🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
BG v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing14 sources retrieved model claude-sonnet-5 · 2026-08-05

Bulgaria

BG schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: AIC

Last updated · 10 categories · 26 claims · 27 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
26Claimsbaseline..claims[]
11Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Bulgaria's data-protection enforcement posture shows a notable transparency contraction this cycle. The Commission for Personal Data Protection (CPDP) published no publicly available enforcement decisions in either 2024 or 2025, reversing an earlier practice of publishing selected decisions. This is understood to have occurred rather than being asserted with full confidence, as the underlying claim rests on Tier-3 sourcing and has not been independently corroborated against the CPDP's own decisions register this cycle. Alongside this contraction, the Bulgarian Supreme Administrative Court is understood to have referred questions on state liability for GDPR-breach damages, arising from the National Revenue Agency's 2019 data leak, to the CJEU for a preliminary ruling.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Fully GDPR-aligned omnibus regime with an operational, actively enforcing DPA and a national implementing act; no material regulatory gaps identified.

Primary frameworkRegulation (EU) 2016/679 (GDPR) as complemented by the Protection of Personal Data Act 2002 (last amended 2023)
Traffic-light rationale — GreenFully GDPR-aligned omnibus regime with an operational, actively enforcing DPA and a national implementing act; no material regulatory gaps identified.

Sub-modules (5)

Regulator And AuthorityGreen

CPDP is Bulgaria's independent supervisory authority, empowered to investigate, inspect and issue final decisions on GDPR compliance, including acting as lead or concerned supervisory authority in one-stop-shop cross-border cases.

Claims (1):

  • The Commission for Personal Data Protection (CPDP) is Bulgaria's independent supervisory authority for data protection, empowered to investigate breaches, conduct document inspections, and issue final enforcement decisions, including as lead or concerned supervisory authority in EU one-stop-shop cooperation.

Act And InstrumentsGreen

GDPR applies directly; the Protection of Personal Data Act 2002 (last amended 2023) is the operative national complementing statute.

Claims (1):

  • GDPR (Regulation (EU) 2016/679) applies directly in Bulgaria and is complemented by the Protection of Personal Data Act 2002, last amended in 2023, which supplies national procedural rules (DPO notification, ROPA content, breach-notification detail).

Material ScopeGreen

National derogation exists for scientific/historical research and statistics under Article 25m of the Act, implementing GDPR Article 89(1) safeguards.

Claims (1):

  • Article 25m of the Bulgarian Act requires controllers to apply pseudonymisation and appropriate technical/organisational measures safeguarding data-subject rights when processing personal data for scientific/historical research or statistical purposes under GDPR Article 89(1).

Territorial ScopeGreen

GDPR Article 3(2) targeting-criterion applies directly in Bulgaria to non-established controllers/processors offering goods/services to, or monitoring, data subjects in Bulgaria/the Union; no distinct national territorial-scope variant was identified.

Claims (1):

  • GDPR Article 3(2) extends applicability, directly effective in Bulgaria, to controllers/processors not established in the EU where processing relates to offering goods/services to, or monitoring the behaviour of, data subjects located in Bulgaria/the Union.

Regulator Registration And FilingGreen

Bulgaria abolished pre-GDPR general processing registration but retains a targeted notification duty: controllers/processors must notify CPDP of DPO identity/contact details under Article 25b of the Act.

Claims (1):

  • Article 25b of the Bulgarian Act requires controllers and processors to notify CPDP of the identity and contact details of their appointed DPO, and any subsequent changes, per a procedure fixed in CPDP's Rules of Procedure under Article 9(2) of the Act.

Key findings (3)

  • Article 25k of the Bulgarian PDPA (SG No 17/2019) deems National Archival Fund processing public-interest and disapplies GDPR Articles 15,16,18,19,20,21; corrects a prior fabricated six-month retention characterisation. — source on file
  • Article 25k of the Bulgarian PDPA (SG No 17/2019) deems National Archival Fund processing public-interest and disapplies GDPR Articles 15,16,18,19,20,21; corrects a prior fabricated six-month retention characterisation. — source on file
  • Article 25k of the Bulgarian PDPA (SG No 17/2019) deems National Archival Fund processing public-interest and disapplies GDPR Articles 15,16,18,19,20,21; corrects a prior fabricated six-month retention characterisation. — source on file
Category narrative52 words

Bulgaria is an EU Member State applying the GDPR directly since 25 May 2018, supplemented by the national Protection of Personal Data Act 2002 (last amended 2023), which layers DPO-notification, ROPA, and breach-notification procedural rules onto the GDPR baseline. The Commission for Personal Data Protection (CPDP) is the designated independent supervisory authority.

Periodic update · new data 2026-09-21

Regulator & Framework

Bulgaria's data-protection supervisory architecture is anchored by the Commission for Personal Data Protection (CPDP), the confirmed principal GDPR and PDPA authority for Bulgaria. A structurally significant carve-out applies to the judiciary: compliance by courts, the prosecution service and investigation bodies with GDPR and the PDPA is instead supervised by the Inspectorate of the Supreme Judicial Council, not the CPDP. This split is a standing feature of the framework rather than a new development, but it is frequently missed by readers assuming CPDP jurisdiction is total, and it materially affects where a complaint concerning a judicial-sector data controller should be directed.

The Personal Data Protection Act, Bulgaria's domestic implementing statute alongside the directly applicable GDPR, was amended on 10 February 2026. The specific content of that amendment has not been independently confirmed this cycle; the finding rests on Probable confidence, reflecting that the fact of amendment is reasonably well evidenced while its substance remains an open gap. Readers should treat the framework as having moved, in a confirmed but as-yet under-specified way, on that date, with the practical consequences of the change to be clarified in a future cycle once the amendment's text is retrieved and reviewed.

Outlook

The primary item to watch is the substantive content of the 10 February 2026 PDPA amendment, which was not retrieved this cycle beyond confirmation that the amendment occurred. A future cycle that closes this gap would materially sharpen the regulator-and-framework picture and clarify whether the amendment touches supervisory competence, penalty structure, or another dimension of the framework.

