Technical audit · 2026-06-15

diritto.it

Legal Information Portal

The Diritto.it legal information portal (the Maggioli publishing group). 169 requests, 13 domains. There is no consent banner on the site at all, while from the first second a full-fledged SalesManago marketing-automation platform launches with a persistent visitor identifier and web push, plus the ShareThis data broker and several more trackers. The available policy, meanwhile, is written for the pre-GDPR code.

Timeline of the leak

+112–153 ms · a wave of trackers from the first milliseconds
In the first hundred and fifty milliseconds the following connect all at once: the ShareThis sharing widget (+125 ms), the SalesManago form (+125 ms), the Parse.ly content analytics (+132 ms), WordPress Stats (+133 ms), Cloudflare Insights (+133 ms) and Google Tag Manager (+149 ms). There is no consent banner on the page.
not applicable — there is no consent mechanism
The site has no banner or consent system whatsoever. The only similar thing is SalesManago's own consent form, but it loads late (+1465–1773 ms), after the tracking has already fired.
+392–1079 ms · the full SalesManago platform and a pixel with an identifier
The SalesManago core and dozens of modules load: event tracking, visit history, traffic sources, engagement, web push, Firebase. At +1079 ms the tracking pixel goes out, carrying a persistent visitor identifier (uuid). Not a single Set-Cookie throughout the entire session — the identifier is passed right in the pixel's parameters.

Declared versus actual

+ SalesManago — не заявлен
+ ShareThis — не заявлен
+ Parse.ly — не заявлен
+ WordPress Stats / Jetpack — не заявлен
+ Cloudflare Insights — не заявлен
+ Google Tag Manager — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.diritto.it is an Italian legal information portal, owned by the Maggioli publishing group. People come here to read about legal matters — and this is a topic on which a visitor’s interests are revealed quite a lot. The capture shows 169 requests to 13 domains. The publisher itself is correctly named as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. The case is systemic: the problem is not a single miscalculation, but the combination of three at once — no consent, no up-to-date policy, and a serious tracking machine working on top of that.

Who receives the data

Spotted here were: SalesManago, ShareThis, Parse.ly, Automattic, Cloudflare, Google.

There is no banner at all. The site lacks any consent mechanism — none of the common systems, nor an in-house implementation. The only thing that remotely resembles consent is the built-in form of the SalesManago platform itself, but even it loads late, after the tracking has already fired and the visitor identifier has been sent. That is, consent here is absent at the site level and lags even within the marketing tool itself.

A full-fledged tracking platform from the first second

The main thing to understand about this site: SalesManago is not a subscription form but a deployed marketing-automation platform. It conducts event tracking, stores visit history, detects the traffic source, can send web-push notifications and personalise content. And crucially — its pixel carries a persistent visitor identifier, by which a person can be recognised between visits. All of this launches immediately on entry, without any consent. Alongside, from the very first milliseconds, several more third-party services work, and among them ShareThis — a «share» buttons widget which by its business model also collects data about visitors for the advertising market. In sum this is a serious volume of tracking, switching on before the user manages to understand anything.

A policy from the pre-GDPR era

The available document is notable for its age. It is written for the old national personal-data code and contains not a single mention of the European regulation in force that took effect in 2018. That is, over the intervening years the policy has formally not been brought into line with the current law. Substantively it describes only generic categories — «necessary» and «advertising» cookies — and honestly acknowledges that data is transferred to advertisers, but names not a single specific recipient of those that actually work on the site.

What cannot be claimed from the capture

A few honest caveats. It is possible the site also has a more recent version of the policy; what is available for comparison is a document of the pre-GDPR era. ShareThis’s role as a data collector is its known business model, not a conclusion from the capture itself; in the capture I see only the fact of its widget loading. The visitor identifier is visible right in the tracking pixel’s parameters. The capture covers the home page.

Conclusion

This is a systemic case where three problems coincided at once. The site has no consent mechanism as such. There is no policy in force, brought into line with the current law, either — only a document many years old is available, naming not a single actual tool. And against this backdrop, from the very first second, a full-fledged behavioural-tracking platform with a persistent visitor identifier and web push works, plus a data broker and several more trackers. The main takeaway for the reader: on a portal where people come to sort out their legal problems, they are recognised and tracked from the doorstep — silently, without asking, and without an up-to-date document that would at least explain who is behind it.

Evidence
Original (audit)
HAR file: it/www-diritto-it-2026-06-15.har
SHA-256: 546a8142ad5c99148dcd9c11f2855eb5a25b8e55909ac2c25f9a07c2c2dd6e1a
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website diritto.it.

2. Circumstances
I visited the website diritto.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) There is no consent mechanism on the site at all — not a single known banner, nor an in-house implementation. Yet immediately on page load a full-fledged SalesManago marketing-automation platform launches: the tracking pixel carries a persistent visitor identifier (uuid), and alongside it the modules for visit history, traffic-source detection, web-push notifications and personalisation work. In parallel, in the very first milliseconds, ShareThis, Parse.ly, WordPress Stats, Cloudflare Insights and Google Tag Manager load. A characteristic detail: SalesManago's own consent form loads at +1465 ms — after the tracking pixel with the identifier has already been sent (+1079 ms).

2) The available document is written for the old national data code (196/2003) and contains not a single mention of the regulation in force (679/2016). Formally the policy is not updated to the current legislation.

3) The cookies are described only in general terms — «necessary» and «targeting/advertising» — and it is acknowledged that data is transferred to advertisers. But not a single actual tool (SalesManago, ShareThis, Parse.ly, WordPress Stats, Cloudflare, Google) is named in the document.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-diritto-it/

3. Provisions violated
Art. 6(1)(a) GDPR — tracking from the first second without consent; Art. 13 GDPR — a policy from the pre-GDPR era; Art. 13(1)(e) GDPR — recipients not named

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]