Technical audit · 2026-06-15

comunicazione.camera.it

Chamber of Deputies of Italy — Communications Site

The communications site of Italy's Chamber of Deputies. 130 requests — and all three domains involved belong to the Chamber itself. No Google, no Facebook, no third-party fonts, not a single external tracker. The analytics is self-hosted, deployed on the Chamber's server and configured without a tracking identifier. The policy honestly describes exactly this. For the first time in the series — a site to which there is essentially no complaint.

Timeline of the leak

+0–314 ms · loading the site
A Drupal site. All the code, images, promo banners and fonts load exclusively from its own domains. No outward requests.
not applicable — there is no banner, and it is not needed
There is no consent banner, and this is lawful. Only technical session cookies and first-party analytics configured without a tracking identifier are used. There is nothing to ask consent for — hence there is no banner.
+315–424 ms · only its own analytics
At +315 ms the Matomo analytics script loads from the Chamber's server (webanalytics.camera.it), at +424 ms a visit measurement goes out. There are no external domains in the capture at all.

Declared versus actual

Technical session cookies — заявлен
First-party Matomo analytics (described as a technical tool) — заявлен
+ The analytics is not named (Matomo / Web Analytics Italia) in the policy — described as the category «technical cookies», without indicating the specific tool; this is a question of completeness, not a violation — не заявлен

Detected trackers

Context

comunicazione.camera.it is the communications site of Italy’s Chamber of Deputies, one of the two chambers of the Italian parliament. It is built on Drupal. The capture shows 130 requests, and here what is immediately striking is what was not present on any previous site in the series: all three domains involved belong to the Chamber itself. Not a single outward request — not to Google, not to social networks, not even to external fonts. I read the live cookie policy separately; it is open and accessible. And, getting ahead of myself, I will say honestly: after five sites with discrepancies, this one is the first to which there is essentially no complaint. So the analysis below is devoted mainly to how it is done right.

There is no banner — and this is absolutely lawful. The site uses only technical session cookies and its own analytics configured as gently as possible. Since there is no profiling, no third-party trackers and no tracking cookies here, there is simply nothing to ask consent for. The absence of a banner here is not an oversight but a natural consequence of there being little to collect. (The promo banners in the site’s code are advertising images of events, not a consent mechanism; they are easy to confuse by the name, but they have nothing to do with cookies.)

What the capture showed

The picture is extremely simple and clean. The whole site runs on its own domains: the main content and promo images from comunicazione.camera.it, the analytics from webanalytics.camera.it, and one request to www.camera.it. That is all. No Google Analytics, no Facebook Pixel, no advertising pixels, no third-party fonts. The analytics is the government Matomo platform (that very Web Analytics Italia), but, unlike other government sites in the series, deployed directly on the Chamber’s own server.

The analytics is configured privately — and it is visible right in the capture

Here is the most telling detail. On all the previous sites the analytics measurement took away a persistent visitor identifier — a unique marker by which a person is recognised on subsequent visits. On this site there is no such identifier in the capture at all. This means the analytics is configured without a tracking cookie: it counts visits but assigns the visitor no persistent marker. Not a single cookie was set throughout the entire session. In addition, the government platform de-identifies the IP address by default. In other words, before us is web analytics about as private as it ever gets: first-party, without cookies, with a de-identified IP. I will honestly note that the screen resolution and browser data do still go out with the measurement — that is, it is not a mathematical zero — but without a persistent identifier and without cookies this fully fits the category of technical means requiring no consent.

The policy matches reality

And here is the very thing for which the comparison is undertaken at all. The Chamber’s cookie policy states: exclusively technical session cookies are used, no profiling is conducted, no other active or passive tracking means are applied. The capture confirms this word for word — that is exactly how it is. The data controller is named as the Chamber of Deputies itself, not a nameless contractor or a third-party firm — that is, the visitor clearly understands who is responsible for their data. The policy also honestly describes the YouTube videos separately: they occur only on some pages, are enabled in privacy mode and only after the user’s explicit consent. On the home page covered by the capture there were no videos at all — and this again matches.

The only trifle

So that the analysis does not look uncritical, I will name the only thing that could be improved. The policy describes the analytics correctly by category — as a technical tool — but does not name it (Matomo / Web Analytics Italia). The exemplary site of the series, the site of the digital agency itself, went further and listed each cookie by name with its lifetime. Here this is absent. This is a question of completeness and transparency, not a violation: the law in this case does not directly require naming, but conscientious practice is to name the tool explicitly.

What cannot be claimed from the capture

A few honest caveats. The capture covers only the home page — on internal pages, according to the policy, YouTube is sometimes embedded in privacy mode with consent, but I did not capture those pages and cannot confirm their behaviour. The server configuration of the analytics beyond what is visible in the capture I also do not see. And this lightweight export does not preserve the servers’ IP addresses, but in this case it does not matter: all the domains belong to the Chamber anyway.

Conclusion

This is the benchmark of cleanliness for the whole series. After sites that handed visitors over to Google and Meta from the first second, here is a model of how a government body can conduct web analytics without leaking anyone anywhere: its own server, no third-party trackers, analytics without a tracking identifier and with a de-identified IP, a correctly named controller and a policy that matches reality. Consent is not required and is justifiably absent. The only thing worth adding would be to name the analytics tool. The main takeaway for the reader: the gap between promise and behaviour that we saw with others is not an inevitability but a choice. Here the choice is made in the visitor’s favour.

Evidence
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.