EnglishBG
Bulgaria flag

Bulgaria

Bulgaria Data Privacy Laws: GDPR & PDPA Complete Guide (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 13 primary sources cited on this page. How we verify our legal content

Bulgaria Data Privacy Laws: GDPR & PDPA Complete Guide (2026)

Frequently Asked Questions

What is Bulgaria's main data protection law?

Bulgaria's primary national data protection legislation is the Personal Data Protection Act (Zakon za zashtita na lichnite danni, ZZLD), promulgated in State Gazette No. 17 of 26 February 2019 and most recently amended in State Gazette No. 70 of 20 August 2024. The ZZLD supplements the directly applicable EU GDPR by covering areas where EU law permits national discretion, including the CPDP's structure and powers, the age of digital consent (14 years), video surveillance provisions, journalistic expression exemptions, and transposition of the Law Enforcement Directive.

What is the CPDP and what powers does it have?

The Commission for Personal Data Protection (CPDP/КЗЛД) is Bulgaria's independent data protection supervisory authority under GDPR Article 51. It consists of a chairperson and four members appointed by parliament for five-year terms. The CPDP can investigate complaints, conduct on-site inspections, issue warnings and compliance orders, impose processing bans, and levy administrative fines of up to EUR 20 million or 4% of global annual turnover. A data subject must refer a matter to the Commission within six months of learning of the infringement and no later than two years after it was committed (ZZLD Art. 38(1)). The CPDP's chairperson participates in the European Data Protection Board as Bulgaria's representative.

What was the NRA data breach and what was the fine?

In 2019, the Bulgarian National Revenue Agency (NRA) suffered a cyberattack in which a hacker gained remote unauthorized access to NRA servers and took personal data from approximately 6,074,140 records. The stolen data included names, EGN (unified civil numbers), addresses, income, and tax and social security details. The CPDP found that the NRA had failed to implement adequate technical and organizational security measures under GDPR Article 32, and its chairperson issued Penalty Decree No. 004 of 28 August 2019 for BGN 5,100,000 (about EUR 2,607,591). That decree no longer stands. The Administrative Court Sofia-city annulled it on 26 February 2024 and terminated the proceedings because the absolute limitation period of four years and six months had expired, in a decision that is final and cannot be appealed, so the NRA never paid it.

What is the EGN and how is it protected under Bulgarian law?

The EGN (Edinen Grazhdanski Nomer) is Bulgaria's unique ten-digit unified civil number assigned to citizens at birth, encoding the holder's date of birth and sex. It is used widely across government, healthcare, banking, and private sector systems. Under the ZZLD and GDPR Article 87 (which permits national rules on identification numbers), processing of EGNs requires a specific legal justification. The CPDP has issued guidance limiting unnecessary EGN disclosure in official sanctions and other public documents. The NRA breach demonstrated the severe identity fraud risks of EGN exposure.

What is the age of digital consent in Bulgaria?

Bulgaria set the age of digital consent at 14 years for information society services, lower than the GDPR's default of 16 years but within the permissible range of GDPR Article 8(1) (which allows member states to lower the threshold to a minimum of 13 years). Children under 14 require parental or guardian consent for consent-based processing. The CPDP's March 2022 guidance requires separate consent per processing activity, active opt-in interfaces, and strict data minimization for children's services.

Does a business operating in Bulgaria need a Data Protection Officer?

A DPO is mandatory when: (1) the organization is a public authority or body (except courts acting in their judicial capacity); (2) core activities require regular and systematic large-scale monitoring of data subjects; or (3) core activities involve large-scale processing of special categories of data or criminal records data. Bulgaria does not impose additional DPO requirements beyond GDPR Article 37. If a DPO is required, their appointment must be registered with the CPDP using the approved registration form, even if the DPO is based outside Bulgaria.

How does the EU AI Act affect businesses in Bulgaria?

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Bulgaria. Prohibited AI practices, including certain uses of real-time remote biometric identification in public spaces and AI systems that exploit vulnerabilities or assign social scores, have been unlawful since 2 February 2025. Core obligations for high-risk AI systems apply from 2 December 2027 for Annex III systems and 2 August 2028 for AI built into regulated products, moved by the July 2026 Digital Omnibus. The CPDP has been designated as one of seven competent fundamental-rights bodies under the AI Act. Businesses should classify their AI systems for risk, conduct DPIAs for high-risk systems, and monitor the CPDP's developing guidance.

