Senato.it is the official website of the Senate of the Republic, the upper house of Italy's parliament. Home-page capture: 50 requests, 6 domains. The Senate's analytics is correct — its own Matomo on European hosting. But alongside, on the very first contact and without any consent, social plugins load: the Facebook «Like» button and the Twitter/X widget. The Facebook plugin transmits to Meta the visitor's IP and the page address — and from the address it is visible that the person is viewing the senators section; the Twitter widget exchanges a session identifier and logs the impression. There is no consent banner at all, and in the policy the word «consent» does not occur, although the policy itself acknowledges that these services receive data about the visit. That is, a constitutional body hands information about whose deputy pages a citizen is browsing to American social networks — without consent.
Timeline of the leak
Declared versus actual
Detected trackers
- Facebook («Like» plugin)
- Twitter / X (widget)
- Matomo (EU-hosted)
- Mailchimp (mailing-widget CSS)
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — third-party social plugins transmit data about the visit before consent, without a bannerIn a clean session, on first contact, the site loads the Facebook «Like» social plugin and the Twitter/X widget. The Facebook plugin, on loading, transmits to Meta the visitor's IP address and the address of the page being viewed — and in this address it is visible that the visitor is in the section of the senators list. The Twitter widget exchanges a session identifier with Twitter's servers and logs the impression via its tracking endpoint. Both are third-party recipients in the USA. Meanwhile there is no consent banner on the site: neither a consent-collection platform nor a request for a choice is presented to the user, and in the policy itself the word «consent» does not occur. The Senate's own privacy page explicitly acknowledges that Facebook and Twitter «acquisiscono i dati relativi alla visita» — receive data about the visit — but no consent mechanism is provided for this transmission. By Garante's rules, third-party social plugins must be blocked until consent is obtained; here they fire immediately.
Context
www.senato.it is the official website of the Senate of the Republic, the upper house of Italy’s parliament. The data controller is the Senate of the Republic; the processing is governed, among other things, by the Senate’s internal regulation on personal data. The site is informational: about the house’s structure, senators, legislative activity, documents. Capture: 50 requests to 6 domains, the home page (the section with the senators list), taken on a clean Edge browser with no VPN and no blocker. The analytics is its own Matomo on European hosting. But besides it, third-party social plugins work on the page.
Who receives the data
Spotted here were: Meta / Facebook, Twitter / X. Facebook receives data via the «Like» plugin: on page load the visitor’s IP and the address of the page being viewed go to Meta. Twitter receives data via its widget: an exchange of a session identifier and an impression record at a tracking endpoint. Both services are in the USA. Separately: the Matomo analytics is hosted on European hosting and transmits no data to advertising third parties — this is the least problematic part. The subscription-form styles are loaded from the Mailchimp CDN (USA) — a static resource.
Was there a consent banner
No. Neither a consent-collection platform nor a cookie banner was found on the site, and in the policy text the word «consent» does not occur once. Meanwhile the Senate’s own privacy page explicitly describes that the Facebook and Twitter social widgets receive data about the user’s visit. What results is a mismatch: the document acknowledges the transmission of data to third-party social networks but provides no consent mechanism for it. By Garante’s rules, third-party social plugins must be blocked until consent is obtained — while here they fire on first contact.
What fires before consent
On the first visit, without any user choice, the following fire:
- the Facebook «Like» plugin — transmitting to Meta the IP and page address (the senators section);
- the Twitter/X widget — exchanging a session identifier and an impression record at a Twitter endpoint;
- the own Matomo analytics (European hosting, the least problematic);
- the loading of the subscription-form styles from the Mailchimp CDN. The key ones are the two social plugins. Under established practice (the Fashion ID case and Garante’s guidelines), a social plugin that transmits data about the visit to a social network on page load requires prior consent. Here it is not requested at all.
Why this is especially sensitive
This is a parliament’s site, and the leak concerns politically significant information. The page address that the Facebook plugin transmits to Meta shows that the visitor is in the senators section — that is, Meta receives information about whose deputy pages and which parliamentary materials a specific user is viewing. For a commercial site this is already disputed; for a constitutional body, the transmission of data about citizens’ political interest to American social networks without consent is a separately serious matter.
Conclusion
Senato.it shows a gap between the correct part and the ill-conceived one. The Senate did the analytics competently — its own Matomo on European hosting, without advertising third parties. But the Facebook and Twitter social plugins fire on first contact and transmit data about the visit to Meta and Twitter in the USA — without consent and without a banner, although the policy itself acknowledges the fact of this transmission. The main takeaway for the reader: even for parliament, third-party social plugins turn out to be switched on by default and transmit information about exactly what a citizen views on the Senate’s site to foreign social networks — while consent for this is not requested, and the rules require blocking such plugins until consent. It would have been enough either to remove the widgets or to install a real banner with prior blocking.
96bb4556df0f6894d727c38730d22880fa010d10781780918984f4c5ad0a6c00Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website senato.it. 2. Circumstances I visited the website senato.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) In a clean session, on first contact, the site loads the Facebook «Like» social plugin and the Twitter/X widget. The Facebook plugin, on loading, transmits to Meta the visitor's IP address and the address of the page being viewed — and in this address it is visible that the visitor is in the section of the senators list. The Twitter widget exchanges a session identifier with Twitter's servers and logs the impression via its tracking endpoint. Both are third-party recipients in the USA. Meanwhile there is no consent banner on the site: neither a consent-collection platform nor a request for a choice is presented to the user, and in the policy itself the word «consent» does not occur. The Senate's own privacy page explicitly acknowledges that Facebook and Twitter «acquisiscono i dati relativi alla visita» — receive data about the visit — but no consent mechanism is provided for this transmission. By Garante's rules, third-party social plugins must be blocked until consent is obtained; here they fire immediately. Full technical documentation is published at: https://gdpru.eu/en/audits/it-senato-it/ 3. Provisions violated Art. 6(1)(a) GDPR — third-party social plugins transmit data about the visit before consent, without a banner 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]