Policy changed — see what exactly · 2026-07-11 →
Hm.com is the Dutch site of the H&M fashion retailer (domain www2.hm.com). Homepage scan: 197 requests, 16 domains (among them, edge.microsoft.com is Edge's built-in page-translation feature, not site tracking). The site loads its own H&M cookie banner (turbocookie, 3034 ms), but no consent decision is observed in the scan. Meanwhile, a data-collection and activation layer fires: the Tealium tag manager/CDP (utag + tags), H&M Group's own event collector depcollect (/dep/v1/ and identifier synchronization idsync from 4268 ms), the Hightouch activation platform, and Optimizely A/B experiments (datafile). Behavioral data collection, identifier synchronization, and experiments require consent, and here they fire without it.
Timeline of the leak
Declared versus actual
Detected trackers
- Tealium (tag manager/CDP, utag + tags — before consent)
- H&M Group primary event collection (depcollect /dep/v1/ and idsync — before consent)
- Hightouch (CDP activation, H&M Group subdomain — before consent)
- Optimizely / 'fabulous' (A/B experiments, datafile — before consent)
- turbocookie (H&M cookie banner); mPulse/akstat (RUM), Akamai (anti-bot) — technical
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — the data-collection layer, identifier syncing, and experiments run before consentThe site loads its own H&M cookie banner (turbocookie.hmgroup.com/cookie-banner-hm.js at 3034 ms), but no consent decision is observed in this session. Meanwhile, a full data-collection and activation layer fires. The Tealium tag manager and customer data platform (tags.tiqcdn.com) loads the utag.js container (3035 ms) and deploys tags (utag.491, utag.545 at 4101 ms). H&M Group's own event collector depcollect.hmgroup.com sends POST requests to /dep/v1/ with events and to /dep/v1/idsync/ — identifier synchronization (from 4268 ms). The Hightouch customer-data-activation platform (hightouch.hmgroup.com) makes a profile request (3084 ms). The A/B-testing platform (Optimizely, served as 'fabulous.hmgroup.com') loads an experiments datafile (2092 ms). Behavioral data collection, identifier synchronization, and experiments are non-technical purposes requiring consent under art. 11.7a Telecommunicatiewet and Art. 6(1)(a) GDPR. H&M Group's own policy classifies marketing, personalized advertising, and tracking technologies as consent-based processing, and explicitly mentions advertising partners and interest assessment. Here, however, the collection and synchronization layer fires with no observed consent, even though the banner has already loaded. The identifier synchronization (idsync) is especially telling — an advertising-adjacent purpose — occurring before consent. The content of the events cannot be assessed from the sanitized HAR, since the payload has been stripped — so the behavior itself is what's recorded: collection and synchronization requests before consent.
Context
www2.hm.com is the Dutch site of H&M, one of the world’s largest fashion retailers (catalog, account area, membership program, checkout). The data controller is H&M Group. The site is commercial.
Scan: 197 requests to 16 domains, homepage, captured in a clean browser without a VPN or ad blocker. The stack is built around H&M Group’s own infrastructure (hm.com, hmgroup.com) and a customer data platform. The site has its own cookie banner. Requests to edge.microsoft.com are Edge’s built-in page-translation feature, not site tracking.
Who receives the data
Directly, before consent (third-party): Tealium.
The Tealium tag manager and customer data platform (tags.tiqcdn.com) loads its container and deploys tags. H&M Group’s own layer is served from hmgroup.com subdomains: event collection via depcollect (with identifier synchronization idsync), the Hightouch customer-data-activation platform, and the Optimizely A/B-testing platform (“fabulous”) — meaning that, from a network perspective, these are requests to H&M Group domains, but by purpose they are a CDP, activation, and experiments. On the technical side, there’s mPulse/akstat performance monitoring (Akamai) and Akamai bot protection.
Was there a consent banner
Yes, the site has its own H&M cookie banner (turbocookie.hmgroup.com/cookie-banner-hm.js, loads at 3034 ms). But no request carrying a consent decision is observed in this session — the banner merely loads.