1 earlier distinct update(s)
Periodic update · new data 2026-09-14

Regulator & Framework

The Bulgarian Personal Data Protection Act is understood to have last been amended on 10 February 2026. The Commission for Personal Data Protection remains Bulgaria's principal data protection authority, continuing to supervise compliance under the amended framework. This finding rests on law-firm commentary rather than direct retrieval of the CPDP's own publications or the State Gazette text of the amendment this cycle, and should be read with that sourcing limitation in mind.

Outlook

The item to watch is whether direct confirmation of the 10 February 2026 amendment's substantive content becomes available, which would allow a fuller assessment of what specifically changed in the Bulgarian framework this cycle beyond the fact of the amendment itself.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ConfirmedCommission for Personal Data Protection — The Commission for Personal Data Protection (CPDP) is Bulgaria's independent supervisory authority for data protection, empowered to investigate breaches, conduct document inspections, and issue final enforcement decisions, including as lead or concerned supervisory authority in EU one-stop-shop cooperation.observed
  2. ConfirmedDataGuidance — GDPR (Regulation (EU) 2016/679) applies directly in Bulgaria and is complemented by the Protection of Personal Data Act 2002, last amended in 2023, which supplies national procedural rules (DPO notification, ROPA content, breach-notification detail).observed
  3. ProbableEDPB — Article 25m of the Bulgarian Act requires controllers to apply pseudonymisation and appropriate technical/organisational measures safeguarding data-subject rights when processing personal data for scientific/historical research or statistical purposes under GDPR Article 89(1).observed
  4. ConfirmedEDPB — GDPR Article 3(2) extends applicability, directly effective in Bulgaria, to controllers/processors not established in the EU where processing relates to offering goods/services to, or monitoring the behaviour of, data subjects located in Bulgaria/the Union.observed
  5. ConfirmedDataGuidance — Article 25b of the Bulgarian Act requires controllers and processors to notify CPDP of the identity and contact details of their appointed DPO, and any subsequent changes, per a procedure fixed in CPDP's Rules of Procedure under Article 9(2) of the Act.observed

#

Core lawful-basis and special-category rules are GDPR-aligned and evidenced by national case law/guidance; consent-threshold sub-module carries a research gap.

Primary frameworkGDPR Articles 6, 7, 9 as applied via the Protection of Personal Data Act 2002 (amended)
Traffic-light rationale — GreenCore lawful-basis and special-category rules are GDPR-aligned and evidenced by national case law/guidance; consent-threshold sub-module carries a research gap.

Sub-modules (4)

Lawful BasesGreen

A Bulgarian court (Administrativen sad – Blagoevgrad) referred questions to the CJEU on Article 6(1)(c)/(e) GDPR basis for prosecutorial processing of victim data, evidencing national application of the lawful-basis framework in law-enforcement-adjacent contexts.

Claims (1):

  • In Case C-180/21, a Bulgarian court referred questions on the legal basis under Article 6(1)(c) and (e) GDPR for processing victim personal data by the Public Prosecutor's Office in connection with subsequent prosecution and defence of related civil claims, illustrating Bulgaria's national application of the GDPR lawful-basis framework alongside Directive (EU) 2016/680.

Special CategoriesGreen

GDPR Article 9 special-category protections apply directly; CPDP has issued sector guidance addressing biometric (facial-recognition) processing by retailers, applying the special-category framework to a novel processing context.

Claims (1):

  • The CPDP issued an opinion addressing the use of facial-recognition/biometric data-processing technology by stores, applying GDPR Article 9 special-category safeguards to retail biometric identification systems in Bulgaria.

Pseudonymisation And AnonymisationGreen

Article 25m of the Act operationalises pseudonymisation obligations for research/statistical processing under GDPR Article 89(1).

Claims (1):

  • Article 25m of the Bulgarian Act requires pseudonymisation and appropriate technical/organisational measures for personal data processed for scientific/historical research or statistical purposes, implementing GDPR Article 89(1).

Key findings (3)

  • Bulgaria sets the digital age of consent at 14 under Article 25c PDPA, derogating from the GDPR Article 8 default of 16. — source on file
  • Bulgaria sets the digital age of consent at 14 under Article 25c PDPA, derogating from the GDPR Article 8 default of 16. — source on file
  • Bulgaria sets the digital age of consent at 14 under Article 25c PDPA, derogating from the GDPR Article 8 default of 16. — source on file
Category narrative48 words

Bulgaria applies the GDPR Article 6 lawful-basis framework and Article 9 special-category regime directly, illustrated nationally by a Bulgarian-court CJEU referral on prosecutorial data processing and CPDP guidance on biometric data in retail. Consent-threshold specifics beyond the GDPR Article 7 standard were not confirmed in this research pass.

Sources and claims (3)
  1. ConfirmedEUR-Lex — In Case C-180/21, a Bulgarian court referred questions on the legal basis under Article 6(1)(c) and (e) GDPR for processing victim personal data by the Public Prosecutor's Office in connection with subsequent prosecution and defence of related civil claims, illustrating Bulgaria's national application of the GDPR lawful-basis framework alongside Directive (EU) 2016/680.observed
  2. ProbableDataGuidance — The CPDP issued an opinion addressing the use of facial-recognition/biometric data-processing technology by stores, applying GDPR Article 9 special-category safeguards to retail biometric identification systems in Bulgaria.observed
  3. ProbableEDPB — Article 25m of the Bulgarian Act requires pseudonymisation and appropriate technical/organisational measures for personal data processed for scientific/historical research or statistical purposes, implementing GDPR Article 89(1).observed

#

Rights framework is GDPR-standard with confirmed national procedural detail on access and retention; remaining sub-modules present as GDPR-baseline-only gaps.

Primary frameworkGDPR Chapter III (Articles 12-23) as applied via the Protection of Personal Data Act
Traffic-light rationale — GreenRights framework is GDPR-standard with confirmed national procedural detail on access and retention; remaining sub-modules present as GDPR-baseline-only gaps.

