Bulgaria
Bulgaria Data Privacy Laws: GDPR & PDPA Complete Guide (2026)
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 13 primary sources cited on this page. How we verify our legal content

Bulgaria's personal data is governed by the EU GDPR (Regulation (EU) 2016/679), which applies directly, and the national Personal Data Protection Act (ZZLD), last amended by State Gazette No. 70 of 20 August 2024. The independent CPDP supervises compliance and may fine violators up to EUR 20 million or 4% of global annual turnover.
Bulgaria implements EU data protection law through the directly applicable General Data Protection Regulation (GDPR) and the national Personal Data Protection Act (ZZLD), supervised by the Commission for Personal Data Protection (CPDP). The framework covers all personal data processing by controllers and processors operating in Bulgaria, regardless of whether the data subjects are Bulgarian citizens.
Information last verified on 10 September 2026. This article presents general legal information about Bulgarian data protection law. It is not legal advice.
Jurisdiction scope: This article addresses the data protection law of the Republic of Bulgaria, principally the EU GDPR (Regulation (EU) 2016/679) and the Bulgarian Personal Data Protection Act (Zakon za zashtita na lichnite danni, ZZLD), as amended by State Gazette No. 70 of 2024, whose ZZLD change took effect on 1 January 2026. It also addresses the EU AI Act (Regulation (EU) 2024/1689) as it applies in Bulgaria, and the ECHR context from Ekimdzhiev and Others v. Bulgaria. For the broader EU framework, see our EU data privacy laws guide. For Bulgarian recording and wiretapping rules, see our Bulgaria recording laws guide.
Quick Answer: Is Bulgaria GDPR-Compliant?
Bulgaria is an EU member state. The GDPR applies directly and in full throughout Bulgaria without the need for national transposition. The Bulgarian Personal Data Protection Act (ZZLD), promulgated in State Gazette No. 17 of 26 February 2019 and most recently amended in State Gazette No. 70 of 20 August 2024, supplements the GDPR in areas where the regulation expressly permits or requires national legislation. These include the structure and powers of the CPDP as supervisory authority, the age of digital consent (set at 14 years), provisions on video surveillance, rules for processing personal data for journalistic and academic purposes, and the transposition of Directive (EU) 2016/680 (the Law Enforcement Directive). Any natural or legal person, including non-EU organizations, that processes personal data of individuals in Bulgaria must comply with both the GDPR and the ZZLD. Non-compliance can result in administrative fines of up to EUR 20 million or 4% of global annual turnover, as well as criminal sanctions under the Bulgarian Criminal Code for certain categories of breach.

Legal Framework: GDPR, the Bulgarian PDPA, and the CPDP
The legal architecture of Bulgarian data protection rests on three layers. First, the GDPR provides the binding EU-level framework, applicable since 25 May 2018. Second, the ZZLD provides national implementing legislation. Third, the CPDP issues binding decisions, guidance, and opinions that interpret the framework in Bulgarian practice.
The ZZLD has been amended several times since 2019 to reflect legislative developments. The known amendment timeline is:
- State Gazette No. 17/26 February 2019 (principal implementing act, entered into force 2 March 2019)
- State Gazette No. 93/26 November 2019 (promulgation of Constitutional Court Decision No. 8 of 15 November 2019, which struck down ZZLD Art. 25h(2), the mandatory list of criteria for balancing expression against data protection)
- State Gazette No. 11/2 February 2023 (Whistleblower Protection Act integration, designating the CPDP as competent controlling body under the new Whistleblower Protection Act, entered into force 4 May 2023)
- State Gazette No. 84/6 October 2023 (consequential amendment aligning ZZLD Art. 8(4) with the Anti-Corruption Act, as a ground for early termination of a Commission member's mandate)
- State Gazette No. 70/20 August 2024 (Euro Introduction Act; the ZZLD change it makes, to Art. 85(6), entered into force on 1 January 2026 when Bulgaria adopted the euro)
Cookies and similar storage on a user's device are not governed by the Electronic Communications Act. Bulgaria placed that rule in Art. 4a of the Electronic Commerce Act, which requires the information listed in GDPR Article 13 plus an opportunity for the user to refuse the storage or the access.
The Electronic Communications Act governs direct marketing (Art. 261) and the retention of traffic and location data (Arts. 251b and following). Art. 261(1), in this form since State Gazette No. 105 of 2011, requires prior consent for marketing calls, messages and e-mail to consumers. Art. 261(2) then allows a business that obtained a customer's electronic contact details during a sale to market its own similar products or services to that customer, provided the customer is given a free and easy way to object both at the time of the sale and in every later message.
Constitutional Foundation
The Bulgarian Constitution of 1991 provides the fundamental rights basis for data protection. Article 32 guarantees that no one shall be subjected to interference with their personal or family affairs or correspondence. Everyone has the right to protection against unlawful collection, storage, use, and dissemination of information about them. Article 34 protects the freedom and secrecy of correspondence and other communications. These constitutional guarantees underpin the ZZLD and give Bulgarian courts the authority to strike down legislation that fails to provide adequate protection.
The Bulgarian Constitutional Court has also engaged with data protection questions. In Decision No. 8 of 15 November 2019 (State Gazette No. 93 of 26 November 2019), it struck down ZZLD Art. 25h(2), which had set a predetermined list of criteria for assessing whether processing for journalistic, academic, artistic or literary expression was proportionate. The Court found those criteria unclear enough to create legal uncertainty and to restrict freedom of expression disproportionately, leaving case-by-case balancing in their place.

