Technical audit · 2026-06-15

acquistinretepa.it

Italy's Public Procurement Portal

Consip is Italy's central public-procurement platform, under the Ministry of Economy and Finance. 115 requests, 4 domains. The policy categorically denies any tracking and any transfer of data abroad. In fact, Google Analytics, Dynatrace and an embedded Salesforce chat are active — with no cookie banner.

Timeline of the leak

+0–244 ms · loading the OpenCMS/Angular stack
OpenCMS, an AngularJS application. The Dynatrace RUM agent (ruxitagentjs) and gtag.js (G-BY17HR7MZ8) load simultaneously, at +236 ms — in the common stream with the rest of the theme scripts.
not applicable
There is no cookie banner at all. The only mention of «cookie» in the HAR is the angular-cookies.js library, a standard AngularJS module with nothing to do with consent management.
+613–5625 ms · full tracking stack
region1.google-analytics.com/g/collect (+613 ms and again at +5625 ms), service.force.com/embeddedservice/esw.min.js — the Salesforce chat widget (+1192 ms), five Dynatrace beacons (rb_, +2601…+5519 ms).

Declared versus actual

+ Google Tag Manager — не заявлен
+ Google Analytics 4 — не заявлен
+ Dynatrace RUM — не заявлен
+ Salesforce Embedded Service — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.acquistinretepa.it is the portal of Consip S.p.A. («Acquisti in Rete PA»), Italy’s central public-procurement platform. The policy names the Ministero dell’Economia e delle Finanze directly as the data controller. HAR: 115 requests, 4 domains.

A categorical statement against the facts

The policy’s wording leaves no room for interpretation: cookies are not used to transmit personal information, persistent cookies and user-tracking systems are not used at all, and navigation data is neither communicated to anyone nor disseminated. Yet already at +236 ms, in parallel with the ordinary theme resources, Google Tag Manager and the Dynatrace RUM agent load, and at +613 ms a full Google Analytics 4 hit is sent with the client ID and browser data.

Salesforce and international transfer

The embedded Salesforce Embedded Service chat widget (service.force.com) loads at +1192 ms. The policy separately declares the absence of any transfer of data to third countries — yet both Google and Salesforce are American companies that receive data on every visit.

Conclusion

www.acquistinretepa.it is one of the most direct contradictions between the text of a policy and the technical behaviour of a site in the whole project: the document does not merely fail to name the trackers, it explicitly denies their existence and any transfer of data abroad, while three separate external services (Google, Dynatrace, Salesforce) are active without a single consent mechanism.

Evidence
Original (audit)
HAR file: it/www-acquistinretepa-it-2026-06-15.har
SHA-256: 9d5c46f02fa36684784e5cd9afd12c08cc82fb8f695fee2128ee3c564b60a748
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website acquistinretepa.it.

2. Circumstances
I visited the website acquistinretepa.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The policy states categorically: «Non viene fatto uso di cookies... né vengono utilizzati... sistemi per il tracciamento degli utenti» and «Nessun dato derivante dalla navigazione nel sito web viene comunicato o diffuso». In fact, Google Tag Manager and GA4 (region1.google-analytics.com/g/collect) are active at +236–613 ms, Dynatrace sends a beacon five times (+2601–5519 ms), and the embedded Salesforce chat (service.force.com) loads at +1192 ms — without a single cookie banner throughout the entire session.

2) The policy states: «Non è prevista la trasmissione di dati personali a paesi terzi o organizzazioni internazionale». Google and Salesforce are both American companies that receive the visitor's data on every page load.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-acquistinretepa-it/

3. Provisions violated
Art. 5(1)(a) / Art. 13 GDPR; Art. 44–49 GDPR (international data transfer)

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]