Technical audit · 2026-06-15

mit.gov.it

Ministry of Infrastructure and Transport of Italy

The website of Italy's Ministry of Infrastructure and Transport. 159 requests, 17 domains. The policy was opened in full and compared with the capture — and it contradicts itself: it promises that data does not leave the EU and that there is no tracking, whereas the IP and browser parameters fly off to Google's and Twitter's servers in the USA in the first seconds, before the consent banner even appears at 5.3 seconds.

Timeline of the leak

+0–650 ms · the site loads, there is no banner yet
The site's Drupal base loads. At +585 ms only the styling of the future consent banner arrives — the styles are ready, but the window itself is not yet on the screen.
+651–5273 ms · data is already going out, the banner is still not there
In the very first second the Twitter widget (+651 ms) and the YouTube video in regular mode (+657 ms) connect. The government analytics sends the first visit measurement at +831 ms. After YouTube come Google's systems: the DoubleClick advertising (+1208 ms) and a utility domain (+2686 ms). By this second the visitor's IP and browser parameters have already gone to servers outside the EU. The consent banner is not shown all this time.
+5274 ms · the banner appears; +12054 ms · the decision is recorded
Only at 5.3 seconds does the banner physically appear on the screen — before this nothing can be pressed on it. The decision is recorded at the 12th second. By this moment all the third-party systems have already fired.

Declared versus actual

YouTube (named directly, with a reference to Google's policy) — заявлен
Third-party content and social networks in general (a general reference) — заявлен
+ Web Analytics Italia government analytics (the policy names Google Analytics instead of it) — не заявлен
+ Google DoubleClick and a Google utility domain (come with regular YouTube, not named; meanwhile the policy states there is no tracking) — не заявлен
+ Transfer of data to the USA (the policy promises that data does not leave the EU) — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

mit.gov.it is the official website of Italy’s Ministry of Infrastructure and Transport. It is built on the widespread Drupal system, in the unified design of Italian government sites. In the capture taken — 159 requests to 17 different domains. I opened the policy myself, on the live site, and read it in full. An important detail: the page turned out to be clean and fully accessible — one coherent page, without a maze of nested links and without access blocking. The document is recent, the last change marked April 2026, that is, just a couple of months before the audit — the discrepancies cannot be written off as «outdated text». And so the problem here is not that the policy was hidden, but that it directly diverges from what the site actually does. It is precisely these discrepancies that are visible only on comparing the full text with the capture — and it is precisely them that we analyse point by point below.

Yes, there is a banner. But it appears not immediately, but with a large delay — and this is one of the key plots of the analysis.

  • +0.6 s — the Twitter widget already works on the page.
  • +0.7 s — the YouTube video launches in regular (not privacy) mode.
  • +0.8 s — the government analytics sends the first visit measurement.
  • +1.2 s — the Google DoubleClick advertising system connects.
  • +2.7 s — a Google utility domain connects.
  • +5.3 s — and only now does the consent banner physically appear on the screen. Before this second nothing can be pressed on it.
  • +12 s — the cookie decision is recorded. In plain words: for the first five seconds there is no banner on the screen, while five third-party connections have already taken place. For an ordinary visitor this means that data about them began going out before they were even given the opportunity to consent or refuse.

Data goes to the USA — while the policy promises it does not leave the EU

This is the most serious discrepancy. The policy has a separate, unambiguous paragraph: data is not transferred outside the European Economic Area. The capture shows the opposite. Already in the first seconds the visitor’s browser reaches out to Google’s servers (YouTube video, DoubleClick advertising, a Google utility domain) and to Twitter’s servers — and these are American companies. With every such request the visitor’s IP address and detailed browser parameters automatically go out. And here there is a subtlety that makes the discrepancy especially weighty: the policy itself, in the section on the data collected, explicitly names the IP address as personal data. It turns out the document promises not to transfer outside the EU precisely what it in fact transfers in the very first seconds.

«No profiling, no other trackers» — but there is DoubleClick and Twitter telemetry

Another paragraph of the policy asserts: no cookies for profiling are used and no other tracking methods are applied. In the capture, however, there is the Google DoubleClick advertising system — a domain whose direct task is connected with advertising profiling — and there is Twitter event telemetry, which sends data about actions on the page in separate requests. One can argue how actively they profile in this particular case, but their very presence already refutes the phrase «no other tracking methods are applied». The document’s statement and the site’s behaviour diverge.

