Technical audit · 2026-06-15

garanteprivacy.it

Data Protection Authority of Italy

The website of Italy's data-protection regulator itself. 110 requests, 3 domains. The own analytics is implemented exemplarily — on its own domain, without a tracking identifier, with IP masking exactly as described in the policy. The only catch is the ReadSpeaker text-to-speech service: it is European, sets no cookies, but as a third-party recipient of the IP it is not mentioned in the policy — even though it is precisely this body that obliges everyone else to list such services.

Timeline of the leak

+0–547 ms · portal load
The portal runs on the Liferay platform, the fonts self-hosted. The standard set of site styles and scripts.
+552–650 ms · analytics, ReadSpeaker and the cookie bar
The Matomo analytics from its own domain (+552 ms) and the ReadSpeaker text-to-speech service (+601 ms) load before the cookie-bar scripts (+649–650 ms). For Matomo this is not a problem: pseudonymised analytics requires no consent. For ReadSpeaker the question is not the timing, but the fact that it is not in the policy.
+972 ms · Matomo measurement
The Matomo visit measurement (+972 ms) — with a masked IP and without a persistent identifier. Not a single cookie throughout the entire session — neither from the analytics nor from ReadSpeaker.

Declared versus actual

Matomo on gpdp.it (Garante's own domain, listed in the policy, IP masked by 2 bytes) — заявлен
+ ReadSpeaker (cdn-eu.readspeaker.com) — European text-to-speech service, receives the IP, absent from the list of data recipients — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

garanteprivacy.it is the official website of the Garante per la protezione dei dati personali, that is, of Italy’s data-protection supervisory authority itself. The very one that writes the third-party-declaration rules for all the country’s other sites. It is built on the Liferay platform. The capture shows 110 requests to three domains. The policy correctly names Garante itself as the controller and lists a dozen and a half domains belonging to it, including gpdp.it. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. Since this is a regulator’s site, there is a special interest in it: does the author of the rules observe its own requirements? For the most part — yes, and quite carefully. But one detail stands out.

The analytics — exemplary

First about what is done right. The web analytics here is on Garante’s own domain, not on a third-party service. The capture shows the same as the policy: the IP address is masked by zeroing the last two bytes — exactly as written in the document — no persistent identifier is assigned to the visitor, and not a single cookie is set during the session. This is tidy, private-by-design analytics, and the promised fully coincides with the fact. In this area the regulator practises exactly what it preaches.

ReadSpeaker — the only undeclared party

And now the catch. The ReadSpeaker service works on the site — a tool that reads the page text aloud, needed above all by people with visual impairments. It loads at the start of the visit, and with it the visitor’s IP address goes to this service’s servers. Here it is important to keep proportion and not blow up the finding. First, ReadSpeaker is a European service, its address directly points to European infrastructure, so there is no leak of data outside the EU here. Second, it is not an advertising or behavioural tracker but an auxiliary accessibility tool — a rather commendable thing. Third, it sets no cookies in this session, so the policy’s literal statement «no third-party cookies are set» formally remains correct. The problem is narrow but real: the policy provides a closed list of six specific data recipients, and ReadSpeaker is not among them — nor is it mentioned anywhere in the text. Yet it is a third-party recipient of the visitor’s IP address. That is, the declaration is incomplete.

The irony — and why it is nonetheless worth noting

The omission itself is small and fixed with a single line in the document. But the place of the finding gives it weight: it is precisely Garante whose guidance obliges every Italian site to list all third-party services receiving users’ data. And on its own site one such service is absent from the list. In essence this is not hypocrisy — ReadSpeaker’s function is benign, there is no leak — but rather an oversight. But a symbolic oversight: the author of the rule fell one position short of fulfilling it itself.

What cannot be claimed from the capture

A few honest caveats. The contents of the analytics measurement go out not in the request address, so on the IP masking I rely on the policy — and it is consistent with there being no cookie and no persistent identifier in the capture. ReadSpeaker’s belonging to European infrastructure I determine from its domain; the exact server location is not recorded in the lightweight export. The capture covers the home page.

Conclusion

The regulator’s site for the most part shows exactly what the regulator requires of others: its own analytics on its own domain, without a tracking identifier, with IP masking down to the byte, as recorded in the policy. The only blemish is the ReadSpeaker text-to-speech service, which receives the visitor’s IP but does not appear in the list of data recipients. It is European, harmless in function and sets no cookies, so this is about the incompleteness of the declaration, not a leak. The main takeaway for the reader: even a fundamentally exemplary site — and even the data-protection authority itself — has an unclosed trifle; and it is all the more valuable that here it is indeed a trifle, not hidden tracking, as on other analysed sites.

Evidence
Original (audit)
HAR file: it/garanteprivacy-it-2026-06-15.har
SHA-256: 455c1b44c2b8552792cc047270477f0152665cff3fee2139fa455d276d668807
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website garanteprivacy.it.

2. Circumstances
I visited the website garanteprivacy.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The policy categorically states that no third-party cookies are set and provides a closed list of six specific data recipients designated by Garante. Among them there is no ReadSpeaker service (reading text aloud), which loads on every visit and receives the visitor's IP address. Formally the statement about cookies is correct — ReadSpeaker does not set them — but as a third-party data recipient it is not named in the document at all. The service is European and its function is auxiliary, so this is a question of the completeness of the declaration, not a data leak.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-garanteprivacy-it/

3. Provisions violated
Art. 13(1)(e) GDPR — a third-party service is not listed among the recipients

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]