The CPDP: Structure, Powers, and Enforcement
The Commission for Personal Data Protection (CPDP/КЗЛД) is Bulgaria's independent supervisory authority under Article 51 of the GDPR. The CPDP is a collegial body consisting of a chairperson and four members, all appointed by the National Assembly (parliament) for five-year terms. The current chairperson is Borislav Bozhinov. Former chairperson Ventsislav Karadjov previously served as a Vice-Chair of the European Data Protection Board during an earlier term.
The CPDP's annual budget for 2024 was BGN 6,403,403 (approximately EUR 3,274,008). The Commission has an authorised establishment of 117 posts including the five Commission members. Its annual reports record 85 of those posts filled at 31 December 2024 and 88 at 31 December 2025. The CPDP's Rules of Operation were last updated on 28 April 2023.
The CPDP publishes a bimonthly newsletter that provides information on enforcement decisions and regulatory developments. Since 2024, the CPDP has reduced the number of individually published decisions on its website, so the newsletter has become the primary channel for tracking enforcement trends between annual reports.
Since 2023, the CPDP has additionally served as the competent controlling body under Bulgaria's Whistleblower Protection Act (Zakon za zashtita na litsata, podavashti signali ili publichno opovestyavashti informatsiya za narusheniya, ZZLPSPOIN). Sessions at which the CPDP acts in this capacity are closed.
CPDP Powers and Functions
The CPDP holds the full range of GDPR supervisory and corrective powers under Articles 58 and 83. These include:
- Conducting investigations into complaints filed by individuals or on the CPDP's own initiative
- Carrying out on-site inspections of controllers and processors
- Issuing warnings, reprimands, and orders to comply
- Imposing temporary or permanent bans on processing
- Ordering suspension of data flows to third-country recipients
- Levying administrative fines in accordance with GDPR Articles 83(4) and 83(5)
The CPDP also fulfils advisory functions: issuing opinions on proposed legislation, providing guidance to controllers, and conducting public awareness campaigns. It maintains a public register of controllers and processors who have appointed Data Protection Officers, and a register of accredited certification bodies.
The CPDP does not itself enforce its fines through collection proceedings. Enforcement of financial sanctions follows a separate administrative procedure under the Bulgarian Administrative Violations and Penalties Act (ZANN). This distinction is relevant for businesses assessing the timeline from fine imposition to actual collection.
Enforcement Statistics
CPDP enforcement activity by year:
| Year | On-Site Inspections | Complaints From Individuals | Total Sanctions Imposed |
|---|---|---|---|
| 2022 | 324 (predominantly video surveillance) | 770 | BGN 1,000,000 penalty decree against Bulgarian Posts |
| 2023 | 237 | 900 | BGN 25,000 (political party); BGN 2,000 (Interior Ministry) |
| 2024 | Not specified | 1,080 (plus 637 signals and requests) | BGN 74,700 (about EUR 38,194) |
| 2025 | 687 ordered, 443 of them on complaints and signals | more than 1,700 | BGN 226,000 (about EUR 115,553) |
The CPDP's 2025 Activity Report lists the sectors that drew the most complaints from individuals that year: video surveillance (425 complaints), banks and credit institutions (131), private individuals (106), state bodies (105), telecommunications (56) and media (48). Video surveillance has led every year since 2023, rising from 178 complaints in 2023 to 345 in 2024 and 425 in 2025.
Bulgaria adopted the euro on 1 January 2026 at the fixed rate of 1 EUR to 1.95583 BGN, so every sanction below that predates the changeover was imposed in leva and is converted at that rate here. The typical range for GDPR and ZZLD penalty proceedings is BGN 1,000 to BGN 10,000 (about EUR 511 to EUR 5,113). The CPDP usually imposes either a fine or mandatory corrective instructions, rarely both at once. The landmark 2019 penalty decrees against the NRA and DSK Bank were exceptional rather than representative of everyday enforcement, and the NRA decree was later annulled by the courts.
Notable Enforcement Actions
National Revenue Agency (penalty decree of BGN 5,100,000, about EUR 2,607,591, issued 2019 and annulled in 2024): The largest sanction the CPDP has ever issued followed a cyberattack in which a hacker gained remote unauthorized access to NRA servers and took personal data from approximately 6,074,140 records. The data included names, personal identification numbers (EGN), addresses, income information, and tax and social security details. The CPDP found that the NRA had failed to implement adequate technical and organizational security measures as required by Article 32 of the GDPR, and its chairperson issued Penalty Decree No. 004 of 28 August 2019 for BGN 5,100,000.
That decree is no longer in force. On 26 February 2024 the Administrative Court Sofia-city set aside the Sofia District Court decision of 26 October 2023 that had upheld it, annulled Penalty Decree No. 004 and terminated the administrative penalty proceedings, because the absolute limitation period of four years and six months had expired. The court recorded that its decision is final and not subject to appeal or protest, so the NRA never paid the sanction. The breach itself still prompted a national reckoning with public-sector cybersecurity and elevated data protection to a political priority.
DSK Bank (penalty decree of BGN 1,000,000, about EUR 511,292, 2019): The CPDP issued a BGN 1,000,000 penalty decree against DSK Bank in 2019 after unauthorized parties accessed personal and financial data of more than 33,000 customers. The CPDP found that the bank had not implemented appropriate technical and organizational measures to protect customer data under Article 32 of the GDPR. We have not been able to confirm the final outcome of that decree on an official court source, so read it as a decree that was issued rather than as a sanction known to have survived appeal.
Bulgarian Posts EAD (penalty decree of BGN 1,000,000, about EUR 511,292, 2022): The CPDP issued a BGN 1,000,000 penalty decree against Bulgarian Posts in 2022 for inappropriate technical and operational security measures that resulted in unauthorized access to and disclosure of personal data, including identity documents, addresses, phone numbers, financial data, and health information. As with DSK Bank, the final outcome of that decree is not confirmed on an official court source here.
