Bulgaria
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Bulgaria — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Bulgaria is an ordinary European Union country for data. Personal data can leave, as long as you use one of the standard European transfer tools. No general rule forces data to stay in Bulgaria. Online gambling is the exception. A control server must physically sit on Bulgarian soil. Bulgaria switched to the euro on 1 January 2026, so all fines are now in euro.
Data governance in Bulgaria
The eight things that decide how you handle data about people in Bulgaria. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes, it can reach you when you have no office in Bulgaria. The European Union's privacy rulebook applies to anyone who offers goods or services to people in Europe. It also applies to anyone who watches what they do online. Bulgaria's own Personal Data Protection Act sits on top and adds extra local duties. There is no revenue or staff-count threshold. Bulgaria does not demand its own local representative. The European-wide duty to name a representative in Europe is the only one, and that person can be in any European country.
- What you have to do here:
- Appoint a representative · Appoint a data protection officer
The Personal Data Protection Act (Закон за защита на личните данни, promulgated in State Gazette No. 1 of 4 January 2002, comprehensively rewritten by State Gazette No. 17 of 26 February 2019) says in Article 1(1) that it governs matters 'in so far as they are not governed by Regulation (EU) 2016/679'. So the General Data Protection Regulation does the heavy lifting on who is covered, through its Article 3. The Bulgarian Act adds national rules on top. Two Bulgarian points matter here. Article 1(7) treats the European Economic Area states AND Switzerland as equal to European Union member states. So a transfer to Switzerland is not a transfer to a third country under Bulgarian law at all. Article 1(6) leaves out data about dead people, except for the narrow case in Article 25e. Article 1(5) leaves out national defence and national security work, unless a special law says otherwise. There is no registration or licensing step before you may use personal data. But Article 25b applies to every company, and to every supplier that handles data for them. You must tell the regulator your data protection officer's name, Bulgarian personal identification number and contact details. You must also report any later change.
Sources
- Official sourceAgency for Public Enterprises and Control, Republic of BulgariaPersonal Data Protection Act (Закон за защита на личните данни), consolidated text, Articles 1 and 25b
aref.government.bg
“Този закон урежда обществените отношения, свързани със защитата на правата на физическите лица при обработване на личните им данни, доколкото същите не са уредени в Регламент (ЕС) 2016/679.”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Article 3 territorial scope
eur-lex.europa.eu
Link checked 18 August 2026
Where the data is allowed to live
In general, yes. Bulgaria has no law telling ordinary businesses to keep personal data inside the country. Data moves freely to the rest of Europe, to Switzerland, and to countries Europe has approved. Anywhere else needs a standard contract or a similar tool. Two industries are different. Online gambling operators must keep a control server physically in Bulgaria. Telecoms operators must build interception equipment that plugs into Bulgarian state agencies, and that cannot sit abroad.
Industry by industry, checked 18 August 2026. ONLINE GAMBLING — a copy must stay in the country The Gambling Act (Закон за хазарта) Article 6(1)(2) covers the communications equipment and the central point housing the central computer system. Both must be in Bulgaria or another European Union member state. Article 6(4) goes further. ALL data must be stored on a data storage device, a 'control local server', located on the territory of the Republic of Bulgaria. Article 6(2) says 'territory of the Republic of Bulgaria' means only the geographic territory of the country. Article 6(1)(4) requires a system feeding session information in real time to a server of the National Revenue Agency. This is the only strict keep-it-in-Bulgaria rule we found. TELECOMS — data can leave only if conditions are met in law, but Bulgarian equipment on the ground. The Electronic Communications Act (Закон за електронните съобщения) Article 251b makes providers of public electronic communications networks or services keep six categories of connection data for six months. The Act does NOT say where that data must sit. But Articles 304, 305 and 307 make operators provide, install and maintain interception interfaces at their own expense. Those interfaces feed the State Agency for Technical Operations and the State Agency for National Security. Operators must also hand over encrypted traffic in its original form. That is a duty to build physical equipment in Bulgaria, not a rule about where data lives. BANKING, PAYMENTS, INSURANCE, SECURITIES — data can leave only if conditions are met We found no Bulgarian rule about where data must sit, checked 18 August 2026. The Credit Institutions Act Article 62 imposes bank secrecy. That restricts WHO may see data, not WHERE it sits. The European Union's Digital Operational Resilience Act governs outsourcing. It requires the contract to say where data is handled, but it does not require data to stay in any country. HEALTH — data can leave only if conditions are met We found no rule forcing data to stay in Bulgaria. The National Health Information System is a central state system run by the Ministry of Health. So state-held electronic prescription and referral data is in Bulgaria by design. Private clinics are not told where to host their own records. GOVERNMENT — data can leave only if conditions are met The Electronic Governance Act defines a 'State hybrid private cloud' as central state infrastructure. The State Agency, and later the Ministry of Electronic Governance, build and share it. Neither that Act nor the ordinance on general requirements for information systems says public bodies' data must stay in Bulgaria. Public buying rules push systems into the state cloud anyway. MAPPING AND GEOSPATIAL — data can leave only if conditions are met, with a permit before you collect. The Geodesy and Cartography Act Article 15(2) requires aerial photography and other remote-sensing work to be cleared in advance. Five bodies must clear it: the Ministry of Defence, the Ministry of the Interior, the State Agency for National Security, the Ministry of Foreign Affairs and the transport ministry. Article 20 requires state-commissioned survey material to be deposited in the state Geo-Cartographic Fund. Article 21 keeps aerial films, digital aerial data and satellite imagery there indefinitely. EDUCATION, ECOMMERCE, SOCIAL MEDIA, DEFENCE — we found no separate Bulgarian rule forcing data to stay in the country, checked 18 August 2026. Defence and national security work is left out of the Personal Data Protection Act entirely and is handled under classified information law.
