TerraLex Guide to Data Protection

Welcome to the Terralex cross-border guide to data protection

Data protection continues to be a top issue for companies around the globe. With the ever-changing technology and responding legislation, it is important that businesses be prepared to handle a patchwork of data protection regulations. This guide, prepared by TerraLex members from around the globe, provides initial guidance on some of the key aspects to consider.

How to Use: You can use the tools below to create bespoke reports for the jurisdiction(s) and topic(s) covered. Click into single jurisdiction for one location or use the compare tool to compare multiple jurisdictions. Select the jurisdictions and topics of interest to create your unique report. You also have the option to print or download using the ellipsis button in the top right corner.

Bulgaria TerraLex Guide to Data Protection Guide

Date posted:
03/09/2024
Last update:
13/11/2024

Legislation and regulations

What national laws regulate the processing of personal data in your jurisdiction?

As Bulgaria is a member state of the European Union (“EU”), Regulation (EU) 2016/679 (General Data Protection Regulation) (the “GDPR”) is the primary data protection law with direct effect in Bulgaria. The GDPR sets the main principles and terms of personal data processing and protection, the rights of data subjects and the obligations of data controllers and processors, the enforcement mechanisms, including powers and competences of data protection authorities and maximum amounts of permissible sanctions for non-compliance. In Bulgaria, the GDPR is supplemented by the Personal Data Protection Act (“PDPA”), which has been in force since 2002. The PDPA introduces specific national provisions and applies only in particular situations where the GDPR permits EU member states to enact national regulations. The PDPA primarily regulates:

  • public relations concerning the protection of individuals’ rights in the processing of their personal data as far as these are not governed by the GDPR;
  • the status of the Commission for Personal Data Protection (“CPDP”) as the Bulgarian supervisory authority responsible for safeguarding the fundamental rights and freedoms of individuals concerning the processing and facilitating the free movement of personal data within the EU;
  • the powers of the Inspectorate of the Supreme Judicial Council ("SJC Inspectorate") in exercising supervision over the processing of personal data in specific situations relating to the processing of personal data for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the protection against and prevention of threats to public order and security;
  • the means and venues of legal protection in case of violation of data protection rights;
  • the accreditation and certification in the field of personal data protection; and
  • special cases of personal data processing.

While the GDPR and the PDPA are core piece of Bulgarian legislation governing personal data processing, certain additional rules and obligations regarding data protection are also set out in other legal instruments. For example, there are certain relevant sector-specific legal provisions in the Bulgarian Accounting Act (Закон за счетоводството), Tax and Social Security Procedure Code (Данъчно-осигурителен процесуален кодекс), and Financial Instruments Markets Act (Закон за пазарите на финансови инструменти). In addition, certain secondary pieces of legislation, such as rules and regulations, set specific rules on specific aspects of data protection, as per example, storage limitation requirements.

Beyond statutory laws, the legal landscape continues to evolve through the practice of the CPDP, which issues guidelines, decisions, and interpretations in respect of matters concerning the processing of personal data.

Additionally, the European Data Protection Board (“EDPB”) plays a crucial role in shaping data protection practices across the EU, including in Bulgaria. The EDPB’s opinions, guidelines, and recommendations serve as authoritative guidance for interpreting GDPR provisions and addressing controversial or emerging data protection issues.

To whom do the laws apply?

The territorial and material scope of data protection is set out in the GDPR. It applies to all natural persons whose personal data is processed from Bulgaria (or any other EU member state) and in respect of all natural persons in the EU. The GDPR does not apply to the processing of personal data related to legal entities, such as businesses and organizations, including their names, legal forms, and contact details.

The territorial application of the Bulgaria’s data protection legislation, as outlined under Article 3 of the GDPR, extends beyond the borders of the EU. It applies not only to organizations within the EU but also to those outside the EU if they process personal data related to offering goods or services to individuals in the EU or monitor the behaviour of individuals within the EU.

The material scope of Bulgaria’s data protection legislation, on the other side, includes the processing of personal data wholly or partly by automated means as well as manual processing if it forms part of a filing system or is intended to do so. However, certain exceptions apply. The GDPR does not apply to processing conducted by a natural person strictly for personal or household activities, such as private correspondence or personal social media use, provided it is unconnected to any professional or commercial activity. Additionally, data processing by law enforcement for criminal justice purposes and processing for activities outside the scope of EU law, such as national security, are also excluded from GDPR’s application. Children merit specific protection with regard to their data privacy, as they are considered less aware of the risks, consequences, safeguards concerned and their rights in relation to the processing of personal data. The PDPA stipulates that processing the personal data of a data subject under the age of 14, based on consent as defined by the GDPR, is lawful only if consent is provided by a parent with parental rights or a legal guardian. This requirement applies in all cases, including when information society services are offered directly to the child.

