Policy changed — see what exactly · 2026-07-13 →
Salute.gov.it is the official website of Italy's Ministry of Health, that is, a category of special sensitivity (health subject matter, Art. 9). Home-page capture: 102 requests, 9 domains. For a health ministry the picture is decent: there are no third-party advertising trackers, no Google Analytics, no social plugins, not a single cookie was set during the session. The analytics is the government Web Analytics Italia (AgID), de-identified and exempt from consent. The videos are embedded in the YouTube no-cookie privacy mode, which sets no tracking cookies. The only thing that goes outward before consent is requests to Google: the autoloading of the YouTube embeds (they send a utility log_event) and the loading of Google Fonts, that is, the visitor's IP reaches Google. No violations recorded; this is a borderline clean case where the remarks are pinpoint.
Timeline of the leak
Declared versus actual
Detected trackers
- Web Analytics Italia (AgID)
- YouTube (no-cookie mode)
- Google Fonts
Context
www.salute.gov.it is the official website of Italy’s Ministry of Health. The data controller is the Ministero della Salute (Rome). This is a category of special sensitivity: the pages’ subject matter is connected with health, and the user’s very interest in particular sections already counts as delicate information. The site is informational: health news, campaigns (blood donation, rare diseases), documents and services. Capture: 102 requests to 9 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. The analytics is the government Web Analytics Italia. There are no third-party advertising trackers, no Google Analytics and no social plugins; the videos are embedded in the YouTube no-cookie privacy mode.
Who receives the data
Spotted here was: Google — and only in connection with the YouTube embeds and font loading. The government Web Analytics Italia analytics anonymises the data and keeps it within Italy’s infrastructure — nothing goes to advertising third parties. The YouTube videos are embedded via the privacy domain youtube-nocookie.com: it sets no tracking cookies, but loads the player from Google’s servers and sends a utility log_event, so Google does nonetheless receive the fact of the visit. The fonts are loaded from the Google Fonts domain — a static resource, but the IP is transmitted there.
Was there a consent banner
No consent banner or consent-collection platform was found on the site. In itself this is not a complaint here: the site sets no third-party tracking cookies (the policy explicitly states their absence, and the capture confirms this — no cookie was set at all), and the only analytics is government-run and exempt from consent. The only open question is the autoloading of the YouTube embeds: they load immediately, without the user’s choice, and transmit utility messages to Google. But this is privacy mode without cookies, and the policy itself mentions the video embedding.
What fires before consent
Before any user decision, the following fire:
- the government Web Analytics Italia analytics (de-identified, exempt from consent);
- the autoloading of the YouTube videos in no-cookie mode (without tracking cookies, but with requests to Google);
- the loading of Google Fonts (the IP goes to Google). There is no Google Analytics, no advertising networks, no social-network pixels, no social plugins, no third-party exchanges and no visitor identifiers. No cookies are set.
What is worth tightening up
The remarks are pinpoint and mild, but for a health ministry they are worth naming. First, the YouTube embeds load automatically and reach out to Google before any consent — this can be closed with «click to play», where the video and its player load only on a press. Second, the Google Fonts transmit the IP to Google and are not named in the policy — they can be hosted locally, and the document supplemented at the same time. Neither of these is data collection or profiling, so it does not affect the «no violations recorded» assessment — but on a health site, where the interest in sections is itself delicate, minimising external requests is especially fitting.
Conclusion
Salute.gov.it is an example of a configuration decent for the public sector, albeit not ideal. There are no third-party cookies (and this is explicitly stated in the policy and confirmed by the capture), no advertising and no Google Analytics, no social plugins, the analytics is government-run and de-identified, and the videos are embedded in the YouTube no-cookie privacy mode. Only pinpoint requests to Google remain — the autoloading of the YouTube embeds and the Google Fonts — in which the visitor’s IP reaches Google before consent. The main takeaway for the reader: this is restrained, mostly correct behaviour, especially valuable for a health site; to reach full cleanliness a few trifles are missing — deferring the video load until a click and removing the fonts from the Google domain. Against the backdrop of the commercial sites in the series, this is a model of how to minimise tracking when it is actually done.
421994ee42cffa08ba3e413afa761cb9682580c5475868c5ab53f670b6be7d2e