Political Party (BGN 25,000 / EUR 12,782, 2023): The CPDP fined a political party BGN 25,000 for unlawful processing of personal data of supporters in connection with national parliamentary elections, demonstrating that enforcement extends beyond the private sector.
Interior Ministry (BGN 2,000 / EUR 1,022, 2023): The CPDP fined the Interior Ministry BGN 2,000 for retaining personal data beyond the statutory retention period, illustrating that even modest violations by public authorities attract formal sanctions.

Constitutional Basis and ECHR Context
Bulgaria's commitment to privacy protection extends beyond the ZZLD and GDPR. Article 8 of the European Convention on Human Rights (ECHR), which Bulgaria has ratified, guarantees the right to respect for private and family life, home, and correspondence. The European Court of Human Rights (ECHR) has adjudicated directly on Bulgarian surveillance practices.
In Ekimdzhiev and Others v. Bulgaria (App. No. 70078/12, judgment of 11 January 2022), the Court held unanimously that Bulgaria had violated Article 8 of the Convention in two respects. First, Bulgarian legislation governing secret surveillance (special intelligence means) lacked effective legal safeguards against arbitrariness and abuse, failing the quality-of-law requirement of the Convention. Second, Bulgarian rules governing the retention of and law enforcement access to telecommunications traffic data were also deficient, leaving surveillance data without adequate protection against nefarious use. The case concerned both the general legal framework and the practices of Bulgaria's State Agency for National Security (DANS).
The Ekimdzhiev judgment has direct significance for data protection in Bulgaria. It reinforces that surveillance activities must be grounded in clear, accessible, and foreseeable law. Any processing of personal data by Bulgarian intelligence or law enforcement agencies that falls outside the ZZLD's Law Enforcement Directive transposition provisions must independently comply with ECHR Article 8 standards.
A subsequent related case, Kanev and Bulgarian Helsinki Committee v. Bulgaria, found that the State Agency for National Security's refusal to confirm or deny holding data on a human rights activist and an NGO violated Article 8 due to the lack of effective safeguards against arbitrary processing.
Lawful Bases and Consent
The GDPR's six lawful bases under Article 6 apply directly in Bulgaria without national modification. A controller processing personal data must identify and document at least one applicable basis before processing begins:
| Lawful Basis | Article 6 Ref | Bulgarian Note |
|---|---|---|
| Consent | Art. 6(1)(a) | Must be freely given, specific, informed, unambiguous. Age threshold: 14 years for information society services. |
| Contract performance | Art. 6(1)(b) | No national derogation. |
| Legal obligation | Art. 6(1)(c) | Many Bulgarian statutory obligations qualify. |
| Vital interests | Art. 6(1)(d) | Narrow; emergency use only. |
| Public task | Art. 6(1)(e) | Applies to public authorities and bodies exercising official authority. |
| Legitimate interests | Art. 6(1)(f) | Not available to public authorities acting in their official capacity. Balancing test required. |
The ZZLD adds a specific rule in Art. 25a. Where a data subject has supplied personal data to a controller or processor without a legal basis under Article 6(1) or contrary to the Article 5 principles, the controller or processor must return the data within one month of becoming aware. Only where return is impossible or would require disproportionate effort may it erase or destroy the data instead, and the erasure or destruction must be documented.
Special Categories of Personal Data
Special categories (Article 9 GDPR) receive heightened protection in Bulgaria. Processing requires both a lawful basis under Article 6 and an additional condition under Article 9(2). The ZZLD does not impose additional restrictions beyond the GDPR for most special categories, and it contains no separate rule on criminal-conviction or offence data. That subject is governed by GDPR Article 10 itself, which allows such processing only under the control of official authority or where Union or member state law authorizes it.
The ZZLD's employment-specific rules sit elsewhere. Art. 25i requires an employer or appointing authority to adopt, document and communicate rules and procedures for whistleblowing systems, restrictions on the use of internal information resources, and access, working-time and work-discipline control systems. Art. 25j(1) caps retention of recruitment data at six months without the candidate's consent, and Art. 25j(2) requires originals or notarised copies of qualification documents to be returned to an unsuccessful candidate within six months of the procedure closing.
The CPDP has also issued guidance on biometric technologies in educational settings, emphasizing that the use of facial recognition in schools requires a compelling justification given the special category nature of biometric data and the vulnerability of child data subjects.
Age of Digital Consent
Bulgaria set the age of digital consent at 14 years, lower than the GDPR's default of 16 years but within the permissible range of Article 8(1) of the GDPR (which allows member states to lower the threshold to 13 years). The CPDP published an information booklet in March 2022 setting out detailed requirements: consent for children's online services must be collected per processing activity, using active positive selection interfaces (no pre-ticked boxes), and with data minimization principles strictly applied. Children under 14 require parental or guardian consent for consent-based processing in information society services.
Data Subject Rights
Under the GDPR and ZZLD, individuals in Bulgaria have the following rights:
- Right of access (Article 15): Individuals may request confirmation of whether their data is processed and obtain a copy. The first copy is free of charge. The controller, not the CPDP, may charge a reasonable fee based on administrative costs for further copies or for requests that are manifestly unfounded or excessive, and may instead refuse to act, bearing the burden of showing that the request was manifestly unfounded or excessive (GDPR Articles 12(5) and 15(3)).
- Right to rectification (Article 16): Individuals may request correction of inaccurate data and completion of incomplete data.
- Right to erasure (Article 17): Also known as the right to be forgotten. Applies where the data is no longer necessary, consent is withdrawn (and no other basis exists), or processing is unlawful. Exemptions apply for legal claims, public interest, and archiving purposes.
- Right to restriction of processing (Article 18): Applies during accuracy disputes, when processing is contested, or when the data subject requires data for legal claims.
