🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
BG · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 14 sources retrieved model claude-sonnet-5 ·

Bulgaria

BG schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 26 claims · 14 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
26Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Fully GDPR-aligned omnibus regime with an operational, actively enforcing DPA and a national implementing act; no material regulatory gaps identified.

Primary frameworkRegulation (EU) 2016/679 (GDPR) as complemented by the Protection of Personal Data Act 2002 (last amended 2023)
Traffic-light rationale — GreenFully GDPR-aligned omnibus regime with an operational, actively enforcing DPA and a national implementing act; no material regulatory gaps identified.

Sub-modules (5)

Regulator And AuthorityGreen

CPDP is Bulgaria's independent supervisory authority, empowered to investigate, inspect and issue final decisions on GDPR compliance, including acting as lead or concerned supervisory authority in one-stop-shop cross-border cases.

Claims: CLM-BG-1a2b3c4d

Act And InstrumentsGreen

GDPR applies directly; the Protection of Personal Data Act 2002 (last amended 2023) is the operative national complementing statute.

Claims: CLM-BG-2b3c4d5e

Material ScopeGreen

National derogation exists for scientific/historical research and statistics under Article 25m of the Act, implementing GDPR Article 89(1) safeguards.

Claims: CLM-BG-3c4d5e6f

Territorial ScopeGreen

GDPR Article 3(2) targeting-criterion applies directly in Bulgaria to non-established controllers/processors offering goods/services to, or monitoring, data subjects in Bulgaria/the Union; no distinct national territorial-scope variant was identified.

Claims: CLM-BG-4d5e6f70

Regulator Registration And FilingGreen

Bulgaria abolished pre-GDPR general processing registration but retains a targeted notification duty: controllers/processors must notify CPDP of DPO identity/contact details under Article 25b of the Act.

Claims: CLM-BG-5e6f7081

Category narrative52 words

Bulgaria is an EU Member State applying the GDPR directly since 25 May 2018, supplemented by the national Protection of Personal Data Act 2002 (last amended 2023), which layers DPO-notification, ROPA, and breach-notification procedural rules onto the GDPR baseline. The Commission for Personal Data Protection (CPDP) is the designated independent supervisory authority.

Sources and claims (5)
  1. ConfirmedCommission for Personal Data ProtectionThe Commission for Personal Data Protection (CPDP) is Bulgaria's independent supervisory authority for data protection, empowered to investigate breaches, conduct document inspections, and issue final enforcement decisions, including as lead or concerned supervisory authority in EU one-stop-shop cooperation.
  2. ConfirmedDataGuidanceGDPR (Regulation (EU) 2016/679) applies directly in Bulgaria and is complemented by the Protection of Personal Data Act 2002, last amended in 2023, which supplies national procedural rules (DPO notification, ROPA content, breach-notification detail).
  3. ProbableEDPBArticle 25m of the Bulgarian Act requires controllers to apply pseudonymisation and appropriate technical/organisational measures safeguarding data-subject rights when processing personal data for scientific/historical research or statistical purposes under GDPR Article 89(1).
  4. ConfirmedEDPBGDPR Article 3(2) extends applicability, directly effective in Bulgaria, to controllers/processors not established in the EU where processing relates to offering goods/services to, or monitoring the behaviour of, data subjects located in Bulgaria/the Union.
  5. ConfirmedDataGuidanceArticle 25b of the Bulgarian Act requires controllers and processors to notify CPDP of the identity and contact details of their appointed DPO, and any subsequent changes, per a procedure fixed in CPDP's Rules of Procedure under Article 9(2) of the Act.

#

Core lawful-basis and special-category rules are GDPR-aligned and evidenced by national case law/guidance; consent-threshold sub-module carries a research gap.

Primary frameworkGDPR Articles 6, 7, 9 as applied via the Protection of Personal Data Act 2002 (amended)
Traffic-light rationale — GreenCore lawful-basis and special-category rules are GDPR-aligned and evidenced by national case law/guidance; consent-threshold sub-module carries a research gap.

