Data Collection Categories
Collects identification, contact, subscription, token, and browsing data.
🌐 www.ilfattoquotidiano.it
Clearly lists data categories, mentions security measures and blockchain for tokens, but lacks specifics on encryption, breach notification, and sensitive data handling.
Explicitly references GDPR, details legal bases, user rights, and provides contact for DPO, but lacks CCPA/other regional law mentions.
Outlines user rights and consent mechanisms, but data retention for contracts is long (10 years), and some clauses favor business interests.
Uses structured sections and plain language, but lengthy with embedded navigation elements; cookie tables are detailed but technical.
The document is a privacy policy for a website. It contains several problematic aspects when analyzed for compliance with data protection principles, particularly the GDPR.
The policy states that data collected for subscriptions and related promotions will be retained for 10 years after the contractual relationship ends, citing the statute of limitations for the company's actionable rights. This retention period appears excessively long and may not be proportionate or necessary for the stated purpose.
The policy mentions using a blockchain platform to manage user tokens. The use of blockchain for personal data processing raises significant concerns regarding data immutability, the practical application of data subject rights like erasure, and the compatibility of blockchain's inherent characteristics with GDPR principles.
The policy states that data collected for marketing and profiling purposes will be retained for three years. While a timeframe is given, the policy does not specify the lawful basis or necessity for this specific duration, nor does it explain the criteria used to determine it.
The policy lists data transfers outside the European Economic Area based on Standard Contractual Clauses. It does not mention conducting Transfer Impact Assessments or detailing supplementary measures to address risks in third countries, which is a recommended practice.
The cookie policy section states that analytical cookies do not require user consent because mechanisms like IP anonymization are used. Under the GDPR and ePrivacy rules, the legal basis for non-essential analytical cookies is often consent, not merely anonymization. The classification of these cookies as not requiring consent is potentially non-compliant.
The cookie tables list providers like Clickio, Mapp, Nielsen, and Weborama. The policy provides links to their privacy policies but lacks specific, accessible information about what data these third parties collect, how they use it, and the user's ability to control this sharing directly from the primary site.
The policy states that disabling some technical cookies might compromise the website's functionality. While this can be true, it is a standard notice. However, the policy does not clearly differentiate between strictly necessary cookies for basic functionality and other cookies that the site bundles as "technical," which could be misleading.
The policy mentions that third-party cookie providers may process data outside the EU as independent data controllers. It refers users to the third parties' privacy policies for details. This practice shifts the burden of understanding international data transfers entirely onto the user, which is not transparent or user-friendly.
The document is cluttered with extensive website navigation menus, promotional content, and subscription offers. This formatting makes the privacy policy itself difficult to read, locate, and understand, potentially violating the GDPR requirement for transparent and accessible information.
The policy states it was last updated on 25 September 2025, which is a future date at the time of this analysis. This is likely an error but creates an immediate impression of inaccuracy.
Collects identification, contact, subscription, token, and browsing data.
Processes data for contracts, legal obligations, consent for marketing, and legitimate interests.
Retains account data until deactivation, subscription data for 10 years post-termination.
Transfers data outside EU using standard contractual clauses.
Users have rights to access, rectify, delete, restrict, and port their data.
Install the free Termzy AI browser extension and get instant AI-powered analysis of any legal document you encounter online.
Add Termzy AI to the Browser - It's Free