#
Fully GDPR-aligned omnibus regime with an operational, actively enforcing DPA and a national implementing act; no material regulatory gaps identified.
Sub-modules (5)
Regulator And AuthorityGreen
CPDP is Bulgaria's independent supervisory authority, empowered to investigate, inspect and issue final decisions on GDPR compliance, including acting as lead or concerned supervisory authority in one-stop-shop cross-border cases.
Claims (1):
- The Commission for Personal Data Protection (CPDP) is Bulgaria's independent supervisory authority for data protection, empowered to investigate breaches, conduct document inspections, and issue final enforcement decisions, including as lead or concerned supervisory authority in EU one-stop-shop cooperation.
Act And InstrumentsGreen
GDPR applies directly; the Protection of Personal Data Act 2002 (last amended 2023) is the operative national complementing statute.
Claims (1):
- GDPR (Regulation (EU) 2016/679) applies directly in Bulgaria and is complemented by the Protection of Personal Data Act 2002, last amended in 2023, which supplies national procedural rules (DPO notification, ROPA content, breach-notification detail).
Material ScopeGreen
National derogation exists for scientific/historical research and statistics under Article 25m of the Act, implementing GDPR Article 89(1) safeguards.
Claims (1):
- Article 25m of the Bulgarian Act requires controllers to apply pseudonymisation and appropriate technical/organisational measures safeguarding data-subject rights when processing personal data for scientific/historical research or statistical purposes under GDPR Article 89(1).
Territorial ScopeGreen
GDPR Article 3(2) targeting-criterion applies directly in Bulgaria to non-established controllers/processors offering goods/services to, or monitoring, data subjects in Bulgaria/the Union; no distinct national territorial-scope variant was identified.
Claims (1):
- GDPR Article 3(2) extends applicability, directly effective in Bulgaria, to controllers/processors not established in the EU where processing relates to offering goods/services to, or monitoring the behaviour of, data subjects located in Bulgaria/the Union.
Regulator Registration And FilingGreen
Bulgaria abolished pre-GDPR general processing registration but retains a targeted notification duty: controllers/processors must notify CPDP of DPO identity/contact details under Article 25b of the Act.
Claims (1):
- Article 25b of the Bulgarian Act requires controllers and processors to notify CPDP of the identity and contact details of their appointed DPO, and any subsequent changes, per a procedure fixed in CPDP's Rules of Procedure under Article 9(2) of the Act.
Key findings (3)
- Article 25k of the Bulgarian PDPA (SG No 17/2019) deems National Archival Fund processing public-interest and disapplies GDPR Articles 15,16,18,19,20,21; corrects a prior fabricated six-month retention characterisation. — source on file
- Article 25k of the Bulgarian PDPA (SG No 17/2019) deems National Archival Fund processing public-interest and disapplies GDPR Articles 15,16,18,19,20,21; corrects a prior fabricated six-month retention characterisation. — source on file
- Article 25k of the Bulgarian PDPA (SG No 17/2019) deems National Archival Fund processing public-interest and disapplies GDPR Articles 15,16,18,19,20,21; corrects a prior fabricated six-month retention characterisation. — source on file
Regulator & Framework
Bulgaria's data-protection supervisory architecture is anchored by the Commission for Personal Data Protection (CPDP), the confirmed principal GDPR and PDPA authority for Bulgaria. A structurally significant carve-out applies to the judiciary: compliance by courts, the prosecution service and investigation bodies with GDPR and the PDPA is instead supervised by the Inspectorate of the Supreme Judicial Council, not the CPDP. This split is a standing feature of the framework rather than a new development, but it is frequently missed by readers assuming CPDP jurisdiction is total, and it materially affects where a complaint concerning a judicial-sector data controller should be directed.
The Personal Data Protection Act, Bulgaria's domestic implementing statute alongside the directly applicable GDPR, was amended on 10 February 2026. The specific content of that amendment has not been independently confirmed this cycle; the finding rests on Probable confidence, reflecting that the fact of amendment is reasonably well evidenced while its substance remains an open gap. Readers should treat the framework as having moved, in a confirmed but as-yet under-specified way, on that date, with the practical consequences of the change to be clarified in a future cycle once the amendment's text is retrieved and reviewed.
Outlook
The primary item to watch is the substantive content of the 10 February 2026 PDPA amendment, which was not retrieved this cycle beyond confirmation that the amendment occurred. A future cycle that closes this gap would materially sharpen the regulator-and-framework picture and clarify whether the amendment touches supervisory competence, penalty structure, or another dimension of the framework.
1 earlier distinct update(s)
Regulator & Framework
The Bulgarian Personal Data Protection Act is understood to have last been amended on 10 February 2026. The Commission for Personal Data Protection remains Bulgaria's principal data protection authority, continuing to supervise compliance under the amended framework. This finding rests on law-firm commentary rather than direct retrieval of the CPDP's own publications or the State Gazette text of the amendment this cycle, and should be read with that sourcing limitation in mind.
Outlook
The item to watch is whether direct confirmation of the 10 February 2026 amendment's substantive content becomes available, which would allow a fuller assessment of what specifically changed in the Bulgarian framework this cycle beyond the fact of the amendment itself.
1 further periodic run re-emitted the standing brief unchanged and is not shown.
Sources and claims (5)
- ConfirmedCommission for Personal Data Protection — The Commission for Personal Data Protection (CPDP) is Bulgaria's independent supervisory authority for data protection, empowered to investigate breaches, conduct document inspections, and issue final enforcement decisions, including as lead or concerned supervisory authority in EU one-stop-shop cooperation.observed
- ConfirmedDataGuidance — GDPR (Regulation (EU) 2016/679) applies directly in Bulgaria and is complemented by the Protection of Personal Data Act 2002, last amended in 2023, which supplies national procedural rules (DPO notification, ROPA content, breach-notification detail).observed
- ProbableEDPB — Article 25m of the Bulgarian Act requires controllers to apply pseudonymisation and appropriate technical/organisational measures safeguarding data-subject rights when processing personal data for scientific/historical research or statistical purposes under GDPR Article 89(1).observed
- ConfirmedEDPB — GDPR Article 3(2) extends applicability, directly effective in Bulgaria, to controllers/processors not established in the EU where processing relates to offering goods/services to, or monitoring the behaviour of, data subjects located in Bulgaria/the Union.observed
- ConfirmedDataGuidance — Article 25b of the Bulgarian Act requires controllers and processors to notify CPDP of the identity and contact details of their appointed DPO, and any subsequent changes, per a procedure fixed in CPDP's Rules of Procedure under Article 9(2) of the Act.observed