Technical audit · 2026-06-15

epicentro.iss.it

Epidemiology Portal of Italy's Institute of Health

EpiCentro is the epidemiological-surveillance portal of Italy's Institute of Health (ISS). 16 requests, 7 domains. The ShinyStat and Google Analytics declared in the policy did not fire in the session, while the only actually active third-party service — Google Fonts — is undeclared and takes the IP to the USA.

Timeline of the leak

+0–180 ms · only CDN libraries
A standard front-end stack: Bootstrap (BootstrapCDN), jQuery (code.jquery.com), Popper (jsDelivr), Font Awesome (Cloudflare). There are no trackers at this stage.
not applicable — there is no banner
No consent notice was found. The policy permits anonymous analytics without prior consent, with a reference to the regulator's 2014 ruling — but the declared analytics itself does not work in this session.
+192–193 ms · Google Fonts
The font-style description from fonts.googleapis.com and the font file itself from fonts.gstatic.com — the only actually active external service during the session. No ShinyStat, no Google Analytics, not a single Set-Cookie.

Declared versus actual

ShinyStat — declared, not active in the session — заявлен
Google Analytics — declared, not active in the session — заявлен
+ Google Fonts — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

epicentro.iss.it is the EpiCentro portal, an epidemiological-surveillance resource of Italy’s Institute of Health (ISS). People come here to read about health and epidemiology — a topic on which a visitor’s interests say something. The capture shows 16 requests to seven domains — the site is light. The institute itself is correctly named as the data controller, and the policy relies on the regulation in force. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. The finding here is minor but characteristic: the document and reality diverged in two directions at once.

Who receives the data

Spotted here was: Google.

There is no consent notice. The policy explicitly permits anonymous analytics without prior consent — with a reference to an old regulator ruling. But there is a nuance here: the declared analytics itself did not fire in the capture, so there is in fact nothing to permit. And the only actually active third-party service — Google Fonts — is not analytics, and does not fall under the permission for statistics.

The declared analytics did not fire

The policy names two statistics tools — ShinyStat and Google Analytics, both with a note about IP anonymisation. Neither of them appears in the capture. This can be read in different ways: either the tools were removed and the document was forgotten to be updated, or they load under certain conditions that did not occur on this visit. If the analytics was indeed removed, this is in favour of privacy; but then the document ought to be brought into line. In any case, the declared and the observed do not coincide.

The wrong Google service is named

The most curious thing is in the direction of the mismatch. The document mentions Google Analytics, which is not on the site. And at the same time it stays silent about Google Fonts, which is on the site and works. That is, of the two Google services the absent one is named, while the actually working one is skipped. And it is precisely Google Fonts that transmits the visitor’s IP address to Google in the USA on every page load. Plus several front-end libraries are pulled from external CDNs, which also exposes the IP to third-party platforms — a trifle against the rest, but in sum the picture of the «light» site turns out slightly less self-contained than it seems.

What cannot be claimed from the capture

A few honest caveats. The absence of the analytics in this session does not prove it was removed forever — it could load under other conditions; I record only that it is not in the capture. The request to Google Fonts already transmits the IP in itself, independently of anything further. The capture is light, only sixteen requests, and covers the home page.

Conclusion

A light site with an outdated declaration. The policy names two analytics tools, including Google Analytics, none of which works in the capture — while the only actually active third-party service, Google Fonts, is not named and quietly sends the visitor’s IP to Google in the USA. If the analytics was removed, that is good, but the document should reflect this and at the same time name the Google service that is actually used. It is all fixed in a couple of moves: move the fonts to one’s own server and update the policy. The main takeaway for the reader: sometimes the divergence of the document from reality works in both directions — the absent is named and the present is kept silent about.

Evidence
Original (audit)
HAR file: it/epicentro-iss-it-2026-06-15.har
SHA-256: 5514b2c5e5c746dcb1c0410f85d877bbca03e31644afd57a69bbfa13f44df712
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website epicentro.iss.it.

2. Circumstances
I visited the website epicentro.iss.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The policy names two statistics tools — ShinyStat and Google Analytics, both with an anonymised IP. Neither of them appears in the capture. Meanwhile the only actually working external service — Google Fonts — is not mentioned in the document at all. What results is a double mismatch: what is not there is named, and what is there is not named.

2) The Google fonts are loaded directly from Google's servers, and every such request transmits the visitor's IP address to Google (USA). This service is not named in the policy, and there is no section on the transfer of data outside the EU in it. Additionally, several front-end libraries load from external CDNs, which also exposes the IP to third-party platforms.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-epicentro-iss-it/

3. Provisions violated
Art. 13(1)(e) GDPR — the declared analytics does not work, the real service is not named; Art. 13(1)(f) GDPR — Google Fonts takes the IP to the USA

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]