Technical audit · 2026-06-15

uniroma1.it

Public University — Sapienza, Rome

Sapienza is Italy's largest university and one of the largest in Europe. The capture was taken on the alumni section: 89 requests, only 3 domains. This is a clean case in the series: no Google, no advertising, no profiling, not a single cookie set throughout the entire session. The analytics is only the government Web Analytics Italia (AgID, the Matomo engine): it anonymises the IP, keeps the data within Italy's government infrastructure, requires no consent and is explicitly named in the cookie policy. The only third-party request besides it is the loading of the Font Awesome icon font from an American CDN; it sets no cookies and collects no data, but is not mentioned in the policy. No violations recorded.

Timeline of the leak

223 ms · consent banner and icon font
The styles of the site's own cookie banner (a built-in mechanism, on Drupal) and the Font Awesome icon font from the third-party CDN maxcdn.bootstrapcdn.com load. The CDN is American — that is, the visitor's IP goes to the USA already at this step.
589 ms · government analytics
The Web Analytics Italia analytics script (the Matomo engine, operator AgID) loads. This is the only analytics on the site.
732 ms · page view goes to WAI
A page-view message goes to the WAI analytics (the «Laureati» section). The transmission is anonymised, the data stays within Italy's government infrastructure; this type of collection requires no consent.

Declared versus actual

Web Analytics Italia — заявлен
+ Font Awesome (BootstrapCDN) — не заявлен

Detected trackers

Context

www.uniroma1.it is the portal of Sapienza, the public University of Rome, the largest in Italy and one of the largest in Europe. The controller is Sapienza — Università degli studi di Roma (Rome, Piazzale Aldo Moro, 5). The capture was taken on the alumni section. Capture: 89 requests to only 3 domains, taken on a clean Edge browser with no VPN and no blocker. Of the three domains, one is its own, the second is the government analytics, the third is a third-party CDN with a static font. The site’s cookie banner is its own, built-in. Against the backdrop of the series, this is the cleanest site: there is no advertising-and-analytics layer at all.

Who receives the data

Spotted here were: Web Analytics Italia (AgID), BootstrapCDN. Both roles are mild. Web Analytics Italia is the government analytics platform, to which Sapienza migrated on AgID’s instructions: it anonymises the IP, stores the data on servers in Italy and is designed to work without consent. BootstrapCDN is a third-party American CDN from which the Font Awesome icon font loads; it sets no cookies and collects no data, but by the very fact of loading receives the visitor’s IP.

Yes. The site’s cookie banner is its own, built-in (on Drupal), and appears on first contact. No «accepted/declined» decision was made in this visit — the capture was taken in a clean session. But the key point here is different: consent is not in principle a condition being bypassed here. Throughout the whole session the site set not a single cookie, and the only analytics — the government WAI — belongs to the category of collection requiring no consent. That is, before the user’s decision nothing fires that would require that decision.

Practically nothing requiring attention:

  • the loading of the Font Awesome icon font from a third-party American CDN (a static resource, without cookies);
  • the government WAI analytics — anonymised and exempt from consent by its design. No advertising requests, no social-network pixels, no Google Analytics, no third-party exchanges and no visitor identifiers were recorded in the session. No cookies are set at all.

The only observation — a font from a US CDN

Exactly one thing is worth noting, and mildly. The Font Awesome icon font loads from an American CDN (maxcdn.bootstrapcdn.com). In itself it sets no cookies and does no tracking, but when any external resource loads it receives the visitor’s IP address — and the IP counts as personal data. In Sapienza’s cookie policy this third-party CDN is not named: the policy honestly describes WAI and session cookies, but stays silent about the font loading from the USA. This is not data collection or profiling — merely a pinpoint inconsistency between «only technical cookies, first- and third-party» in the policy text and the actual transmission of the IP to an external CDN in the USA. Keep it in view as an observation, not a violation.

Conclusion

Sapienza is a model of how a government site without an advertising-and-analytics layer can look. There is no profiling, no advertising recipients, no Google and no social networks, no cookies set, and the only analytics is government-run, anonymised and exempt from consent in advance, and explicitly named in the policy at that. The main takeaway for the reader: this is a working counter-example to the whole series — the technical possibility of running a large public portal without leaking anything before consent exists and is implemented. The only trifle worth noting honestly is the icon font from an American CDN, transmitting the IP outside the EU and not mentioned in the cookie policy; it does not affect the «no violations recorded» assessment, but shows that even clean sites have details to tighten up.

Evidence
Original (audit)
HAR file: it/uniroma1-it-2026-06-15.har
SHA-256: fd425c12c6d565e81865c9eec7e99a7a76c1f55ace1a2889611a7dca1a29e68b
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.