The open-data portal of Italy's national grid operator. 501 requests, 19 domains — most from the embedded Power BI dashboards. The site is on the whole built competently: it uses consent mode, sets not a single cookie, and Google Analytics honestly fired in refusal mode. But the Dynatrace monitoring works independently of consent — both before the banner and against the refusal — while the provider table promised in the policy is absent from the document.
Timeline of the leak
Declared versus actual
Detected trackers
- Dynatrace RUM — first-party monitoring, works independently of consent
- Google Analytics 4 — fired in denied-consent mode, without cookies
- Cookiebot (consent banner)
- Microsoft Power BI and Azure Application Insights — telemetry of the embedded dashboards
- Google Fonts
- CDN (unpkg, npmcdn, jsdelivr)
Indicators of GDPR non-compliance
- Italian regulator's cookie guidance (2021) / Art. 6(1)(a) GDPR — monitoring outside consentThe Dynatrace RUM monitoring (the ruxitagentjs agent) loads at +793 ms, before the consent banner appears, and its telemetry begins going out from +3613 ms. In total 13 such transmissions went out during the session — eight before consent was recorded and five after. Meanwhile the recorded consent declines statistics. That is, Dynatrace works unconditionally: both before the user's choice and against the refusal of statistics. It is first-party, no data leaks outward, but as a behavioural-analytics tool it should by the regulator's rules wait for consent — and it ignores it.
- Art. 13(1)(e) GDPR — the promised provider table is absentThe cookie section of the policy correctly describes the categories and explicitly refers to «the table that follows below», with a list of providers and links to their terms. There is no such table in the document at all — right after the promise comes the next section. As a result, not a single actually working tool (Dynatrace, Google Analytics, Microsoft, Cookiebot) is named.
Context
dati.terna.it is the open-data portal of Terna, the operator of Italy’s national electricity transmission grid. It is built on the Sitecore CMS, the main content being several embedded interactive Power BI reports. The capture shows 501 requests to 19 domains, and the overwhelming majority of them are the Power BI infrastructure and accompanying Microsoft telemetry, that is, the working innards of the dashboards for the sake of which the portal exists. The policy names Terna itself as the data controller — correctly and unambiguously. The capture, like the whole series, was taken on a clean Edge browser — with no VPN and no ad blocker. This is a deliberate method: a blocking browser would simply cut out the trackers and show an empty picture, whereas the task is to see exactly what the site does to an ordinary visitor with default settings. So everything described below is the site’s behaviour in a real, typical visit, not in artificially «cleaned» conditions.
Was there a consent banner
There is a banner — the Cookiebot system. Its script initialises at +1010 ms. But the key detail: both Google Tag Manager and the Dynatrace monitoring agent load earlier — at +793 ms, before the banner even appears on the page. That is, by the moment the user is shown a choice, some of the tools are already loaded. The cookie decision itself is recorded at +5835 ms. And here is the interesting part: although in the log it is marked as «accepted», in fact it is a refusal — the individual categories (statistics, marketing, preferences) are recorded as declined. In other words, only the strictly necessary is allowed. This is the bar against which the trackers’ behaviour must be measured further on.
Google Analytics behaved correctly
Credit where it is due. After the refusal was recorded, Google Analytics sent exactly one measurement — and did so in denied-consent mode: with an anonymisation flag, without personalisation and, most importantly, without setting a single cookie. That is, Google’s analytics here respects the user’s refusal: it does not begin full-fledged tracking but sends a single anonymised signal. This is a correct, modern implementation — and it is important not to confuse it with a violation.
Dynatrace, on the contrary, ignores the refusal
And here is the real problem. The Dynatrace monitoring — a tool that watches how the user behaves on the page and how fast it works — sent thirteen telemetry packets during the session. Eight of them went out before the user recorded a decision, and five after. And these «after» ones are especially telling: the consent is recorded as a refusal of statistics, yet Dynatrace nonetheless continues to send data. That is, it works unconditionally — both before the choice and against it. A significant mitigation: Dynatrace here is deployed first-party, on Terna’s own domain, and the telemetry goes there too, not to some third-party advertising player. The data does not leak outward, into others’ hands. But by the regulator’s rules, behavioural-analytics monitoring is not a «strictly necessary» tool, and it should have been launched only with consent. And it does not ask for it.
