Policy changed — see what exactly · 2026-08-14 →
The website of the Government of Italy (Presidenza del Consiglio dei Ministri). 66 requests, 3 domains. Two government Matomo counters work in parallel, both carry the visitor identifier, and on one of them session recording is active — behaviour observation that the policy does not mention. Meanwhile nothing leaves the country.
Timeline of the leak
Declared versus actual
Detected trackers
- Matomo / Sogei (dmlws-analytics.sogei.it, idsite=8) — carries the visitor identifier, with a session-recording module
- Matomo / Web Analytics Italia (ingestion.webanalytics.italia.it, idsite=363) — carries the visitor identifier
Indicators of GDPR non-compliance
- Art. 13(1)(e) and Art. 5(1)(a) GDPR — session recording not declaredThe policy describes the navigation data as collected in anonymous form for statistics, denies profiling and, of third-party services, names only YouTube. In fact, two Matomo instances work — on Sogei's infrastructure (idsite=8) and in the national Web Analytics Italia platform (idsite=363) — and on the Sogei instance a session-recording module is additionally active (HeatmapSessionRecording, configs.php responds 200). This is the recording of visitor behaviour, not aggregate anonymous statistics, and it is not mentioned in the document. The same Sogei module has already appeared in the series on the sites of the tax authority and the cybersecurity agency — that is, this is a trait of the shared government platform.
- Art. 6(1)(a) GDPR / regulator's guidance — behaviour recording without consentThe consent-management module is installed on the site, but the analytics and session recording fire independently of it. By the Italian regulator's position, behaviour monitoring requires consent and cannot pass as a technical cookie. Here consent is not requested.
Context
governo.it is the official website of the Government of Italy, the office of the President of the Council of Ministers. It is built on Drupal. The capture shows 66 requests to three domains: the site itself, the analytics of the government contractor Sogei and the national analytics platform. The government office is correctly named as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. This is the highest-level site among those analysed, and it is all the more interesting that two patterns familiar from the series intersect on it. But one of them is not on the scale it might have seemed, and this is worth clarifying honestly.
Who receives the data
Spotted here were: Sogei, Web Analytics Italia (both government-run, Italy).
Was there a consent banner
The consent-management module is installed on the site — its script loads at the start of the visit. But it does not hold back the analytics: both counters and the session recording fire independently of it. For anonymous government statistics consent is not required anyway, but, as seen below, session recording does not fall under this exemption. It is also worth noting that both measurements carry the visitor identifier, so the «anonymity» here comes with a caveat.
Two government counters at once
Two different Matomo instances work in parallel on the site — on Sogei’s infrastructure and in the national Web Analytics Italia platform — with different site identifiers, both recording the same visit almost synchronously. This is already the fourth case of a «double counter» in the series after the medicines agency, the research council and Rome. An important plus here specifically: both counters are government-run, and nothing leaves the country — no Google, no other foreign recipients.
Session recording — one, not two
And here a correction is needed, because it is tempting to say «double session recording», but the capture does not confirm this. Both counters try to load the session-recording module, but it really works only on one — the Sogei instance, where the corresponding request passes successfully. The national platform has no such module: the request to it returns a «not found» error. That is, session recording here happens once, on Sogei’s side, while the second attempt simply fails. But even one is enough for the essence of the matter: session recording is observation of the visitor’s behaviour, not aggregate counting, and the policy stays silent about it. The same Sogei module has already appeared in the series on the sites of the tax authority and the cybersecurity agency — which means this is a trait of the shared government platform, and now it has surfaced on the government’s site.
«Anonymous, without profiling» — with a caveat
The policy describes the collection as anonymous and explicitly denies profiling. The capture refines the picture: both counters carry the visitor identifier — a marker by which a person can be recognised — and on one of them session recording is additionally conducted. IP masking is probably present, but the identifier plus behaviour recording sit poorly with the words «anonymous» and «without profiling». It would be more accurate to say «partially de-identified».
What cannot be claimed from the capture
A few honest caveats. The error when loading the recording module at the national platform means that in this session the session-recording data did not go there; whether it works there under other conditions cannot be judged from a single capture. On the IP masking I judge from the analytics’ default configuration; the visitor identifier, meanwhile, is visible right in the capture. Both analytics are government-run, so the question of the servers’ geography does not arise here. The capture covers the home page.
Conclusion
On the government’s own site two government counters work, each of which marks the visitor with an identifier, and on one of them session recording is additionally conducted — behaviour observation that the policy does not mention, promising in return anonymous statistics and the absence of profiling. A significant plus is that all this stays within the government infrastructure and does not leave the country. And an honest correction to the first impression: session recording here is one, not two — the second attempt simply fails. The main takeaway for the reader: the same session-recording module that we saw at the tax authority and the cybersecurity agency has reached the government’s site too — this is no longer the chance of an individual body, but a trait of the shared platform, and it ought to be either honestly described in the policy or have consent asked for it.
8a7b87cab1f8772bcea311db8c913b4475a2ca989f1d8cf9d1c52d3537ab6a1bWhere to file: Italian Data Protection Authority (Garante) — garanteprivacy.it
To: Italian Data Protection Authority (Garante) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website governo.it. 2. Circumstances I visited the website governo.it and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 15 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) The policy describes the navigation data as collected in anonymous form for statistics, denies profiling and, of third-party services, names only YouTube. In fact, two Matomo instances work — on Sogei's infrastructure (idsite=8) and in the national Web Analytics Italia platform (idsite=363) — and on the Sogei instance a session-recording module is additionally active (HeatmapSessionRecording, configs.php responds 200). This is the recording of visitor behaviour, not aggregate anonymous statistics, and it is not mentioned in the document. The same Sogei module has already appeared in the series on the sites of the tax authority and the cybersecurity agency — that is, this is a trait of the shared government platform. 2) The consent-management module is installed on the site, but the analytics and session recording fire independently of it. By the Italian regulator's position, behaviour monitoring requires consent and cannot pass as a technical cookie. Here consent is not requested. Full technical documentation is published at: https://gdpru.eu/en/audits/it-governo-it/ 3. Provisions violated Art. 13(1)(e) and Art. 5(1)(a) GDPR — session recording not declared; Art. 6(1)(a) GDPR / regulator's guidance — behaviour recording without consent 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]