Sub-modules (5)

Access RightGreen

Data subjects may exercise the Article 15 access right directly with controllers or via CPDP; CPDP has produced public-facing educational materials to raise awareness of this right.

Claims (1):

  • Data subjects in Bulgaria may lodge GDPR Article 15 access requests with controllers, and CPDP has developed public educational and awareness materials, including guidance for parents and children, to support exercise of the right of access.

Rectification And ErasureAmber

No Bulgaria-specific derogation to GDPR Articles 16-17 (rectification/erasure) was identified in this research pass; GDPR baseline presumed to apply unmodified.

Restriction And ObjectionAmber

No Bulgaria-specific derogation to GDPR Articles 18 and 21 was identified; GDPR baseline presumed to apply unmodified.

Data PortabilityAmber

No Bulgaria-specific derogation to GDPR Article 20 was identified; GDPR baseline presumed to apply unmodified.

Deadlines And Response WindowsGreen

Article 25k of the Act sets a six-month storage period tied to identity-verification documentation gathered in the course of data-subject rights requests, alongside the standard GDPR one-month (extendable to three-month) response window.

Claims (1):

  • Article 25k of the Bulgarian Personal Data Protection Act establishes a six-month storage period for identity-verification documentation collected in connection with data-subject rights requests.
Category narrative62 words

Data subjects exercise GDPR Chapter III rights directly; CPDP supplements this with public-facing right-of-access awareness materials, and Article 25k of the Act sets a national retention rule (six months) tied to identity-verification documentation gathered when processing rights requests. Rectification, erasure, restriction, objection and portability rights rely on the unmodified GDPR baseline; no Bulgaria-specific derogation was found for those sub-modules in this pass.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ConfirmedEDPB — Data subjects in Bulgaria may lodge GDPR Article 15 access requests with controllers, and CPDP has developed public educational and awareness materials, including guidance for parents and children, to support exercise of the right of access.observed
  2. ProbableEDPB — Article 25k of the Bulgarian Personal Data Protection Act establishes a six-month storage period for identity-verification documentation collected in connection with data-subject rights requests.observed

#

Well-evidenced via a published CPDP final decision and DataGuidance analysis of the Act's specific articles; joint-controller and retention/disposal sub-modules rely on unmodified GDPR baseline.

Primary frameworkGDPR Articles 5, 24-43 as detailed in the Protection of Personal Data Act (Articles 25b, 62(2), 66, 67(3))
Traffic-light rationale — GreenWell-evidenced via a published CPDP final decision and DataGuidance analysis of the Act's specific articles; joint-controller and retention/disposal sub-modules rely on unmodified GDPR baseline.

Sub-modules (7)

Accountability And DpiaAmber

CPDP's LockTrip decision found the controller failed to demonstrate Article 5(1) GDPR compliance, violating the Article 5(2) accountability principle in conjunction with Article 33(5), and that no DPIA had been performed before the breach.

Claims (1):

  • In its 2023 final decision on the LockTrip Ltd. breach, CPDP found the controller failed to demonstrate compliance with GDPR Article 5(1), violating the Article 5(2) accountability principle in conjunction with Article 33(5), and noted no DPIA had been carried out prior to the breach despite one being prepared afterward addressing client-data risks.

Dpo RequirementsGreen

Article 25b of the Act mandates notification of DPO identity/contact details to CPDP.

Claims (1):

  • Article 25b of the Bulgarian Act requires controllers/processors to notify CPDP of DPO identity and contact details and any ensuing changes, per a procedure set out in CPDP's Rules of Procedure under Article 9(2) of the Act.

Ropa RequirementsGreen

Article 62(2) of the Act prescribes specific processor ROPA content beyond the bare GDPR Article 30 minimum.

Claims (1):

  • Article 62(2) of the Act requires a data processor to maintain a record of processing activities containing processor/controller contact details, DPO details where applicable, processing categories, any third-country transfers, and a description of Article 66 security measures.

Joint Controller ArrangementsAmber

No Bulgaria-specific derogation to GDPR Article 26 joint-controller arrangements was identified in this research pass; GDPR baseline presumed to apply unmodified.

Security MeasuresAmber

CPDP's LockTrip decision documents a real-world security-measures failure (compromised device via public Wi-Fi) assessed by CPDP's own Risk Assessment Methodology (adopted 24 June 2021) at 'medium risk' to data subjects.

Claims (1):

  • CPDP's LockTrip decision found that unauthorised access via a compromised employee device connected to public Wi-Fi, leaking partner-platform passwords affecting 2,108 EU citizens (including 420 Bulgarian) and 2,423 third-country nationals, constituted a personal-data breach assessed at 'medium risk' to data subjects' rights and freedoms.

Breach NotificationGreen

Article 67(3) of the Act specifies mandatory breach-notification content, and CPDP applies a bespoke Methodology for Risk Assessment upon a Personal Data Breach.

Claims (1):

  • Article 67(3) of the Bulgarian Act specifies mandatory breach-notification content (breach description, categories/approximate numbers of affected subjects and records, DPO contact, likely consequences, mitigation measures), and CPDP registers and risk-assesses notifications using its Methodology for Risk Assessment upon a Personal Data Breach adopted 24 June 2021.

Retention And DisposalAmber

No standalone Bulgaria-specific general retention/disposal regime beyond GDPR Article 5(1)(e) storage limitation and Article 25k's specific six-month rule (see data_subject_rights) was identified.

Category narrative46 words

Bulgaria's controller/processor duties are anchored in GDPR Articles 5, 24-43 and detailed nationally in the Act's DPO-notification (Art. 25b), processor-ROPA (Art. 62(2)), and breach-notification-content (Art. 67(3)) provisions. The CPDP's 2023 LockTrip Ltd. final decision is the clearest evidenced enforcement precedent on accountability, DPIA, and breach-notification duties.

