portaleservizi.mef.gov.it
The access portal for the services of Italy's Ministry of Economy and Finance. 83 requests, a single domain — not one external service. Dynatrace monitoring works on its own domain and sets not a single cookie, as described in the policy. And a rare case: the promise «data is not transferred abroad» is actually kept here.
Timeline of the leak
Declared versus actual
Detected trackers
- Dynatrace RUM — first-party, anonymised, without cookies
Context
portaleservizi.mef.gov.it is the access portal for the services of Italy’s Ministry of Economy and Finance. It is built on the Liferay platform and involves registration of users from organisations that receive the services. The capture shows 83 requests, all to a single domain. The policy correctly names the ministry itself as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. This is another case where comparing the document with the fact gives a match. So the analysis is about what is done right, and about one small legal nuance.
Was there a consent banner
There is no banner, and it is not needed. On the site there are technical cookies for the services’ operation and statistical ones in anonymised form, without profiling. Consent for anonymous statistics is not required, so the absence of a banner here is natural, not an oversight.
The declaration matches the fact
The policy does not name the specific tool, but precisely describes its nature: statistics in anonymised form, without profiling. And this fully coincides with what is visible in the capture. The monitoring here is its own, on the ministry’s own domain, and throughout the entire session it sets not a single cookie and assigns the visitor no persistent marker. No external services — no Google, no social networks, not even third-party fonts. I will separately note what on the government sites in the series often turned out to be false: the policy promises that data is not transferred abroad — and here this promise is kept. The site runs entirely on its own infrastructure, not a single request goes outward, so there is simply nothing to transfer outside the EU. After sites where the same phrase broke against an embedded YouTube or Google fonts, it is pleasant to record that here word and deed coincide.
A small nuance with the basis of processing
So that the analysis is not entirely uncritical, I will name the only thing one can nitpick — and immediately stipulate why this is a trifle. The policy justifies the statistics by «legitimate interest». The Italian regulator has questions about such a basis precisely for analytics: usually such statistics is conducted not through «legitimate interest», but as an essentially technical tool requiring no consent. But since the statistics here is anonymised, first-party and sets not a single cookie, it fits the technical regime anyway — the basis no longer plays a role. So this is a remark about the document’s wording, not about the site’s behaviour.
What cannot be claimed from the capture
A few honest caveats. The content of the telemetry goes out in the request body, which is not preserved in the lightweight export, so on the anonymisation I rely on the policy — and it is consistent with there being no cookie and no persistent identifier in the capture. The capture covers the part of the portal accessible without login; the behaviour of the sections after authentication is not visible from here. The exact server IP addresses are absent from the export, but the single domain belongs to the agency anyway.
Conclusion
A clean result in essence: a single domain, not one external tracker, not one cookie, anonymous statistics on its own infrastructure — exactly as described in the policy. And the promise not to transfer data abroad here, for once, does not diverge from the fact. The only nitpick is about the legal wording of the basis, and even that is removed by the anonymity of the implementation. The main takeaway for the reader: no third-party company learns of their visit to this portal, and the policy’s words and the site’s behaviour say one and the same thing.
e6da8a81c9ef9504bd0f8fb40846e1fd53825334f3f7344d0d3e4971d57119db