What is the significance of Ekimdzhiev and Others v. Bulgaria for data protection?

Ekimdzhiev and Others v. Bulgaria (App. No. 70078/12, ECHR, 11 January 2022) found that Bulgarian secret surveillance legislation violated ECHR Article 8 because it lacked effective safeguards against arbitrariness and abuse. The Court also found violations in the rules governing telecommunications traffic data retention and law enforcement access. The judgment requires that any processing of personal data by Bulgarian intelligence or law enforcement agencies outside the ZZLD's Law Enforcement Directive provisions must independently satisfy the ECHR's quality-of-law standard.

What are Bulgaria's rules on cross-border data transfers?

Bulgaria imposes no restrictions on cross-border transfers beyond the GDPR framework of Articles 44 to 49. Transfers outside the EEA require an adequacy decision, appropriate safeguards (Standard Contractual Clauses, Binding Corporate Rules, approved code/certification), or an applicable Article 49 derogation. Following the Schrems II judgment, controllers relying on SCCs or BCRs must conduct transfer impact assessments evaluating the law and practice of the destination country. Bulgaria completed Schengen accession in January 2025, although it was already connected to the Schengen Information System before that date; SIS processing is governed by dedicated EU SIS regulations.

What sectors face the most CPDP enforcement scrutiny in Bulgaria?

The CPDP's 2025 activity report ranks the sectors that drew the most complaints from individuals: video surveillance (425 complaints), banks and credit institutions (131), private individuals (106), state bodies (105), telecommunications (56) and media (48). Complaints passed 1,700 in 2025 against 1,080 in 2024, and total sanctions rose from BGN 74,700 (about EUR 38,194) in 2024 to BGN 226,000 (about EUR 115,553) in 2025. Organizations in high-complaint sectors should conduct proactive compliance reviews rather than waiting for a complaint to trigger CPDP scrutiny.

What are the criminal penalties for data protection violations in Bulgaria?

Beyond administrative fines under the GDPR and ZZLD, Bulgaria's Criminal Code provides criminal sanctions for certain data protection breaches. Unlawful access to an information system is punishable under Art. 319a(1) by up to six years of imprisonment plus a fine of up to BGN 3,000 (about EUR 1,534) in cases that are not minor. Distributing computer programs, passwords or access codes in order to commit such an offence carries up to six years under Art. 319d(1). Where the act discloses personal data, classified information or another secret protected by law, Art. 319d(2) sets a range of four to seven years, so there is a four-year minimum. These criminal sanctions sit alongside, not instead of, administrative CPDP proceedings.

How did Bulgaria's full Schengen accession affect data protection?

Bulgaria became a full member of the Schengen Area on 1 January 2025 when land border controls were lifted pursuant to a Council decision of 12 December 2024. Bulgaria was already connected to the Schengen Information System (SIS) before that date, through the National Schengen Information System run by the Ministry of the Interior. All personal data processing through SIS must comply with Regulation (EU) 2018/1861 (SIS for border checks), Regulation (EU) 2018/1862 (SIS for police cooperation), and the Law Enforcement Directive as transposed by the ZZLD. Schengen accession does not change the standard GDPR rules governing commercial cross-border data transfers.

Updates

Corrected the record on Bulgaria's largest data protection sanction: the BGN 5,100,000 penalty decree against the National Revenue Agency was annulled in full by the Administrative Court Sofia-city on 26 February 2024 and never paid. Updated the EU AI Act deadlines after the Digital Omnibus (Annex III high-risk from 2 December 2027, Annex I from 2 August 2028, Article 50 transparency from 2 August 2026), corrected the Criminal Code penalties for unlawful system access and password distribution, added the six-month and two-year deadlines for complaining to the CPDP, moved cookie rules to the Electronic Commerce Act, replaced CERT.bg with the sectoral CSIRT (SERIKS) as the NIS2 reporting body, corrected what the 2019, 2023 and 2024 State Gazette amendments actually did, added 2025 enforcement figures, and restated every leva figure at the fixed euro rate of 1.95583 following Bulgaria's euro adoption on 1 January 2026.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

AI Act dates updated for the July 2026 Digital Omnibus (Regulation (EU) 2026/1744): high-risk obligations now apply 2 December 2027 for Annex III systems and 2 August 2028 for AI built into regulated products, and the Article 50 transparency date has been corrected to 2 August 2026.

