Technical audit · 2026-06-15

salute.gov.it

Website of Italy's Ministry of Health

Salute.gov.it is the official website of Italy's Ministry of Health, that is, a category of special sensitivity (health subject matter, Art. 9). Home-page capture: 102 requests, 9 domains. For a health ministry the picture is decent: there are no third-party advertising trackers, no Google Analytics, no social plugins, not a single cookie was set during the session. The analytics is the government Web Analytics Italia (AgID), de-identified and exempt from consent. The videos are embedded in the YouTube no-cookie privacy mode, which sets no tracking cookies. The only thing that goes outward before consent is requests to Google: the autoloading of the YouTube embeds (they send a utility log_event) and the loading of Google Fonts, that is, the visitor's IP reaches Google. No violations recorded; this is a borderline clean case where the remarks are pinpoint.

Timeline of the leak

156–381 ms · government analytics
The government Web Analytics Italia (AgID) analytics loads and sends a de-identified page view. The data is anonymised, stays within Italy's infrastructure, this type of collection requires no consent.
423 ms · YouTube autoloading in no-cookie mode
The videos on the page are embedded via the privacy domain youtube-nocookie.com and load automatically. This mode sets no tracking cookies, but the embed loads the player from Google's servers.
555 ms · Google Fonts
A font loads from the Google domain (fonts.gstatic.com). A static resource, but the visitor's IP goes to Google in the process. This third-party domain is not named in the policy.
1747–2097 ms · Google anti-abuse attestation
Utility requests of the YouTube player to Google fire (environment check). This is part of the embed's mechanics, not a separate tracker.
around 4.7 seconds · YouTube log_event
The embed sends a utility impression message to Google (log_event). That is, data about the visit goes to Google, but without cookies and without a tracking identifier.
there is no consent banner, no cookie set
No consent-collection platform or cookie banner was found. Throughout the entire session the site set not a single cookie, and the policy explicitly states that the site uses no third-party cookies.

Declared versus actual

Web Analytics Italia — заявлен
YouTube — заявлен
+ Google Fonts — не заявлен

Detected trackers

Context

www.salute.gov.it is the official website of Italy’s Ministry of Health. The data controller is the Ministero della Salute (Rome). This is a category of special sensitivity: the pages’ subject matter is connected with health, and the user’s very interest in particular sections already counts as delicate information. The site is informational: health news, campaigns (blood donation, rare diseases), documents and services. Capture: 102 requests to 9 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. The analytics is the government Web Analytics Italia. There are no third-party advertising trackers, no Google Analytics and no social plugins; the videos are embedded in the YouTube no-cookie privacy mode.

Who receives the data

Spotted here was: Google — and only in connection with the YouTube embeds and font loading. The government Web Analytics Italia analytics anonymises the data and keeps it within Italy’s infrastructure — nothing goes to advertising third parties. The YouTube videos are embedded via the privacy domain youtube-nocookie.com: it sets no tracking cookies, but loads the player from Google’s servers and sends a utility log_event, so Google does nonetheless receive the fact of the visit. The fonts are loaded from the Google Fonts domain — a static resource, but the IP is transmitted there.

No consent banner or consent-collection platform was found on the site. In itself this is not a complaint here: the site sets no third-party tracking cookies (the policy explicitly states their absence, and the capture confirms this — no cookie was set at all), and the only analytics is government-run and exempt from consent. The only open question is the autoloading of the YouTube embeds: they load immediately, without the user’s choice, and transmit utility messages to Google. But this is privacy mode without cookies, and the policy itself mentions the video embedding.

Before any user decision, the following fire:

  • the government Web Analytics Italia analytics (de-identified, exempt from consent);
  • the autoloading of the YouTube videos in no-cookie mode (without tracking cookies, but with requests to Google);
  • the loading of Google Fonts (the IP goes to Google). There is no Google Analytics, no advertising networks, no social-network pixels, no social plugins, no third-party exchanges and no visitor identifiers. No cookies are set.

What is worth tightening up

The remarks are pinpoint and mild, but for a health ministry they are worth naming. First, the YouTube embeds load automatically and reach out to Google before any consent — this can be closed with «click to play», where the video and its player load only on a press. Second, the Google Fonts transmit the IP to Google and are not named in the policy — they can be hosted locally, and the document supplemented at the same time. Neither of these is data collection or profiling, so it does not affect the «no violations recorded» assessment — but on a health site, where the interest in sections is itself delicate, minimising external requests is especially fitting.

Conclusion

Salute.gov.it is an example of a configuration decent for the public sector, albeit not ideal. There are no third-party cookies (and this is explicitly stated in the policy and confirmed by the capture), no advertising and no Google Analytics, no social plugins, the analytics is government-run and de-identified, and the videos are embedded in the YouTube no-cookie privacy mode. Only pinpoint requests to Google remain — the autoloading of the YouTube embeds and the Google Fonts — in which the visitor’s IP reaches Google before consent. The main takeaway for the reader: this is restrained, mostly correct behaviour, especially valuable for a health site; to reach full cleanliness a few trifles are missing — deferring the video load until a click and removing the fonts from the Google domain. Against the backdrop of the commercial sites in the series, this is a model of how to minimise tracking when it is actually done.

Evidence
Original (audit)
HAR file: it/salute-gov-it-2026-06-15.har
SHA-256: 421994ee42cffa08ba3e413afa761cb9682580c5475868c5ab53f670b6be7d2e
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.