The website of Italy's Digital Agency — the body that itself writes the formatting rules for all the country's government sites and recommends government analytics to them. 52 requests, 4 domains. The cookie policy here is exemplary: every cookie is named, with its lifetime and purpose, and everything matches the capture. The only hole is the Google fonts, which transmit the visitor's IP to the USA in defiance of the policy's explicit promise not to transfer data anywhere outside the EU.
Timeline of the leak
Declared versus actual
Detected trackers
- Web Analytics Italia government analytics (Matomo) — precisely declared
- Google Fonts — undeclared, transmit the visitor's IP to the USA
Indicators of GDPR non-compliance
- Art. 13(1)(f) and Art. 44 GDPR — data transfer to the USA via fontsThe policy explicitly states that data is not transferred to third countries, and the list of data recipients names only the agency's staff and technical contractors. Yet three font families (Noto Sans, Roboto Mono, Titillium Web) are loaded directly from Google's servers in the USA, rather than from a local delivery. Each such load transmits the visitor's IP address to Google — that is, both a transfer outside the EU, which the policy denies, and a data recipient that is not in the policy. Courts in the EU have already found precisely this practice — loading Google fonts from Google's servers — to be an unlawful transfer of the IP address.
Context
www.agid.gov.it is the website of Italy’s Digital Agency. This is no ordinary body: it is AgID that writes the formatting and privacy rules for all the country’s government sites, and it is AgID that recommends government analytics to the rest instead of foreign analytics. That is, from this site one can reasonably judge how well the very author of the rules complies with them. I read the live policy in full — it is open and accessible, with the last update marked May 2024. The document states two things important for the analysis: that only the listed technical cookies are used, and that no transfer of data to third countries or international organisations is envisaged. The site is built on Drupal; the capture shows 52 requests to four domains.
Was there a consent banner
There is no banner — and this is the rare case where its absence is lawful. The site uses only technical cookies and government analytics, which under Italian rules is equated to technical means and requires no consent. There is simply nothing to ask consent for, and so there is no banner. This is important to say plainly: the empty space where the banner would be is not an oversight here, but a natural outcome.
The exemplary part — credit where due
Before speaking of the hole, honestly about what is done right, because against the backdrop of other sites this stands out. The policy names every cookie by name, with an exact lifetime and purpose: the return-visits identifier for 13 months, the session identifier for 30 minutes, the editor’s utility cookie and the load-balancer cookie. Everything listed matches what is seen in the capture one to one. No session recording, no hidden modules, nothing beyond the government infrastructure as far as analytics goes. This is the most accurate and honest cookie policy in the whole series of analysed sites.
The only hole — Google fonts
And against this impeccable backdrop the single gap stands out all the more. Three font families — Noto Sans, Roboto Mono and Titillium Web — are loaded not from the site’s local delivery, but directly from Google’s servers. And any request to a Google server automatically transmits the visitor’s IP address to it, and those servers are in the USA. Here two discrepancies with the policy come together at once. First, the document explicitly promises that data does not leave the EU — yet it does, to Google, on every page load. Second, in the list of those who receive data, the policy names only the agency’s staff and technical contractors; Google is not there at all. And this is not a theoretical quibble: courts in the EU have already issued rulings that precisely this loading of Google fonts from Google’s servers is an unlawful transfer of the user’s IP address. It is fixed trivially — the fonts are simply placed on one’s own server, and the requests to Google disappear.
Why here this is not a trifle
Technically the hole is tiny — just fonts. But the place where it was found gives it weight. AgID is the body that writes the design standard and privacy rules for all the other government sites, and many of them inherit the same template and the same design theme. Tellingly, word for word the same phrase «data is not transferred to third countries» stands on dozens of sites across the whole AgID ecosystem. If the common template pulls Google fonts from their servers, then exactly the same leak and exactly the same false promise are replicated across the whole chain of dependent sites — and then this is no longer an isolated oversight, but a defect of the standard. There is also a direct regulatory touch. When the Italian regulator at one time approved AgID’s design rules, it separately reminded: in relations with suppliers located in third countries, the data-transfer rules must be observed. That is, the author of the standard was explicitly warned about precisely this class of problems — and on its own site it stumbled on exactly that.
What cannot be claimed from the capture
A few honest caveats. The capture covers only the home page. The cookie lifetimes are stated in the policy itself, but they cannot be confirmed in the capture — these cookies are set by a script on the browser side, rather than arriving in the headers. And separately: the government analytics itself, which AgID recommends as a «European» alternative, in this capture responds from an address in the Amazon cloud range; Amazon’s European regions are within the EU, and the exact region is not visible from the capture, so I do not raise a separate transfer complaint here — I note it only as an observation.
Conclusion
This is the best site in the series in terms of the honesty of its policy — and that is precisely why the single hole in it is so telling. The cookie policy is exemplary, consent is not required and is justifiably absent, the analytics is government-run and precisely described. But the Google fonts transmit the visitor’s IP to the USA on every visit — directly against the promise not to hand data anywhere outside the EU, and bypassing the list of recipients, where Google does not appear. This is fixed with a single move — moving the fonts to one’s own server. The main takeaway for the reader: even the author of the rules makes mistakes, and since its template is inherited by dozens of other government sites, this trifle is almost certainly not its alone.
8a062754617f2966c80aae725ebb0df5c128cbea5f5d80ef92a53d842fef32bdWhere to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website agid.gov.it. 2. Circumstances I visited the website agid.gov.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The policy explicitly states that data is not transferred to third countries, and the list of data recipients names only the agency's staff and technical contractors. Yet three font families (Noto Sans, Roboto Mono, Titillium Web) are loaded directly from Google's servers in the USA, rather than from a local delivery. Each such load transmits the visitor's IP address to Google — that is, both a transfer outside the EU, which the policy denies, and a data recipient that is not in the policy. Courts in the EU have already found precisely this practice — loading Google fonts from Google's servers — to be an unlawful transfer of the IP address. Full technical documentation is published at: https://gdpru.eu/en/audits/it-agid-gov-it/ 3. Provisions violated Art. 13(1)(f) and Art. 44 GDPR — data transfer to the USA via fonts 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]