Technical audit · 2026-06-15

cittametropolitana.mi.it

Metropolitan City of Milan

The website of the Metropolitan City of Milan. 65 requests, 5 domains. The analytics is government-run, anonymous, and named in a separate cookie policy. But the main policy categorically promises not to transfer data outside the EEA — while the Google fonts take the visitor's IP to the USA, and in full families and named nowhere at that.

Timeline of the leak

+0–2915 ms · portal load
The portal runs on the outdated OpenCms system with a legacy URL structure. The theme resources come from its own domain.
not applicable — there is no consent banner
No consent banner was found. Government anonymous analytics is equated to technical means and requires no consent, so the absence of a banner is not in itself a violation. But Google Fonts, meanwhile, loads unconditionally.
+3047–4078 ms · Google Fonts and analytics
At +3047 ms three requests for font families go out to Google's servers, at +3567–3738 ms the font files themselves from the same place. The government analytics loads at +3723 ms and sends a measurement at +4078 ms — and the measurement carries the visitor identifier. Not a single cookie throughout the entire session.

Declared versus actual

Web Analytics Italia government analytics (named on the separate cookie page as anonymous) — declared
+ Google Fonts (full font families) — transmission of the IP to the USA, named nowhere — not declared

Detected trackers

Indicators of GDPR non-compliance

Context

www.cittametropolitana.mi.it is the website of the Metropolitan City of Milan, a level of local government between the region and the municipalities. It is built on the outdated OpenCms system with a characteristic legacy URL structure. The capture shows 65 requests to five domains: the site itself and its utility subdomain, the government analytics and Google’s font servers. The policy correctly names the metropolitan city itself as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. This is again a case familiar from the series, and again with a refinement in favour of precision that surfaced on comparison with the live site.

There is no consent banner. Government anonymous analytics under Italian rules is equated to technical means and requires no consent, so the absence of a banner is not in itself a violation here. It is only worth noting that the analytics measurement carries the visitor identifier, so the «anonymity» here, as on a number of other government sites, means more de-identification with IP masking than complete impersonality. But the Google fonts, meanwhile, load unconditionally, without depending on any consent.

What turned out about the policy

Here is an important correction to the first impression. The exported document — the main policy — indeed contains not a word about cookies. But this does not mean the section is absent altogether: the site has a separate cookie page, available on the resource itself, and on it the Web Analytics Italia government analytics is named directly and described as anonymous statistics equated to technical cookies. That is, the analytics layer is both disclosed and correctly implemented — the gap was in the export, not on the site. This must be recorded honestly, so as not to log as a violation something that is actually disclosed.

Google Fonts takes the IP to the USA — while the policy promises «EEA only»

And this is the real and confirmed flaw. The main policy contains a categorical promise: data is not transferred to third countries outside the European Economic Area. Meanwhile the site loads the fonts not from its own server, but directly from Google’s servers — and to the full extent at that: both the font-style description and the family files themselves (Roboto and others). And any such request transmits the visitor’s IP address to Google, an American company. Here there are two coinciding discrepancies. First, this directly contradicts the promise to keep data within the EEA. Second, Google as a recipient is named nowhere — neither in the main policy nor on the separate cookie page. And this is not a theoretical quibble: European courts have already issued rulings that precisely this loading of Google fonts from its servers is an unlawful transfer of the user’s IP address, and the only lawful path in the absence of consent is to place the fonts on one’s own server. Here, however, they are pulled from Google in full families.

What cannot be claimed from the capture

A few honest caveats. The separate cookie page I read from the available publication rather than exporting in full, so I vouch that the government analytics is named there, but I cannot claim with one-hundred-percent completeness that Google Fonts is mentioned nowhere at all in its text — in the part I saw, it is not there. On the IP masking in the analytics I rely on its default configuration; in the capture the visitor identifier is visible, but not a cookie. The capture covers the home page; the exact server addresses are not preserved in the lightweight export.

Conclusion

As in the case of the energy regulator from this series, the first impression had to be refined: the government analytics is in fact disclosed — on a separate cookie page that was not in the export. But the main policy’s categorical promise — «data does not leave the EEA» — is directly refuted by the Google fonts, which take the visitor’s IP to the USA, and in full families and without a single mention anywhere at that. The flaw is small in volume and fixed with a single move — moving the fonts to one’s own server — but it is precisely the divergence of word and deed on which there is already case law in Europe. The main takeaway for the reader: almost everything here is European and honestly disclosed, except the fonts, which silently send your IP across the ocean in defiance of an explicit promise to the contrary.

Evidence
Original (audit)
HAR file: it/www-cittametropolitana-mi-it-2026-06-15.har
SHA-256: cb1d7f07da2d6c4ab2a78bb111654240fe4a48492ff8ae82305994cf0c61134c
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website cittametropolitana.mi.it.

2. Circumstances
I visited the website cittametropolitana.mi.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The main policy explicitly and categorically states: «data is not transferred to third countries outside the European Economic Area». Yet the fonts (Roboto and other families) are loaded directly from Google's servers — both the style description and the font files themselves — and every such request transmits the visitor's IP address to Google, a US company. Google Fonts is named neither in the main policy nor on the separate cookie page. This is a direct divergence of promise from fact. It is precisely this practice — loading Google fonts from Google's servers — that European courts have already found to be an unlawful transfer of the IP address.

2) The main policy contains not a word about cookies. In fairness: the site has a separate cookie page, available on the resource itself, and on it the Web Analytics Italia government analytics is named and described as anonymous. So the analytics is essentially disclosed — the gap is in the export, not on the site. The only thing disclosed nowhere is Google Fonts.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-cittametropolitana-mi-it/

3. Provisions violated
Art. 13(1)(f) and Art. 44 GDPR — transmission of the IP to the USA against the «EEA only» promise; Art. 13(1)(e) GDPR — the cookie section is absent from the exported document

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]