Technical audit · 2026-05-29

grao.bg

Civil Registration and Administrative Services

GRAO — the Bulgarian civil registration authority — 21 requests, a single domain. All resources, including fonts, are hosted locally; there are no external calls, trackers, or cookies. No violations have been recorded.

Timeline of the leak

+0 ms · portal load
All resources — HTML, stylesheets, scripts, fonts (ttf), images — are served from the first-party domain grao.bg (Bulgarian hosting).
no third-party calls
Analytics, Google, third-party CDN fonts and scripts, advertising, and session recording are absent from the capture.

Declared versus actual

No privacy policy was provided as part of this package; behaviorally, there is no third-party processing — заявлен

Context

grao.bg is the website of the Main Directorate “Civil Registration and Administrative Services” (GRAO) of Bulgaria, an authority under the Ministry of Regional Development responsible for the population register and the Unified Civil Number (UCN). The data controller is GRAO. No privacy policy was provided as part of this package. Capture: 21 requests, a single domain, recorded in a clean browser.

Declared versus Actual

The capture reveals a fully self-sufficient page. All resources — markup, stylesheets, scripts, fonts, and images — load from the first-party domain grao.bg; fonts (in ttf format) are hosted locally. There are no external domains present in the capture whatsoever: no analytics, no Google, no third-party CDNs, no advertising pixels, no session recording. Inspection of the first-party domain’s paths revealed no hidden analytics or build endpoints. No cookies are set (Set-Cookie is zero).

No separate privacy policy was provided as part of this audit; however, since there is no third-party processing or non-essential cookies present in the capture, no discrepancy between “declared” and “actual” substantively arises.

All calls go to the site’s own domain. There are no third-party resources on the page requiring consent; no cookies are set. For an authority handling the population register, minimizing external calls is the correct approach.

What Cannot Be Asserted from This Capture

The capture covers the home page. The authority’s functional services (certificates, electronic services) may involve additional server-side processing that a browser-based capture does not cover. The existence of a separate cookie policy was not assessed against the capture, since there are no third-party trackers present. Server-side processing is not visible in a browser-based capture.

Conclusion

The website of Bulgaria’s civil registration authority is implemented cleanly: all resources, including fonts, are hosted locally on the site’s own domain, there are no external calls whatsoever, and trackers and cookies are absent. No violations have been recorded in the capture.

Evidence
Original (audit)
HAR file: bg/grao-bg-2026-05-29.har
SHA-256: f5ee00c8860339be9229eccaf83b724cb7f5f5b180d6472c67107fee5ed212f6
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.