Periodic update · new data 2026-09-14

Controller/Processor Duties

Bulgaria's breach-notification environment showed an elevated volume in 2025: 112 breach notifications were recorded, with approximately 2.5 million data subjects affected, and 87 percent of these breaches attributed to external hacking attacks. This figure is understood to reflect an escalating trajectory in controller and processor breach-reporting activity, though it has not been independently confirmed against CPDP primary data this cycle and rests on law-firm commentary.

Separately, a Sofia City Administrative Court decision dated 5 January 2026 reduced the financial penalty against Bulgarian Post EAD arising from its 2022 data-breach case. This court-driven reduction is a material development for how breach-related enforcement outcomes should be read: it indicates that CPDP enforcement figures in this area are subject to judicial moderation on appeal, tempering the practical weight of headline penalty figures.

Outlook

The trajectory to watch is whether the elevated 2025 breach-notification volume continues into 2026, and whether further judicial reductions of CPDP breach-related penalties follow the Bulgarian Post EAD pattern, which would reinforce the signal that appeal mechanisms are functioning as a meaningful check on enforcement outcomes.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ConfirmedEDPB / CPDP — In its 2023 final decision on the LockTrip Ltd. breach, CPDP found the controller failed to demonstrate compliance with GDPR Article 5(1), violating the Article 5(2) accountability principle in conjunction with Article 33(5), and noted no DPIA had been carried out prior to the breach despite one being prepared afterward addressing client-data risks.observed
  2. ConfirmedDataGuidance — Article 25b of the Bulgarian Act requires controllers/processors to notify CPDP of DPO identity and contact details and any ensuing changes, per a procedure set out in CPDP's Rules of Procedure under Article 9(2) of the Act.observed
  3. ConfirmedDataGuidance — Article 62(2) of the Act requires a data processor to maintain a record of processing activities containing processor/controller contact details, DPO details where applicable, processing categories, any third-country transfers, and a description of Article 66 security measures.observed
  4. ConfirmedDataGuidance — Article 67(3) of the Bulgarian Act specifies mandatory breach-notification content (breach description, categories/approximate numbers of affected subjects and records, DPO contact, likely consequences, mitigation measures), and CPDP registers and risk-assesses notifications using its Methodology for Risk Assessment upon a Personal Data Breach adopted 24 June 2021.observed
  5. ConfirmedEDPB / CPDP — CPDP's LockTrip decision found that unauthorised access via a compromised employee device connected to public Wi-Fi, leaking partner-platform passwords affecting 2,108 EU citizens (including 420 Bulgarian) and 2,423 third-country nationals, constituted a personal-data breach assessed at 'medium risk' to data subjects' rights and freedoms.observed

#

Core transfer mechanisms are GDPR-standard, but TIA-specific and SCC/BCR-uptake detail for Bulgaria was not separately confirmed in this pass; adequacy sub-modules are not applicable at Member-State level.

Primary frameworkGDPR Chapter V (Articles 44-49)
Traffic-light rationale — AmberCore transfer mechanisms are GDPR-standard, but TIA-specific and SCC/BCR-uptake detail for Bulgaria was not separately confirmed in this pass; adequacy sub-modules are not applicable at Member-State level.

Sub-modules (6)

Transfer MechanismsAmber

GDPR Chapter V transfer mechanisms (adequacy, SCCs, BCRs, Article 49 derogations) apply directly; CPDP is the competent authority for Bulgarian-established controllers' BCR approvals and ad hoc contractual clauses.

Claims (1):

  • As an EU Member State, Bulgaria applies the GDPR Chapter V transfer regime directly, with CPDP acting as the competent national authority for approving BCRs and contractual clauses for Bulgarian-established controllers.

Adequacy ReceivedGreen

Not applicable at individual Member-State level: the European Commission, not Bulgaria, issues/receives adequacy determinations on behalf of all EU Member States under GDPR Article 45.

Adequacy GrantedGreen

Not applicable at individual Member-State level for the same structural reason as adequacy_received.

Sccs And BcrsAmber

The EU Commission's 2021 SCC modules apply directly in Bulgaria; no Bulgaria-specific SCC variant or BCR-uptake statistics were identified in this research pass.

Transfer Impact AssessmentAmber

The post-Schrems II TIA requirement applies GDPR-wide; no Bulgaria-specific TIA guidance from CPDP was identified in this research pass.

Data LocalisationGreen

Bulgaria operates the National Schengen Information System (N.SIS) under a national ordinance in conjunction with EU SIS Regulations and the Ministry of Interior Act, reflecting a sector-specific law-enforcement/immigration data-residency arrangement rather than a general commercial data-localisation mandate.

Claims (1):

  • Bulgaria operates a National Schengen Information System (N.SIS) under Ordinance No. 8121з-465 of 26 August 2014, processing data in compliance with EU Regulations 2018/1860-1862, the Ministry of Interior Act, and the Personal Data Protection Act, constituting a sector-specific data-residency arrangement for law-enforcement/immigration alert data.
Category narrative60 words

As an EU Member State, Bulgaria applies the GDPR Chapter V transfer regime directly (adequacy decisions, SCCs, BCRs, derogations); adequacy decisions are issued/received at EU-Commission level rather than by Bulgaria individually, so the adequacy_received/adequacy_granted sub-modules are structurally not applicable to a single Member State. A sector-specific data-residency arrangement exists for Schengen/immigration-alert data (N.SIS) processed under national ordinance alongside EU Regulations.

Periodic update · new data 2026-09-14

Cross-Border & Adequacy

Regulation (EU) 2025/2518 is understood to lay down additional procedural rules for the enforcement of the GDPR in cross-border cases, and is reported to apply from April 2027. This is a forward-dated, not-yet-effective instrument that will affect how the Commission for Personal Data Protection cooperates procedurally with other EU data protection authorities on cases involving cross-border data flows or multi-jurisdiction complaints once it becomes applicable.

