What national laws regulate the processing of personal data in your jurisdiction?
As Bulgaria is a member state of the European Union (“EU”), Regulation (EU) 2016/679 (General Data Protection Regulation) (the “GDPR”) is the primary data protection law with direct effect in Bulgaria. The GDPR sets the main principles and terms of personal data processing and protection, the rights of data subjects and the obligations of data controllers and processors, the enforcement mechanisms, including powers and competences of data protection authorities and maximum amounts of permissible sanctions for non-compliance. In Bulgaria, the GDPR is supplemented by the Personal Data Protection Act (“PDPA”), which has been in force since 2002. The PDPA introduces specific national provisions and applies only in particular situations where the GDPR permits EU member states to enact national regulations. The PDPA primarily regulates:
- public relations concerning the protection of individuals’ rights in the processing of their personal data as far as these are not governed by the GDPR;
- the status of the Commission for Personal Data Protection (“CPDP”) as the Bulgarian supervisory authority responsible for safeguarding the fundamental rights and freedoms of individuals concerning the processing and facilitating the free movement of personal data within the EU;
- the powers of the Inspectorate of the Supreme Judicial Council ("SJC Inspectorate") in exercising supervision over the processing of personal data in specific situations relating to the processing of personal data for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the protection against and prevention of threats to public order and security;
- the means and venues of legal protection in case of violation of data protection rights;
- the accreditation and certification in the field of personal data protection; and
- special cases of personal data processing.
While the GDPR and the PDPA are core piece of Bulgarian legislation governing personal data processing, certain additional rules and obligations regarding data protection are also set out in other legal instruments. For example, there are certain relevant sector-specific legal provisions in the Bulgarian Accounting Act (Закон за счетоводството), Tax and Social Security Procedure Code (Данъчно-осигурителен процесуален кодекс), and Financial Instruments Markets Act (Закон за пазарите на финансови инструменти). In addition, certain secondary pieces of legislation, such as rules and regulations, set specific rules on specific aspects of data protection, as per example, storage limitation requirements.
Beyond statutory laws, the legal landscape continues to evolve through the practice of the CPDP, which issues guidelines, decisions, and interpretations in respect of matters concerning the processing of personal data.
Additionally, the European Data Protection Board (“EDPB”) plays a crucial role in shaping data protection practices across the EU, including in Bulgaria. The EDPB’s opinions, guidelines, and recommendations serve as authoritative guidance for interpreting GDPR provisions and addressing controversial or emerging data protection issues.