Technical audit · 2026-06-15

ingenio-web.it

Engineering and Construction Technical Portal

The website of Ingenio-web.it — an Italian engineering-and-construction technical portal (publisher IMREADY Srl). 64 requests, 12 domains. The stack is almost entirely from Google, but implemented mostly correctly: consent is declined by default, the analytics goes without cookies, the advertising is in non-personalised mode. The only catch is that the recipients are not named in the main document.

Timeline of the leak

+548–656 ms · search and tag system
Google's embedded search and the tag-management system load.
+1132–1528 ms · consent banner
The Klaro consent-management system (from the company KIProtect) loads.
+1694–2078 ms · advertising in non-personalised mode
First Google's ad-traffic-quality check fires (anti-fraud for advertising), then the AdSense advertising request goes out. Since consent is in the «declined» state, the advertising is served in non-personalised form.
+6232 ms · analytics without cookies
Google Analytics sends a measurement with the consent flag in the «declined» position (gcs=G100) — that is, in anonymised mode, without saving identifiers. Not a single Set-Cookie throughout the entire session.

Declared versus actual

+ Google AdSense — не заявлен
+ Google Analytics 4 — не заявлен
+ Google Tag Manager / Custom Search — не заявлен
+ Klaro / KIProtect — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.ingenio-web.it is an Italian engineering-and-construction technical portal, published by the company IMREADY Srl. The capture shows 64 requests to 12 domains, and almost all the external ones are Google services. The publisher is correctly named as the data controller, and the Klaro consent-management system is installed on the site. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. The case is interesting in that, against the backdrop of the commercial sites in the series, it stands out favourably in its consent mechanics — and the analysis is mainly about what is done right.

Who receives the data

Spotted here were: Google, KIProtect.

There is a banner — the Klaro system. And, unlike most commercial sites in the series, it works to the point: the consent-state flag is by default in the «declined» position. This means that before the user’s explicit consent, data collection is limited — which is confirmed further on.

Done mostly right

This is the main observation and a plus for the site. Google’s analytics sends a measurement with the flag «consent declined» — that is, in anonymised mode, without saving identifiers and cookies. The AdSense advertising, although it loads, is served in non-personalised form under declined consent — that is, selected by the page content rather than by the visitor’s profile. Throughout the whole session not a single cookie was set. In other words, before consent the site behaves restrainedly: no identifying analytics, no personalised advertising. This is the direct opposite of those commercial sites in the series where trackers merged the visitor’s identifiers from the first second.

The recipients are not named in the main document

The only real catch is about the document. The main policy names the publisher as the controller, mentions profiling among the possible purposes and stipulates that data may be transferred abroad — but all of this in general formulations. Specific services are not named: neither Google’s advertising system and analytics, nor the embedded search, nor the consent tool itself. Most likely the detailed list is moved to a separate part of the cookie policy, which is not in the export, so I record this as incompleteness of what is available rather than proven concealment.

What cannot be claimed from the capture

A few honest caveats. On the non-personalised advertising mode I judge from the declined consent flag and the absence of cookies; the content of the advertising response itself is not visible in the capture. There is no recorded click on the banner — the «declined» state is the default value, and it did not change in this session. I did not export the separate cookie documentation. The capture covers the home page.

Conclusion

The stack here is almost entirely from Google — advertising, analytics, search, tags — but it is assembled mostly correctly. Before consent the flag is in the «declined» position: the analytics goes without cookies and without identifiers, the advertising is in non-personalised mode, not a single cookie is set. This is noticeably closer to a correct implementation than most commercial sites in the series. The only unclosed point is documentary: the main policy names neither Google nor the consent tool, limiting itself to general words about profiling and transfer abroad. The main takeaway for the reader: even on a site where almost everything external belongs to Google, one can behave restrainedly before consent — and here this is mostly done; the questions remain about the completeness of the document, not the behaviour.

Evidence
Original (audit)
HAR file: it/ingenio-web-it-2026-06-15.har
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website ingenio-web.it.

2. Circumstances
I visited the website ingenio-web.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The consent mechanics here are implemented mostly correctly (see below), and the main complaint is about disclosure. The main policy names the controller and mentions profiling and possible transfer abroad in general terms, but does not name specific services — neither Google's advertising system, nor the analytics, nor the consent tool itself. The cookie details are apparently moved to a separate part that did not make it into the export, so this is a limitation of the check, not proven concealment.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-ingenio-web-it/

3. Provisions violated
Art. 13(1)(e) GDPR — recipients not named in the main document

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]