{
 "jurisdiction_id": "BG",
 "jurisdiction": "Bulgaria",
 "url": "https://dataprotection.gi/jurisdictions/bulgaria/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 26,
  "sub_modules": 57,
  "source_register": 15
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bulgaria/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Fully GDPR-aligned omnibus regime with an operational, actively enforcing DPA and a national implementing act; no material regulatory gaps identified.",
   "claims": [
    {
     "statement": "The Commission for Personal Data Protection (CPDP) is Bulgaria's independent supervisory authority for data protection, empowered to investigate breaches, conduct document inspections, and issue final enforcement decisions, including as lead or concerned supervisory authority in EU one-stop-shop cooperation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Commission for Personal Data Protection",
     "source_url": "https://www.cpdp.bg/en/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR (Regulation (EU) 2016/679) applies directly in Bulgaria and is complemented by the Protection of Personal Data Act 2002, last amended in 2023, which supplies national procedural rules (DPO notification, ROPA content, breach-notification detail).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/bulgaria-employee-monitoring",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 25m of the Bulgarian Act requires controllers to apply pseudonymisation and appropriate technical/organisational measures safeguarding data-subject rights when processing personal data for scientific/historical research or statistical purposes under GDPR Article 89(1).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/documents/2022-01/legalstudy_on_the_appropriate_safeguards_89.1.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Article 3(2) extends applicability, directly effective in Bulgaria, to controllers/processors not established in the EU where processing relates to offering goods/services to, or monitoring the behaviour of, data subjects located in Bulgaria/the Union.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_3_2018_territorial_scope_after_public_consultation_en_1.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 25b of the Bulgarian Act requires controllers and processors to notify CPDP of the identity and contact details of their appointed DPO, and any subsequent changes, per a procedure fixed in CPDP's Rules of Procedure under Article 9(2) of the Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/bulgaria-overview-vendor-privacy-contracts",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bulgaria/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core lawful-basis and special-category rules are GDPR-aligned and evidenced by national case law/guidance; consent-threshold sub-module carries a research gap.",
   "claims": [
    {
     "statement": "In Case C-180/21, a Bulgarian court referred questions on the legal basis under Article 6(1)(c) and (e) GDPR for processing victim personal data by the Public Prosecutor's Office in connection with subsequent prosecution and defence of related civil claims, illustrating Bulgaria's national application of the GDPR lawful-basis framework alongside Directive (EU) 2016/680.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A62021CC0180",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CPDP issued an opinion addressing the use of facial-recognition/biometric data-processing technology by stores, applying GDPR Article 9 special-category safeguards to retail biometric identification systems in Bulgaria.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/bulgaria-cpdp-issues-opinion-facial-recognition-stores",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 25m of the Bulgarian Act requires pseudonymisation and appropriate technical/organisational measures for personal data processed for scientific/historical research or statistical purposes, implementing GDPR Article 89(1).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/documents/2022-01/legalstudy_on_the_appropriate_safeguards_89.1.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bulgaria/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights framework is GDPR-standard with confirmed national procedural detail on access and retention; remaining sub-modules present as GDPR-baseline-only gaps.",
   "claims": [
    {
     "statement": "Data subjects in Bulgaria may lodge GDPR Article 15 access requests with controllers, and CPDP has developed public educational and awareness materials, including guidance for parents and children, to support exercise of the right of access.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2025-01/edpb_cef-report-2024_20250116_annex_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 25k of the Bulgarian Personal Data Protection Act establishes a six-month storage period for identity-verification documentation collected in connection with data-subject rights requests.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2025-01/edpb_cef-report-2024_20250116_annex_en.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bulgaria/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Well-evidenced via a published CPDP final decision and DataGuidance analysis of the Act's specific articles; joint-controller and retention/disposal sub-modules rely on unmodified GDPR baseline.",
   "claims": [
    {
     "statement": "In its 2023 final decision on the LockTrip Ltd. breach, CPDP found the controller failed to demonstrate compliance with GDPR Article 5(1), violating the Article 5(2) accountability principle in conjunction with Article 33(5), and noted no DPIA had been carried out prior to the breach despite one being prepared afterward addressing client-data risks.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / CPDP",
     "source_url": "https://www.edpb.europa.eu/system/files/2023-08/bg_2023-01_decisionpublic.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 25b of the Bulgarian Act requires controllers/processors to notify CPDP of DPO identity and contact details and any ensuing changes, per a procedure set out in CPDP's Rules of Procedure under Article 9(2) of the Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/bulgaria-overview-vendor-privacy-contracts",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 62(2) of the Act requires a data processor to maintain a record of processing activities containing processor/controller contact details, DPO details where applicable, processing categories, any third-country transfers, and a description of Article 66 security measures.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/bulgaria-overview-vendor-privacy-contracts",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 67(3) of the Bulgarian Act specifies mandatory breach-notification content (breach description, categories/approximate numbers of affected subjects and records, DPO contact, likely consequences, mitigation measures), and CPDP registers and risk-assesses notifications using its Methodology for Risk Assessment upon a Personal Data Breach adopted 24 June 2021.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/bulgaria-overview-vendor-privacy-contracts",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "CPDP's LockTrip decision found that unauthorised access via a compromised employee device connected to public Wi-Fi, leaking partner-platform passwords affecting 2,108 EU citizens (including 420 Bulgarian) and 2,423 third-country nationals, constituted a personal-data breach assessed at 'medium risk' to data subjects' rights and freedoms.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / CPDP",
     "source_url": "https://www.edpb.europa.eu/system/files/2023-08/bg_2023-01_decisionpublic.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bulgaria/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Core transfer mechanisms are GDPR-standard, but TIA-specific and SCC/BCR-uptake detail for Bulgaria was not separately confirmed in this pass; adequacy sub-modules are not applicable at Member-State level.",
   "claims": [
    {
     "statement": "As an EU Member State, Bulgaria applies the GDPR Chapter V transfer regime directly, with CPDP acting as the competent national authority for approving BCRs and contractual clauses for Bulgarian-established controllers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Commission for Personal Data Protection",
     "source_url": "https://www.cpdp.bg/en/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Bulgaria operates a National Schengen Information System (N.SIS) under Ordinance No. 8121з-465 of 26 August 2014, processing data in compliance with EU Regulations 2018/1860-1862, the Ministry of Interior Act, and the Personal Data Protection Act, constituting a sector-specific data-residency arrangement for law-enforcement/immigration alert data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files_en?file=2026-04%2Fcsc_guide_right_of_access_rectification_and_erasure_20230403_en.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bulgaria/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Partial coverage: employment and telecoms overlays confirmed; five of seven sub-modules carry an explicit research gap.",
   "claims": [
    {
     "statement": "Bulgarian employee-monitoring rules draw on GDPR, the Protection of Personal Data Act 2002 (last amended 2023), the Labor Code 1986, the Electronic Communications Act, and the Constitution of the Republic of Bulgaria, creating a multi-instrument overlay governing employer processing of employee personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/bulgaria-employee-monitoring",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Electronic Communications Act is identified as relevant national legislation intersecting with GDPR for communications-related personal data processing, operating alongside the EU ePrivacy framework in Bulgaria.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/bulgaria-employee-monitoring",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bulgaria/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Only the cookies/trackers sub-module has confirmed national-instrument grounding; the remaining five sub-modules carry an explicit research gap.",
   "claims": [
    {
     "statement": "Cookie and electronic-communications tracking consent in Bulgaria is governed by the Electronic Communications Act implementing the ePrivacy Directive, operating alongside GDPR consent standards; no additional Bulgaria-specific cookie legislation was identified in this research pass.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/bulgaria-employee-monitoring",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bulgaria/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Biometric and state-surveillance-carveout sub-modules are evidenced; profiling/ADM/AI-risk/genetic-data sub-modules default to GDPR baseline without confirmed national specificity, and EU AI Act national-authority designation status for Bulgaria remains unresolved.",
   "claims": [
    {
     "statement": "CPDP issued an opinion addressing the use of facial-recognition and biometric data-processing technology by stores/retailers, applying GDPR Article 9 special-category safeguards to biometric identification systems in Bulgaria.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/bulgaria-cpdp-issues-opinion-facial-recognition-stores",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law-enforcement and immigration data processing in Bulgaria (e.g., National Schengen Information System alerts) is carried out under the Ministry of Interior Act and related ordinances rather than GDPR directly, reflecting transposition of the Law Enforcement Directive (EU) 2016/680, as illustrated by the Bulgarian court's CJEU referral in Case C-180/21 concerning the GDPR/LED interplay in prosecutorial data processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files_en?file=2026-04%2Fcsc_guide_right_of_access_rectification_and_erasure_20230403_en.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "red",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bulgaria/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Only a non-binding awareness-activity claim is evidenced; the core binding parental-consent age threshold and other sub-modules carry an explicit, unresolved research gap.",
   "claims": [
    {
     "statement": "CPDP has developed child-oriented educational materials, including publications, guidelines, leaflets and videos, and produced advice materials for parents on children's personal data and internet use, as part of its digital-safety and right-of-access awareness activities.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2025-01/edpb_cef-report-2024_20250116_annex_en.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/bulgaria/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Regulator powers and recent enforcement/jurisprudential activity are well evidenced; collective-redress, private-right-of-action, and regulator-funding sub-modules carry research gaps.",
   "claims": [
    {
     "statement": "CPDP exercises GDPR Article 58 corrective powers, including document-inspection procedures, and can impose administrative fines up to GDPR Article 83 maxima; it previously fined Bulgaria's National Revenue Agency BGN 5.1 million for GDPR violations following a major data leak.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/bulgarian-dpa-issued-bgn-5-1m-fine-to-national-revenue-agency-for-gdpr-violations/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In 2022-2023, CPDP conducted a formal document-inspection and Article 60 cooperation procedure regarding a breach notification from LockTrip Ltd., coordinating via the EU Internal Market Information System with Finland and Spain as concerned supervisory authorities and Poland commenting on the draft decision.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / CPDP",
     "source_url": "https://www.edpb.europa.eu/system/files/2023-08/bg_2023-01_decisionpublic.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 9 July 2026, the CJEU delivered judgment in Case C-199/24 interpreting the GDPR Article 85(2) 'journalistic purposes' exemption strictly, with the Bulgarian Government among the governments submitting observations, marking an active EU-level jurisprudential development relevant to national application of journalistic-purpose derogations from GDPR obligations.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62024CJ0199",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}