Technical audit · 2026-05-31

aise.it

International Foreign Press Agency

An Italian press agency for foreign media, diplomatic missions and MPs elected abroad. 123 requests, 14 domains — the heaviest stack in the series, and here all five trackers actually fired. Facebook received a hashed visitor identifier before consent, Google Analytics runs on a long-disabled version, and the 2018 policy knows only one tracker out of five, promises anonymity and names a third-party firm as the controller.

Timeline of the leak

+0–297 ms · loading the site
The site's core, libraries and fonts load from its own domain. At +277 ms the styling of the consent banner arrives, at +298 ms its script.
+298–299 ms · the banner blocks nothing
The consent-banner script loads at +298 ms. Already at +299 ms — one millisecond later — the first external tracker (ShinyStat) starts. Between the banner's appearance and the start of tracking there is not even a pause: the banner here is purely decorative.
+299–4951 ms · all five trackers fire
Google Analytics and its visit measurement (+323–377 ms); Facebook — pixel load, transmission of the hashed identifier (+424 ms) and the view event (+511 ms); Embedly (+740 ms); the brznetwork advertising pixel (+778 ms); ShinyStat with five requests, some of which land as late as 4.8–4.95 seconds. All responses successful — the trackers really did fire.

Declared versus actual

Google Analytics — заявлен
+ Facebook Pixel with a hashed identifier (Advanced Matching) — не заявлен
+ ShinyStat (five addresses) — не заявлен
+ Embedly — не заявлен
+ brznetwork advertising pixel — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

AISE (Agenzia Internazionale Stampa Estero) is an Italian press agency founded in 1975. Its audience is specific: Italian media abroad, diplomatic missions and Italian MPs elected abroad. It is not a government body but a private news agency with a subscriber base. The capture shows 123 requests to 14 domains — the most saturated tracking stack of all the sites analysed in the series. And an important difference from similar cases straight away: here the trackers were not merely called — they actually fired. All external requests came back successfully, the scripts loaded and executed. So this is not about intent, but about tracking that took place.

There is a banner, but it is decorative. Its script loads at +298 ms — and already at +299 ms, exactly one millisecond later, the first external tracker starts. Between the appearance of the consent mechanism and the start of tracking there is not even a pause for the user to press anything. There is no trace of a recorded decision in the capture. In other words, the banner is present on the site for show only: holding back the trackers until the user’s choice — its one and only task — it does not perform.

Five trackers — and all really fired

In the very first second a whole set comes to life on the page: for Italy, something government-run would be usual, but here everything is foreign and commercial. Google Analytics with its visit measurement. The Facebook Pixel. The brznetwork advertising pixel. The Embedly service. And the Italian counter ShinyStat — with five separate requests at once, some of which land almost five seconds after opening. Five independent external services, and not one of them failed in this capture — unlike some other sites where trackers broke down on an error, here they fired in full.

Facebook received a hashed visitor identifier

This is the most serious finding. The request to Facebook carries a parameter with a 64-character value — a hashed visitor identifier (typically a hashed email address), sent via the technique Meta calls Advanced Matching. The point of this technique is exactly one: to match a seemingly anonymous site visitor with their specific profile on Facebook and Instagram. And here is the fundamental discrepancy with the policy. The document promises that the data collected is «fully anonymous and does not allow individual visitors to be identified». But the transmission of an identifier tied to a person is the opposite of anonymity. The fact that it is hashed changes nothing in essence: the hash is irreversible for an outsider, but for Meta it is a working key to identifying the user. And all of this goes out at +424 ms — long before any consent. Facebook is not mentioned in the policy by a single word.

Google Analytics is present — but already dead

A curious detail visible only on careful reading. Google Analytics here runs on the old version — so-called Universal Analytics. And Google itself disabled it back in mid-2023: these counters no longer process data. What this means in practice: the request to Google still goes out, and the visitor’s IP address with it — but it no longer collects any useful analytics, the data goes nowhere. That is, the IP leak to the USA persists, while the point of the tracking was long lost. This is further evidence that no one maintains the stack on the site: it was simply left hanging.