The key issue is that the data-collection and activation layer fired regardless: Optimizely experiments (2092 ms), Tealium (3035 ms), Hightouch (3084 ms), and depcollect event collection with identifier synchronization (4268 ms) — all with no observed consent.
What fires without observed consent
The following fire without observed consent:
- Optimizely / “fabulous” A/B experiments — a datafile (2092 ms);
- Tealium (tag manager/CDP) — container and tags (from 3035 ms);
- Hightouch (customer-data activation) — a profile request (3084 ms);
- depcollect event collection and idsync identifier synchronization (from 4268 ms);
- the idservice identity service (930 ms).
Performance monitoring and bot protection raise no concerns — these are technical and security purposes. The concern is the data-collection layer, identifier synchronization, and experiments: these are non-technical purposes, and they fire with no observed consent. Identifier synchronization (idsync) is especially telling — an advertising-adjacent purpose.
Why “served via first-party subdomains” is not a free pass
This point matters for understanding the issue. The fact that much of this layer is served from H&M Group’s own subdomains looks, from a network standpoint, like first-party data collection. But legally, the question isn’t whose domain the request goes to — it’s the nature and legal basis of the collection. Event collection and identifier synchronization are behavioral and advertising-adjacent processing; Tealium is a third-party customer data platform; Optimizely runs experiments — all of them require consent. H&M Group’s own policy classifies marketing, personalized advertising, and tracking technologies as consent-based processing, and explicitly mentions advertising partners and interest assessment. Launching this layer without observed consent contradicts both the rule and the site’s own documentation.
Conclusion
Hm.com is a case where a consent mechanism is present (the cookie banner loads), but the customer-data-collection layer doesn’t wait for it. Tealium deploys tags, H&M Group’s own event collector synchronizes identifiers, the Hightouch platform requests a profile, and Optimizely experiments start — all with no observed consent, even though the site’s own policy classifies marketing, advertising, and tracking as consent-based processing. The key takeaway for the reader: neither serving requests through first-party subdomains nor the mere presence of a banner eliminates the consent requirement — the data-collection layer, identifier synchronization, and experiments should be gated on consent so they don’t fire before the user’s choice.
bce2971fa4da4ac8a64ab1fd74c59e0f3d4197d312c2f13735d72dde6a3d63f5Where to file: Dutch Data Protection Authority (AP) — autoriteitpersoonsgegevens.nl
To: Dutch Data Protection Authority (AP) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website hm.com. 2. Circumstances I visited the website hm.com and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 23 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site loads its own H&M cookie banner (turbocookie.hmgroup.com/cookie-banner-hm.js at 3034 ms), but no consent decision is observed in this session. Meanwhile, a full data-collection and activation layer fires. The Tealium tag manager and customer data platform (tags.tiqcdn.com) loads the utag.js container (3035 ms) and deploys tags (utag.491, utag.545 at 4101 ms). H&M Group's own event collector depcollect.hmgroup.com sends POST requests to /dep/v1/ with events and to /dep/v1/idsync/ — identifier synchronization (from 4268 ms). The Hightouch customer-data-activation platform (hightouch.hmgroup.com) makes a profile request (3084 ms). The A/B-testing platform (Optimizely, served as 'fabulous.hmgroup.com') loads an experiments datafile (2092 ms). Behavioral data collection, identifier synchronization, and experiments are non-technical purposes requiring consent under art. 11.7a Telecommunicatiewet and Art. 6(1)(a) GDPR. H&M Group's own policy classifies marketing, personalized advertising, and tracking technologies as consent-based processing, and explicitly mentions advertising partners and interest assessment. Here, however, the collection and synchronization layer fires with no observed consent, even though the banner has already loaded. The identifier synchronization (idsync) is especially telling — an advertising-adjacent purpose — occurring before consent. The content of the events cannot be assessed from the sanitized HAR, since the payload has been stripped — so the behavior itself is what's recorded: collection and synchronization requests before consent. Full technical documentation is published at: https://gdpru.eu/en/audits/nl-hm-com/ 3. Provisions violated Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — the data-collection layer, identifier syncing, and experiments run before consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]