Traffic-light rationale — GreenFully GDPR-aligned omnibus regime with an operational, actively enforcing DPA and a national implementing act; no material regulatory gaps identified.
Sub-modules (5)
Regulator And AuthorityGreen
CPDP is Bulgaria's independent supervisory authority, empowered to investigate, inspect and issue final decisions on GDPR compliance, including acting as lead or concerned supervisory authority in one-stop-shop cross-border cases.
Claims: CLM-BG-1a2b3c4d
Act And InstrumentsGreen
GDPR applies directly; the Protection of Personal Data Act 2002 (last amended 2023) is the operative national complementing statute.
Claims: CLM-BG-2b3c4d5e
Material ScopeGreen
National derogation exists for scientific/historical research and statistics under Article 25m of the Act, implementing GDPR Article 89(1) safeguards.
Claims: CLM-BG-3c4d5e6f
Territorial ScopeGreen
GDPR Article 3(2) targeting-criterion applies directly in Bulgaria to non-established controllers/processors offering goods/services to, or monitoring, data subjects in Bulgaria/the Union; no distinct national territorial-scope variant was identified.
Claims: CLM-BG-4d5e6f70
Regulator Registration And FilingGreen
Bulgaria abolished pre-GDPR general processing registration but retains a targeted notification duty: controllers/processors must notify CPDP of DPO identity/contact details under Article 25b of the Act.
Claims: CLM-BG-5e6f7081
Category narrative52 words
Bulgaria is an EU Member State applying the GDPR directly since 25 May 2018, supplemented by the national Protection of Personal Data Act 2002 (last amended 2023), which layers DPO-notification, ROPA, and breach-notification procedural rules onto the GDPR baseline. The Commission for Personal Data Protection (CPDP) is the designated independent supervisory authority.
Sources and claims (5)
ConfirmedCommission for Personal Data Protection — The Commission for Personal Data Protection (CPDP) is Bulgaria's independent supervisory authority for data protection, empowered to investigate breaches, conduct document inspections, and issue final enforcement decisions, including as lead or concerned supervisory authority in EU one-stop-shop cooperation.
ConfirmedDataGuidance — GDPR (Regulation (EU) 2016/679) applies directly in Bulgaria and is complemented by the Protection of Personal Data Act 2002, last amended in 2023, which supplies national procedural rules (DPO notification, ROPA content, breach-notification detail).
ProbableEDPB — Article 25m of the Bulgarian Act requires controllers to apply pseudonymisation and appropriate technical/organisational measures safeguarding data-subject rights when processing personal data for scientific/historical research or statistical purposes under GDPR Article 89(1).
ConfirmedEDPB — GDPR Article 3(2) extends applicability, directly effective in Bulgaria, to controllers/processors not established in the EU where processing relates to offering goods/services to, or monitoring the behaviour of, data subjects located in Bulgaria/the Union.
ConfirmedDataGuidance — Article 25b of the Bulgarian Act requires controllers and processors to notify CPDP of the identity and contact details of their appointed DPO, and any subsequent changes, per a procedure fixed in CPDP's Rules of Procedure under Article 9(2) of the Act.
Core lawful-basis and special-category rules are GDPR-aligned and evidenced by national case law/guidance; consent-threshold sub-module carries a research gap.
Primary frameworkGDPR Articles 6, 7, 9 as applied via the Protection of Personal Data Act 2002 (amended)
Traffic-light rationale — GreenCore lawful-basis and special-category rules are GDPR-aligned and evidenced by national case law/guidance; consent-threshold sub-module carries a research gap.
Sub-modules (4)
Lawful BasesGreen
A Bulgarian court (Administrativen sad – Blagoevgrad) referred questions to the CJEU on Article 6(1)(c)/(e) GDPR basis for prosecutorial processing of victim data, evidencing national application of the lawful-basis framework in law-enforcement-adjacent contexts.
