Bulgarian National Radio (BNR) — 520 requests, 113 domains. Full-scale advertising monetization: the Google advertising tag (GPT) launches at +902 ms, before the consent banner even appears (+1826 ms), after which the visitor's IP address and identifiers are dispersed to more than 100 third-party advertising platforms. No consent is collected during the session: partners receive an empty TCF string placeholder and a gdpr=0 signal, while Google Analytics sends data flagged as 'consent not given.' The Cookie Policy, meanwhile, states that advertising cookies are used only with consent.
Timeline of the leak
Declared versus actual
Transfer timings
Google Publisher Tag (GPT). Google, USA. Launches before the CMP.
Google Funding Choices — the consent banner.
First identifier synchronization. A wave of cookie-sync follows.
Google Analytics G-FDKFTKB3MV. Telemetry flagged as 'consent not given.'
Detected trackers
- Google Ad Manager / GPT (securepubads.g.doubleclick.net) — advertising tag prior to the consent banner
- Google Analytics (region1.google-analytics.com, G-FDKFTKB3MV) — with a denied signal
- Google Funding Choices (fundingchoicesmessages.google.com) — CMP, appears after advertising has already launched
- Prebid / header bidding: bidmatic, sparteo, onetag, adtelligent, smilewanted, media.net, creativecdn, and others
- RTB/DSP/SSP and cookie-sync: Criteo, Rubicon (Magnite), PubMatic, OpenX, Xandr, Index Exchange, Teads, Outbrain, Adform, Smart/Equativ, 33Across, ID5, InMobi, TripleLift, Sharethrough, RTB House, Smaato, LoopMe, Eskimi, BidSwitch, Opera Ads, and dozens of others
- Temu (temu.com) — advertiser
Indicators of GDPR non-compliance
- GDPR Art. 6 + ePrivacy — processing of advertising cookies and data transfer without consentBNR's Cookie Policy states directly that advertising and targeting cookies are used only with the visitor's consent. The capture, however, shows the advertising machinery operating without consent having been collected: the Google advertising tag (GPT, securepubads.g.doubleclick.net/tag/js/gpt.js) loads at +902 ms, before the CMP banner (Google Funding Choices, +1826 ms) even appears, after which an auction and identifier synchronization begin with more than 100 third-party domains. No TCF consent string is passed to partners — instead, an unsubstituted placeholder, gdpr_consent={gdpr_consent}, is sent, and 177 requests carry gdpr=0 (a signal that 'GDPR does not apply'). Google Analytics (G-FDKFTKB3MV) meanwhile transmits telemetry with the signal gcs=G100 (consent not given).
- GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and cross-border transferThe visitor's IP address and identifiers are dispersed to more than 100 third-party advertising recipients prior to any consent, including Google (USA) and major RTB platforms. The policy names only Google DoubleClick for Publishers and refers generically to 'advertisers and advertising networks'; a named list of the dozens of recipients (Criteo, Rubicon, PubMatic, OpenX, Xandr, Teads, Outbrain, Adform, 33Across, ID5, InMobi, and others) is not disclosed. A significant proportion of these companies are located in the USA.
Context
bnr.bg is the website of Bulgarian National Radio (Българско национално радио, BNR), the country’s public broadcaster and one of Bulgaria’s three public media organizations, alongside the national television broadcaster and the national news agency. The data controller is BNR. The site is built on Next.js. The broadcaster maintains a Privacy Policy and a separate Cookie Policy. Capture: 520 requests, 113 domains, recorded in a clean browser.
Direct Recipients of Data (prior to consent)
Google (USA) — the GPT advertising tag, Google Analytics, Funding Choices. Criteo, Rubicon (Magnite), PubMatic, OpenX, Xandr, Index Exchange, Teads, Outbrain, Adform, Smart/Equativ, Media.net, 33Across, ID5, InMobi, TripleLift, Sharethrough, RTB House, Smaato, LoopMe, Eskimi, BidSwitch, Opera Ads, Temu — IP address and identifiers via the advertising auction and cookie-sync (more than 100 third-party domains in total).
Declared versus Actual
BNR’s Cookie Policy states directly: cookies for advertising and targeting record the visit and are used to display personalized advertising, and their use requires the visitor’s consent. The Privacy Policy confirms this: processing via cookies is based on consent expressed on the site. Of the specific recipients, the policy names only the Google DoubleClick for Publishers platform by name, describing the rest generically as “advertisers and advertising networks.”
The capture reveals a fundamentally different picture. Advertising monetization launches almost immediately, without regard to consent. At +902 ms, immediately after the Next.js bundle loads, the Google Publisher Tag (securepubads.g.doubleclick.net/tag/js/gpt.js) and the bidmatic prebid wrapper launch. The consent banner — Google Funding Choices — appears only at +1826 ms, meaning the Google advertising tag has already executed before the visitor even sees a request for consent.
