Skip to the content
Global Data RulesData governance rules, country by country

Bulgaria

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Depends on your industryWork: MediumEnforcement: Active

Bulgaria is an ordinary European Union country for data. Personal data can leave, as long as you use one of the standard European transfer tools. There is no general rule forcing data to stay in Bulgaria. But online gambling is a hard exception: a control server must physically sit on Bulgarian soil. Bulgaria switched to the euro on 1 January 2026, so all fines are now in euro.

Eight questions about Bulgaria

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Bulgaria's rules apply to my company?

Yes, it can reach you with no office in Bulgaria. The European Union's privacy rulebook applies to anyone who offers goods or services to people in Europe or watches what they do online. Bulgaria's own Personal Data Protection Act sits on top of that and adds extra local duties. There is no revenue or headcount threshold, and no Bulgaria-specific representative: the European-wide requirement to name a representative in Europe is the only one, and it can be in any European country.

High confidenceAppoint a local representativeAppoint a data protection officercontrollerprocessor

Can I store my users' data outside Bulgaria?

In general, yes. Bulgaria has no law telling ordinary businesses to keep personal data inside the country. Data moves freely to the rest of Europe, to Switzerland, and to countries Europe has approved; anywhere else needs a standard contract or a similar tool. Two industries break that pattern. Online gambling operators must keep a control server physically in Bulgaria. Telecoms operators must build interception equipment that plugs into Bulgarian state agencies, which cannot sit abroad.

High confidenceDepends on your industryBlocklistOnline gamingTelecomsMapping and location

What do I need in place before data leaves Bulgaria?

Bulgaria uses Europe's system, not its own. There is no Bulgarian list of banned countries and no Bulgarian permit to apply for. If the destination is inside Europe, the wider European Economic Area or Switzerland, nothing extra is needed. Otherwise you need either an official European approval of that country, or the standard European contract, or approved group-wide rules. One Bulgarian twist: Bulgarian law explicitly puts Switzerland on the same footing as a European Union country.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesExplicit consentNeeded for a contractLegal claims

Who enforces the rules in Bulgaria, and what can they do?

The Commission for Personal Data Protection is the main regulator. It is real, staffed and it does issue formal decisions, including ones published across Europe. But it is not a heavy hitter. In a Europe-wide check on deletion rights reported in February 2026, it contacted twenty-three organisations, opened no formal investigations, imposed no penalties, and said it did not plan to. A separate inspectorate polices the courts and prosecutors. Cybersecurity has its own separate regulators.

Medium confidenceActiveRegulator

How long do I have to keep the data?

Bulgaria has strong minimum-keeping rules and a few sharp delete-by rules. You must keep payroll records for fifty years, accounting books and financial statements for ten years, and other accounting papers for three years. Telecoms firms keep connection records for six months. Going the other way, job applicants' data must be deleted within six months unless they agree otherwise, and data you were given with no legal basis must be returned or destroyed within one month.

High confidenceKeep data for a minimum periodDelete data after a periodEmployee dataTelecom network data

What happens if there is a breach?

There are at least three clocks and they do not agree. A personal data breach must reach the privacy regulator within seventy-two hours. Under the cybersecurity law rewritten in February 2026, an early warning must reach the response team within twenty-four hours and a fuller report within seventy-two hours. Trust service providers get twenty-four hours for that fuller report. Financial firms answer to the separate European financial-resilience rules on top.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Bulgaria?

Five things bite people in Bulgaria. You may not photocopy someone's identity card, driving licence or residence permit unless a law lets you. Children need a parent's consent up to age fourteen, not sixteen. Job applicant files must go within six months. Your accounting software must be able to output in Bulgarian. And one clause of the privacy law was struck down by the Constitutional Court in 2019 but is still printed in the statute.

High confidenceGet a parent's consent for childrenAppoint a data protection officerDelete data after a periodUnenforceable

What is changing soon in Bulgaria?

Two dated changes are already fixed. From 12 January 2027 every cloud provider must let customers move their data out for free. Bulgaria's new cybersecurity duties started on 13 February 2026 and enforcement is only now warming up. The biggest live risk is not Bulgarian at all: Europe's approval of United States data transfers is being challenged, and Europe's own privacy board asked the Commission on 31 July 2026 to re-examine it.

