Technical audit · 2026-05-29

government.bg

Council of Ministers of Bulgaria

The portal of the Council of Ministers of Bulgaria — 35 requests, 2 domains. All content is served from the first-party domain; the sole external resource is the cookie-bar consent banner library from an open CDN. There are no third-party trackers, analytics, Google, or advertising, and no cookies are set. No violations have been recorded.

Timeline of the leak

+0 ms · portal load
Content, stylesheets, scripts, and fonts are served from the first-party domain government.bg.
+247 ms · consent banner
cdn.jsdelivr.net/npm/cookie-bar — loading of the cookie-bar notice library (script, theme, and language file) from an open CDN.
no third-party trackers
Analytics, Google, maps, advertising, and session recording are absent from the capture.

Declared versus actual

No privacy policy was provided as part of this package; the site displays a cookie notice banner — declared
+ cookie-bar loads from an external CDN (jsDelivr/Fastly) — a consent tool, noted for completeness — not declared

Transfer timings

+247 ms cdn.jsdelivr.net

cookie-bar banner library. Not a tracker. Fastly CDN.

Detected trackers

Context

government.bg is the official portal of the Council of Ministers of Bulgaria (Министерски съвет), the country’s executive authority. The data controller is the administration of the Council of Ministers. No privacy policy was provided as part of this package. Capture: 35 requests, 2 domains, recorded in a clean browser.

Declared versus Actual

The capture reveals a page that is nearly self-sufficient. Content, stylesheets, scripts, and fonts load from the first-party domain government.bg. The sole external domain is cdn.jsdelivr.net, and the calls to it load not a tracking tool but the cookie-bar notice library itself (the cookiebar-latest.min.js script, a theme, and a language file). That is, the external contact relates to the cookie-notice mechanism itself, not to analytics or advertising.

There are no third-party trackers in the capture: no Google, no analytics, no advertising pixels, no session recording, no Google Fonts. No cookies are set (Set-Cookie is zero). The one observation worth noting is that the banner library is pulled from an external CDN (Fastly infrastructure), which, like any external request, discloses the visitor’s IP address to the CDN; hosting cookie-bar locally would eliminate even this contact. Since there is no third-party processing on the page requiring consent, no discrepancy between “declared” and “actual” substantively arises.

There is a single external call — the loading of the consent banner library at +247 ms. There are no trackers on the page requiring consent; no cookies are set.

What Cannot Be Asserted from This Capture

The capture covers the home page. No separate privacy policy was provided as part of this audit; since there are no third-party trackers, its absence from the package does not affect the assessment of the capture. Server-side processing is not visible in a browser-based capture.

Conclusion

The portal of the Council of Ministers of Bulgaria is implemented cleanly: content and fonts are served from the first-party domain, the sole external resource is the cookie-notice banner library from an open CDN, there are no third-party trackers, Google, analytics, or advertising, and no cookies are set. No violations have been recorded in the capture. For the sake of completeness, it would be worth hosting the banner library locally, eliminating the one remaining external contact.

Evidence
Original (audit)
HAR file: bg/government-bg-2026-05-29.har
SHA-256: 3eb242d502b404d8f4c2e66d5687a6743263d664cfff835005e595459b1ae34e
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.