- Right to data portability (Article 20): Applies where processing is based on consent or contract performance, and is carried out by automated means.
- Right to object (Article 21): Applies to processing based on public task or legitimate interests. Also provides an absolute right to object to direct marketing at any time.
Requests must be submitted in writing, dated, and signed. The ZZLD preserves standard GDPR exceptions for journalistic, academic, artistic, and literary expression purposes. Controllers must respond to data subject requests without undue delay and within one month, extendable by two further months for complex requests.
Individuals whose rights are denied or ignored may lodge a complaint with the CPDP, which is free of charge, or pursue judicial remedies in Bulgarian courts under Article 79 of the GDPR.
The CPDP route carries a hard deadline. Under ZZLD Art. 38(1), a data subject may refer a matter to the Commission within six months of learning of the infringement and in any event no later than two years after it was committed. The two limits apply together, and a complaint filed outside either of them is dismissed without being examined on the merits.
Data Protection Officer Requirements
DPO appointments in Bulgaria follow GDPR Article 37 without additional national requirements. A DPO must be appointed when:
- The controller or processor is a public authority or body (except courts acting in their judicial capacity)
- Core activities consist of processing operations that require regular and systematic monitoring of data subjects on a large scale
- Core activities consist of large-scale processing of special categories of data (Article 9) or criminal convictions and offences data (Article 10)
The CPDP maintains a public register of controllers and processors that have appointed DPOs. Controllers must notify the CPDP of DPO details using approved registration forms. Bulgaria-based organizations may appoint DPOs located abroad, but those DPOs must be registered with the CPDP.
DPOs cannot be dismissed or penalized for performing their functions and must report directly to the highest management level of the organization. They may be employed by the organization (internal DPO) or act under a service contract (external DPO). Shared DPOs across a group of undertakings are permissible where the DPO is easily accessible from each establishment.
Breach Notification
Standard GDPR breach notification requirements apply in Bulgaria. Controllers must notify the CPDP of a personal data breach without undue delay and no later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights and freedoms. Where notification cannot be provided within 72 hours, the notification must be accompanied by reasons for the delay.
Where a breach is likely to result in a high risk to individuals' rights and freedoms, the controller must also notify the affected individuals without undue delay. The CPDP provides template notification forms. The Commission maintains a non-public register of personal data breaches.
The NRA breach underscored the CPDP's serious approach to breach investigations. The Commission examined not only whether notification was timely, but also whether the underlying security architecture was adequate under Article 32 of the GDPR.
NIS2 Incident Reporting (From February 2026)
Separately, Bulgaria's Cybersecurity Act was amended to transpose the NIS2 Directive (Directive (EU) 2022/2555) by the amending act promulgated in State Gazette No. 17 of 13 February 2026, in force from 17 February 2026. Reports go to the sectoral computer security incident response team (SERIKS) that sits with the relevant national competent authority, not to CERT.bg. Essential and important entities must file:
- 24 hours: Early warning after identifying a significant incident. Trust service providers must file the full incident notification within 24 hours as well.
- 72 hours: Incident notification that updates the early warning and gives an initial assessment of severity and impact
- On request: An interim report, if SERIKS asks for one
- One month: Final report, due no later than one month after the 72-hour notification. If the incident is still unresolved at that point, the entity files an interim report and then a final report within one month of resolving it.
Where a cybersecurity incident also constitutes a personal data breach, both SERIKS and the CPDP must be notified. However, if the CPDP has already imposed a fine for the same infringement under data protection law, the cybersecurity authority should not impose an additional fine for the identical violation. Bulgaria's NIS2 transposition expanded covered sectors from 8 to 18 and brought an estimated 10,000 to 12,000 entities into scope. Bulgaria received a formal reasoned opinion from the European Commission on 7 May 2025 for failing to notify full transposition before the October 2024 deadline, reflecting the delays in the legislative process.
Cross-Border Data Transfers
Bulgaria follows the standard GDPR framework for international data transfers under Articles 44 to 49. Transfers of personal data to third countries outside the European Economic Area (EEA) require one of the following:
- An adequacy decision by the European Commission (e.g., the EU-US Data Privacy Framework, the UK adequacy decisions, Switzerland)
- Appropriate safeguards such as Standard Contractual Clauses (SCCs) adopted by the Commission
- Binding Corporate Rules (BCRs) approved by a competent supervisory authority
- An approved code of conduct or certification mechanism
- Derogations for specific situations under Article 49 (limited scope; not for systematic transfers)
Following the Court of Justice of the European Union's Schrems II judgment (Case C-311/18, Data Protection Commissioner v Facebook Ireland and Maximillian Schrems, 16 July 2020), Bulgarian controllers and processors must conduct transfer impact assessments (TIAs) when relying on SCCs or BCRs to assess whether the law and practices of the destination country provide equivalent protection to EU standards. The CPDP has not issued Bulgaria-specific supplementary guidance on TIAs beyond the general EDPB recommendations.
Schengen Accession and SIS Data Sharing
Bulgaria joined the Schengen Area by stages. Air and sea border controls were lifted on 31 March 2024. Full Schengen membership, including lifting of land border controls, took effect on 1 January 2025 following a Council decision of 12 December 2024. Access to the Schengen Information System (SIS) did not start then. The Ministry of the Interior already operated Bulgaria's National Schengen Information System, connected to Central SIS, along with the SIRENE Bureau for supplementary information exchange, well before full accession. SIS is the EU's database for border management, law enforcement cooperation, and immigration control. All data processing through SIS must comply with Regulation (EU) 2018/1861 (SIS for border checks), Regulation (EU) 2018/1862 (SIS for police cooperation), and the Law Enforcement Directive (EU) 2016/680 as transposed by the ZZLD. The Schengen accession does not alter the standard GDPR rules for commercial cross-border data transfers, which remain governed by the framework described above.
