Technical audit · 2026-06-15

dt.mef.gov.it

Treasury Department of Italy's Ministry of Economy and Finance

The website of the Treasury Department of Italy's Ministry of Economy and Finance (management of public debt and financial markets). 57 requests, 2 domains. The analytics is declared as anonymous aggregate statistics, but in fact a session-recording module works on the same Sogei government infrastructure as on a number of other government sites in the series. Meanwhile nothing leaves the country.

Timeline of the leak

+0–85 ms · loading the portal and consent module
Its own content-management system on Sogei's infrastructure. In the common stream the standard AGID consent module (cookie_consent.js) connects — but, as seen further on, it does not hold back the analytics.
+508 ms · analytics load
The Sogei analytics script (matomo.js) — the same infrastructure as the tax authority, the cybersecurity agency and the government.
+1064–1068 ms · measurement and session recording simultaneously
The visit measurement (idsite=54, carries the visitor identifier) and immediately after it the activation of the session-recording module — almost within one millisecond. Not a single Set-Cookie throughout the entire session.

Declared versus actual

+ Matomo on Sogei's infrastructure — with session recording — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

www.dt.mef.gov.it is the website of the Treasury Department (Dipartimento del Tesoro), part of the structure of Italy’s Ministry of Economy and Finance: management of public debt and financial markets. It is built on the content-management system of the government contractor Sogei. The capture shows 57 requests to two domains: the site itself and Sogei’s analytics. The department itself is correctly named as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. By this point in the series the case is already familiar down to the detail: a government site on Sogei’s infrastructure — and the same old session-recording module.

Who receives the data

Spotted here was: Sogei (government-run, Italy). There are no foreign or commercial recipients.

The standard AGID consent module is installed on the site, its code loads at the start of the visit. But it does not hold back the analytics and session recording — they fire independently. Basic anonymous counting under Italian rules may be conducted without consent, but behaviour recording does not fall under this exemption. The measurement, meanwhile, carries the visitor identifier, so the «anonymity» here comes with a caveat.

The same session-recording module — again

Besides the ordinary measurement, a session-recording module is active on the site: the request to it passes successfully, that is, it really works. This is the same tool on the same Sogei infrastructure that has already appeared in the series on the sites of the tax authority, the cybersecurity agency, the government and the finance department. The recurrence across different bodies unambiguously indicates: this is not the setting of an individual site, but a trait of the shared government platform.

Where the data goes — nowhere abroad

A significant plus. All the analytics is on Sogei’s government infrastructure, nothing leaves the country. The problem here is not the transfer, but the fact that the behaviour recording is kept silent about and no consent is asked for.

What cannot be claimed from the capture

On the session recording’s activity I judge from the successful response of its module; the content of the recording itself is not visible in the capture. The visitor identifier is visible right in the capture. The analytics is government-run, so the question of the servers’ geography does not arise. The capture covers the home page.

Conclusion

Another government site with the same systemic gap: the analytics is promised as anonymous and aggregate, while in fact, alongside the counting, session recording is conducted, and the counter marks the visitor with an identifier. All of this stays within the government infrastructure — a real plus — but Sogei’s systemic session-recording module surfaces once again, now at the treasury. The main takeaway for the reader: this is no longer a coincidence but a regularity of the platform, and the gap needs to be closed at its level — either describe the session recording in the policies, or ask for consent to it.

Evidence
Original (audit)
HAR file: it/www-dt-mef-gov-it-2026-06-15.har
SHA-256: dae99f01f4ea99106a394e34cb158209eebabbda3413091110357ce26b49e3dd
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website dt.mef.gov.it.

2. Circumstances
I visited the website dt.mef.gov.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The policy describes the analytics cookies as equated to technical ones, collecting data in aggregate form, and denies profiling, without naming a specific tool. In fact, alongside the ordinary visit measurement a session-recording module is active (HeatmapSessionRecording, configs.php responds 200) on Sogei's government infrastructure. This is the recording of visitor behaviour, not aggregate statistics, and it is not mentioned in the document. The same module on the same Sogei infrastructure has already been confirmed in the series on the sites of the tax authority, the cybersecurity agency, the government and the finance department.

2) The standard AGID consent module is installed on the site, but it does not hold back the analytics and session recording — they fire independently of it. By the Italian regulator's position, behaviour monitoring requires consent and cannot pass as a technical cookie.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-dt-mef-gov-it/

3. Provisions violated
Art. 13(1)(e) and Art. 5(1)(a) GDPR — session recording not declared; Art. 6(1)(a) GDPR / regulator's guidance — behaviour recording without consent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]