libertaciviliimmigrazione.dlci.interno.gov.it
Policy changed — see what exactly · 2026-08-14 →
The portal of the Department for Civil Liberties and Immigration of Italy's Ministry of the Interior. 67 requests, a single domain — not one external service. Drupal on the standard government theme; a cookie-banner module is installed, but throughout the entire session not a single cookie was set — it has nothing to permit. Given that the portal is read by migrants and citizenship applicants, the absence of tracking here is especially fitting.
Timeline of the leak
Context
libertaciviliimmigrazione.dlci.interno.gov.it is the portal of the Department for Civil Liberties and Immigration of Italy’s Ministry of the Interior. Here news about citizenship, migrant integration and departmental circulars is published. It is built on Drupal, on the standard government theme. The capture shows 67 requests, all to a single domain. The policy correctly names the Ministry of the Interior itself as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. This portal has a special audience: it is read by people in a vulnerable position — migrants, citizenship applicants, those looking into their rights. For them the question «who sees what I read here» is not abstract. And it is all the more important that the answer here is — no outsider.
Was there a consent banner
Formally the consent mechanism is installed on the site — the styles and script of the standard cookie-banner module load. But throughout the entire session not a single cookie was set, so it has nothing to obtain consent for. What results is almost a paradox: the infrastructure for requesting consent is there, but there is nothing to collect with it. For the user this is the best possible outcome — not «a banner that does not work», but «a banner that has nothing to fire on».
Complete absence of trackers
The picture is extremely clean: not a single external domain, not a single cookie, not a single analytics script throughout the entire session. Only the portal’s pages and its own images. The policy, meanwhile, contains no separate section on cookies at all — and this is not an oversight but an honest reflection of the fact: there is nothing to collect via cookies. The section on navigation data describes only server logs — IP address, request address, time — which are used for general attendance statistics and monitoring the portal’s operation. This is standard server-side processing, it happens on the server side and does not manifest in the browser’s requests.
What cannot be claimed from the capture
A few honest caveats. The capture covers the portal’s public news pages; the behaviour of internal or service sections is not visible from here. The server-side log statistics mentioned in the policy by their nature are not reflected in the browser capture, so I record only the absence of client-side trackers and cookies. The exact server IP addresses are not preserved in the lightweight export, but this does not matter: the single domain belongs to the agency itself.
Conclusion
A clean result with no substantive caveats: no trackers, no cookies, no third-party domains, no discrepancies with the policy. The processing is reduced to server logs for statistics — the minimum necessary for the site’s operation. Against the backdrop of portals that handed visitors over to Google and Meta from the first second, here there is not a single point of leakage. And given who reads this portal — people for whom the privacy of reading may be truly important — such asceticism is not merely formally correct, but fitting in essence. The main takeaway for the reader: no one but the agency itself will learn of their visit here.
461efb079e5d9a4d1bc100520fd1fbe580917774d0cd6d50bdacfbc4380e5191