Technical audit · 2026-05-29

bnr.bg

Bulgarian National Radio

Bulgarian National Radio (BNR) — 520 requests, 113 domains. Full-scale advertising monetization: the Google advertising tag (GPT) launches at +902 ms, before the consent banner even appears (+1826 ms), after which the visitor's IP address and identifiers are dispersed to more than 100 third-party advertising platforms. No consent is collected during the session: partners receive an empty TCF string placeholder and a gdpr=0 signal, while Google Analytics sends data flagged as 'consent not given.' The Cookie Policy, meanwhile, states that advertising cookies are used only with consent.

Timeline of the leak

+0…+879 ms · portal load
Markup, scripts, stylesheets, and fonts — served from the first-party domain bnr.bg (Next.js, x-powered-by: Next.js). Fonts are local, from the _next/static directory.
+902 ms · Google advertising prior to the banner
securepubads.g.doubleclick.net/tag/js/gpt.js (Google Publisher Tag) and player.bidmatic.io (prebid) launch immediately after the bundle loads — before the consent banner appears.
+1826 ms · CMP appears after advertising
fundingchoicesmessages.google.com — loading of Google Funding Choices (the consent banner). By this point, the Google advertising tag has already executed.
+2959…+9000 ms · wave of cookie-sync
After the banner appears, but still without consent, identifier synchronization proceeds with more than 100 domains: Criteo, Rubicon, PubMatic, OpenX, Xandr, Index Exchange, Teads, Outbrain, Adform, Smart/Equativ, Media.net, 33Across, ID5, InMobi, TripleLift, RTB House, Smaato, LoopMe, Eskimi, BidSwitch, Opera Ads, and others. 91 cookie-sync redirect chains.

Declared versus actual

Cookie Policy — advertising and targeting cookies only with consent ('ни е необходимо Вашето съгласие') — заявлен
Privacy Policy — processing via cookies is based on consent expressed on the site — заявлен
Google DoubleClick for Publishers named specifically; others described generically as 'advertisers and advertising networks' — заявлен
+ No TCF consent string is passed to partners — the placeholder gdpr_consent={gdpr_consent} is sent instead — не заявлен
+ gdpr=0 (a signal that 'GDPR does not apply') in 177 requests to advertising partners — не заявлен
+ A named list of the dozens of advertising recipients (Criteo, Rubicon, PubMatic, OpenX, Xandr, Teads, Outbrain, Adform, 33Across, ID5, InMobi, and others), a significant proportion of which are located in the USA — не заявлен

Transfer timings

+902 ms securepubads.g.doubleclick.net

Google Publisher Tag (GPT). Google, USA. Launches before the CMP.

+1826 ms fundingchoicesmessages.google.com

Google Funding Choices — the consent banner.

+2959 ms ident.mygaru.com

First identifier synchronization. A wave of cookie-sync follows.

+3124 ms region1.google-analytics.com

Google Analytics G-FDKFTKB3MV. Telemetry flagged as 'consent not given.'

Detected trackers

Indicators of GDPR non-compliance

Context

bnr.bg is the website of Bulgarian National Radio (Българско национално радио, BNR), the country’s public broadcaster and one of Bulgaria’s three public media organizations, alongside the national television broadcaster and the national news agency. The data controller is BNR. The site is built on Next.js. The broadcaster maintains a Privacy Policy and a separate Cookie Policy. Capture: 520 requests, 113 domains, recorded in a clean browser.

Google (USA) — the GPT advertising tag, Google Analytics, Funding Choices. Criteo, Rubicon (Magnite), PubMatic, OpenX, Xandr, Index Exchange, Teads, Outbrain, Adform, Smart/Equativ, Media.net, 33Across, ID5, InMobi, TripleLift, Sharethrough, RTB House, Smaato, LoopMe, Eskimi, BidSwitch, Opera Ads, Temu — IP address and identifiers via the advertising auction and cookie-sync (more than 100 third-party domains in total).

Declared versus Actual

BNR’s Cookie Policy states directly: cookies for advertising and targeting record the visit and are used to display personalized advertising, and their use requires the visitor’s consent. The Privacy Policy confirms this: processing via cookies is based on consent expressed on the site. Of the specific recipients, the policy names only the Google DoubleClick for Publishers platform by name, describing the rest generically as “advertisers and advertising networks.”

The capture reveals a fundamentally different picture. Advertising monetization launches almost immediately, without regard to consent. At +902 ms, immediately after the Next.js bundle loads, the Google Publisher Tag (securepubads.g.doubleclick.net/tag/js/gpt.js) and the bidmatic prebid wrapper launch. The consent banner — Google Funding Choices — appears only at +1826 ms, meaning the Google advertising tag has already executed before the visitor even sees a request for consent.

