in the consent interface; Art. 13(1)(e) GDPR — some actual recipients are not named even in the detailed policy 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]