The website of the Constitutional Court of Italy. 44 requests, 5 domains. The policy names the government analytics, YouTube, Vimeo and Spreaker — and in a session taken without consent none of these services activates: the Iubenda banner works in auto-blocking mode and genuinely holds back the third-party tags until consent. The behaviour matches the document exactly.
Timeline of the leak
Declared versus actual
Detected trackers
- Iubenda (consent banner, auto-blocking mode) — does not launch the declared services before consent
Context
www.cortecostituzionale.it is the website of the Constitutional Court of Italy. It is built on its own content-management system. The capture shows 44 requests to five domains. The policy correctly names the court’s secretary-general as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. This is one of the best results in the series — and a rare case where the consent mechanism is not a formality but genuinely works.
Who receives the data
In this session without consent, third-party trackers received no data: the auto-blocking held them back until the user’s choice. Only requests to the Iubenda banner itself and one request to a third-party JavaScript-module store went out — neither of which is a tracker.
Was there a consent banner
There is a banner, and here this is the site’s main merit. It works in auto-blocking mode: a separate script physically prevents third-party tags from executing until the user has given consent. This is fundamentally different from most sites in the series, where the banner is present purely formally while the trackers fire independently of it. Here it is the opposite: nothing third-party launches before consent.
The declaration matches the fact
The best confirmation that the auto-blocking is not merely declarative is the comparison with the policy. The document honestly names the third-party services used: the government analytics from AGID, the YouTube and Vimeo video platforms, the Spreaker podcast platform. And none of them appears in the capture without consent. That is, the declared services exist but launch only after consent — exactly as it should be. Word and deed coincide.
A conscious choice against transfer across the ocean
The decision behind the choice of analytics is worth noting separately. The policy explicitly explains why it uses precisely the government AGID platform rather than Google: with a reference to the well-known European Court ruling on the inadmissibility of uncontrolled transfer of data to the USA. That is, here it is not simply «it turned out that way» — here a tool that keeps data within the EU was consciously chosen, and this is explained in the document. For a site of this level, this is the correct and mature approach.
What cannot be claimed from the capture
A few honest caveats. The capture records the state before consent; how the declared services behave after «accept» is pressed is not visible from here — but it is precisely the blocking before consent that is required, and it works. The only external request besides the banner is to a third-party JavaScript-module store; it transmits the IP to this CDN but does no tracking. The capture covers the home page.
Conclusion
This is an exemplary result. The consent mechanism here is not for show: the auto-blocking genuinely holds back all the declared third-party services — the government analytics, video, podcasts — until the user consents. And the choice of analytics itself is made consciously in favour of a solution that keeps data in Europe, and this is honestly explained in the policy. The main takeaway for the reader: this is how a properly configured site should look — the declared tools are named individually, and before consent not one of them fires.
dfb2160ef5a5305b8e791cd12dfce4fb8cc31c17282f5cdb846adebf9bb789cb