In addition, the PDPA provides for and regulates special cases of personal data processing, including:

  • data processing by competent authorities for the purposes of prevention, investigation, detection or prosecution of criminal offences or execution of criminal penalties;
  • data processing for journalistic purposes and for the purposes of academic, artistic or literary expression;
  • data processing for the purposes of the National Archive Fund of the Republic of Bulgaria, whereas this processing is deemed to be in public interest;
  • data processing for statistical purposes;
  • data processing for humanitarian purposes by public bodies or humanitarian organizations, as well as data processing in cases of disaster within the meaning of the Disaster Protection Act.

Furthermore, personal data originally collected for a different purpose may be processed for the purposes of the National Archive Fund, and for scientific, historical research or statistical purposes. In such cases, the controller shall apply appropriate technical and organizational measures to safeguard the rights and freedoms of the data subject in accordance with the GDPR.

Scope of protection

What type of data is covered by the law?

Any information relating to an identified or identifiable natural person (“data subject”) is personal data. There are two main categories of personal data: general personal data and special category personal data.

Special categories of personal data include data revealing or including the racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data, data concerning health or data concerning the sex life or sexual orientation of a data subject (“sensitive personal data”).

Processing of sensitive personal data receives enhanced protection and in principle, is prohibited under the GDPR, except under specific conditions exhaustively listed in Article 9 of the GDPR, including when the data subject has given explicit consent for the processing, or the processing is necessary for the purposes of fulfilling obligations in the field of employment, social security and social protection.

Data concerning health includes all data pertaining to the health status of a data subject which reveal information relating to the past, current or future physical or mental health status of the data subject. Furthermore, the Bulgarian Health Act (Закон за здравето) provides that individuals' human genome data is confidential data and cannot be provided to employers, health insurance organizations or insurance companies.

Personal data subject to the data protection laws in Bulgari include also pseudonymized personal data as such data can be linked to a specific individual following the use of additional tools and/or information. All objective factors, such as cost, amount of time and technological developments, must be considered when determining whether information can be used to identify a person.

Accordingly, the protection does not extend to anonymous information, which by its nature cannot be linked to a specific individual and help to identify that individual.

What are the main exemptions (if any)?

Processing of personal data for the purposes of national defense and national security as well as processing of personal data of deceased persons falls outside the scope of protection, except where expressly provided otherwise in the local law.

According to the PDPA, a data controller or processor may process personal data of deceased persons only if there is a valid legal basis. In such cases, the data controller or processor shall take the appropriate measures to ensure that there will be no adverse effects over the rights and freedoms of other persons, and is obliged to provide, upon request, access to the personal data of the deceased person to his heirs or other persons with legal interest, unless otherwise provided for by law.

What rights do the laws grant to the data owners?

Privacy and right to personal data protection is a fundamental right of natural persons. The GDPR includes principles and rules for the lawful processing of personal data so that all fundamental rights of natural persons such as respect for privacy and family life, home and communications, freedom of thought, and other, are respected. For processing to be lawful, personal data must be processed on the basis of the data subject's consent or on another legal basis set out in the GDPR in relation to legitimate purposes. This right may be affected only on expressly set conditions and for limited purposes always subject to full transparency.

According to GDPR, data subjects have the following rights:

(i) right of information; (ii) right to request access; (iii) right to rectification; (iv) right to erasure (‘right to be forgotten’); (v) right to restriction of processing; (vi) right to data portability; (vii) right to object to the data processing; and (viii) right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

Data subjects can exercise their data protection rights by way of a written application submitted to the data controller or by another method determined and communicated by the data controller.

Data subject rights are broad but not absolute. They are subject to certain limitations under terms set forth in the GDPR.

