Yoox.com is a luxury online clothing store (the YNAP group). Home-page capture: 70 requests, 13 domains. The set is more restrained than that of many commercial sites: there is no programmatic advertising exchange here, no advertising cookies are set in the session. But there is a timing problem. There is a Commanders Act consent platform, but its choice centre is presented late — at around the 39th second, whereas Google Analytics sends a page view already at 2.8 seconds, and with analytics allowed by default at that. That is, the analytics is on without the user's choice. In parallel, before consent, the Riskified anti-fraud fires, collecting device characteristics. The transparency, meanwhile, is good: all services are named in the policy — the question is precisely that they fire before consent.
Timeline of the leak
Declared versus actual
Detected trackers
- Google Analytics 4
- Riskified (anti-fraud)
- Dynatrace
- Akamai mPulse
- Commanders Act / Trust Commander
- Server-side GTM
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — analytics is on by default and fires before consentThe site has a Commanders Act (Trust Commander) consent-collection platform, but its choice centre in this session appears late — at around the 39th second. Meanwhile Google Analytics sends a page-view event already at 2.8 seconds, and the Google consent signal in this request shows that the analytics storage is allowed by default while the advertising one is denied. That is, the analytics part is on without any user choice: it fires before the consent centre is even presented. Google analytics under EU rules is not exempt from consent (the data goes to Google in the USA), so its launch with permission by default, before the choice is presented, is processing without consent. Additionally, before consent the Riskified anti-fraud service fires, which collects device characteristics and sends them to its servers; the policy treats it as necessary for fraud protection, but in fact the device-fingerprint collection also happens before the user's choice.
Context
www.yoox.com is a luxury online store for clothing and accessories, part of the YNAP group. The data controller is the YOOX operator. The site is commercial: catalogue, search, cart, personal account. Capture: 70 requests to 13 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. There is a Commanders Act (Trust Commander) consent-collection platform. There is no heavy programmatic advertising infrastructure here — the stack is closer to analytics, performance monitoring and fraud protection.
Who receives the data
Spotted here were: Google, Riskified. Google receives analytics (Google Analytics), and the view event is sent via YOOX’s own server-side tag container. Riskified is a fraud-protection service that collects device characteristics for risk assessment. Additionally, the Dynatrace and Akamai mPulse performance monitoring work — these are technical services for observing speed and errors. The Commanders Act consent platform is not a complaint in itself.
Was there a consent banner
There is a consent-collection platform on the site, but its choice centre in this session is presented late — at around the 39th second. By this moment the analytics and anti-fraud have already fired. No decision was made in the session — the capture was taken in a clean session. The key point: the Google consent signal in the analytics requests shows that the analytics storage is allowed by default. That is, the analytics is on not after a choice, but from the start.
What fires before consent
Before the choice is presented, the following fire:
- Google Analytics — a page-view event, with analytics allowed by default;
- the Riskified anti-fraud — collection of device characteristics;
- the Dynatrace and Akamai mPulse performance monitoring (technical). Google analytics under EU rules is not exempt from consent, since the data goes to Google in the USA. Its launch with permission by default, before the user is even presented with a choice, is processing without consent. The policy classes the Riskified anti-fraud as necessary for fraud protection; such a treatment is disputed for a home page without order placement, but in any case the device-fingerprint collection here happens before consent.
What is in the site’s favour
The positive is worth
707d5ea5dd726942a743f7dd40f1891f921ca4dfe1c80b23c0060162c98e2c55Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website yoox.com. 2. Circumstances I visited the website yoox.com and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 20 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site has a Commanders Act (Trust Commander) consent-collection platform, but its choice centre in this session appears late — at around the 39th second. Meanwhile Google Analytics sends a page-view event already at 2.8 seconds, and the Google consent signal in this request shows that the analytics storage is allowed by default while the advertising one is denied. That is, the analytics part is on without any user choice: it fires before the consent centre is even presented. Google analytics under EU rules is not exempt from consent (the data goes to Google in the USA), so its launch with permission by default, before the choice is presented, is processing without consent. Additionally, before consent the Riskified anti-fraud service fires, which collects device characteristics and sends them to its servers; the policy treats it as necessary for fraud protection, but in fact the device-fingerprint collection also happens before the user's choice. Full technical documentation is published at: https://gdpru.eu/en/audits/it-yoox-com/ 3. Provisions violated Art. 6(1)(a) GDPR — analytics is on by default and fires before consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]