Claims: CLM-BG-6f708192
Consent ThresholdsAmber
No Bulgaria-specific derogation from the GDPR Article 7 consent standard (freely given, informed, specific, revocable) was identified in this research pass; the EU baseline is presumed to apply without national variation.
Special CategoriesGreen
GDPR Article 9 special-category protections apply directly; CPDP has issued sector guidance addressing biometric (facial-recognition) processing by retailers, applying the special-category framework to a novel processing context.
Claims: CLM-BG-708192a3
Pseudonymisation And AnonymisationGreen
Article 25m of the Act operationalises pseudonymisation obligations for research/statistical processing under GDPR Article 89(1).
Claims: CLM-BG-8192a3b4
Category narrative48 words
Bulgaria applies the GDPR Article 6 lawful-basis framework and Article 9 special-category regime directly, illustrated nationally by a Bulgarian-court CJEU referral on prosecutorial data processing and CPDP guidance on biometric data in retail. Consent-threshold specifics beyond the GDPR Article 7 standard were not confirmed in this research pass.
Sources and claims (3)
ConfirmedEUR-Lex — In Case C-180/21, a Bulgarian court referred questions on the legal basis under Article 6(1)(c) and (e) GDPR for processing victim personal data by the Public Prosecutor's Office in connection with subsequent prosecution and defence of related civil claims, illustrating Bulgaria's national application of the GDPR lawful-basis framework alongside Directive (EU) 2016/680.
ProbableDataGuidance — The CPDP issued an opinion addressing the use of facial-recognition/biometric data-processing technology by stores, applying GDPR Article 9 special-category safeguards to retail biometric identification systems in Bulgaria.
ProbableEDPB — Article 25m of the Bulgarian Act requires pseudonymisation and appropriate technical/organisational measures for personal data processed for scientific/historical research or statistical purposes, implementing GDPR Article 89(1).
Rights framework is GDPR-standard with confirmed national procedural detail on access and retention; remaining sub-modules present as GDPR-baseline-only gaps.
Primary frameworkGDPR Chapter III (Articles 12-23) as applied via the Protection of Personal Data Act
Traffic-light rationale — GreenRights framework is GDPR-standard with confirmed national procedural detail on access and retention; remaining sub-modules present as GDPR-baseline-only gaps.
Sub-modules (5)
Access RightGreen
Data subjects may exercise the Article 15 access right directly with controllers or via CPDP; CPDP has produced public-facing educational materials to raise awareness of this right.
Claims: CLM-BG-92a3b4c5
Rectification And ErasureAmber
No Bulgaria-specific derogation to GDPR Articles 16-17 (rectification/erasure) was identified in this research pass; GDPR baseline presumed to apply unmodified.
Restriction And ObjectionAmber
No Bulgaria-specific derogation to GDPR Articles 18 and 21 was identified; GDPR baseline presumed to apply unmodified.
Data PortabilityAmber
No Bulgaria-specific derogation to GDPR Article 20 was identified; GDPR baseline presumed to apply unmodified.
Deadlines And Response WindowsGreen
Article 25k of the Act sets a six-month storage period tied to identity-verification documentation gathered in the course of data-subject rights requests, alongside the standard GDPR one-month (extendable to three-month) response window.
Claims: CLM-BG-a3b4c5d6
Category narrative62 words
Data subjects exercise GDPR Chapter III rights directly; CPDP supplements this with public-facing right-of-access awareness materials, and Article 25k of the Act sets a national retention rule (six months) tied to identity-verification documentation gathered when processing rights requests. Rectification, erasure, restriction, objection and portability rights rely on the unmodified GDPR baseline; no Bulgaria-specific derogation was found for those sub-modules in this pass.
Sources and claims (2)
ConfirmedEDPB — Data subjects in Bulgaria may lodge GDPR Article 15 access requests with controllers, and CPDP has developed public educational and awareness materials, including guidance for parents and children, to support exercise of the right of access.
