Technical audit · 2026-06-15

dati.terna.it

Italy's National Grid Operator, Open Data Portal

The open-data portal of Italy's national grid operator. 501 requests, 19 domains — most from the embedded Power BI dashboards. The site is on the whole built competently: it uses consent mode, sets not a single cookie, and Google Analytics honestly fired in refusal mode. But the Dynatrace monitoring works independently of consent — both before the banner and against the refusal — while the provider table promised in the policy is absent from the document.

Timeline of the leak

+0–792 ms · stack load
A Sitecore portal. The usual libraries, Google fonts and styling load. There is no consent banner yet.
+793–1102 ms · trackers start before the banner
At +793 ms, simultaneously with the usual assets, Google Tag Manager and the Dynatrace monitoring agent load — before the Cookiebot consent banner even appears on the page (+1010 ms). That is, the tools are loaded before the consent interface.
+3613–6245 ms · telemetry, consent, a single analytics hit
The first Dynatrace telemetry goes out at +3613 ms — more than two seconds before consent is recorded. The cookie decision is recorded at +5835 ms, and with the status «statistics and marketing declined». After this, Google Analytics 4 sends exactly one anonymised measurement (+6245 ms) in denied-consent mode, without setting a cookie. Dynatrace, meanwhile, continues to send telemetry further on.

Declared versus actual

+ Dynatrace RUM (monitoring agent, works independently of consent) — не заявлен
+ All providers from the promised but absent policy table (Google, Microsoft, Cookiebot, Dynatrace) — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

dati.terna.it is the open-data portal of Terna, the operator of Italy’s national electricity transmission grid. It is built on the Sitecore CMS, the main content being several embedded interactive Power BI reports. The capture shows 501 requests to 19 domains, and the overwhelming majority of them are the Power BI infrastructure and accompanying Microsoft telemetry, that is, the working innards of the dashboards for the sake of which the portal exists. The policy names Terna itself as the data controller — correctly and unambiguously. The capture, like the whole series, was taken on a clean Edge browser — with no VPN and no ad blocker. This is a deliberate method: a blocking browser would simply cut out the trackers and show an empty picture, whereas the task is to see exactly what the site does to an ordinary visitor with default settings. So everything described below is the site’s behaviour in a real, typical visit, not in artificially «cleaned» conditions.

There is a banner — the Cookiebot system. Its script initialises at +1010 ms. But the key detail: both Google Tag Manager and the Dynatrace monitoring agent load earlier — at +793 ms, before the banner even appears on the page. That is, by the moment the user is shown a choice, some of the tools are already loaded. The cookie decision itself is recorded at +5835 ms. And here is the interesting part: although in the log it is marked as «accepted», in fact it is a refusal — the individual categories (statistics, marketing, preferences) are recorded as declined. In other words, only the strictly necessary is allowed. This is the bar against which the trackers’ behaviour must be measured further on.

Google Analytics behaved correctly

Credit where it is due. After the refusal was recorded, Google Analytics sent exactly one measurement — and did so in denied-consent mode: with an anonymisation flag, without personalisation and, most importantly, without setting a single cookie. That is, Google’s analytics here respects the user’s refusal: it does not begin full-fledged tracking but sends a single anonymised signal. This is a correct, modern implementation — and it is important not to confuse it with a violation.

Dynatrace, on the contrary, ignores the refusal

And here is the real problem. The Dynatrace monitoring — a tool that watches how the user behaves on the page and how fast it works — sent thirteen telemetry packets during the session. Eight of them went out before the user recorded a decision, and five after. And these «after» ones are especially telling: the consent is recorded as a refusal of statistics, yet Dynatrace nonetheless continues to send data. That is, it works unconditionally — both before the choice and against it. A significant mitigation: Dynatrace here is deployed first-party, on Terna’s own domain, and the telemetry goes there too, not to some third-party advertising player. The data does not leak outward, into others’ hands. But by the regulator’s rules, behavioural-analytics monitoring is not a «strictly necessary» tool, and it should have been launched only with consent. And it does not ask for it.

