Technical audit · 2026-06-20

zalando.it

Clothing and Footwear Marketplace

Zalando.it is a large clothing and footwear marketplace. Home-page capture: 221 requests, 16 domains. The set is more restrained than that of sites with a scattering of advertising exchanges: there is no third-party programmatic advertising and no RTB here, no advertising cookies are set. There is a Usercentrics consent platform, and Google's advertising-and-analytics layer is configured to observe consent — the «not given» signal, the advertising non-personalised, no cookies set. But before consent Google's tags do fire: Google Analytics sends view, content-visibility and scroll events, and the AdSense advertising tag sends a utility ping. That is, the behavioural events go to Google in the USA before the user's choice, albeit in anonymised mode.

Timeline of the leak

533 ms · error monitoring
Sentry loads — an error-monitoring service. This is a technical failure-tracking tool, not an advertising tracker.
2569 ms · Google tag system
Google Tag Manager connects — the tag manager through which the analytics and advertising tag are launched.
3109–3667 ms · Usercentrics consent platform
The Usercentrics consent-collection platform loads. A consent mechanism is provided on the site.
4245 ms · Google AdSense advertising tag
The Google AdSense advertising tag sends a utility ping. The consent signal is «not given», the advertising is marked non-personalised.
4420 ms · Google Analytics sends a view
Google Analytics sends a page-view event. The consent signal is «not given», the transmission anonymised, but the fact of the visit goes to Google.
4431 ms onward · behavioural events
View, content-visibility and scroll events are sent. That is, the user's behaviour on the page also goes to Google, still in «consent not given» mode.
there is Usercentrics, consent not given
The consent platform is present, no decision was made in the session, no cookie was set during the session. Google's tags fired before consent, albeit in anonymised mode.

Declared versus actual

Google Analytics — заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.zalando.it is a large online marketplace for clothing, footwear and accessories. The data controller is Zalando. The site is commercial: catalogue, search, personalised selections, cart, personal account. Capture: 221 requests to 16 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. There is a Usercentrics consent-collection platform. There is no heavy third-party advertising infrastructure in the capture — the main external recipient is a single one.

Who receives the data

Spotted here was: Google. Google is present through analytics (Google Analytics), an advertising tag (AdSense) and a tag system (Tag Manager). Additionally, Sentry works — an error-monitoring service, a technical tool. There are no third-party advertising exchanges, no social-network pixels and no cross-site advertising identifiers in the capture. I will separately clarify about the requests to the Microsoft Edge domain: they relate to the built-in page-translation function in the browser itself and are not site tracking — the site is not responsible for them.

Yes, the site has a Usercentrics consent-collection platform. No decision was made in this visit — the capture was taken in a clean session. And here it is important to note the positive honestly: Google’s advertising-and-analytics layer is configured to observe consent. The Google Consent Mode signal transmits the «not given» state, the advertising is marked non-personalised, no tracking cookies were set during the session. That is, Google does not ignore the refusal.

Before the user’s decision, the following fire:

  • Google Analytics — page-view, content-visibility and scroll events (anonymised, but with transmission to Google);
  • the Google AdSense advertising tag — a utility ping (in non-personalised mode);
  • Sentry — error monitoring (technical). The fundamental point. Some of this Google keeps in «consent not given» mode — without cookies and without personalisation, and this counts in the site’s favour. But the requests themselves still happen: the behavioural events (what was viewed, how it was scrolled) go to Google in the USA before consent. Google analytics under EU rules is not exempt from consent, so its launch before the user’s choice remains processing started before consent.

What is in the site’s favour

The positive is worth noting too. There is no third-party programmatic advertising here: no advertising exchanges, no cross-site advertising identifiers, no social-network pixels, no session recording. Google’s advertising layer works in non-personalised mode, no cookies are set. That is, the problem is not an advertising leak across two dozen companies, but a narrow one — that Google’s analytics and advertising tag fire before consent.

Conclusion

Zalando.it is a moderate commercial case. There is no heavy third-party advertising and no advertising exchanges, and Google’s advertising-and-analytics layer is configured to observe consent: the «not given» mode, without cookies, the advertising non-personalised. But Google’s analytics and advertising tag do fire before the user’s choice and send view and scroll events to Google in the USA. The main takeaway for the reader: observing consent in Google’s mode is correct and distinguishes the site favourably from those that ignore the refusal, but even anonymised analytics requests must wait for consent, since Google analytics is not considered exempt from it. It would be enough to switch the launch of the tags into consent-waiting mode, and the narrow discrepancy would close.

Evidence
Original (audit)
HAR file: it/zalando-it-2026-06-20.har
SHA-256: ee89ce774f07181bbad3e83baf7ce12a63bbe4c86113a349d54cd28b1c6a6512
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website zalando.it.

2. Circumstances
I visited the website zalando.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 20 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site has a Usercentrics consent-collection platform, but in a clean session, before any user decision, Google's tags fire. In the site's favour it must be said honestly: they work in «consent not given» mode — the Google Consent Mode signal transmits the «denied» state, the advertising is marked non-personalised, not a single cookie was set during the session. That is, Google observes the refusal and does not personalise. But the requests themselves still happen: Google Analytics sends page-view, content-visibility and scroll events, and the Google AdSense advertising tag sends a utility ping. The behavioural events (what was viewed, how it was scrolled), meanwhile, go to Google in the USA before consent. Under EU rules Google analytics is not exempt from consent, so its launch before the user's choice, even in anonymised mode, remains processing started before consent.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-zalando-it/

3. Provisions violated
Art. 6(1)(a) GDPR — Google analytics and advertising tag fire before consent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]