A data controller or processor may fully or partially refuse the exercise of data subjects' rights if the exercise of these rights or the fulfillment of the obligation poses a risk to:

a) national security; b) defense; c) public order and security; d) the prevention, investigation, detection, or prosecution of criminal offenses or the execution of imposed penalties, including the prevention of and protection against threats to public order and security; e) other important objectives of significant public interest, particularly those related to economic or financial matters, including monetary, budgetary, and taxation issues, public health, and social security; f) the protection of the independence of the judiciary and judicial proceedings; g) the prevention, investigation, detection, and prosecution of breaches of professional codes of ethics in regulated professions; h) a monitoring, inspection or regulatory function connected, even occasionally, to the exercise of official authority in the cases referred to in points (a) to (e) and (g); i) the protection of the data subject or the rights and freedoms of others; j) the enforcement of civil law claims.

In cases of infringement, the data subject is entitled to the following:

  • submit a claim or signal to the CPDP referring an infringement of his/her data protection rights or violation of the GDPR or PDPA; the data subject can exercise this right of action within six months after having become aware of the infringement or violation but no later than two years after the infringement or violation has occurred; or
  • submit a complaint to the SJC Inspectorate within six months after becoming aware of the infringement but not later than two years after the infringement has occurred if the infringement has been executed by the court, the prosecution or the investigating authorities when acting in their judical capacity for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties; or
  • challenge the actions of the relevant data controller and/or processor in court pursuant to the Bulgarian Administrative Procedure Code (Административно процесуален кодекс) and seek damages within these proceedings.

Processing requirement and main obligations

What are the lawful grounds for processing personal data or sensitive personal data (if different)?

The legal grounds for personal data processing are as set out in Article 6 of the GDPR, for general personal data, and Article 9 of the GDPR, for sensitive personal data, respectively.

The processing of general personal data is lawful only if and to extent that at least one of the following applies:

(i) the data subject has given consent to the processing; (ii) the processing is necessary for the performance of a contract to which the data subject is party or to take steps at the request of the data subject prior to entering a contract; (iii) the processing is necessary for the compliance with a legal obligation to which the controller is subject; (iv) the processing is necessary to protect the vital interests of the data subject or of another natural person; (v) the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; (vi) the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, where the data subject is a child.

Sensitive personal data can be processed on the following legal grounds:

a) the data subject has given explicit consent to the processing of the personal data for one or more specified purposes; b) processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law; c) processing is necessary to protect the vital interests of the data subject or of another natural person where the data subject is physically or legally incapable of giving consent; d) processing is carried out in the course of its legitimate activities by a foundation, association or any other not-for-profit body with a political, philosophical, religious or trade union aim and on condition that the processing relates solely to the members or to former members of the body or to persons who have regular contact with it in connection with its purposes and that the personal data are not disclosed outside that body without the consent of the data subjects; e) processing relates to personal data which are manifestly made public by the data subject; f) processing is necessary for the establishment, exercise, or defence of legal claims or whenever courts are acting in their judicial capacity; g) processing is necessary for reasons of substantial public interest, based on Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject; h) processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services based on EU or Bulgarian local law or pursuant to contract with a health professional; i) processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices based on EU or Bulgarian local law which provides for suitable and specific measures to safeguard the rights and freedoms of the data subject, in particular professional secrecy; j) processing is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes based on EU or Bulgarian local law. Additional terms and conditions apply to the processing of sensitive personal data on most of these legal grounds.

What are the main obligations imposed by the law?

Obligations of data controllers procure the implementation of the data protection principles, and all are set out in the GDPR. Pursuant to the legal framework, a breach of a data protection principle is considered as a major noncompliance and, accordingly, subject to a strict sanction.

The data protection principle are as follows:

(i) lawfulness, fairness, and transparency to data subjects; (ii) purpose limitation; (iii) data minimization; (iv) accurate and up-to-date personal data; (v) storage limitation; (vi) integrity, confidentiality, and security; and (vii) security.

One of the most important obligations of data controllers is related to ensuring the transparency of data processing. They shall notify data subjects of the various circumstances provided for in Article 13 of the GDPR, related to the processing of personal data. In this sense, data controllers are required to make available to the data subject at least the following information:

  • the identity and the contact details of the controller;
  • the contact details of the data protection officer, where applicable;
  • the purposes for which the personal data are intended as well as the legal basis for the processing;
  • if applicable, the legitimate interests pursued by the controller or by a third party;
  • if applicable, the recipients of the personal data;
  • the period for which the personal data will be stored;
  • the rights of data subjects under the law;
  • information whether the provision of personal data is a statutory or contractual requirement and whether the data subject is obliged to provide the personal data and the possible consequences of failure to provide such data; and
  • the applicability of automated decision-making, including profiling.

