Registroimprese.it is Italy's official business register, run by InfoCamere (the IT company of the chambers of commerce). Home-page capture: 165 requests, 11 domains. For a government register the set of third-party services is unexpectedly commercial: Google Analytics, the Google AdSense advertising tag, the Facebook SDK, the Google reCAPTCHA Enterprise bot protection, plus the Didomi CMP. In the site's favour: Google's advertising layer observes consent — the state «not given», the advertising non-personalised, no cookie set. But the contacts with the USA still happen before consent: GA4 sends a view and scroll, the AdSense tag pings, the Facebook SDK loads (the IP goes to Meta), reCAPTCHA collects device data. And this while the site's legal terms explicitly promise to use third-party trackers only after consent.
Timeline of the leak
Declared versus actual
Detected trackers
- Google Analytics 4
- Google AdSense (tag)
- Facebook SDK
- reCAPTCHA Enterprise
- Google Tag Manager
- Didomi
- Google Fonts
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — third-party services make contact before consent, against the policy's own promiseThe site's legal terms explicitly promise: third-party cookies and tracking tools are used «solo previo consenso» — only after prior consent. Nevertheless, in a clean session, before any decision and with the Didomi banner in place, several third-party services in the USA manage to make contact before consent. In the site's favour it must be said honestly: Google's advertising-and-analytics layer is configured to observe consent — Google Consent Mode transmits the state «not given», the advertising is marked as non-personalised, not a single cookie was set during the session. But this does not cancel the contacts themselves: Google Analytics sends page-view and scroll events, the Google AdSense advertising tag sends a utility ping, the Facebook SDK loads (that is, the IP goes to Meta), and the Google reCAPTCHA Enterprise bot protection works, collecting device characteristics. All these requests to Google and Meta happen before consent, which the policy itself declares an obligatory condition for third-party tools.
Context
www.registroimprese.it is Italy’s official public business register: data on all registered companies, their directors, shareholders, balance sheets. The technical operator and controller is InfoCamere S.C.p.A., the IT company of the chambers-of-commerce system. This is a highly sensitive category: the register contains personal data of many individuals connected with companies. Capture: 165 requests to 11 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. There is a Didomi consent-collection platform. The technical stack includes a noticeable commercial Google and Meta layer.
Who receives the data
Spotted here were: Google, Meta / Facebook. Google is present through several services at once: analytics (Google Analytics), advertising tag (AdSense), tag system (Tag Manager), bot protection (reCAPTCHA Enterprise) and fonts (Google Fonts). Meta — via the loading of the Facebook SDK. Both are recipients in the USA. The Didomi consent platform is European (Denmark) and is not a complaint in itself. Importantly, to be honest: Google’s advertising-and-analytics layer is configured to observe consent. The consent state is transmitted as «not given», the advertising is marked non-personalised, no tracking cookies were set during the session. That is, Google here does not ignore the refusal — unlike a number of commercial sites in the series.
Was there a consent banner
Yes, the Didomi banner is present and loads at the 211th millisecond. No «accept/decline» decision was made in this visit — the capture was taken in a clean session. And it is precisely against this backdrop that the mismatch with the site’s own document is visible. The site’s legal terms explicitly promise: third-party cookies and tracking tools are used only after prior consent («solo previo consenso»). Yet by the capture, requests to Google and Meta already happen before consent.
What fires before consent
Before any user decision, the following manage to fire:
- Google Analytics — page-view and scroll events (anonymised, but the fact of the visit goes to Google);
- the Google AdSense advertising tag — a utility ping (in non-personalised mode);
- the Facebook SDK — the module loads, with the IP going to Meta;
- reCAPTCHA Enterprise — Google’s bot protection collecting device characteristics;
- Google Fonts — the fonts load with the IP transmitted to Google. The key point is in the distinction. Some of this Google keeps in «consent not given» — without cookies and without personalisation, and this counts in the site’s favour. But the contacts as such still happen: the Facebook SDK load is not tied to Google’s consent mode and simply sends a request to Meta, while the analytics and reCAPTCHA reach out to Google. For a site that itself promised not to engage third-party tools before consent, this is a divergence between the promised and the actual.
Why this is especially sensitive
This is an official business register — a resource with a large volume of individuals’ personal data. The presence on it of the AdSense advertising tag and the Facebook SDK is telling in itself: commercial advertising-social infrastructure on a government register. Even though Google observes consent and the Facebook pixel event did not fire, the presence of these services and their requests before consent sit poorly with the role of an official register.
Conclusion
Registroimprese.it is a mixed case. The positive part is real: Google’s advertising-and-analytics layer is configured to observe consent — «not given», without cookies, the advertising non-personalised, and this distinguishes the site favourably from those that ignore the refusal. But the picture is not clean: before consent the Facebook SDK still loads (IP to Meta), Google Analytics sends a view and scroll, the AdSense advertising tag pings, and reCAPTCHA collects device data — while the site’s own legal terms promise to engage third-party tools only after consent. The main takeaway for the reader: even a correct consent configuration for one provider (Google) does not make the page clean if, alongside, a third-party social SDK loads before consent and an advertising-and-analytics layer works, and an official register of personal data is the last place where an advertising tag and social-network infrastructure are appropriate.
5e4a2e30a54ac3bef1ba66b84a409dda1f9140ff24d1a0b5e8a8033e6f7f6ce9Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website registroimprese.it. 2. Circumstances I visited the website registroimprese.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The site's legal terms explicitly promise: third-party cookies and tracking tools are used «solo previo consenso» — only after prior consent. Nevertheless, in a clean session, before any decision and with the Didomi banner in place, several third-party services in the USA manage to make contact before consent. In the site's favour it must be said honestly: Google's advertising-and-analytics layer is configured to observe consent — Google Consent Mode transmits the state «not given», the advertising is marked as non-personalised, not a single cookie was set during the session. But this does not cancel the contacts themselves: Google Analytics sends page-view and scroll events, the Google AdSense advertising tag sends a utility ping, the Facebook SDK loads (that is, the IP goes to Meta), and the Google reCAPTCHA Enterprise bot protection works, collecting device characteristics. All these requests to Google and Meta happen before consent, which the policy itself declares an obligatory condition for third-party tools. Full technical documentation is published at: https://gdpru.eu/en/audits/it-registroimprese-it/ 3. Provisions violated Art. 6(1)(a) GDPR — third-party services make contact before consent, against the policy's own promise 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]