Sub-modules (4)

Lawful BasesGreen

A Bulgarian court (Administrativen sad – Blagoevgrad) referred questions to the CJEU on Article 6(1)(c)/(e) GDPR basis for prosecutorial processing of victim data, evidencing national application of the lawful-basis framework in law-enforcement-adjacent contexts.

Claims: CLM-BG-6f708192

Special CategoriesGreen

GDPR Article 9 special-category protections apply directly; CPDP has issued sector guidance addressing biometric (facial-recognition) processing by retailers, applying the special-category framework to a novel processing context.

Claims: CLM-BG-708192a3

Pseudonymisation And AnonymisationGreen

Article 25m of the Act operationalises pseudonymisation obligations for research/statistical processing under GDPR Article 89(1).

Claims: CLM-BG-8192a3b4

Category narrative48 words

Bulgaria applies the GDPR Article 6 lawful-basis framework and Article 9 special-category regime directly, illustrated nationally by a Bulgarian-court CJEU referral on prosecutorial data processing and CPDP guidance on biometric data in retail. Consent-threshold specifics beyond the GDPR Article 7 standard were not confirmed in this research pass.

Sources and claims (3)
  1. ConfirmedEUR-LexIn Case C-180/21, a Bulgarian court referred questions on the legal basis under Article 6(1)(c) and (e) GDPR for processing victim personal data by the Public Prosecutor's Office in connection with subsequent prosecution and defence of related civil claims, illustrating Bulgaria's national application of the GDPR lawful-basis framework alongside Directive (EU) 2016/680.
  2. ProbableDataGuidanceThe CPDP issued an opinion addressing the use of facial-recognition/biometric data-processing technology by stores, applying GDPR Article 9 special-category safeguards to retail biometric identification systems in Bulgaria.
  3. ProbableEDPBArticle 25m of the Bulgarian Act requires pseudonymisation and appropriate technical/organisational measures for personal data processed for scientific/historical research or statistical purposes, implementing GDPR Article 89(1).

#

Rights framework is GDPR-standard with confirmed national procedural detail on access and retention; remaining sub-modules present as GDPR-baseline-only gaps.

Primary frameworkGDPR Chapter III (Articles 12-23) as applied via the Protection of Personal Data Act
Traffic-light rationale — GreenRights framework is GDPR-standard with confirmed national procedural detail on access and retention; remaining sub-modules present as GDPR-baseline-only gaps.

Sub-modules (5)

Access RightGreen

Data subjects may exercise the Article 15 access right directly with controllers or via CPDP; CPDP has produced public-facing educational materials to raise awareness of this right.

Claims: CLM-BG-92a3b4c5

Rectification And ErasureAmber

No Bulgaria-specific derogation to GDPR Articles 16-17 (rectification/erasure) was identified in this research pass; GDPR baseline presumed to apply unmodified.

Restriction And ObjectionAmber

No Bulgaria-specific derogation to GDPR Articles 18 and 21 was identified; GDPR baseline presumed to apply unmodified.

Data PortabilityAmber

No Bulgaria-specific derogation to GDPR Article 20 was identified; GDPR baseline presumed to apply unmodified.

Deadlines And Response WindowsGreen

Article 25k of the Act sets a six-month storage period tied to identity-verification documentation gathered in the course of data-subject rights requests, alongside the standard GDPR one-month (extendable to three-month) response window.

Claims: CLM-BG-a3b4c5d6

Category narrative62 words

Data subjects exercise GDPR Chapter III rights directly; CPDP supplements this with public-facing right-of-access awareness materials, and Article 25k of the Act sets a national retention rule (six months) tied to identity-verification documentation gathered when processing rights requests. Rectification, erasure, restriction, objection and portability rights rely on the unmodified GDPR baseline; no Bulgaria-specific derogation was found for those sub-modules in this pass.

