Technical audit · 2026-06-15

senato.it

Website of the Senate of the Republic

Senato.it is the official website of the Senate of the Republic, the upper house of Italy's parliament. Home-page capture: 50 requests, 6 domains. The Senate's analytics is correct — its own Matomo on European hosting. But alongside, on the very first contact and without any consent, social plugins load: the Facebook «Like» button and the Twitter/X widget. The Facebook plugin transmits to Meta the visitor's IP and the page address — and from the address it is visible that the person is viewing the senators section; the Twitter widget exchanges a session identifier and logs the impression. There is no consent banner at all, and in the policy the word «consent» does not occur, although the policy itself acknowledges that these services receive data about the visit. That is, a constitutional body hands information about whose deputy pages a citizen is browsing to American social networks — without consent.

Timeline of the leak

63 ms · mailing-widget CSS (Mailchimp)
The subscription-form stylesheet loads from the Mailchimp CDN. A static resource, but the domain is third-party (USA), and it is not named in the policy.
79 ms · own Matomo analytics
The Matomo analytics script on European hosting (senato.matomo.cloud) loads. This is correct, EU-hosted analytics — the least problematic part.
87 ms · Twitter/X widget script
The Twitter/X social-widget script connects. A third-party social-network service loads on first contact, without consent.
96 ms · Facebook «Like» plugin
The Facebook «Like» plugin loads, and on loading the visitor's IP goes to Meta together with the page address — and in the address the senators-list section is visible. That is, Meta receives which specific page the visitor is viewing, without any consent.
348–557 ms · Twitter exchanges data and logs the impression
The Twitter widget reaches out to syndication.twitter.com with a session identifier and sends an impression record to Twitter's tracking endpoint, indicating that the source is senato.it. That is, Twitter receives data about the visit.
there is no consent banner
Neither a consent-collection platform nor a cookie banner was found on the site. Any transmission of data to social networks here happens before and without consent, because there is nowhere to collect it.

Declared versus actual

Facebook — заявлен
Twitter — заявлен
+ Matomo — не заявлен
+ Mailchimp — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.senato.it is the official website of the Senate of the Republic, the upper house of Italy’s parliament. The data controller is the Senate of the Republic; the processing is governed, among other things, by the Senate’s internal regulation on personal data. The site is informational: about the house’s structure, senators, legislative activity, documents. Capture: 50 requests to 6 domains, the home page (the section with the senators list), taken on a clean Edge browser with no VPN and no blocker. The analytics is its own Matomo on European hosting. But besides it, third-party social plugins work on the page.

Who receives the data

Spotted here were: Meta / Facebook, Twitter / X. Facebook receives data via the «Like» plugin: on page load the visitor’s IP and the address of the page being viewed go to Meta. Twitter receives data via its widget: an exchange of a session identifier and an impression record at a tracking endpoint. Both services are in the USA. Separately: the Matomo analytics is hosted on European hosting and transmits no data to advertising third parties — this is the least problematic part. The subscription-form styles are loaded from the Mailchimp CDN (USA) — a static resource.

No. Neither a consent-collection platform nor a cookie banner was found on the site, and in the policy text the word «consent» does not occur once. Meanwhile the Senate’s own privacy page explicitly describes that the Facebook and Twitter social widgets receive data about the user’s visit. What results is a mismatch: the document acknowledges the transmission of data to third-party social networks but provides no consent mechanism for it. By Garante’s rules, third-party social plugins must be blocked until consent is obtained — while here they fire on first contact.

On the first visit, without any user choice, the following fire:

  • the Facebook «Like» plugin — transmitting to Meta the IP and page address (the senators section);
  • the Twitter/X widget — exchanging a session identifier and an impression record at a Twitter endpoint;
  • the own Matomo analytics (European hosting, the least problematic);
  • the loading of the subscription-form styles from the Mailchimp CDN. The key ones are the two social plugins. Under established practice (the Fashion ID case and Garante’s guidelines), a social plugin that transmits data about the visit to a social network on page load requires prior consent. Here it is not requested at all.

Why this is especially sensitive

This is a parliament’s site, and the leak concerns politically significant information. The page address that the Facebook plugin transmits to Meta shows that the visitor is in the senators section — that is, Meta receives information about whose deputy pages and which parliamentary materials a specific user is viewing. For a commercial site this is already disputed; for a constitutional body, the transmission of data about citizens’ political interest to American social networks without consent is a separately serious matter.

Conclusion

Senato.it shows a gap between the correct part and the ill-conceived one. The Senate did the analytics competently — its own Matomo on European hosting, without advertising third parties. But the Facebook and Twitter social plugins fire on first contact and transmit data about the visit to Meta and Twitter in the USA — without consent and without a banner, although the policy itself acknowledges the fact of this transmission. The main takeaway for the reader: even for parliament, third-party social plugins turn out to be switched on by default and transmit information about exactly what a citizen views on the Senate’s site to foreign social networks — while consent for this is not requested, and the rules require blocking such plugins until consent. It would have been enough either to remove the widgets or to install a real banner with prior blocking.

Evidence
Original (audit)
HAR file: it/senato-it-2026-06-15.har
SHA-256: 96bb4556df0f6894d727c38730d22880fa010d10781780918984f4c5ad0a6c00
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website senato.it.

2. Circumstances
I visited the website senato.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) In a clean session, on first contact, the site loads the Facebook «Like» social plugin and the Twitter/X widget. The Facebook plugin, on loading, transmits to Meta the visitor's IP address and the address of the page being viewed — and in this address it is visible that the visitor is in the section of the senators list. The Twitter widget exchanges a session identifier with Twitter's servers and logs the impression via its tracking endpoint. Both are third-party recipients in the USA. Meanwhile there is no consent banner on the site: neither a consent-collection platform nor a request for a choice is presented to the user, and in the policy itself the word «consent» does not occur. The Senate's own privacy page explicitly acknowledges that Facebook and Twitter «acquisiscono i dati relativi alla visita» — receive data about the visit — but no consent mechanism is provided for this transmission. By Garante's rules, third-party social plugins must be blocked until consent is obtained; here they fire immediately.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-senato-it/

3. Provisions violated
Art. 6(1)(a) GDPR — third-party social plugins transmit data about the visit before consent, without a banner

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]