The Bulgarian National Bank (BNB) — 58 requests, a single domain. All resources, including scripts, stylesheets, and images, are hosted locally on the site's own domain; there are no external calls, trackers, font services, or CDNs whatsoever. No cookies are set. The policy declares only technical session cookies — the capture confirms this. No violations have been recorded.
Timeline of the leak
Declared versus actual
Context
bnb.bg is the website of the Bulgarian National Bank (Българска народна банка, BNB), the central bank of Bulgaria. The Bank is responsible for monetary policy, banking system supervision, and payment systems, and maintains the Central Credit Register (CCR) and the Register of Bank Accounts and Safe Deposit Boxes (RBASDB). The data controller is the BNB. The site is served by an Apache server, with resources delivered from the bnbweb directory. Capture: 58 requests, a single domain, recorded in a clean browser.
Declared versus Actual
The BNB’s policy contains a dedicated section on cookies and states directly that the site uses only those cookies necessary for its full functionality and the operation of its services — for example, to identify and maintain the visitor’s session, and to maintain the authentication chain when using electronic administrative services. The policy separately states that information capable of being linked to a specific visitor is not retained, and that the cookies themselves are deleted automatically upon session termination. The policy makes no mention of analytics, third-party services, font providers, or CDNs.
The capture confirms this in full. All 58 requests go to the single domain bnb.bg; there is not a single external domain present in the capture whatsoever — no font services, no CDNs, no analytics, no advertising pixels, no session recording. Scripts, stylesheets, and images are served locally from the bnbweb directory. Inspection of the first-party domain’s paths revealed no hidden analytics or build endpoints. No cookies are set (Set-Cookie is zero). The responses carry a Content Security Policy (CSP), as well as HSTS and X-Frame-Options SAMEORIGIN headers.
Accordingly, no discrepancy between “declared” and “actual” arises: only technical cookies are declared, and in fact not even those are set, with the site making no external calls whatsoever.
Timing Relative to Consent
All calls go to the site’s own domain. There are no third-party resources on the page requiring consent; no cookies are set, and a consent banner is therefore unnecessary here. For the website of a central bank, this is exemplary behavior.
What Cannot Be Asserted from This Capture
The capture covers the bnb.bg home page in its pre-consent state. The Bank’s electronic administrative services and authenticated sections, where session and authentication cookies may be set under the policy, are not covered by this capture; such technical cookies do not require consent. Server-side processing is not visible in a browser-based capture.
Conclusion
The website of the central bank of Bulgaria demonstrates a fully self-sufficient configuration: all resources, including scripts, stylesheets, and images, are hosted locally on the site’s own domain, there are no external calls whatsoever, trackers, font services, and CDNs are absent, and no cookies are set. What is declared in the policy — technical session cookies only — matches actual behavior, and the capture shows that not even those are set. No violations have been recorded in the capture.
522064bc09e9121fb0d9eef68ec6f4b20648dd9d8cff012305b42c9086311397