Technical audit · 2026-06-15

governo.it

Government of Italy

The website of the Government of Italy (Presidenza del Consiglio dei Ministri). 66 requests, 3 domains. Two government Matomo counters work in parallel, both carry the visitor identifier, and on one of them session recording is active — behaviour observation that the policy does not mention. Meanwhile nothing leaves the country.

Timeline of the leak

+0–197 ms · portal load
A Drupal site. In the common stream the cookie-consent-management module (cookiebar.js) connects — but, as seen further on, it does not hold back the analytics.
+251 ms · first counter
The first counter's script loads — on the infrastructure of the government contractor Sogei.
+622–624 ms · two counters at once
The visit measurement goes out almost simultaneously to two places: the Sogei counter (idsite=8) and the national Web Analytics Italia platform (idsite=363). Both measurements carry the visitor identifier.
+630 ms · session recording — on one of the two
Immediately after, both counters try to load the session-recording module. On the Sogei instance it is really active (configs.php responds successfully), while Web Analytics Italia has no such module — the request returns a 404 error. That is, session recording here works once, on Sogei's side, not twice. Not a single Set-Cookie throughout the entire session.

Declared versus actual

+ Matomo / Sogei (with session recording) — не заявлен
+ Matomo / Web Analytics Italia — не заявлен

Detected trackers

Indicators of GDPR non-compliance

Context

governo.it is the official website of the Government of Italy, the office of the President of the Council of Ministers. It is built on Drupal. The capture shows 66 requests to three domains: the site itself, the analytics of the government contractor Sogei and the national analytics platform. The government office is correctly named as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. This is the highest-level site among those analysed, and it is all the more interesting that two patterns familiar from the series intersect on it. But one of them is not on the scale it might have seemed, and this is worth clarifying honestly.

Who receives the data

Spotted here were: Sogei, Web Analytics Italia (both government-run, Italy).

The consent-management module is installed on the site — its script loads at the start of the visit. But it does not hold back the analytics: both counters and the session recording fire independently of it. For anonymous government statistics consent is not required anyway, but, as seen below, session recording does not fall under this exemption. It is also worth noting that both measurements carry the visitor identifier, so the «anonymity» here comes with a caveat.

Two government counters at once

Two different Matomo instances work in parallel on the site — on Sogei’s infrastructure and in the national Web Analytics Italia platform — with different site identifiers, both recording the same visit almost synchronously. This is already the fourth case of a «double counter» in the series after the medicines agency, the research council and Rome. An important plus here specifically: both counters are government-run, and nothing leaves the country — no Google, no other foreign recipients.

Session recording — one, not two

And here a correction is needed, because it is tempting to say «double session recording», but the capture does not confirm this. Both counters try to load the session-recording module, but it really works only on one — the Sogei instance, where the corresponding request passes successfully. The national platform has no such module: the request to it returns a «not found» error. That is, session recording here happens once, on Sogei’s side, while the second attempt simply fails. But even one is enough for the essence of the matter: session recording is observation of the visitor’s behaviour, not aggregate counting, and the policy stays silent about it. The same Sogei module has already appeared in the series on the sites of the tax authority and the cybersecurity agency — which means this is a trait of the shared government platform, and now it has surfaced on the government’s site.

«Anonymous, without profiling» — with a caveat

The policy describes the collection as anonymous and explicitly denies profiling. The capture refines the picture: both counters carry the visitor identifier — a marker by which a person can be recognised — and on one of them session recording is additionally conducted. IP masking is probably present, but the identifier plus behaviour recording sit poorly with the words «anonymous» and «without profiling». It would be more accurate to say «partially de-identified».

What cannot be claimed from the capture

A few honest caveats. The error when loading the recording module at the national platform means that in this session the session-recording data did not go there; whether it works there under other conditions cannot be judged from a single capture. On the IP masking I judge from the analytics’ default configuration; the visitor identifier, meanwhile, is visible right in the capture. Both analytics are government-run, so the question of the servers’ geography does not arise here. The capture covers the home page.

Conclusion

On the government’s own site two government counters work, each of which marks the visitor with an identifier, and on one of them session recording is additionally conducted — behaviour observation that the policy does not mention, promising in return anonymous statistics and the absence of profiling. A significant plus is that all this stays within the government infrastructure and does not leave the country. And an honest correction to the first impression: session recording here is one, not two — the second attempt simply fails. The main takeaway for the reader: the same session-recording module that we saw at the tax authority and the cybersecurity agency has reached the government’s site too — this is no longer the chance of an individual body, but a trait of the shared platform, and it ought to be either honestly described in the policy or have consent asked for it.

Evidence
Original (audit)
HAR file: it/governo-it-2026-06-15.har
SHA-256: 8a7b87cab1f8772bcea311db8c913b4475a2ca989f1d8cf9d1c52d3537ab6a1b
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Italian Data Protection Authority (Garante)garanteprivacy.it

To: Italian Data Protection Authority (Garante)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website governo.it.

2. Circumstances
I visited the website governo.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) The policy describes the navigation data as collected in anonymous form for statistics, denies profiling and, of third-party services, names only YouTube. In fact, two Matomo instances work — on Sogei's infrastructure (idsite=8) and in the national Web Analytics Italia platform (idsite=363) — and on the Sogei instance a session-recording module is additionally active (HeatmapSessionRecording, configs.php responds 200). This is the recording of visitor behaviour, not aggregate anonymous statistics, and it is not mentioned in the document. The same Sogei module has already appeared in the series on the sites of the tax authority and the cybersecurity agency — that is, this is a trait of the shared government platform.

2) The consent-management module is installed on the site, but the analytics and session recording fire independently of it. By the Italian regulator's position, behaviour monitoring requires consent and cannot pass as a technical cookie. Here consent is not requested.

Full technical documentation is published at: https://gdpru.eu/en/audits/it-governo-it/

3. Provisions violated
Art. 13(1)(e) and Art. 5(1)(a) GDPR — session recording not declared; Art. 6(1)(a) GDPR / regulator's guidance — behaviour recording without consent

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]