Sources
- Official sourceBulgarian Institute of Metrology (official copy of the Act)Gambling Act (Закон за хазарта), Article 6 — location of equipment and control local server
bim.government.bg
“Организаторът трябва да осигури съхраняването на всички данни ... на оборудване за съхранение на данни (контролен локален сървър), разположено на територията на Република България”
Link checked 18 August 2026
- Official sourceCommunications Regulation CommissionElectronic Communications Act (Закон за електронните съобщения), Articles 251b, 304, 305, 307
crc.bg
“Предприятията, предоставящи обществени електронни съобщителни мрежи и/или услуги, съхраняват за срок от 6 месеца данни, създадени или обработени в процеса на тяхната дейност”
Link checked 18 August 2026
- Official sourceMinistry of Regional Development and Public WorksGeodesy and Cartography Act (Закон за геодезията и картографията), Articles 15, 20 and 21
mrrb.bg
“Аерозаснемането се извършва от физически или юридически лица след съгласуване с Министерството на отбраната, Министерството на вътрешните работи, Държавна агенция "Национална сигурност", Министерството на външните работи и Министерството на транспорта, информационните технологии и съобщенията.”
Link checked 18 August 2026
- Official sourceAgency for Quality of Social Services (official copy of the Act)Electronic Governance Act (Закон за електронното управление) — definition of the State hybrid private cloud
aksu.government.bg
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on the free flow of non-personal data — bans member state localisation except on public security grounds
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
Bulgaria uses Europe's system, not its own. There is no Bulgarian list of banned countries and no Bulgarian permit to apply for. If the destination is inside Europe, the wider European Economic Area or Switzerland, nothing extra is needed. Otherwise you need one of three things. An official European decision that the country is safe enough. Or the standard European contract. Or approved group-wide rules. One Bulgarian point: Bulgarian law expressly puts Switzerland on the same footing as a European Union country.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · Needed for a contract · Legal claims
The model is: you can only send data to approved countries, and the approving is done at European Union level. The list is well populated. As verified against the European Commission's own list on 18 August 2026, the approved destinations are: Andorra, Argentina, Brazil (new, 26 January 2026, mutual), Canada (commercial organisations only), the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea (first review confirmed 23 July 2026), Switzerland, the United Kingdom (renewed 19 December 2025, running to 2031), Uruguay, the United States for entities self-certified under the EU-US Data Privacy Framework, and the European Patent Organisation. None has been withdrawn or suspended. Outside that list, the 2021 Standard Contractual Clauses (Decision (EU) 2021/914) are the main tool and remain unchanged. The promised new clauses, for importers already directly caught by the Regulation, are still not adopted as of 18 August 2026. Binding Corporate Rules remain available. The Article 49 exceptions are narrow and are not a route for routine or large-scale transfers. You are still expected to write a transfer impact assessment. The EU-US Data Privacy Framework is in force and legally valid on 18 August 2026, but under pressure. The Latombe challenge was dismissed by the General Court on 3 September 2025 and has been on appeal to the Court of Justice since 31 October 2025. On 31 July 2026 the European Data Protection Board formally asked the Commission to examine whether changes in United States institutions affect the decision's validity. The Commission has not suspended or revoked it. Bulgaria adds nothing on top. The Personal Data Protection Act has no separate transfer chapter for ordinary business and no rule that data must stay in the country. Its Article 1(7) does add that European Economic Area states and Switzerland rank equal to European Union member states.
Sources
- Official sourceEuropean CommissionAdequacy decisions — the European Commission's own list of approved destinations
commission.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceAgency for Public Enterprises and Control, Republic of BulgariaPersonal Data Protection Act, Article 1(7) — European Economic Area states and Switzerland are equal to European Union member states
aref.government.bg
“държавите, които са страни по Споразумението за Европейското икономическо пространство, и Конфедерация Швейцария са равнопоставени на държавите - членки на Европейския съюз. Всички други държави са трети държави.”
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Commission for Personal Data Protection is the main regulator. It is real, staffed, and it does issue formal decisions, including ones published across Europe. But it does not hit hard. In a Europe-wide check on deletion rights reported in February 2026, it contacted twenty-three organisations. It opened no formal investigations, imposed no penalties, and said it did not plan to. A separate inspectorate polices the courts and prosecutors. Cybersecurity has its own separate regulators.
The Commission for Personal Data Protection (Комисия за защита на личните данни) is set up under Chapter Two of the Personal Data Protection Act. It is the supervisory authority for the General Data Protection Regulation in Bulgaria. It is working. It issues administrative acts, its decisions have been published through the European Data Protection Board's document library, and it took part in the Board's 2025 coordinated enforcement action. That action is also the clearest recent sign of how it behaves. In the national report published by the Board in February 2026, Bulgaria reported contacting twenty-three companies: six public sector, sixteen private sector, and one military education body. All of them replied. Bulgaria then answered 'no' to whether it planned formal investigations, and 'no' to whether the exercise would change its enforcement work. It said it would run an information campaign instead. Enforcement acts are taken by decision of the Commission, and penalty orders are issued by its chair, under Articles 84 to 87 of the Act. Appeals go to the administrative courts within fourteen days. A second, separate supervisor exists. The Inspectorate to the Supreme Judicial Council oversees how courts, prosecutors and investigators handle data. Cybersecurity is supervised by the Minister of Electronic Governance, together with the regulator for each industry, under the amended Cybersecurity Act. Gambling, including the local-server rule, is supervised by the National Revenue Agency. One thing worth knowing: the Commission's own website was unreachable from our infrastructure on 18 August 2026, returning a server error every time. So we could not read its 2025 annual report figures directly, and they are on the unconfirmed list.