Outlook

The item to watch as this cycle's horizon item approaches is how the CPDP prepares operationally for the April 2027 application date of Regulation (EU) 2025/2518, and whether any transitional guidance is issued in the interim regarding cross-border case handling.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (2)
  1. ProbableCommission for Personal Data Protection — As an EU Member State, Bulgaria applies the GDPR Chapter V transfer regime directly, with CPDP acting as the competent national authority for approving BCRs and contractual clauses for Bulgarian-established controllers.observed
  2. ProbableEDPB — Bulgaria operates a National Schengen Information System (N.SIS) under Ordinance No. 8121з-465 of 26 August 2014, processing data in compliance with EU Regulations 2018/1860-1862, the Ministry of Interior Act, and the Personal Data Protection Act, constituting a sector-specific data-residency arrangement for law-enforcement/immigration alert data.observed

#

Partial coverage: employment and telecoms overlays confirmed; five of seven sub-modules carry an explicit research gap.

Primary frameworkGDPR plus sector-specific national instruments (Labor Code 1986, Electronic Communications Act)
Traffic-light rationale — AmberPartial coverage: employment and telecoms overlays confirmed; five of seven sub-modules carry an explicit research gap.

Sub-modules (7)

Financial Sector OverlayRed

No Bulgaria-specific financial-sector data-protection overlay (e.g., banking-secrecy interplay with GDPR) was identified. Searches run: "Bulgaria financial sector data protection overlay", general CPDP/DataGuidance overview queries.

Health Sector OverlayRed

No Bulgaria-specific health-sector data-protection overlay was identified in this research pass.

Telecoms And EprivacyAmber

The Electronic Communications Act (ECA) is identified as the national instrument intersecting with GDPR/ePrivacy for communications-related personal data.

Claims (1):

  • The Electronic Communications Act is identified as relevant national legislation intersecting with GDPR for communications-related personal data processing, operating alongside the EU ePrivacy framework in Bulgaria.

Employment DataGreen

Employee monitoring in Bulgaria is governed by a multi-instrument overlay: GDPR, the Act, the Labor Code 1986, the ECA, and the Constitution.

Claims (1):

  • Bulgarian employee-monitoring rules draw on GDPR, the Protection of Personal Data Act 2002 (last amended 2023), the Labor Code 1986, the Electronic Communications Act, and the Constitution of the Republic of Bulgaria, creating a multi-instrument overlay governing employer processing of employee personal data.

Credit And ScoringRed

No Bulgaria-specific credit-scoring data-protection overlay was identified in this research pass.

EducationRed

No Bulgaria-specific education-sector data-protection overlay was identified in this research pass.

InsuranceRed

No Bulgaria-specific insurance-sector data-protection overlay was identified in this research pass.

Category narrative42 words

Confirmed sectoral overlay evidence is limited to the employment-data and telecoms/eprivacy domains, where the Labor Code, Electronic Communications Act, and Constitution intersect with GDPR/the Act. No Bulgaria-specific financial-sector, health-sector, credit-scoring, education, or insurance data-protection overlay instruments were identified in this research pass.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. ConfirmedDataGuidance — Bulgarian employee-monitoring rules draw on GDPR, the Protection of Personal Data Act 2002 (last amended 2023), the Labor Code 1986, the Electronic Communications Act, and the Constitution of the Republic of Bulgaria, creating a multi-instrument overlay governing employer processing of employee personal data.observed
  2. ProbableDataGuidance — The Electronic Communications Act is identified as relevant national legislation intersecting with GDPR for communications-related personal data processing, operating alongside the EU ePrivacy framework in Bulgaria.observed

#

Only the cookies/trackers sub-module has confirmed national-instrument grounding; the remaining five sub-modules carry an explicit research gap.

Primary frameworkGDPR plus Electronic Communications Act (ePrivacy implementation)
Traffic-light rationale — AmberOnly the cookies/trackers sub-module has confirmed national-instrument grounding; the remaining five sub-modules carry an explicit research gap.

Sub-modules (6)

Cookies And TrackersAmber

Cookie/tracking consent is governed by the ECA (ePrivacy implementation) alongside GDPR; no additional Bulgaria-specific cookie legislation was identified.

Claims (1):

  • Cookie and electronic-communications tracking consent in Bulgaria is governed by the Electronic Communications Act implementing the ePrivacy Directive, operating alongside GDPR consent standards; no additional Bulgaria-specific cookie legislation was identified in this research pass.

Dark PatternsRed

No Bulgaria-specific dark-pattern prohibition beyond general EDPB guidance (applicable EU-wide) was identified in this research pass. Searches run: general CPDP/DataGuidance overview queries.

Opt Out SignalsRed

No Bulgaria-specific recognition of technical opt-out signals (e.g., Global Privacy Control) was identified.

Clean Rooms And DcrRed

No Bulgaria-specific clean-room/data-collaboration-room rules were identified.

Cross Context AdvertisingRed

No Bulgaria-specific cross-context advertising ('sale'/'share') concept analogous to US state law was identified; GDPR consent/legitimate-interest framework applies as the general floor.

Direct MarketingRed

No Bulgaria-specific direct-marketing consent/suppression rule beyond GDPR Article 21(2)/ECA implementation of ePrivacy Article 13 was identified in this research pass.

Category narrative44 words

Cookie/tracker consent in Bulgaria relies on the Electronic Communications Act implementing the EU ePrivacy Directive alongside GDPR consent standards. No Bulgaria-specific rules on dark patterns, opt-out signals, clean rooms, cross-context advertising, or direct-marketing suppression beyond the GDPR/ePrivacy baseline were identified in this research pass.

Sources and claims (1)
  1. UncertainDataGuidance — Cookie and electronic-communications tracking consent in Bulgaria is governed by the Electronic Communications Act implementing the ePrivacy Directive, operating alongside GDPR consent standards; no additional Bulgaria-specific cookie legislation was identified in this research pass.observed

#

Biometric and state-surveillance-carveout sub-modules are evidenced; profiling/ADM/AI-risk/genetic-data sub-modules default to GDPR baseline without confirmed national specificity, and EU AI Act national-authority designation status for Bulgaria remains unresolved.

