Law note · Bulgaria

GDPR Articles 33-34, Breach Notification

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2018-05-25 reviewed 2026-08-24

A controller must notify KZLD within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. Commentary adds a procedural detail, that KZLD maintains non-public breach registers and approved notification templates in Bulgarian only, which is a procedural addition rather than a substantive derogation from the 72-hour standard; no primary text was read.

What it asks of an app

  • Notify KZLD within 72 hours of becoming aware of a personal-data breach affecting a person in Bulgaria, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them, using KZLD's own Bulgarian-language notification template.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, processes_biometrics

Primary source: GDPR Arts. 33-34
DLA Piper commentary

← Back to the example  ·  Lint your app →