dt.mef.gov.it
The website of the Treasury Department of Italy's Ministry of Economy and Finance (management of public debt and financial markets). 57 requests, 2 domains. The analytics is declared as anonymous aggregate statistics, but in fact a session-recording module works on the same Sogei government infrastructure as on a number of other government sites in the series. Meanwhile nothing leaves the country.
Timeline of the leak
Declared versus actual
Detected trackers
- Matomo on Sogei's infrastructure (aaws-aanalytics.sogei.it, idsite=54) — carries the visitor identifier, with an active session-recording module
Indicators of GDPR non-compliance
- Art. 13(1)(e) and Art. 5(1)(a) GDPR — session recording not declaredThe policy describes the analytics cookies as equated to technical ones, collecting data in aggregate form, and denies profiling, without naming a specific tool. In fact, alongside the ordinary visit measurement a session-recording module is active (HeatmapSessionRecording, configs.php responds 200) on Sogei's government infrastructure. This is the recording of visitor behaviour, not aggregate statistics, and it is not mentioned in the document. The same module on the same Sogei infrastructure has already been confirmed in the series on the sites of the tax authority, the cybersecurity agency, the government and the finance department.
- Art. 6(1)(a) GDPR / regulator's guidance — behaviour recording without consentThe standard AGID consent module is installed on the site, but it does not hold back the analytics and session recording — they fire independently of it. By the Italian regulator's position, behaviour monitoring requires consent and cannot pass as a technical cookie.
Context
www.dt.mef.gov.it is the website of the Treasury Department (Dipartimento del Tesoro), part of the structure of Italy’s Ministry of Economy and Finance: management of public debt and financial markets. It is built on the content-management system of the government contractor Sogei. The capture shows 57 requests to two domains: the site itself and Sogei’s analytics. The department itself is correctly named as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. By this point in the series the case is already familiar down to the detail: a government site on Sogei’s infrastructure — and the same old session-recording module.
Who receives the data
Spotted here was: Sogei (government-run, Italy). There are no foreign or commercial recipients.
Was there a consent banner
The standard AGID consent module is installed on the site, its code loads at the start of the visit. But it does not hold back the analytics and session recording — they fire independently. Basic anonymous counting under Italian rules may be conducted without consent, but behaviour recording does not fall under this exemption. The measurement, meanwhile, carries the visitor identifier, so the «anonymity» here comes with a caveat.
The same session-recording module — again
Besides the ordinary measurement, a session-recording module is active on the site: the request to it passes successfully, that is, it really works. This is the same tool on the same Sogei infrastructure that has already appeared in the series on the sites of the tax authority, the cybersecurity agency, the government and the finance department. The recurrence across different bodies unambiguously indicates: this is not the setting of an individual site, but a trait of the shared government platform.
Where the data goes — nowhere abroad
A significant plus. All the analytics is on Sogei’s government infrastructure, nothing leaves the country. The problem here is not the transfer, but the fact that the behaviour recording is kept silent about and no consent is asked for.
What cannot be claimed from the capture
On the session recording’s activity I judge from the successful response of its module; the content of the recording itself is not visible in the capture. The visitor identifier is visible right in the capture. The analytics is government-run, so the question of the servers’ geography does not arise. The capture covers the home page.
Conclusion
Another government site with the same systemic gap: the analytics is promised as anonymous and aggregate, while in fact, alongside the counting, session recording is conducted, and the counter marks the visitor with an identifier. All of this stays within the government infrastructure — a real plus — but Sogei’s systemic session-recording module surfaces once again, now at the treasury. The main takeaway for the reader: this is no longer a coincidence but a regularity of the platform, and the gap needs to be closed at its level — either describe the session recording in the policies, or ask for consent to it.
dae99f01f4ea99106a394e34cb158209eebabbda3413091110357ce26b49e3ddWhere to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website dt.mef.gov.it. 2. Circumstances I visited the website dt.mef.gov.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The policy describes the analytics cookies as equated to technical ones, collecting data in aggregate form, and denies profiling, without naming a specific tool. In fact, alongside the ordinary visit measurement a session-recording module is active (HeatmapSessionRecording, configs.php responds 200) on Sogei's government infrastructure. This is the recording of visitor behaviour, not aggregate statistics, and it is not mentioned in the document. The same module on the same Sogei infrastructure has already been confirmed in the series on the sites of the tax authority, the cybersecurity agency, the government and the finance department. 2) The standard AGID consent module is installed on the site, but it does not hold back the analytics and session recording — they fire independently of it. By the Italian regulator's position, behaviour monitoring requires consent and cannot pass as a technical cookie. Full technical documentation is published at: https://gdpru.eu/en/audits/it-dt-mef-gov-it/ 3. Provisions violated Art. 13(1)(e) and Art. 5(1)(a) GDPR — session recording not declared; Art. 6(1)(a) GDPR / regulator's guidance — behaviour recording without consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]