Policy changed — see what exactly · 2026-07-13 →
The website of Confindustria — Italy's largest confederation of industrialists. 110 requests, 13 domains. Google Analytics receives the status «analytics allowed» before the consent banner is even shown to the user: the analytics is on by default rather than after consent. There is no general cookie policy in the export — only a newsletter document is provided.
Timeline of the leak
Declared versus actual
Detected trackers
- Google Analytics 4 (G-VV02JFVMJB) — analytics_storage allowed by default
- AccessiWay (acsbapp.com) — accessibility widget
- CookieScript (consent banner)
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — analytics on by default (opt-out)The first Google Analytics 4 measurement goes out at +1191 ms with a consent-state flag in which the analytics storage is already allowed. Meanwhile the CookieScript consent banner is first shown to the user only at +4637 ms — three and a half seconds later. The second analytics measurement (+6205 ms) keeps the same flag — that is, there is no transition between «by default» and «after the user's choice». In other words, the analytics is allowed in advance rather than switched off until explicit consent, as the opt-in approach requires.
- Art. 13 GDPR — a general cookie policy is not providedIn the export there is only a PDF notice on the newsletter subscription (processing of email via a third-party mailing platform). There is no general policy on cookies and tracking, so the declared and actual tools (Google Analytics, AccessiWay, CookieScript itself) cannot be compared from the available data. I note this as a limitation of the check, not as proven concealment.
Context
www.confindustria.it is the website of Confindustria, Italy’s largest confederation of industrialists and employers. Consent management on the site is handled by the CookieScript system. The capture shows 110 requests to 13 domains. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. The case is uncomplicated in composition but telling in essence: the problem is not a long list of trackers, but a single consent setting.
Who receives the data
Spotted here were: Google, AccessiWay, CookieScript.
The wrong document is provided
Let me flag a limitation of the check straight away. The only file in the export is a notice on the newsletter subscription, describing the processing of email addresses for the news mailing. There is no general policy on the site’s cookies and tracking in the export. So whether Google Analytics, the accessibility widget or CookieScript itself is named anywhere I cannot tell from the available data — and I do not pretend that the provided document covers the whole site. This is an honest limitation, not proven concealment.
Analytics is allowed by default
And this is visible from the capture itself, independently of the policy text, and this is the main thing. The embedded Google analytics has a flag that reports whether data collection is allowed. And so, the very first measurement goes out with this flag in the «allowed» position — at +1191 ms. And the consent banner is first shown to the user only at +4637 ms, three and a half seconds later. That is, the analytics already works with an allowed status before the person even had the opportunity to see the banner and choose anything. And this is not a temporary «warm-up»: the second measurement, already after the banner is shown, keeps exactly the same allowed status. There is no transition from the default state to the state after the user’s choice at all. What results is an «on by default» scheme: consent to the analytics here is presumed in advance, and the user is left, at most, to switch off the collection after the fact. This is the opposite of the correct approach, in which the analytics stays silent until explicit consent. Against the backdrop of the bank from this series, where «declined» was the default and collection was switched on strictly after consent, the difference is especially clear.
What cannot be claimed from the capture
A few honest caveats. I did not see the general cookie policy, so I leave the question of declaring the tools open. There is no recorded click on the banner in the capture — but the allowed-analytics flag itself and its immutability are visible right in the requests, and this is enough for the conclusion about «opt-out by default». The accessibility widget and the banner itself also connect without a visible dependence on the user’s choice. The capture covers the home page.
Conclusion
Here the problem is not an abundance of tracking — the composition is modest — but the consent setting itself. Google’s analytics receives the status «allowed» before the banner is even shown to the user, and this status does not change afterwards. That is, data collection is on by default rather than off until consent. On top of this, there is no general cookie policy in the export against which one could compare. The main takeaway for the reader: «there is a consent banner» and «consent is genuinely asked before collection» are not the same thing; here the banner is present, but the analytics starts without waiting for it.
38686b3bdf156ecef2b83d963c14201cd8ac3f08231267276babeb653652df46Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website confindustria.it. 2. Circumstances I visited the website confindustria.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The first Google Analytics 4 measurement goes out at +1191 ms with a consent-state flag in which the analytics storage is already allowed. Meanwhile the CookieScript consent banner is first shown to the user only at +4637 ms — three and a half seconds later. The second analytics measurement (+6205 ms) keeps the same flag — that is, there is no transition between «by default» and «after the user's choice». In other words, the analytics is allowed in advance rather than switched off until explicit consent, as the opt-in approach requires. 2) In the export there is only a PDF notice on the newsletter subscription (processing of email via a third-party mailing platform). There is no general policy on cookies and tracking, so the declared and actual tools (Google Analytics, AccessiWay, CookieScript itself) cannot be compared from the available data. I note this as a limitation of the check, not as proven concealment. Full technical documentation is published at: https://gdpru.eu/en/audits/it-confindustria-it/ 3. Provisions violated Art. 6(1)(a) GDPR — analytics on by default (opt-out); Art. 13 GDPR — a general cookie policy is not provided 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]