Furthermore, each data controller or processor has the obligation to maintain records of personal data processing activities. These records shall be maintained in writing, including in electronic form.

In addition, controllers and processors shall implement appropriate technical and organisational measures that ensure a level of security appropriate to the risk of the personal data processing.

Where the data processing, particularly when using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall carry out an assessment of the impact of the envisaged processing operations on the protection of personal data (also known as a data protection impact assessment). If such assessment indicates that the processing would result in a high risk, the controller shall consult the CPDP prior to executing the processing concerned.

Do the laws establish a data retention period to be observed?

One of the data protection principles in the GDPR, is storage limitation. In certain cases, Bulgarian laws do provide for specific storage retention periods. For example, the PDPA mandates that any appointing authority, acting as a data controller, must establish a retention period for the personal data of job applicants in selection procedures, which may not exceed six months, unless the applicant provides explicit consent for an extended storage period.

Further, the Bulgarian Accountancy Act specifies various retention periods for diverse types of documents. Payroll records must be retained for 50 years, while accounting records, financial statements, and documents related to tax control, audits, and subsequent financial inspections must be kept for 10 years. All other carriers of accounting information are to be retained for 3 years.

Bulgarian secondary legislation also sets statutory retention periods. An interesting example in this respect provides Article 9, para. 2 of Ordinance No RD-07-2 of 16 December 2009 on the conditions and procedure for periodic training and instruction of employees on the rules for ensuring occupational health and safety, which requires that documents related to trainings under the Health and Safety at Work Act, as well as other documents related to the implementation of the obligations under the latter, shall be kept for no less than 5 years from their creation.

We note that when there is no statutory established period for personal data retention, data controllers are required to introduce such period at their discretion in view of what is necessary in view of the purpose of data processing and inform the relevant data subjects accordingly. According to the guidance provided by the European Data Protection Board, stating “personal data will be stored for no longer than is necessary for the purposes for which the personal data are processed” is not compliant with the data privacy legislation. There must be either a specifically defined retention period or clear criteria that determine, in time, how long the data will be processed by the data controller.

Must the data processing activities be recorded under the law?

As noted above, GDPR provides for the obligation of controllers and processors to maintain records of personal data processing activities. This obligation is related to the accountability principle.

In the case of controllers, the registers shall contain the following information:

(a) the name and contact details of the controller and, where applicable, the joint controller, the controller's representative, and the data protection officer; (b) the purposes of the processing; (c) a description of the categories of data subjects and of the categories of personal data; (d) the categories of recipients to whom the personal data have been or will be disclosed including recipients in third countries or international organisations; (e) where applicable, transfers of personal data to a third country or an international organisation, including the identification of that third country or international organisation and, the documentation of suitable safeguards; (f) where possible, the envisaged time limits for erasure of the different categories of data; and (g) where possible, a general description of the implemented technical and organisational security measures.

In the case of data processors, the registers shall contain the following information:

(a) the name and contact details of the processor or processors and of each controller on behalf of which the processor is acting, and, where applicable, of the controller's or the processor's representative, and the data protection officer; (b) the categories of processing conducted on behalf of each controller; (c) where applicable, transfers of personal data to a third country or an international organization, including the identification of that third country or international organization, and the documentation of suitable safeguards; and (d) where possible, a general description of the implemented technical and organizational security measures.

National authority and DPO

Is there a Data Protection National Authority? If so, what is the National Authority main role?

The data protection authority in Bulgaria is the Commission for Personal Data Protection (in Bulgarian, Комисия за защита на личните данни) – the CPDP. It is an independent supervisory authority, and its main competence, tasks and powers include data protection and are set out in the GDPR. In addition, further to the PDPA, the CPDP:

  • issues secondary legislative acts in the area of personal data protection;
  • ensures the implementation of the decisions of the European Commission in the area of personal data protection and the implementation of the legally binding decisions of the EDPB under Article 65 of GDPR;
  • participates in international cooperation with other personal data protection authorities and international organisations on personal data protection issues;
  • participates in the negotiations and the conclusion of bilateral or multilateral agreements on matters within its competence;
  • organises, coordinates, and provides personal data protection training;
  • issues general and statutory administrative acts related to its powers in cases foreseen in law.
  • refers any infringement of the GDPR for review and resolution to court;
  • gives instructions, issues guidelines, recommendations, and best practices in relation to personal data protection;
  • conducts accreditation of certification bodies;
  • approves codes of conduct by sector and field of action, pursuant to GDPR, etc.