EU AI Act Overlay
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies directly in Bulgaria as an EU member state. The Digital Omnibus on AI (Regulation (EU) 2026/1744), in force since 27 July 2026, moved several of its deadlines, most importantly the ones for high-risk systems. The current phased timeline is:
| Date | What Applies |
|---|---|
| 2 February 2025 | Prohibited AI practices as originally enacted (Article 5(1)(a) to (h)) and AI literacy obligations (Article 4) |
| 2 August 2025 | General-purpose AI model obligations (Chapter V, Articles 51 to 56); governance and penalties |
| 2 August 2026 | Transparency obligations for certain AI systems (Article 50), including chatbot disclosure, machine-readable marking of synthetic content and deepfake labelling. Also standards, conformity assessment and registration (Chapter III, Section 5) |
| 2 December 2026 | Deadline under Article 111(4) for providers of synthetic-content systems already on the market before 2 August 2026 to meet Article 50(2), and start of the new prohibitions on AI systems generating child sexual abuse material or non-consensual intimate imagery |
| 2 December 2027 | Core obligations for most high-risk AI systems (Annex III), moved by the July 2026 Digital Omnibus |
| 2 August 2028 | High-risk AI embedded in regulated products (Annex I), the last block of the Act to apply |
The AI Act supplements rather than replaces the GDPR. Data protection obligations for AI systems that process personal data remain governed by the GDPR. The AI Act adds a risk-based overlay: high-risk AI systems must implement quality management systems, maintain technical documentation, enable human oversight, and achieve conformity assessment before deployment.
Bulgaria has still not completed its national implementation framework for the AI Act. The European Commission's register of AI Act market-surveillance single points of contact, last updated on 7 September 2026, shows no designated authority for Bulgaria. A Bulgarian Ministry of Electronic Governance report had earlier confirmed that no decisions were taken on the national coordination model, competent market surveillance authorities, or sanctioning regime, and an interdepartmental working group was established without producing a framework.
The CPDP has been designated as one of seven competent bodies for the protection of fundamental rights under the AI Act pursuant to Council of Ministers Decision No. 398 of 18 June 2025. The other six designated bodies are the National Ombudsman, the Central Election Commission, the Commission for Protection against Discrimination, the Commission for Consumer Protection, the State Agency for Child Protection, and the General Labour Inspectorate Executive Agency.
For AI systems that process personal data, businesses operating in Bulgaria should expect dual-authority scrutiny: the CPDP reviewing GDPR compliance, and (once the national AI Act framework is in place) the relevant market surveillance authority reviewing AI Act compliance. The GDPR's requirements for data protection impact assessments (DPIAs) under Article 35 are directly relevant to high-risk AI systems. Controllers should conduct DPIAs proactively for any AI system that profiles individuals, uses biometric data, or makes automated decisions with significant effects.
EGN Personal Identification Number
Bulgaria's Edinen Grazhdanski Nomer (EGN), or unified civil number, is a unique ten-digit personal identification number assigned to Bulgarian citizens at birth. The EGN encodes the holder's date of birth and sex. It is used pervasively across government administration, healthcare, social services, banking, and private sector transactions.
The CPDP has established guidelines limiting unnecessary EGN disclosure. When imposing administrative sanctions such as public reprimands, the CPDP's guidance confirms that the decision should not disclose the subject's EGN, date and place of birth, ID number, exact address, personal data of third parties, or unrelated personal information.
Under the GDPR's framework, the EGN qualifies as personal data and may constitute a unique identifier that warrants protection analogous to special categories depending on context. Article 87 of the GDPR expressly permits member states to specify the conditions under which national identification numbers may be processed. Bulgaria has implemented this through ZZLD provisions that require a specific legal justification for EGN processing beyond general data minimization obligations.
The NRA breach illustrated the catastrophic risks of EGN exposure. Because the EGN encodes birth information and is used as a primary identification key across multiple government databases, exposure enables coordinated identity theft, fraud, and targeted phishing on a national scale. The breach prompted public calls for redesigning EGN-dependent systems to reduce the number of entities that require and store the full EGN.
Video Surveillance
The ZZLD includes specific provisions on video surveillance that supplement the GDPR's general framework. The CPDP has been active in this area: 324 of its 2022 on-site inspections focused predominantly on video surveillance compliance. Controllers deploying CCTV systems in Bulgaria must:
- Establish and document a legitimate basis for surveillance
- Provide clear and conspicuous information to individuals entering surveilled areas (layered notices are acceptable for small signs)
- Conduct a DPIA where surveillance is likely to result in high risk, including large-scale monitoring of public spaces
- Establish proportionate retention periods and delete footage that is no longer necessary
- Apply access controls limiting who can review footage
The CPDP has investigated complaints about video surveillance in workplaces, residential buildings, and commercial premises, and has issued orders requiring removal of cameras that lacked legal justification or that monitored areas where individuals had a reasonable expectation of privacy.
Recent Developments 2024-2026
PDPA Amendment (in force January 2026): The ZZLD was last amended by the Act on Adopting the Euro in the Republic of Bulgaria, promulgated in State Gazette No. 70 of 20 August 2024. Its ZZLD provision did not take effect on that date. It entered into force on the date Bulgaria adopted the euro, 1 January 2026. The change is confined to Art. 85(6), which now sets the administrative penalties under paragraphs 1 to 5 by reference to the criteria in Article 83(2) of the GDPR.
Whistleblower Protection Act (2023, ongoing): The CPDP became the competent controlling body under Bulgaria's Whistleblower Protection Act (entered into force 4 May 2023). Organizations with 50 or more employees must establish internal reporting channels under the Act. The CPDP oversees the confidentiality and data protection obligations attached to whistleblower reports, which are a distinct processing activity requiring its own GDPR compliance analysis.