Sources and claims (2)
  1. ConfirmedEDPBData subjects in Bulgaria may lodge GDPR Article 15 access requests with controllers, and CPDP has developed public educational and awareness materials, including guidance for parents and children, to support exercise of the right of access.
  2. ProbableEDPBArticle 25k of the Bulgarian Personal Data Protection Act establishes a six-month storage period for identity-verification documentation collected in connection with data-subject rights requests.

#

Well-evidenced via a published CPDP final decision and DataGuidance analysis of the Act's specific articles; joint-controller and retention/disposal sub-modules rely on unmodified GDPR baseline.

Primary frameworkGDPR Articles 5, 24-43 as detailed in the Protection of Personal Data Act (Articles 25b, 62(2), 66, 67(3))
Traffic-light rationale — GreenWell-evidenced via a published CPDP final decision and DataGuidance analysis of the Act's specific articles; joint-controller and retention/disposal sub-modules rely on unmodified GDPR baseline.

Sub-modules (7)

Accountability And DpiaAmber

CPDP's LockTrip decision found the controller failed to demonstrate Article 5(1) GDPR compliance, violating the Article 5(2) accountability principle in conjunction with Article 33(5), and that no DPIA had been performed before the breach.

Claims: CLM-BG-b4c5d6e7

Dpo RequirementsGreen

Article 25b of the Act mandates notification of DPO identity/contact details to CPDP.

Claims: CLM-BG-c5d6e7f8

Ropa RequirementsGreen

Article 62(2) of the Act prescribes specific processor ROPA content beyond the bare GDPR Article 30 minimum.

Claims: CLM-BG-d6e7f809

Joint Controller ArrangementsAmber

No Bulgaria-specific derogation to GDPR Article 26 joint-controller arrangements was identified in this research pass; GDPR baseline presumed to apply unmodified.

Security MeasuresAmber

CPDP's LockTrip decision documents a real-world security-measures failure (compromised device via public Wi-Fi) assessed by CPDP's own Risk Assessment Methodology (adopted 24 June 2021) at 'medium risk' to data subjects.

Claims: CLM-BG-f8091a2b

Breach NotificationGreen

Article 67(3) of the Act specifies mandatory breach-notification content, and CPDP applies a bespoke Methodology for Risk Assessment upon a Personal Data Breach.

Claims: CLM-BG-e7f8091a

Retention And DisposalAmber

No standalone Bulgaria-specific general retention/disposal regime beyond GDPR Article 5(1)(e) storage limitation and Article 25k's specific six-month rule (see data_subject_rights) was identified.

Category narrative46 words

Bulgaria's controller/processor duties are anchored in GDPR Articles 5, 24-43 and detailed nationally in the Act's DPO-notification (Art. 25b), processor-ROPA (Art. 62(2)), and breach-notification-content (Art. 67(3)) provisions. The CPDP's 2023 LockTrip Ltd. final decision is the clearest evidenced enforcement precedent on accountability, DPIA, and breach-notification duties.

Sources and claims (5)
  1. ConfirmedEDPB / CPDPIn its 2023 final decision on the LockTrip Ltd. breach, CPDP found the controller failed to demonstrate compliance with GDPR Article 5(1), violating the Article 5(2) accountability principle in conjunction with Article 33(5), and noted no DPIA had been carried out prior to the breach despite one being prepared afterward addressing client-data risks.
  2. ConfirmedDataGuidanceArticle 25b of the Bulgarian Act requires controllers/processors to notify CPDP of DPO identity and contact details and any ensuing changes, per a procedure set out in CPDP's Rules of Procedure under Article 9(2) of the Act.
  3. ConfirmedDataGuidanceArticle 62(2) of the Act requires a data processor to maintain a record of processing activities containing processor/controller contact details, DPO details where applicable, processing categories, any third-country transfers, and a description of Article 66 security measures.
  4. ConfirmedDataGuidanceArticle 67(3) of the Bulgarian Act specifies mandatory breach-notification content (breach description, categories/approximate numbers of affected subjects and records, DPO contact, likely consequences, mitigation measures), and CPDP registers and risk-assesses notifications using its Methodology for Risk Assessment upon a Personal Data Breach adopted 24 June 2021.
  5. ConfirmedEDPB / CPDPCPDP's LockTrip decision found that unauthorised access via a compromised employee device connected to public Wi-Fi, leaking partner-platform passwords affecting 2,108 EU citizens (including 420 Bulgarian) and 2,423 third-country nationals, constituted a personal-data breach assessed at 'medium risk' to data subjects' rights and freedoms.

