Technical audit · 2026-06-15

difesa.it

Ministry of Defence of Italy

The website of Italy's Ministry of Defence. 141 requests, 12 domains. The own analytics is implemented exemplarily — with IP masking and without cookies, as promised. But the policy explicitly states that data does not leave the EU, whereas two YouTube videos in regular mode hand the visitor's IP to Google (USA), and the operations map to the American mapper Esri. All of this before consent, which is not present in the capture.

Timeline of the leak

+0–815 ms · stack load
A site on the standard Italian government-site theme. The main code and fonts come from its own domain. The consent-banner scripts are loaded in the common bundle at +652–655 ms.
+652–655 ms · banner loaded, but there is no decision
The consent-banner files are present, but there is not a single acceptance or refusal event in the capture. And, as seen further on, it does not hold back the embedded YouTube clips and the map tiles: they load independently of the banner.
+2535–5798 ms · analytics, map in the USA, YouTube and Google advertising
The own analytics sends measurements (+2571, +3308 ms) — with IP masking, without cookies. In parallel, the operations map pulls tiles from Esri / ArcGIS servers in the USA (+2535 ms). Two YouTube videos in regular mode (+2882 ms) pull in the DoubleClick advertising (+4035 ms), its ad-status script (+4046 ms) and a Google utility domain (+5540 ms). A little later YouTube sends further logging events (+7718, +8737 ms). All of this without recorded consent.

Declared versus actual

YouTube (listed among the third-party services) — заявлен
Own analytics with IP masking (matches the policy) — заявлен
+ Google DoubleClick (advertising infrastructure) — не заявлен
+ Google utility domain (WAA) — не заявлен
+ Esri / ArcGIS map tiles (USA) — не заявлен
+ Transmission of the IP to the USA (the policy promises the opposite) — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

difesa.it is the official portal of Italy’s Ministry of Defence. It is built on the standard Italian government-site theme, with an interactive operations map. The capture shows 141 requests to 12 domains. The policy correctly names the ministry itself as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker — that is, it reflects what an ordinary visitor sees. And let me state the main observation straight away: this site shows two completely different levels of care within a single page. One thing here was done exemplarily. And another — exactly the opposite, and all the more noticeable against the backdrop of the first.

The analytics — done right

I will begin with praise. The web analytics on the site is its own, on the government platform, deployed on a subdomain of the ministry itself. The policy honestly describes what exactly is collected: the IP address, and masked at that — the last two bytes are zeroed, so the exact visitor cannot be worked out from it — as well as the type of browser, system and device. The capture confirms this: the analytics sets not a single cookie and assigns the visitor no persistent marker. Here the promised and the done coincide.

YouTube pulls in Google’s advertising machine

But further on comes a discrepancy. Two YouTube videos are embedded on the home page, and they are embedded in regular mode rather than privacy mode. The difference is fundamental: regular mode, the moment the page opens, itself pulls in Google’s advertising infrastructure — the DoubleClick domain, its ad-status script and Google’s utility domains — even if the visitor did not press «play». This is exactly what is visible in the capture: Google advertising is active from the fourth second. A little later YouTube also sends logging events about the viewing. The policy, meanwhile, promises that such third-party services switch on only after consent via the banner — and there is no consent in the capture at all, and the banner does nothing to hold back these clips.

The operations map takes the IP to the USA

Something easy to miss behind the more noticeable YouTube. The interactive map on the site loads its base layer — the map tiles — from the servers of the company Esri (the ArcGIS service), and this is an American supplier. This happens already at +2535 ms, at the moment the map is drawn, and with every such request the visitor’s IP address goes to the USA. The map is functional and needed by the site, but the data recipient is a foreign company, and it is not named in the policy.

The policy promises not to transfer data abroad — but does

Here everything converges to a single point, and this is the most serious part. The ministry’s policy explicitly states two things: that data is not transferred to third parties beyond those listed, and that it is not transferred to countries outside the EU. Only YouTube and social networks are listed. But in fact the visitor’s IP, in the very first seconds, goes to the USA in two streams at once — to Google (via YouTube’s advertising innards) and to Esri (via the map). Neither the advertising Google nor Esri is on the list, and the promise of «we do not transfer outside the EU» diverges from reality directly. On the site of a defence ministry, where even the mere fact of who reads it is sensitive, such a discrepancy cannot be considered a formality.

What cannot be claimed from the capture

A few honest caveats. The contents of the own analytics’ measurements go out not in the request address but in the body, which is not preserved in this lightweight export — so on the IP masking I rely on the policy text, and it is consistent with the absence of cookies and an identifier. The absence of a consent event in the capture may mean either that the banner received no press, or that it does not hold back third-party content in principle — but for the outcome this does not change the picture: the third-party domains fired independently. The capture covers the home page, the exact server IP addresses are not preserved in the export, I take the geography from the ownership of the domains and companies.

Conclusion

Within a single site — two different approaches to privacy. The ministry did the analytics exemplarily: its own, with IP masking, without cookies, exactly as written in the policy. But alongside this, the home page in the first seconds hands the visitor’s IP to Google — via YouTube videos in regular mode, dragging along the DoubleClick advertising — and to the American mapper Esri via the operations map. And all of this directly against the policy’s own promise not to transfer data either to unnecessary third parties or outside the EU, and before any consent. The main takeaway for the reader: the ministry clearly knows how to do it right — it proved this with its analytics — which means the leaking of the defence portal’s readers to Google and to the USA is not incompetence but an oversight, one that should all the more be eliminated.

Evidence
Original (audit)
HAR file: it/difesa-it-2026-06-15.har
SHA-256: a7f4340c338d5444488836f8e762e9ce1335c0fce9731e0366946d12f7105952
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website difesa.it.

2. Circumstances
I visited the website difesa.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The policy explicitly states that data is transferred neither to third parties beyond those listed, nor to third countries outside the EU. In fact, when the home page opens, the visitor's IP address goes to the USA in two directions at once: to Google — via the YouTube videos embedded in regular mode, which pull in the DoubleClick advertising and Google utility domains — and to the American mapping company Esri, whose tiles are loaded by the interactive operations map. Both recipients are US companies, and the policy warns of no such transfer. For the site of a defence ministry this discrepancy is especially weighty.

2) The policy promises that non-technical and third-party services are activated only after the user's consent via the banner. In the capture the YouTube videos and the associated Google advertising and utility domains are active at +2882–5798 ms, while there is no recorded consent in the capture: the banner scripts are loaded, but the acceptance event is absent, and it does not hold back the embedded clips.

3) The videos are embedded in regular YouTube mode instead of privacy mode. It is precisely because of this that simply opening the home page — without playing any video — automatically pulls in Google's advertising infrastructure. Privacy-mode embedding would not do this.

4) YouTube and social networks are listed in the policy, but the DoubleClick advertising, the Google utility domain and the Esri / ArcGIS mapping service are mentioned neither by name nor as categories of data recipients.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-difesa-it/

3. Provisions violated
Art. 13(1)(f) and Chapter V GDPR — transfer to the USA against an explicit promise; The site's own policy / Art. 6(1)(a) GDPR — third-party content before consent; Art. 25 GDPR — privacy is not built into the design; Art. 13(1)(e) GDPR — some recipients are not named

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]