Technical audit · 2026-06-15

agcom.it

Italy's Communications Regulatory Authority

The website of Italy's communications regulator (AGCOM). 60 requests, 2 domains. The declared analytics (Web Analytics Italia) is not activated at all in this session. The only catch is the undeclared AddToAny widget.

Timeline of the leak

+0–589 ms · loading the Drupal stack
Drupal 10, the pa_theme theme (standard for Italian government sites). The eu_cookie_compliance css module is loaded in the common stream (+588 ms).
+591–592 ms · widget and banner simultaneously
static.addtoany.com/menu/page.js (+591 ms) loads in the same millisecond as eu_cookie_compliance.min.js (+592 ms) — without any dependency of one on the other.
+870–917 ms · finishing AddToAny
static.addtoany.com/menu/modules/core.js (+870 ms) and sm.25.html (+917 ms) — standard assets of the sharing widget. Not a single Set-Cookie throughout the entire session, including from AddToAny. Web Analytics Italia/Matomo is not recorded in the HAR at all.

Declared versus actual

Web Analytics Italia / Matomo (declared, but not active in this session) — заявлен
+ AddToAny (static.addtoany.com) — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.agcom.it is the official website of the Autorità per le Garanzie nelle Comunicazioni (AGCOM), Italy’s regulator for communications and media. Drupal 10, the English version of the page. HAR: 60 requests, 2 domains.

Analytics — declared, but not active

The policy describes in detail (16,084 characters) Web Analytics Italia/Matomo as the sole third-party service for analytics cookies, specifying the place of processing (on-premise, Italy) and a link to opt out. In this particular session no requests to Matomo are recorded at all — that is, in practice there is no tracking in this slice, which does not contradict the policy but rather gives no occasion to test it.

AddToAny — the only catch

The AddToAny social-sharing widget loads automatically, at the same moment as the cookie-banner script, and is not mentioned in the document, which names «Web Analytics Italia» as the sole third party. Not a single cookie from AddToAny is recorded in this session — the violation is formal in nature (similar to the esploradati.istat.it/jsdelivr precedent).

Conclusion

www.agcom.it is a practically clean result with one formal inaccuracy: the AddToAny widget is not among the third parties listed in the policy. The main declared tracker (Web Analytics Italia) did not manifest itself at all in this session.

Evidence
Original (audit)
HAR file: it/www-agcom-it-2026-06-15.har
SHA-256: 4f45f1725d5d9374294a801baa26206c4fac61b5babb8bd16d57d62e531e9bf2
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website agcom.it.

2. Circumstances
I visited the website agcom.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The policy names «Web Analytics Italia» as the sole third party for cookies. The AddToAny social-sharing widget (static.addtoany.com) loads automatically at +591 ms — in parallel with the script of the cookie banner itself — and is not mentioned in the document.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-agcom-it/

3. Provisions violated
Art. 13(1)(e) GDPR

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]