Technical audit · 2026-06-15

cnr.it

National Research Council of Italy

The website of the National Research Council of Italy (CNR), Drupal. 64 requests, 3 domains — all its own. Two Matomo instances work in parallel, and neither is named in the policy. But this is the most private variant of analytics in the series: both are cookieless, without an identifier, nothing leaves CNR. The only question is about disclosure.

Timeline of the leak

+0–156 ms · portal load
A Drupal site, on a standard theme. All resources, including fonts, come from its own domain.
not applicable — there is no banner, and it is not needed
There is no consent banner. The policy permits only technical session cookies, for which consent is not required. And since the analytics here works without cookies at all, there really is nothing to ask consent for.
+564–582 ms · two parallel Matomos
The script and measurement of the first Matomo (idsite=20) at +564–579 ms, the measurement of the second (idsite=1) at +582 ms — two different instances record the same page view practically within one millisecond of each other. Both are on CNR's own subdomains, both without a visitor identifier. Not a single cookie throughout the entire session.

Declared versus actual

+ Matomo (metrics.cedrc.cnr.it, idsite=20) — cookieless — не заявлен
+ Matomo (matomo.rsi.cnr.it, idsite=1) — cookieless — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.cnr.it is the website of the Consiglio Nazionale delle Ricerche, Italy’s principal state research institution. It is built on Drupal. The capture shows 64 requests to three domains — and all three belong to CNR itself. The policy correctly names the council itself as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. This is an interesting case, because formally there is something to nitpick here, while in essence the site behaves almost exemplarily. I will lay out both sides honestly.

There is no consent banner, and it is not needed. The policy permits only technical session cookies, for which consent is not required by law. And since the analytics on this site works without cookies at all, there really is nothing to ask consent for. The absence of a banner here is entirely natural.

Two Matomo instances at once

A technical peculiarity of the site: two different, unconnected Matomo counters work on it in parallel — on two different CNR subdomains, with different site identifiers. Both record the same visit, practically within one millisecond of each other. This most resembles a situation where two departments of a large institution each set up their own counter, and both were left running on the shared site. The case recalls the medicines agency from this series, which also had two Matomos — but with two differences, and both in CNR’s favour.

But this is the most private variant of analytics in the series

Here is the side that is important to name directly. Both counters here work without a single cookie and without a visitor identifier — that is, they assign the person no marker by which they could be recognised between visits. Both are hosted on CNR’s own domains, nothing goes to Google or any third-party services, nothing is transmitted beyond the institution. This means that the policy’s explicit statement — «cookies are not used for profiling» — is the plain truth here. Of all the analysed sites where analytics works at all, this is perhaps the most private implementation of it: they count visits, but do not track the person. The difference from the medicines agency is exactly this: there both counters carried a visitor identifier, here neither does. But there at least one of the two was named in the policy, while here neither is — and this is the only real nitpick.

What is missing — only the declaration

The flaw comes down to disclosure. The policy describes only technical session cookies and does not set out statistics as a separate category at all — there are no words in the document about the site conducting analytics, albeit anonymous. So formally any analytics tool here turns out to be undeclared, and there are two of them at that. This is a question of the precision and completeness of informing, not of data security: the visitor ought to know that their visits are being counted, even if counted in an utterly harmless way.

What cannot be claimed from the capture

A few honest caveats. The conclusion that both counters work without an identifier I draw from the capture itself — there is neither a cookie nor a visitor identifier in it. The version of «two departments, two counters» is the most plausible explanation, but intent cannot be determined from the capture; I record the mere fact of the double counting. The capture covers the home page; the exact server addresses are not preserved in the lightweight export, but all three domains belong to CNR anyway.

Conclusion

Unlike the heavy commercial cases in the series, here the data-processing practice itself is almost exemplary: two first-party counters, both without cookies and without an identifier, nothing leaves CNR, there is no profiling — and this is not a promise but an observable fact. The only thing there is a complaint about is that neither of the two tools is named in the policy, and that the analytics is not set out in it as a separate category at all, while there are for some reason two counters. The main takeaway for the reader: there is such a thing as «undeclared yet harmless» — and this is exactly such a case; the site need only honestly add to the policy what it already does more carefully than many.

Evidence
Original (audit)
HAR file: it/www-cnr-it-2026-06-15.har
SHA-256: ecdf07517d93aa798ecc18ce114099d370d92e1b89bb94f3a92158f18ee22604
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website cnr.it.

2. Circumstances
I visited the website cnr.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The policy describes only technical session cookies and explicitly states that there is no profiling; there is no separate category of statistical/analytics cookies in the document at all. In fact, two independent Matomo instances work in parallel on the site — metrics.cedrc.cnr.it (idsite=20) and matomo.rsi.cnr.it (idsite=1) — both recording the same visit almost simultaneously. An important caveat in the site's favour: both work without cookies and without a visitor identifier, entirely on CNR's own domains, so the promise «no profiling» is truthful here. The violation here is in the incompleteness of disclosure (the analytics tool is not named and not set out as a separate category), not in a data leak.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-cnr-it/

3. Provisions violated
Art. 13(1)(e) GDPR — analytics not disclosed (though harmless in essence)

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]