The website of Italy's energy, networks and environment regulator (ARERA). 124 requests, 3 domains. The analytics is government-run, anonymous, and described in the cookie policy. Most of the fonts are self-hosted. But the icon font loads from Google's servers and takes the visitor's IP to the USA — directly against the main policy's promise that data does not leave the EU.
Timeline of the leak
Declared versus actual
Detected trackers
- Web Analytics Italia government analytics (Matomo) — carries the visitor identifier, described in the cookie policy
- Google Fonts (Material Symbols icon font) — transmits the IP to the USA, named nowhere
Indicators of GDPR non-compliance
- Art. 13(1)(f) GDPR — transmission of the IP to the USA against the «EU only» promiseThe main policy explicitly states that personal data is processed within the European Union and stored on servers inside the EU. Yet the site loads the Material Symbols icon font directly from Google's servers (fonts.googleapis.com), and every such request transmits the visitor's IP address to Google — a US company. This service is named neither in the main policy nor in the separate cookie policy. That is, the promise «data does not leave the EU» diverges from the fact, and the recipient is not disclosed.
- Art. 13(1)(e) GDPR — the cookie section is absent from the exported documentThe main policy refers to the Cookie Policy section «below», but in the exported document it is absent — the text breaks off at the data-subject rights. In fairness: the site does have a separate cookie policy, it is available on the resource itself and describes anonymous analytics. So this is about the incompleteness of the export specifically, not the absence of the section as such.
Context
www.arera.it is the website of ARERA, the Italian regulator for energy, networks and the environment: tariffs for electricity, gas, water, waste management. It is built on TYPO3. The capture shows 124 requests to three domains: the site itself, the government analytics and Google’s font servers. The policy correctly names the authority itself as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. Let me note the good straight away: the site keeps its main typography self-hosted — the roboto and zilla-slab fonts load from its own domain rather than from Google. Only one request goes out to Google — for the icon font. And it is precisely that one that creates the single, but real, problem.
Was there a consent banner
There is a cookie-management module on the site, but it connects late — at +3541 ms, after the government analytics has already sent its measurement (+3184 ms). For anonymous government statistics, equated to technical means, consent is not required, so in itself this is not a violation. It is only worth noting that the analytics measurement carries the visitor identifier, so the «anonymity» here, as on a number of other government sites, is more «de-identification with IP masking» than complete impersonality.
What is done mostly right
The analytics here is a government platform on national infrastructure, with IP masking by default, and it sets not a single cookie during the session. And, unlike what it seemed from the incomplete export, the site does have a separate cookie policy: on the resource itself it is available and describes this anonymous analytics as technical cookies requiring no consent. That is, the analytics layer is both disclosed and correctly implemented. This must be recorded honestly.
Google Fonts takes the IP to the USA — while the policy promises «EU only»
And here is the single real flaw. The main policy contains an unambiguous promise: personal data is processed within the European Union and stored on servers inside the EU. Meanwhile the site loads the Material Symbols icon font not from its own server, but directly from Google’s servers. And any such request transmits the visitor’s IP address to Google — an American company. Here two discrepancies come together. First, this directly contradicts the promise that data does not leave the EU. Second, Google as a recipient is named nowhere — neither in the main policy nor in the separate cookie policy. And most notable of all is that it is fixed trivially: the site has already placed its main typography with itself, so putting the icon font alongside it is a single step, after which the last request to Google disappears.
What cannot be claimed from the capture
A few honest caveats. On the IP masking in the analytics I rely on its default configuration and on the cookie policy; in the capture itself the visitor identifier is visible, but not a cookie. The separate cookie policy I read from the available publication rather than exporting in full, so I vouch for the description of the anonymous analytics but not for an exhaustive list of all the services mentioned in it. The capture covers the home page; the exact server addresses are not preserved in the lightweight export.
Conclusion
In essence the site is done mostly right: government anonymous analytics, described in a separate cookie policy, and almost all the typography on its own domain. The only thing that stands out is the icon font, which is pulled from Google’s servers and takes the visitor’s IP to the USA, directly against the policy’s promise to keep data within the EU, and without a mention anywhere. The flaw is small and fixed with a single move, but on the site of a regulator promising «EU only», even one such leak is a divergence of word and deed. The main takeaway for the reader: almost everything here is honest and European, except one line of code that sends your IP across the ocean.
cbdc0449fa27ca6ae788c0517257697ed701059457413b479ff3fb1e0694d728Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website arera.it. 2. Circumstances I visited the website arera.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The main policy explicitly states that personal data is processed within the European Union and stored on servers inside the EU. Yet the site loads the Material Symbols icon font directly from Google's servers (fonts.googleapis.com), and every such request transmits the visitor's IP address to Google — a US company. This service is named neither in the main policy nor in the separate cookie policy. That is, the promise «data does not leave the EU» diverges from the fact, and the recipient is not disclosed. 2) The main policy refers to the Cookie Policy section «below», but in the exported document it is absent — the text breaks off at the data-subject rights. In fairness: the site does have a separate cookie policy, it is available on the resource itself and describes anonymous analytics. So this is about the incompleteness of the export specifically, not the absence of the section as such. Full technical documentation is published at: https://gdpru.eu/en/audits/it-arera-it/ 3. Provisions violated Art. 13(1)(f) GDPR — transmission of the IP to the USA against the «EU only» promise; Art. 13(1)(e) GDPR — the cookie section is absent from the exported document 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]