Policy changed — see what exactly · 2026-07-11 →
The website of GSE (Gestore dei Servizi Energetici), the state operator of energy services. 123 requests, 10 domains. There is no consent banner, while two behaviour-recording systems work on the site at once — the ShinyStat session module and Siteimprove heatmaps — plus an advertising pixel. The tracking configuration, meanwhile, carries a company name from twenty years ago.
Timeline of the leak
Declared versus actual
Detected trackers
- ShinyStat (codicebusiness/ssa/optin.shinystat.com) — counter with a session-recording module (sesrec), parameter USER=grtn
- Siteimprove Analytics + heatmaps (heat.aspx)
- BRZ Network advertising pixel (advm.brznetwork.com)
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR / regulator's guidance — behaviour recording without consentThere is no consent mechanism on the site at all. Yet two tools recording the visitor's behaviour work at once: ShinyStat loads a session-recording module (sesrec.min.js), and Siteimprove builds heatmaps (three requests to heat.aspx). By the Italian regulator's position, behaviour monitoring is not a technical cookie but a separate tool for which consent is required. A basic anonymous counter could still work without asking, but session recording and heatmaps do not fall under this exception.
- Art. 13(1)(e) GDPR — the advertising pixel and trackers are not namedBesides analytics, a request to an advertising network (advm.brznetwork.com) was recorded in the capture — an advertising pixel on the site of a state operator. Neither it, nor ShinyStat, nor Siteimprove is named in the provided document. The policy refers to a separate cookie page, whose content did not make it into the export and could not be confirmed.
- Art. 5(1) GDPR — the tracking configuration is outdatedThe ShinyStat requests carry the parameter USER=grtn — an abbreviation of the company's former name (GRTN), in effect until the 2005 renaming. A sign that the tracking setup has not been revised for about twenty years.
Context
gse.it is the website of GSE S.p.A. (Gestore dei Servizi Energetici), a state company that manages incentives and services in the field of renewable energy in Italy. It is built on the Microsoft SharePoint platform. The capture shows 123 requests to ten domains. The company itself is correctly named as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. At first glance there is just a couple of counters here. But on closer inspection the set turns out to be heavier than it seems, and it works without any consent.
Who receives the data
Spotted here were: ShinyStat, Siteimprove, BRZ Network.
Was there a consent banner
There is no banner at all — no consent mechanism was found on the site. Precision is needed here: a basic anonymous visit counter under Italian rules can be equated to technical means and not require consent. So the problem is not the mere fact of counting, but the fact that alongside the counters tools of a different kind work, which do not fall under this exemption.
Two behaviour-recording systems at once
The main thing. Besides the ordinary counting, two tools recording the behaviour of a specific visitor work on the site. ShinyStat loads a session-recording module — it tracks the user’s actions on the page. And Siteimprove builds heatmaps: three separate requests to the corresponding function record where the visitor looks and where they click. This is no longer a count of «how many visits in total», but observation of behaviour, and by the Italian regulator’s position such observation requires consent. And there is no consent here at all. Conceptually this is the same thing as the session recording on government sites encountered in the series — only implemented by different vendors.
An advertising pixel on a state operator’s site
A separate finding. In the capture there is a request to an advertising network — an advertising pixel on the site of a state energy-services operator. What it does there does not follow from the capture itself, but its presence on a government site is a question in itself: advertising networks exist to gather an audience for targeting, and here there is neither a basis for this nor a mention in the document.
A twenty-year-old configuration
A characteristic detail. The ShinyStat measurements carry a parameter with the abbreviation of the company’s former name, which it bore until the 2005 renaming. This indicates that the tracking setup has not been revised for about twenty years — it simply works by inertia with long-established parameters.
What cannot be claimed from the capture
A few honest caveats. The policy refers to a separate cookie page, and I was unable to obtain this page, so I cannot confirm whether ShinyStat and Siteimprove are named on it — this concerns the incompleteness of what is available, not proven concealment. Both analytics vendors are European and claim anonymisation, so the basic counter may well be disclosed there as technical; but session recording, heatmaps and the advertising pixel are a different matter. The exact time of the request to the advertising network I did not separately record; I note the fact itself. The capture covers the home page.
Conclusion
The state energy-services operator keeps two behaviour-observation systems on its site at once — session recording and heatmaps — as well as an advertising pixel, and all of this works without any consent banner, on a tracking configuration not updated for about twenty years. The basic visit counting could itself be lawful even without asking, but behaviour observation and an advertising network do not fall under this exemption. The main takeaway for the reader: even where there is «just a couple of counters», it is worth looking closer — here behind that couple hide behaviour recording and advertising, which the visitor is not asked about and not warned of in the available document.
acf29faf80b8f0be7666ca81ea1b7f51d6d37a9dbff763922891bfa6a2472ca6Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website gse.it. 2. Circumstances I visited the website gse.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) There is no consent mechanism on the site at all. Yet two tools recording the visitor's behaviour work at once: ShinyStat loads a session-recording module (sesrec.min.js), and Siteimprove builds heatmaps (three requests to heat.aspx). By the Italian regulator's position, behaviour monitoring is not a technical cookie but a separate tool for which consent is required. A basic anonymous counter could still work without asking, but session recording and heatmaps do not fall under this exception. 2) Besides analytics, a request to an advertising network (advm.brznetwork.com) was recorded in the capture — an advertising pixel on the site of a state operator. Neither it, nor ShinyStat, nor Siteimprove is named in the provided document. The policy refers to a separate cookie page, whose content did not make it into the export and could not be confirmed. 3) The ShinyStat requests carry the parameter USER=grtn — an abbreviation of the company's former name (GRTN), in effect until the 2005 renaming. A sign that the tracking setup has not been revised for about twenty years. Full technical documentation is published at: https://gdpru.eu/en/audits/it-gse-it/ 3. Provisions violated Art. 6(1)(a) GDPR / regulator's guidance — behaviour recording without consent; Art. 13(1)(e) GDPR — the advertising pixel and trackers are not named; Art. 5(1) GDPR — the tracking configuration is outdated 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]