The contact details of the CPDP are as follows: Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592
Е-mail: [email protected]; website: www.cpdp.bg

Does the law impose the obligation of designating a data protection officer (DPO)? If so, what is the role of the DPO under the law?

Bulgarian data protection laws do not impose a general obligation for data controllers or processors of designating a data protection officer (“DPO”).

Pursuant to Article 37 of the GDPR, a DPO shall be designated when:

  • the processing is carried out by a public authority or body, except for courts acting in their judicial capacity;
  • the core activities of the controller or the processor consist of processing operations which, by virtue of their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or
  • the core activities of the controller or the processor consist of processing on a large scale of special categories of data pursuant to Article 9 of the GDPR and personal data relating to criminal convictions and offences referred to in Article 10 of the GDPR.

Separately, a DPO may also be designated by a data controller or data processor voluntarily at its discretion in any other case.

When a DPO is designated, this circumstance shall be registered in the CPDP public registry of controllers and processors which have a data protection officer appointed.

The principal tasks of a DPO include:

  • to inform and advise the controller or the processor and the employees who carry out processing of their obligations pursuant to GDPR and to other EU or Member State data protection provisions;
  • to monitor compliance with GDPR, with other EU or Member State data protection provisions, and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits;
  • to provide advice as regards the data protection impact assessment and monitor its performance pursuant to GDPR;
  • to cooperate with the CPDP as the supervisory authority; and
  • to act as the contact point for the CPDP on issues relating to data processing, including the prior consultation referred to in Article 36 of the GDPR, and to consult, where appropriate, regarding any other matter.

Cross-border transfers

What rules regulate the transfer of data outside your jurisdiction?

Cross-border data transfers from Bulgaria to countries within the European Economic Area (“EEA”) are considered internal and, consequently, do not require the implementation of additional transfer mechanisms and safeguards due to the harmonized data protection framework established by the GDPR.

While data transfers within the EEA are unrestricted, the GDPR introduces a comprehensive legal regime for transferring data to third countries or international organizations outside the EEA. These transfers are subject to specific conditions to ensure that the level of data protection remains adequate, even when the personal data leaves the EEA. These key rules regulating the transfer of personal data outside the EEA are set forth in Articles 44 to 49 of the GDPR. Such transfers must be:

(i) based on a valid transfer mechanism, such as an adequacy decision adopted by the European Commission, or another appropriate safeguard specified under Article 46 of the GDPR; (ii) accompanied by a transfer impact assessment (TIA) that evaluates the risks associated with transferring personal data to the third country considering the legal and practical circumstances of that country; (iii) accompanied by supplementary technical, contractual, and organizational measures when the TIA indicates that the transfer mechanism used alone is insufficient to ensure data protection.

Is it necessary to notify the National Authority prior to the international transfer?

It is not necessary to notify the CPDP prior to executing international personal data transfers and such transfers do not require any specific authorisation.

Security standards, data breaches, and sanctions

Do the laws impose any information security standards and/or requirements?

National data protection laws do not prescribe specific security standards or requirements. Instead, the GDPR’s principle of integrity and confidentiality establishes the baseline security standard that controllers and processors must follow. Under this principle, controllers and processors are required to implement appropriate technical and organizational measures to safeguard personal data against unauthorized access, alteration, loss, or destruction. These technical and organizational measures shall ensure a level of security appropriate to the risk, considering the state of the art, the costs of implementation and the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, as per Article 32 of the GDPR.

We note that on 14 December 2023, the Court of Justice of the European Union (CJEU) issued a preliminary ruling further to a request lodged by the Bulgarian Supreme Administrative Court, in which it provided important affirmations in respect of the assessment of appropriateness of technical and organizational measures adopted by a controller pursuant to Article 32. The CJEU emphasized that the evaluation must consider the nature and content of the security measures, how they are implemented, and their practical impact on the level of security the controller must maintain, considering the risks specific to the data processing activities.

Do the laws establish any kind of mandatory notification duty?

In accordance with the GDPR, in the case of a personal data breach the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the CPDP, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the CPDP is not made within 72 hours, it shall be accompanied by reasons for the delay.