ProbableEDPB — Article 25k of the Bulgarian Personal Data Protection Act establishes a six-month storage period for identity-verification documentation collected in connection with data-subject rights requests.
Well-evidenced via a published CPDP final decision and DataGuidance analysis of the Act's specific articles; joint-controller and retention/disposal sub-modules rely on unmodified GDPR baseline.
Primary frameworkGDPR Articles 5, 24-43 as detailed in the Protection of Personal Data Act (Articles 25b, 62(2), 66, 67(3))
Traffic-light rationale — GreenWell-evidenced via a published CPDP final decision and DataGuidance analysis of the Act's specific articles; joint-controller and retention/disposal sub-modules rely on unmodified GDPR baseline.
Sub-modules (7)
Accountability And DpiaAmber
CPDP's LockTrip decision found the controller failed to demonstrate Article 5(1) GDPR compliance, violating the Article 5(2) accountability principle in conjunction with Article 33(5), and that no DPIA had been performed before the breach.
Claims: CLM-BG-b4c5d6e7
Dpo RequirementsGreen
Article 25b of the Act mandates notification of DPO identity/contact details to CPDP.
Claims: CLM-BG-c5d6e7f8
Ropa RequirementsGreen
Article 62(2) of the Act prescribes specific processor ROPA content beyond the bare GDPR Article 30 minimum.
Claims: CLM-BG-d6e7f809
Joint Controller ArrangementsAmber
No Bulgaria-specific derogation to GDPR Article 26 joint-controller arrangements was identified in this research pass; GDPR baseline presumed to apply unmodified.
Security MeasuresAmber
CPDP's LockTrip decision documents a real-world security-measures failure (compromised device via public Wi-Fi) assessed by CPDP's own Risk Assessment Methodology (adopted 24 June 2021) at 'medium risk' to data subjects.
Claims: CLM-BG-f8091a2b
Breach NotificationGreen
Article 67(3) of the Act specifies mandatory breach-notification content, and CPDP applies a bespoke Methodology for Risk Assessment upon a Personal Data Breach.
Claims: CLM-BG-e7f8091a
Retention And DisposalAmber
No standalone Bulgaria-specific general retention/disposal regime beyond GDPR Article 5(1)(e) storage limitation and Article 25k's specific six-month rule (see data_subject_rights) was identified.
Category narrative46 words
Bulgaria's controller/processor duties are anchored in GDPR Articles 5, 24-43 and detailed nationally in the Act's DPO-notification (Art. 25b), processor-ROPA (Art. 62(2)), and breach-notification-content (Art. 67(3)) provisions. The CPDP's 2023 LockTrip Ltd. final decision is the clearest evidenced enforcement precedent on accountability, DPIA, and breach-notification duties.
Sources and claims (5)
ConfirmedEDPB / CPDP — In its 2023 final decision on the LockTrip Ltd. breach, CPDP found the controller failed to demonstrate compliance with GDPR Article 5(1), violating the Article 5(2) accountability principle in conjunction with Article 33(5), and noted no DPIA had been carried out prior to the breach despite one being prepared afterward addressing client-data risks.
ConfirmedDataGuidance — Article 25b of the Bulgarian Act requires controllers/processors to notify CPDP of DPO identity and contact details and any ensuing changes, per a procedure set out in CPDP's Rules of Procedure under Article 9(2) of the Act.
ConfirmedDataGuidance — Article 62(2) of the Act requires a data processor to maintain a record of processing activities containing processor/controller contact details, DPO details where applicable, processing categories, any third-country transfers, and a description of Article 66 security measures.
ConfirmedDataGuidance — Article 67(3) of the Bulgarian Act specifies mandatory breach-notification content (breach description, categories/approximate numbers of affected subjects and records, DPO contact, likely consequences, mitigation measures), and CPDP registers and risk-assesses notifications using its Methodology for Risk Assessment upon a Personal Data Breach adopted 24 June 2021.
