Digital Audit - Zara
Domain: Digital / Technology Entity scope (brand-floor): Zara (flagship of Inditex). Group-level technology forming Zara’s operating stack is in scope; Inditex parent context is flagged. Vendor-domicile rule applied: Israeli-domiciled entities are the focus of this audit. Compiled: 2026-06-21 Method: Live web search only
Enterprise Technology Stack & Vendor Relationships
Zara’s core technology is deployed at Inditex group level: an omnichannel e-commerce platform (zara.com), an RFID-based inventory system across all stores, in-store assisted self-checkout, automated Click & Collect, and a cloud analytics estate.1
RFID: Inditex runs a chain-wide RFID inventory system using RAIN RFID chips applied at manufacture; Tyco Retail Solutions (Johnson Controls / Sensormatic) and chip-layer provider Impinj are cited - both US-domiciled, not Israeli.2 In-store checkout: Zara’s assisted self-checkout, deployed to 100% of stores and integrated with RFID, is described as developed internally; no Israeli vendor identified.3 Cloud/analytics: Inditex uses Google Cloud (BigQuery), Snowflake, Azure, and AWS with Python/Power BI tooling - all non-Israeli hyperscalers.4
Key Israeli-domiciled vendor - Anodot/Glassbox. Public reporting from the April 2026 data breach (below) confirms Inditex had contracted Anodot - an AI-powered business-monitoring/anomaly-detection platform - for analytics services, including read-access integration into Inditex’s Google BigQuery instances.5 Anodot is domiciled in Petach Tikva, Israel,6 and was acquired by Glassbox Ltd (incorporated in Israel, same Petach Tikva HQ, Tel Aviv Stock Exchange-listed) on 4 November 2025.78 Inditex described the breach source as a “former technology provider,” indicating the Anodot contract had ended, but authentication tokens issued during the live contract had not been revoked, leaving residual access active.9
Negative checks (no Zara/Inditex relationship identified): Riskified (Israeli-founded, NYC-domiciled - not Israeli-domiciled), Forter (Israeli-founded, US-domiciled - not Israeli-domiciled), Dynamic Yield (Israeli-founded, now Mastercard/US - not Israeli-domiciled), Trigo (Israeli; documented clients are Tesco/REWE/Netto, not Inditex),10 and Check Point (Israeli; no named Zara/Inditex relationship).
Surveillance, Biometrics & Retail Technology
Anodot/Glassbox analytics integration (key finding). Inditex granted Anodot read access to BigQuery data warehouses holding Zara customer transaction records.5 Anodot performs real-time anomaly detection on business metrics using unsupervised machine learning;11 Israeli-domiciled infrastructure (Anodot, subsequently a Glassbox subsidiary) therefore held persistent read-level access to Inditex’s e-commerce customer data - email addresses, order IDs, product SKUs, purchase histories, geographic market identifiers, and support-ticket metadata.12 Glassbox’s own product is a digital-experience analytics platform (session replay, journey analysis) processing over a trillion customer journeys annually;1314 no public evidence indicates Inditex/Zara separately contracted Glassbox’s session-replay product distinct from the Anodot relationship.
RFID and in-store tracking: Zara’s RFID system tracks garments from manufacture to sale (FY2025 reporting cites “soft tag alarm technology” in 100% of stores, 90% of products); it does not involve facial recognition, customer biometrics, or computer-vision surveillance, and no Israeli vendor was identified in this subsystem.1 AI virtual try-on: “Zara Try-on” (synthetic-avatar virtual fitting, 43 markets, 7M+ sessions by end-2025) names no Israeli AI vendor.1
Cloud Infrastructure, Data Residency & Sovereign Cloud Participation
Inditex’s disclosed cloud platforms - Google Cloud (BigQuery), Snowflake, Azure, AWS - are US-domiciled hyperscalers.4 The Anodot relationship created a channel through which a Petach Tikva-domiciled entity, operating under Israeli jurisdiction, held authenticated access to Inditex’s BigQuery environment hosting Zara customer data;5 the precise data-residency region (EU vs US) is not specified in public reporting. No public evidence identified of Inditex participation in Israeli cloud programs, Israeli government data frameworks, or Israeli sovereign-cloud infrastructure.
Defence, Intelligence & Security Sector Technology Relationships
No public evidence identified of any Zara or Inditex technology relationship with Israeli defence, intelligence, or security-sector entities, nor of Zara using Israeli cybersecurity vendors (Check Point, CyberArk, Radware) in named relationships. No public evidence identified that Anodot or Glassbox holds material Israeli defence or intelligence contracts placing Inditex data in proximity to the Israeli security establishment.
