The website of the Supreme Court of Cassation of Italy. 29 requests, 3 domains. The policy is detailed and tidy, but without a section on third-party services: the YouTube player embedded on the home page is not named, and it works in regular mode and takes the visitor's IP to Google, USA.
Timeline of the leak
Declared versus actual
Detected trackers
- Web Analytics Italia / Matomo (ingestion.webanalytics.italia.it) — carries the visitor identifier
- YouTube in regular mode ([www.youtube.com](https://www.youtube.com)) — transmits the IP to Google, USA
Indicators of GDPR non-compliance
- Art. 13(1)(e) GDPR — the embedded YouTube is not declaredThe detailed policy examines session and functional cookies, denies profiling and describes the statistics as anonymous, but there is no section on third-party services in it at all. On the home page (the media centre), meanwhile, a YouTube video player is embedded, which is not mentioned in the document even once.
- Art. 13(1)(f) GDPR — transmission of the IP to Google USA via regular YouTubeThe video is embedded in regular mode ([www.youtube.com](https://www.youtube.com)), not privacy mode (youtube-nocookie.com). The very loading of the player infrastructure already transmits the visitor's IP address to Google, an American company. The policy stays silent about such a transfer and at the same time asserts that no personal information is transmitted via cookies — which sits poorly with the request to Google. It is fixed by replacing the regular embedding with privacy mode.
Context
www.cortedicassazione.it is the website of the Supreme Court of Cassation of Italy, the country’s highest judicial instance. It is built on its own content-management system on the Ministry of Justice platform. The capture shows 29 requests to three domains. The court itself is correctly named as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. The case is on the whole tidy: a short capture, government analytics, a detailed policy. But there is one gap, and it concerns Google.
Who receives the data
Spotted here were: Google.
Was there a consent banner
There is a cookie notice on the site — its styles load at the start of the visit. The government analytics is equated to technical means and requires no consent, so in itself its firing is not a violation. It is only worth noting that its measurement carries the visitor identifier, so the «anonymity» here, as on other government sites, comes with a caveat. But the YouTube player launches independently of the notice — and this is the main plot.
A detailed policy — but without a section on third parties
The document carefully examines the cookie categories: session, functional, explicitly denies profiling and persistent cookies, and calls the statistics anonymous. Done in detail and competently. But there is no section on third-party services in the policy at all — while on the home page, in the media centre, a YouTube video player is embedded. It is not mentioned in the document even once, although it is a third-party service that receives the visitor’s data.
YouTube in regular mode takes the IP to Google
Here is where the flaw lies. Video can be embedded in two ways: in regular mode and in privacy mode, specially designed so as not to reach out to Google until the video is played and not to set tracking cookies. On this site regular mode is chosen. And that means the very loading of the player already reaches Google’s infrastructure and transmits the visitor’s IP address to the USA. What results is a double mismatch: the third-party service is not named in the policy, and at the same time the document asserts that no personal information is transmitted via cookies — whereas a request to Google does occur. This is fixed simply, by replacing the regular embedding with privacy mode, after which the request to Google before the video plays disappears.
What cannot be claimed from the capture
A few honest caveats. In the capture the loading of the player’s interface and program part is visible; the heavier requests to Google’s servers occur when the video is played, and in this session there are none — but even loading the player in regular mode already transmits the IP. On the IP masking in the government analytics I judge from its default configuration; the visitor identifier, meanwhile, is visible right in the capture. The policy, by the way, relies on the old national data code rather than on the regulation in force — a detail indicating the document’s age. The capture covers the home page.
Conclusion
A tidy and detailed policy with two linked gaps, and both about one thing — the silent request to Google. The embedded YouTube player works in regular mode and transmits the visitor’s IP to the USA, named nowhere in the document, while the document itself promises that no personal data is transmitted via cookies. Plus the government analytics, described as anonymous, in fact carries the visitor identifier. Neither of these is a catastrophe, and it is fixed in a couple of moves. The main takeaway for the reader: even on the site of the highest court, a single innocent embedded video can quietly send your IP to Google — precisely because regular mode was chosen instead of privacy mode.
c9d1b2b735d2ab0a3a02a1b5e562cc2952d56931ad60ae49a8c5de6ba51241edWhere to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website cortedicassazione.it. 2. Circumstances I visited the website cortedicassazione.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The detailed policy examines session and functional cookies, denies profiling and describes the statistics as anonymous, but there is no section on third-party services in it at all. On the home page (the media centre), meanwhile, a YouTube video player is embedded, which is not mentioned in the document even once. 2) The video is embedded in regular mode ([www.youtube.com](https://www.youtube.com)), not privacy mode (youtube-nocookie.com). The very loading of the player infrastructure already transmits the visitor's IP address to Google, an American company. The policy stays silent about such a transfer and at the same time asserts that no personal information is transmitted via cookies — which sits poorly with the request to Google. It is fixed by replacing the regular embedding with privacy mode. Full technical documentation is published at: https://gdpru.eu/en/audits/it-cortedicassazione-it/ 3. Provisions violated Art. 13(1)(e) GDPR — the embedded YouTube is not declared; Art. 13(1)(f) GDPR — transmission of the IP to Google USA via regular YouTube 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]