Technical audit · 2026-06-15

inteltoday.org

Blog on European Intelligence Services

The section on Italian intelligence services on the Intel Today blog — a WordPress.com platform site with the WordAds advertising program. 94 requests, 37 domains — the largest advertising stack in the series. The machine consent string that all the exchanges carry says «no consent for anything» — while a dozen and a half advertising exchanges synchronise identifiers anyway. This is not the blog's choice, but the platform's standard scheme for millions of sites.

Timeline of the leak

+0–903 ms · the page and the first trackers
A WordPress site. Already at +778 ms — the platform's own analytics (stats.wp.com), at +904 ms — Google Analytics Classic (ga.js), a script long disabled by Google.
+1120–2261 ms · advertising before the consent notice
The Prebid wrapper (+1120 ms), Google DoubleClick (+1259 ms), Amazon (+1919 ms) are loaded and launched before the cookie notice itself appears (+2261 ms). Moreover, the first identifier synchronisation with the SmartAdServer exchange goes out already at +1310 ms.
+9610–13381 ms · full auction with the «refusal» string
The consent vendor list loads as one of the last (+9610 ms). From +10250 ms an exchange of identifiers goes on between a dozen exchanges (Rubicon, OpenX, TripleLift, 33Across, GumGum, Media.net, Casale Media, OmnitagJS, SmartAdServer) — and all requests carry the same consent string, in which not a single purpose is allowed.

Declared versus actual

+ Google Analytics — не заявлен
+ Google DoubleClick GPT — не заявлен
+ Amazon APS — не заявлен
+ Rubicon/Magnite — не заявлен
+ OpenX — не заявлен
+ TripleLift — не заявлен
+ 33Across — не заявлен
+ GumGum — не заявлен
+ Media.net — не заявлен
+ Casale Media — не заявлен
+ OmnitagJS — не заявлен
+ SmartAdServer — не заявлен
+ Automattic/Jetpack analytics — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

inteltoday.org is an independent blog about European intelligence services, hosted on the WordPress.com platform and earning through its WordAds advertising program. The audit was done on the section «European Agencies: Italy». An important caveat about jurisdiction: the blog itself has no separate Italian attachment — both the platform and the privacy policy belong to the American company Automattic and are common to the whole platform. The capture shows 94 requests to 37 domains — this is the largest advertising stack in the whole series. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker.

There is a banner, but it appears later than the advertising itself. The cookie notice arrives at +2261 ms, while the full list of advertising vendors loads only at +9610 ms — at almost the tenth second. By this time the advertising infrastructure has long been working: the analytics, the auction wrapper, Google and Amazon were launched in the first two seconds, and the first identifier synchronisation with an exchange went out as early as +1310 ms — before the notice even showed. There is no explicit «accept» press in the capture.

This is the heart of the analysis, and precision is needed here. Each request to the advertising exchanges carries a special machine string — the standard industry format for recording what the user consented to. I decoded this string. And in it not a single data-processing purpose is allowed: there is no consent for anything. That is, the exchanges receive an unambiguous signal «the user allowed nothing» — and still do their thing: more than ten advertising platforms synchronise the visitor’s identifiers among themselves in order to recognise them on different sites and select advertising. The refusal signal and the actual behaviour directly contradict each other. This is no longer simply «trackers fired before consent» — this is working on top of an explicitly recorded absence of consent.

Who receives the data

To be concrete, here is who participates in this exchange: Google’s advertising system, Amazon, and a whole range of advertising exchanges — Rubicon, OpenX, TripleLift, 33Across, GumGum, Media.net, Casale Media, OmnitagJS, SmartAdServer. A dozen and a half recipients, and each takes its share of the data about the visit. In the policy, meanwhile, not one of them is named — only generic «advertising partners». The visitor will in no way learn from the document that their data spreads across such a number of companies.

Google Analytics — twice dead here

A separate detail. The installed counter is not even the previous, but the version before last of Google Analytics, even older than the one Google disabled in 2023. A request to it still goes out, and the visitor’s IP with it, but there has long been nothing to process this data — the counter is dead. Yet more evidence that the stack was assembled by inertia and is maintained by no one.

This is the platform’s scheme, not the blog’s choice

Important for fairness. This whole advertising auction is not something the author of the intelligence-services blog set up. It is the standard monetisation of WordPress.com: you connect WordAds — and the platform itself hangs the whole set of exchanges on the site. So exactly the same picture recurs on millions of free blogs with this program, regardless of their content. On the one hand, this removes the question of the author’s personal intent. On the other, it makes the finding far larger in scale: this is the behaviour not of one site, but of a whole platform.

What cannot be claimed from the capture

A few honest caveats. Cookie-setting on the exchanges’ side is not directly visible in this lightweight export — on the identifier synchronisation I judge from the characteristic exchange requests, not from saved headers. The absence of an «accept» press means the refusal string is the default state rather than necessarily the conscious refusal of a live person; but this is exactly what an ordinary visitor sees in the first seconds. Some of the exchanges may formally rely on «legitimate interest» for certain operations, but advertising-identifier synchronisation is precisely what requires consent by the rules. And to recall: the platform and the policy are common, American; the section on Italy was audited.

Conclusion

This is the heaviest case in the series in terms of the volume of advertising tracking. A full real-time auction — Google, Amazon and a dozen exchanges — synchronises the visitor’s identifiers, although the machine consent record explicitly says that nothing is allowed. Not one of the dozen and a half recipients is named in the policy, and on top of that a dead Google counter leaks the IP in vain. And since all this is the platform’s standard monetisation rather than the choice of a specific blog, the same scheme works on millions of similar sites. The main takeaway for the reader: here the reader’s interests — in this case an interest in the topic of intelligence services — go to the advertising market despite the signal that they gave no consent.

Evidence
Original (audit)
HAR file: it/inteltoday-org-2026-06-15.har
SHA-256: 36a2bb8ac653e3f8d8a70508ee5609b8ec6f40d4554eb8b4a6fe605c6ed6ad75
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website inteltoday.org.

2. Circumstances
I visited the website inteltoday.org and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) All requests to the advertising exchanges carry a machine consent string in the standard industry format. On decoding it, one sees: consent is not given for any processing purpose — all permissions zeroed. Nevertheless, over ten exchanges perform identifier synchronisation and bid requests, carrying precisely this «nothing allowed» string. The first such synchronisation (SmartAdServer) goes out already at +1310 ms — before the cookie notice even appears on the page (+2261 ms), while the main exchange with the exchanges goes on from +10250 ms. There is no explicit «accept» press in the capture: the refusal string is the default state, and the advertising works on top of it.

2) The Automattic policy describes advertising in general terms — «advertising partners» — without naming a single one of the more than fifteen actual data recipients (Google, Amazon, Rubicon, OpenX, TripleLift, 33Across, GumGum, Media.net, Casale Media and others). The specific list is moved to a separate page not included in the document itself.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-inteltoday-org-it/

3. Provisions violated
Art. 6(1)(a) GDPR — advertising works against the «no consent» signal; Art. 13(1)(e) GDPR — data recipients not named

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]