AI, Algorithmic & Autonomous Systems
Inditex describes broad internal AI use for demand forecasting, replenishment, pricing, personalisation, and virtual try-on, referencing partnerships with Google (AI/ML) and AWS (cloud).154 Zara’s “Try-on” tool launched December 2025 (43 markets, 7M+ sessions).1 Anodot’s unsupervised-ML anomaly-detection platform - integrated into Inditex’s BigQuery environment before contract termination - is the one Israeli-domiciled AI tool identified in Zara’s operating stack.7 No other Israeli AI/algorithmic vendor was identified as providing named services to Zara/Inditex.
Technology Ecosystem & R&D Footprint
Inditex operates its own technology and digital division in Arteixo, Galicia, with significant in-house development, and committed ~€2.3 billion ordinary capex for FY2026 toward technology integration and online-platform improvement.31 No public evidence identified of Inditex R&D partnerships, accelerator programmes, or venture investments in Israeli technology companies. (Context: Glassbox, now Anodot’s parent, was incorporated in Israel in 2010 as Clarisite, IPO’d on the Tel Aviv Stock Exchange in June 2021, and is engineered in Petach Tikva; Anodot was founded in Israel in 2014.136)
Civil Society Scrutiny & Regulatory History
April 2026 data breach - Anodot as attack vector. In April 2026, the ShinyHunters extortion group named Zara as a victim, claiming access to “BigQuery instances data … via Anodot.com.”1617 Inditex acknowledged “unauthorised access to databases hosted by a third party containing information on transactions with customers,” activated security protocols, and notified regulators including Spain’s AEPD.18 Have I Been Pwned catalogued the breach on 8 May 2026: ~197,400 unique email addresses with product SKUs, order IDs, geographic identifiers, and support-ticket origins; Inditex denied names, passwords, or payment data were included.1918 Researchers attributed the vector to compromised, un-revoked Anodot authentication tokens retaining BigQuery read access after the contract ended;912 the same Anodot pathway was used against Vimeo, Rockstar Games, McGraw Hill, 7-Eleven, and Carnival in the same campaign.20 The incident is significant here because the attack vector ran through an Israeli-domiciled provider (Anodot, Petach Tikva; Glassbox subsidiary), placing Israeli-jurisdiction infrastructure in the data-access chain for Zara’s customer records.
Worker pressure (context): Inditex’s European Works Council urged termination of the Israeli franchise agreements following the September 2024 ETUC statement - a commercial-operations matter, not a technology finding.21 No prior GDPR fines or data-protection enforcement against Inditex/Zara were identified for 2024–2026.
End Notes
Footnotes
-
https://www.inditex.com/itxcomweb/api/media/1da2c9d1-dbca-49fb-9563-982a8a27fae6/INDITEXFullYear2025.pdf ↩ ↩2 ↩3 ↩4 ↩5
-
https://www.impinj.com/library/blog/zaras-retail-inventory-management-system-driv ↩
-
https://www.retail-week.com/fashion/store-gallery-zara-unveils-most-tech-driven-store-yet-with-scan-and-go-payments-and-automated-returns/7041641.article ↩ ↩2
-
https://www.klover.ai/inditex-ai-strategy-analysis-of-dominance-in-new-era-fashion/ ↩ ↩2 ↩3
-
https://cyberinsider.com/inditex-confirms-third-party-breach-as-hackers-threaten-zara-data-leak/ ↩ ↩2 ↩3
-
https://www.glassbox.com/news/glassbox-anodot-acquisition/ ↩ ↩2
-
https://israeldesks.com/glassbox-raises-usd-100-million-at-usd-500-million-valuation-in-tel-aviv-stock-exchange-ipo/ ↩
-
https://www.cybersecurity-insiders.com/zara-data-breach-retired-provider-cloud-tokens/ ↩ ↩2
-
https://securityaffairs.com/191859/cyber-crime/zara-data-breach-197000-customers-exposed-in-third-party-security-incident.html ↩ ↩2
-
https://www.calcalistech.com/ctech/articles/0,7340,L-3909635,00.html ↩ ↩2
-
https://cybernews.com/security/zara-carnival-7eleven-ransomware-shinyhunters-leak-warning/ ↩
-
https://www.brinztech.com/breach-alerts/brinztech-alert-inditex-zara-bershka-retail-giant-breached-global-customer-database-for-sale/ ↩
-
https://ground.news/article/zara-owner-inditex-reports-unauthorised-access-to-transaction-databases ↩ ↩2
-
https://www.rescana.com/post/vimeo-data-breach-2026-shinyhunters-exploit-anodot-integration-to-expose-119-000-user-records-via-snowflake-and-bigquery/ ↩