Technical audit · 2026-05-29

bnb.bg

Bulgarian National Bank

The Bulgarian National Bank (BNB) — 58 requests, a single domain. All resources, including scripts, stylesheets, and images, are hosted locally on the site's own domain; there are no external calls, trackers, font services, or CDNs whatsoever. No cookies are set. The policy declares only technical session cookies — the capture confirms this. No violations have been recorded.

Timeline of the leak

+0 ms · portal load
All resources — HTML, stylesheets, scripts, images — are served from the first-party domain bnb.bg (Apache), from the bnbweb directory. HSTS and X-Frame-Options SAMEORIGIN headers are present.
local resources
Scripts, CSS, and images are served from the site's own domain, with no calls to external font services, CDNs, or analytics.
no consent banner required
There is no consent management platform or consent banner on the page. There are no third-party resources on the page requiring consent; technical cookies do not require consent.
no third-party calls
Google, analytics, maps, advertising, and session recording are absent from the capture. All calls are confined to the first-party domain.

Declared versus actual

BNB Personal Data Processing Policy, Section II 'Visits to the BNB website (Cookie Policy)' — technical cookies only, for functionality and session purposes — заявлен
Cookies are deleted automatically upon session termination; no data linkable to a specific visitor is retained — заявлен

Context

bnb.bg is the website of the Bulgarian National Bank (Българска народна банка, BNB), the central bank of Bulgaria. The Bank is responsible for monetary policy, banking system supervision, and payment systems, and maintains the Central Credit Register (CCR) and the Register of Bank Accounts and Safe Deposit Boxes (RBASDB). The data controller is the BNB. The site is served by an Apache server, with resources delivered from the bnbweb directory. Capture: 58 requests, a single domain, recorded in a clean browser.

Declared versus Actual

The BNB’s policy contains a dedicated section on cookies and states directly that the site uses only those cookies necessary for its full functionality and the operation of its services — for example, to identify and maintain the visitor’s session, and to maintain the authentication chain when using electronic administrative services. The policy separately states that information capable of being linked to a specific visitor is not retained, and that the cookies themselves are deleted automatically upon session termination. The policy makes no mention of analytics, third-party services, font providers, or CDNs.

The capture confirms this in full. All 58 requests go to the single domain bnb.bg; there is not a single external domain present in the capture whatsoever — no font services, no CDNs, no analytics, no advertising pixels, no session recording. Scripts, stylesheets, and images are served locally from the bnbweb directory. Inspection of the first-party domain’s paths revealed no hidden analytics or build endpoints. No cookies are set (Set-Cookie is zero). The responses carry a Content Security Policy (CSP), as well as HSTS and X-Frame-Options SAMEORIGIN headers.

Accordingly, no discrepancy between “declared” and “actual” arises: only technical cookies are declared, and in fact not even those are set, with the site making no external calls whatsoever.

All calls go to the site’s own domain. There are no third-party resources on the page requiring consent; no cookies are set, and a consent banner is therefore unnecessary here. For the website of a central bank, this is exemplary behavior.

What Cannot Be Asserted from This Capture

The capture covers the bnb.bg home page in its pre-consent state. The Bank’s electronic administrative services and authenticated sections, where session and authentication cookies may be set under the policy, are not covered by this capture; such technical cookies do not require consent. Server-side processing is not visible in a browser-based capture.

Conclusion

The website of the central bank of Bulgaria demonstrates a fully self-sufficient configuration: all resources, including scripts, stylesheets, and images, are hosted locally on the site’s own domain, there are no external calls whatsoever, trackers, font services, and CDNs are absent, and no cookies are set. What is declared in the policy — technical session cookies only — matches actual behavior, and the capture shows that not even those are set. No violations have been recorded in the capture.

Evidence
Original (audit)
HAR file: bg/bnb-bg-2026-05-29.har
SHA-256: 522064bc09e9121fb0d9eef68ec6f4b20648dd9d8cff012305b42c9086311397
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.