A full-scale advertising auction and identifier synchronization then unfold: the visitor’s IP address and identifiers are dispersed to more than 100 third-party domains — the largest RTB, DSP, and SSP platforms (Criteo, Rubicon, PubMatic, OpenX, Xandr, Index Exchange, Teads, Outbrain, Adform, Smart/Equativ, Media.net, 33Across, ID5, InMobi, TripleLift, RTB House, and dozens of others). Synchronization proceeds via redirect chains — 91 of them appear in the capture.
Critically: no consent is collected during the session, and this is evident from the requests themselves. In requests to partners, the TCF consent string is not substituted — the unmodified programmatic placeholder gdpr_consent={gdpr_consent} is sent instead. 177 requests carry gdpr=0, signaling to partners that GDPR does not apply to the processing. Google Analytics (identifier G-FDKFTKB3MV) transmits telemetry with the signal gcs=G100, corresponding to a state of “consent not given.” In other words, a consent mechanism is present on the site in the form of a banner, but the actual transfer of data to advertising partners does not depend on it and occurs irrespective of the user’s choice.
Timing Relative to Consent
The Google advertising tag loads at +902 ms; the consent banner only at +1826 ms. Identifier synchronization begins at +2959 ms and continues in a wave through the end of loading. All of this occurs with consent not collected: the TCF string placeholder is unfilled, gdpr=0 is transmitted, and Google Analytics flags the data as sent without consent. That is, between the banner’s appearance and the actual transfer of data to a hundred partners, there is no genuine pause for the user’s choice — the data leaves regardless of consent.
What Cannot Be Asserted from This Capture
The capture covers the home page in its pre-consent state. Set-Cookie is absent from the captured headers — in this capture, identifier synchronization is visible through redirect chains and request parameters rather than through Set-Cookie headers. Many advertising companies use edge nodes within the EU; the conclusion drawn therefore concerns the recipients’ corporate affiliation (a significant proportion being US companies), not the physical location of the nodes. Behavior following a click on “accept” or “reject” is not observed in this session; the capture records the state prior to any choice. Server-side processing is not visible in a browser-based capture.
Conclusion
The website of Bulgarian National Radio launches full-scale advertising monetization before the visitor can give consent: the Google advertising tag starts before the banner, after which the visitor’s IP address and identifiers are dispersed to more than 100 third-party advertising platforms. Meanwhile, consent is not, in fact, collected — partners receive an empty TCF string placeholder and a gdpr=0 signal, and Google Analytics flags the data as sent without consent. BNR’s Cookie Policy states directly the opposite: that advertising and targeting cookies are used only with consent. The discrepancy between what is declared and what actually occurs here is fundamental rather than technical: a consent mechanism is present in the form of a banner, but it does not govern the actual transfer of data. For a publicly funded public broadcaster, transferring audience data to a hundred advertising recipients without consent having been collected, and without disclosure of a named list of recipients, constitutes a violation of the requirements concerning the legal basis for processing, the disclosure of recipients, and cross-border transfer.
c29d5e67dd7ce11fd97b21bf7daeb3225309476cb0e658d96e8da4262cbf40a5Where to file: Commission for Personal Data Protection (CPDP) — file a complaint online →
To: Commission for Personal Data Protection (CPDP)
From: [Your name], [contact email]
1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website bnr.bg.
2. Circumstances
I visited the website bnr.bg and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications:
1) BNR's Cookie Policy states directly that advertising and targeting cookies are used only with the visitor's consent. The capture, however, shows the advertising machinery operating without consent having been collected: the Google advertising tag (GPT, securepubads.g.doubleclick.net/tag/js/gpt.js) loads at +902 ms, before the CMP banner (Google Funding Choices, +1826 ms) even appears, after which an auction and identifier synchronization begin with more than 100 third-party domains. No TCF consent string is passed to partners — instead, an unsubstituted placeholder, gdpr_consent={gdpr_consent}, is sent, and 177 requests carry gdpr=0 (a signal that 'GDPR does not apply'). Google Analytics (G-FDKFTKB3MV) meanwhile transmits telemetry with the signal gcs=G100 (consent not given).
2) The visitor's IP address and identifiers are dispersed to more than 100 third-party advertising recipients prior to any consent, including Google (USA) and major RTB platforms. The policy names only Google DoubleClick for Publishers and refers generically to 'advertisers and advertising networks'; a named list of the dozens of recipients (Criteo, Rubicon, PubMatic, OpenX, Xandr, Teads, Outbrain, Adform, 33Across, ID5, InMobi, and others) is not disclosed. A significant proportion of these companies are located in the USA.
Full technical documentation is published at: https://gdpru.eu/en/audits/bg-bnr-bg/
3. Provisions violated
GDPR Art. 6 + ePrivacy — processing of advertising cookies and data transfer without consent; GDPR Art. 13(1)(e) + Chapter V — disclosure of recipients and cross-border transfer
4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.
5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.
[Date] [Signature / name]