Quirinale.it is the official website of the President of the Italian Republic, the highest constitutional body. Home-page capture: 65 requests, 7 domains. By the series' standards the set is restrained: no Google Analytics, no advertising, no advertising domains, no YouTube. But on page load, without consent, social widgets fire: the Twitter/X widget exchanges data about the visit with Twitter's servers, and the Instagram embedding script reaches out to Meta. There is a consent banner on the site, but these services fire before it, and they are not named in the policy and no consent is provided for them. Additionally, the private Cloudflare Insights analytics works — which is in fact named in the policy. The main problem: on the head of state's site, data about the visit goes to Twitter and Meta before consent.
Timeline of the leak
Declared versus actual
Detected trackers
- Twitter / X (widget)
- Instagram (Meta)
- Cloudflare Insights
- Google Fonts
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — social widgets transmit data about the visit before consentThe site has a consent banner, but in a clean session, on page load and without any user decision, third-party social services fire. The Twitter/X widget loads and reaches out to Twitter's servers, exchanging data about the visit. The Instagram embedding script reaches out to Meta. Both are third-party recipients in the USA, and both fire before consent. Additionally, the third-party Cloudflare Insights analytics works (it is private, without cookies, and named in the policy). Meanwhile the social widgets themselves are not mentioned in the policy, and no consent mechanism is provided for them — the word «consent» does not occur in the document at all. That is, on the head of state's site data about the visit goes to Twitter and Meta before any consent.
- Art. 13 GDPR — the actual social recipients are not named in the policyThe policy names as third-party services Cloudflare (access optimisation), as well as YouTube and Vimeo (video). However, neither YouTube nor Vimeo fired on the home page. What actually fires is the Twitter/X widget and the Instagram embedding — and neither of them is named in the policy. What results is a mirror discrepancy: the services that did not fire here are named, and those that actually transmit data about the visit to Twitter and Meta are not named.
Context
www.quirinale.it is the official website of the President of the Italian Republic (the Quirinale). The data controller is the Presidenza della Repubblica. This is the highest constitutional body; the site is informational: about the President’s activity, institutional events, documents, access to the Library. Capture: 65 requests to 7 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. There is a consent banner on the site. There is no heavy advertising-and-analytics layer, but social widgets and third-party analytics are present.
Who receives the data
Spotted here were: Twitter / X, Meta / Instagram. Twitter receives data via its widget: it reaches out to Twitter’s servers and exchanges data about the visit. Meta — via the Instagram embedding script, which reaches out to its servers on page load. Both services are hosted in the USA. Additionally, the Cloudflare Insights analytics works — it is private (without cookies) and named in the policy, so the least problematic. The fonts are loaded from Google Fonts.
Was there a consent banner
Yes, there is a consent banner on the site. No «accept/decline» decision was made in this visit, and not a single cookie was set during the session — that is, consent is not given. And it is precisely against this backdrop that the discrepancy is visible: the social widgets fire before consent, while in the policy they are not mentioned at all. The word «consent» does not occur in the policy text, that is, no consent mechanism is provided for the social services.
What fires before consent
On page load, without any user choice, the following fire:
- the Twitter/X widget — with an exchange of data about the visit with Twitter’s servers;
- the Instagram embedding — with a request to Meta;
- the third-party Cloudflare Insights analytics (private, without cookies — the least problematic);
- the loading of Google Fonts. The key ones are the two social widgets. Under established practice, a social plugin that transmits data about the visit to a social network on page load requires prior consent; here it is not requested.
The discrepancy of the documents with reality
A separate mismatch — a mirror one. The policy names as third-party services Cloudflare, as well as YouTube and Vimeo. But YouTube and Vimeo did not fire on the home page. What actually works is the Twitter/X widget and the Instagram embedding — and neither of them is named in the policy. That is, the document names services that are not here, and stays silent about those that actually transmit data about the visit to Twitter and Meta.
Conclusion
Quirinale.it is a restrained case compared with other government sites in the series: there is no advertising, no advertising domains and no Google Analytics here, and the only analytics is private and named. But on the head of state’s site the Twitter and Instagram social widgets transmit data about the visit to Twitter and Meta on page load — without consent and without a mention in the policy, while there is a consent banner on the site. The main takeaway for the reader: even on the President’s site the social widgets turn out to be switched on by default and hand information about the visit to foreign social networks before consent, and the policy names some services while others work. It would be enough to make the social widgets click-to-load and bring the policy into line with the actual recipients.
d5f374ff0a02e832ed66a66fd7e603c3b8cb8482f9bd8ecb810d28abcf218e60Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website quirinale.it. 2. Circumstances I visited the website quirinale.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site has a consent banner, but in a clean session, on page load and without any user decision, third-party social services fire. The Twitter/X widget loads and reaches out to Twitter's servers, exchanging data about the visit. The Instagram embedding script reaches out to Meta. Both are third-party recipients in the USA, and both fire before consent. Additionally, the third-party Cloudflare Insights analytics works (it is private, without cookies, and named in the policy). Meanwhile the social widgets themselves are not mentioned in the policy, and no consent mechanism is provided for them — the word «consent» does not occur in the document at all. That is, on the head of state's site data about the visit goes to Twitter and Meta before any consent. 2) The policy names as third-party services Cloudflare (access optimisation), as well as YouTube and Vimeo (video). However, neither YouTube nor Vimeo fired on the home page. What actually fires is the Twitter/X widget and the Instagram embedding — and neither of them is named in the policy. What results is a mirror discrepancy: the services that did not fire here are named, and those that actually transmit data about the visit to Twitter and Meta are not named. Full technical documentation is published at: https://gdpru.eu/en/audits/it-quirinale-it/ 3. Provisions violated Art. 6(1)(a) GDPR — social widgets transmit data about the visit before consent; Art. 13 GDPR — the actual social recipients are not named in the policy 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]