Sicurezzanazionale.gov.it is the portal of the Republic's Information Security System (Italy's intelligence community, DIS/AISE/AISI). Home-page capture: 47 requests, only 2 domains. This is an exemplarily clean case, and in the most sensitive category of the series at that. There are no third-party trackers at all: the analytics is its own, on its own domain, the data does not go to third parties; the only external contact is static video previews from YouTube. Not a single cookie was set during the session. There is a consent banner, and it is symmetrical — «accept» and «decline» are equal, with no dark patterns. No violations recorded; the only mild observation is that the YouTube previews are pulled from the Google domain, that is, the visitor's IP goes there.
Timeline of the leak
Declared versus actual
Detected trackers
- Own analytics on the site's domain
- YouTube (static video previews)
Context
www.sicurezzanazionale.gov.it is the official portal of the Republic’s Information Security System, that is, Italy’s intelligence community (the DIS Department and the AISE/AISI agencies under the President of the Council of Ministers). The data processing is subject to Legislative Decree 196/2003 in the part applicable to security bodies. The site is informational: about the structure, tasks, publications and security culture. Capture: 47 requests to only 2 domains, the home page, taken on a clean Edge browser with no VPN and no blocker. Of the two domains, one is its own, the second is YouTube, and only for the sake of static video previews. No third-party analytics, advertising or trackers.
Who receives the data
Spotted here was: Google — and only in the form of loading static video previews from YouTube. The site’s analytics is its own, deployed on its own domain: the navigation data, as stated in the policy, is collected anonymously and only for statistics, not transmitted to third parties. This is the right choice for a government site — not to hand analytics to an external provider.
Was there a consent banner
Yes, and it is done correctly. The banner offers an equal choice: «accept» and «decline» side by side, without a bias towards consent. A refusal (or closing) leaves only the technical default settings. By the banner’s text, the statistical cookies are first-party, not from third-party companies. In the clean session no choice was made, and throughout the entire session the site set not a single cookie. That is, the consent mechanism here is not decorative but genuinely works as a gate: without consent no non-technical cookies are set.
What fires before consent
Practically nothing of significance. Before any decision, only the following fires:
- the own analytics on the site’s domain (anonymous, the data does not go outward);
- the loading of four static video previews from YouTube. There is no Google Analytics, no advertising networks, no social-network pixels, no third-party exchanges and no visitor identifiers in the session. No cookies are set at all.
The only observation — previews from the Google domain
Exactly one thing is worth noting, and mildly. The video previews load from img.youtube.com, that is, from Google’s infrastructure. In themselves these are static images — without an embedded player and tracking scripts, and the policy explicitly stipulates that the YouTube functionality is configured so as not to track users’ behaviour. But when any external resource loads, its server receives the visitor’s IP address — and here this is a Google domain in the USA. For an ordinary site a trifle; for an intelligence-community portal, the only detail that can be closed if desired, by hosting the previews locally. This does not affect the «no violations recorded» assessment.
Conclusion
Sicurezzanazionale.gov.it is an example of how a sensitive government site should look. There is no third-party tracking: the analytics is its own and anonymous, there is no advertising and no trackers, no cookies are set, and the consent banner is done honestly — with an equal refusal, without dark patterns, and it genuinely holds back non-technical cookies until consent. The only thing that goes outward at all is static video previews from the Google domain, and the policy explicitly names this third-party service and stipulates its configuration without tracking. The main takeaway for the reader: an exemplary configuration is technically achievable, and here it is implemented — even for a security body, where it is especially fitting. The contrast with the commercial sites in the series shows that the matter is not technical limitations but choice.
a386bb496994cd508615bb3b81aefe8a3e75cf649ddf0976f8d7a2306586f91a