Sources
- Official sourceEuropean Data Protection BoardAnnex: National reports on the 2025 Coordinated Enforcement Framework on the right to erasure — Bulgaria section
edpb.europa.eu
“Following the results of the fact-finding exercise, do you plan to launch formal investigations relating to the right to erasure in the near future? [no]”
Link checked 18 August 2026
- Official sourceLink may be brokenCommission for Personal Data ProtectionCommission for Personal Data Protection — official site
cpdp.bg
Link checked 18 August 2026
- Official sourceAgency for Public Enterprises and Control, Republic of BulgariaPersonal Data Protection Act, Chapter Two and Articles 84–87 — the Commission, the judicial Inspectorate, and how penalties are imposed
aref.government.bg
Link checked 18 August 2026
- Official sourceState Gazette of the Republic of BulgariaAct amending the Cybersecurity Act, State Gazette No. 17 of 13 February 2026 — competent authorities
dv.parliament.bg
Link checked 18 August 2026
How long you must keep it — and when to delete it
Bulgaria has strong minimum keeping periods and a few strict deletion deadlines. You must keep payroll records for fifty years. Accounting books and financial statements go ten years. Other accounting papers go three years. Telecoms firms keep connection records for six months. Going the other way, job applicants' data must be deleted within six months unless they agree otherwise. Data you were given with no legal basis must be returned or destroyed within one month.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
MINIMUM KEEPING PERIODS. The Accountancy Act (Закон за счетоводството, State Gazette No. 95 of 8 December 2015, last amended State Gazette No. 61 of 2025 in force 31 October 2025) Article 12(1) sets three periods. All are counted from 1 January of the reporting period following the one they relate to. Payroll sheets: fifty years. Accounting registers and financial statements, including documents for tax control, audit and later financial inspections: ten years. All other carriers of accounting information: three years. Article 12(1) says this information is kept 'in the enterprise', on paper and/or a technical medium. Article 12(2) allows storage in private or state archives under the National Archive Fund Act. Article 12(4) sends payroll sheets to the National Social Security Institute if a company is wound up with no successor. The Electronic Communications Act Article 251b(1) requires six months for six categories of connection data. The Gambling Act Article 6(4) requires gambling data to be kept in the form in which it was created. The period is five years after the limitation period for public liabilities expires. Article 6(5) sets a minimum of at least twelve months from collection. The Geodesy and Cartography Act Article 21(3) requires carriers of field measurement data to be kept fifty years. Article 21(2) keeps aerial films, digital aerial data and satellite imagery indefinitely in the state Geo-Cartographic Fund. DELETION DEADLINES. Personal Data Protection Act Article 25k(1): an employer must set a keeping period for job candidates' data. It cannot be longer than six months unless the candidate agrees to longer. After that the documents must be erased or destroyed, unless a special law says otherwise. Article 25k(2): originals or notarised copies of fitness, qualification and service-record documents must be returned to unsuccessful candidates within six months of the procedure closing. Article 25a: where data was handed over with no lawful basis, or against the principles of the European rulebook, you must return it within one month of finding out. If returning it is impossible or disproportionate, you erase or destroy it, and you must write the erasure down. The European rulebook's general rule against keeping data longer than you need it applies throughout. WHEN THE RULES CLASH. Bulgarian drafting settles it in favour of the specific statutory minimum. Article 25k twice carries the phrase 'unless a special law provides otherwise'. So keep the record for the statutory minimum, then delete it.