#

Core transfer mechanisms are GDPR-standard, but TIA-specific and SCC/BCR-uptake detail for Bulgaria was not separately confirmed in this pass; adequacy sub-modules are not applicable at Member-State level.

Primary frameworkGDPR Chapter V (Articles 44-49)
Traffic-light rationale — AmberCore transfer mechanisms are GDPR-standard, but TIA-specific and SCC/BCR-uptake detail for Bulgaria was not separately confirmed in this pass; adequacy sub-modules are not applicable at Member-State level.

Sub-modules (6)

Transfer MechanismsAmber

GDPR Chapter V transfer mechanisms (adequacy, SCCs, BCRs, Article 49 derogations) apply directly; CPDP is the competent authority for Bulgarian-established controllers' BCR approvals and ad hoc contractual clauses.

Claims: CLM-BG-091a2b3c

Adequacy ReceivedGreen

Not applicable at individual Member-State level: the European Commission, not Bulgaria, issues/receives adequacy determinations on behalf of all EU Member States under GDPR Article 45.

Adequacy GrantedGreen

Not applicable at individual Member-State level for the same structural reason as adequacy_received.

Sccs And BcrsAmber

The EU Commission's 2021 SCC modules apply directly in Bulgaria; no Bulgaria-specific SCC variant or BCR-uptake statistics were identified in this research pass.

Transfer Impact AssessmentAmber

The post-Schrems II TIA requirement applies GDPR-wide; no Bulgaria-specific TIA guidance from CPDP was identified in this research pass.

Data LocalisationGreen

Bulgaria operates the National Schengen Information System (N.SIS) under a national ordinance in conjunction with EU SIS Regulations and the Ministry of Interior Act, reflecting a sector-specific law-enforcement/immigration data-residency arrangement rather than a general commercial data-localisation mandate.

Claims: CLM-BG-1a2b3c4e

Category narrative60 words

As an EU Member State, Bulgaria applies the GDPR Chapter V transfer regime directly (adequacy decisions, SCCs, BCRs, derogations); adequacy decisions are issued/received at EU-Commission level rather than by Bulgaria individually, so the adequacy_received/adequacy_granted sub-modules are structurally not applicable to a single Member State. A sector-specific data-residency arrangement exists for Schengen/immigration-alert data (N.SIS) processed under national ordinance alongside EU Regulations.

Sources and claims (2)
  1. ProbableCommission for Personal Data ProtectionAs an EU Member State, Bulgaria applies the GDPR Chapter V transfer regime directly, with CPDP acting as the competent national authority for approving BCRs and contractual clauses for Bulgarian-established controllers.
  2. ProbableEDPBBulgaria operates a National Schengen Information System (N.SIS) under Ordinance No. 8121з-465 of 26 August 2014, processing data in compliance with EU Regulations 2018/1860-1862, the Ministry of Interior Act, and the Personal Data Protection Act, constituting a sector-specific data-residency arrangement for law-enforcement/immigration alert data.

#

Partial coverage: employment and telecoms overlays confirmed; five of seven sub-modules carry an explicit research gap.

Primary frameworkGDPR plus sector-specific national instruments (Labor Code 1986, Electronic Communications Act)
Traffic-light rationale — AmberPartial coverage: employment and telecoms overlays confirmed; five of seven sub-modules carry an explicit research gap.

Sub-modules (7)

Financial Sector OverlayRed

No Bulgaria-specific financial-sector data-protection overlay (e.g., banking-secrecy interplay with GDPR) was identified. Searches run: "Bulgaria financial sector data protection overlay", general CPDP/DataGuidance overview queries.

