Technical audit · 2026-06-15

italia.it

Official National Tourism Portal of Italy

The official national tourism portal of Italy (Ministry of Tourism). 199 requests, 26 domains. Despite the OneTrust consent system with auto-blocking, Adobe data collection, the Google measurement and Hotjar session recording fire before the banner even appears. And the policy, meanwhile, categorically promises not to transfer data abroad — whereas Adobe and Google are located in the USA.

Timeline of the leak

+674–740 ms · stack and auto-blocking
The portal's own modules (search, login integration), Google's tag system, Adobe's tag system and the OneTrust consent system with auto-blocking enabled load.
+1360–1749 ms · embedded audio guide
The bulky embedded Loquis audio guide loads — dozens of files, including mapping and player components.
+1944 ms · Hotjar before the banner
The Hotjar session-recording and heatmap system loads — even before the consent banner appears.
+2157–2331 ms · Adobe and Google collection before the banner
Real Adobe Experience Cloud data collection (edge.adobedc.net/interact) and the Google measurement go out. The request at +2181 ms to OneTrust is merely region geolocation, not consent.
+2432 ms · the banner is rendered last
Only now does the visual part of the OneTrust banner load — when Adobe, Google and Hotjar have already fired. Not a single Set-Cookie throughout the entire session.

Declared versus actual

+ Adobe Experience Cloud — не заявлен
+ Google (Maps, YouTube, Tag Manager) — не заявлен
+ Hotjar — не заявлен
+ Gigya / SAP — не заявлен
+ Loquis — не заявлен
+ Algolia — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.italia.it is the official national tourism portal of Italy, for which the Ministry of Tourism is responsible. Through it the country presents itself to travellers from all over the world. The capture shows 199 requests to 26 domains — this is a saturated site with search, maps, an embedded audio guide, login and analytics. The OneTrust consent system with an auto-blocking function is installed on the site. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker.

The case is telling in that the consent mechanism here is not merely present but declared in an enhanced variant — with auto-blocking — and it is all the more noticeable that it does not fire as it should.

Who receives the data

Spotted here were: Adobe, Google, Hotjar, Gigya, Loquis, Algolia.

There is a banner, and it is OneTrust with auto-blocking enabled — a mode that should physically hold back third-party tags until consent. But in the capture it does not cope. The visible part of the banner is rendered as one of the last, by +2432 ms, while the request easily mistaken for consent is merely region geolocation. There is no recorded user decision in the capture. And, most importantly, by the moment the banner appears the key trackers have already fired.

Here is the essence. Despite the declared auto-blocking, before the banner appears three serious services manage to fire. Adobe Experience Cloud sends real collection of data about the visit. Google takes its measurement. And the Hotjar system, conducting session recording and heatmaps, loads even earlier than the rest. The policy itself classes profiling as processing requiring consent — but these services do not wait for consent. That is, the enhanced consent mechanism is present here on paper and in the code, but in fact does not perform its task.

«We do not transfer abroad» — against Adobe and Google in the USA

A separate and more severe finding. The policy contains a categorical statement: the controller does not transfer personal data to third countries or international organisations. Meanwhile among the recipients are Adobe and Google, American companies. Every request to their services transmits the visitor’s data outside the EU. This is a direct contradiction between the document’s explicit promise and the national portal’s actual behaviour.

The main policy names the processing purposes, including profiling, but does not list specific recipients, referring to a separate cookie policy published on the site. This separate part did not make it into the export, so whether Adobe, Google and Hotjar are named there I cannot confirm — I record that they are not in the main document.

What cannot be claimed from the capture

A few honest caveats. The Adobe request is a real data-collection call; on Hotjar session recording I judge from the loading of its system. OneTrust’s auto-blocking is present, but in this session the listed services did not wait for it. I did not export the separate cookie policy. Hotjar is hosted in the EU, so the transfer-abroad complaint does not apply to it — it concerns Adobe and Google. The capture covers the home page.

Conclusion

The country’s official tourism portal carries a heavy stack — Adobe, Google, Hotjar with session recording, identification, an audio guide, search — and the key trackers fire before the consent banner appears, even though enhanced auto-blocking, which should have held them back, is enabled on the site. And the policy, meanwhile, explicitly promises not to transfer data abroad — whereas Adobe and Google are located in the USA. The main takeaway for the reader: even an enhanced consent mechanism is only a promise until it is tested in practice; here auto-blocking is in place, and Adobe, Google and session recording fire before the asking anyway, and the categorical «data does not leave the EU» does not withstand comparison.

Evidence
Original (audit)
HAR file: it/italia-it-2026-06-15.har
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website italia.it.

2. Circumstances
I visited the website italia.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The OneTrust consent system with an auto-blocking function is installed on the site. But the banner is rendered as one of the last (+2432 ms), and before it the following already fire: Adobe Experience Cloud data collection (edge.adobedc.net/interact, +2166 ms), the Google measurement (+2331 ms) and the loading of the Hotjar session-recording system (+1944 ms). The request at +2181 ms is region geolocation, not consent; there is no recorded «accepted/declined» decision in the capture. Meanwhile the policy itself classes profiling as processing based on consent. That is, auto-blocking is present, but Adobe, Google and Hotjar do not wait for it.

2) The policy categorically states that the controller does not transfer personal data to third countries or international organisations. Yet among the recipients are Adobe and Google, American companies, and the requests to their services transmit the visitor's data outside the EU. Promise and fact diverge directly.

3) The main policy names the processing purposes, but does not list specific recipients — Adobe, Google, Hotjar, Gigya, Loquis — moving the details to a separate cookie policy not included in the export.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-italia-it/

3. Provisions violated
Art. 6(1)(a) GDPR — trackers before consent, despite auto-blocking; Art. 44 GDPR — «we do not transfer abroad» against Adobe and Google in the USA; Art. 13(1)(e) GDPR — recipients not named in the main document

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]