finanze.gov.it
The website of the Finance Department of Italy's Ministry of Economy and Finance. 44 requests, 2 domains. The analytics is declared as anonymous aggregate statistics, but in fact a session-recording module works on the same Sogei government infrastructure as on a number of other government sites in the series. Meanwhile nothing leaves the country.
Timeline of the leak
Declared versus actual
Detected trackers
- Matomo on Sogei's infrastructure (aaws-aanalytics.sogei.it, idsite=8) — carries the visitor identifier, with an active session-recording module
Indicators of GDPR non-compliance
- Art. 13(1)(e) and Art. 5(1)(a) GDPR — session recording not declaredThe policy describes the navigation data as used only to obtain anonymous statistics and explicitly denies profiling, without naming a specific tool. In fact, alongside the ordinary visit measurement a session-recording module is active (HeatmapSessionRecording, configs.php responds 200) on Sogei's government infrastructure. This is the recording of visitor behaviour, not aggregate anonymous statistics, and it is not mentioned in the document. The same Sogei module has already appeared in the series on the sites of the tax authority, the cybersecurity agency and the government — that is, this is a trait of the shared government platform.
- Art. 6(1)(a) GDPR / regulator's guidance — behaviour recording without consentThere is no consent banner in the capture. By the Italian regulator's position, behaviour monitoring requires consent and cannot pass as a technical cookie. Here the session recording launches without any asking.
Context
finanze.gov.it is the website of the Finance Department (Dipartimento delle Finanze), a structural unit of Italy’s Ministry of Economy and Finance responsible for tax and fiscal policy. It is built on the content-management system of the government contractor Sogei. The capture shows 44 requests to two domains: the site itself and Sogei’s analytics. The department itself is correctly named as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. A case that by this point in the series has, unfortunately, become recognisable: a government site on Sogei’s infrastructure, and on it the same old session-recording module.
Who receives the data
Spotted here was: Sogei (government-run, Italy). There are no foreign or commercial recipients.
Was there a consent banner
There is no consent notice in the capture. Government anonymous statistics is equated to technical means and requires no consent — but, as on other sites with this module, only the ordinary counting falls under this exemption, not the behaviour recording. It is also worth noting that the measurement carries the visitor identifier, so the «anonymity» here comes with a caveat.
The same session-recording module — again
Besides the ordinary visit measurement, a session-recording module is active on the site — it records the behaviour of a specific visitor rather than counting de-identified visits. The request to it passes successfully, that is, the module really works. This is exactly the same tool on the same Sogei infrastructure that has already appeared in the series on the sites of the tax authority, the cybersecurity agency and the government itself. The recurrence across different bodies indicates that this is not the setting of an individual site, but a trait of the shared government platform — and it is replicated across all the portals built on it.
The policy promises «anonymous and without profiling»
The document describes the collection as anonymous and explicitly denies profiling. The capture refines this: the counter carries the visitor identifier, and on top of that session recording is conducted. Both sit poorly with the words «anonymous» and «without profiling» — it would be more accurate to say «partially de-identified». Meanwhile the tool itself is not named in the policy, and there is not a word about session recording.
Where the data goes — nowhere abroad
A significant plus that must be named honestly. All the analytics is on Sogei’s government infrastructure, and nothing leaves the country: no Google, no other foreign recipients. Against the backdrop of the commercial sites in the series that handed data across the ocean, this is an important difference. The problem here is not where the data goes, but the fact that the behaviour recording is kept silent about and no consent is asked for.
What cannot be claimed from the capture
A few honest caveats. On the session recording’s activity I judge from the successful response of its module; the content of the recording itself is not visible in the capture. The consent notice was not recorded in this session — perhaps it is shown under other conditions, but by the moment of the capture the recording had already fired. The visitor identifier is visible right in the capture. The analytics is government-run, so the question of the servers’ geography does not arise. The capture covers the home page.
Conclusion
Another government site repeating the gap familiar from the series: the analytics is promised as anonymous and without profiling, while in fact, alongside the counting, session recording is conducted, and the counter marks the visitor with an identifier. It is important that all this stays within the government infrastructure and does not leave abroad — this is a real plus. But Sogei’s systemic session-recording module surfaces again, now at the department responsible for fiscal policy. The main takeaway for the reader: this is no longer the oversight of an individual body, but a trait of the platform on which dozens of government sites are built — and it needs to be closed at the platform level too: either honestly describe the session recording in the policy, or ask for consent to it.
659fab1915c8fee0db0c6f8cbd54c84f1c93d6a1e0653a733a498d345d2f9136Where to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website finanze.gov.it. 2. Circumstances I visited the website finanze.gov.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The policy describes the navigation data as used only to obtain anonymous statistics and explicitly denies profiling, without naming a specific tool. In fact, alongside the ordinary visit measurement a session-recording module is active (HeatmapSessionRecording, configs.php responds 200) on Sogei's government infrastructure. This is the recording of visitor behaviour, not aggregate anonymous statistics, and it is not mentioned in the document. The same Sogei module has already appeared in the series on the sites of the tax authority, the cybersecurity agency and the government — that is, this is a trait of the shared government platform. 2) There is no consent banner in the capture. By the Italian regulator's position, behaviour monitoring requires consent and cannot pass as a technical cookie. Here the session recording launches without any asking. Full technical documentation is published at: https://gdpru.eu/en/audits/it-finanze-gov-it/ 3. Provisions violated Art. 13(1)(e) and Art. 5(1)(a) GDPR — session recording not declared; Art. 6(1)(a) GDPR / regulator's guidance — behaviour recording without consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]