The website of Italy's Ministry of Defence. 141 requests, 12 domains. The own analytics is implemented exemplarily — with IP masking and without cookies, as promised. But the policy explicitly states that data does not leave the EU, whereas two YouTube videos in regular mode hand the visitor's IP to Google (USA), and the operations map to the American mapper Esri. All of this before consent, which is not present in the capture.
Timeline of the leak
Declared versus actual
Detected trackers
- Web Analytics Italia own analytics with IP masking — matches the policy
- YouTube (regular mode, not privacy)
- Google DoubleClick (advertising)
- Google WAA (utility domain)
- ArcGIS / Esri map tiles (USA)
Indicators of GDPR non-compliance
- Art. 13(1)(f) and Chapter V GDPR — transfer to the USA against an explicit promiseThe policy explicitly states that data is transferred neither to third parties beyond those listed, nor to third countries outside the EU. In fact, when the home page opens, the visitor's IP address goes to the USA in two directions at once: to Google — via the YouTube videos embedded in regular mode, which pull in the DoubleClick advertising and Google utility domains — and to the American mapping company Esri, whose tiles are loaded by the interactive operations map. Both recipients are US companies, and the policy warns of no such transfer. For the site of a defence ministry this discrepancy is especially weighty.
- The site's own policy / Art. 6(1)(a) GDPR — third-party content before consentThe policy promises that non-technical and third-party services are activated only after the user's consent via the banner. In the capture the YouTube videos and the associated Google advertising and utility domains are active at +2882–5798 ms, while there is no recorded consent in the capture: the banner scripts are loaded, but the acceptance event is absent, and it does not hold back the embedded clips.
- Art. 25 GDPR — privacy is not built into the designThe videos are embedded in regular YouTube mode instead of privacy mode. It is precisely because of this that simply opening the home page — without playing any video — automatically pulls in Google's advertising infrastructure. Privacy-mode embedding would not do this.
- Art. 13(1)(e) GDPR — some recipients are not namedYouTube and social networks are listed in the policy, but the DoubleClick advertising, the Google utility domain and the Esri / ArcGIS mapping service are mentioned neither by name nor as categories of data recipients.
Context
difesa.it is the official portal of Italy’s Ministry of Defence. It is built on the standard Italian government-site theme, with an interactive operations map. The capture shows 141 requests to 12 domains. The policy correctly names the ministry itself as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker — that is, it reflects what an ordinary visitor sees. And let me state the main observation straight away: this site shows two completely different levels of care within a single page. One thing here was done exemplarily. And another — exactly the opposite, and all the more noticeable against the backdrop of the first.
The analytics — done right
I will begin with praise. The web analytics on the site is its own, on the government platform, deployed on a subdomain of the ministry itself. The policy honestly describes what exactly is collected: the IP address, and masked at that — the last two bytes are zeroed, so the exact visitor cannot be worked out from it — as well as the type of browser, system and device. The capture confirms this: the analytics sets not a single cookie and assigns the visitor no persistent marker. Here the promised and the done coincide.
YouTube pulls in Google’s advertising machine
But further on comes a discrepancy. Two YouTube videos are embedded on the home page, and they are embedded in regular mode rather than privacy mode. The difference is fundamental: regular mode, the moment the page opens, itself pulls in Google’s advertising infrastructure — the DoubleClick domain, its ad-status script and Google’s utility domains — even if the visitor did not press «play». This is exactly what is visible in the capture: Google advertising is active from the fourth second. A little later YouTube also sends logging events about the viewing. The policy, meanwhile, promises that such third-party services switch on only after consent via the banner — and there is no consent in the capture at all, and the banner does nothing to hold back these clips.
The operations map takes the IP to the USA
Something easy to miss behind the more noticeable YouTube. The interactive map on the site loads its base layer — the map tiles — from the servers of the company Esri (the ArcGIS service), and this is an American supplier. This happens already at +2535 ms, at the moment the map is drawn, and with every such request the visitor’s IP address goes to the USA. The map is functional and needed by the site, but the data recipient is a foreign company, and it is not named in the policy.
The policy promises not to transfer data abroad — but does
Here everything converges to a single point, and this is the most serious part. The ministry’s policy explicitly states two things: that data is not transferred to third parties beyond those listed, and that it is not transferred to countries outside the EU. Only YouTube and social networks are listed. But in fact the visitor’s IP, in the very first seconds, goes to the USA in two streams at once — to Google (via YouTube’s advertising innards) and to Esri (via the map). Neither the advertising Google nor Esri is on the list, and the promise of «we do not transfer outside the EU» diverges from reality directly. On the site of a defence ministry, where even the mere fact of who reads it is sensitive, such a discrepancy cannot be considered a formality.
What cannot be claimed from the capture
A few honest caveats. The contents of the own analytics’ measurements go out not in the request address but in the body, which is not preserved in this lightweight export — so on the IP masking I rely on the policy text, and it is consistent with the absence of cookies and an identifier. The absence of a consent event in the capture may mean either that the banner received no press, or that it does not hold back third-party content in principle — but for the outcome this does not change the picture: the third-party domains fired independently. The capture covers the home page, the exact server IP addresses are not preserved in the export, I take the geography from the ownership of the domains and companies.
Conclusion
Within a single site — two different approaches to privacy. The ministry did the analytics exemplarily: its own, with IP masking, without cookies, exactly as written in the policy. But alongside this, the home page in the first seconds hands the visitor’s IP to Google — via YouTube videos in regular mode, dragging along the DoubleClick advertising — and to the American mapper Esri via the operations map. And all of this directly against the policy’s own promise not to transfer data either to unnecessary third parties or outside the EU, and before any consent. The main takeaway for the reader: the ministry clearly knows how to do it right — it proved this with its analytics — which means the leaking of the defence portal’s readers to Google and to the USA is not incompetence but an oversight, one that should all the more be eliminated.
a7f4340c338d5444488836f8e762e9ce1335c0fce9731e0366946d12f7105952Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website difesa.it. 2. Circumstances I visited the website difesa.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The policy explicitly states that data is transferred neither to third parties beyond those listed, nor to third countries outside the EU. In fact, when the home page opens, the visitor's IP address goes to the USA in two directions at once: to Google — via the YouTube videos embedded in regular mode, which pull in the DoubleClick advertising and Google utility domains — and to the American mapping company Esri, whose tiles are loaded by the interactive operations map. Both recipients are US companies, and the policy warns of no such transfer. For the site of a defence ministry this discrepancy is especially weighty. 2) The policy promises that non-technical and third-party services are activated only after the user's consent via the banner. In the capture the YouTube videos and the associated Google advertising and utility domains are active at +2882–5798 ms, while there is no recorded consent in the capture: the banner scripts are loaded, but the acceptance event is absent, and it does not hold back the embedded clips. 3) The videos are embedded in regular YouTube mode instead of privacy mode. It is precisely because of this that simply opening the home page — without playing any video — automatically pulls in Google's advertising infrastructure. Privacy-mode embedding would not do this. 4) YouTube and social networks are listed in the policy, but the DoubleClick advertising, the Google utility domain and the Esri / ArcGIS mapping service are mentioned neither by name nor as categories of data recipients. Full technical documentation is published at: https://gdpru.eu/en/audits/it-difesa-it/ 3. Provisions violated Art. 13(1)(f) and Chapter V GDPR — transfer to the USA against an explicit promise; The site's own policy / Art. 6(1)(a) GDPR — third-party content before consent; Art. 25 GDPR — privacy is not built into the design; Art. 13(1)(e) GDPR — some recipients are not named 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]