EpiCentro is the epidemiological-surveillance portal of Italy's Institute of Health (ISS). 16 requests, 7 domains. The ShinyStat and Google Analytics declared in the policy did not fire in the session, while the only actually active third-party service — Google Fonts — is undeclared and takes the IP to the USA.
Timeline of the leak
Declared versus actual
Detected trackers
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — transmits the IP to Google, USA
- CDN libraries: BootstrapCDN, Cloudflare, jQuery, jsDelivr
Indicators of GDPR non-compliance
- Art. 13(1)(e) GDPR — the declared analytics does not work, the real service is not namedThe policy names two statistics tools — ShinyStat and Google Analytics, both with an anonymised IP. Neither of them appears in the capture. Meanwhile the only actually working external service — Google Fonts — is not mentioned in the document at all. What results is a double mismatch: what is not there is named, and what is there is not named.
- Art. 13(1)(f) GDPR — Google Fonts takes the IP to the USAThe Google fonts are loaded directly from Google's servers, and every such request transmits the visitor's IP address to Google (USA). This service is not named in the policy, and there is no section on the transfer of data outside the EU in it. Additionally, several front-end libraries load from external CDNs, which also exposes the IP to third-party platforms.
Context
epicentro.iss.it is the EpiCentro portal, an epidemiological-surveillance resource of Italy’s Institute of Health (ISS). People come here to read about health and epidemiology — a topic on which a visitor’s interests say something. The capture shows 16 requests to seven domains — the site is light. The institute itself is correctly named as the data controller, and the policy relies on the regulation in force. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. The finding here is minor but characteristic: the document and reality diverged in two directions at once.
Who receives the data
Spotted here was: Google.
Was there a consent banner
There is no consent notice. The policy explicitly permits anonymous analytics without prior consent — with a reference to an old regulator ruling. But there is a nuance here: the declared analytics itself did not fire in the capture, so there is in fact nothing to permit. And the only actually active third-party service — Google Fonts — is not analytics, and does not fall under the permission for statistics.
The declared analytics did not fire
The policy names two statistics tools — ShinyStat and Google Analytics, both with a note about IP anonymisation. Neither of them appears in the capture. This can be read in different ways: either the tools were removed and the document was forgotten to be updated, or they load under certain conditions that did not occur on this visit. If the analytics was indeed removed, this is in favour of privacy; but then the document ought to be brought into line. In any case, the declared and the observed do not coincide.
The wrong Google service is named
The most curious thing is in the direction of the mismatch. The document mentions Google Analytics, which is not on the site. And at the same time it stays silent about Google Fonts, which is on the site and works. That is, of the two Google services the absent one is named, while the actually working one is skipped. And it is precisely Google Fonts that transmits the visitor’s IP address to Google in the USA on every page load. Plus several front-end libraries are pulled from external CDNs, which also exposes the IP to third-party platforms — a trifle against the rest, but in sum the picture of the «light» site turns out slightly less self-contained than it seems.
What cannot be claimed from the capture
A few honest caveats. The absence of the analytics in this session does not prove it was removed forever — it could load under other conditions; I record only that it is not in the capture. The request to Google Fonts already transmits the IP in itself, independently of anything further. The capture is light, only sixteen requests, and covers the home page.
Conclusion
A light site with an outdated declaration. The policy names two analytics tools, including Google Analytics, none of which works in the capture — while the only actually active third-party service, Google Fonts, is not named and quietly sends the visitor’s IP to Google in the USA. If the analytics was removed, that is good, but the document should reflect this and at the same time name the Google service that is actually used. It is all fixed in a couple of moves: move the fonts to one’s own server and update the policy. The main takeaway for the reader: sometimes the divergence of the document from reality works in both directions — the absent is named and the present is kept silent about.
5514b2c5e5c746dcb1c0410f85d877bbca03e31644afd57a69bbfa13f44df712Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website epicentro.iss.it. 2. Circumstances I visited the website epicentro.iss.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The policy names two statistics tools — ShinyStat and Google Analytics, both with an anonymised IP. Neither of them appears in the capture. Meanwhile the only actually working external service — Google Fonts — is not mentioned in the document at all. What results is a double mismatch: what is not there is named, and what is there is not named. 2) The Google fonts are loaded directly from Google's servers, and every such request transmits the visitor's IP address to Google (USA). This service is not named in the policy, and there is no section on the transfer of data outside the EU in it. Additionally, several front-end libraries load from external CDNs, which also exposes the IP to third-party platforms. Full technical documentation is published at: https://gdpru.eu/en/audits/it-epicentro-iss-it/ 3. Provisions violated Art. 13(1)(e) GDPR — the declared analytics does not work, the real service is not named; Art. 13(1)(f) GDPR — Google Fonts takes the IP to the USA 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]