The website of Italy's National Cybersecurity Agency. 163 requests, 2 domains — its own and government analytics. The basic statistics are implemented correctly, and the data indeed does not leave the EU. But the site records the individual visitor's session — clicks, cursor, scrolling — while the policy promises only anonymous aggregates and does not mention this recording at all. And all of it without a consent banner.
Timeline of the leak
Declared versus actual
Detected trackers
- Sogei government analytics (Matomo) — transmits a visitor identifier
- Matomo HeatmapSessionRecording — session recording and heatmaps
Indicators of GDPR non-compliance
- Art. 13(1)(e) and Art. 5(1)(a) GDPR — undeclared session recordingThe policy states that the site uses no profiling cookies and describes its analytics as anonymous aggregate statistics — the number of pages visited and time spent on the site. In the capture, however, a separate session-recording module is active: it logs the behaviour of an individual visitor — clicks, cursor movement, scrolling — under a unique session identifier. This is a qualitatively different level of data than an aggregate counter, and the document does not mention it at all. The same module was found on the Revenue Agency portal running on the same Sogei government infrastructure — meaning this is a trait of the shared platform, not the oversight of a single site.
- Art. 6(1)(a) GDPR / Italian regulator's guidance — tracking without consentUnder the Italian regulator's rules, monitoring visitor behaviour is not a technical cookie but a separate tracking tool that requires consent. The site has no consent banner at all: both the basic analytics and the session recording are treated as technical means that require no prompt. For session recording this treatment is incorrect.
Context
www.acn.gov.it is the official portal of Italy’s National Cybersecurity Agency, the body responsible for protecting the country’s cyberspace and for promoting a culture of digital security and data protection. It is built on the Liferay platform. The capture shows 163 requests to two domains: the portal itself and the government analytics infrastructure of the provider Sogei. The policy correctly names the agency itself as the data controller, and it denies any transfer of data outside the EU — which in this case is true: everything runs on national infrastructure. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. Given what this agency does, it is held to a special standard: of all bodies, a cybersecurity agency should handle visitors’ data exemplarily. On the basic layer — yes. But one layer stands out, and it is the same one as at the Revenue Agency.
Was there a consent banner
There is no consent banner. The policy classifies analytics as a technical means for which no consent need be requested. For anonymous aggregate statistics this approach is permissible. The problem is that the site treats session recording exactly the same way — as a technical tool requiring no prompt. And session recording does not fall under this rule.
The basic analytics — fine
First, what is done correctly. The basic visit counter runs on the government platform, on national infrastructure, the IP address is masked as described in the policy, and not a single cookie is set during the session. Data does not leave the EU — the policy’s promise is kept here. At this level everything matches what was declared.
The site records the session — while the policy promises only aggregates
And here is the discrepancy, and it is a serious one. Alongside the ordinary counter, a session-recording and heatmap module is active on the site. This is not a tally of “how many pages were opened in total and how much time was spent” — it is a record of a specific visitor’s behaviour: where they clicked, how they moved the cursor, how they scrolled the page — tied to an individual session identifier. By its very nature this is the opposite of the “anonymous aggregate statistics” the policy promises. The document does not mention this module by a single word — neither among the types of cookies nor in the categories of processed data. And this is not a chance one-off setting: the exact same module on the same government infrastructure was found on the Revenue Agency portal. A match across two different bodies indicates that this is a trait of the provider’s shared platform, and therefore most likely replicated on other government sites built on the same foundation.
“Anonymous” — with a caveat
The “anonymity” itself is worth clarifying too. Unlike a number of other government sites in the series, where analytics ran with no identifier at all, here the visit measurement carries the visitor identifier right in the request parameters. IP masking is indeed present, and it reduces recognisability — but the visitor identifier plus the recording of their session together make the word “anonymous” rather conditional. It would be more accurate to say “partially de-identified”.
By the regulator’s rules this requires consent
And the final layer. The Italian regulator draws a clear distinction: technical cookies are one thing, and tools that monitor visitor behaviour are another, and for the latter explicit consent is required. Session recording is precisely behavioural monitoring. So classifying it among “technical means requiring no consent” is incorrect by the regulator’s own position. And on the site it works exactly that way: it launches automatically, with no banner, with no prompt.
What cannot be claimed from the capture
A few honest caveats. The capture covers the portal’s public home page; what happens in the sections after login is not visible from here. I do not observe any server-side configuration of the session recording beyond what is visible in the capture — the conclusion that it launches is drawn from the mere fact of the request to the module. I record the visitor identifier directly from the request parameters. The exact IP addresses of the servers are not preserved in the lightweight export, but both domains belong to government infrastructure anyway.
Conclusion
The basic layer here is done correctly: government analytics, IP masking, no transfer abroad — and this is honestly reflected in the policy. But on top of it runs the recording of individual sessions — clicks, cursor, scrolling — which is not in the policy at all, which is treated as requiring no consent, and which carries the visitor identifier. And this finding is not unique: the same platform module has already been seen on the Revenue Agency site. There is a particular bitterness in the fact that this is the site of a body whose direct mission is to promote a culture of cybersecurity and data protection. The main takeaway for the reader: even an agency that teaches others to safeguard data silently records visitors’ behaviour on its own portal — and, it seems, it is not the only one on this platform.
2b5d113120a6633526bf12401f2460efcbf279b42bad5528d389689dc86eca41Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website acn.gov.it. 2. Circumstances I visited the website acn.gov.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The policy states that the site uses no profiling cookies and describes its analytics as anonymous aggregate statistics — the number of pages visited and time spent on the site. In the capture, however, a separate session-recording module is active: it logs the behaviour of an individual visitor — clicks, cursor movement, scrolling — under a unique session identifier. This is a qualitatively different level of data than an aggregate counter, and the document does not mention it at all. The same module was found on the Revenue Agency portal running on the same Sogei government infrastructure — meaning this is a trait of the shared platform, not the oversight of a single site. 2) Under the Italian regulator's rules, monitoring visitor behaviour is not a technical cookie but a separate tracking tool that requires consent. The site has no consent banner at all: both the basic analytics and the session recording are treated as technical means that require no prompt. For session recording this treatment is incorrect. Full technical documentation is published at: https://gdpru.eu/en/audits/it-acn-gov-it/ 3. Provisions violated Art. 13(1)(e) and Art. 5(1)(a) GDPR — undeclared session recording; Art. 6(1)(a) GDPR / Italian regulator's guidance — tracking without consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]