Technical audit · 2026-06-15

cni.it

National Council of Engineers of Italy

The website of the National Council of Engineers of Italy (CNI), Joomla. 46 requests, 6 domains. The policy names Google Analytics with processing in the USA — but it is not on the site; what actually works is Matomo on the foundation's domain. But this does not make it «more private than declared»: the visitor's IP still goes to Google in the USA — via jQuery and Google fonts, named nowhere.

Timeline of the leak

+0–176 ms · loading the Joomla stack
A Joomla site. Already at +172 ms the jQuery library from Google's servers connects, at +176 ms the consent-banner script from the Cloudflare CDN.
+176–289 ms · banner and analytics almost simultaneously
The Google fonts load at +201–212 ms. Matomo sends a measurement at +275 ms — before the visual part of the consent banner loads (+289 ms). The visitor identifier is present in the measurement.
+231–275 ms · Matomo, not Google Analytics
The Matomo script and measurement from the foundation's domain (idsite=22). Not a single request to Google Analytics domains throughout the entire session. Not a single cookie. Meanwhile the IP has already gone to Google — via jQuery and fonts.

Declared versus actual

Google Analytics (named in the policy, but absent from the site) — заявлен
+ Matomo (matomo.fondazionecni.org) — the real analytics, not named — не заявлен
+ jQuery from Google's servers and Google Fonts — real transmission of the IP to the USA, not named — не заявлен
+ Cloudflare CDN (banner script) — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.cni.it is the website of the Consiglio Nazionale degli Ingegneri, the National Council of Engineers of Italy: a professional body of public-law status that maintains the register of engineers. It is built on Joomla, the policy drawn up from a boilerplate builder template. The capture shows 46 requests to six domains. The policy correctly names the council itself as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. At first glance this is a simple case of «named the wrong counter». But on careful reading of the capture it turns out to be more interesting — and in one place the opposite of the first impression.

There is a consent banner on the site, its script loads from an external CDN at the very start. But by the moment its visible part loads (+289 ms), the Matomo analytics has already sent its measurement (+275 ms). For first-party analytics equated to technical means, consent is not required, so in itself this is not a violation. I will only note that the measurement carries the visitor identifier, so the «anonymity» here, as on a number of other sites, comes with a caveat.

The wrong analytics is named

The policy unambiguously names Google Analytics as the sole statistics tool, and with a direct indication of the place of processing — the USA. But in the capture there is not a single request to Google Analytics domains. Visitors are counted by an entirely different system — Matomo, hosted on the affiliated foundation’s domain (Fondazione CNI). This analytics is decent in itself: first-party in essence, without setting cookies. But it is not mentioned in the document, while a service that is not on the site is named.

«More private than declared» — this is not so: the IP still goes to Google

Here is the correction that is easy to miss and that overturns the simple reading. It is tempting to say: since instead of the American Google Analytics there is one’s own Matomo, then in fact it is more private than promised. But this is wrong. In the capture the visitor’s IP address still goes to Google, in the USA — only not via the analytics, but via two other things: the jQuery library, which the site pulls directly from Google’s servers, and the Google Fonts. Plus the consent-banner script loads from the Cloudflare company’s CDN. That is, a transfer of data across the ocean does exist here, it just goes through channels other than the one described in the policy.

The document describes the wrong transfer

From this a curious picture of mismatch in both directions forms. The policy warns of a transfer of data to the USA — but ties this warning to Google Analytics, which is not on the site. While the real transfers of the IP to Google — via jQuery and fonts — are not mentioned in the document at all. It turns out the visitor is warned of exactly what does not happen, and kept silent about exactly what does. For conscientious informing this is worse than a simple typo in the name: the document does not match reality either in what it asserts or in what it stays silent about.

What cannot be claimed from the capture

A few honest caveats. On Matomo’s first-party nature and absence of cookies I judge from the capture itself — the visitor identifier is visible in it, but there is no cookie. Whether jQuery and the Google fonts are «strictly necessary technical» components is a matter of interpretation; but even in that case the transmission of the IP to Google remains a fact, and it is not reflected in the policy. The capture covers the home page; the exact server addresses are not preserved in the lightweight export.

Conclusion

The choice of analytics here is rather a plus: instead of the American Google Analytics — one’s own Matomo on the foundation’s domain, without cookies. But the document describes reality wrongly in two senses at once. It names Google Analytics as the statistics tool, which is not there, and warns of the associated transfer to the USA — also non-existent. And meanwhile it stays silent about the real transfers of the IP to Google that do occur on the site — via jQuery and fonts. The main takeaway for the reader: «more private in words» and «more private in fact» are not the same thing; here good analytics in essence coexists with quiet leaks to Google that the policy does not mention, while it warns in detail about what is not on the site.

Evidence
Original (audit)
HAR file: it/www-cni-it-2026-06-15.har
SHA-256: e32466e0aab7fb929e163bcce8a12313495f6f685d6ffcb46832115300902b6a
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website cni.it.

2. Circumstances
I visited the website cni.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The policy unambiguously names Google Analytics (Google Inc.) as the sole statistics tool, specifying the place of processing — the USA. In the capture there is not a single request to Google Analytics domains. What actually works is Matomo, hosted on the affiliated foundation's domain (matomo.fondazionecni.org). The analytics itself is decent — first-party in essence, without cookies — but it is not named in the document at all, while a service that is not present is named.

2) The policy warns of a transfer of data to the USA in relation to Google Analytics, which is not on the site. Meanwhile real transfers of the IP address to Google in the USA do nonetheless occur — via the jQuery library loaded from Google's servers, and via the Google Fonts. These requests are not mentioned in the document. Thus the description of the transfer is wrong in both directions: they warn of what is not there, and stay silent about what is.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-cni-it/

3. Provisions violated
Art. 13(1)(e) GDPR — the wrong analytics tool is named; Art. 13(1)(f) GDPR — the wrong transfer abroad is described

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]