High confidenceMake switching cloud provider possibleIn forceProposed

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    1 rule here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    3 rules here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    7 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules1 rule

Регламент (ЕС) 2016/679 (Общ регламент относно защитата на данните)

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

Europe's privacy rulebook is the base layer in Bulgaria. It does not require data to stay in Europe. It regulates the conditions on which data leaves, and it is where almost all of the compliance work sits.

In force since 25 May 2018

Enforced by Commission for Personal Data Protection

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Important public interest, Someone's life is at risk

High confidence

National rules3 rules

Закон за защита на личните данни

Act of parliament · State Gazette No. 1 of 4 January 2002; rewritten by State Gazette No. 17 of 26 February 2019; last amendment traced State Gazette No. 84 of 6 October 2023

In forceYes — store it anywhere

Bulgaria's own privacy statute. It adds no residency rule at all, but it does add real national duties on children, employees, identity documents and the data protection officer. It also treats Switzerland as if it were a European Union country.

In force since 1 January 2002But only enforceable from 2 March 2019

Enforced by Commission for Personal Data Protection

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence

Решение № 8 от 2019 г. на Конституционния съд на Република България

court decision · Published in State Gazette No. 93 of 26 November 2019; declares Article 25z(2) of the Personal Data Protection Act unconstitutional

UnenforceableYes — store it anywhere

The privacy law still prints ten criteria for balancing journalism against privacy. The Constitutional Court declared that paragraph unconstitutional in 2019 and it cannot be enforced. The penalty article was never tidied up and still lists it.

In force since 26 November 2019

Enforced by Constitutional Court of the Republic of Bulgaria

Medium confidence

Закон за киберсигурност, изменен и допълнен

Act of parliament · Original: State Gazette No. 94 of 13 November 2018. Transposing amendment: State Gazette No. 17 of 13 February 2026, in force on publication

In forceYes — store it anywhere

Bulgaria's cybersecurity law was rewritten in February 2026 to bring in Europe's network and information security directive. It imposes no data localisation, but it does impose new reporting clocks and turnover-based fines, and it replaced the old two-hour reporting rule.

In force since 13 February 2026

Enforced by Ministry of Electronic Governance

High confidence

Industry rules7 rules

Закон за хазарта

Act of parliament · State Gazette No. 26 of 30 March 2012; last amendment State Gazette No. 26 of 27 March 2025; Article 6 · Online gaming

In forceA copy must stay

The one genuine Bulgarian data-residency wall. A licensed online gambling operator must keep a control server holding all its data physically inside Bulgaria and stream live game session data to the tax authority.

In force since 1 July 2012

Enforced by National Revenue Agency

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

High confidence

Закон за електронните съобщения, чл. 251б – 251и, чл. 304 – 307

Act of parliament · State Gazette No. 41 of 22 May 2007; retention chapter inserted by State Gazette No. 24 of 2015, in force 31 March 2015 · Telecoms

Partly in forceYes, with paperwork

Telecoms operators must keep six months of connection records and build interception equipment wired into two Bulgarian state agencies. The law does not say where the retained records must physically sit, but the interception equipment cannot be run from abroad.

In force since 31 March 2015

Enforced by Communications Regulation Commission

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

High confidence

Решение № 8 от 23 юни 2026 г. на Конституционния съд по к.д. № 19/2025 г.

court decision · Published in State Gazette No. 60 of 1 July 2026 · Telecoms

UnenforceableYes, with paperwork

In June 2026 the Constitutional Court struck down the parts of the telecoms law that let the competition regulator pull six months of people's connection records for ordinary competition investigations. The wording is still in the printed statute but cannot be used.

In force since 1 July 2026

Enforced by Constitutional Court of the Republic of Bulgaria

High confidence

Who you would hear from

  • Комисия за защита на личните данни

    General privacy law supervision under the European rulebook and the Personal Data Protection Act

    Staffed and issuing formal decisions; its decisions appear in the European Data Protection Board's document library and it took part in the Board's 2025 coordinated enforcement action. Its posture is cautious: in that action, reported in February 2026, it contacted 23 controllers, opened no formal investigations and imposed no corrective measures or fines, and said it did not plan to. Its own website returned a server error on every attempt from our infrastructure on 18 August 2026, so its 2025 annual report figures and the current composition of the commission could not be verified directly.