Primary frameworkGDPR Article 9 and Article 22, plus Ministry of Interior Act (Directive (EU) 2016/680 transposition) for law-enforcement carve-outs
Traffic-light rationale — AmberBiometric and state-surveillance-carveout sub-modules are evidenced; profiling/ADM/AI-risk/genetic-data sub-modules default to GDPR baseline without confirmed national specificity, and EU AI Act national-authority designation status for Bulgaria remains unresolved.

Sub-modules (6)

Profiling RestrictionsAmber

No Bulgaria-specific derogation to GDPR Article 22 profiling restrictions was identified; GDPR baseline presumed to apply unmodified.

Automated Decision Making TransparencyAmber

No Bulgaria-specific ADM transparency rule beyond GDPR Articles 13(2)(f)/14(2)(g)/15(1)(h) was identified.

Ai Risk AssessmentsRed

Bulgaria's national competent authority designation and implementation status under the EU AI Act was not confirmed in this research pass; flagged as an unresolved question.

Biometric RegimeGreen

CPDP has issued an opinion specifically addressing facial-recognition/biometric processing by retailers, applying Article 9 special-category safeguards.

Claims (1):

  • CPDP issued an opinion addressing the use of facial-recognition and biometric data-processing technology by stores/retailers, applying GDPR Article 9 special-category safeguards to biometric identification systems in Bulgaria.

Genetic DataAmber

No Bulgaria-specific genetic-data regime beyond the GDPR Article 9 special-category baseline was identified.

State Surveillance CarveoutsAmber

Law-enforcement/immigration data processing (e.g., N.SIS alerts) is carried out under the Ministry of Interior Act rather than GDPR directly, reflecting Bulgaria's transposition of Directive (EU) 2016/680, as illustrated in the CJEU C-180/21 referral on the GDPR/LED interplay in prosecutorial processing.

Claims (1):

  • Law-enforcement and immigration data processing in Bulgaria (e.g., National Schengen Information System alerts) is carried out under the Ministry of Interior Act and related ordinances rather than GDPR directly, reflecting transposition of the Law Enforcement Directive (EU) 2016/680, as illustrated by the Bulgarian court's CJEU referral in Case C-180/21 concerning the GDPR/LED interplay in prosecutorial data processing.
Category narrative67 words

Biometric processing (facial recognition) has been addressed directly by CPDP guidance applying GDPR Article 9 to retail use cases. Law-enforcement/immigration processing (e.g., N.SIS) is carved out under the Ministry of Interior Act transposing Directive (EU) 2016/680, illustrated by a Bulgarian-court CJEU referral on the GDPR/LED interplay. Profiling restrictions, ADM transparency, AI-specific risk assessments, and genetic-data regime rely on the unmodified GDPR baseline with no Bulgaria-specific layer identified.

Periodic update · new data 2026-09-14

Algorithmic, Biometric & Surveillance Governance

The Commission for Personal Data Protection is understood to have adopted, in 2025, an official opinion addressing the use of facial recognition technologies in shops. This is interpretive guidance rather than binding rulemaking, reflecting the regulator's evolving approach to biometric surveillance in commercial retail settings, and it has not been independently corroborated beyond a single secondary commentary source this cycle.

Outlook

The item to watch is whether this interpretive opinion is followed by binding rulemaking or enforcement action against a specific retailer's facial-recognition deployment, which would mark a shift from guidance to active supervision in this area.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (2)
  1. ProbableDataGuidance — CPDP issued an opinion addressing the use of facial-recognition and biometric data-processing technology by stores/retailers, applying GDPR Article 9 special-category safeguards to biometric identification systems in Bulgaria.observed
  2. ProbableEDPB — Law-enforcement and immigration data processing in Bulgaria (e.g., National Schengen Information System alerts) is carried out under the Ministry of Interior Act and related ordinances rather than GDPR directly, reflecting transposition of the Law Enforcement Directive (EU) 2016/680, as illustrated by the Bulgarian court's CJEU referral in Case C-180/21 concerning the GDPR/LED interplay in prosecutorial data processing.observed

#

Only a non-binding awareness-activity claim is evidenced; the core binding parental-consent age threshold and other sub-modules carry an explicit, unresolved research gap.

Primary frameworkGDPR Article 8 (children's consent) as applied via the Protection of Personal Data Act
Traffic-light rationale — RedOnly a non-binding awareness-activity claim is evidenced; the core binding parental-consent age threshold and other sub-modules carry an explicit, unresolved research gap.

Sub-modules (5)

Age VerificationRed

The Bulgarian age-of-consent threshold under GDPR Article 8 (default 16, or a national lowering to as low as 13) was not confirmed in this research pass. Searches run: general CPDP/DataGuidance overview queries; a targeted search for the specific statutory age was not conclusive.

Minor Profiling BansRed

No Bulgaria-specific minor-profiling ban beyond the GDPR baseline (recital 38 caution on profiling of children) was identified.

Education SettingsRed

No Bulgaria-specific education-settings data-protection rule was identified in this research pass.

Dependent AdultsRed

No Bulgaria-specific dependent-adults (elderly/incapacitated) data-protection provision was identified in this research pass.

Category narrative46 words

CPDP conducts child-oriented digital-safety and right-of-access awareness activities, including materials for parents. The specific national age-of-consent threshold under GDPR Article 8 (whether Bulgaria retains the default age 16 or has lowered it) was not confirmed in this research pass, nor were minor-profiling-ban, education-setting-specific, or dependent-adult-specific rules.

Periodic update · new data 2026-09-21

Children & Vulnerable Groups

The CPDP's Annual Report for 2025 declares a focus on protecting minors' personal data online, marking children and vulnerable groups as an emerging priority area for Bulgarian data-protection supervision. This is reported at Probable confidence: the declared priority itself is reasonably well evidenced, but the practical supervisory activity that will follow from it, whether new guidance, targeted investigations, or enforcement action specifically concerning minors, has not yet been evidenced this cycle beyond the stated focus.

This declared focus sits alongside, but is currently distinct from, the CPDP's historical enforcement concentration in video surveillance and banking-sector complaints, which together dominate the Commission's current complaint volume. Whether the minors'-data priority will translate into a comparable volume of complaint or enforcement activity in future reporting periods is not yet established from the evidence available this cycle.

