Policy changed — see what exactly · 2026-07-13 →
Ovs.it is a clothing-store chain. Home-page capture: 278 requests, 24 domains. There is a OneTrust consent-collection platform, but its consent check in this session is recorded very late — at around the 25th second. And before it, profiling and advertising already fire: Salesforce's profiling services (personalisation and the recommendation engine) launch in the first second, the Blueknow remarketing pixel at the fifth, while Google Analytics and the site's own analytics layer work with analytics allowed by default. Meanwhile the Blueknow remarketing and the iGoDigital personalisation service are not even named in the policy. That is, profiling and follow-up advertising are switched on long before consent and partly undisclosed.
Timeline of the leak
Declared versus actual
Detected trackers
- Salesforce iGoDigital (profiling)
- Salesforce Einstein (CQuotient)
- Blueknow (remarketing)
- Google Analytics 4
- Usabilla (surveys)
- Opticks (anti-fraud)
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — profiling and remarketing fire before consentThe site has a OneTrust consent-collection platform, but its consent check in this session is recorded very late — at around the 25th second. And before it, profiling and advertising fire. Already in the first second Salesforce's profiling services launch — the personalisation service and the Einstein recommendation engine. By the fifth second the Blueknow remarketing pixel fires — that is, advertising retargeting, a follow-up-advertising tool. Google Analytics and the site's own analytics layer, meanwhile, launch with analytics allowed by default. The site's own policy classes the profiling cookies, which track behaviour for personalisation and targeted advertising, in the category requiring consent. That is, the profiling and remarketing, which by the site's own document require consent, fire two dozen seconds before consent is recorded.
- Art. 13 GDPR — the Blueknow remarketing and iGoDigital personalisation are not named in the policyOf the actually working profiling and advertising services, the policy names only the Salesforce recommendation engine. The Blueknow remarketing pixel and the iGoDigital personalisation service are not mentioned in the policy. That is, advertising retargeting and part of the profiling work, but are not disclosed in the list of recipients — the user cannot learn from the document that their data goes to these services.
Context
www.ovs.it is a clothing-store chain, one of the large Italian clothing retailers. The data controller is the OVS operator. The site is commercial: catalogue, search, cart, personal account, customer service via chat. Capture: 278 requests to 24 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. There is a OneTrust consent-collection platform. The technical stack includes Salesforce profiling, advertising retargeting and analytics.
Who receives the data
Spotted here were: Salesforce, Blueknow, Google. Salesforce is represented by profiling services — personalisation and the recommendation engine — as well as the personal-account and support-chat infrastructure. Blueknow is an advertising-retargeting (follow-up-advertising) service. Google — by analytics. Additionally, the LiveStory visual showcase, the Usabilla surveys service, the Opticks fraud protection and the site’s own analytics layer work. I will separately clarify about the requests to the Microsoft Edge domain: they relate to the built-in page-translation function in the browser itself and are not site tracking — the site is not responsible for them.
Was there a consent banner
Yes, the site has a OneTrust consent-collection platform, but its consent check in this session is recorded very late — at around the 25th second. By this moment the profiling, remarketing and analytics have already fired. Meanwhile the site’s own policy classes the profiling cookies — those that track behaviour for personalisation and targeted advertising — in the category requiring consent. That is, the platform itself declares consent obligatory for profiling, while it starts in the first second.
What fires before consent
Before consent is recorded, the following fire:
- Salesforce profiling — personalisation and the recommendation engine;
- the Blueknow remarketing pixel — advertising retargeting;
- Google Analytics and the site’s own analytics layer — with analytics allowed by default;
- the Usabilla surveys service. Profiling and advertising retargeting are non-technical purposes requiring consent, which the policy itself confirms. Here they unfold more than twenty seconds before consent.
The discrepancy with the policy and the undisclosed recipients
Two points. First, the profiling and remarketing fire before consent, whereas the policy classes profiling as consent-based processing. Second, of the actually working services the policy names only the Salesforce recommendation engine, while the Blueknow remarketing pixel and the iGoDigital personalisation service are not mentioned. That is, advertising retargeting works but is not disclosed in the list of recipients.
Conclusion
Ovs.it is a case typical of large retail, with a double discrepancy. Salesforce profiling and Blueknow advertising retargeting fire in the first seconds, the analytics is on by default, and the consent check is recorded only by the 25th second — that is, all these collections happen long before consent. Meanwhile the remarketing and part of the profiling are not even named in the policy. The main takeaway for the reader: when a site itself classes profiling as consent-based processing, launching it and advertising retargeting in the first second contradicts its own document, and an undisclosed remarketing pixel means the user cannot learn of it from the policy. It would be enough to switch the profiling and remarketing into consent-waiting mode and supplement the list of recipients with the actually working services.
869f74ed182f034e1e057a334a45068c64e8d13d91f5b23e3b55fb9deaacb00fWhere to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website ovs.it. 2. Circumstances I visited the website ovs.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 20 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site has a OneTrust consent-collection platform, but its consent check in this session is recorded very late — at around the 25th second. And before it, profiling and advertising fire. Already in the first second Salesforce's profiling services launch — the personalisation service and the Einstein recommendation engine. By the fifth second the Blueknow remarketing pixel fires — that is, advertising retargeting, a follow-up-advertising tool. Google Analytics and the site's own analytics layer, meanwhile, launch with analytics allowed by default. The site's own policy classes the profiling cookies, which track behaviour for personalisation and targeted advertising, in the category requiring consent. That is, the profiling and remarketing, which by the site's own document require consent, fire two dozen seconds before consent is recorded. 2) Of the actually working profiling and advertising services, the policy names only the Salesforce recommendation engine. The Blueknow remarketing pixel and the iGoDigital personalisation service are not mentioned in the policy. That is, advertising retargeting and part of the profiling work, but are not disclosed in the list of recipients — the user cannot learn from the document that their data goes to these services. Full technical documentation is published at: https://gdpru.eu/en/audits/it-ovs-it/ 3. Provisions violated Art. 6(1)(a) GDPR — profiling and remarketing fire before consent; Art. 13 GDPR — the Blueknow remarketing and iGoDigital personalisation are not named in the policy 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]