Technical audit · 2026-06-20

chicco.it

Children's and Baby Products Store

Chicco.it is an online store of children's and baby products (the Artsana group). Home-page capture: 135 requests, 20 domains. The subject matter makes the case especially sensitive: the policy explicitly mentions the collection of minors' data and the estimated date of birth, that is, the term of pregnancy — while behavioural profiling works on the site. There is a Cookiebot consent platform, but in the first three seconds, before any decision, Salesforce profiling (Interaction Studio and Einstein), Google advertising and Klarna tracking fire. And separately serious: in this session the user ultimately refused consent, but Salesforce profiling continued to send behavioural events even after the refusal, whereas Google advertising fell silent after the refusal. That is, not everyone honoured the refusal.

Timeline of the leak

634–637 ms · profiling starts together with the banner
Simultaneously with the loading of the Cookiebot consent platform, Salesforce profiling (the Interaction Studio beacon), the Einstein commercial profiler (CQuotient), Klarna tracking and Cloudflare Insights analytics start. This happens before any user choice.
1636 ms · Google advertising activity
Google receives an advertising-activity request. The consent signal shows that analytics is allowed by default while advertising is not — that is, the analytics part is already on without an explicit choice.
2554–3250 ms · behavioural events and recommendations
Salesforce profiling sends behavioural events to its servers, and Einstein requests personalised product recommendations. All of this is before consent.
55363 ms · the user refuses
The user refuses consent — the Cookiebot platform records the refusal. By law, from this moment non-technical processing must cease.
63260 and 123264 ms · profiling continues after refusal
Despite the refusal, Salesforce profiling twice sends behavioural events after it. Google advertising, meanwhile, fell silent — that is, not all services honoured the refusal.

Declared versus actual

Salesforce / Evergage — заявлен
Klarna — заявлен
Google — заявлен
+ Einstein / CQuotient — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.chicco.it is the online store and brand site of Chicco, children’s and baby products (the Artsana group). The data controller is Artsana. The audience is parents and parents-to-be. The policy explicitly states that the data collected includes minors’ data and the estimated date of birth (the term of pregnancy), which makes the subject matter sensitive. Capture: 135 requests to 20 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. There is a Cookiebot consent-collection platform. The technical stack is the Salesforce commercial platform with behavioural profiling, Google advertising and Klarna payment tracking.

Who receives the data

Spotted here were: Salesforce, Google, Klarna. Salesforce is represented by two profiling services: Interaction Studio (the Evergage domains) builds a behavioural profile of the user, and Einstein (CQuotient) issues personalised product recommendations based on behaviour. Google receives advertising activity. Klarna — the instalment-payment service — runs its own tracking. Additionally, Cloudflare Insights analytics and a tag service on the site’s own subdomain work.

Yes, the site has the Cookiebot consent-collection platform. In this session the user ultimately made a choice — refused consent. But by the moment of the refusal the profiling and advertising had already fired, and some of them continued to work afterwards as well.

In the first three seconds, before any decision, the following fire:

  • Salesforce behavioural profiling (Interaction Studio) — beacon and events;
  • the Salesforce Einstein commercial profiler — recommendations based on behaviour;
  • Google advertising activity;
  • tracking by the Klarna payment service;
  • Cloudflare Insights analytics. Behavioural profiling for marketing is a non-technical purpose requiring prior consent. Here it unfolds before it.

Not everyone honoured the refusal

This is the pivotal and most serious point. In the session the user refused consent. After this, Google’s advertising requests ceased — that is, it is technically possible to execute a refusal. But Salesforce profiling continued to send behavioural events after the refusal — twice, tens of seconds later. That is, the very service that builds the marketing profile ignored the refusal. This contradicts both the legal requirement to cease processing upon refusal and the policy’s promise that consent is withdrawn as easily as it is given.

Sensitive context

The subject matter is worth emphasising separately. The policy explicitly names the collection of minors’ data and the estimated date of birth — that is, the term of pregnancy. The behavioural profiling that works here before consent and continues after refusal operates in a context connected with pregnancy and small children. This is one of the most sensitive areas for marketing targeting, and the requirements for the basis of processing are especially strict here.

Conclusion

Chicco.it is a serious commercial case, and the seriousness is heightened by the subject matter. There is a consent platform on the site, but Salesforce behavioural profiling, Google advertising and Klarna tracking fire before consent, and after an explicit refusal Salesforce profiling does not stop — it keeps sending behavioural events, whereas Google advertising honoured the refusal. The main takeaway for the reader: a refusal of consent should stop processing, and here it is clear that honouring it is technically possible — Google did so — but the profiling service continued to work. On a site where the term of pregnancy and data about children are collected, this divergence between the promised withdrawal and the profiler’s actual behaviour is especially weighty.

Evidence
Original (audit)
HAR file: it/chicco-it-2026-06-20.har
SHA-256: 93ef59451c691464517b687fbab87e27a40fdd2181603db54d40ca0ddbc982f4
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website chicco.it.

2. Circumstances
I visited the website chicco.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 20 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site has the Cookiebot consent-collection platform, but in a clean session a whole range of services fires in the first three seconds, before any user decision. Salesforce behavioural profiling (Interaction Studio, the Evergage domains) sends its beacon and begins recording events; the Salesforce Einstein commercial profiler (CQuotient) loads and requests personalised recommendations; the Klarna payment service runs its own tracking; Google requests advertising activity. Google's consent signal at this moment shows that analytics is allowed by default while advertising is not — that is, the analytics part is on without an explicit choice. Behavioural profiling for marketing under EU rules requires prior consent, and here it unfolds before it.

2) In this session the user ultimately refused consent — the Cookiebot platform recorded the refusal. However, the Salesforce profiling (Interaction Studio) did not stop: already after the refusal it twice sent behavioural events to its servers. That is, the refusal was ignored by the very part of the stack that builds the marketing profile. This directly contradicts both the law, which requires processing to cease upon withdrawal or refusal of consent, and the policy's own promise that consent can be withdrawn as easily as it was given. For comparison: Google's advertising requests ceased after the refusal — that is, it is technically possible to honour a refusal, but the profiling service did not do so.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-chicco-it/

3. Provisions violated
Art. 6(1)(a) GDPR — behavioural profiling and advertising fire before consent; Art. 7(3) GDPR — after refusal, Salesforce profiling continues

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]