Health Sector OverlayRed

No Bulgaria-specific health-sector data-protection overlay was identified in this research pass.

Telecoms And EprivacyAmber

The Electronic Communications Act (ECA) is identified as the national instrument intersecting with GDPR/ePrivacy for communications-related personal data.

Claims: CLM-BG-3c4d5e70

Employment DataGreen

Employee monitoring in Bulgaria is governed by a multi-instrument overlay: GDPR, the Act, the Labor Code 1986, the ECA, and the Constitution.

Claims: CLM-BG-2b3c4d5f

Credit And ScoringRed

No Bulgaria-specific credit-scoring data-protection overlay was identified in this research pass.

EducationRed

No Bulgaria-specific education-sector data-protection overlay was identified in this research pass.

InsuranceRed

No Bulgaria-specific insurance-sector data-protection overlay was identified in this research pass.

Category narrative42 words

Confirmed sectoral overlay evidence is limited to the employment-data and telecoms/eprivacy domains, where the Labor Code, Electronic Communications Act, and Constitution intersect with GDPR/the Act. No Bulgaria-specific financial-sector, health-sector, credit-scoring, education, or insurance data-protection overlay instruments were identified in this research pass.

Sources and claims (2)
  1. ConfirmedDataGuidanceBulgarian employee-monitoring rules draw on GDPR, the Protection of Personal Data Act 2002 (last amended 2023), the Labor Code 1986, the Electronic Communications Act, and the Constitution of the Republic of Bulgaria, creating a multi-instrument overlay governing employer processing of employee personal data.
  2. ProbableDataGuidanceThe Electronic Communications Act is identified as relevant national legislation intersecting with GDPR for communications-related personal data processing, operating alongside the EU ePrivacy framework in Bulgaria.

#

Only the cookies/trackers sub-module has confirmed national-instrument grounding; the remaining five sub-modules carry an explicit research gap.

Primary frameworkGDPR plus Electronic Communications Act (ePrivacy implementation)
Traffic-light rationale — AmberOnly the cookies/trackers sub-module has confirmed national-instrument grounding; the remaining five sub-modules carry an explicit research gap.

Sub-modules (6)

Cookies And TrackersAmber

Cookie/tracking consent is governed by the ECA (ePrivacy implementation) alongside GDPR; no additional Bulgaria-specific cookie legislation was identified.

Claims: CLM-BG-4d5e6f81

Dark PatternsRed

No Bulgaria-specific dark-pattern prohibition beyond general EDPB guidance (applicable EU-wide) was identified in this research pass. Searches run: general CPDP/DataGuidance overview queries.

Opt Out SignalsRed

No Bulgaria-specific recognition of technical opt-out signals (e.g., Global Privacy Control) was identified.

Clean Rooms And DcrRed

No Bulgaria-specific clean-room/data-collaboration-room rules were identified.

Cross Context AdvertisingRed

No Bulgaria-specific cross-context advertising ('sale'/'share') concept analogous to US state law was identified; GDPR consent/legitimate-interest framework applies as the general floor.

Direct MarketingRed

No Bulgaria-specific direct-marketing consent/suppression rule beyond GDPR Article 21(2)/ECA implementation of ePrivacy Article 13 was identified in this research pass.

Category narrative44 words

Cookie/tracker consent in Bulgaria relies on the Electronic Communications Act implementing the EU ePrivacy Directive alongside GDPR consent standards. No Bulgaria-specific rules on dark patterns, opt-out signals, clean rooms, cross-context advertising, or direct-marketing suppression beyond the GDPR/ePrivacy baseline were identified in this research pass.

Sources and claims (1)
  1. UncertainDataGuidanceCookie and electronic-communications tracking consent in Bulgaria is governed by the Electronic Communications Act implementing the ePrivacy Directive, operating alongside GDPR consent standards; no additional Bulgaria-specific cookie legislation was identified in this research pass.

#

Biometric and state-surveillance-carveout sub-modules are evidenced; profiling/ADM/AI-risk/genetic-data sub-modules default to GDPR baseline without confirmed national specificity, and EU AI Act national-authority designation status for Bulgaria remains unresolved.