A full-scale advertising auction and identifier synchronization then unfold: the visitor’s IP address and identifiers are dispersed to more than 100 third-party domains — the largest RTB, DSP, and SSP platforms (Criteo, Rubicon, PubMatic, OpenX, Xandr, Index Exchange, Teads, Outbrain, Adform, Smart/Equativ, Media.net, 33Across, ID5, InMobi, TripleLift, RTB House, and dozens of others). Synchronization proceeds via redirect chains — 91 of them appear in the capture.

Critically: no consent is collected during the session, and this is evident from the requests themselves. In requests to partners, the TCF consent string is not substituted — the unmodified programmatic placeholder gdpr_consent={gdpr_consent} is sent instead. 177 requests carry gdpr=0, signaling to partners that GDPR does not apply to the processing. Google Analytics (identifier G-FDKFTKB3MV) transmits telemetry with the signal gcs=G100, corresponding to a state of “consent not given.” In other words, a consent mechanism is present on the site in the form of a banner, but the actual transfer of data to advertising partners does not depend on it and occurs irrespective of the user’s choice.

The Google advertising tag loads at +902 ms; the consent banner only at +1826 ms. Identifier synchronization begins at +2959 ms and continues in a wave through the end of loading. All of this occurs with consent not collected: the TCF string placeholder is unfilled, gdpr=0 is transmitted, and Google Analytics flags the data as sent without consent. That is, between the banner’s appearance and the actual transfer of data to a hundred partners, there is no genuine pause for the user’s choice — the data leaves regardless of consent.

What Cannot Be Asserted from This Capture

The capture covers the home page in its pre-consent state. Set-Cookie is absent from the captured headers — in this capture, identifier synchronization is visible through redirect chains and request parameters rather than through Set-Cookie headers. Many advertising companies use edge nodes within the EU; the conclusion drawn therefore concerns the recipients’ corporate affiliation (a significant proportion being US companies), not the physical location of the nodes. Behavior following a click on “accept” or “reject” is not observed in this session; the capture records the state prior to any choice. Server-side processing is not visible in a browser-based capture.

Conclusion

The website of Bulgarian National Radio launches full-scale advertising monetization before the visitor can give consent: the Google advertising tag starts before the banner, after which the visitor’s IP address and identifiers are dispersed to more than 100 third-party advertising platforms. Meanwhile, consent is not, in fact, collected — partners receive an empty TCF string placeholder and a gdpr=0 signal, and Google Analytics flags the data as sent without consent. BNR’s Cookie Policy states directly the opposite: that advertising and targeting cookies are used only with consent. The discrepancy between what is declared and what actually occurs here is fundamental rather than technical: a consent mechanism is present in the form of a banner, but it does not govern the actual transfer of data. For a publicly funded public broadcaster, transferring audience data to a hundred advertising recipients without consent having been collected, and without disclosure of a named list of recipients, constitutes a violation of the requirements concerning the legal basis for processing, the disclosure of recipients, and cross-border transfer.

Evidence
Original (audit)
HAR file: bg/bnr-bg-2026-05-29.har
SHA-256: c29d5e67dd7ce11fd97b21bf7daeb3225309476cb0e658d96e8da4262cbf40a5
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Commission for Personal Data Protection (CPDP)file a complaint online →

To: Commission for Personal Data Protection (CPDP)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website bnr.bg.

2. Circumstances
I visited the website bnr.bg and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) BNR's Cookie Policy states directly that advertising and targeting cookies are used only with the visitor's consent. The capture, however, shows the advertising machinery operating without consent having been collected: the Google advertising tag (GPT, securepubads.g.doubleclick.net/tag/js/gpt.js) loads at +902 ms, before the CMP banner (Google Funding Choices, +1826 ms) even appears, after which an auction and identifier synchronization begin with more than 100 third-party domains. No TCF consent string is passed to partners — instead, an unsubstituted placeholder, gdpr_consent={gdpr_consent}, is sent, and 177 requests carry gdpr=0 (a signal that 'GDPR does not apply'). Google Analytics (G-FDKFTKB3MV) meanwhile transmits telemetry with the signal gcs=G100 (consent not given).

2) The visitor's IP address and identifiers are dispersed to more than 100 third-party advertising recipients prior to any consent, including Google (USA) and major RTB platforms. The policy names only Google DoubleClick for Publishers and refers generically to 'advertisers and advertising networks'; a named list of the dozens of recipients (Criteo, Rubicon, PubMatic, OpenX, Xandr, Teads, Outbrain, Adform, 33Across, ID5, InMobi, and others) is not disclosed. A significant proportion of these companies are located in the USA.

Full technical documentation is published at: https://gdpru.eu/en/audits/bg-bnr-bg/

3. Provisions violated
GDPR Art. 6 + ePrivacy — processing of advertising cookies and data transfer without consent; GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and cross-border transfer

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]