The website of Italy's communications regulator (AGCOM). 60 requests, 2 domains. The declared analytics (Web Analytics Italia) is not activated at all in this session. The only catch is the undeclared AddToAny widget.
Timeline of the leak
Declared versus actual
Detected trackers
- AddToAny (social-sharing widget)
Indicators of GDPR non-compliance
- Art. 13(1)(e) GDPRThe policy names «Web Analytics Italia» as the sole third party for cookies. The AddToAny social-sharing widget (static.addtoany.com) loads automatically at +591 ms — in parallel with the script of the cookie banner itself — and is not mentioned in the document.
Context
www.agcom.it is the official website of the Autorità per le Garanzie nelle Comunicazioni (AGCOM), Italy’s regulator for communications and media. Drupal 10, the English version of the page. HAR: 60 requests, 2 domains.
Analytics — declared, but not active
The policy describes in detail (16,084 characters) Web Analytics Italia/Matomo as the sole third-party service for analytics cookies, specifying the place of processing (on-premise, Italy) and a link to opt out. In this particular session no requests to Matomo are recorded at all — that is, in practice there is no tracking in this slice, which does not contradict the policy but rather gives no occasion to test it.
AddToAny — the only catch
The AddToAny social-sharing widget loads automatically, at the same moment as the cookie-banner script, and is not mentioned in the document, which names «Web Analytics Italia» as the sole third party. Not a single cookie from AddToAny is recorded in this session — the violation is formal in nature (similar to the esploradati.istat.it/jsdelivr precedent).
Conclusion
www.agcom.it is a practically clean result with one formal inaccuracy: the AddToAny widget is not among the third parties listed in the policy. The main declared tracker (Web Analytics Italia) did not manifest itself at all in this session.
4f45f1725d5d9374294a801baa26206c4fac61b5babb8bd16d57d62e531e9bf2Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website agcom.it. 2. Circumstances I visited the website agcom.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The policy names «Web Analytics Italia» as the sole third party for cookies. The AddToAny social-sharing widget (static.addtoany.com) loads automatically at +591 ms — in parallel with the script of the cookie banner itself — and is not mentioned in the document. Full technical documentation is published at: https://gdpru.eu/en/audits/it-agcom-it/ 3. Provisions violated Art. 13(1)(e) GDPR 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]