World Watch/Bulgaria/Data & Privacy

Data & Privacy · Bulgaria

Data protection & privacy laws in Bulgaria (2026)

Comprehensive lawEU GDPR (Regulation (EU) 2016/679) directly applicable, supplemented by Bulgaria's Personal Data Protection Act (PDPA, State Gazette No. 17/26.02.2019, in force 2 March 2019); supervised by the Commission for Personal Data Protection (CPDP)Country index 96 · A+

Bulgaria shaded by its data & privacy status

Bulgaria operates under the EU GDPR as the primary binding framework, complemented by the national PDPA which exercises permitted national discretions covering employment data, children's consent for digital services, personal identification numbers, and data of deceased persons. The Commission for Personal Data Protection (CPDP) is the independent supervisory authority, while the Inspectorate to the Supreme Judicial Council holds concurrent competence for judicial-body processing. NIS2 transposition via Cybersecurity Act amendments entered into force in February 2026, integrating incident-reporting pathways with GDPR breach notification.

Key points

Primary Legal Basis

The GDPR applies directly as EU law. The national PDPA (State Gazette No. 17/26.02.2019) supplements it without repeating GDPR provisions, exercising national discretions permitted by Articles 6(2), 9(4), and 88, replacing the prior 2002 Data Protection Act.

Supervisory Authority

The Commission for Personal Data Protection (CPDP), an independent body comprising a chairman and four members, is the lead supervisory authority for both GDPR and PDPA compliance. The Inspectorate to the Supreme Judicial Council holds concurrent competence exclusively for data processing by courts, prosecution offices, and criminal investigative bodies acting as judicial authorities.

National PDPA Specifics

The PDPA addresses areas where GDPR grants member-state discretion: employment-related data processing, a 14-year age threshold for children's consent to information-society services, use of personal identification numbers, freedom of expression and journalism exemptions, and processing of data belonging to deceased individuals.

Enforcement Record

The largest GDPR enforcement action in Bulgaria was a BGN 5.1 million (~€2.61 million) fine against the National Revenue Agency following unlawful access and online distribution of personal data of more than 6 million individuals. Routine CPDP sanctions have generally been modest (BGN 1,000–10,000), partly due to resource constraints and governance issues within the commission.

Whistleblower Protection Integration

Since May 2023, the CPDP has been additionally designated as the competent controlling body under the Bulgarian Whistleblower Protection Act, expanding its regulatory remit beyond personal data supervision.

NIS2 & Harmonised Incident Reporting

Bulgaria's Cybersecurity Act amendments transposing the NIS2 Directive entered into force on 17 February 2026 following significant delay (the EU Commission issued a reasoned opinion for non-transposition in May 2025). The framework establishes a single-entry notification point harmonising breach-reporting obligations across NIS2, GDPR, DORA, and eIDAS.

Bulgaria - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →