Technical audit · 2026-06-23

hm.com

Website of the H&M fashion retailer

Hm.com is the Dutch site of the H&M fashion retailer (domain www2.hm.com). Homepage scan: 197 requests, 16 domains (among them, edge.microsoft.com is Edge's built-in page-translation feature, not site tracking). The site loads its own H&M cookie banner (turbocookie, 3034 ms), but no consent decision is observed in the scan. Meanwhile, a data-collection and activation layer fires: the Tealium tag manager/CDP (utag + tags), H&M Group's own event collector depcollect (/dep/v1/ and identifier synchronization idsync from 4268 ms), the Hightouch activation platform, and Optimizely A/B experiments (datafile). Behavioral data collection, identifier synchronization, and experiments require consent, and here they fire without it.

Timeline of the leak

930 ms · identity service
H&M's identity service (idservice.hm.com) loads, along with the 'fabulous' bundle (experiments platform). Primary initialization.
2092 ms · A/B experiments
The A/B-testing platform (Optimizely, served as fabulous.hmgroup.com) loads an experiments datafile (datafile_nl_nl.json). This is behavioral bucketing into variants, before consent.
3034 ms · cookie-banner loads
H&M's own cookie banner loads (turbocookie.hmgroup.com/cookie-banner-hm.js). Since a consent mechanism exists, anything that fires before the choice occurs before consent.
3035–4101 ms · Tealium (tag manager/CDP)
Tealium (tags.tiqcdn.com) loads the utag.js container (3035 ms) and deploys tags (utag.491, utag.545). This is a third-party tag manager and customer data platform, before consent.
3084 ms · Hightouch customer-data activation
The Hightouch customer-data-activation platform (hightouch.hmgroup.com) makes a profile request. This is CDP activation, before consent.
4268 ms · event collection and identifier synchronization
H&M Group's own event collector depcollect.hmgroup.com sends POST requests to /dep/v1/ with events and to /dep/v1/idsync/ — identifier synchronization. This is behavioral data collection and advertising-adjacent synchronization, before consent (a series continues up to 4365 ms and later at 24–27 s).
no consent decision observed in the scan; the collection/synchronization layer had already fired
The cookie banner is loaded (3034 ms), but no request carrying a consent decision is observed in this session. Tealium, depcollect event collection with identifier synchronization, Hightouch, and Optimizely experiments had all fired by this point — with no observed consent.

Declared versus actual

Marketing, personalized advertising, and tracking technologies — gated on consent (policy) — заявлен
Advertising partners and interest assessment — mentioned in the policy — заявлен
+ Tealium, Hightouch, Optimizely (not named individually in the policy) — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www2.hm.com is the Dutch site of H&M, one of the world’s largest fashion retailers (catalog, account area, membership program, checkout). The data controller is H&M Group. The site is commercial.

Scan: 197 requests to 16 domains, homepage, captured in a clean browser without a VPN or ad blocker. The stack is built around H&M Group’s own infrastructure (hm.com, hmgroup.com) and a customer data platform. The site has its own cookie banner. Requests to edge.microsoft.com are Edge’s built-in page-translation feature, not site tracking.

Who receives the data

Directly, before consent (third-party): Tealium.

The Tealium tag manager and customer data platform (tags.tiqcdn.com) loads its container and deploys tags. H&M Group’s own layer is served from hmgroup.com subdomains: event collection via depcollect (with identifier synchronization idsync), the Hightouch customer-data-activation platform, and the Optimizely A/B-testing platform (“fabulous”) — meaning that, from a network perspective, these are requests to H&M Group domains, but by purpose they are a CDP, activation, and experiments. On the technical side, there’s mPulse/akstat performance monitoring (Akamai) and Akamai bot protection.

Yes, the site has its own H&M cookie banner (turbocookie.hmgroup.com/cookie-banner-hm.js, loads at 3034 ms). But no request carrying a consent decision is observed in this session — the banner merely loads.

The key issue is that the data-collection and activation layer fired regardless: Optimizely experiments (2092 ms), Tealium (3035 ms), Hightouch (3084 ms), and depcollect event collection with identifier synchronization (4268 ms) — all with no observed consent.

