GRAO — the Bulgarian civil registration authority — 21 requests, a single domain. All resources, including fonts, are hosted locally; there are no external calls, trackers, or cookies. No violations have been recorded.
Timeline of the leak
Declared versus actual
Context
grao.bg is the website of the Main Directorate “Civil Registration and Administrative Services” (GRAO) of Bulgaria, an authority under the Ministry of Regional Development responsible for the population register and the Unified Civil Number (UCN). The data controller is GRAO. No privacy policy was provided as part of this package. Capture: 21 requests, a single domain, recorded in a clean browser.
Declared versus Actual
The capture reveals a fully self-sufficient page. All resources — markup, stylesheets, scripts, fonts, and images — load from the first-party domain grao.bg; fonts (in ttf format) are hosted locally. There are no external domains present in the capture whatsoever: no analytics, no Google, no third-party CDNs, no advertising pixels, no session recording. Inspection of the first-party domain’s paths revealed no hidden analytics or build endpoints. No cookies are set (Set-Cookie is zero).
No separate privacy policy was provided as part of this audit; however, since there is no third-party processing or non-essential cookies present in the capture, no discrepancy between “declared” and “actual” substantively arises.
Timing Relative to Consent
All calls go to the site’s own domain. There are no third-party resources on the page requiring consent; no cookies are set. For an authority handling the population register, minimizing external calls is the correct approach.
What Cannot Be Asserted from This Capture
The capture covers the home page. The authority’s functional services (certificates, electronic services) may involve additional server-side processing that a browser-based capture does not cover. The existence of a separate cookie policy was not assessed against the capture, since there are no third-party trackers present. Server-side processing is not visible in a browser-based capture.
Conclusion
The website of Bulgaria’s civil registration authority is implemented cleanly: all resources, including fonts, are hosted locally on the site’s own domain, there are no external calls whatsoever, and trackers and cookies are absent. No violations have been recorded in the capture.
f5ee00c8860339be9229eccaf83b724cb7f5f5b180d6472c67107fee5ed212f6