Policy changed — see what exactly · 2026-07-11 →
The section on Italian intelligence services on the Intel Today blog — a WordPress.com platform site with the WordAds advertising program. 94 requests, 37 domains — the largest advertising stack in the series. The machine consent string that all the exchanges carry says «no consent for anything» — while a dozen and a half advertising exchanges synchronise identifiers anyway. This is not the blog's choice, but the platform's standard scheme for millions of sites.
Timeline of the leak
Declared versus actual
Detected trackers
- Full real-time advertising auction: Google DoubleClick GPT, Amazon APS, Rubicon/Magnite, OpenX, TripleLift, 33Across, GumGum, Media.net, Casale Media, OmnitagJS, SmartAdServer (via a Prebid wrapper)
- Google Analytics Classic (ga.js, long disabled by Google)
- Automattic/Jetpack analytics (stats.wp.com, pixel.wp.com)
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — advertising works against the «no consent» signalAll requests to the advertising exchanges carry a machine consent string in the standard industry format. On decoding it, one sees: consent is not given for any processing purpose — all permissions zeroed. Nevertheless, over ten exchanges perform identifier synchronisation and bid requests, carrying precisely this «nothing allowed» string. The first such synchronisation (SmartAdServer) goes out already at +1310 ms — before the cookie notice even appears on the page (+2261 ms), while the main exchange with the exchanges goes on from +10250 ms. There is no explicit «accept» press in the capture: the refusal string is the default state, and the advertising works on top of it.
- Art. 13(1)(e) GDPR — data recipients not namedThe Automattic policy describes advertising in general terms — «advertising partners» — without naming a single one of the more than fifteen actual data recipients (Google, Amazon, Rubicon, OpenX, TripleLift, 33Across, GumGum, Media.net, Casale Media and others). The specific list is moved to a separate page not included in the document itself.
Context
inteltoday.org is an independent blog about European intelligence services, hosted on the WordPress.com platform and earning through its WordAds advertising program. The audit was done on the section «European Agencies: Italy». An important caveat about jurisdiction: the blog itself has no separate Italian attachment — both the platform and the privacy policy belong to the American company Automattic and are common to the whole platform. The capture shows 94 requests to 37 domains — this is the largest advertising stack in the whole series. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker.
Was there a consent banner
There is a banner, but it appears later than the advertising itself. The cookie notice arrives at +2261 ms, while the full list of advertising vendors loads only at +9610 ms — at almost the tenth second. By this time the advertising infrastructure has long been working: the analytics, the auction wrapper, Google and Amazon were launched in the first two seconds, and the first identifier synchronisation with an exchange went out as early as +1310 ms — before the notice even showed. There is no explicit «accept» press in the capture.
Consent says «no» — while the advertising works anyway
This is the heart of the analysis, and precision is needed here. Each request to the advertising exchanges carries a special machine string — the standard industry format for recording what the user consented to. I decoded this string. And in it not a single data-processing purpose is allowed: there is no consent for anything. That is, the exchanges receive an unambiguous signal «the user allowed nothing» — and still do their thing: more than ten advertising platforms synchronise the visitor’s identifiers among themselves in order to recognise them on different sites and select advertising. The refusal signal and the actual behaviour directly contradict each other. This is no longer simply «trackers fired before consent» — this is working on top of an explicitly recorded absence of consent.
Who receives the data
To be concrete, here is who participates in this exchange: Google’s advertising system, Amazon, and a whole range of advertising exchanges — Rubicon, OpenX, TripleLift, 33Across, GumGum, Media.net, Casale Media, OmnitagJS, SmartAdServer. A dozen and a half recipients, and each takes its share of the data about the visit. In the policy, meanwhile, not one of them is named — only generic «advertising partners». The visitor will in no way learn from the document that their data spreads across such a number of companies.
Google Analytics — twice dead here
A separate detail. The installed counter is not even the previous, but the version before last of Google Analytics, even older than the one Google disabled in 2023. A request to it still goes out, and the visitor’s IP with it, but there has long been nothing to process this data — the counter is dead. Yet more evidence that the stack was assembled by inertia and is maintained by no one.
This is the platform’s scheme, not the blog’s choice
Important for fairness. This whole advertising auction is not something the author of the intelligence-services blog set up. It is the standard monetisation of WordPress.com: you connect WordAds — and the platform itself hangs the whole set of exchanges on the site. So exactly the same picture recurs on millions of free blogs with this program, regardless of their content. On the one hand, this removes the question of the author’s personal intent. On the other, it makes the finding far larger in scale: this is the behaviour not of one site, but of a whole platform.
What cannot be claimed from the capture
A few honest caveats. Cookie-setting on the exchanges’ side is not directly visible in this lightweight export — on the identifier synchronisation I judge from the characteristic exchange requests, not from saved headers. The absence of an «accept» press means the refusal string is the default state rather than necessarily the conscious refusal of a live person; but this is exactly what an ordinary visitor sees in the first seconds. Some of the exchanges may formally rely on «legitimate interest» for certain operations, but advertising-identifier synchronisation is precisely what requires consent by the rules. And to recall: the platform and the policy are common, American; the section on Italy was audited.
Conclusion
This is the heaviest case in the series in terms of the volume of advertising tracking. A full real-time auction — Google, Amazon and a dozen exchanges — synchronises the visitor’s identifiers, although the machine consent record explicitly says that nothing is allowed. Not one of the dozen and a half recipients is named in the policy, and on top of that a dead Google counter leaks the IP in vain. And since all this is the platform’s standard monetisation rather than the choice of a specific blog, the same scheme works on millions of similar sites. The main takeaway for the reader: here the reader’s interests — in this case an interest in the topic of intelligence services — go to the advertising market despite the signal that they gave no consent.
36a2bb8ac653e3f8d8a70508ee5609b8ec6f40d4554eb8b4a6fe605c6ed6ad75Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website inteltoday.org. 2. Circumstances I visited the website inteltoday.org and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) All requests to the advertising exchanges carry a machine consent string in the standard industry format. On decoding it, one sees: consent is not given for any processing purpose — all permissions zeroed. Nevertheless, over ten exchanges perform identifier synchronisation and bid requests, carrying precisely this «nothing allowed» string. The first such synchronisation (SmartAdServer) goes out already at +1310 ms — before the cookie notice even appears on the page (+2261 ms), while the main exchange with the exchanges goes on from +10250 ms. There is no explicit «accept» press in the capture: the refusal string is the default state, and the advertising works on top of it. 2) The Automattic policy describes advertising in general terms — «advertising partners» — without naming a single one of the more than fifteen actual data recipients (Google, Amazon, Rubicon, OpenX, TripleLift, 33Across, GumGum, Media.net, Casale Media and others). The specific list is moved to a separate page not included in the document itself. Full technical documentation is published at: https://gdpru.eu/en/audits/it-inteltoday-org-it/ 3. Provisions violated Art. 6(1)(a) GDPR — advertising works against the «no consent» signal; Art. 13(1)(e) GDPR — data recipients not named 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]