Not a single cookie throughout the whole session
It is worth noting separately: across all 501 requests the site set not a single cookie. Not one. The tracking, where it exists, goes on without saving markers on the user’s device — which is noticeably better than most of the analysed commercial sites.
The policy refers to a table that is not there
The policy text, unlike many, is written competently: it correctly examines the cookie categories per the regulator’s 2021 guidance and honestly acknowledges that a transfer of data abroad is possible and relies on the safeguards provided for by the GDPR — that is, there is no false promise of «we transfer nowhere» here. But in one place the document breaks off: the cookie section explicitly refers to «the table that follows below», where the providers and links to their terms should be listed — and there is no table itself in the document. Right after the promise comes the next section. Because of this omission, not a single actually working tool — neither Dynatrace, nor Google, nor Microsoft, nor Cookiebot — is ever named. The promise of transparency is there, but the transparency itself is not, in this spot.
Fonts and Microsoft infrastructure
Two points for completeness. First, the fonts are loaded from Google’s servers, which means the visitor’s IP goes to Google before consent — the same mechanism as on a number of other sites; but since the policy acknowledges transfer abroad in principle, this is not a separate false promise here. Second, the bulk of the requests are Power BI and Microsoft telemetry (Application Insights), which switches on already deep in the session, at the 16th second, as the dashboards themselves load. This is the functional innards of the reports for the sake of which the portal is made; I note it as Microsoft telemetry but do not classify it as hidden tracking.
What cannot be claimed from the capture
Honest caveats. The capture covers one page with dashboards — the behaviour of the other sections is not visible from here. I do not see what exactly is configured inside the Google Tag Manager container — only that down the chain the analytics fired in refusal mode. This lightweight export has no server IP addresses, so I take the geography from the domains. And since no one manually pressed the cookie decision in the automatic capture, the recorded status «declined» reflects the default behaviour rather than the conscious choice of a live person — but this is exactly what an ordinary visitor sees in the first seconds.
Conclusion
This is a carefully assembled site with one specific flaw. In its favour: a modern consent mode, not a single cookie set, Google analytics that fired correctly in refusal mode, a correctly named controller and an honest acknowledgement of data transfer abroad. Against it — the Dynatrace monitoring, which works independently of consent (both before the banner and against the refusal of statistics), and the provider table promised but absent from the policy, because of which not a single tool is named. The main takeaway for the reader: there is no predatory advertising tracking here, as on other sites — the problem is pinpoint and mostly technical, but consent on this portal so far works only halfway.
d6db18792b81748de48adf21e508ca0795a3b9c488b53988e931157e875286b6Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website dati.terna.it. 2. Circumstances I visited the website dati.terna.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The Dynatrace RUM monitoring (the ruxitagentjs agent) loads at +793 ms, before the consent banner appears, and its telemetry begins going out from +3613 ms. In total 13 such transmissions went out during the session — eight before consent was recorded and five after. Meanwhile the recorded consent declines statistics. That is, Dynatrace works unconditionally: both before the user's choice and against the refusal of statistics. It is first-party, no data leaks outward, but as a behavioural-analytics tool it should by the regulator's rules wait for consent — and it ignores it. 2) The cookie section of the policy correctly describes the categories and explicitly refers to «the table that follows below», with a list of providers and links to their terms. There is no such table in the document at all — right after the promise comes the next section. As a result, not a single actually working tool (Dynatrace, Google Analytics, Microsoft, Cookiebot) is named. Full technical documentation is published at: https://gdpru.eu/en/audits/it-dati-terna-it/ 3. Provisions violated Italian regulator's cookie guidance (2021) / Art. 6(1)(a) GDPR — monitoring outside consent; Art. 13(1)(e) GDPR — the promised provider table is absent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]