Technical audit · 2026-06-20

yoox.com

Luxury Online Clothing Store

Yoox.com is a luxury online clothing store (the YNAP group). Home-page capture: 70 requests, 13 domains. The set is more restrained than that of many commercial sites: there is no programmatic advertising exchange here, no advertising cookies are set in the session. But there is a timing problem. There is a Commanders Act consent platform, but its choice centre is presented late — at around the 39th second, whereas Google Analytics sends a page view already at 2.8 seconds, and with analytics allowed by default at that. That is, the analytics is on without the user's choice. In parallel, before consent, the Riskified anti-fraud fires, collecting device characteristics. The transparency, meanwhile, is good: all services are named in the policy — the question is precisely that they fire before consent.

Timeline of the leak

439–463 ms · tag manager and monitoring
The Commanders Act tag manager and the Akamai mPulse performance monitoring load. This is preparation of the stack before the choice is presented.
1756–2000 ms · tag system and consent script
Google Tag Manager and the Trust Commander consent-platform script connect. The consent mechanism loads, but its choice centre is not yet presented.
2809 ms · Google Analytics sends a view
Via the own server-side tag container, Google Analytics sends a page-view event. The consent signal shows that the analytics storage is allowed by default — that is, the analytics is on without the user's choice.
2967–4439 ms · Riskified anti-fraud collects device data
The Riskified anti-fraud service sends a series of requests and transmits device characteristics to its servers. The policy treats it as necessary for fraud protection, but the device-fingerprint collection happens before consent.
7829 ms · request to Google Analytics
Google Analytics reaches out directly to its collection domain. The consent signal is unchanged — analytics allowed, advertising not.
around 39 seconds · consent centre presented
The consent platform's choice centre is presented only at around the 39th second — that is, the analytics and anti-fraud have already fired by this moment. No cookie was set via the headers during the session.

Declared versus actual

Google Analytics — заявлен
Riskified — заявлен
Dynatrace — заявлен
Akamai — заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.yoox.com is a luxury online store for clothing and accessories, part of the YNAP group. The data controller is the YOOX operator. The site is commercial: catalogue, search, cart, personal account. Capture: 70 requests to 13 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. There is a Commanders Act (Trust Commander) consent-collection platform. There is no heavy programmatic advertising infrastructure here — the stack is closer to analytics, performance monitoring and fraud protection.

Who receives the data

Spotted here were: Google, Riskified. Google receives analytics (Google Analytics), and the view event is sent via YOOX’s own server-side tag container. Riskified is a fraud-protection service that collects device characteristics for risk assessment. Additionally, the Dynatrace and Akamai mPulse performance monitoring work — these are technical services for observing speed and errors. The Commanders Act consent platform is not a complaint in itself.

There is a consent-collection platform on the site, but its choice centre in this session is presented late — at around the 39th second. By this moment the analytics and anti-fraud have already fired. No decision was made in the session — the capture was taken in a clean session. The key point: the Google consent signal in the analytics requests shows that the analytics storage is allowed by default. That is, the analytics is on not after a choice, but from the start.

Before the choice is presented, the following fire:

  • Google Analytics — a page-view event, with analytics allowed by default;
  • the Riskified anti-fraud — collection of device characteristics;
  • the Dynatrace and Akamai mPulse performance monitoring (technical). Google analytics under EU rules is not exempt from consent, since the data goes to Google in the USA. Its launch with permission by default, before the user is even presented with a choice, is processing without consent. The policy classes the Riskified anti-fraud as necessary for fraud protection; such a treatment is disputed for a home page without order placement, but in any case the device-fingerprint collection here happens before consent.

What is in the site’s favour

The positive is worth

Evidence
Original (audit)
HAR file: it/yoox-com-2026-06-20.har
SHA-256: 707d5ea5dd726942a743f7dd40f1891f921ca4dfe1c80b23c0060162c98e2c55
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website yoox.com.

2. Circumstances
I visited the website yoox.com and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 20 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site has a Commanders Act (Trust Commander) consent-collection platform, but its choice centre in this session appears late — at around the 39th second. Meanwhile Google Analytics sends a page-view event already at 2.8 seconds, and the Google consent signal in this request shows that the analytics storage is allowed by default while the advertising one is denied. That is, the analytics part is on without any user choice: it fires before the consent centre is even presented. Google analytics under EU rules is not exempt from consent (the data goes to Google in the USA), so its launch with permission by default, before the choice is presented, is processing without consent. Additionally, before consent the Riskified anti-fraud service fires, which collects device characteristics and sends them to its servers; the policy treats it as necessary for fraud protection, but in fact the device-fingerprint collection also happens before the user's choice.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-yoox-com/

3. Provisions violated
Art. 6(1)(a) GDPR — analytics is on by default and fires before consent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]