The wrong analytics is named — and described contradictorily

The policy promises that statistics is collected by Google Analytics. It is not on the site in any form — visitors are counted by an entirely different system, government Italian analytics that the document does not mention once. This collection itself is most likely within the law: it is government-run, de-identified and under Italian rules equated to technical cookies. But in its capture it is visible that, together with the fact of the visit, a visitor identifier, screen resolution and detailed browser data go out — that is, this is not a clean anonymous count, but at least a de-identified device profile. This is worth keeping in mind, although it probably does not cross the edge of the law. It separately stands out that the document describes the analytics while contradicting itself: in one section it is said that the analytics is equated to technical cookies and consent for it is not required, and in another — that analytics cookies are set only after explicit consent. Two mutually exclusive formulations in one text — the visitor, with all the will in the world, will not understand which rule applies.

The chain: one embedded video drags along six domains

It is worth showing where such a scattering of third-party connections comes from at all. The site itself reaches out directly to only a few external addresses. But the YouTube video embedded in regular mode (rather than privacy mode, which sets no extra cookies) works as a gateway: it is precisely it that then pulls in the DoubleClick advertising, Google utility domains and the rest. That is, a significant part of the whole third-party load is a consequence of a single decision: to insert the clip in regular mode instead of privacy mode. Had the embedding mode been changed — half of these domains would simply not have appeared.

What cannot be claimed from the capture

Honest caveats, to separate facts from guesses. First, the recording of the decision at the 12th second is not proof that «the user pressed consent». The capture was taken automatically, no live person pressed the buttons. This decision could have been saved from a previous visit or triggered by default. Second, from this capture the exact cookie lifetimes are not visible — the technical headers that set them are not preserved in the export. So we speak of the fact that the systems connected, but do not undertake to name for how many days or months they settle in the browser. Third, I do not have the source code of the page’s scripts — only their calls. The conclusions about the chain of connections are drawn from who called whom in the capture, not from analysing the code itself.

Conclusion

The picture at this site is heavier than it seems at first glance, and the matter is not a hidden policy — it is in fact open and recent. The matter is that the text contradicts the behaviour in several directions at once. The document promises that data does not leave the EU — while the IP and browser parameters fly off to Google’s and Twitter’s servers in the USA in the first seconds. It promises that there is no tracking — while in the capture there is DoubleClick advertising and Twitter telemetry. It names Google Analytics, which is not there, and contradicts itself on the question of consent for analytics. And everything third-party connects before the consent banner even appears on the screen, at 5.3 seconds. The main takeaway for the reader: on this site the policy’s promises and the actual actions are two different documents.

Evidence
Original (audit)
HAR file: it/mit-gov-it-2026-06-15.har
SHA-256: a474b3c5e0e0be18dfdfb0d11a132cc6bed9ef42ea5a17bafd36792b0bee487e
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website mit.gov.it.

2. Circumstances
I visited the website mit.gov.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The policy explicitly states that personal data is not transferred outside the European Economic Area. In fact, in the first seconds of loading, the visitor's IP address and browser parameters go to Google's servers (YouTube video, DoubleClick advertising, a Google utility domain) and Twitter — US companies. This is a transfer of data outside the EU, directly against the policy text. The document itself classes the IP address as personal data.

2) The policy asserts in a separate paragraph: no profiling is conducted and no other tracking methods are applied. Yet in the capture the Google DoubleClick advertising system and Twitter event telemetry are present, which send data about the visitor. The document's statement does not match the site's behaviour.

3) The policy promises that statistics is collected by Google Analytics. It is not on the site — a different, government Italian analytics system works, not mentioned in the document once. The collection itself is probably lawful, but the visitor is given incorrect information about who measures them and with what. In addition, the document describes the analytics contradictorily: in one section — «consent is not required», in another — «only after explicit consent».

4) The policy promises that third-party content is connected only after explicit consent. In fact, the consent banner appears on the screen only at 5.3 seconds, while the YouTube video, the Twitter widget and the Google systems pulled in by them establish a connection already in the first second — long before the person was given a choice.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-mit-gov-it/

3. Provisions violated
Art. 13(1)(f) and Chapter V GDPR — transfer of data outside the EU; Internal contradiction of the policy — «no tracking» declared; Art. 13(1)(e) GDPR — incorrectly named analytics tool; Art. 6(1)(a) GDPR — third-party content before consent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]