The brznetwork advertising pixel

Another undeclared guest — a request to the brznetwork advertising network, dressed up as the load of a tiny image. This is a classic advertising tracking pixel: it shows nothing itself, its task is to record the fact of a visit for the advertising network. In the policy it too, of course, is not mentioned.

The policy — someone else’s, old, and promising too much

The document is dated 2018. As the data controller it names not the AISE agency itself, but a third-party company, Sogedi srl, with contacts on a foreign domain — so the visitor fundamentally cannot tell who is responsible for their data. Of the five actually working trackers, the policy knows exactly one — Google Analytics — and it is precisely about it that it promises full anonymity. To be fair, one thing this policy does not violate: unlike a number of other sites, it does not falsely claim that data is not transferred abroad — on the contrary, it explicitly allows transfer abroad. So there is no complaint here about a «false promise not to transfer abroad». But there is another internal contradiction: the document separately stipulates that marketing requires explicit consent — yet the Facebook marketing pixel fires without any consent, in the very first second.

Why «low» sensitivity is not enough here

It is worth explaining why I raised the sensitivity rating compared with the initial one. It is not about the site itself, but about its audience. This agency is read by diplomatic missions and MPs elected abroad — that is, among the tracked visitors there are, with high probability, people whose profiling in Meta’s advertising system is far more sensitive than the profiling of a random news reader. Transmitting such a visitor’s hashed identifier to Meta is not a harmless counter. That is why I consider the «low» rating an understatement and set it to medium.

What cannot be claimed from the capture

A few honest caveats. The hash in the request to Facebook is irreversible — from it I cannot restore the original address and do not claim whose identifier it is; I record the mere fact of the transmission of a value tied to the visitor. The capture covers only the home page. This lightweight export does not preserve the servers’ IP addresses, so I take the geography from the domains’ ownership. And I do not see what exactly is configured inside the counters beyond the transmitted parameters.

Conclusion

This is the heaviest case in the series. Five different external trackers, and all of them actually fired in this capture rather than breaking down. Facebook received a hashed identifier tied to the visitor before consent — directly against the policy’s promise of full anonymity. Google Analytics hangs on a long-disabled version and now merely leaks the IP to the USA in vain. The advertising pixel and the Italian counter are not named at all. The consent banner is purely decorative and holds nothing back. And the policy itself is from 2018, with the wrong controller, knowing one tracker out of five. The main takeaway for the reader: an agency read by diplomats and MPs abroad hands them over to Meta’s advertising machine from the very first second — and promises them anonymity that does not exist.

Evidence
Original (audit)
HAR file: it/aise-it-2026-05-31.har
SHA-256: d6a19703139c74da2737ddb4fe1abeb30928f8059791e1c8fc913be01e27bc28
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website aise.it.

2. Circumstances
I visited the website aise.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 31 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) The policy asserts that the data collected is «fully anonymous and does not allow individual visitors to be identified». On the same page, the Facebook Pixel transmits to Meta a hashed visitor identifier (a 64-character SHA-256) via the Advanced Matching technique, which serves precisely to match a visitor with their Meta profile. A visitor identifier is the opposite of anonymity. ShinyStat also operates on individual visitors rather than in aggregate.

2) The policy mentions only Google Analytics. The Facebook Pixel, ShinyStat (five addresses), Embedly and the brznetwork advertising pixel are not named at all — neither by name nor as a category of data recipients.

3) The consent-banner script loads at +298 ms, and the first external tracker at +299 ms, one millisecond later, without any pause for the user's choice. Then, in the very first second, Google, Facebook, ShinyStat, Embedly and the advertising pixel run. There is no trace of recorded consent in the capture. Meanwhile the policy itself separately stipulates that marketing requires explicit consent — yet the Facebook marketing pixel fires unconditionally.

4) The document is dated 2018 and names as the data controller not the AISE agency itself, but a third-party company, Sogedi srl, with a contact address on a foreign domain. The visitor cannot tell who is actually responsible for their data.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-aise-it/

3. Provisions violated
Art. 5(1)(a) GDPR — anonymity promised, an identifier transmitted; Art. 13(1)(e) GDPR — one tracker out of five is named; Italian regulator's cookie guidance — trackers above consent; Art. 13(1)(a) GDPR — the wrong controller is named

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]