ConfirmedEDPB / CPDP — CPDP's LockTrip decision found that unauthorised access via a compromised employee device connected to public Wi-Fi, leaking partner-platform passwords affecting 2,108 EU citizens (including 420 Bulgarian) and 2,423 third-country nationals, constituted a personal-data breach assessed at 'medium risk' to data subjects' rights and freedoms.
Core transfer mechanisms are GDPR-standard, but TIA-specific and SCC/BCR-uptake detail for Bulgaria was not separately confirmed in this pass; adequacy sub-modules are not applicable at Member-State level.
Traffic-light rationale — AmberCore transfer mechanisms are GDPR-standard, but TIA-specific and SCC/BCR-uptake detail for Bulgaria was not separately confirmed in this pass; adequacy sub-modules are not applicable at Member-State level.
Sub-modules (6)
Transfer MechanismsAmber
GDPR Chapter V transfer mechanisms (adequacy, SCCs, BCRs, Article 49 derogations) apply directly; CPDP is the competent authority for Bulgarian-established controllers' BCR approvals and ad hoc contractual clauses.
Claims: CLM-BG-091a2b3c
Adequacy ReceivedGreen
Not applicable at individual Member-State level: the European Commission, not Bulgaria, issues/receives adequacy determinations on behalf of all EU Member States under GDPR Article 45.
Adequacy GrantedGreen
Not applicable at individual Member-State level for the same structural reason as adequacy_received.
Sccs And BcrsAmber
The EU Commission's 2021 SCC modules apply directly in Bulgaria; no Bulgaria-specific SCC variant or BCR-uptake statistics were identified in this research pass.
Transfer Impact AssessmentAmber
The post-Schrems II TIA requirement applies GDPR-wide; no Bulgaria-specific TIA guidance from CPDP was identified in this research pass.
Data LocalisationGreen
Bulgaria operates the National Schengen Information System (N.SIS) under a national ordinance in conjunction with EU SIS Regulations and the Ministry of Interior Act, reflecting a sector-specific law-enforcement/immigration data-residency arrangement rather than a general commercial data-localisation mandate.
Claims: CLM-BG-1a2b3c4e
Category narrative60 words
As an EU Member State, Bulgaria applies the GDPR Chapter V transfer regime directly (adequacy decisions, SCCs, BCRs, derogations); adequacy decisions are issued/received at EU-Commission level rather than by Bulgaria individually, so the adequacy_received/adequacy_granted sub-modules are structurally not applicable to a single Member State. A sector-specific data-residency arrangement exists for Schengen/immigration-alert data (N.SIS) processed under national ordinance alongside EU Regulations.
Sources and claims (2)
ProbableCommission for Personal Data Protection — As an EU Member State, Bulgaria applies the GDPR Chapter V transfer regime directly, with CPDP acting as the competent national authority for approving BCRs and contractual clauses for Bulgarian-established controllers.
ProbableEDPB — Bulgaria operates a National Schengen Information System (N.SIS) under Ordinance No. 8121з-465 of 26 August 2014, processing data in compliance with EU Regulations 2018/1860-1862, the Ministry of Interior Act, and the Personal Data Protection Act, constituting a sector-specific data-residency arrangement for law-enforcement/immigration alert data.
Traffic-light rationale — AmberPartial coverage: employment and telecoms overlays confirmed; five of seven sub-modules carry an explicit research gap.
Sub-modules (7)
Financial Sector OverlayRed
No Bulgaria-specific financial-sector data-protection overlay (e.g., banking-secrecy interplay with GDPR) was identified. Searches run: "Bulgaria financial sector data protection overlay", general CPDP/DataGuidance overview queries.
Health Sector OverlayRed
No Bulgaria-specific health-sector data-protection overlay was identified in this research pass.
Telecoms And EprivacyAmber
The Electronic Communications Act (ECA) is identified as the national instrument intersecting with GDPR/ePrivacy for communications-related personal data.
