Technical audit · 2026-06-15

registroimprese.it

Official Business Register of Italy

Registroimprese.it is Italy's official business register, run by InfoCamere (the IT company of the chambers of commerce). Home-page capture: 165 requests, 11 domains. For a government register the set of third-party services is unexpectedly commercial: Google Analytics, the Google AdSense advertising tag, the Facebook SDK, the Google reCAPTCHA Enterprise bot protection, plus the Didomi CMP. In the site's favour: Google's advertising layer observes consent — the state «not given», the advertising non-personalised, no cookie set. But the contacts with the USA still happen before consent: GA4 sends a view and scroll, the AdSense tag pings, the Facebook SDK loads (the IP goes to Meta), reCAPTCHA collects device data. And this while the site's legal terms explicitly promise to use third-party trackers only after consent.

Timeline of the leak

183 ms · Google Fonts
Font styles load from the Google domain. A static resource, but the visitor's IP goes to Google.
211 ms · Didomi consent platform
The Didomi consent-collection platform loads. That is, a consent mechanism is provided on the site.
384 ms · Google reCAPTCHA Enterprise bot protection
Google's reCAPTCHA Enterprise connects: the script loads and a background handler launches. This is usually justified by bot protection, but the service collects device characteristics and reaches out to Google before consent.
498 ms · Google AdSense advertising tag
The Google AdSense advertising tag sends a utility ping. Consent, meanwhile, is marked as «not given», the advertising non-personalised — Google takes the consent mode into account.
875 ms · Google Analytics sends a view
Google Analytics sends a page-view event. The consent signal is «not given», the transmission anonymised, but the fact of the visit goes to Google.
1021 ms · Facebook SDK load
The Facebook software module (SDK) loads. No separate pixel event was recorded, but the request itself transmits the visitor's IP to Meta — and happens before consent.
6021 ms · Google Analytics sends a scroll
Google Analytics sends a page-scroll event — that is, behaviour is tracked too, still in «consent not given» mode.
there is a Didomi banner, consent not given
The Didomi consent banner is present, no «accept/decline» decision was made in this visit. All the listed requests happened before consent.

Declared versus actual

+ Google Analytics — не заявлен
+ Google AdSense — не заявлен
+ Facebook SDK — не заявлен
+ reCAPTCHA Enterprise — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.registroimprese.it is Italy’s official public business register: data on all registered companies, their directors, shareholders, balance sheets. The technical operator and controller is InfoCamere S.C.p.A., the IT company of the chambers-of-commerce system. This is a highly sensitive category: the register contains personal data of many individuals connected with companies. Capture: 165 requests to 11 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. There is a Didomi consent-collection platform. The technical stack includes a noticeable commercial Google and Meta layer.

Who receives the data

Spotted here were: Google, Meta / Facebook. Google is present through several services at once: analytics (Google Analytics), advertising tag (AdSense), tag system (Tag Manager), bot protection (reCAPTCHA Enterprise) and fonts (Google Fonts). Meta — via the loading of the Facebook SDK. Both are recipients in the USA. The Didomi consent platform is European (Denmark) and is not a complaint in itself. Importantly, to be honest: Google’s advertising-and-analytics layer is configured to observe consent. The consent state is transmitted as «not given», the advertising is marked non-personalised, no tracking cookies were set during the session. That is, Google here does not ignore the refusal — unlike a number of commercial sites in the series.

Yes, the Didomi banner is present and loads at the 211th millisecond. No «accept/decline» decision was made in this visit — the capture was taken in a clean session. And it is precisely against this backdrop that the mismatch with the site’s own document is visible. The site’s legal terms explicitly promise: third-party cookies and tracking tools are used only after prior consent («solo previo consenso»). Yet by the capture, requests to Google and Meta already happen before consent.

Before any user decision, the following manage to fire:

  • Google Analytics — page-view and scroll events (anonymised, but the fact of the visit goes to Google);
  • the Google AdSense advertising tag — a utility ping (in non-personalised mode);
  • the Facebook SDK — the module loads, with the IP going to Meta;
  • reCAPTCHA Enterprise — Google’s bot protection collecting device characteristics;
  • Google Fonts — the fonts load with the IP transmitted to Google. The key point is in the distinction. Some of this Google keeps in «consent not given» — without cookies and without personalisation, and this counts in the site’s favour. But the contacts as such still happen: the Facebook SDK load is not tied to Google’s consent mode and simply sends a request to Meta, while the analytics and reCAPTCHA reach out to Google. For a site that itself promised not to engage third-party tools before consent, this is a divergence between the promised and the actual.

Why this is especially sensitive

This is an official business register — a resource with a large volume of individuals’ personal data. The presence on it of the AdSense advertising tag and the Facebook SDK is telling in itself: commercial advertising-social infrastructure on a government register. Even though Google observes consent and the Facebook pixel event did not fire, the presence of these services and their requests before consent sit poorly with the role of an official register.

Conclusion

Registroimprese.it is a mixed case. The positive part is real: Google’s advertising-and-analytics layer is configured to observe consent — «not given», without cookies, the advertising non-personalised, and this distinguishes the site favourably from those that ignore the refusal. But the picture is not clean: before consent the Facebook SDK still loads (IP to Meta), Google Analytics sends a view and scroll, the AdSense advertising tag pings, and reCAPTCHA collects device data — while the site’s own legal terms promise to engage third-party tools only after consent. The main takeaway for the reader: even a correct consent configuration for one provider (Google) does not make the page clean if, alongside, a third-party social SDK loads before consent and an advertising-and-analytics layer works, and an official register of personal data is the last place where an advertising tag and social-network infrastructure are appropriate.

Evidence
Original (audit)
HAR file: it/registroimprese-it-2026-06-15.har
SHA-256: 5e4a2e30a54ac3bef1ba66b84a409dda1f9140ff24d1a0b5e8a8033e6f7f6ce9
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website registroimprese.it.

2. Circumstances
I visited the website registroimprese.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The site's legal terms explicitly promise: third-party cookies and tracking tools are used «solo previo consenso» — only after prior consent. Nevertheless, in a clean session, before any decision and with the Didomi banner in place, several third-party services in the USA manage to make contact before consent. In the site's favour it must be said honestly: Google's advertising-and-analytics layer is configured to observe consent — Google Consent Mode transmits the state «not given», the advertising is marked as non-personalised, not a single cookie was set during the session. But this does not cancel the contacts themselves: Google Analytics sends page-view and scroll events, the Google AdSense advertising tag sends a utility ping, the Facebook SDK loads (that is, the IP goes to Meta), and the Google reCAPTCHA Enterprise bot protection works, collecting device characteristics. All these requests to Google and Meta happen before consent, which the policy itself declares an obligatory condition for third-party tools.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-registroimprese-it/

3. Provisions violated
Art. 6(1)(a) GDPR — third-party services make contact before consent, against the policy's own promise

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]