Zalando.it is a large clothing and footwear marketplace. Home-page capture: 221 requests, 16 domains. The set is more restrained than that of sites with a scattering of advertising exchanges: there is no third-party programmatic advertising and no RTB here, no advertising cookies are set. There is a Usercentrics consent platform, and Google's advertising-and-analytics layer is configured to observe consent — the «not given» signal, the advertising non-personalised, no cookies set. But before consent Google's tags do fire: Google Analytics sends view, content-visibility and scroll events, and the AdSense advertising tag sends a utility ping. That is, the behavioural events go to Google in the USA before the user's choice, albeit in anonymised mode.
Timeline of the leak
Declared versus actual
Detected trackers
- Google Analytics 4
- Google AdSense (tag)
- Google Tag Manager
- Usercentrics
- Sentry
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — Google analytics and advertising tag fire before consentThe site has a Usercentrics consent-collection platform, but in a clean session, before any user decision, Google's tags fire. In the site's favour it must be said honestly: they work in «consent not given» mode — the Google Consent Mode signal transmits the «denied» state, the advertising is marked non-personalised, not a single cookie was set during the session. That is, Google observes the refusal and does not personalise. But the requests themselves still happen: Google Analytics sends page-view, content-visibility and scroll events, and the Google AdSense advertising tag sends a utility ping. The behavioural events (what was viewed, how it was scrolled), meanwhile, go to Google in the USA before consent. Under EU rules Google analytics is not exempt from consent, so its launch before the user's choice, even in anonymised mode, remains processing started before consent.
Context
www.zalando.it is a large online marketplace for clothing, footwear and accessories. The data controller is Zalando. The site is commercial: catalogue, search, personalised selections, cart, personal account. Capture: 221 requests to 16 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. There is a Usercentrics consent-collection platform. There is no heavy third-party advertising infrastructure in the capture — the main external recipient is a single one.
Who receives the data
Spotted here was: Google. Google is present through analytics (Google Analytics), an advertising tag (AdSense) and a tag system (Tag Manager). Additionally, Sentry works — an error-monitoring service, a technical tool. There are no third-party advertising exchanges, no social-network pixels and no cross-site advertising identifiers in the capture. I will separately clarify about the requests to the Microsoft Edge domain: they relate to the built-in page-translation function in the browser itself and are not site tracking — the site is not responsible for them.
Was there a consent banner
Yes, the site has a Usercentrics consent-collection platform. No decision was made in this visit — the capture was taken in a clean session. And here it is important to note the positive honestly: Google’s advertising-and-analytics layer is configured to observe consent. The Google Consent Mode signal transmits the «not given» state, the advertising is marked non-personalised, no tracking cookies were set during the session. That is, Google does not ignore the refusal.
What fires before consent
Before the user’s decision, the following fire:
- Google Analytics — page-view, content-visibility and scroll events (anonymised, but with transmission to Google);
- the Google AdSense advertising tag — a utility ping (in non-personalised mode);
- Sentry — error monitoring (technical). The fundamental point. Some of this Google keeps in «consent not given» mode — without cookies and without personalisation, and this counts in the site’s favour. But the requests themselves still happen: the behavioural events (what was viewed, how it was scrolled) go to Google in the USA before consent. Google analytics under EU rules is not exempt from consent, so its launch before the user’s choice remains processing started before consent.
What is in the site’s favour
The positive is worth noting too. There is no third-party programmatic advertising here: no advertising exchanges, no cross-site advertising identifiers, no social-network pixels, no session recording. Google’s advertising layer works in non-personalised mode, no cookies are set. That is, the problem is not an advertising leak across two dozen companies, but a narrow one — that Google’s analytics and advertising tag fire before consent.
Conclusion
Zalando.it is a moderate commercial case. There is no heavy third-party advertising and no advertising exchanges, and Google’s advertising-and-analytics layer is configured to observe consent: the «not given» mode, without cookies, the advertising non-personalised. But Google’s analytics and advertising tag do fire before the user’s choice and send view and scroll events to Google in the USA. The main takeaway for the reader: observing consent in Google’s mode is correct and distinguishes the site favourably from those that ignore the refusal, but even anonymised analytics requests must wait for consent, since Google analytics is not considered exempt from it. It would be enough to switch the launch of the tags into consent-waiting mode, and the narrow discrepancy would close.
ee89ce774f07181bbad3e83baf7ce12a63bbe4c86113a349d54cd28b1c6a6512Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website zalando.it. 2. Circumstances I visited the website zalando.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 20 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site has a Usercentrics consent-collection platform, but in a clean session, before any user decision, Google's tags fire. In the site's favour it must be said honestly: they work in «consent not given» mode — the Google Consent Mode signal transmits the «denied» state, the advertising is marked non-personalised, not a single cookie was set during the session. That is, Google observes the refusal and does not personalise. But the requests themselves still happen: Google Analytics sends page-view, content-visibility and scroll events, and the Google AdSense advertising tag sends a utility ping. The behavioural events (what was viewed, how it was scrolled), meanwhile, go to Google in the USA before consent. Under EU rules Google analytics is not exempt from consent, so its launch before the user's choice, even in anonymised mode, remains processing started before consent. Full technical documentation is published at: https://gdpru.eu/en/audits/it-zalando-it/ 3. Provisions violated Art. 6(1)(a) GDPR — Google analytics and advertising tag fire before consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]