Claims: CLM-BG-3c4d5e70
Employment DataGreen
Employee monitoring in Bulgaria is governed by a multi-instrument overlay: GDPR, the Act, the Labor Code 1986, the ECA, and the Constitution.
Claims: CLM-BG-2b3c4d5f
Credit And ScoringRed
No Bulgaria-specific credit-scoring data-protection overlay was identified in this research pass.
EducationRed
No Bulgaria-specific education-sector data-protection overlay was identified in this research pass.
InsuranceRed
No Bulgaria-specific insurance-sector data-protection overlay was identified in this research pass.
Category narrative42 words
Confirmed sectoral overlay evidence is limited to the employment-data and telecoms/eprivacy domains, where the Labor Code, Electronic Communications Act, and Constitution intersect with GDPR/the Act. No Bulgaria-specific financial-sector, health-sector, credit-scoring, education, or insurance data-protection overlay instruments were identified in this research pass.
Sources and claims (2)
ConfirmedDataGuidance — Bulgarian employee-monitoring rules draw on GDPR, the Protection of Personal Data Act 2002 (last amended 2023), the Labor Code 1986, the Electronic Communications Act, and the Constitution of the Republic of Bulgaria, creating a multi-instrument overlay governing employer processing of employee personal data.
ProbableDataGuidance — The Electronic Communications Act is identified as relevant national legislation intersecting with GDPR for communications-related personal data processing, operating alongside the EU ePrivacy framework in Bulgaria.
Traffic-light rationale — AmberOnly the cookies/trackers sub-module has confirmed national-instrument grounding; the remaining five sub-modules carry an explicit research gap.
Sub-modules (6)
Cookies And TrackersAmber
Cookie/tracking consent is governed by the ECA (ePrivacy implementation) alongside GDPR; no additional Bulgaria-specific cookie legislation was identified.
Claims: CLM-BG-4d5e6f81
Dark PatternsRed
No Bulgaria-specific dark-pattern prohibition beyond general EDPB guidance (applicable EU-wide) was identified in this research pass. Searches run: general CPDP/DataGuidance overview queries.
Opt Out SignalsRed
No Bulgaria-specific recognition of technical opt-out signals (e.g., Global Privacy Control) was identified.
Clean Rooms And DcrRed
No Bulgaria-specific clean-room/data-collaboration-room rules were identified.
Cross Context AdvertisingRed
No Bulgaria-specific cross-context advertising ('sale'/'share') concept analogous to US state law was identified; GDPR consent/legitimate-interest framework applies as the general floor.
Direct MarketingRed
No Bulgaria-specific direct-marketing consent/suppression rule beyond GDPR Article 21(2)/ECA implementation of ePrivacy Article 13 was identified in this research pass.
Category narrative44 words
Cookie/tracker consent in Bulgaria relies on the Electronic Communications Act implementing the EU ePrivacy Directive alongside GDPR consent standards. No Bulgaria-specific rules on dark patterns, opt-out signals, clean rooms, cross-context advertising, or direct-marketing suppression beyond the GDPR/ePrivacy baseline were identified in this research pass.
Sources and claims (1)
UncertainDataGuidance — Cookie and electronic-communications tracking consent in Bulgaria is governed by the Electronic Communications Act implementing the ePrivacy Directive, operating alongside GDPR consent standards; no additional Bulgaria-specific cookie legislation was identified in this research pass.
Biometric and state-surveillance-carveout sub-modules are evidenced; profiling/ADM/AI-risk/genetic-data sub-modules default to GDPR baseline without confirmed national specificity, and EU AI Act national-authority designation status for Bulgaria remains unresolved.
Primary frameworkGDPR Article 9 and Article 22, plus Ministry of Interior Act (Directive (EU) 2016/680 transposition) for law-enforcement carve-outs
Traffic-light rationale — AmberBiometric and state-surveillance-carveout sub-modules are evidenced; profiling/ADM/AI-risk/genetic-data sub-modules default to GDPR baseline without confirmed national specificity, and EU AI Act national-authority designation status for Bulgaria remains unresolved.
