Technical audit · 2026-06-15

quirinale.it

Website of the President of the Italian Republic

Quirinale.it is the official website of the President of the Italian Republic, the highest constitutional body. Home-page capture: 65 requests, 7 domains. By the series' standards the set is restrained: no Google Analytics, no advertising, no advertising domains, no YouTube. But on page load, without consent, social widgets fire: the Twitter/X widget exchanges data about the visit with Twitter's servers, and the Instagram embedding script reaches out to Meta. There is a consent banner on the site, but these services fire before it, and they are not named in the policy and no consent is provided for them. Additionally, the private Cloudflare Insights analytics works — which is in fact named in the policy. The main problem: on the head of state's site, data about the visit goes to Twitter and Meta before consent.

Timeline of the leak

140 ms · Google Fonts
Fonts load from the Google domain. A static resource, but the visitor's IP goes to Google.
145 ms · Twitter/X widget
The Twitter/X widget script loads. A third-party social-network service connects on first contact, before consent.
146 ms · Instagram embedding
The Instagram embedding script loads, reaching out to Meta. That is, Meta receives a request about the visit before consent.
148 ms · consent banner
The consent banner loads. A consent mechanism is provided on the site — which means that what fired earlier happened before consent.
149 ms · Cloudflare Insights analytics
The third-party Cloudflare Insights analytics connects. It is private, without cookies, and named in the policy — the least problematic part.
457 ms · data exchange with Twitter
The Twitter widget reaches out to syndication.twitter.com and exchanges data about the visit. That is, the widget is not merely rendered — it transmitted data to Twitter, still without consent.
there is a banner, consent not given
The consent banner is present on the site, no decision was made in this visit, no cookie was set during the session. All the social-widget requests happened before consent.

Declared versus actual

Cloudflare — заявлен
+ Twitter / X — не заявлен
+ Instagram — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.quirinale.it is the official website of the President of the Italian Republic (the Quirinale). The data controller is the Presidenza della Repubblica. This is the highest constitutional body; the site is informational: about the President’s activity, institutional events, documents, access to the Library. Capture: 65 requests to 7 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. There is a consent banner on the site. There is no heavy advertising-and-analytics layer, but social widgets and third-party analytics are present.

Who receives the data

Spotted here were: Twitter / X, Meta / Instagram. Twitter receives data via its widget: it reaches out to Twitter’s servers and exchanges data about the visit. Meta — via the Instagram embedding script, which reaches out to its servers on page load. Both services are hosted in the USA. Additionally, the Cloudflare Insights analytics works — it is private (without cookies) and named in the policy, so the least problematic. The fonts are loaded from Google Fonts.

Yes, there is a consent banner on the site. No «accept/decline» decision was made in this visit, and not a single cookie was set during the session — that is, consent is not given. And it is precisely against this backdrop that the discrepancy is visible: the social widgets fire before consent, while in the policy they are not mentioned at all. The word «consent» does not occur in the policy text, that is, no consent mechanism is provided for the social services.

On page load, without any user choice, the following fire:

  • the Twitter/X widget — with an exchange of data about the visit with Twitter’s servers;
  • the Instagram embedding — with a request to Meta;
  • the third-party Cloudflare Insights analytics (private, without cookies — the least problematic);
  • the loading of Google Fonts. The key ones are the two social widgets. Under established practice, a social plugin that transmits data about the visit to a social network on page load requires prior consent; here it is not requested.

The discrepancy of the documents with reality

A separate mismatch — a mirror one. The policy names as third-party services Cloudflare, as well as YouTube and Vimeo. But YouTube and Vimeo did not fire on the home page. What actually works is the Twitter/X widget and the Instagram embedding — and neither of them is named in the policy. That is, the document names services that are not here, and stays silent about those that actually transmit data about the visit to Twitter and Meta.

Conclusion

Quirinale.it is a restrained case compared with other government sites in the series: there is no advertising, no advertising domains and no Google Analytics here, and the only analytics is private and named. But on the head of state’s site the Twitter and Instagram social widgets transmit data about the visit to Twitter and Meta on page load — without consent and without a mention in the policy, while there is a consent banner on the site. The main takeaway for the reader: even on the President’s site the social widgets turn out to be switched on by default and hand information about the visit to foreign social networks before consent, and the policy names some services while others work. It would be enough to make the social widgets click-to-load and bring the policy into line with the actual recipients.

Evidence
Original (audit)
HAR file: it/quirinale-it-2026-06-15.har
SHA-256: d5f374ff0a02e832ed66a66fd7e603c3b8cb8482f9bd8ecb810d28abcf218e60
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website quirinale.it.

2. Circumstances
I visited the website quirinale.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site has a consent banner, but in a clean session, on page load and without any user decision, third-party social services fire. The Twitter/X widget loads and reaches out to Twitter's servers, exchanging data about the visit. The Instagram embedding script reaches out to Meta. Both are third-party recipients in the USA, and both fire before consent. Additionally, the third-party Cloudflare Insights analytics works (it is private, without cookies, and named in the policy). Meanwhile the social widgets themselves are not mentioned in the policy, and no consent mechanism is provided for them — the word «consent» does not occur in the document at all. That is, on the head of state's site data about the visit goes to Twitter and Meta before any consent.

2) The policy names as third-party services Cloudflare (access optimisation), as well as YouTube and Vimeo (video). However, neither YouTube nor Vimeo fired on the home page. What actually fires is the Twitter/X widget and the Instagram embedding — and neither of them is named in the policy. What results is a mirror discrepancy: the services that did not fire here are named, and those that actually transmit data about the visit to Twitter and Meta are not named.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-quirinale-it/

3. Provisions violated
Art. 6(1)(a) GDPR — social widgets transmit data about the visit before consent; Art. 13 GDPR — the actual social recipients are not named in the policy

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]