Technical audit · 2026-06-15

trenitalia.com

State Railway Operator

Trenitalia (controller Trenitalia S.p.A., the Ferrovie dello Stato group) is Italy's national railway operator. Home-page capture: 67 requests, 8 domains. Consent is collected on OneTrust, and the banner honestly requires an explicit «Accetta» for profiling. But in a clean session, after the banner has appeared and without any decision, Adobe Analytics sends a page view together with a persistent visitor identifier and a flag of integration with Adobe Audience Manager — that is, profiling-level analytics fires before consent, despite the auto-blocker connected on OneTrust. Meanwhile not a single cookie was set via the headers during the session: the identifier goes out past the cookie mechanism, and the absence of cookies here does not mean the absence of tracking.

Timeline of the leak

64 ms · third-party performance monitoring
The very first of the third-party to load is Adobe Helix RUM (rum.hlx.page) — external monitoring of speed and errors. The server address is third-party, the request happens before the banner.
65–96 ms · OneTrust consent platform
OneTrust loads: the banner scripts, visitor-region detection and the tag auto-blocking module, which by design should hold back third-party tags until consent.
72 ms · Adobe tag system
Adobe DTM (assets.adobedtm.com) connects — Adobe's tag manager, through which the analytics is then launched.
425–703 ms · third-party site search
Raffle.ai loads — an external site-search service (its script and configuration). A third-party domain receives a request before consent.
1069–1147 ms · consent-banner rendering
The visible part of the OneTrust banner is rendered (styles, texts, logos). From this moment the user is shown a choice; no «accepted/declined» decision was made in this visit.
1486 ms · Adobe Analytics sends a page view
Adobe Analytics sends a page view to Adobe's servers together with a persistent visitor identifier and a flag of integration with Adobe Audience Manager. This happens after the banner has appeared, but without any user consent decision.

Detected trackers

Indicators of GDPR non-compliance

Context

www.trenitalia.com is the website of Trenitalia, Italy’s national railway operator, part of the state group Ferrovie dello Stato Italiane. The controller is Trenitalia S.p.A. This is a commercial-service portal with train search, ticket sales, a personal account and a loyalty programme. Capture: 67 requests to 8 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. There is a OneTrust consent-collection platform with a tag auto-blocker connected. The technical stack is predominantly Adobe: tags, analytics and performance monitoring.

Who receives the data

Spotted here were: Adobe, Raffle.ai. Adobe is present through three services — analytics (Adobe Analytics), tag system (Adobe DTM) and performance monitoring (Adobe Helix RUM). Raffle.ai is a third-party site-search service. OneTrust here is not a complaint but the consent-collection tool itself.

Yes, and it is a custom-configured OneTrust. The banner is rendered at around 1.1 seconds and uses a soft model: profiling cookies are set only after an explicit «Accetta», and closing the banner does not count as consent, although it does not block navigation. No «accepted/declined» decision was made in this visit — the capture was taken in a clean session. And it is precisely against this backdrop that the failure is visible: consent is not given, while the cross-site analytics fires anyway. OneTrust has a tag auto-blocking module for before consent connected, but the Adobe Analytics request did not wait for it.

Before any user decision, the following manage to fire:

  • the third-party Adobe Helix RUM performance monitoring (the very first, at 64 ms);
  • the Adobe DTM tag system;
  • the Raffle.ai third-party site search;
  • and the key one — Adobe Analytics, which at 1.5 seconds sends a page view together with a persistent visitor identifier and a flag of integration with Adobe Audience Manager. This is not de-identified statistics: a cross-site identifier is transmitted, allowing visits to be linked. Under Italian rules such third-party analytics is equated to profiling and requires prior consent — which is absent in the session.

It is worth emphasising separately, because it is easy to miss. Throughout the whole session the site set not a single cookie via the response headers. The naive conclusion «no cookies — so it is clean» would be a mistake here: the persistent visitor identifier went to Adobe even without a cookie mechanism. That is, the absence of cookies does not equal the absence of tracking — identification can be built bypassing cookies too.

Conclusion

Trenitalia is an example where the consent infrastructure is outwardly built correctly (OneTrust, an explicit «Accetta» for profiling, an auto-blocker), but in fact does not hold back the very thing for which it exists. In a clean session, after the banner has appeared and without any user decision, Adobe Analytics sends a page view with a cross-site visitor identifier — profiling-level analytics fires before the consent that the platform itself requires for it. The main takeaway for the reader: the presence of a banner and even a technical auto-blocker proves nothing — it is verified only by a network capture, and here the capture shows that consent is there on paper but is not waited for on the wire. And also: the absence of cookies is not an indulgence; the identifier can go out past them too.

Evidence
Original (audit)
HAR file: it/trenitalia-com-2026-06-15.har
SHA-256: be434a5f489608411be339a98493001d67c020b9d030fd46eaa96726484dcbb5
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website trenitalia.com.

2. Circumstances
I visited the website trenitalia.com and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site's own banner explicitly conditions profiling on explicit consent: profiling cookies are set only after pressing «Accetta», and closing the banner does not count as consent. Nevertheless, in a clean session, after the OneTrust banner has been rendered (at around 1.1 seconds) and without any user decision, at 1.5 seconds Adobe Analytics sends a page view to Adobe's servers together with a persistent visitor identifier and a flag of integration with Adobe Audience Manager — that is, with a cross-site identifier, not de-identified statistics. This is analytics equated to profiling, and it fires before the consent that the platform itself requires for it. Separately telling is that OneTrust has a tag auto-blocking module for before consent connected, but the Adobe request did not wait for it — the consent infrastructure is there but in fact does not hold back the analytics.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-trenitalia-com-it/

3. Provisions violated
Art. 6(1)(a) GDPR — profiling-level analytics fires before consent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]