Technical audit · 2026-05-26

oenb.at

National Bank of Austria

National Bank of Austria — 81 requests, 4 domains. The one external service, consentmanager.net: the CMP loads first, blocking everything else. Matomo On-Premise is declared with two legal bases — it did not appear in the HAR.

Timeline of the leak

+647 ms · consentmanager autoblocking
cdn.consentmanager.net loads the autoblocking script — it blocks all trackers until consent is obtained.
+983–2468 ms · CMP initialization
consentmanager.net loads the CMP, configuration, logos, and language flags. The banner is displayed.
Session total
Matomo, YouTube, social networks — did not appear in the HAR. Autoblocking holds. 81 requests, 13 of them to consentmanager.net.

Declared versus actual

Matomo On-Premise — declared, Art. 6(1)(f) for anonymous analytics, Art. 6(1)(a) for cookie-based tracking, absent from the HAR — заявлен
YouTube, X, LinkedIn, SoundCloud, Flickr, Bluesky — declared as embedded content — заявлен
captcha.eu and Friendly Captcha — declared for forms, Art. 6(1)(f) — заявлен

Transfer timings

+647 ms cdn.consentmanager.net

Autoblocking script — the first external request, blocks trackers until consent.

Context

OeNB (Oesterreichische Nationalbank) is Austria’s central bank, a member of the ECB’s Eurosystem. HAR: 81 requests, 4 domains.

Consentmanager — first in line

The only external service is consentmanager.net, an Austrian CMP provider. It loads before everything else: the autoblocking script at +647 ms intercepts all subsequent tracker requests and holds them until the user makes a choice. 13 requests to consentmanager.net per session — initialization, configuration, cross-domain synchronization.

Matomo declared carefully

The privacy policy distinguishes between two Matomo modes: anonymous server-side analytics based on legitimate interest (Art. 6(1)(f)) and cookie-based tracking based on consent (Art. 6(1)(a) + TKG § 165). Matomo did not appear in the HAR — autoblocking worked. Captcha is handled via the Austrian service captcha.eu, rather than Google reCAPTCHA.

Conclusion

OeNB has built an architecture where the CMP genuinely blocks trackers, the policy distinguishes legal bases clearly, and external dependencies are reduced to a single consent-management tool. The central bank meets the very standard it regulates for financial institutions.

Evidence
Original (audit)
HAR file: at/oenb-at-2026-05-26.har
SHA-256: d5a9d5896956c211785bef4a04f7cfd073dcbb4d6660ceb8da3b9c11b075858b
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.