It is worth noting separately: across all 501 requests the site set not a single cookie. Not one. The tracking, where it exists, goes on without saving markers on the user’s device — which is noticeably better than most of the analysed commercial sites.

The policy refers to a table that is not there

The policy text, unlike many, is written competently: it correctly examines the cookie categories per the regulator’s 2021 guidance and honestly acknowledges that a transfer of data abroad is possible and relies on the safeguards provided for by the GDPR — that is, there is no false promise of «we transfer nowhere» here. But in one place the document breaks off: the cookie section explicitly refers to «the table that follows below», where the providers and links to their terms should be listed — and there is no table itself in the document. Right after the promise comes the next section. Because of this omission, not a single actually working tool — neither Dynatrace, nor Google, nor Microsoft, nor Cookiebot — is ever named. The promise of transparency is there, but the transparency itself is not, in this spot.

Fonts and Microsoft infrastructure

Two points for completeness. First, the fonts are loaded from Google’s servers, which means the visitor’s IP goes to Google before consent — the same mechanism as on a number of other sites; but since the policy acknowledges transfer abroad in principle, this is not a separate false promise here. Second, the bulk of the requests are Power BI and Microsoft telemetry (Application Insights), which switches on already deep in the session, at the 16th second, as the dashboards themselves load. This is the functional innards of the reports for the sake of which the portal is made; I note it as Microsoft telemetry but do not classify it as hidden tracking.

What cannot be claimed from the capture

Honest caveats. The capture covers one page with dashboards — the behaviour of the other sections is not visible from here. I do not see what exactly is configured inside the Google Tag Manager container — only that down the chain the analytics fired in refusal mode. This lightweight export has no server IP addresses, so I take the geography from the domains. And since no one manually pressed the cookie decision in the automatic capture, the recorded status «declined» reflects the default behaviour rather than the conscious choice of a live person — but this is exactly what an ordinary visitor sees in the first seconds.

Conclusion

This is a carefully assembled site with one specific flaw. In its favour: a modern consent mode, not a single cookie set, Google analytics that fired correctly in refusal mode, a correctly named controller and an honest acknowledgement of data transfer abroad. Against it — the Dynatrace monitoring, which works independently of consent (both before the banner and against the refusal of statistics), and the provider table promised but absent from the policy, because of which not a single tool is named. The main takeaway for the reader: there is no predatory advertising tracking here, as on other sites — the problem is pinpoint and mostly technical, but consent on this portal so far works only halfway.

Evidence
Original (audit)
HAR file: it/dati-terna-it-2026-06-15.har
SHA-256: d6db18792b81748de48adf21e508ca0795a3b9c488b53988e931157e875286b6
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website dati.terna.it.

2. Circumstances
I visited the website dati.terna.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The Dynatrace RUM monitoring (the ruxitagentjs agent) loads at +793 ms, before the consent banner appears, and its telemetry begins going out from +3613 ms. In total 13 such transmissions went out during the session — eight before consent was recorded and five after. Meanwhile the recorded consent declines statistics. That is, Dynatrace works unconditionally: both before the user's choice and against the refusal of statistics. It is first-party, no data leaks outward, but as a behavioural-analytics tool it should by the regulator's rules wait for consent — and it ignores it.

2) The cookie section of the policy correctly describes the categories and explicitly refers to «the table that follows below», with a list of providers and links to their terms. There is no such table in the document at all — right after the promise comes the next section. As a result, not a single actually working tool (Dynatrace, Google Analytics, Microsoft, Cookiebot) is named.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-dati-terna-it/

3. Provisions violated
Italian regulator's cookie guidance (2021) / Art. 6(1)(a) GDPR — monitoring outside consent; Art. 13(1)(e) GDPR — the promised provider table is absent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]