Technical audit · 2026-06-15

cortecostituzionale.it

Constitutional Court of Italy

The website of the Constitutional Court of Italy. 44 requests, 5 domains. The policy names the government analytics, YouTube, Vimeo and Spreaker — and in a session taken without consent none of these services activates: the Iubenda banner works in auto-blocking mode and genuinely holds back the third-party tags until consent. The behaviour matches the document exactly.

Timeline of the leak

+0–420 ms · theme and auto-blocking
Its own content-management system. Almost immediately the Iubenda auto-blocking script loads — the very one that physically prevents third-party tags from executing before the user's explicit consent.
+420–835 ms · full banner initialisation
The stub, the main banner module and its configuration load — the standard Iubenda set. Neither the government analytics, nor YouTube, nor Vimeo, nor Spreaker (all declared in the policy as third-party services) appear in the capture — exactly what is expected with auto-blocking working without consent.
not applicable
The session ends without a single third-party tracker firing. Not a single Set-Cookie throughout the entire session of 44 requests.

Declared versus actual

Web Analytics Italia government analytics (AGID) — correctly not launched without consent — заявлен
YouTube and Vimeo (video) — not active on the page — заявлен
Spreaker (podcasts) — not active on the page — заявлен

Detected trackers

Context

www.cortecostituzionale.it is the website of the Constitutional Court of Italy. It is built on its own content-management system. The capture shows 44 requests to five domains. The policy correctly names the court’s secretary-general as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. This is one of the best results in the series — and a rare case where the consent mechanism is not a formality but genuinely works.

Who receives the data

In this session without consent, third-party trackers received no data: the auto-blocking held them back until the user’s choice. Only requests to the Iubenda banner itself and one request to a third-party JavaScript-module store went out — neither of which is a tracker.

There is a banner, and here this is the site’s main merit. It works in auto-blocking mode: a separate script physically prevents third-party tags from executing until the user has given consent. This is fundamentally different from most sites in the series, where the banner is present purely formally while the trackers fire independently of it. Here it is the opposite: nothing third-party launches before consent.

The declaration matches the fact

The best confirmation that the auto-blocking is not merely declarative is the comparison with the policy. The document honestly names the third-party services used: the government analytics from AGID, the YouTube and Vimeo video platforms, the Spreaker podcast platform. And none of them appears in the capture without consent. That is, the declared services exist but launch only after consent — exactly as it should be. Word and deed coincide.

A conscious choice against transfer across the ocean

The decision behind the choice of analytics is worth noting separately. The policy explicitly explains why it uses precisely the government AGID platform rather than Google: with a reference to the well-known European Court ruling on the inadmissibility of uncontrolled transfer of data to the USA. That is, here it is not simply «it turned out that way» — here a tool that keeps data within the EU was consciously chosen, and this is explained in the document. For a site of this level, this is the correct and mature approach.

What cannot be claimed from the capture

A few honest caveats. The capture records the state before consent; how the declared services behave after «accept» is pressed is not visible from here — but it is precisely the blocking before consent that is required, and it works. The only external request besides the banner is to a third-party JavaScript-module store; it transmits the IP to this CDN but does no tracking. The capture covers the home page.

Conclusion

This is an exemplary result. The consent mechanism here is not for show: the auto-blocking genuinely holds back all the declared third-party services — the government analytics, video, podcasts — until the user consents. And the choice of analytics itself is made consciously in favour of a solution that keeps data in Europe, and this is honestly explained in the policy. The main takeaway for the reader: this is how a properly configured site should look — the declared tools are named individually, and before consent not one of them fires.

Evidence
Original (audit)
HAR file: it/www-cortecostituzionale-it-2026-06-15.har
SHA-256: dfb2160ef5a5305b8e791cd12dfce4fb8cc31c17282f5cdb846adebf9bb789cb
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.