Corrected stale EDPB leadership claim: Ventsislav Karadjov no longer chairs the CPDP (current chair: Borislav Bozhinov) and no longer holds EDPB Vice-Chair status (current Vice-Chairs: Jelena Virant Burnik, Zdravko Vukic). Updated KeyTakeaways, body paragraph, and FAQ entry accordingly.

Major expansion from ~2,380 to ~6,000+ words. Added H2 sections on Quick Answer, Data Subject Rights, Lawful Bases and Consent, DPO Requirements, EU AI Act Overlay, and Recent Developments 2024-2026. Expanded enforcement statistics with 2022-2024 CPDP activity data. Added PDPA amendment timeline (State Gazette dates through 2024). Added Schengen full accession (January 2025) and SIS data-sharing context. Added NIS2 Directive transposition (February 2026). Added Ekimdzhiev v. Bulgaria ECHR surveillance judgment context. Added AI Act implementation status. Expanded FAQ from 5 to 12 pairs. Internal links added to Bulgaria recording laws and EU data privacy laws.

Reviewed and approved by an editor

Sources and References

  1. CPDP - Commission for Personal Data Protection (official site)(cpdp.bg).gov
  2. CPDP - Personal Data Protection Act (ZZLD)(cpdp.bg).gov
  3. GDPR - Regulation (EU) 2016/679 (EUR-Lex)(eur-lex.europa.eu).gov
  4. EU AI Act - Regulation (EU) 2024/1689 (EUR-Lex)(eur-lex.europa.eu).gov
  5. Ekimdzhiev and Others v. Bulgaria, App. No. 70078/12 (ECHR, 11 January 2022)(hudoc.echr.coe.int).gov
  6. Linklaters - Data Protected: Bulgaria(linklaters.com)
  7. CMS - Data Protection and Cybersecurity Laws in Bulgaria(cms.law)
  8. CMS - GDPR Enforcement Tracker: Bulgaria(cms.law)
  9. Pinsent Masons - GDPR Fines for Data Breaches in Bulgaria(pinsentmasons.com)
  10. Wolf Theiss - Bulgaria Fines in Millions for Personal Data Breaches(wolftheiss.com)
  11. INPLP - Significant Fines Imposed by the Bulgarian CPDP(inplp.com)
  12. Kinstellar - Bulgaria Introduces Derogations from GDPR(kinstellar.com)
  13. Kinstellar - Bulgaria Long Road to NIS2 is Over(kinstellar.com)
  14. European Commission - Bulgaria and Romania Join the Schengen Area(home-affairs.ec.europa.eu).gov
  15. Council of the EU - Schengen Land Border Decision (December 2024)(consilium.europa.eu).gov
  16. BTA - Bulgaria Still Lacks Oversight of High-Risk AI Systems(bta.bg)
  17. GDPRhub - Data Protection in Bulgaria(gdprhub.eu)
  18. EDPB - European Data Protection Board(edpb.europa.eu).gov
  19. Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 (Digital Omnibus on AI), OJ L 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
  20. Administrative Court Sofia-city, press release of 26 February 2024: Penalty Decree No. 004/2019 against the National Revenue Agency annulled on limitation grounds, proceedings terminated (final)(sofia-adms-g.justice.bg).gov
  21. Ministry of Justice of Bulgaria, consolidated Criminal Code (Наказателен кодекс), Arts. 319a to 319d(justice.government.bg).gov
  22. Commission for Personal Data Protection, Annual Report 2024(cpdp.bg).gov
  23. Commission for Personal Data Protection, Annual Report 2025 (corrected, 12 March 2026)(cpdp.bg).gov
Share: