The website of the Italian Medicines Agency (AIFA). 73 requests, 3 domains. The policy explicitly promises that only government analytics is used and no other tracking methods. In fact, the same visit is written simultaneously by two independent counters — the national one and the agency's own Piwik, not mentioned in the document. Meanwhile nothing goes abroad.
Timeline of the leak
Declared versus actual
Detected trackers
- Web Analytics Italia government analytics — carries the visitor identifier
- AIFA's own Piwik (servizionline.aifa.gov.it) — a second counter, not mentioned in the policy
Indicators of GDPR non-compliance
- Art. 13(1)(e) and Art. 5(1)(a) GDPR — two counters instead of the one promisedThe policy categorically names the government platform Web Analytics Italia as the sole analytics tool and states verbatim: «other tracking and profiling methods are not used». In the capture, however, a second, separate counter works in parallel with it — AIFA's own Piwik on the subdomain servizionline.aifa.gov.it. Both record the same visit, in the same millisecond, and each carries the visitor identifier. The second tool is not mentioned in the document at all, which directly refutes the phrase about the «absence of other methods».
Context
www.aifa.gov.it is the website of the Italian Medicines Agency (AIFA), the regulator for pharmaceuticals. It is built on the Liferay platform. The capture shows 73 requests to three domains: the site itself, its own analytics subdomain, and the government analytics platform. The policy correctly names the agency itself as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. This site has a sensitive audience: people come here to read about medicines, and which specific pages about drugs a person opens can indirectly say something about their health. So precision about who counts visitors and how matters here more than usual.
Was there a consent banner
There is a cookie bar on the site — its styling loads together with the page. But it does not hold back the analytics: the counters run independently of it. For government anonymous statistics, equated to technical means, consent is not required anyway. So the problem here is not the banner or the timing, but how many counters actually work and whether this matches the policy’s promise.
The same visit — recorded twice
The main finding is simple and clear. At the same moment, at +1350 ms, the site sends two different measurements of the same visit: one to the national government platform Web Analytics Italia, the second to the agency’s own counter on its subdomain (this is Piwik, the former name of the same Matomo system). Two independent analytics tools record one visit in parallel.
The policy promised only one tool — and «nothing more»
And here is the discrepancy. The policy does not merely name the government platform as the main tool — it categorically adds that no other tracking and profiling methods are used. This is a closed formulation, leaving no room for a second counter. Meanwhile the second counter exists, works on every visit, and is not mentioned in the document by a single word. Most likely there is no malicious intent behind this: it most resembles an old in-house counter that stayed running after the agency migrated to the new national platform — it was simply forgotten and not switched off. But for the user and for the letter of the document this does not much matter: the policy explicitly asserts that there are no other methods, and there are. The promise and the fact diverge.
«Anonymous» and «without profiling» — with a caveat
The anonymity is worth clarifying too. Both measurements carry the visitor identifier — a marker by which a person can be recognised between visits. IP masking and aggregate use may keep this within the bounds of technical statistics, but a persistent identifier, and in two systems at once, sits poorly with the explicit promise of «no profiling». It would be more accurate to say that the de-identification here is partial.
Where the data goes — nowhere abroad
An important plus that must be named. Both counters are government-run and first-party: one on the agency’s own infrastructure, the other on the national platform. There is no Google, no social networks, no foreign recipients in this visit, and nothing leaves the country. The Google service for the application mentioned in the policy concerns only the mobile app and only when subscribing to notifications — on the site itself it is not engaged.
What cannot be claimed from the capture
A few honest caveats. I offer the version of the «old counter forgotten during migration» as the most plausible explanation, but intent cannot be determined from the capture — I record the mere fact of the double counting. The contents of the measurements go out in the body of the request, which is not fully preserved in the lightweight export; the visitor identifier, however, is visible right in the parameters. The capture covers the home page. Both domains are government-run, so the question of the servers’ geography does not arise here.
Conclusion
Where the data goes — everything is fine here: only government infrastructure, nothing abroad. But the policy’s categorical promise — «only government analytics is used and no other tracking methods» — is directly refuted by the fact: two independent counters work in parallel on the site, and each carries the visitor identifier. Most likely this is a legacy of migration rather than intent — but on the site of a medicines agency, where the pages read can indirectly say something about health, the divergence between «we count you by one declared method» and «in fact by two, and one is not named» is exactly the kind of inaccuracy that matters.
8af53d3b77403b6228435b7662acc7962db3a5d769baa8896cbebe9dc381ba56Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website aifa.gov.it. 2. Circumstances I visited the website aifa.gov.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The policy categorically names the government platform Web Analytics Italia as the sole analytics tool and states verbatim: «other tracking and profiling methods are not used». In the capture, however, a second, separate counter works in parallel with it — AIFA's own Piwik on the subdomain servizionline.aifa.gov.it. Both record the same visit, in the same millisecond, and each carries the visitor identifier. The second tool is not mentioned in the document at all, which directly refutes the phrase about the «absence of other methods». Full technical documentation is published at: https://gdpru.eu/en/audits/it-aifa-gov-it/ 3. Provisions violated Art. 13(1)(e) and Art. 5(1)(a) GDPR — two counters instead of the one promised 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]