Technical audit · 2026-06-15

comune.roma.it

City of Rome

The website of the city of Rome (Roma Capitale). 272 requests, 23 domains. Two parallel Matomos, Google Analytics 4, a chatbot via Microsoft's infrastructure, Google translation, an accessibility widget and a video portal — an extensive technology stack, of which the policy names not a single tool, limiting itself to general navigation data and social-network plugins.

Timeline of the leak

+2529 ms · translation preparation
The styling of the embedded Google translator loads.
+2720–2722 ms · widgets and the in-house bar all at once
Almost simultaneously the following load: the in-house-developed cookie bar (romacookiebar.js, bannerhome.min.js with the parameters thirdparty=1&always=1), the Google translator (translate.google.com), the Julia chatbot scripts and the embedding of the AccessiWay accessibility widget (embeds.accessiway.com). All of this before any confirmation of consent.
+3287 ms · analytics loads
The Matomo script loads.
+3354–3952 ms · the chatbot deploys
The chatbot endpoint (julia.comune.roma.it) and its main program module connect.
+4849–4850 ms · the bar and Iubenda for accessibility
The minimal version of the cookie bar is rendered, and the accessibility widget loads via Iubenda. Iubenda here is used only for the accessibility widget, not for cookie-consent management.
+5644 ms · two Matomos at once
Two different Matomo instances on the same domain but in different paths (/matomo/, idsite=1 and /matomo-apprc/, idsite=5) send a measurement of the same visit practically within one millisecond. Both carry the visitor identifier.
+5780–5783 ms · accessibility active
The main AccessiWay script (acsbapp.com) loads and a utility data request of the accessibility widget goes out.
+6840 ms · chatbot via Microsoft
The Julia chatbot goes out to the Microsoft Bot Framework infrastructure (europe.directline.botframework.com) — the channel through which the user's dialogue passes.
+7265 ms onward · Google Analytics 4
Google Analytics 4 (G-FWY4SWRLK5) sends real visit measurements — at +7265, +9627 and +15054 ms — and without any consent-state flag. It connects last of all. Not a single Set-Cookie throughout the entire session of 272 requests.

Declared versus actual

+ Matomo (/matomo/, idsite=1) — не заявлен
+ Matomo (/matomo-apprc/, idsite=5) — не заявлен
+ Google Analytics 4 — не заявлен
+ Julia chatbot + Microsoft Bot Framework — не заявлен
+ Google Translate — не заявлен
+ AccessiWay — не заявлен
+ Streamcloud — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.comune.roma.it is the official website of the municipality of Rome, the capital commune Roma Capitale. An in-house-developed platform, with a self-made cookie bar. The capture shows 272 requests to 23 domains — including its own video portal with streaming video. Roma Capitale itself is correctly named as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. The capital’s site carries an extensive technology stack: dual analytics, a chatbot, translation, accessibility, video. And almost none of this is described in the policy.

Who receives the data

Spotted here were: Google, Microsoft, AccessiWay, Streamcloud, Iubenda.

Consent here is arranged in a peculiar way. Cookie management is handled by Roma Capitale’s in-house bar, which loads early, at +2721 ms, and with parameters that permit third-party components. And the Iubenda system, used on other sites as a consent banner, is connected here only for the accessibility widget — it has nothing to do with cookie management. There is no recorded «accepted/declined» event in the capture, and the analytics fires later without any sign that the bar held it back. It is telling that Google Analytics goes out without any consent-state flag at all — that is, it sends real measurements without checking against the user’s choice.

The third case of double Matomo in the series

Two different Matomo instances work in parallel on the site — on the same domain but in different paths, with different site identifiers. Both record the same page view almost synchronously, and both carry the visitor identifier. This is already the third such case after the medicines agency and the research council. It seems that the parallel installation of several independent counters — for different systems or contractors of one organisation — is a frequent phenomenon in large Italian government structures. But unlike the research council, where the counters worked without an identifier, here both assign the visitor a marker, so the «anonymity» of this statistics is conditional.

A chatbot that goes through Microsoft

The Julia chatbot deserves separate attention. Technically it works not on the city’s own infrastructure, but through Microsoft’s cloud platform. This means that the user’s dialogue with the bot passes through an American company’s service. On a city hall’s site, where a person may ask a question with personal details, this is significant — but neither the chatbot itself, nor still less whose infrastructure it works through, is mentioned in the policy.

The policy describes only the most general

The document limits itself to two subjects: the general navigation data that the site receives inevitably, and social-network plugins. It also contains a phrase precise in its own way — that the cookies are configured so as to set nothing on visiting a page; and this is even confirmed by the capture, where there is indeed not a single Set-Cookie. But beyond this narrow truth the document stays silent about everything that actually works: the two counters with a visitor identifier, Google Analytics, the chatbot on Microsoft’s infrastructure, the Google translator, the accessibility widget and the video portal. There is no section on the transfer of data outside the EEA at all, although the recipients are American.

What cannot be claimed from the capture

A few honest caveats. There is no recorded consent event in the capture, so on the operation of the in-house bar I judge from the load order, not from someone’s click; but the absence of a consent-state flag on Google Analytics is a fact from the requests themselves. The content of the dialogue with the chatbot I do not observe and do not claim that anything was entered into it — this is about the channel through which it passes. The visitor identifier of both counters is visible right in the parameters. The capture covers the public home page.

Conclusion

The website of Italy’s capital carries a large and heterogeneous technology stack — two counters with a visitor identifier, Google Analytics with no regard for consent, a chatbot via Microsoft’s infrastructure, translation from Google, an accessibility widget and a video portal. The policy, meanwhile, describes only the most general, inevitable navigation data and social-network plugins, naming not one of these tools and staying silent about the transfer of data across the ocean. The main takeaway for the reader: the larger the government structure, the longer its technology tail — and the more noticeable the gap between what the site actually does and the short paragraph with which it describes it.

Evidence
Original (audit)
HAR file: it/www-comune-roma-it-2026-06-15.har
SHA-256: 1bbecf4b6861d724f11aa891d9267d3591efb7b406a4fa23b965a2fe551014ad
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website comune.roma.it.

2. Circumstances
I visited the website comune.roma.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The policy describes only general navigation data and, separately, social-network plugins (with the caveat that without active use they set no cookies). In reality, two Matomo instances (both with a visitor identifier), Google Analytics 4, a chatbot via Microsoft's infrastructure, Google Translate, the AccessiWay accessibility widget and a video portal on the Streamcloud platform work on the site. Not one of these tools is named in the policy.

2) Among the data recipients are Google, Microsoft and AccessiWay (American services). Google Analytics, meanwhile, sends real measurements without any consent-state flag. There is no section on the transfer of data outside the EU/EEA in the policy at all, although such a transfer does actually occur.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-comune-roma-it/

3. Provisions violated
Art. 13(1)(e) GDPR — the real stack is not declared; Art. 13(1)(f) GDPR — transfer to the USA without disclosure

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]