NIS2 Transposition (February 2026): Bulgaria's amendments to the Cybersecurity Act transposing NIS2 entered into force on 17 February 2026. The law expanded the list of covered sectors, introduced new incident notification timelines, and brought an estimated 10,000 to 12,000 entities into mandatory cybersecurity compliance. Entities in essential sectors such as energy, transport, banking, health, digital infrastructure, and water supply now have mandatory security obligations that intersect with GDPR security requirements.
Full Schengen Accession (January 2025): Bulgaria became a full Schengen member on 1 January 2025 when land border controls were lifted. Bulgaria was already connected to SIS before that date, so what changed was the volume and pattern of cross-border law enforcement data flows subject to the Law Enforcement Directive transposition provisions of the ZZLD, not the existence of SIS access.
EU AI Act Application (February 2025 onwards): Prohibited AI practices, including the use of real-time remote biometric identification in public spaces for law enforcement (with narrow exceptions), have been unlawful in Bulgaria since 2 February 2025. Bulgarian law enforcement and public authorities using AI systems must assess whether their systems fall within prohibited categories. The CPDP's designation as a fundamental rights body under the AI Act (Council of Ministers Decision No. 398, 18 June 2025) gives it formal standing to assess the fundamental rights impact of AI deployments.
Enforcement Trend (2024 to 2025): The CPDP worked on 637 signals and requests received during 2024 and imposed sanctions totalling BGN 74,700 (about EUR 38,194) that year. No individual decisions were published on the CPDP website during 2024, and enforcement developments were communicated through the bimonthly newsletter. The 2025 report reverses the picture: sanctions totalled BGN 226,000 (about EUR 115,553), made up of BGN 39,000 by penalty decrees, BGN 2,000 by settlements and BGN 185,000 by Commission decisions, and complaints from individuals passed 1,700. Neither year approaches the 2019 decrees, but since 2024 the trend has been upward, not downward.
Business Compliance Guide
Organizations operating in Bulgaria or processing data of Bulgarian residents should address the following areas:
1. Legal basis mapping. Document the lawful basis for each processing activity. Where processing relies on consent, ensure consent collection meets GDPR Article 7 standards. For children's services, implement age-verification or parental consent mechanisms calibrated to the 14-year threshold.
2. DPO appointment. Assess whether your organization's core activities meet the Article 37 criteria. If a DPO is required, register the appointment with the CPDP using the approved form. If the DPO is based outside Bulgaria, the registration requirement still applies.
3. Cybersecurity and the NRA lesson. The NRA and DSK Bank decrees show that the CPDP treats Article 32 security failures as substantial violations warranting substantial penalties. The NRA decree was later annulled on limitation grounds rather than on the merits, so the security finding, not the sanction, is the part to plan around. Conduct regular security assessments. Ensure technical measures (encryption, access controls, penetration testing, patch management) are actually implemented and documented. Do not rely on policy documentation alone.
4. EGN handling. Minimize collection and storage of EGN numbers. Exclude EGNs from published documents, API responses, and data exports where they are not strictly necessary for the processing purpose. Assess whether your use of EGN falls within the ZZLD's specific authorization requirements.
5. Breach response readiness. Test incident response plans. Ensure you can identify, contain, and assess a breach rapidly enough to meet the 72-hour CPDP notification requirement and (from February 2026) the 24-hour early warning to your sectoral CSIRT (SERIKS) for NIS2-covered entities. Maintain a documented internal breach log even for low-risk breaches that do not require regulatory notification.
6. Video surveillance. Review CCTV deployments for legal basis, information notices, and proportionality. The CPDP's 2022 inspection wave focused heavily on surveillance. New deployments should include a preliminary privacy assessment.
7. Direct marketing. Confirm that e-mail marketing to Bulgarian consumers has prior consent under Art. 261(1) of the Electronic Communications Act, or that it fits the Art. 261(2) exception for marketing your own similar products to an existing customer whose contact details you obtained during a sale. Give a free and easy way to object at the point of sale and in every message, maintain withdrawal records, and honor opt-outs without delay.
8. AI systems. Conduct a preliminary AI Act risk classification for any AI system used in Bulgaria. Prohibited practices (including certain biometric identification and social scoring systems) are unlawful since 2 February 2025. High-risk systems require DPIAs under the GDPR and, from 2 December 2027 for Annex III systems and 2 August 2028 for AI built into regulated products, the full high-risk regime under the AI Act. Monitor the CPDP's guidance as its role as a fundamental rights body under the AI Act develops.
9. NIS2 compliance. If your organization is an essential or important entity under Bulgaria's Cybersecurity Act (as amended in February 2026), register with the relevant competent authority, implement required security measures, and establish incident reporting procedures.
10. Cross-border transfers. Where transferring data outside the EEA, document the transfer mechanism. For SCCs or BCRs, conduct a transfer impact assessment. Monitor the European Commission's adequacy decision register for updates.
Disclaimer: This article provides general information about Bulgaria's data protection laws and does not constitute legal advice. Data protection law is subject to frequent change. Consult a qualified lawyer licensed to practice in Bulgaria for guidance on your specific situation. Statutes cited in this article reflect their in-force version as of 10 September 2026.
Frequently Asked Questions
What is Bulgaria's main data protection law?
Bulgaria's primary national data protection legislation is the Personal Data Protection Act (Zakon za zashtita na lichnite danni, ZZLD), promulgated in State Gazette No. 17 of 26 February 2019 and most recently amended in State Gazette No. 70 of 20 August 2024. The ZZLD supplements the directly applicable EU GDPR by covering areas where EU law permits national discretion, including the CPDP's structure and powers, the age of digital consent (14 years), video surveillance provisions, journalistic expression exemptions, and transposition of the Law Enforcement Directive.