Primary frameworkGDPR Article 9 and Article 22, plus Ministry of Interior Act (Directive (EU) 2016/680 transposition) for law-enforcement carve-outs
Traffic-light rationale — AmberBiometric and state-surveillance-carveout sub-modules are evidenced; profiling/ADM/AI-risk/genetic-data sub-modules default to GDPR baseline without confirmed national specificity, and EU AI Act national-authority designation status for Bulgaria remains unresolved.

Sub-modules (6)

Profiling RestrictionsAmber

No Bulgaria-specific derogation to GDPR Article 22 profiling restrictions was identified; GDPR baseline presumed to apply unmodified.

Automated Decision Making TransparencyAmber

No Bulgaria-specific ADM transparency rule beyond GDPR Articles 13(2)(f)/14(2)(g)/15(1)(h) was identified.

Ai Risk AssessmentsRed

Bulgaria's national competent authority designation and implementation status under the EU AI Act was not confirmed in this research pass; flagged as an unresolved question.

Biometric RegimeGreen

CPDP has issued an opinion specifically addressing facial-recognition/biometric processing by retailers, applying Article 9 special-category safeguards.

Claims: CLM-BG-5e6f7092

Genetic DataAmber

No Bulgaria-specific genetic-data regime beyond the GDPR Article 9 special-category baseline was identified.

State Surveillance CarveoutsAmber

Law-enforcement/immigration data processing (e.g., N.SIS alerts) is carried out under the Ministry of Interior Act rather than GDPR directly, reflecting Bulgaria's transposition of Directive (EU) 2016/680, as illustrated in the CJEU C-180/21 referral on the GDPR/LED interplay in prosecutorial processing.

Claims: CLM-BG-6f7081a3

Category narrative67 words

Biometric processing (facial recognition) has been addressed directly by CPDP guidance applying GDPR Article 9 to retail use cases. Law-enforcement/immigration processing (e.g., N.SIS) is carved out under the Ministry of Interior Act transposing Directive (EU) 2016/680, illustrated by a Bulgarian-court CJEU referral on the GDPR/LED interplay. Profiling restrictions, ADM transparency, AI-specific risk assessments, and genetic-data regime rely on the unmodified GDPR baseline with no Bulgaria-specific layer identified.

Sources and claims (2)
  1. ProbableDataGuidanceCPDP issued an opinion addressing the use of facial-recognition and biometric data-processing technology by stores/retailers, applying GDPR Article 9 special-category safeguards to biometric identification systems in Bulgaria.
  2. ProbableEDPBLaw-enforcement and immigration data processing in Bulgaria (e.g., National Schengen Information System alerts) is carried out under the Ministry of Interior Act and related ordinances rather than GDPR directly, reflecting transposition of the Law Enforcement Directive (EU) 2016/680, as illustrated by the Bulgarian court's CJEU referral in Case C-180/21 concerning the GDPR/LED interplay in prosecutorial data processing.

#

Only a non-binding awareness-activity claim is evidenced; the core binding parental-consent age threshold and other sub-modules carry an explicit, unresolved research gap.

Primary frameworkGDPR Article 8 (children's consent) as applied via the Protection of Personal Data Act
Traffic-light rationale — RedOnly a non-binding awareness-activity claim is evidenced; the core binding parental-consent age threshold and other sub-modules carry an explicit, unresolved research gap.

Sub-modules (5)

Age VerificationRed

The Bulgarian age-of-consent threshold under GDPR Article 8 (default 16, or a national lowering to as low as 13) was not confirmed in this research pass. Searches run: general CPDP/DataGuidance overview queries; a targeted search for the specific statutory age was not conclusive.

Minor Profiling BansRed

No Bulgaria-specific minor-profiling ban beyond the GDPR baseline (recital 38 caution on profiling of children) was identified.

Education SettingsRed

No Bulgaria-specific education-settings data-protection rule was identified in this research pass.

