Technical audit · 2026-06-15

arera.it

Italy's Energy, Networks and Environment Regulator

The website of Italy's energy, networks and environment regulator (ARERA). 124 requests, 3 domains. The analytics is government-run, anonymous, and described in the cookie policy. Most of the fonts are self-hosted. But the icon font loads from Google's servers and takes the visitor's IP to the USA — directly against the main policy's promise that data does not leave the EU.

Timeline of the leak

+0–2170 ms · portal load
The portal runs on TYPO3, on a standard government theme. The main fonts (roboto, zilla-slab) load from its own domain.
+2172–3556 ms · the Google font and analytics before the consent module
At +2172 ms a request for the Material Symbols icon font goes out to Google's servers — the only outward call to Google. The government analytics loads at +2221 ms and sends a measurement at +3184 ms — and the measurement carries the visitor identifier. The cookie-management module connects only at +3541–3556 ms, after the analytics has already fired.
not applicable
The rest of the session is static theme resources. Not a single cookie throughout the entire session.

Declared versus actual

Web Analytics Italia government analytics (described in the separate cookie policy as anonymous) — заявлен
+ Google Fonts (Material Symbols icon font) — transmission of the IP to the USA, named nowhere — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.arera.it is the website of ARERA, the Italian regulator for energy, networks and the environment: tariffs for electricity, gas, water, waste management. It is built on TYPO3. The capture shows 124 requests to three domains: the site itself, the government analytics and Google’s font servers. The policy correctly names the authority itself as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. Let me note the good straight away: the site keeps its main typography self-hosted — the roboto and zilla-slab fonts load from its own domain rather than from Google. Only one request goes out to Google — for the icon font. And it is precisely that one that creates the single, but real, problem.

There is a cookie-management module on the site, but it connects late — at +3541 ms, after the government analytics has already sent its measurement (+3184 ms). For anonymous government statistics, equated to technical means, consent is not required, so in itself this is not a violation. It is only worth noting that the analytics measurement carries the visitor identifier, so the «anonymity» here, as on a number of other government sites, is more «de-identification with IP masking» than complete impersonality.

What is done mostly right

The analytics here is a government platform on national infrastructure, with IP masking by default, and it sets not a single cookie during the session. And, unlike what it seemed from the incomplete export, the site does have a separate cookie policy: on the resource itself it is available and describes this anonymous analytics as technical cookies requiring no consent. That is, the analytics layer is both disclosed and correctly implemented. This must be recorded honestly.

Google Fonts takes the IP to the USA — while the policy promises «EU only»

And here is the single real flaw. The main policy contains an unambiguous promise: personal data is processed within the European Union and stored on servers inside the EU. Meanwhile the site loads the Material Symbols icon font not from its own server, but directly from Google’s servers. And any such request transmits the visitor’s IP address to Google — an American company. Here two discrepancies come together. First, this directly contradicts the promise that data does not leave the EU. Second, Google as a recipient is named nowhere — neither in the main policy nor in the separate cookie policy. And most notable of all is that it is fixed trivially: the site has already placed its main typography with itself, so putting the icon font alongside it is a single step, after which the last request to Google disappears.

What cannot be claimed from the capture

A few honest caveats. On the IP masking in the analytics I rely on its default configuration and on the cookie policy; in the capture itself the visitor identifier is visible, but not a cookie. The separate cookie policy I read from the available publication rather than exporting in full, so I vouch for the description of the anonymous analytics but not for an exhaustive list of all the services mentioned in it. The capture covers the home page; the exact server addresses are not preserved in the lightweight export.

Conclusion

In essence the site is done mostly right: government anonymous analytics, described in a separate cookie policy, and almost all the typography on its own domain. The only thing that stands out is the icon font, which is pulled from Google’s servers and takes the visitor’s IP to the USA, directly against the policy’s promise to keep data within the EU, and without a mention anywhere. The flaw is small and fixed with a single move, but on the site of a regulator promising «EU only», even one such leak is a divergence of word and deed. The main takeaway for the reader: almost everything here is honest and European, except one line of code that sends your IP across the ocean.

Evidence
Original (audit)
HAR file: it/www-arera-it-2026-06-15.har
SHA-256: cbdc0449fa27ca6ae788c0517257697ed701059457413b479ff3fb1e0694d728
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website arera.it.

2. Circumstances
I visited the website arera.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The main policy explicitly states that personal data is processed within the European Union and stored on servers inside the EU. Yet the site loads the Material Symbols icon font directly from Google's servers (fonts.googleapis.com), and every such request transmits the visitor's IP address to Google — a US company. This service is named neither in the main policy nor in the separate cookie policy. That is, the promise «data does not leave the EU» diverges from the fact, and the recipient is not disclosed.

2) The main policy refers to the Cookie Policy section «below», but in the exported document it is absent — the text breaks off at the data-subject rights. In fairness: the site does have a separate cookie policy, it is available on the resource itself and describes anonymous analytics. So this is about the incompleteness of the export specifically, not the absence of the section as such.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-arera-it/

3. Provisions violated
Art. 13(1)(f) GDPR — transmission of the IP to the USA against the «EU only» promise; Art. 13(1)(e) GDPR — the cookie section is absent from the exported document

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]