The following fire without observed consent:

  • Optimizely / “fabulous” A/B experiments — a datafile (2092 ms);
  • Tealium (tag manager/CDP) — container and tags (from 3035 ms);
  • Hightouch (customer-data activation) — a profile request (3084 ms);
  • depcollect event collection and idsync identifier synchronization (from 4268 ms);
  • the idservice identity service (930 ms).

Performance monitoring and bot protection raise no concerns — these are technical and security purposes. The concern is the data-collection layer, identifier synchronization, and experiments: these are non-technical purposes, and they fire with no observed consent. Identifier synchronization (idsync) is especially telling — an advertising-adjacent purpose.

Why “served via first-party subdomains” is not a free pass

This point matters for understanding the issue. The fact that much of this layer is served from H&M Group’s own subdomains looks, from a network standpoint, like first-party data collection. But legally, the question isn’t whose domain the request goes to — it’s the nature and legal basis of the collection. Event collection and identifier synchronization are behavioral and advertising-adjacent processing; Tealium is a third-party customer data platform; Optimizely runs experiments — all of them require consent. H&M Group’s own policy classifies marketing, personalized advertising, and tracking technologies as consent-based processing, and explicitly mentions advertising partners and interest assessment. Launching this layer without observed consent contradicts both the rule and the site’s own documentation.

Conclusion

Hm.com is a case where a consent mechanism is present (the cookie banner loads), but the customer-data-collection layer doesn’t wait for it. Tealium deploys tags, H&M Group’s own event collector synchronizes identifiers, the Hightouch platform requests a profile, and Optimizely experiments start — all with no observed consent, even though the site’s own policy classifies marketing, advertising, and tracking as consent-based processing. The key takeaway for the reader: neither serving requests through first-party subdomains nor the mere presence of a banner eliminates the consent requirement — the data-collection layer, identifier synchronization, and experiments should be gated on consent so they don’t fire before the user’s choice.

Evidence
Original (audit)
HAR file: nl/hm-com-2026-06-23.har
SHA-256: bce2971fa4da4ac8a64ab1fd74c59e0f3d4197d312c2f13735d72dde6a3d63f5
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Dutch Data Protection Authority (AP)autoriteitpersoonsgegevens.nl

To: Dutch Data Protection Authority (AP)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website hm.com.

2. Circumstances
I visited the website hm.com and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 23 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site loads its own H&M cookie banner (turbocookie.hmgroup.com/cookie-banner-hm.js at 3034 ms), but no consent decision is observed in this session. Meanwhile, a full data-collection and activation layer fires. The Tealium tag manager and customer data platform (tags.tiqcdn.com) loads the utag.js container (3035 ms) and deploys tags (utag.491, utag.545 at 4101 ms). H&M Group's own event collector depcollect.hmgroup.com sends POST requests to /dep/v1/ with events and to /dep/v1/idsync/ — identifier synchronization (from 4268 ms). The Hightouch customer-data-activation platform (hightouch.hmgroup.com) makes a profile request (3084 ms). The A/B-testing platform (Optimizely, served as 'fabulous.hmgroup.com') loads an experiments datafile (2092 ms). Behavioral data collection, identifier synchronization, and experiments are non-technical purposes requiring consent under art. 11.7a Telecommunicatiewet and Art. 6(1)(a) GDPR. H&M Group's own policy classifies marketing, personalized advertising, and tracking technologies as consent-based processing, and explicitly mentions advertising partners and interest assessment. Here, however, the collection and synchronization layer fires with no observed consent, even though the banner has already loaded. The identifier synchronization (idsync) is especially telling — an advertising-adjacent purpose — occurring before consent. The content of the events cannot be assessed from the sanitized HAR, since the payload has been stripped — so the behavior itself is what's recorded: collection and synchronization requests before consent.

Full technical documentation is published at: https://gdpru.eu/en/audits/nl-hm-com/

3. Provisions violated
Art. 6(1)(a) GDPR and art. 11.7a Telecommunicatiewet — the data-collection layer, identifier syncing, and experiments run before consent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]