Law note · Bulgaria

GDPR Article 9 and PDPA Employment and National-ID-Number Rules

cite Regulation (EU) 2016/679, Art. 9; PDPA (ЗЗЛД), employment and ЕГН provisions stage Enacted reviewed 2026-08-24

General Data Protection Regulation (GDPR) Article 9(1) treats biometric data processed for unique identification as a special category.

Two commentary sources agree Bulgaria has not adopted a distinct biometric restriction beyond GDPR; the Act's own additions described in commentary sit instead in employment data (identification-document copies only if required by law, criminal-background-check information only under explicit legal authorization rather than consent or legitimate interest, a 6-month recruitment-data retention cap) and in protecting the Bulgarian national identification number (ЕГН, Edinen grazhdanski nomer, Unified Civil Number, English: EGN): public access only if required by law, with technical measures required to prevent its use as a sole service identifier.

None of this was independently verified against the Act's own text this session. No commencement date is recorded for this instrument: this document rests entirely on commentary with no primary-source text read, and status is downgraded from in_effect to enacted rather than asserting an unconfirmed effective date.

What it asks of an app

  • Obtain an explicit General Data Protection Regulation (GDPR) Article 9(2) legal basis before processing biometric, health, or other special-category personal data of a person in Bulgaria.
  • Do not use the Bulgarian national identification number (ЕГН) as a sole service identifier, and grant public access to it only where required by law, per commentary describing the PDPA; verify against the Act's own text before relying on it.

When LexLint raises it

Declared activities: processes_biometrics, processes_voice, high_risk_decisions

Primary source: CMS and DLA Piper commentary only
Act's own text not read this session

← Back to the example  ·  Lint your app →