Sub-modules (6)
Profiling RestrictionsAmber
No Bulgaria-specific derogation to GDPR Article 22 profiling restrictions was identified; GDPR baseline presumed to apply unmodified.
Automated Decision Making TransparencyAmber
No Bulgaria-specific ADM transparency rule beyond GDPR Articles 13(2)(f)/14(2)(g)/15(1)(h) was identified.
Ai Risk AssessmentsRed
Bulgaria's national competent authority designation and implementation status under the EU AI Act was not confirmed in this research pass; flagged as an unresolved question.
Biometric RegimeGreen
CPDP has issued an opinion specifically addressing facial-recognition/biometric processing by retailers, applying Article 9 special-category safeguards.
Claims: CLM-BG-5e6f7092
Genetic DataAmber
No Bulgaria-specific genetic-data regime beyond the GDPR Article 9 special-category baseline was identified.
State Surveillance CarveoutsAmber
Law-enforcement/immigration data processing (e.g., N.SIS alerts) is carried out under the Ministry of Interior Act rather than GDPR directly, reflecting Bulgaria's transposition of Directive (EU) 2016/680, as illustrated in the CJEU C-180/21 referral on the GDPR/LED interplay in prosecutorial processing.
Claims: CLM-BG-6f7081a3
Category narrative67 words
Biometric processing (facial recognition) has been addressed directly by CPDP guidance applying GDPR Article 9 to retail use cases. Law-enforcement/immigration processing (e.g., N.SIS) is carved out under the Ministry of Interior Act transposing Directive (EU) 2016/680, illustrated by a Bulgarian-court CJEU referral on the GDPR/LED interplay. Profiling restrictions, ADM transparency, AI-specific risk assessments, and genetic-data regime rely on the unmodified GDPR baseline with no Bulgaria-specific layer identified.
Sources and claims (2)
ProbableDataGuidance — CPDP issued an opinion addressing the use of facial-recognition and biometric data-processing technology by stores/retailers, applying GDPR Article 9 special-category safeguards to biometric identification systems in Bulgaria.
ProbableEDPB — Law-enforcement and immigration data processing in Bulgaria (e.g., National Schengen Information System alerts) is carried out under the Ministry of Interior Act and related ordinances rather than GDPR directly, reflecting transposition of the Law Enforcement Directive (EU) 2016/680, as illustrated by the Bulgarian court's CJEU referral in Case C-180/21 concerning the GDPR/LED interplay in prosecutorial data processing.
Only a non-binding awareness-activity claim is evidenced; the core binding parental-consent age threshold and other sub-modules carry an explicit, unresolved research gap.
Primary frameworkGDPR Article 8 (children's consent) as applied via the Protection of Personal Data Act
Traffic-light rationale — RedOnly a non-binding awareness-activity claim is evidenced; the core binding parental-consent age threshold and other sub-modules carry an explicit, unresolved research gap.
Sub-modules (5)
Age VerificationRed
The Bulgarian age-of-consent threshold under GDPR Article 8 (default 16, or a national lowering to as low as 13) was not confirmed in this research pass. Searches run: general CPDP/DataGuidance overview queries; a targeted search for the specific statutory age was not conclusive.
Parental ConsentAmber
CPDP produces parent-facing advice materials on children's personal data and internet use as part of broader awareness activity, but the binding parental-consent mechanism/age threshold was not separately confirmed.
Claims: CLM-BG-7081a3c4
Minor Profiling BansRed
No Bulgaria-specific minor-profiling ban beyond the GDPR baseline (recital 38 caution on profiling of children) was identified.
Education SettingsRed
No Bulgaria-specific education-settings data-protection rule was identified in this research pass.
Dependent AdultsRed
No Bulgaria-specific dependent-adults (elderly/incapacitated) data-protection provision was identified in this research pass.
