The Diritto.it legal information portal (the Maggioli publishing group). 169 requests, 13 domains. There is no consent banner on the site at all, while from the first second a full-fledged SalesManago marketing-automation platform launches with a persistent visitor identifier and web push, plus the ShareThis data broker and several more trackers. The available policy, meanwhile, is written for the pre-GDPR code.
Timeline of the leak
Declared versus actual
Detected trackers
- SalesManago — marketing-automation platform, persistent visitor uuid, web push
- ShareThis — sharing widget and data broker
- Parse.ly — content analytics
- WordPress Stats / Jetpack (Automattic)
- Cloudflare Insights
- Google Tag Manager + Firebase (web push)
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — tracking from the first second without consentThere is no consent mechanism on the site at all — not a single known banner, nor an in-house implementation. Yet immediately on page load a full-fledged SalesManago marketing-automation platform launches: the tracking pixel carries a persistent visitor identifier (uuid), and alongside it the modules for visit history, traffic-source detection, web-push notifications and personalisation work. In parallel, in the very first milliseconds, ShareThis, Parse.ly, WordPress Stats, Cloudflare Insights and Google Tag Manager load. A characteristic detail: SalesManago's own consent form loads at +1465 ms — after the tracking pixel with the identifier has already been sent (+1079 ms).
- Art. 13 GDPR — a policy from the pre-GDPR eraThe available document is written for the old national data code (196/2003) and contains not a single mention of the regulation in force (679/2016). Formally the policy is not updated to the current legislation.
- Art. 13(1)(e) GDPR — recipients not namedThe cookies are described only in general terms — «necessary» and «targeting/advertising» — and it is acknowledged that data is transferred to advertisers. But not a single actual tool (SalesManago, ShareThis, Parse.ly, WordPress Stats, Cloudflare, Google) is named in the document.
Context
www.diritto.it is an Italian legal information portal, owned by the Maggioli publishing group. People come here to read about legal matters — and this is a topic on which a visitor’s interests are revealed quite a lot. The capture shows 169 requests to 13 domains. The publisher itself is correctly named as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. The case is systemic: the problem is not a single miscalculation, but the combination of three at once — no consent, no up-to-date policy, and a serious tracking machine working on top of that.
Who receives the data
Spotted here were: SalesManago, ShareThis, Parse.ly, Automattic, Cloudflare, Google.
Was there a consent banner
There is no banner at all. The site lacks any consent mechanism — none of the common systems, nor an in-house implementation. The only thing that remotely resembles consent is the built-in form of the SalesManago platform itself, but even it loads late, after the tracking has already fired and the visitor identifier has been sent. That is, consent here is absent at the site level and lags even within the marketing tool itself.
A full-fledged tracking platform from the first second
The main thing to understand about this site: SalesManago is not a subscription form but a deployed marketing-automation platform. It conducts event tracking, stores visit history, detects the traffic source, can send web-push notifications and personalise content. And crucially — its pixel carries a persistent visitor identifier, by which a person can be recognised between visits. All of this launches immediately on entry, without any consent. Alongside, from the very first milliseconds, several more third-party services work, and among them ShareThis — a «share» buttons widget which by its business model also collects data about visitors for the advertising market. In sum this is a serious volume of tracking, switching on before the user manages to understand anything.
A policy from the pre-GDPR era
The available document is notable for its age. It is written for the old national personal-data code and contains not a single mention of the European regulation in force that took effect in 2018. That is, over the intervening years the policy has formally not been brought into line with the current law. Substantively it describes only generic categories — «necessary» and «advertising» cookies — and honestly acknowledges that data is transferred to advertisers, but names not a single specific recipient of those that actually work on the site.
What cannot be claimed from the capture
A few honest caveats. It is possible the site also has a more recent version of the policy; what is available for comparison is a document of the pre-GDPR era. ShareThis’s role as a data collector is its known business model, not a conclusion from the capture itself; in the capture I see only the fact of its widget loading. The visitor identifier is visible right in the tracking pixel’s parameters. The capture covers the home page.
Conclusion
This is a systemic case where three problems coincided at once. The site has no consent mechanism as such. There is no policy in force, brought into line with the current law, either — only a document many years old is available, naming not a single actual tool. And against this backdrop, from the very first second, a full-fledged behavioural-tracking platform with a persistent visitor identifier and web push works, plus a data broker and several more trackers. The main takeaway for the reader: on a portal where people come to sort out their legal problems, they are recognised and tracked from the doorstep — silently, without asking, and without an up-to-date document that would at least explain who is behind it.
546a8142ad5c99148dcd9c11f2855eb5a25b8e55909ac2c25f9a07c2c2dd6e1aWhere to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website diritto.it. 2. Circumstances I visited the website diritto.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) There is no consent mechanism on the site at all — not a single known banner, nor an in-house implementation. Yet immediately on page load a full-fledged SalesManago marketing-automation platform launches: the tracking pixel carries a persistent visitor identifier (uuid), and alongside it the modules for visit history, traffic-source detection, web-push notifications and personalisation work. In parallel, in the very first milliseconds, ShareThis, Parse.ly, WordPress Stats, Cloudflare Insights and Google Tag Manager load. A characteristic detail: SalesManago's own consent form loads at +1465 ms — after the tracking pixel with the identifier has already been sent (+1079 ms). 2) The available document is written for the old national data code (196/2003) and contains not a single mention of the regulation in force (679/2016). Formally the policy is not updated to the current legislation. 3) The cookies are described only in general terms — «necessary» and «targeting/advertising» — and it is acknowledged that data is transferred to advertisers. But not a single actual tool (SalesManago, ShareThis, Parse.ly, WordPress Stats, Cloudflare, Google) is named in the document. Full technical documentation is published at: https://gdpru.eu/en/audits/it-diritto-it/ 3. Provisions violated Art. 6(1)(a) GDPR — tracking from the first second without consent; Art. 13 GDPR — a policy from the pre-GDPR era; Art. 13(1)(e) GDPR — recipients not named 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]