Consip is Italy's central public-procurement platform, under the Ministry of Economy and Finance. 115 requests, 4 domains. The policy categorically denies any tracking and any transfer of data abroad. In fact, Google Analytics, Dynatrace and an embedded Salesforce chat are active — with no cookie banner.
Timeline of the leak
Declared versus actual
Detected trackers
- Google Tag Manager
- Google Analytics 4
- Dynatrace RUM
- Salesforce Embedded Service (chat)
Indicators of GDPR non-compliance
- Art. 5(1)(a) / Art. 13 GDPRThe policy states categorically: «Non viene fatto uso di cookies... né vengono utilizzati... sistemi per il tracciamento degli utenti» and «Nessun dato derivante dalla navigazione nel sito web viene comunicato o diffuso». In fact, Google Tag Manager and GA4 (region1.google-analytics.com/g/collect) are active at +236–613 ms, Dynatrace sends a beacon five times (+2601–5519 ms), and the embedded Salesforce chat (service.force.com) loads at +1192 ms — without a single cookie banner throughout the entire session.
- Art. 44–49 GDPR (international data transfer)The policy states: «Non è prevista la trasmissione di dati personali a paesi terzi o organizzazioni internazionale». Google and Salesforce are both American companies that receive the visitor's data on every page load.
Context
www.acquistinretepa.it is the portal of Consip S.p.A. («Acquisti in Rete PA»), Italy’s central public-procurement platform. The policy names the Ministero dell’Economia e delle Finanze directly as the data controller. HAR: 115 requests, 4 domains.
A categorical statement against the facts
The policy’s wording leaves no room for interpretation: cookies are not used to transmit personal information, persistent cookies and user-tracking systems are not used at all, and navigation data is neither communicated to anyone nor disseminated. Yet already at +236 ms, in parallel with the ordinary theme resources, Google Tag Manager and the Dynatrace RUM agent load, and at +613 ms a full Google Analytics 4 hit is sent with the client ID and browser data.
Salesforce and international transfer
The embedded Salesforce Embedded Service chat widget (service.force.com) loads at +1192 ms. The policy separately declares the absence of any transfer of data to third countries — yet both Google and Salesforce are American companies that receive data on every visit.
Conclusion
www.acquistinretepa.it is one of the most direct contradictions between the text of a policy and the technical behaviour of a site in the whole project: the document does not merely fail to name the trackers, it explicitly denies their existence and any transfer of data abroad, while three separate external services (Google, Dynatrace, Salesforce) are active without a single consent mechanism.
9d5c46f02fa36684784e5cd9afd12c08cc82fb8f695fee2128ee3c564b60a748Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website acquistinretepa.it. 2. Circumstances I visited the website acquistinretepa.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The policy states categorically: «Non viene fatto uso di cookies... né vengono utilizzati... sistemi per il tracciamento degli utenti» and «Nessun dato derivante dalla navigazione nel sito web viene comunicato o diffuso». In fact, Google Tag Manager and GA4 (region1.google-analytics.com/g/collect) are active at +236–613 ms, Dynatrace sends a beacon five times (+2601–5519 ms), and the embedded Salesforce chat (service.force.com) loads at +1192 ms — without a single cookie banner throughout the entire session. 2) The policy states: «Non è prevista la trasmissione di dati personali a paesi terzi o organizzazioni internazionale». Google and Salesforce are both American companies that receive the visitor's data on every page load. Full technical documentation is published at: https://gdpru.eu/en/audits/it-acquistinretepa-it/ 3. Provisions violated Art. 5(1)(a) / Art. 13 GDPR; Art. 44–49 GDPR (international data transfer) 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]