Technical audit · 2026-06-15

acn.gov.it

Italy's National Cybersecurity Agency

The website of Italy's National Cybersecurity Agency. 163 requests, 2 domains — its own and government analytics. The basic statistics are implemented correctly, and the data indeed does not leave the EU. But the site records the individual visitor's session — clicks, cursor, scrolling — while the policy promises only anonymous aggregates and does not mention this recording at all. And all of it without a consent banner.

Timeline of the leak

+0–272 ms · portal load
The portal runs on the Liferay platform, on a standard government theme. All resources come from its own domain.
not applicable — no banner
There is no consent banner. The policy classifies analytics as a technical means requiring no consent. For anonymous aggregate statistics this is permissible — but, as seen further on, the site treats session recording exactly the same way, and that is incorrect.
+273–1199 ms · analytics and session recording
The Sogei government analytics script loads at +273 ms. At +1198 ms the visit measurement is sent — and it carries the visitor identifier right in its parameters. And at +1199 ms a separate request launches the session-recording module for a specific identifier. Not a single cookie is set during the whole session: the identifier is passed through a request parameter rather than a cookie.

Declared versus actual

Sogei government analytics — declared as anonymous aggregate statistics with IP masking — заявлен
+ Session recording and heatmaps (HeatmapSessionRecording module) — не заявлен
+ Transmission of the visitor identifier in the measurement — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.acn.gov.it is the official portal of Italy’s National Cybersecurity Agency, the body responsible for protecting the country’s cyberspace and for promoting a culture of digital security and data protection. It is built on the Liferay platform. The capture shows 163 requests to two domains: the portal itself and the government analytics infrastructure of the provider Sogei. The policy correctly names the agency itself as the data controller, and it denies any transfer of data outside the EU — which in this case is true: everything runs on national infrastructure. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. Given what this agency does, it is held to a special standard: of all bodies, a cybersecurity agency should handle visitors’ data exemplarily. On the basic layer — yes. But one layer stands out, and it is the same one as at the Revenue Agency.

There is no consent banner. The policy classifies analytics as a technical means for which no consent need be requested. For anonymous aggregate statistics this approach is permissible. The problem is that the site treats session recording exactly the same way — as a technical tool requiring no prompt. And session recording does not fall under this rule.

The basic analytics — fine

First, what is done correctly. The basic visit counter runs on the government platform, on national infrastructure, the IP address is masked as described in the policy, and not a single cookie is set during the session. Data does not leave the EU — the policy’s promise is kept here. At this level everything matches what was declared.

The site records the session — while the policy promises only aggregates

And here is the discrepancy, and it is a serious one. Alongside the ordinary counter, a session-recording and heatmap module is active on the site. This is not a tally of “how many pages were opened in total and how much time was spent” — it is a record of a specific visitor’s behaviour: where they clicked, how they moved the cursor, how they scrolled the page — tied to an individual session identifier. By its very nature this is the opposite of the “anonymous aggregate statistics” the policy promises. The document does not mention this module by a single word — neither among the types of cookies nor in the categories of processed data. And this is not a chance one-off setting: the exact same module on the same government infrastructure was found on the Revenue Agency portal. A match across two different bodies indicates that this is a trait of the provider’s shared platform, and therefore most likely replicated on other government sites built on the same foundation.

“Anonymous” — with a caveat

The “anonymity” itself is worth clarifying too. Unlike a number of other government sites in the series, where analytics ran with no identifier at all, here the visit measurement carries the visitor identifier right in the request parameters. IP masking is indeed present, and it reduces recognisability — but the visitor identifier plus the recording of their session together make the word “anonymous” rather conditional. It would be more accurate to say “partially de-identified”.

And the final layer. The Italian regulator draws a clear distinction: technical cookies are one thing, and tools that monitor visitor behaviour are another, and for the latter explicit consent is required. Session recording is precisely behavioural monitoring. So classifying it among “technical means requiring no consent” is incorrect by the regulator’s own position. And on the site it works exactly that way: it launches automatically, with no banner, with no prompt.

What cannot be claimed from the capture

A few honest caveats. The capture covers the portal’s public home page; what happens in the sections after login is not visible from here. I do not observe any server-side configuration of the session recording beyond what is visible in the capture — the conclusion that it launches is drawn from the mere fact of the request to the module. I record the visitor identifier directly from the request parameters. The exact IP addresses of the servers are not preserved in the lightweight export, but both domains belong to government infrastructure anyway.

Conclusion

The basic layer here is done correctly: government analytics, IP masking, no transfer abroad — and this is honestly reflected in the policy. But on top of it runs the recording of individual sessions — clicks, cursor, scrolling — which is not in the policy at all, which is treated as requiring no consent, and which carries the visitor identifier. And this finding is not unique: the same platform module has already been seen on the Revenue Agency site. There is a particular bitterness in the fact that this is the site of a body whose direct mission is to promote a culture of cybersecurity and data protection. The main takeaway for the reader: even an agency that teaches others to safeguard data silently records visitors’ behaviour on its own portal — and, it seems, it is not the only one on this platform.

Evidence
Original (audit)
HAR file: it/www-acn-gov-it-2026-06-15.har
SHA-256: 2b5d113120a6633526bf12401f2460efcbf279b42bad5528d389689dc86eca41
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website acn.gov.it.

2. Circumstances
I visited the website acn.gov.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The policy states that the site uses no profiling cookies and describes its analytics as anonymous aggregate statistics — the number of pages visited and time spent on the site. In the capture, however, a separate session-recording module is active: it logs the behaviour of an individual visitor — clicks, cursor movement, scrolling — under a unique session identifier. This is a qualitatively different level of data than an aggregate counter, and the document does not mention it at all. The same module was found on the Revenue Agency portal running on the same Sogei government infrastructure — meaning this is a trait of the shared platform, not the oversight of a single site.

2) Under the Italian regulator's rules, monitoring visitor behaviour is not a technical cookie but a separate tracking tool that requires consent. The site has no consent banner at all: both the basic analytics and the session recording are treated as technical means that require no prompt. For session recording this treatment is incorrect.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-acn-gov-it/

3. Provisions violated
Art. 13(1)(e) and Art. 5(1)(a) GDPR — undeclared session recording; Art. 6(1)(a) GDPR / Italian regulator's guidance — tracking without consent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]