Law note · Bulgaria
GDPR Article 9 and PDPA Employment and National-ID-Number Rules
General Data Protection Regulation (GDPR) Article 9(1) treats biometric data processed for unique identification as a special category.
Two commentary sources agree Bulgaria has not adopted a distinct biometric restriction beyond GDPR; the Act's own additions described in commentary sit instead in employment data (identification-document copies only if required by law, criminal-background-check information only under explicit legal authorization rather than consent or legitimate interest, a 6-month recruitment-data retention cap) and in protecting the Bulgarian national identification number (ЕГН, Edinen grazhdanski nomer, Unified Civil Number, English: EGN): public access only if required by law, with technical measures required to prevent its use as a sole service identifier.
None of this was independently verified against the Act's own text this session. No commencement date is recorded for this instrument: this document rests entirely on commentary with no primary-source text read, and status is downgraded from in_effect to enacted rather than asserting an unconfirmed effective date.
What it asks of an app
- Obtain an explicit General Data Protection Regulation (GDPR) Article 9(2) legal basis before processing biometric, health, or other special-category personal data of a person in Bulgaria.
- Do not use the Bulgarian national identification number (ЕГН) as a sole service identifier, and grant public access to it only where required by law, per commentary describing the PDPA; verify against the Act's own text before relying on it.
When LexLint raises it
Declared activities: processes_biometrics, processes_voice, high_risk_decisions
Primary source: CMS and DLA Piper commentary only
Act's own text not read this session