What is the CPDP and what powers does it have?
The Commission for Personal Data Protection (CPDP/КЗЛД) is Bulgaria's independent data protection supervisory authority under GDPR Article 51. It consists of a chairperson and four members appointed by parliament for five-year terms. The CPDP can investigate complaints, conduct on-site inspections, issue warnings and compliance orders, impose processing bans, and levy administrative fines of up to EUR 20 million or 4% of global annual turnover. A data subject must refer a matter to the Commission within six months of learning of the infringement and no later than two years after it was committed (ZZLD Art. 38(1)). The CPDP's chairperson participates in the European Data Protection Board as Bulgaria's representative.
What was the NRA data breach and what was the fine?
In 2019, the Bulgarian National Revenue Agency (NRA) suffered a cyberattack in which a hacker gained remote unauthorized access to NRA servers and took personal data from approximately 6,074,140 records. The stolen data included names, EGN (unified civil numbers), addresses, income, and tax and social security details. The CPDP found that the NRA had failed to implement adequate technical and organizational security measures under GDPR Article 32, and its chairperson issued Penalty Decree No. 004 of 28 August 2019 for BGN 5,100,000 (about EUR 2,607,591). That decree no longer stands. The Administrative Court Sofia-city annulled it on 26 February 2024 and terminated the proceedings because the absolute limitation period of four years and six months had expired, in a decision that is final and cannot be appealed, so the NRA never paid it.
What is the EGN and how is it protected under Bulgarian law?
The EGN (Edinen Grazhdanski Nomer) is Bulgaria's unique ten-digit unified civil number assigned to citizens at birth, encoding the holder's date of birth and sex. It is used widely across government, healthcare, banking, and private sector systems. Under the ZZLD and GDPR Article 87 (which permits national rules on identification numbers), processing of EGNs requires a specific legal justification. The CPDP has issued guidance limiting unnecessary EGN disclosure in official sanctions and other public documents. The NRA breach demonstrated the severe identity fraud risks of EGN exposure.
What is the age of digital consent in Bulgaria?
Bulgaria set the age of digital consent at 14 years for information society services, lower than the GDPR's default of 16 years but within the permissible range of GDPR Article 8(1) (which allows member states to lower the threshold to a minimum of 13 years). Children under 14 require parental or guardian consent for consent-based processing. The CPDP's March 2022 guidance requires separate consent per processing activity, active opt-in interfaces, and strict data minimization for children's services.
Does a business operating in Bulgaria need a Data Protection Officer?
A DPO is mandatory when: (1) the organization is a public authority or body (except courts acting in their judicial capacity); (2) core activities require regular and systematic large-scale monitoring of data subjects; or (3) core activities involve large-scale processing of special categories of data or criminal records data. Bulgaria does not impose additional DPO requirements beyond GDPR Article 37. If a DPO is required, their appointment must be registered with the CPDP using the approved registration form, even if the DPO is based outside Bulgaria.
How does the EU AI Act affect businesses in Bulgaria?
The EU AI Act (Regulation (EU) 2024/1689) applies directly in Bulgaria. Prohibited AI practices, including certain uses of real-time remote biometric identification in public spaces and AI systems that exploit vulnerabilities or assign social scores, have been unlawful since 2 February 2025. Core obligations for high-risk AI systems apply from 2 December 2027 for Annex III systems and 2 August 2028 for AI built into regulated products, moved by the July 2026 Digital Omnibus. The CPDP has been designated as one of seven competent fundamental-rights bodies under the AI Act. Businesses should classify their AI systems for risk, conduct DPIAs for high-risk systems, and monitor the CPDP's developing guidance.
What is the significance of Ekimdzhiev and Others v. Bulgaria for data protection?
Ekimdzhiev and Others v. Bulgaria (App. No. 70078/12, ECHR, 11 January 2022) found that Bulgarian secret surveillance legislation violated ECHR Article 8 because it lacked effective safeguards against arbitrariness and abuse. The Court also found violations in the rules governing telecommunications traffic data retention and law enforcement access. The judgment requires that any processing of personal data by Bulgarian intelligence or law enforcement agencies outside the ZZLD's Law Enforcement Directive provisions must independently satisfy the ECHR's quality-of-law standard.
What are Bulgaria's rules on cross-border data transfers?
Bulgaria imposes no restrictions on cross-border transfers beyond the GDPR framework of Articles 44 to 49. Transfers outside the EEA require an adequacy decision, appropriate safeguards (Standard Contractual Clauses, Binding Corporate Rules, approved code/certification), or an applicable Article 49 derogation. Following the Schrems II judgment, controllers relying on SCCs or BCRs must conduct transfer impact assessments evaluating the law and practice of the destination country. Bulgaria completed Schengen accession in January 2025, although it was already connected to the Schengen Information System before that date; SIS processing is governed by dedicated EU SIS regulations.
What sectors face the most CPDP enforcement scrutiny in Bulgaria?
The CPDP's 2025 activity report ranks the sectors that drew the most complaints from individuals: video surveillance (425 complaints), banks and credit institutions (131), private individuals (106), state bodies (105), telecommunications (56) and media (48). Complaints passed 1,700 in 2025 against 1,080 in 2024, and total sanctions rose from BGN 74,700 (about EUR 38,194) in 2024 to BGN 226,000 (about EUR 115,553) in 2025. Organizations in high-complaint sectors should conduct proactive compliance reviews rather than waiting for a complaint to trigger CPDP scrutiny.
What are the criminal penalties for data protection violations in Bulgaria?
