Law note · Bulgaria
Personal Data Protection Act (Zakon za zashtita na lichnite danni, ZZLD)
Bulgaria gives the General Data Protection Regulation (GDPR) domestic effect through the Personal Data Protection Act (Закон за защита на личните данни, PDPA), originally promulgated 4 January 2002, predating the GDPR like Hungary's act though far less substantially rewritten, and substantially amended 26 February 2019 for GDPR alignment.
This session could not read the Act's primary text: cpdp.bg, the Bulgarian data protection commission's own site, served only WordPress and emoji-polyfill JavaScript to a direct fetch and to a crawler-based reader, confirmed on repeated attempts. Every finding below rests on two commentary sources (CMS, DLA Piper) rather than a primary-source read.
What it asks of an app
- Establish a General Data Protection Regulation (GDPR) Article 6 lawful basis before processing personal data of a person in Bulgaria; this document could not confirm the Act's own text and any Bulgarian-specific addition to that basis is unverified.
When LexLint raises it
Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics
Primary source: CMS and DLA Piper commentary only
cpdp.bg confirmed unreadable (JavaScript shell, not the document)