Outlook

Future cycles should watch for whether the CPDP's declared focus on minors' personal data online produces concrete regulatory output, such as targeted guidance, a dedicated enforcement action, or a measurable shift in complaint-category volume toward children's and vulnerable-groups matters, none of which has yet been evidenced.

1 earlier distinct update(s)
Periodic update · new data 2026-09-14

Children & Vulnerable Groups

The Commission for Personal Data Protection's Annual Report for 2025 is understood to have declared a focus on protecting minors' personal data online. This reflects an active supervisory priority for the regulator going into the current cycle, though it does not, on the evidence available this cycle, constitute a new binding rule specific to children's data processing.

Outlook

The item to watch is whether this declared supervisory focus translates into concrete guidance, rulemaking, or enforcement action specifically targeting minors' data protection online in the coming cycles.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (1)
  1. ConfirmedEDPB — CPDP has developed child-oriented educational materials, including publications, guidelines, leaflets and videos, and produced advice materials for parents on children's personal data and internet use, as part of its digital-safety and right-of-access awareness activities.observed

#

Regulator powers and recent enforcement/jurisprudential activity are well evidenced; collective-redress, private-right-of-action, and regulator-funding sub-modules carry research gaps.

Primary frameworkGDPR Articles 58, 77-84 as applied by the Commission for Personal Data Protection
Traffic-light rationale — GreenRegulator powers and recent enforcement/jurisprudential activity are well evidenced; collective-redress, private-right-of-action, and regulator-funding sub-modules carry research gaps.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

CPDP can impose administrative fines up to GDPR Article 83 maxima and previously fined the National Revenue Agency BGN 5.1 million for GDPR violations.

Claims (1):

  • CPDP exercises GDPR Article 58 corrective powers, including document-inspection procedures, and can impose administrative fines up to GDPR Article 83 maxima; it previously fined Bulgaria's National Revenue Agency BGN 5.1 million for GDPR violations following a major data leak.

Enforcement Activity IndexGreen

The 2022-2023 LockTrip Ltd. case shows CPDP conducting a formal document-inspection and Article 60 cross-border cooperation procedure with Finland, Spain, and Poland as concerned/commenting supervisory authorities.

Claims (1):

  • In 2022-2023, CPDP conducted a formal document-inspection and Article 60 cooperation procedure regarding a breach notification from LockTrip Ltd., coordinating via the EU Internal Market Information System with Finland and Spain as concerned supervisory authorities and Poland commenting on the draft decision.

Regulator Funding And CapacityRed

No specific CPDP budget/headcount data was identified in this research pass.

Collective Redress And Class ActionsRed

No Bulgaria-specific collective-redress mechanism for data-protection claims (beyond general GDPR Article 80 representative-action provisions) was confirmed in this research pass.

Private Right Of ActionAmber

GDPR Articles 79/82 judicial-remedy and compensation rights apply directly; no Bulgaria-specific procedural variant was confirmed in this research pass.

Recent Developments 180DGreen

CJEU judgment of 9 July 2026 in Case C-199/24 interprets the GDPR Article 85(2) journalistic-purposes exemption strictly; the Bulgarian Government was among the governments submitting observations.

Claims (1):

  • On 9 July 2026, the CJEU delivered judgment in Case C-199/24 interpreting the GDPR Article 85(2) 'journalistic purposes' exemption strictly, with the Bulgarian Government among the governments submitting observations, marking an active EU-level jurisprudential development relevant to national application of journalistic-purpose derogations from GDPR obligations.
Category narrative79 words

CPDP exercises GDPR Article 58 corrective powers up to the Article 83 maximum fines and has a track record of significant enforcement, including a BGN 5.1 million fine against Bulgaria's National Revenue Agency (2019) and an active, EU-cooperative investigation/decision in the LockTrip Ltd. breach case (2022-2023). Recent 180-day-window development: CJEU judgment (9 July 2026) in Case C-199/24 on the GDPR Article 85 journalistic-purposes exemption, with the Bulgarian Government among the intervening governments, bearing on national application of that derogation.

Periodic update · new data 2026-09-28

Enforcement & Redress

Bulgaria's enforcement and redress posture is defined this cycle by a transparency contraction at the Commission for Personal Data Protection (CPDP). The CPDP is understood to have published no publicly available enforcement decisions in either 2024 or 2025, a reversal from an earlier practice of publishing selected decisions. This claim is sourced to Tier-3 commentary rather than the CPDP's own decisions register, and has not been independently corroborated against that register this cycle, so the finding should be read as probable rather than settled fact.

The CPDP's formal sanctioning power has not diminished alongside this apparent publication gap. The CPDP may impose administrative fines of up to EUR 20,000,000 or 4% of worldwide annual turnover under Article 83 GDPR, the standard ceiling applied across GDPR supervisory authorities, together with non-monetary sanctions including warnings and injunctions. The combination of a confirmed, unchanged, high statutory ceiling and a reported absence of published decisions creates an interpretive tension: either enforcement activity has genuinely slowed, or it continues but is no longer being made public in the way it once was. The evidence available this cycle does not resolve which explanation applies.

A separate and independently significant redress development is the Bulgarian Supreme Administrative Court's referral of questions on state liability for GDPR-breach damages to the Court of Justice of the European Union for a preliminary ruling. The referral arises from the National Revenue Agency's 2019 data leak, a long-running matter now reaching the CJEU on the specific question of whether and how the Bulgarian state can be held liable in damages for the consequences of that breach. This is a pending referral, not a decided case, and the evidence available this cycle does not establish an expected ruling date.

Read together, the two developments describe an enforcement and redress landscape in Bulgaria that is more active in the courts than it appears to be in the regulator's own public decision-making record. The private right of action against the state, now before the CJEU, sits alongside a regulator whose own visible enforcement footprint has contracted.