Sources
- Official sourceAgency for Public Procurement Control (official copy of the Act)Accountancy Act (Закон за счетоводството), Articles 11–14 — retention periods for accounting information
appk.government.bg
“Счетоводната информация се съхранява на хартиен и/или на технически носител в предприятието в следните срокове: 1. ведомости за заплати – 50 години ... 2. счетоводни регистри и финансови отчети ... – 10 години ... 3. всички останали носители на счетоводна информация – три години”
Link checked 18 August 2026
- Official sourceAgency for Public Enterprises and Control, Republic of BulgariaPersonal Data Protection Act, Articles 25a and 25k — one-month return duty and the six-month recruitment ceiling
aref.government.bg
“определя срок за съхранение на лични данни на участници в процедури по набиране и подбор на персонала, който не може да е по-дълъг от 6 месеца, освен ако кандидатът е дал своето съгласие за съхранение за по-дълъг срок”
Link checked 18 August 2026
- Official sourceCommunications Regulation CommissionElectronic Communications Act, Article 251b(1) — six-month retention of connection data
crc.bg
Link checked 18 August 2026
- Official sourceBulgarian Institute of Metrology (official copy of the Act)Gambling Act, Article 6(4) and 6(5) — gambling record retention
bim.government.bg
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There are at least three deadlines and they do not agree. A personal data breach must reach the privacy regulator within seventy-two hours. Under the cybersecurity law rewritten in February 2026, an early warning must reach the response team within twenty-four hours. A fuller report follows within seventy-two hours. Trust service providers get twenty-four hours for that fuller report. Financial firms answer to the separate European financial-resilience rules on top.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Deadline one: the General Data Protection Regulation, Article 33. Tell the Commission for Personal Data Protection without undue delay, and where possible within 72 hours of becoming aware. Tell the people affected without undue delay where the risk to them is high. This is the deadline that catches most organisations. Deadline two: the Cybersecurity Act as rewritten by the Act published in State Gazette No. 17 of 13 February 2026. It brings in the European network and information security directive known as NIS2. For a significant incident, an essential or important entity must send an early warning within 24 hours of establishing the incident, and an incident notification within 72 hours. Qualified trust service providers must send that notification within 24 hours. The old 2018 text demanded an early warning within two hours and a full report within five working days. It has been replaced. The Minister of Electronic Governance keeps the register of covered entities, and the regulator for each industry supervises. Deadline three: for financial firms, Regulation (EU) 2022/2554, the Digital Operational Resilience Act, has applied since 17 January 2025. It adds its own initial, intermediate and final report deadlines. It is a specialist set of rules that takes precedence over general national information technology rules for those firms. The overlap is where organisations fail. One incident at a bank can be a personal data breach, a significant cybersecurity incident and a major financial technology incident all at once. That means three different recipients and three different formats.
Sources
- Official sourceState Gazette of the Republic of BulgariaAct amending and supplementing the Cybersecurity Act, State Gazette No. 17 of 13 February 2026 — 24-hour early warning and 72-hour notification
dv.parliament.bg
“до 24 часа след установяването на значителен инцидент”
Link checked 18 August 2026
- Official sourceState Gazette of the Republic of BulgariaCybersecurity Act as originally promulgated, State Gazette No. 94 of 13 November 2018 — the superseded two-hour rule
dv.parliament.bg
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2022/2554 (Digital Operational Resilience Act) — incident reporting for financial entities
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things catch people out in Bulgaria. You may not photocopy someone's identity card, driving licence or residence permit unless a law lets you. Children need a parent's consent up to age fourteen, not sixteen. Job applicant files must go within six months. Your accounting software must be able to produce output in Bulgarian. And one clause of the privacy law was struck down by the Constitutional Court in 2019, but is still printed in the statute.
- What you have to do here:
- Get a parent's consent for children · Appoint a data protection officer · Delete data after a period
Trap 1 — no copying identity documents. Personal Data Protection Act Article 25g: you may copy an identity card, a driving licence or a residence document only where a law provides for it. That binds you and any supplier handling data for you. Foreign 'take a photo of your passport' sign-up flows walk straight into this. A breach carries the higher European fine tier under Article 85(2). Trap 2 — children's age is fourteen. Article 25c requires a parent's or guardian's consent where you rely on consent for anyone under fourteen. That includes direct offers of information society services. Bulgaria chose the lowest age the European rulebook permits. So a global product built to sixteen does more than Bulgaria requires, and one built to thirteen breaks the rules here. Trap 3 — the six-month recruitment limit. Article 25k(1) caps how long you may keep unsuccessful candidates' data at six months, unless they agree to longer. Article 25k(2) forces return of original or notarised documents within six months. Applicant tracking systems set to a two-year default breach this. Trap 4 — a dead clause still printed in the law. Article 25z(2) sets out ten criteria for balancing free expression against privacy in journalism. The Constitutional Court declared it unconstitutional by Decision No. 8 of 2019, published in State Gazette No. 93 of 26 November 2019. The text remains in the consolidated statute with only a bracketed note. Article 85(2) still lists 'Article 25z, paragraphs 1 and 2' among the punishable breaches. A plain text search reads this as binding. It is not. Trap 5 — a language requirement on your systems, and duties on named people. Accountancy Act Article 11(2): where accounting software is used, it must be built to this Act's requirements. It must also allow the data it handles and its output documents to be in the Bulgarian language. Separately, Personal Data Protection Act Article 25b makes you tell the regulator about your data protection officer. You give their name, their Bulgarian personal identification number (or the equivalent for a foreigner) and contact details. You must also report every later change. Article 25i makes employers adopt and publish written rules and procedures for whistleblowing systems, for restrictions on internal company resources, and for any access-control, working-time or discipline-monitoring systems. Article 25zh(2) bans using the Bulgarian personal identification number as the only way of identifying a user for remote access to an online service.
Sources
- Official sourceAgency for Public Enterprises and Control, Republic of BulgariaPersonal Data Protection Act, Articles 25b, 25c, 25g, 25i, 25k, 25zh and 25z(2) with the unconstitutionality note
aref.government.bg
“(2) (Обявена за противоконституционна с РКС № 8 от 2019 г. - ДВ, бр. 93 от 2019 г.)”
Link checked 18 August 2026
- Official sourceAgency for Public Procurement Control (official copy of the Act)Accountancy Act, Article 11(2) — accounting software must be able to produce data and output documents in Bulgarian
appk.government.bg
“Когато при осъществяване на счетоводството се използва счетоводен софтуер, той трябва да е разработен при спазване на изискванията на този закон и да дава възможност обработваните чрез него данни и изходните документи да са на български език.”
