Technical audit · 2026-06-16

mediamarkt.nl

Website of the MediaMarkt consumer electronics chain

Mediamarkt.nl is the site of a major consumer electronics retail chain. Homepage scan: 107 requests, 11 domains. For an online store, the result is unusually clean. Tag-manager containers load but deploy no commercial trackers: no Google Analytics, no advertising, no social media pixels, and no session recording fire in the clean, no-consent session — the site has its own consent mechanism, and commercial analytics is held behind it. Before consent, only a fraud-protection service, running under legitimate interest, and technical performance monitoring fire. Not a single cookie was set during the session. No violations were recorded.

Timeline of the leak

662 ms · performance monitoring
Technical page-performance monitoring loads — measuring load speed, not tracking.
2681 ms · tag-manager containers
Tag-manager containers load. Importantly, on their own they deploy no commercial trackers: analytics, advertising, and pixels did not fire in this session.
4462 ms · consent category request
The site requests consent categories via its own mechanism — meaning commercial tools are tied to the user's choice.
7941 мс · fraud protection
A fraud-protection service loads, collecting device signals to detect suspicious transactions. This is a security measure under legitimate interest, disclosed in the policy, not marketing tracking.
commercial trackers gated on consent, no cookie set
The site has its own consent mechanism, and commercial analytics is held behind it — it did not fire in the clean session. Before consent, only fraud protection and performance monitoring fired. Not a single cookie was set during the session.

Declared versus actual

Fraud protection (legitimate interest) — заявлен

Detected trackers

Context

www.mediamarkt.nl is the site of a major Dutch consumer electronics retail chain (part of the MediaMarktSaturn group). The data controller is MediaMarkt. The site is commercial, an online store with a catalog, search, and account area.

Scan: 107 requests to 11 domains, homepage, captured in a clean Edge browser without a VPN or ad blocker. The site has its own consent mechanism. The technical stack looks unusually restrained for an online store.

Who receives the data

Among third-party services, only the fraud-protection service is active before consent.

Tag-manager containers load but deploy no commercial trackers: Google Analytics, advertising, social media pixels, and session recording did not fire in this session. Before consent, a fraud-protection service — collecting device signals to detect suspicious transactions — and technical performance monitoring fire. The former operates under legitimate interest as a security measure, the latter is functional.

Yes, the site has its own consent mechanism, and it’s set up correctly: commercial analytics and advertising are held behind it. In the clean, no-consent session, the tag-manager containers loaded but deployed no commercial trackers whatsoever. Not a single cookie was set during the entire session.

Before consent, the following fire:

  • fraud protection — collecting device signals as a security measure under legitimate interest;
  • performance monitoring — measuring load speed.

Neither purpose relates to marketing or visitor analytics: fraud protection is security, disclosed in the policy as processing under legitimate interest, and performance monitoring is technical. Commercial measurement tools are held pending consent here.

What works in the site’s favor

This is worth highlighting, as it’s rare for an online store. Despite four loaded tag-manager containers, neither Google Analytics, advertising, social media pixels, nor session recording fired before consent. The policy explicitly promises to ask for consent in advance where required, and the scan confirms this.

Conclusion

Mediamarkt.nl is an example of how an online store can hold commercial tracking pending consent. Tag managers load on the page but deploy no analytics, advertising, pixels, or session recording without consent. Before consent, only fraud protection under legitimate interest and technical performance monitoring fire — neither of which is marketing tracking. The key takeaway for the reader: this is close to the model e-commerce should aim for — commercial measurement tools wait for consent, and before that, only what is justified by security or functionality runs. No violations were recorded.

Evidence
Original (audit)
HAR file: nl/mediamarkt-nl-2026-06-16.har
SHA-256: b6815dd000d7744babf8b88552aa32a9dee516a3e191fb59e1224e5622778858
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.