Privacy Policy

ilfattoquotidiano's Privacy Policy Overview

🌐 www.ilfattoquotidiano.it

Il Fatto Quotidiano is an Italian online newspaper known for its investigative journalism and independent reporting.
AI-Powered Analysis
Last analyzed March 29, 2026 20:36
View Original Privacy Policy
74
Moderate Score

Overall Rating: 74/100

Based on analysis of data protection, legal compliance, transparency, and fairness

75

User Data Protection

Clearly lists data categories, mentions security measures and blockchain for tokens, but lacks specifics on encryption, breach notification, and sensitive data handling.

85

Legal Compliance

Explicitly references GDPR, details legal bases, user rights, and provides contact for DPO, but lacks CCPA/other regional law mentions.

65

Balance & Fairness

Outlines user rights and consent mechanisms, but data retention for contracts is long (10 years), and some clauses favor business interests.

70

Transparency & Readability

Uses structured sections and plain language, but lengthy with embedded navigation elements; cookie tables are detailed but technical.

AI Summary

The document is a privacy policy for a website. It contains several problematic aspects when analyzed for compliance with data protection principles, particularly the GDPR.

The policy states that data collected for subscriptions and related promotions will be retained for 10 years after the contractual relationship ends, citing the statute of limitations for the company's actionable rights. This retention period appears excessively long and may not be proportionate or necessary for the stated purpose.

The policy mentions using a blockchain platform to manage user tokens. The use of blockchain for personal data processing raises significant concerns regarding data immutability, the practical application of data subject rights like erasure, and the compatibility of blockchain's inherent characteristics with GDPR principles.

The policy states that data collected for marketing and profiling purposes will be retained for three years. While a timeframe is given, the policy does not specify the lawful basis or necessity for this specific duration, nor does it explain the criteria used to determine it.

The policy lists data transfers outside the European Economic Area based on Standard Contractual Clauses. It does not mention conducting Transfer Impact Assessments or detailing supplementary measures to address risks in third countries, which is a recommended practice.

The cookie policy section states that analytical cookies do not require user consent because mechanisms like IP anonymization are used. Under the GDPR and ePrivacy rules, the legal basis for non-essential analytical cookies is often consent, not merely anonymization. The classification of these cookies as not requiring consent is potentially non-compliant.

The cookie tables list providers like Clickio, Mapp, Nielsen, and Weborama. The policy provides links to their privacy policies but lacks specific, accessible information about what data these third parties collect, how they use it, and the user's ability to control this sharing directly from the primary site.

The policy states that disabling some technical cookies might compromise the website's functionality. While this can be true, it is a standard notice. However, the policy does not clearly differentiate between strictly necessary cookies for basic functionality and other cookies that the site bundles as "technical," which could be misleading.

The policy mentions that third-party cookie providers may process data outside the EU as independent data controllers. It refers users to the third parties' privacy policies for details. This practice shifts the burden of understanding international data transfers entirely onto the user, which is not transparent or user-friendly.

The document is cluttered with extensive website navigation menus, promotional content, and subscription offers. This formatting makes the privacy policy itself difficult to read, locate, and understand, potentially violating the GDPR requirement for transparent and accessible information.

The policy states it was last updated on 25 September 2025, which is a future date at the time of this analysis. This is likely an error but creates an immediate impression of inaccuracy.

📋 Key Clauses Analyzed

Data Collection Categories

Collects identification, contact, subscription, token, and browsing data.

Legal Basis for Processing

Processes data for contracts, legal obligations, consent for marketing, and legitimate interests.

Data Retention Periods

Retains account data until deactivation, subscription data for 10 years post-termination.

International Data Transfers

Transfers data outside EU using standard contractual clauses.

User Rights Under GDPR

Users have rights to access, rectify, delete, restrict, and port their data.

❓ Questions About This Privacy Policy

✨ AI Enhanced Answers
Generating AI response
The policy states that data collected for subscriptions and promotions will be retained for 10 years after the contractual relationship ends, citing the statute of limitations. This period appears excessively long and may not be proportionate or necessary for the stated purpose, as GDPR requires that retention periods be limited to what is strictly necessary.
Generating AI response
The policy mentions using blockchain to manage user tokens, which raises significant concerns about data immutability and the practical application of data subject rights like erasure. Blockchain's inherent characteristics may conflict with GDPR principles, such as the right to erasure, because data on a blockchain is typically difficult to modify or delete.
Generating AI response
The policy states that data collected for marketing and profiling will be retained for three years but does not specify the lawful basis or the criteria used to determine this duration. Under GDPR, you must provide clear justification for retention periods, explaining why that specific timeframe is necessary and proportionate.
The policy mentions transfers based on Standard Contractual Clauses but does not mention conducting Transfer Impact Assessments or detailing supplementary measures to address risks in third countries. This is a recommended practice under GDPR to ensure an adequate level of protection for your data when transferred internationally.
The policy claims that analytical cookies do not require consent because IP anonymization is used, but under GDPR and ePrivacy rules, the legal basis for non-essential analytical cookies is often consent. Simply anonymizing IP addresses does not automatically negate the need for consent, as other data may still be collected and processed.

Never blindly click "agree" again

Install the free Termzy AI browser extension and get instant AI-powered analysis of any legal document you encounter online.

Add Termzy AI to the Browser - It's Free
🎉

Thank You for Using Termzy AI!

You're getting the full experience with complete policy analysis, all clauses unlocked, and unlimited FAQ access.