Link checked 18 August 2026
What's changing next
Two dated changes are already fixed. From 12 January 2027 every cloud provider must let customers move their data out for free. Bulgaria's new cybersecurity duties started on 13 February 2026, and enforcement is only now getting going. The biggest live risk is not Bulgarian at all. Europe's approval of United States data transfers is being challenged. Europe's own privacy board asked the Commission on 31 July 2026 to re-examine it.
- What you have to do here:
- Make switching cloud provider possible
DATED AND CERTAIN. 12 January 2027 — the European Data Act (Regulation (EU) 2023/2854) has applied since 12 September 2025. From this date it requires all cloud switching charges and data egress fees to fall to zero. Its Chapter VII also limits foreign government access to non-personal data held in the European Union. 13 February 2026 — Bulgaria's amended Cybersecurity Act came into force on publication in State Gazette No. 17. Registration of essential and important entities, incident reporting and management accountability all began then. Fines reach 10 million euro or 2 percent of worldwide turnover for essential entities, and 7 million euro or 1.4 percent for important entities. The stated minimums are 25,000 euro and 12,500 euro. Supervision here is new and untested. 1 January 2026 — Bulgaria adopted the euro. Every money threshold and fine written in Bulgarian lev must now be read in euro, at the fixed rate of 1.95583 lev to the euro. Contracts, deletion schedules and accounting systems all had to be converted. 2 August 2026 — the European Union Artificial Intelligence Act's transparency duties started applying. POWERS ALREADY HELD THAT COULD CHANGE THINGS WITH NO CONSULTATION. 1. The Electronic Communications Act's access rules keep being widened by ordinary amendment and then trimmed by the Constitutional Court. Parliament can add a new authorised requester to the list of bodies that may pull six months of connection records, in a single amending act. 2. The Gambling Act's control-local-server rule sits in primary legislation. Its reach depends on what counts as a licensed online organiser. Widening the licence net widens the requirement to keep data in Bulgaria. 3. Article 1(5) leaves defence and national security work out of the Personal Data Protection Act entirely. The wording is 'in so far as a special law does not provide otherwise'. So a special law can move a category of work out of the general rules. AT EUROPEAN LEVEL, NOT ADOPTED — do not plan around these. The Digital Omnibus proposal of 19 November 2025, which would extend breach notification from 72 to 96 hours. The Cloud and AI Development Act proposed 3 June 2026. And the European cloud certification scheme, deadlocked since 2020.
Sources
- Official sourceState Gazette of the Republic of BulgariaAct amending and supplementing the Cybersecurity Act, State Gazette No. 17 of 13 February 2026
dv.parliament.bg
Link checked 18 August 2026
- Official sourceCouncil of the European UnionBulgaria ready to use the euro from 1 January 2026 — Council takes final steps
consilium.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2023/2854 (Data Act) — zero switching charges from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Diarise 12 January 2027 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries6 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Online gaming data needs a copy kept in the country
Official name: Закон за хазарта · State Gazette No. 26 of 30 March 2012; last amendment State Gazette No. 26 of 27 March 2025; Article 6 · Act of parliament
The one real Bulgarian rule forcing data to stay in the country. A licensed online gambling operator must keep a control server holding all its data physically inside Bulgaria. It must also stream live game session data to the tax authority.
Enforced by National Revenue Agency
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Keep the data in the countryArticle 6(4): all data must be stored on a data storage device — a control local server — located on the territory of the Republic of Bulgaria. Article 6(2) says that means only the geographic territory of the country.
- Register or notifyArticle 6(1)(2): the communications equipment and the central point housing the central computer system must be in Bulgaria or another European Union member state.
- Keep data for a minimum period — 1 yearArticle 6(5): at least twelve months from collection. Article 6(4) adds five years after the limitation period for public liabilities expires.
- Independent auditArticle 6(1)(4): a system feeding session information in real time to a server of the National Revenue Agency.
What it costs if you get it wrong
- Loss of your licenceOperating outside the licence conditions, including the equipment location requirements
Sources
- Official sourceBulgarian Institute of Metrology (official copy of the Act)Gambling Act (Закон за хазарта), Article 6
bim.government.bg
“комуникационното оборудване и централният пункт, в който се намира централната компютърна система ... да са разположени на територията на Република България или на територията на друга държава - членка на Европейския съюз”
Link checked 18 August 2026
Telecoms rules
Official name: Закон за електронните съобщения, чл. 251б – 251и, чл. 304 – 307 · State Gazette No. 41 of 22 May 2007; retention chapter inserted by State Gazette No. 24 of 2015, in force 31 March 2015 · Act of parliament
Telecoms operators must keep six months of connection records and build interception equipment wired into two Bulgarian state agencies. The law does not say where the retained records must physically sit, but the interception equipment cannot be run from abroad.
Enforced by Communications Regulation Commission
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Keep data for a minimum period — 6 monthsArticle 251b(1): six categories of connection data — source, destination, date, time and duration, type, user device, and cell identifier.
- Keep logsArticle 251g(7): a non-public register of every access order must be kept.
- Secure the dataArticles 304, 305 and 307: operators must provide, install and maintain interception interfaces at their own expense. Those interfaces feed the State Agency for Technical Operations and the State Agency for National Security. Operators must also hand over encrypted traffic in its original form.