Outlook

The CJEU's eventual ruling on state liability for GDPR-breach damages will be the most consequential development to watch, though no expected timeline has been established this cycle. In parallel, confirming or disconfirming the CPDP's reported 2024-2025 decision-publication gap against the CPDP's own public register would materially change how the enforcement posture should be read: a genuine slowdown in enforcement activity is a different finding from a change in publication practice that leaves underlying enforcement unaffected. Neither has been distinguished by the evidence available this cycle.

2 earlier distinct update(s)
Periodic update · new data 2026-09-21

Enforcement & Redress

The CPDP's complaint data for 2025 shows a clear concentration pattern: video surveillance leads with 425 complaints, followed by banks and credit institutions in second place with 131 complaints. The banking-sector complaints chiefly concern unlawful disclosure of personal data to debt collectors, a specific and identifiable friction point rather than a diffuse category of financial-sector grievance. Both figures are reported at Probable confidence, sourced from CMS's GDPR enforcement tracker report on Bulgaria.

The Commission's largest sanction on record is a fine issued against the National Revenue Agency following a large-scale personal-data breach, underlying figure BGN 5.1 million, with minor variation across sources in the EUR-equivalent conversion reported. This remains the CPDP's most significant punitive action to date and demonstrates that the Commission's largest enforcement outcome to date has been directed against a state body rather than a private-sector controller. Separately, most CPDP punitive proceedings in the recent reporting period concern processing without a legal basis under GDPR Article 6(1) and breaches of the Article 5(1) principles, indicating that the Commission's enforcement focus concentrates on foundational lawful-basis and principles compliance rather than more specialised violation categories.

Looking beyond Bulgaria's own enforcement activity, Regulation (EU) 2025/2518, which lays down additional procedural rules for cross-border GDPR enforcement, has been enacted but is not yet effective; it will apply from April 2027. This gives Bulgarian controllers and the CPDP a defined preparation period ahead of a materially more harmonised cross-border enforcement procedure across the EU.

Outlook

The rising banking-sector complaint volume, driven by unlawful disclosure to debt collectors, is worth monitoring for whether it produces a dedicated CPDP enforcement action in a future cycle, distinct from the video-surveillance category that currently dominates complaint volume. Separately, the April 2027 application date for Regulation (EU) 2025/2518 sets a clear horizon marker for when Bulgaria's cross-border enforcement procedure will materially change.

Periodic update · new data 2026-09-14

Enforcement & Redress

The highest GDPR fine imposed in Bulgaria to date, BGN 5.1 million, was levied against the National Revenue Agency, and this figure remains the benchmark enforcement figure for the jurisdiction. This finding is corroborated across two independent commentary sources and is rated Confirmed.

More recently, a Sofia City Administrative Court decision dated 5 January 2026 reduced the financial penalty against Bulgarian Post EAD, a fine originally connected to its 2022 data-breach case. This is a recent, within-180-day-window development that signals a functioning judicial appeal mechanism materially tempering the CPDP's headline enforcement figures, and it should be read alongside the NRA benchmark fine as evidence that Bulgaria's enforcement regime includes meaningful judicial checks rather than unreviewable regulatory penalties.

Outlook

The item to watch is whether the judicial-moderation pattern seen in the Bulgarian Post EAD case recurs in other pending CPDP enforcement matters, which would further establish judicial review as a structural feature of Bulgaria's GDPR enforcement landscape rather than an isolated outcome.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (3)
  1. ConfirmedIAPP — CPDP exercises GDPR Article 58 corrective powers, including document-inspection procedures, and can impose administrative fines up to GDPR Article 83 maxima; it previously fined Bulgaria's National Revenue Agency BGN 5.1 million for GDPR violations following a major data leak.observed
  2. ConfirmedEDPB / CPDP — In 2022-2023, CPDP conducted a formal document-inspection and Article 60 cooperation procedure regarding a breach notification from LockTrip Ltd., coordinating via the EU Internal Market Information System with Finland and Spain as concerned supervisory authorities and Poland commenting on the draft decision.observed
  3. ConfirmedEUR-Lex — On 9 July 2026, the CJEU delivered judgment in Case C-199/24 interpreting the GDPR Article 85(2) 'journalistic purposes' exemption strictly, with the Bulgarian Government among the governments submitting observations, marking an active EU-level jurisprudential development relevant to national application of journalistic-purpose derogations from GDPR obligations.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct66.67
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Bulgaria
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 26 claim(s) (26 category placement(s)), 27 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Modules regulator_and_framework, controller_processor_duties, and enforcement_and_redress achieved the strongest grounding, anchored in a T1 published CPDP final decision (LockTrip Ltd.), T1 CJEU case law (C-180/21, C-199/24), and T2 EDPB reports. lawful_processing_and_special_data and cross_border_and_adequacy achieved partial T1/T2 grounding with some sub-modules (consent_thresholds; adequacy_received/granted, structurally N/A) resting on baseline GDPR inference. sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups relied predominantly on T3 secondary sources (DataGuidance) for the sub-modules that had any evidence at all, with multiple sub-modules (financial/health/credit/education/insurance overlays; dark patterns; opt-out signals; clean rooms; cross-context advertising; AI risk assessments; age verification) carrying explicit absent_field_provenance gaps.

Unresolved questions (6):

  • What is Bulgaria's specific statutory age of consent for children's data processing under GDPR Article 8 (default 16, or nationally lowered)?
  • Are there Bulgaria-specific financial-sector, health-sector, credit-scoring, education-sector, or insurance-sector data-protection overlay instruments beyond GDPR?
  • What is Bulgaria's national competent authority designation and implementation timeline under the EU AI Act?
  • Does Bulgaria have a dedicated cookie-consent statute or CPDP-specific cookie guidance beyond the general Electronic Communications Act reference?
  • What is CPDP's current (2025-2026) enforcement-activity volume and fine total beyond the two historical cases identified (NRA 2019, LockTrip 2022-2023)?
  • Is there a Bulgaria-specific collective-redress or class-action mechanism for data-protection claims beyond GDPR Article 80 representative actions?

Escalate to primary-source review: yes