  • Инспекторат към Висшия съдебен съвет

    Supervises personal data processing by courts, prosecutors and investigating bodies acting in their judicial capacity

    A second, separate data protection supervisor created by Article 1(4)(2) of the Personal Data Protection Act. Its chief inspector issues penalty orders in its own right.

  • Министерство на електронното управление

    E-government, the shared state cloud, and the register of essential and important entities under the cybersecurity law

  • Комисия за регулиране на съобщенията

    Electronic communications networks and services

  • Национална агенция за приходите

    Tax, accounting records, and since 2020 the licensing and supervision of gambling including the local-server rule

  • Българска народна банка

    Banking supervision and payment systems; part of the euro area since 1 January 2026

  • Комисия за финансов надзор

    Insurance, pensions and securities markets

  • Държавна агенция "Национална сигурност"

    National security, anti-money-laundering financial intelligence, and clearance for aerial survey work

  • Агенция по геодезия, картография и кадастър

    Cadastre and the state Geo-Cartographic Fund

  • Конституционен съд на Република България

    Constitutional review; has repeatedly struck down parts of the telecoms data retention and access regime

    Active in this field. Decision No. 2 of 2015 struck down the earlier retention chapter, Decision No. 15 of 2020 struck down pandemic-era access wording, and Decision No. 8 of 23 June 2026 struck down competition-regulator access to retained traffic data.

  • Министерство на здравеопазването

    Health policy and the National Health Information System, which centrally holds electronic referrals and prescriptions

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The Commission for Personal Data Protection's 2025 enforcement statistics — number of complaints, inspections, fines and their total value

    The regulator's own website, cpdp.bg, returned an HTTP 503 server error on every attempt from our infrastructure on 18 August 2026, including its published 2025 annual report. We therefore relied on the European Data Protection Board's February 2026 coordinated-enforcement annex for its posture instead. Enforcement is rated active on that basis, but the rating is one notch less certain than usual.

  • The current composition of the Commission for Personal Data Protection — whether the chair and members are within a valid mandate or serving on after expiry

    Secondary Bulgarian media reporting suggests a selection procedure for new leadership has been running. The National Assembly's own appointments page is rendered by JavaScript and returned no readable content, and the regulator's site was unreachable. We could not verify this from a government source and do not assert it.

  • Whether the Personal Data Protection Act has been amended after State Gazette No. 84 of 6 October 2023, in particular for the euro changeover on 1 January 2026

    The consolidated text we verified carries amendments only to October 2023. Bulgaria's adoption of the euro means lev amounts in statutes are now read in euro at the fixed rate, but we could not confirm whether the Act's own text was formally amended.

  • Retention periods for medical records held by Bulgarian healthcare providers

    The National Health Insurance Fund's guidance pages were protected by an anti-bot challenge and returned HTTP 403, and the Ministry of Health e-health page carries no ordinance references. We did not want to assert periods we could not read in an official text.

  • Bulgaria's Standard Audit File for Tax (SAF-T) phase-in dates and scope

    The National Revenue Agency's SAF-T pages and question-and-answer documents refused connections from our infrastructure. Bulgaria clearly has a SAF-T programme, with the Agency writing to around 470 large taxpayers about a first reporting period, but we could not read the official dates and thresholds, so we have not stated them as fact.

  • The five-year record-keeping period under Bulgaria's anti-money-laundering law

    This is a standard European requirement and almost certainly applies, but we did not fetch the operative Bulgarian article from a government source within this run, so it is not asserted in the retention answer.

  • Whether any Bulgarian banking, insurance or securities regulator circular imposes a data location or in-country hosting condition

    We searched the Bulgarian National Bank's and the Financial Supervision Commission's own legal frameworks and found no such requirement, but their ordinance libraries are large and we did not read every circular. Recorded as 'no rule found, checked 18 August 2026', not as 'there is no rule'.

  • Whether the six-month telecoms retention regime survives European Union law challenge in its current form

    The Court of Justice has repeatedly held general and indiscriminate retention incompatible with European Union law, and Bulgaria's own Constitutional Court has trimmed the access rules three times. Operators still retain for six months. Whether and when the underlying obligation itself falls is not something we can state.

  • The exact date on which Constitutional Court decisions take legal effect

    Bulgarian constitutional practice is that a decision takes effect a short fixed period after publication in the State Gazette. We recorded the publication dates (26 November 2019 and 1 July 2026) rather than assert an effective date we did not read in an official text.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.