Dependent AdultsRed

No Bulgaria-specific dependent-adults (elderly/incapacitated) data-protection provision was identified in this research pass.

Category narrative46 words

CPDP conducts child-oriented digital-safety and right-of-access awareness activities, including materials for parents. The specific national age-of-consent threshold under GDPR Article 8 (whether Bulgaria retains the default age 16 or has lowered it) was not confirmed in this research pass, nor were minor-profiling-ban, education-setting-specific, or dependent-adult-specific rules.

Sources and claims (1)
  1. ConfirmedEDPBCPDP has developed child-oriented educational materials, including publications, guidelines, leaflets and videos, and produced advice materials for parents on children's personal data and internet use, as part of its digital-safety and right-of-access awareness activities.

#

Regulator powers and recent enforcement/jurisprudential activity are well evidenced; collective-redress, private-right-of-action, and regulator-funding sub-modules carry research gaps.

Primary frameworkGDPR Articles 58, 77-84 as applied by the Commission for Personal Data Protection
Traffic-light rationale — GreenRegulator powers and recent enforcement/jurisprudential activity are well evidenced; collective-redress, private-right-of-action, and regulator-funding sub-modules carry research gaps.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

CPDP can impose administrative fines up to GDPR Article 83 maxima and previously fined the National Revenue Agency BGN 5.1 million for GDPR violations.

Claims: CLM-BG-8192a3d5

Enforcement Activity IndexGreen

The 2022-2023 LockTrip Ltd. case shows CPDP conducting a formal document-inspection and Article 60 cross-border cooperation procedure with Finland, Spain, and Poland as concerned/commenting supervisory authorities.

Claims: CLM-BG-92a3b4e6

Regulator Funding And CapacityRed

No specific CPDP budget/headcount data was identified in this research pass.

Collective Redress And Class ActionsRed

No Bulgaria-specific collective-redress mechanism for data-protection claims (beyond general GDPR Article 80 representative-action provisions) was confirmed in this research pass.

Private Right Of ActionAmber

GDPR Articles 79/82 judicial-remedy and compensation rights apply directly; no Bulgaria-specific procedural variant was confirmed in this research pass.

Recent Developments 180DGreen

CJEU judgment of 9 July 2026 in Case C-199/24 interprets the GDPR Article 85(2) journalistic-purposes exemption strictly; the Bulgarian Government was among the governments submitting observations.

Claims: CLM-BG-a3b4c5f7

Category narrative79 words

CPDP exercises GDPR Article 58 corrective powers up to the Article 83 maximum fines and has a track record of significant enforcement, including a BGN 5.1 million fine against Bulgaria's National Revenue Agency (2019) and an active, EU-cooperative investigation/decision in the LockTrip Ltd. breach case (2022-2023). Recent 180-day-window development: CJEU judgment (9 July 2026) in Case C-199/24 on the GDPR Article 85 journalistic-purposes exemption, with the Bulgarian Government among the intervening governments, bearing on national application of that derogation.

Sources and claims (3)
  1. ConfirmedIAPPCPDP exercises GDPR Article 58 corrective powers, including document-inspection procedures, and can impose administrative fines up to GDPR Article 83 maxima; it previously fined Bulgaria's National Revenue Agency BGN 5.1 million for GDPR violations following a major data leak.
  2. ConfirmedEDPB / CPDPIn 2022-2023, CPDP conducted a formal document-inspection and Article 60 cooperation procedure regarding a breach notification from LockTrip Ltd., coordinating via the EU Internal Market Information System with Finland and Spain as concerned supervisory authorities and Poland commenting on the draft decision.
  3. ConfirmedEUR-LexOn 9 July 2026, the CJEU delivered judgment in Case C-199/24 interpreting the GDPR Article 85(2) 'journalistic purposes' exemption strictly, with the Bulgarian Government among the governments submitting observations, marking an active EU-level jurisprudential development relevant to national application of journalistic-purpose derogations from GDPR obligations.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Bulgaria
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 26 claim(s), 15 source(s) in the cumulative register.