Policy changed — see what exactly · 2026-07-29 →
TIGEM (the Telethon Institute of Genetics and Medicine; data controller — Fondazione Telethon, Rome) is a scientific institute in Pozzuoli near Naples. Home-page capture: 71 requests, 5 domains. There is no heavy advertising layer here, but there are two linked problems. The first: there is no consent banner on the site at all, although TIGEM's own policies explicitly require consent on opening the site for third-party cookies and analytics. The second: meanwhile, on the first visit, without any consent, the Twitter/X social widget loads (with a session-identifier exchange) and the Cloudflare Insights analytics — both third-party, both in the USA. Plus the discrepancy of the documents with reality: the policies name YouTube, Google Maps, Google Analytics and the Facebook/LinkedIn social plugins, but none of them fired, while the actually working Twitter and Cloudflare are mentioned nowhere.
Timeline of the leak
Declared versus actual
Detected trackers
- Twitter / X
- Cloudflare Insights
- Font Awesome
Indicators of GDPR non-compliance
- Art. 6(1)(a) GDPR — third-party trackers fire before consent, while there is no consent mechanism at allIn a clean session, on first contact, the site loads the Twitter/X social widget and exchanges a session identifier with Twitter's servers, and also sends an analytics request to Cloudflare Insights. Both are third-party recipients in the USA. Meanwhile there is no consent banner on the site at all: neither a consent-collection platform nor a request for a choice is presented to the user. This directly contradicts the platform's own documents: both TIGEM's privacy policy and cookie policy state verbatim that for third-party cookies and analytics the legal basis is consent collected on opening the site. That is, the consent that the platform itself declares obligatory is technically not requested, while the third-party services fire without it.
- Art. 13(1)(e) GDPR — the actual third-party recipients are not named in the policyThe cookie policy lists the third-party services YouTube, Google Maps and Google Analytics (the last as a «future implementation»), and the privacy policy mentions the Facebook, Google and Microsoft (LinkedIn) social plugins. However, none of these services fired on the home page. What actually fires is Twitter/X, Cloudflare Insights and the third-party font CDN Font Awesome — and none of them is named in the documents. What results is a mirror discrepancy: what is not there is named, and what is there is not named. The documents, meanwhile, are dated 2019 (privacy) and carry traces of an unconfigured template (cookie), that is, they are out of sync with the site's actual arrangement.
Context
www.tigem.it is the website of TIGEM (the Telethon Institute of Genetics and Medicine), a scientific institute of genetics and medicine in Pozzuoli near Naples. The data controller is Fondazione Telethon (Rome, Via Varese 16/B). The site is informational: about the institute’s structure, research, publications and training; no paid access or registration is required on the home page. Capture: 71 requests to 5 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. The site runs on Plone behind Cloudflare. There is no heavy advertising-and-analytics layer, but third-party services are present on the first visit — and no consent is collected for them.
Who receives the data
Spotted here were: Twitter / X, Cloudflare. Twitter/X is a social widget that, on loading, exchanges a session identifier with Twitter (that is, the third-party social network receives data about the visit). Cloudflare Insights is Cloudflare’s third-party web analytics, sending an analytics request. Both services are hosted in the USA. Separately, the Font Awesome icon font loads from an American CDN — it sets no cookies but transmits the IP there.
Was there a consent banner
No. And here this is a standalone problem, not a caveat. Neither a consent-collection platform nor a cookie banner was found on the site: the user is presented with no choice at all. Meanwhile both TIGEM’s privacy policy and cookie policy explicitly write that for third-party cookies and analytics the legal basis is consent collected on opening the site. It turns out the platform itself declares consent obligatory but technically does not request it — while the third-party services (Twitter, Cloudflare) meanwhile fire on first contact. Any firing here by definition happens «before consent», because there is simply nowhere to collect it.
What fires before consent
On the first visit, without any user choice, the following fire:
- the Twitter/X social widget — with a session-identifier exchange with Twitter’s servers;
- the third-party Cloudflare Insights analytics;
- the loading of the icon font from the American CDN Font Awesome. The social widget is the key point. Under established practice, a social plugin that transmits data about the visit to a social network on page load requires prior consent; here it is not requested at all.
The discrepancy of the documents with reality
The second mismatch is a mirror one. TIGEM’s policies name as third-party services YouTube, Google Maps, Google Analytics (and as a «future implementation» at that) and the Facebook, Google, Microsoft (LinkedIn) social plugins. But in the capture none of them fired. What actually works is Twitter/X, Cloudflare Insights and Font Awesome — and none is mentioned in either of the documents. The documents are dated 2019 and carry traces of an unconfigured template, that is, they describe not the site that works now. For the reader this is illustrative: a policy detached from the site’s actual arrangement does not perform its function — it informs about the wrong recipients.
Conclusion
TIGEM is a case where the problem is not an abundance of trackers, but the absence of the consent mechanism itself with third-party recipients present. On the first visit, without any user choice, the Twitter/X social widget exchanges a session identifier with the social network, and Cloudflare Insights sends analytics — while the institute’s own policies explicitly require consent for this, collected on opening the site. And there is no banner at all. In addition, the documents list some third-party recipients, while entirely different ones work. The main takeaway for the reader: the formal presence of a policy promising consent means nothing if consent is technically not requested, and the recipients named in the document do not match those who actually receive the data. This is verified only by a network capture — and here it shows the gap between the promised and the actual.
5be2d2f8547913ae884a7f771c59f2bf274cc09989ccb1889b97149163e94605Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website tigem.it. 2. Circumstances I visited the website tigem.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) In a clean session, on first contact, the site loads the Twitter/X social widget and exchanges a session identifier with Twitter's servers, and also sends an analytics request to Cloudflare Insights. Both are third-party recipients in the USA. Meanwhile there is no consent banner on the site at all: neither a consent-collection platform nor a request for a choice is presented to the user. This directly contradicts the platform's own documents: both TIGEM's privacy policy and cookie policy state verbatim that for third-party cookies and analytics the legal basis is consent collected on opening the site. That is, the consent that the platform itself declares obligatory is technically not requested, while the third-party services fire without it. 2) The cookie policy lists the third-party services YouTube, Google Maps and Google Analytics (the last as a «future implementation»), and the privacy policy mentions the Facebook, Google and Microsoft (LinkedIn) social plugins. However, none of these services fired on the home page. What actually fires is Twitter/X, Cloudflare Insights and the third-party font CDN Font Awesome — and none of them is named in the documents. What results is a mirror discrepancy: what is not there is named, and what is there is not named. The documents, meanwhile, are dated 2019 (privacy) and carry traces of an unconfigured template (cookie), that is, they are out of sync with the site's actual arrangement. Full technical documentation is published at: https://gdpru.eu/en/audits/it-tigem-it/ 3. Provisions violated Art. 6(1)(a) GDPR — third-party trackers fire before consent, while there is no consent mechanism at all; Art. 13(1)(e) GDPR — the actual third-party recipients are not named in the policy 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]