Chicco.it is an online store of children's and baby products (the Artsana group). Home-page capture: 135 requests, 20 domains. The subject matter makes the case especially sensitive: the policy explicitly mentions the collection of minors' data and the estimated date of birth, that is, the term of pregnancy — while behavioural profiling works on the site. There is a Cookiebot consent platform, but in the first three seconds, before any decision, Salesforce profiling (Interaction Studio and Einstein), Google advertising and Klarna tracking fire. And separately serious: in this session the user ultimately refused consent, but Salesforce profiling continued to send behavioural events even after the refusal, whereas Google advertising fell silent after the refusal. That is, not everyone honoured the refusal.
Timeline of the leak
Declared versus actual
Detected trackers
- Salesforce Interaction Studio (Evergage)
- Salesforce Einstein (CQuotient)
- Google Ad Manager
- Klarna
- Cookiebot
- Cloudflare Insights
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — behavioural profiling and advertising fire before consentThe site has the Cookiebot consent-collection platform, but in a clean session a whole range of services fires in the first three seconds, before any user decision. Salesforce behavioural profiling (Interaction Studio, the Evergage domains) sends its beacon and begins recording events; the Salesforce Einstein commercial profiler (CQuotient) loads and requests personalised recommendations; the Klarna payment service runs its own tracking; Google requests advertising activity. Google's consent signal at this moment shows that analytics is allowed by default while advertising is not — that is, the analytics part is on without an explicit choice. Behavioural profiling for marketing under EU rules requires prior consent, and here it unfolds before it.
- Art. 7(3) GDPR — after refusal, Salesforce profiling continuesIn this session the user ultimately refused consent — the Cookiebot platform recorded the refusal. However, the Salesforce profiling (Interaction Studio) did not stop: already after the refusal it twice sent behavioural events to its servers. That is, the refusal was ignored by the very part of the stack that builds the marketing profile. This directly contradicts both the law, which requires processing to cease upon withdrawal or refusal of consent, and the policy's own promise that consent can be withdrawn as easily as it was given. For comparison: Google's advertising requests ceased after the refusal — that is, it is technically possible to honour a refusal, but the profiling service did not do so.
Context
www.chicco.it is the online store and brand site of Chicco, children’s and baby products (the Artsana group). The data controller is Artsana. The audience is parents and parents-to-be. The policy explicitly states that the data collected includes minors’ data and the estimated date of birth (the term of pregnancy), which makes the subject matter sensitive. Capture: 135 requests to 20 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. There is a Cookiebot consent-collection platform. The technical stack is the Salesforce commercial platform with behavioural profiling, Google advertising and Klarna payment tracking.
Who receives the data
Spotted here were: Salesforce, Google, Klarna. Salesforce is represented by two profiling services: Interaction Studio (the Evergage domains) builds a behavioural profile of the user, and Einstein (CQuotient) issues personalised product recommendations based on behaviour. Google receives advertising activity. Klarna — the instalment-payment service — runs its own tracking. Additionally, Cloudflare Insights analytics and a tag service on the site’s own subdomain work.
Was there a consent banner
Yes, the site has the Cookiebot consent-collection platform. In this session the user ultimately made a choice — refused consent. But by the moment of the refusal the profiling and advertising had already fired, and some of them continued to work afterwards as well.
What fires before consent
In the first three seconds, before any decision, the following fire:
- Salesforce behavioural profiling (Interaction Studio) — beacon and events;
- the Salesforce Einstein commercial profiler — recommendations based on behaviour;
- Google advertising activity;
- tracking by the Klarna payment service;
- Cloudflare Insights analytics. Behavioural profiling for marketing is a non-technical purpose requiring prior consent. Here it unfolds before it.
Not everyone honoured the refusal
This is the pivotal and most serious point. In the session the user refused consent. After this, Google’s advertising requests ceased — that is, it is technically possible to execute a refusal. But Salesforce profiling continued to send behavioural events after the refusal — twice, tens of seconds later. That is, the very service that builds the marketing profile ignored the refusal. This contradicts both the legal requirement to cease processing upon refusal and the policy’s promise that consent is withdrawn as easily as it is given.
Sensitive context
The subject matter is worth emphasising separately. The policy explicitly names the collection of minors’ data and the estimated date of birth — that is, the term of pregnancy. The behavioural profiling that works here before consent and continues after refusal operates in a context connected with pregnancy and small children. This is one of the most sensitive areas for marketing targeting, and the requirements for the basis of processing are especially strict here.
Conclusion
Chicco.it is a serious commercial case, and the seriousness is heightened by the subject matter. There is a consent platform on the site, but Salesforce behavioural profiling, Google advertising and Klarna tracking fire before consent, and after an explicit refusal Salesforce profiling does not stop — it keeps sending behavioural events, whereas Google advertising honoured the refusal. The main takeaway for the reader: a refusal of consent should stop processing, and here it is clear that honouring it is technically possible — Google did so — but the profiling service continued to work. On a site where the term of pregnancy and data about children are collected, this divergence between the promised withdrawal and the profiler’s actual behaviour is especially weighty.
93ef59451c691464517b687fbab87e27a40fdd2181603db54d40ca0ddbc982f4Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website chicco.it. 2. Circumstances I visited the website chicco.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 20 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site has the Cookiebot consent-collection platform, but in a clean session a whole range of services fires in the first three seconds, before any user decision. Salesforce behavioural profiling (Interaction Studio, the Evergage domains) sends its beacon and begins recording events; the Salesforce Einstein commercial profiler (CQuotient) loads and requests personalised recommendations; the Klarna payment service runs its own tracking; Google requests advertising activity. Google's consent signal at this moment shows that analytics is allowed by default while advertising is not — that is, the analytics part is on without an explicit choice. Behavioural profiling for marketing under EU rules requires prior consent, and here it unfolds before it. 2) In this session the user ultimately refused consent — the Cookiebot platform recorded the refusal. However, the Salesforce profiling (Interaction Studio) did not stop: already after the refusal it twice sent behavioural events to its servers. That is, the refusal was ignored by the very part of the stack that builds the marketing profile. This directly contradicts both the law, which requires processing to cease upon withdrawal or refusal of consent, and the policy's own promise that consent can be withdrawn as easily as it was given. For comparison: Google's advertising requests ceased after the refusal — that is, it is technically possible to honour a refusal, but the profiling service did not do so. Full technical documentation is published at: https://gdpru.eu/en/audits/it-chicco-it/ 3. Provisions violated Art. 6(1)(a) GDPR — behavioural profiling and advertising fire before consent; Art. 7(3) GDPR — after refusal, Salesforce profiling continues 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]