Category narrative46 words
CPDP conducts child-oriented digital-safety and right-of-access awareness activities, including materials for parents. The specific national age-of-consent threshold under GDPR Article 8 (whether Bulgaria retains the default age 16 or has lowered it) was not confirmed in this research pass, nor were minor-profiling-ban, education-setting-specific, or dependent-adult-specific rules.
Sources and claims (1)
ConfirmedEDPB — CPDP has developed child-oriented educational materials, including publications, guidelines, leaflets and videos, and produced advice materials for parents on children's personal data and internet use, as part of its digital-safety and right-of-access awareness activities.
Regulator powers and recent enforcement/jurisprudential activity are well evidenced; collective-redress, private-right-of-action, and regulator-funding sub-modules carry research gaps.
Primary frameworkGDPR Articles 58, 77-84 as applied by the Commission for Personal Data Protection
Traffic-light rationale — GreenRegulator powers and recent enforcement/jurisprudential activity are well evidenced; collective-redress, private-right-of-action, and regulator-funding sub-modules carry research gaps.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
CPDP can impose administrative fines up to GDPR Article 83 maxima and previously fined the National Revenue Agency BGN 5.1 million for GDPR violations.
Claims: CLM-BG-8192a3d5
Enforcement Activity IndexGreen
The 2022-2023 LockTrip Ltd. case shows CPDP conducting a formal document-inspection and Article 60 cross-border cooperation procedure with Finland, Spain, and Poland as concerned/commenting supervisory authorities.
Claims: CLM-BG-92a3b4e6
Regulator Funding And CapacityRed
No specific CPDP budget/headcount data was identified in this research pass.
Collective Redress And Class ActionsRed
No Bulgaria-specific collective-redress mechanism for data-protection claims (beyond general GDPR Article 80 representative-action provisions) was confirmed in this research pass.
Private Right Of ActionAmber
GDPR Articles 79/82 judicial-remedy and compensation rights apply directly; no Bulgaria-specific procedural variant was confirmed in this research pass.
Recent Developments 180DGreen
CJEU judgment of 9 July 2026 in Case C-199/24 interprets the GDPR Article 85(2) journalistic-purposes exemption strictly; the Bulgarian Government was among the governments submitting observations.
Claims: CLM-BG-a3b4c5f7
Category narrative79 words
CPDP exercises GDPR Article 58 corrective powers up to the Article 83 maximum fines and has a track record of significant enforcement, including a BGN 5.1 million fine against Bulgaria's National Revenue Agency (2019) and an active, EU-cooperative investigation/decision in the LockTrip Ltd. breach case (2022-2023). Recent 180-day-window development: CJEU judgment (9 July 2026) in Case C-199/24 on the GDPR Article 85 journalistic-purposes exemption, with the Bulgarian Government among the intervening governments, bearing on national application of that derogation.
Sources and claims (3)
ConfirmedIAPP — CPDP exercises GDPR Article 58 corrective powers, including document-inspection procedures, and can impose administrative fines up to GDPR Article 83 maxima; it previously fined Bulgaria's National Revenue Agency BGN 5.1 million for GDPR violations following a major data leak.
ConfirmedEDPB / CPDP — In 2022-2023, CPDP conducted a formal document-inspection and Article 60 cooperation procedure regarding a breach notification from LockTrip Ltd., coordinating via the EU Internal Market Information System with Finland and Spain as concerned supervisory authorities and Poland commenting on the draft decision.
ConfirmedEUR-Lex — On 9 July 2026, the CJEU delivered judgment in Case C-199/24 interpreting the GDPR Article 85(2) 'journalistic purposes' exemption strictly, with the Bulgarian Government among the governments submitting observations, marking an active EU-level jurisprudential development relevant to national application of journalistic-purpose derogations from GDPR obligations.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Bulgaria
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 26 claim(s), 15 source(s) in the cumulative register.