What it costs if you get it wrong
- Fixed maximum fineFailure to retain or to provide access on a valid court order
Sources
- Official sourceCommunications Regulation CommissionElectronic Communications Act (Закон за електронните съобщения), Articles 251b to 251i and 304 to 307
crc.bg
“Предприятията, предоставящи обществени електронни съобщителни мрежи и/или услуги, предоставят, въвеждат в експлоатация и поддържат за своя сметка прихващащи интерфейси”
Link checked 18 August 2026
Record-keeping rules for tax and accounts
Official name: Закон за счетоводството · State Gazette No. 95 of 8 December 2015, in force 1 January 2016; last amendment State Gazette No. 61 of 2025, in force 31 October 2025; Articles 11 to 14 · Act of parliament
Bulgaria's longest minimum keeping periods sit in the accounting law. Payroll goes fifty years, the books ten years, and everything else three years. The law says records are kept at the enterprise. Your accounting software must also be able to produce output in Bulgarian.
Enforced by National Revenue Agency
What you have to do
- Keep data for a minimum period — 50 yearsPayroll sheets: fifty years, counted from 1 January of the reporting period following the one they relate to.
- Keep data for a minimum period — 10 yearsAccounting registers and financial statements, including documents for tax control, audit and subsequent financial inspections: ten years.
- Keep data for a minimum period — 3 yearsAll other carriers of accounting information: three years.
- Keep records of how you use dataArticle 11(2): where accounting software is used, it must allow the data it handles and its output documents to be in the Bulgarian language.
What it costs if you get it wrong
- Fixed maximum fineFailure to keep accounting information for the statutory period
Sources
- Official sourceAgency for Public Procurement Control (official copy of the Act)Accountancy Act (Закон за счетоводството), Articles 11 to 14
appk.government.bg
“Счетоводната информация се съхранява на хартиен и/или на технически носител в предприятието”
Link checked 18 August 2026
Telecoms rules (Mapping and location)
Official name: Закон за геодезията и картографията · State Gazette No. 29 of 7 April 2006; Articles 6, 15, 20 and 21 · Act of parliament
You cannot simply fly a survey over Bulgaria. Aerial photography needs advance sign-off from five state bodies, and state-commissioned survey material has to be deposited in a national fund, some of it permanently.
Enforced by Agency for Geodesy, Cartography and Cadastre
What you have to do
- Register or notifyArticle 15(2): aerial photography and other remote-sensing methods need clearance in advance. Five bodies must clear it. They are the Ministry of Defence, the Ministry of the Interior, the State Agency for National Security, the Ministry of Foreign Affairs and the transport ministry.
- Keep data for a minimum period — 50 yearsArticle 21(3): carriers of field measurement and computation data, fifty years. Article 21(2) keeps aerial films, digital aerial data and satellite imagery indefinitely.
- Keep the data in the countryArticle 20: state-commissioned survey material is deposited in the state Geo-Cartographic Fund held by the Agency for Geodesy, Cartography and Cadastre. Article 6(1) makes such material public except where it is classified.
What it costs if you get it wrong
- Fixed maximum fineAerial survey without clearance
- Criminal liabilityUnauthorised handling of classified geodetic material under the Classified Information Protection Act
Sources
- Official sourceMinistry of Regional Development and Public WorksGeodesy and Cartography Act (Закон за геодезията и картографията), Articles 6, 15, 20 and 21
mrrb.bg
“На съхраняване за срок 50 години подлежат носителите с данни от полските измервания и изчисления”
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Закон за електронното управление; Наредба за общите изисквания към информационните системи, регистрите и електронните административни услуги · Act: State Gazette No. 46 of 12 June 2007, state cloud definition added by State Gazette No. 50 of 2016. Ordinance: Council of Ministers Decree No. 3 of 9 January 2017, State Gazette No. 5 of 17 January 2017 · Act of parliament
Bulgaria runs a shared state cloud for public bodies. But neither the e-government law nor its ordinance actually says government data must stay in Bulgaria. The pressure to use the state cloud comes from buying rules and funding, not from a legal ban on sending data abroad. No such rule found, checked 18 August 2026.
Enforced by Ministry of Electronic Governance
What you have to do
- Hold a security certificateThe State hybrid private cloud is defined as centralised state infrastructure spread over several sites meeting protected-data-centre criteria, providing isolated physical and virtual resources to state bodies.
- Keep records of how you use dataArticle 7e requires a public register of e-government projects and Article 7f a register of information resources held by administrative bodies.
Sources
- Official sourceAgency for Quality of Social Services (official copy of the Act)Electronic Governance Act (Закон за електронното управление), Articles 7c to 7f and the definition of the State hybrid private cloud
aksu.government.bg
“"Държавен хибриден частен облак" е централизирана държавна информационна инфраструктура (сървъри, средства за съхранение на данни, комуникационно оборудване, съпътстващо оборудване и системен софтуер), разпределена в няколко локации”
Link checked 18 August 2026
- Official sourceAgency for Quality of Social Services (official copy of the Ordinance)Ordinance on the general requirements for information systems, registers and electronic administrative services
aksu.government.bg
Link checked 18 August 2026
Cloud and outsourcing rules (Banking)
Official name: Закон за кредитните институции, чл. 62 · Credit Institutions Act, Article 62 (bank secrecy) · Act of parliament
Bulgarian banking law says nothing about where data lives, but bank secrecy limits who may see it. That is a contract problem, not a hosting problem. A normal supplier data agreement is not enough for a bank's cloud provider.
Enforced by Bulgarian National Bank
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Extra vendor secrecy termsBank secrecy binds staff and anyone who learns the information through their work. A standard data protection agreement does not satisfy it. Cloud contracts need explicit secrecy promises.
