Technical audit · 2026-06-15

bancaditalia.it

Bank of Italy

The website of the Bank of Italy, the country's central bank. 73 requests, a single domain — not one external service. On the checked home page there are no trackers and no cookies. The policy honestly warns that certain site features carry external platforms (YouTube, X, LinkedIn) — but on the home page they are not active.

Timeline of the leak

+0–871 ms · loading its own theme
The Bank of Italy's own CMS. The code, fonts (Inter, NotoSerif) and basic resources — all from its own domain.
+1020 ms · its own cookie-notice module
The styles and script of its own cookie-notice module load. It connects no external trackers; throughout the entire session not a single cookie was set — it has nothing to hold back.
+1112–1848 ms · home-page content
Images, fonts, carousels — all from its own domain. The YouTube logo in the footer is just an image-link to the channel, not an embedded video. Not a single external request throughout the entire session.

Context

www.bancaditalia.it is the website of the Bank of Italy, the country’s central bank. It is built on its own content-management system. The capture shows 73 requests, all to a single domain. The policy correctly names the Bank of Italy itself as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. This is another clean result — but with an important caveat about coverage, one that the policy itself makes, so I will dwell on it separately.

The site has its own cookie-notice module — its styles and script load at the start of the visit. But throughout the entire session not a single cookie was set, so it essentially has nothing to hold back. This is not «a banner that does not work», but «a banner that has nothing to fire on on the home page».

Complete absence of trackers on the checked page

The picture is extremely clean: not a single external domain, not a single cookie, not a single analytics script throughout the entire session. Even the fonts are self-hosted, and the YouTube logo in the footer is just an image with a link to the bank’s channel, rather than an embedded player that would pull in Google’s infrastructure. The statistical cookies, which the policy describes as anonymous and aggregate, did not fire at all in this capture — that is, the home page is as ascetic as possible.

An honest policy — and a caveat about other pages

The document’s own conscientiousness is worth noting. The policy explicitly warns: some site features live on external platforms — YouTube/Google, X, LinkedIn — and these third parties may collect data even if the user does not use their service. This is a rare honesty by today’s standards: not «everything is clean here», but «here is where third parties may be, bear it in mind». From this follows the framing of my conclusion too. I checked the home page, and on it there are no external platforms at all. But I cannot claim that it is equally clean on the pages with embedded videos or social feeds — and the policy itself explicitly warns that third parties are likely there. So «clean» here is about the checked page, not automatically about the whole site.

What cannot be claimed from the capture

A few honest caveats. The capture covers the home page; the sections with video and social networks, about which the policy warns, I did not capture and cannot judge their behaviour. The statistical processing mentioned in the policy did not manifest on this page — perhaps it is done server-side or on other sections. The exact server addresses are not preserved in the lightweight export, but the single domain belongs to the bank anyway.

Conclusion

On the checked home page of the central bank — a clean result: no external services, no cookies, no discrepancies with the policy. The fonts are self-hosted, the analytics did not fire, the banner has nothing to hold back. And it is separately valuable that the policy does not embellish: it itself honestly names the pages where third parties may appear. The main takeaway for the reader: on the Bank of Italy’s home page no outsider learns of the visit — and where it may be otherwise, the bank honestly warns in advance.

Evidence
Original (audit)
HAR file: it/www-bancaditalia-it-2026-06-15.har
SHA-256: 0cbaa32a6394767597bb95b41199a3e707c8cad5d1821f202977e8fd55234275
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.