Beyond administrative fines under the GDPR and ZZLD, Bulgaria's Criminal Code provides criminal sanctions for certain data protection breaches. Unlawful access to an information system is punishable under Art. 319a(1) by up to six years of imprisonment plus a fine of up to BGN 3,000 (about EUR 1,534) in cases that are not minor. Distributing computer programs, passwords or access codes in order to commit such an offence carries up to six years under Art. 319d(1). Where the act discloses personal data, classified information or another secret protected by law, Art. 319d(2) sets a range of four to seven years, so there is a four-year minimum. These criminal sanctions sit alongside, not instead of, administrative CPDP proceedings.
How did Bulgaria's full Schengen accession affect data protection?
Bulgaria became a full member of the Schengen Area on 1 January 2025 when land border controls were lifted pursuant to a Council decision of 12 December 2024. Bulgaria was already connected to the Schengen Information System (SIS) before that date, through the National Schengen Information System run by the Ministry of the Interior. All personal data processing through SIS must comply with Regulation (EU) 2018/1861 (SIS for border checks), Regulation (EU) 2018/1862 (SIS for police cooperation), and the Law Enforcement Directive as transposed by the ZZLD. Schengen accession does not change the standard GDPR rules governing commercial cross-border data transfers.
Updates
Corrected the record on Bulgaria's largest data protection sanction: the BGN 5,100,000 penalty decree against the National Revenue Agency was annulled in full by the Administrative Court Sofia-city on 26 February 2024 and never paid. Updated the EU AI Act deadlines after the Digital Omnibus (Annex III high-risk from 2 December 2027, Annex I from 2 August 2028, Article 50 transparency from 2 August 2026), corrected the Criminal Code penalties for unlawful system access and password distribution, added the six-month and two-year deadlines for complaining to the CPDP, moved cookie rules to the Electronic Commerce Act, replaced CERT.bg with the sectoral CSIRT (SERIKS) as the NIS2 reporting body, corrected what the 2019, 2023 and 2024 State Gazette amendments actually did, added 2025 enforcement figures, and restated every leva figure at the fixed euro rate of 1.95583 following Bulgaria's euro adoption on 1 January 2026.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
AI Act dates updated for the July 2026 Digital Omnibus (Regulation (EU) 2026/1744): high-risk obligations now apply 2 December 2027 for Annex III systems and 2 August 2028 for AI built into regulated products, and the Article 50 transparency date has been corrected to 2 August 2026.
Corrected stale EDPB leadership claim: Ventsislav Karadjov no longer chairs the CPDP (current chair: Borislav Bozhinov) and no longer holds EDPB Vice-Chair status (current Vice-Chairs: Jelena Virant Burnik, Zdravko Vukic). Updated KeyTakeaways, body paragraph, and FAQ entry accordingly.
Major expansion from ~2,380 to ~6,000+ words. Added H2 sections on Quick Answer, Data Subject Rights, Lawful Bases and Consent, DPO Requirements, EU AI Act Overlay, and Recent Developments 2024-2026. Expanded enforcement statistics with 2022-2024 CPDP activity data. Added PDPA amendment timeline (State Gazette dates through 2024). Added Schengen full accession (January 2025) and SIS data-sharing context. Added NIS2 Directive transposition (February 2026). Added Ekimdzhiev v. Bulgaria ECHR surveillance judgment context. Added AI Act implementation status. Expanded FAQ from 5 to 12 pairs. Internal links added to Bulgaria recording laws and EU data privacy laws.
Reviewed and approved by an editor
Sources and References
- CPDP - Commission for Personal Data Protection (official site)(cpdp.bg).gov
- CPDP - Personal Data Protection Act (ZZLD)(cpdp.bg).gov
- GDPR - Regulation (EU) 2016/679 (EUR-Lex)(eur-lex.europa.eu).gov
- EU AI Act - Regulation (EU) 2024/1689 (EUR-Lex)(eur-lex.europa.eu).gov
- Ekimdzhiev and Others v. Bulgaria, App. No. 70078/12 (ECHR, 11 January 2022)(hudoc.echr.coe.int).gov
- Linklaters - Data Protected: Bulgaria(linklaters.com)
- CMS - Data Protection and Cybersecurity Laws in Bulgaria(cms.law)
- CMS - GDPR Enforcement Tracker: Bulgaria(cms.law)
- Pinsent Masons - GDPR Fines for Data Breaches in Bulgaria(pinsentmasons.com)
- Wolf Theiss - Bulgaria Fines in Millions for Personal Data Breaches(wolftheiss.com)
- INPLP - Significant Fines Imposed by the Bulgarian CPDP(inplp.com)
- Kinstellar - Bulgaria Introduces Derogations from GDPR(kinstellar.com)
- Kinstellar - Bulgaria Long Road to NIS2 is Over(kinstellar.com)
- European Commission - Bulgaria and Romania Join the Schengen Area(home-affairs.ec.europa.eu).gov
- Council of the EU - Schengen Land Border Decision (December 2024)(consilium.europa.eu).gov
- BTA - Bulgaria Still Lacks Oversight of High-Risk AI Systems(bta.bg)
- GDPRhub - Data Protection in Bulgaria(gdprhub.eu)
- EDPB - European Data Protection Board(edpb.europa.eu).gov
- Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), OJ L 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
- Administrative Court Sofia-city, press release of 26 February 2024: Penalty Decree No. 004/2019 against the National Revenue Agency annulled on limitation grounds, proceedings terminated (final)(sofia-adms-g.justice.bg).gov
- Ministry of Justice of Bulgaria, consolidated Criminal Code (Наказателен кодекс), Arts. 319a to 319d(justice.government.bg).gov
- Commission for Personal Data Protection, Annual Report 2024(cpdp.bg).gov
- Commission for Personal Data Protection, Annual Report 2025 (corrected, 12 March 2026)(cpdp.bg).gov