- Written vendor contractAn outsourcing policy is a required part of a bank's internal governance. For financial firms, Regulation (EU) 2022/2554 also requires the contract to say where data is handled and stored.
What it costs if you get it wrong
- Criminal liabilityUnlawful disclosure of bank secrecy
- Loss of your licenceSerious supervisory breach
Sources
- Official sourceBulgarian National BankCredit Institutions Act (Закон за кредитните институции), Article 62 and internal governance requirements
bnb.bg
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2022/2554 (Digital Operational Resilience Act)
eur-lex.europa.eu
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Children's data rules
Official name: Закон за защита на личните данни · State Gazette No. 1 of 4 January 2002; rewritten by State Gazette No. 17 of 26 February 2019; last amendment traced State Gazette No. 84 of 6 October 2023 · Act of parliament
Bulgaria's own privacy statute. It has no rule forcing data to stay in the country. But it does add real national duties on children, employees, identity documents and the data protection officer. It also treats Switzerland as if it were a European Union country.
Enforced by Commission for Personal Data Protection
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Appoint a data protection officerArticle 25b: notify the regulator of the officer's name, Bulgarian personal identification number and contact details, and every later change.
- Get a parent's consent for children — applies at: under 14
- Delete data after a period — applies at: Unsuccessful job applicants, unless they consent to longer, 6 monthsArticle 25k.
- Delete data after a period — applies at: Data received with no lawful basis must be returned, erased or destroyed, 1 monthArticle 25a. The erasure must be documented.
- Keep records of how you use dataArticle 25i: employers must adopt written rules for whistleblowing systems, restrictions on internal company resources and access-control, working-time or discipline-monitoring systems.
- Secure the dataArticle 25zh: the Bulgarian personal identification number may not be the sole means of identifying a user for remote access to a service.
What it costs if you get it wrong
- Percentage of global turnover: The lev equivalent of the European caps in Article 83(4) and 83(5) of Regulation (EU) 2016/679, now read in euro — about $23 millionBreach of the national add-on articles, including the ban on copying identity documents and the children's rule
- Fixed maximum fine: 5,000 Bulgarian lev (about 2,600 euro, roughly $3,000), doubled on repeat — about $3 thousandAny other breach of this Act (Article 86)
Sources
- Official sourceAgency for Public Enterprises and Control, Republic of BulgariaPersonal Data Protection Act (Закон за защита на личните данни), consolidated text
aref.government.bg
“Обработването на данни на субект на данни - лице, ненавършило 14 години, въз основа на съгласие ... е законосъобразно само ако съгласието е дадено от упражняващия родителски права родител или от настойника на субекта на данните.”
Link checked 18 August 2026
Cyber security rules
Official name: Закон за киберсигурност, изменен и допълнен · Original: State Gazette No. 94 of 13 November 2018. Transposing amendment: State Gazette No. 17 of 13 February 2026, in force on publication · Act of parliament
Bulgaria's cybersecurity law was rewritten in February 2026 to bring in Europe's network and information security directive. It has no rule forcing data to stay in the country. It does add new reporting deadlines and fines based on turnover, and it replaced the old two-hour reporting rule.
Enforced by Ministry of Electronic Governance
What you have to do
- Report cyber incidents — within 24 hours, from 13 February 2026Early warning within 24 hours of establishing a significant incident.
- Report cyber incidents — within 72 hours, from 13 February 2026Full incident notification within 72 hours; 24 hours for qualified trust service providers.
- Register or notify — from 13 February 2026The Minister of Electronic Governance creates and maintains the register of essential and important entities.
- Secure the data — from 13 February 2026
- Independent audit — from 13 February 2026
What it costs if you get it wrong
- Percentage of global turnover: €10,000,000 or 2% of worldwide annual turnover, whichever is higher, minimum €25,000 — about $12 millionEssential entities
- Percentage of global turnover: €7,000,000 or 1.4% of worldwide annual turnover, whichever is higher, minimum €12,500 — about $8 millionImportant entities
Sources
- Official sourceState Gazette of the Republic of BulgariaAct amending and supplementing the Cybersecurity Act, State Gazette No. 17 of 13 February 2026
dv.parliament.bg
“до 24 часа след установяването на значителен инцидент”
Link checked 18 August 2026
- Official sourceMinistry of Labour and Social Policy (official copy of the Act)Cybersecurity Act (Закон за киберсигурност), pre-2026 consolidated text showing the superseded two-hour reporting rule
mlsp.government.bg
Link checked 18 August 2026
Applies across the European Union1 rule
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Регламент (ЕС) 2016/679 (Общ регламент относно защитата на данните) · Regulation (EU) 2016/679 · Directly binding regulation
Europe's privacy rulebook is the base layer in Bulgaria. It does not require data to stay in Europe. It regulates the conditions on which data leaves, and it is where almost all of the compliance work sits.
Enforced by Commission for Personal Data Protection
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Important public interest, To save someone’s life
What you have to do
- Tell people what you do
- Secure the data
- Keep records of how you use data
- Assess high-risk projects
- Let people see their data
- Let people delete their data
- Let people take their data elsewhere
- Put a transfer safeguard in place
- Written vendor contract
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Appoint a representativeOnly for companies outside the European Union that are caught by Article 3(2). The representative may be in any member state, not specifically Bulgaria.
