Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Regulation (EU) 2016/679, Arts. 33-34
stage In effect
since 2018-05-25
source GDPR Arts. 33-34
A controller must notify KZLD within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. Commentary adds a procedural detail, that KZLD maintains non-public breach registers and approved notification templates in Bulgarian only, which is a procedural addition rather than a substantive derogation from the 72-hour standard; no primary text was read.
What it asks of an app →
Comprehensive regime
cite Закон за защита на личните данни (ЗЗЛД), Obn. DV. br.1 ot 4 yanuari 2002 g., as amended (English: Personal Data Protection Act, State Gazette No. 1 of 4 January 2002, as amended)
stage In effect
since 2019-02-26
source CMS and DLA Piper commentary only
Bulgaria gives the General Data Protection Regulation (GDPR) domestic effect through the Personal Data Protection Act (Закон за защита на личните данни, PDPA), originally promulgated 4 January 2002, predating the GDPR like Hungary's act though far less substantially rewritten, and substantially amended 26 February 2019 for GDPR alignment.
This session could not read the Act's primary text: cpdp.bg, the Bulgarian data protection commission's own site, served only WordPress and emoji-polyfill JavaScript to a direct fetch and to a crawler-based reader, confirmed on repeated attempts. Every finding below rests on two commentary sources (CMS, DLA Piper) rather than a primary-source read.
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-49, 83(5)(c)
stage In effect
since 2018-05-25
source GDPR Arts. 44-49, 83(5)(c)
A transfer of personal data outside the EEA requires an adequacy decision, appropriate safeguards, or a narrow Article 49 derogation, backed by the Article 83(5)(c) top fine tier. DLA Piper's commentary states no Bulgarian derogations exist and General Data Protection Regulation (GDPR) Articles 44-49 apply directly without modification; no primary text was read.
What it asks of an app →
Data subject rights
cite Regulation (EU) 2016/679, Arts. 12-22
stage In effect
since 2018-05-25
source GDPR Arts. 12-22
General Data Protection Regulation (GDPR) Articles 12-22 apply directly. No Bulgaria-specific derogation was found beyond the employment and national-ID-number rules described above, per two commentary sources; no primary text was read.
What it asks of an app →
Enforcement supervision
cite Regulation (EU) 2016/679, Arts. 82-83
stage In effect
since 2018-05-25
source GDPR Arts. 82-83
Комисия за защита на личните данни (KZLD, English: Commission for Personal Data Protection) is Bulgaria's supervisory authority; an Inspectorate with the Supreme Judicial Council holds a parallel, narrower oversight role whose exact scope was not established in this pass. General Data Protection Regulation (GDPR) Article 82 arms an individual with a direct private right of action.
Commentary describes a Bulgarian procedural avenue, a complaint to KZLD within 6 months of discovering a violation or a direct administrative court claim, mutually exclusive where Commission proceedings on the same matter are already pending; this is an administrative-enforcement and judicial-review structure rather than a distinct civil damages remedy beyond Article 82, and is recorded here as procedural rather than folded into the private-right-of-action finding's basis.
What it asks of an app →
Sensitive categories
cite Regulation (EU) 2016/679, Art. 9; PDPA (ЗЗЛД), employment and ЕГН provisions
stage Enacted
source CMS and DLA Piper commentary only
General Data Protection Regulation (GDPR) Article 9(1) treats biometric data processed for unique identification as a special category.
Two commentary sources agree Bulgaria has not adopted a distinct biometric restriction beyond GDPR; the Act's own additions described in commentary sit instead in employment data (identification-document copies only if required by law, criminal-background-check information only under explicit legal authorization rather than consent or legitimate interest, a 6-month recruitment-data retention cap) and in protecting the Bulgarian national identification number (ЕГН, Edinen grazhdanski nomer, Unified Civil Number, English: EGN): public access only if required by law, with technical measures required to prevent its use as a sole service identifier.
None of this was independently verified against the Act's own text this session. No commencement date is recorded for this instrument: this document rests entirely on commentary with no primary-source text read, and status is downgraded from in_effect to enacted rather than asserting an unconfirmed effective date.
What it asks of an app →