Technical audit · 2026-06-15

bricofer.it

Home and Garden Store Chain

The website of the Bricofer home-and-garden store chain (Magento 2). 384 requests, 22 domains. Facebook with a hashed identifier and TikTok send real tracking events from the first seconds — more than twenty seconds before consent is recorded, without any refusal mode. Both of these trackers, as well as three more services, are not named in the policy.

Timeline of the leak

+0–2000 ms · loading the store
A Magento site. Basic theme resources. The Feedaty reviews widget connects already at +2003 ms.
+2078–2912 ms · trackers and banner load in one wave
Tag Manager (+2078 ms), the Facebook library (+2079 ms) and immediately a request with a hashed identifier (+2293 ms), TikTok (+2455 ms), Universal Analytics (+2453 ms), Clerk (+2558 ms) — all of this loads almost simultaneously with the Iubenda banner stub (+2444 ms), without depending on it in any way.
+2528–24603 ms · real events all this time, consent at the very end
Facebook sends a view event (+2528 ms), Universal Analytics a measurement (+2841 ms), TikTok real events (+3535 ms onward), GA4 (+4379 ms). The stream of Facebook and TikTok events continues up to +24.5 seconds. And only at +24603 ms is the consent decision recorded — that is, after practically all the data collection has already taken place.

Declared versus actual

Clerk.io — заявлен
PayPal — заявлен
Google Tag Manager — заявлен
Hotjar (declared, did not fire in this capture) — заявлен
Google Analytics / GA4 — заявлен
Google reCAPTCHA — заявлен
Google Fonts — заявлен
+ Facebook/Meta Pixel (with a hashed identifier) — не заявлен
+ TikTok Pixel — не заявлен
+ Connectif — не заявлен
+ LiveHelp — не заявлен
+ Feedaty — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.bricofer.it is the website of the Italian chain of home, garden and building-materials stores Bricofer Group. The platform is Magento. The policy is generated by a boilerplate builder, with a tidy list of services by category. The capture shows 384 requests to 22 domains. The policy correctly names the company itself as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. This is a commercial site with a saturated advertising stack, and here, unlike the bank from the same series, consent does not work at all.

There is a banner — the Iubenda system, its stub loads at +2444 ms. But it is purely decorative. The advertising trackers load and send data in one wave together with it and immediately after, without depending on it in any way. The consent decision is recorded only at +24603 ms — almost twenty-four seconds later, when all the main data collection has long taken place. That is, its one and only task — to hold back the trackers until the user’s choice — the banner does not perform.

Advertising works from the first seconds

Here there is no refusal mode and no waiting for consent — simply real tracking events from the first seconds. Facebook sends a view event, TikTok sends its real calls, two versions of Google Analytics work at once. And all of this long before the user was given anything to choose. The stream of Facebook and TikTok events drags on to the twenty-fourth second, and only at its very end is consent recorded. In essence, data collection and consent here exist independently of each other.

Facebook received a hashed visitor identifier

The most essential thing. Already at +2293 ms a hashed visitor identifier goes out in the request to Facebook — the technique Meta calls Advanced Matching, which serves to match a site visitor with their profile on Facebook and Instagram. On a retail site, where the visitor often has an account, this is a key tied to a specific person, sent to Meta’s advertising system before any consent. Facebook is not mentioned in the policy at all.

The two most noticeable trackers — outside the policy

It is telling what exactly did not make it into the declaration. The policy conscientiously lists eight services, including Google analytics and even a session-recording tool. But the two most active advertising trackers — Meta and TikTok — which are precisely the ones that send identifiers to advertising networks, are not named in it by a single word. Nor did the marketing-automation service, the chat and the reviews widget make it in. That is, the gap in the declaration falls precisely on those recipients that collect the most about the visitor.

Google Analytics — half of it already dead

A small detail for completeness. Of the two installed Google counters, one is the deprecated Universal Analytics version, which Google disabled back in mid-2023: its request still goes out and takes the IP, but the data is no longer processed. The second, GA4, is working. Further evidence that the stack was assembled in layers and has not been revised for a long time.

What cannot be claimed from the capture

A few honest caveats. The hash sent to Facebook is irreversible — from it I do not restore the original address and do not claim whose identifier it is; I record the mere fact of the transmission of a value tied to the visitor. The press of the «accept» button is not visible in the capture, so the moment at +24603 ms is the recording of a decision, not necessarily a conscious click by a live person; but for the data collection this no longer matters, it took place earlier in any case. The session-recording tool is declared in the policy but did not fire in this capture. The contents of the cookies are not directly visible in the lightweight export; the conclusion about the trackers is drawn from the requests themselves and their parameters.

Conclusion

This is one of the most blatant commercial cases in the series as far as tracking before consent goes. The advertising stack — Facebook with a hashed identifier, TikTok, two versions of Google Analytics — sends real events with identifiers from the very first seconds, more than twenty seconds before the consent moment, without any refusal mode. The consent banner, meanwhile, is present but holds nothing back. And the two most active trackers, Meta and TikTok, are not even named in the policy. The main takeaway for the reader: here there is neither a technical separation of «before and after consent» nor an honest declaration — the visitor’s data, including a key tied to them for Meta, goes out to the advertising networks immediately, while the asking is supposedly later and supposedly about something else.

Evidence
Original (audit)
HAR file: it/www-bricofer-it-2026-06-15.har
SHA-256: 77913861d3ad1ca34cfeecc3b6452b818164a8dd02b19adfb9569390b0a9a3cc
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website bricofer.it.

2. Circumstances
I visited the website bricofer.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) There is no consent gating on the site at all. The Facebook Pixel transmits a hashed visitor identifier (Advanced Matching) already at +2293 ms and sends a view event at +2528 ms; the TikTok Pixel sends real tracking events from +3535 ms; Google Analytics 4 and the deprecated Universal Analytics are working. All of this is real events with identifiers, without any «denied» mode. And the consent-recording moment comes only at +24603 ms — that is, all the data collection happens more than twenty seconds before consent. The consent banner loads, but the trackers do not depend on it in any way.

2) The boilerplate policy, generated by a builder, lists Clerk.io, PayPal, Google Tag Manager, Hotjar, Google Analytics and GA4, Google reCAPTCHA, Google Fonts. But neither the Facebook/Meta Pixel nor the TikTok Pixel — the two most active advertising trackers, sending identifiers to advertising networks — is mentioned in it at all. Nor are the Connectif marketing-automation service, the LiveHelp chat and the Feedaty reviews widget named. In other words, the declaration lacks precisely those recipients that collect the most.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-bricofer-it/

3. Provisions violated
Art. 6(1)(a) GDPR — advertising works from the first seconds, before consent; Art. 13(1)(e) GDPR — the two most active trackers are not named

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]