Technical audit · 2026-06-15

portaleservizi.mef.gov.it

Services Portal of Italy's Ministry of Economy and Finance

The access portal for the services of Italy's Ministry of Economy and Finance. 83 requests, a single domain — not one external service. Dynatrace monitoring works on its own domain and sets not a single cookie, as described in the policy. And a rare case: the promise «data is not transferred abroad» is actually kept here.

Timeline of the leak

+0–264 ms · portal load
The portal runs on the Liferay platform, on the standard government theme. The fonts are self-hosted, not from Google. The Dynatrace monitoring agent loads from its own domain at +265 ms.
not applicable — there is no banner, and it is not needed
There is no consent banner, and this is lawful. Technical cookies for the services' operation and statistical ones — in anonymised form, without profiling — are used. Consent for such anonymous statistics is not required, so there is no banner.
+2310–5016 ms · Dynatrace telemetry
Five utility monitoring transmissions over the course of the session — the usual behaviour of such an agent. Not a single cookie throughout the entire session, which matches the declared anonymised configuration.

Declared versus actual

Statistical cookies in anonymised form (in fact — Dynatrace) — declared

Detected trackers

Context

portaleservizi.mef.gov.it is the access portal for the services of Italy’s Ministry of Economy and Finance. It is built on the Liferay platform and involves registration of users from organisations that receive the services. The capture shows 83 requests, all to a single domain. The policy correctly names the ministry itself as the data controller. The capture, like the whole series, was taken on a clean Edge browser with no VPN and no blocker. This is another case where comparing the document with the fact gives a match. So the analysis is about what is done right, and about one small legal nuance.

There is no banner, and it is not needed. On the site there are technical cookies for the services’ operation and statistical ones in anonymised form, without profiling. Consent for anonymous statistics is not required, so the absence of a banner here is natural, not an oversight.

The declaration matches the fact

The policy does not name the specific tool, but precisely describes its nature: statistics in anonymised form, without profiling. And this fully coincides with what is visible in the capture. The monitoring here is its own, on the ministry’s own domain, and throughout the entire session it sets not a single cookie and assigns the visitor no persistent marker. No external services — no Google, no social networks, not even third-party fonts. I will separately note what on the government sites in the series often turned out to be false: the policy promises that data is not transferred abroad — and here this promise is kept. The site runs entirely on its own infrastructure, not a single request goes outward, so there is simply nothing to transfer outside the EU. After sites where the same phrase broke against an embedded YouTube or Google fonts, it is pleasant to record that here word and deed coincide.

A small nuance with the basis of processing

So that the analysis is not entirely uncritical, I will name the only thing one can nitpick — and immediately stipulate why this is a trifle. The policy justifies the statistics by «legitimate interest». The Italian regulator has questions about such a basis precisely for analytics: usually such statistics is conducted not through «legitimate interest», but as an essentially technical tool requiring no consent. But since the statistics here is anonymised, first-party and sets not a single cookie, it fits the technical regime anyway — the basis no longer plays a role. So this is a remark about the document’s wording, not about the site’s behaviour.

What cannot be claimed from the capture

A few honest caveats. The content of the telemetry goes out in the request body, which is not preserved in the lightweight export, so on the anonymisation I rely on the policy — and it is consistent with there being no cookie and no persistent identifier in the capture. The capture covers the part of the portal accessible without login; the behaviour of the sections after authentication is not visible from here. The exact server IP addresses are absent from the export, but the single domain belongs to the agency anyway.

Conclusion

A clean result in essence: a single domain, not one external tracker, not one cookie, anonymous statistics on its own infrastructure — exactly as described in the policy. And the promise not to transfer data abroad here, for once, does not diverge from the fact. The only nitpick is about the legal wording of the basis, and even that is removed by the anonymity of the implementation. The main takeaway for the reader: no third-party company learns of their visit to this portal, and the policy’s words and the site’s behaviour say one and the same thing.

Evidence
Original (audit)
HAR file: it/portaleservizi-mef-gov-it-2026-06-15.har
SHA-256: e6da8a81c9ef9504bd0f8fb40846e1fd53825334f3f7344d0d3e4971d57119db
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.