The website of the Bricofer home-and-garden store chain (Magento 2). 384 requests, 22 domains. Facebook with a hashed identifier and TikTok send real tracking events from the first seconds — more than twenty seconds before consent is recorded, without any refusal mode. Both of these trackers, as well as three more services, are not named in the policy.
Timeline of the leak
Declared versus actual
Detected trackers
- Facebook/Meta Pixel — transmits a hashed identifier (Advanced Matching)
- TikTok Pixel
- Google Analytics 4 + Universal Analytics (the latter long disabled)
- Clerk.io
- Connectif
- LiveHelp (chat)
- Feedaty (reviews)
- Iubenda (consent banner, holds nothing back)
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — advertising works from the first seconds, before consentThere is no consent gating on the site at all. The Facebook Pixel transmits a hashed visitor identifier (Advanced Matching) already at +2293 ms and sends a view event at +2528 ms; the TikTok Pixel sends real tracking events from +3535 ms; Google Analytics 4 and the deprecated Universal Analytics are working. All of this is real events with identifiers, without any «denied» mode. And the consent-recording moment comes only at +24603 ms — that is, all the data collection happens more than twenty seconds before consent. The consent banner loads, but the trackers do not depend on it in any way.
- Art. 13(1)(e) GDPR — the two most active trackers are not namedThe boilerplate policy, generated by a builder, lists Clerk.io, PayPal, Google Tag Manager, Hotjar, Google Analytics and GA4, Google reCAPTCHA, Google Fonts. But neither the Facebook/Meta Pixel nor the TikTok Pixel — the two most active advertising trackers, sending identifiers to advertising networks — is mentioned in it at all. Nor are the Connectif marketing-automation service, the LiveHelp chat and the Feedaty reviews widget named. In other words, the declaration lacks precisely those recipients that collect the most.
Context
www.bricofer.it is the website of the Italian chain of home, garden and building-materials stores Bricofer Group. The platform is Magento. The policy is generated by a boilerplate builder, with a tidy list of services by category. The capture shows 384 requests to 22 domains. The policy correctly names the company itself as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. This is a commercial site with a saturated advertising stack, and here, unlike the bank from the same series, consent does not work at all.
Was there a consent banner
There is a banner — the Iubenda system, its stub loads at +2444 ms. But it is purely decorative. The advertising trackers load and send data in one wave together with it and immediately after, without depending on it in any way. The consent decision is recorded only at +24603 ms — almost twenty-four seconds later, when all the main data collection has long taken place. That is, its one and only task — to hold back the trackers until the user’s choice — the banner does not perform.
Advertising works from the first seconds
Here there is no refusal mode and no waiting for consent — simply real tracking events from the first seconds. Facebook sends a view event, TikTok sends its real calls, two versions of Google Analytics work at once. And all of this long before the user was given anything to choose. The stream of Facebook and TikTok events drags on to the twenty-fourth second, and only at its very end is consent recorded. In essence, data collection and consent here exist independently of each other.
Facebook received a hashed visitor identifier
The most essential thing. Already at +2293 ms a hashed visitor identifier goes out in the request to Facebook — the technique Meta calls Advanced Matching, which serves to match a site visitor with their profile on Facebook and Instagram. On a retail site, where the visitor often has an account, this is a key tied to a specific person, sent to Meta’s advertising system before any consent. Facebook is not mentioned in the policy at all.
The two most noticeable trackers — outside the policy
It is telling what exactly did not make it into the declaration. The policy conscientiously lists eight services, including Google analytics and even a session-recording tool. But the two most active advertising trackers — Meta and TikTok — which are precisely the ones that send identifiers to advertising networks, are not named in it by a single word. Nor did the marketing-automation service, the chat and the reviews widget make it in. That is, the gap in the declaration falls precisely on those recipients that collect the most about the visitor.
Google Analytics — half of it already dead
A small detail for completeness. Of the two installed Google counters, one is the deprecated Universal Analytics version, which Google disabled back in mid-2023: its request still goes out and takes the IP, but the data is no longer processed. The second, GA4, is working. Further evidence that the stack was assembled in layers and has not been revised for a long time.
What cannot be claimed from the capture
A few honest caveats. The hash sent to Facebook is irreversible — from it I do not restore the original address and do not claim whose identifier it is; I record the mere fact of the transmission of a value tied to the visitor. The press of the «accept» button is not visible in the capture, so the moment at +24603 ms is the recording of a decision, not necessarily a conscious click by a live person; but for the data collection this no longer matters, it took place earlier in any case. The session-recording tool is declared in the policy but did not fire in this capture. The contents of the cookies are not directly visible in the lightweight export; the conclusion about the trackers is drawn from the requests themselves and their parameters.
Conclusion
This is one of the most blatant commercial cases in the series as far as tracking before consent goes. The advertising stack — Facebook with a hashed identifier, TikTok, two versions of Google Analytics — sends real events with identifiers from the very first seconds, more than twenty seconds before the consent moment, without any refusal mode. The consent banner, meanwhile, is present but holds nothing back. And the two most active trackers, Meta and TikTok, are not even named in the policy. The main takeaway for the reader: here there is neither a technical separation of «before and after consent» nor an honest declaration — the visitor’s data, including a key tied to them for Meta, goes out to the advertising networks immediately, while the asking is supposedly later and supposedly about something else.
77913861d3ad1ca34cfeecc3b6452b818164a8dd02b19adfb9569390b0a9a3ccWhere to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website bricofer.it. 2. Circumstances I visited the website bricofer.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) There is no consent gating on the site at all. The Facebook Pixel transmits a hashed visitor identifier (Advanced Matching) already at +2293 ms and sends a view event at +2528 ms; the TikTok Pixel sends real tracking events from +3535 ms; Google Analytics 4 and the deprecated Universal Analytics are working. All of this is real events with identifiers, without any «denied» mode. And the consent-recording moment comes only at +24603 ms — that is, all the data collection happens more than twenty seconds before consent. The consent banner loads, but the trackers do not depend on it in any way. 2) The boilerplate policy, generated by a builder, lists Clerk.io, PayPal, Google Tag Manager, Hotjar, Google Analytics and GA4, Google reCAPTCHA, Google Fonts. But neither the Facebook/Meta Pixel nor the TikTok Pixel — the two most active advertising trackers, sending identifiers to advertising networks — is mentioned in it at all. Nor are the Connectif marketing-automation service, the LiveHelp chat and the Feedaty reviews widget named. In other words, the declaration lacks precisely those recipients that collect the most. Full technical documentation is published at: https://gdpru.eu/en/audits/it-bricofer-it/ 3. Provisions violated Art. 6(1)(a) GDPR — advertising works from the first seconds, before consent; Art. 13(1)(e) GDPR — the two most active trackers are not named 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]