Processors shall also notify the respective controllers without undue delay after becoming aware of a personal data breach, although data protection legislation does not provide for a specific notification timeframe in this respect. Such timeframe is typically established in the data processing agreement between the controller and the processor.

It is important to note that the notification to CPDP shall at least:

  • describe the nature of the personal data breach including where possible the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
  • communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
  • describe the likely consequences of the personal data breach;
  • describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.

Where it is not possible to provide all required information initially (within the 72 hours term), all relevant and required data shall be provided in phases as soon as available without undue delay.

In addition, the controller shall document any personal data breaches, including the facts relating to the personal data breach concerned, its effects and the remedial action taken.

When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall also communicate this personal data breach to the data subject without undue delay, as per Article 34 of the GDPR. Such data breach notification is not required if any of the following conditions are met:

  • the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption;
  • the controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects is no longer likely to materialise; and
  • it would involve disproportionate effort, whereas in such a case, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.

What are the sanctions for noncompliance with data protection laws?

Maximum sanctions for noncompliance are set forth in the GDPR. Pursuant to its provisions, infringements of obligations such as to keep records of processing activities, to ensure the security of processing under Article 32 of the GDPR, and to notify a personal data breach to the CPDP, are subject to administrative fines of up to EUR 10,000,000, or in the case of an undertaking, up to 2% of the total worldwide annual turnover of the undertaking for the preceding financial year, whichever is higher.

For violation of the GDPR data protection principles and implementing rules, including violations regarding conditions for consent, data subjects’ rights, transfers of personal data to a recipient in a third country, the administrative fines can reach up to EUR 20,000,000, or in the case of an undertaking up to 4% of the total worldwide annual turnover of the undertaking for the preceding financial year, whichever is higher.

In addition, failure to comply with the data protection rules may result in the adoption of corrective measures by the CPDP, such as warnings, prescriptive measures, temporary or permanent prohibition of processing.

Other comments

Other comments

To provide more detailed perspective on the data protection landscape in Bulgaria, according to the CPDP 2023 annual report, the fines and pecuniary sanctions that the CPDP imposed in 2023 range from BGN 500 (for violation of Article 5, para 1, point “d” of the GDPR) up to BGN 35,000 (for violation of Article 6, para 1 of the GDPR). In 2023, the CPDP received a considerable number of complaints, and these reveal widespread violations of key provisions of the applicable data protection legislation in Bulgaria. These violations primarily involved unlawful processing of personal data – in breach of Article 6, para.1 of the GDPR. Additionally, in many cases data processing conducted violated the core principles pursuant to Article 5, para. 1 of the GDPR, including “lawfulness and fairness,” “data minimization,” “integrity and confidentiality,” and “accuracy.” Furthermore, breaches related to inadequate technical and organizational measures for personal data protection, as well as failures to address data subjects' rights requests within the required timeframes, were also frequently reported. The corrective measures of the CPDP imposed in response to these violations reflect a consistent trend from 2021 and 2022.

In 2023, the CPDP has exercised the following corrective powers in relation to complaints received about data protection violations:

  • Eight warnings;
  • Twenty-two reprimands;
  • One order to comply with a data subject’s request for the exercise of rights;
  • 115 orders to bring processing operations into compliance with the GDPR provisions;
  • One ban on data processing;
  • One order to a data controller to notify recipients of personal data regarding a request for personal data erasure;
  • Fifty-one fines.

Due to the specific nature of certain infringements, the CPDP has frequently imposed a pecuniary sanction or fine in addition to imposed corrective measures.

The landscape of data protection in Bulgaria is evolving rapidly and becoming increasingly complex, particularly with the adoption of the EU Artificial Intelligence Act (“EU AI Act”). As artificial intelligence technologies continue to proliferate across various sectors, they bring with them new challenges related to personal data processing, privacy, and ethical standards. The integration of the EU AI Act’s provisions into the existing data protection framework means that businesses now need to navigate both the stringent requirements of the GDPR and the emerging obligations under the EU AI Act. Organizations in Bulgaria will need to enhance their compliance mechanisms and adapt their practices to align with new legal standards. This dynamic regulatory environment underlines the necessity for businesses to remain vigilant and adaptable to effectively navigate the interplay between data protection legislation, on one side, and the rules governing artificial intelligence, on another.

Disclaimer: This guide contains summaries of general principles of law. It is not a substitute for specific legal advice and should not be relied upon in relation to the application of the law or subject matter covered.