The website of the city of Rome (Roma Capitale). 272 requests, 23 domains. Two parallel Matomos, Google Analytics 4, a chatbot via Microsoft's infrastructure, Google translation, an accessibility widget and a video portal — an extensive technology stack, of which the policy names not a single tool, limiting itself to general navigation data and social-network plugins.
Timeline of the leak
Declared versus actual
Detected trackers
- Matomo (/matomo/, idsite=1) — carries the visitor identifier
- Matomo (/matomo-apprc/, idsite=5) — carries the visitor identifier
- Google Analytics 4 (G-FWY4SWRLK5) — real hits without a consent flag
- Julia chatbot via Microsoft Bot Framework (europe.directline.botframework.com)
- Google Translate (translate.google.com, translate.googleapis.com)
- AccessiWay (acsbapp.com, embeds.accessiway.com) — accessibility widget
- Streamcloud (collector-ovp.streamcloud.it) — video portal
- Iubenda (accessibility widget)
Indicators of GDPR non-compliance
- Art. 13(1)(e) GDPR — the real stack is not declaredThe policy describes only general navigation data and, separately, social-network plugins (with the caveat that without active use they set no cookies). In reality, two Matomo instances (both with a visitor identifier), Google Analytics 4, a chatbot via Microsoft's infrastructure, Google Translate, the AccessiWay accessibility widget and a video portal on the Streamcloud platform work on the site. Not one of these tools is named in the policy.
- Art. 13(1)(f) GDPR — transfer to the USA without disclosureAmong the data recipients are Google, Microsoft and AccessiWay (American services). Google Analytics, meanwhile, sends real measurements without any consent-state flag. There is no section on the transfer of data outside the EU/EEA in the policy at all, although such a transfer does actually occur.
Context
www.comune.roma.it is the official website of the municipality of Rome, the capital commune Roma Capitale. An in-house-developed platform, with a self-made cookie bar. The capture shows 272 requests to 23 domains — including its own video portal with streaming video. Roma Capitale itself is correctly named as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. The capital’s site carries an extensive technology stack: dual analytics, a chatbot, translation, accessibility, video. And almost none of this is described in the policy.
Who receives the data
Spotted here were: Google, Microsoft, AccessiWay, Streamcloud, Iubenda.
Was there a consent banner
Consent here is arranged in a peculiar way. Cookie management is handled by Roma Capitale’s in-house bar, which loads early, at +2721 ms, and with parameters that permit third-party components. And the Iubenda system, used on other sites as a consent banner, is connected here only for the accessibility widget — it has nothing to do with cookie management. There is no recorded «accepted/declined» event in the capture, and the analytics fires later without any sign that the bar held it back. It is telling that Google Analytics goes out without any consent-state flag at all — that is, it sends real measurements without checking against the user’s choice.
The third case of double Matomo in the series
Two different Matomo instances work in parallel on the site — on the same domain but in different paths, with different site identifiers. Both record the same page view almost synchronously, and both carry the visitor identifier. This is already the third such case after the medicines agency and the research council. It seems that the parallel installation of several independent counters — for different systems or contractors of one organisation — is a frequent phenomenon in large Italian government structures. But unlike the research council, where the counters worked without an identifier, here both assign the visitor a marker, so the «anonymity» of this statistics is conditional.
A chatbot that goes through Microsoft
The Julia chatbot deserves separate attention. Technically it works not on the city’s own infrastructure, but through Microsoft’s cloud platform. This means that the user’s dialogue with the bot passes through an American company’s service. On a city hall’s site, where a person may ask a question with personal details, this is significant — but neither the chatbot itself, nor still less whose infrastructure it works through, is mentioned in the policy.
The policy describes only the most general
The document limits itself to two subjects: the general navigation data that the site receives inevitably, and social-network plugins. It also contains a phrase precise in its own way — that the cookies are configured so as to set nothing on visiting a page; and this is even confirmed by the capture, where there is indeed not a single Set-Cookie. But beyond this narrow truth the document stays silent about everything that actually works: the two counters with a visitor identifier, Google Analytics, the chatbot on Microsoft’s infrastructure, the Google translator, the accessibility widget and the video portal. There is no section on the transfer of data outside the EEA at all, although the recipients are American.
What cannot be claimed from the capture
A few honest caveats. There is no recorded consent event in the capture, so on the operation of the in-house bar I judge from the load order, not from someone’s click; but the absence of a consent-state flag on Google Analytics is a fact from the requests themselves. The content of the dialogue with the chatbot I do not observe and do not claim that anything was entered into it — this is about the channel through which it passes. The visitor identifier of both counters is visible right in the parameters. The capture covers the public home page.
Conclusion
The website of Italy’s capital carries a large and heterogeneous technology stack — two counters with a visitor identifier, Google Analytics with no regard for consent, a chatbot via Microsoft’s infrastructure, translation from Google, an accessibility widget and a video portal. The policy, meanwhile, describes only the most general, inevitable navigation data and social-network plugins, naming not one of these tools and staying silent about the transfer of data across the ocean. The main takeaway for the reader: the larger the government structure, the longer its technology tail — and the more noticeable the gap between what the site actually does and the short paragraph with which it describes it.
1bbecf4b6861d724f11aa891d9267d3591efb7b406a4fa23b965a2fe551014adWhere to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website comune.roma.it. 2. Circumstances I visited the website comune.roma.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The policy describes only general navigation data and, separately, social-network plugins (with the caveat that without active use they set no cookies). In reality, two Matomo instances (both with a visitor identifier), Google Analytics 4, a chatbot via Microsoft's infrastructure, Google Translate, the AccessiWay accessibility widget and a video portal on the Streamcloud platform work on the site. Not one of these tools is named in the policy. 2) Among the data recipients are Google, Microsoft and AccessiWay (American services). Google Analytics, meanwhile, sends real measurements without any consent-state flag. There is no section on the transfer of data outside the EU/EEA in the policy at all, although such a transfer does actually occur. Full technical documentation is published at: https://gdpru.eu/en/audits/it-comune-roma-it/ 3. Provisions violated Art. 13(1)(e) GDPR — the real stack is not declared; Art. 13(1)(f) GDPR — transfer to the USA without disclosure 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]