Trenitalia (controller Trenitalia S.p.A., the Ferrovie dello Stato group) is Italy's national railway operator. Home-page capture: 67 requests, 8 domains. Consent is collected on OneTrust, and the banner honestly requires an explicit «Accetta» for profiling. But in a clean session, after the banner has appeared and without any decision, Adobe Analytics sends a page view together with a persistent visitor identifier and a flag of integration with Adobe Audience Manager — that is, profiling-level analytics fires before consent, despite the auto-blocker connected on OneTrust. Meanwhile not a single cookie was set via the headers during the session: the identifier goes out past the cookie mechanism, and the absence of cookies here does not mean the absence of tracking.
Timeline of the leak
Detected trackers
- Adobe Analytics
- Adobe DTM
- Adobe Helix RUM
- Raffle.ai
- OneTrust
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — profiling-level analytics fires before consentThe site's own banner explicitly conditions profiling on explicit consent: profiling cookies are set only after pressing «Accetta», and closing the banner does not count as consent. Nevertheless, in a clean session, after the OneTrust banner has been rendered (at around 1.1 seconds) and without any user decision, at 1.5 seconds Adobe Analytics sends a page view to Adobe's servers together with a persistent visitor identifier and a flag of integration with Adobe Audience Manager — that is, with a cross-site identifier, not de-identified statistics. This is analytics equated to profiling, and it fires before the consent that the platform itself requires for it. Separately telling is that OneTrust has a tag auto-blocking module for before consent connected, but the Adobe request did not wait for it — the consent infrastructure is there but in fact does not hold back the analytics.
Context
www.trenitalia.com is the website of Trenitalia, Italy’s national railway operator, part of the state group Ferrovie dello Stato Italiane. The controller is Trenitalia S.p.A. This is a commercial-service portal with train search, ticket sales, a personal account and a loyalty programme. Capture: 67 requests to 8 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. There is a OneTrust consent-collection platform with a tag auto-blocker connected. The technical stack is predominantly Adobe: tags, analytics and performance monitoring.
Who receives the data
Spotted here were: Adobe, Raffle.ai. Adobe is present through three services — analytics (Adobe Analytics), tag system (Adobe DTM) and performance monitoring (Adobe Helix RUM). Raffle.ai is a third-party site-search service. OneTrust here is not a complaint but the consent-collection tool itself.
Was there a consent banner
Yes, and it is a custom-configured OneTrust. The banner is rendered at around 1.1 seconds and uses a soft model: profiling cookies are set only after an explicit «Accetta», and closing the banner does not count as consent, although it does not block navigation. No «accepted/declined» decision was made in this visit — the capture was taken in a clean session. And it is precisely against this backdrop that the failure is visible: consent is not given, while the cross-site analytics fires anyway. OneTrust has a tag auto-blocking module for before consent connected, but the Adobe Analytics request did not wait for it.
What fires before consent
Before any user decision, the following manage to fire:
- the third-party Adobe Helix RUM performance monitoring (the very first, at 64 ms);
- the Adobe DTM tag system;
- the Raffle.ai third-party site search;
- and the key one — Adobe Analytics, which at 1.5 seconds sends a page view together with a persistent visitor identifier and a flag of integration with Adobe Audience Manager. This is not de-identified statistics: a cross-site identifier is transmitted, allowing visits to be linked. Under Italian rules such third-party analytics is equated to profiling and requires prior consent — which is absent in the session.
Not a single cookie — but there is tracking
It is worth emphasising separately, because it is easy to miss. Throughout the whole session the site set not a single cookie via the response headers. The naive conclusion «no cookies — so it is clean» would be a mistake here: the persistent visitor identifier went to Adobe even without a cookie mechanism. That is, the absence of cookies does not equal the absence of tracking — identification can be built bypassing cookies too.
Conclusion
Trenitalia is an example where the consent infrastructure is outwardly built correctly (OneTrust, an explicit «Accetta» for profiling, an auto-blocker), but in fact does not hold back the very thing for which it exists. In a clean session, after the banner has appeared and without any user decision, Adobe Analytics sends a page view with a cross-site visitor identifier — profiling-level analytics fires before the consent that the platform itself requires for it. The main takeaway for the reader: the presence of a banner and even a technical auto-blocker proves nothing — it is verified only by a network capture, and here the capture shows that consent is there on paper but is not waited for on the wire. And also: the absence of cookies is not an indulgence; the identifier can go out past them too.
be434a5f489608411be339a98493001d67c020b9d030fd46eaa96726484dcbb5Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website trenitalia.com. 2. Circumstances I visited the website trenitalia.com and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site's own banner explicitly conditions profiling on explicit consent: profiling cookies are set only after pressing «Accetta», and closing the banner does not count as consent. Nevertheless, in a clean session, after the OneTrust banner has been rendered (at around 1.1 seconds) and without any user decision, at 1.5 seconds Adobe Analytics sends a page view to Adobe's servers together with a persistent visitor identifier and a flag of integration with Adobe Audience Manager — that is, with a cross-site identifier, not de-identified statistics. This is analytics equated to profiling, and it fires before the consent that the platform itself requires for it. Separately telling is that OneTrust has a tag auto-blocking module for before consent connected, but the Adobe request did not wait for it — the consent infrastructure is there but in fact does not hold back the analytics. Full technical documentation is published at: https://gdpru.eu/en/audits/it-trenitalia-com-it/ 3. Provisions violated Art. 6(1)(a) GDPR — profiling-level analytics fires before consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]