Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
BRT (also known as Bartolini) is a major Italian parcel courier. Online retailers embed BRT shipment tracking widgets and delivery iframes so customers can follow their parcels. These components load third party scripts and may set cookies or read identifiers, which carries GDPR and ePrivacy obligations.
BRT, historically known as Bartolini, is one of the largest parcel couriers in Italy. Many e-commerce sites embed BRT tracking widgets and delivery iframes so shoppers can follow a parcel from dispatch to doorstep without leaving the store. These embedded components are served from BRT systems and run third party JavaScript inside the retailer page.
To display tracking, the widget processes a tracking number and the related shipment and recipient data such as delivery address, status events and estimated delivery time. The embedded scripts may set first party or third party cookies for session continuity, load balancing and basic measurement, and they can read browser and device information. The exact cookies depend on the integration mode chosen by the retailer.
Shipment and recipient data are personal data under the GDPR, and embedding a third party widget can make BRT a processor or, for its own purposes, an independent controller. Under the ePrivacy Directive, storing or reading any non essential cookie or identifier requires prior consent. Strictly necessary cookies that are needed only to deliver the tracking function the user requested are generally exempt.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Cookies and scripts that go beyond strict necessity, such as analytics or marketing tags carried by the widget, must wait for freely given, specific and informed opt in consent. A common compliant pattern is to keep the core tracking lookup available under contract performance while gating any measurement or advertising components behind your consent banner.
BRT is an Italian operator and processing is primarily within Italy and the wider EU, so cross border transfer risk is comparatively low. You should still confirm where widget assets are cached, whether any content delivery network or sub processor sits outside the EEA, and ensure Standard Contractual Clauses and a transfer impact assessment cover any such flow.
Map the widget integration, list every cookie it sets, and classify each as necessary or non essential. Load non essential scripts only after consent through your consent management platform, sign a data processing agreement with BRT, name BRT in your privacy and cookie notices, and re test after any integration change so the documentation stays accurate.
Websites using BRT must obtain user consent under GDPR regulations.
DPIA considerations
A full DPIA is usually not required for basic shipment tracking. Document a balancing test for the necessary tracking function and assess any added analytics or marketing tags. Review parcel data flows, recipient details and any profiling before launch.
Sample consent text
We use BRT (Bartolini) delivery and tracking components that may set cookies and read identifiers to show your shipment status. Non essential cookies load only after you accept.
Third-party domains contacted
vas.brt.itwww.brt.ittracking.brt.itCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| BRT_SESSION | Strictly necessary | Session | Maintains the tracking session so the widget can return the correct shipment status to the user |
| BRT_LB | Strictly necessary | Session | Load balancing cookie that routes the request to the right BRT server for reliable delivery |
| brt_prefs | Functional | 6 months | Remembers display preferences such as language for the tracking interface |
| _brt_ga | Analytics | Up to 13 months | Aggregated usage measurement for the tracking widget, loaded only after consent |
BRT uses cookies for user preferences — inform visitors with a consent banner.
It depends on the integration, but the embedded BRT components can set first party or third party cookies for session continuity, load balancing and basic measurement, and may read browser or device identifiers. Audit your live pages to capture the exact cookies, then classify each as strictly necessary or non essential.
Yes for anything beyond strict necessity. Cookies and scripts needed only to perform the tracking lookup the user requested can rely on contract or necessity, but any analytics or marketing cookie carried by the widget needs prior opt in consent under the ePrivacy rules.
The strictly necessary tracking function can rest on performance of the delivery contract or legitimate interest. Non essential cookies and any profiling require consent. Document the basis for each purpose in your records of processing.
BRT is an Italian operator and processing is mainly within Italy and the EU, so US transfers are not a core feature. Still verify any content delivery network or sub processor used to serve widget assets, and apply Standard Contractual Clauses with a transfer impact assessment if data leaves the EEA.
A full DPIA is usually not required for basic shipment tracking. If you combine it with profiling, large scale tracking or additional marketing tags, run a screening assessment and document why a full DPIA is or is not needed.
Load non essential scripts only after consent through your consent management platform, sign a data processing agreement with BRT, list the widget cookies in your cookie notice, and retest after any integration change so your records stay accurate.
You can link out to the BRT tracking page instead of embedding it, use a server side status lookup so no third party script runs in the browser, or choose another carrier integration. Each option changes the cookie and consent profile, so reassess accordingly.
Add an entry naming BRT, the cookie names and purposes, durations and whether they are first or third party, the legal basis, and how users withdraw consent. Review it whenever the integration or carrier changes.