What it costs if you get it wrong
- Percentage of global turnover: €20,000,000 or 4% of worldwide group turnover — about $23 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Order to stopOrder to stop processing or suspend transfers outside Europe
- Claims by individualsCompensation claims by affected individuals
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 — General Data Protection Regulation
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 — free flow of non-personal data; bans member state localisation except on public security grounds
eur-lex.europa.eu
Link checked 18 August 2026
On the books, but not enforceable2 rules
These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.
General data protection law
Official name: Решение № 8 от 2019 г. на Конституционния съд на Република България · Published in State Gazette No. 93 of 26 November 2019; declares Article 25z(2) of the Personal Data Protection Act unconstitutional · Court decision
The privacy law still prints ten criteria for balancing journalism against privacy. The Constitutional Court declared that paragraph unconstitutional in 2019 and it cannot be enforced. The penalty article was never tidied up and still lists it.
Enforced by Constitutional Court of the Republic of Bulgaria
Sources
- Official sourceAgency for Public Enterprises and Control, Republic of BulgariaPersonal Data Protection Act, Article 25z(2) carrying the unconstitutionality note, and Article 85(2) which still penalises it
aref.government.bg
“(2) (Обявена за противоконституционна с РКС № 8 от 2019 г. - ДВ, бр. 93 от 2019 г.) При разкриване чрез предаване, разпространяване или друг начин ... балансът между свободата на изразяване и правото на информация и правото на защита на личните данни се преценява въз основа на следните критерии”
Link checked 18 August 2026
- Official sourceConstitutional Court of the Republic of BulgariaConstitutional Court of the Republic of Bulgaria — acts database
constcourt.bg
Link checked 18 August 2026
Telecoms rules (Telecoms)
Official name: Решение № 8 от 23 юни 2026 г. на Конституционния съд по к.д. № 19/2025 г. · Published in State Gazette No. 60 of 1 July 2026 · Court decision
In June 2026 the Constitutional Court struck down part of the telecoms law. That part let the competition regulator pull six months of people's connection records for ordinary competition investigations. The wording is still in the printed statute, but it cannot be used.
Enforced by Constitutional Court of the Republic of Bulgaria
Sources
- Official sourceState Gazette of the Republic of BulgariaConstitutional Court Decision No. 8 of 23 June 2026 in case No. 19/2025, State Gazette No. 60 of 1 July 2026
dv.parliament.bg
“Обявява за противоконституционни разпоредбите на чл. 251б, ал. 2, изречение първо ... чл. 251в, ал. 1, т. 6 ... и чл. 251г, ал. 9 от Закона за електронните съобщения”
Link checked 18 August 2026
- Official sourceConstitutional Court of the Republic of BulgariaConstitutional Court case file No. 19/2025 — submissions on access to traffic data
constcourt.bg
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The Commission for Personal Data Protection's 2025 enforcement statistics — number of complaints, inspections, fines and their total value
We could not confirm the regulator's 2025 enforcement numbers. Its website, cpdp.bg, returned a server error on every attempt on 18 August 2026, including its published 2025 annual report. We used the European Data Protection Board's February 2026 coordinated-enforcement annex instead. Enforcement is rated active on that basis, but with less certainty than usual.
The current composition of the Commission for Personal Data Protection — whether the chair and members are within a valid mandate or serving on after expiry
We could not confirm who currently sits on the Commission, or whether their terms have expired. Bulgarian media reporting suggests a selection procedure for new leadership has been running. The National Assembly's appointments page returned no readable content, and the regulator's site was down. We do not assert this either way.
Whether the Personal Data Protection Act has been amended after State Gazette No. 84 of 6 October 2023, in particular for the euro changeover on 1 January 2026
We could not confirm whether the Act has been amended since State Gazette No. 84 of 6 October 2023. The consolidated text we checked carries amendments only to October 2023. Bulgaria's move to the euro means lev amounts in statutes are now read in euro at the fixed rate. Whether the Act's own text was formally amended for that, we do not know.
Retention periods for medical records held by Bulgarian healthcare providers
We could not confirm how long Bulgarian healthcare providers must keep medical records. The National Health Insurance Fund's guidance pages blocked our checks, and the Ministry of Health's electronic health page gives no ordinance references. We did not want to state periods we could not read in an official text. If you handle medical records, check before you delete.
Bulgaria's Standard Audit File for Tax (SAF-T) phase-in dates and scope
We could not confirm the dates and thresholds for Bulgaria's Standard Audit File for Tax (SAF-T). The National Revenue Agency's pages on it would not load for us. Bulgaria clearly has such a programme, and the Agency wrote to around 470 large taxpayers about a first reporting period. We have not stated the official dates and thresholds as fact.
The five-year record-keeping period under Bulgaria's anti-money-laundering law
We could not confirm the five-year record-keeping period under Bulgaria's anti-money-laundering law. It is a standard European requirement and almost certainly applies. But we did not read the operative Bulgarian article on a government source, so we do not state it in the retention answer.
Whether any Bulgarian banking, insurance or securities regulator circular imposes a data location or in-country hosting condition
We found no Bulgarian banking, insurance or securities rule about where data must be held. We searched the Bulgarian National Bank's and the Financial Supervision Commission's own legal pages. Their libraries are large and we did not read every circular. Treat this as 'no rule found, checked 18 August 2026', not as 'there is no rule'.
Whether the six-month telecoms retention regime survives European Union law challenge in its current form
We cannot say whether the six-month telecoms retention rule will survive challenge under European Union law. The Court of Justice has repeatedly held general and indiscriminate retention incompatible with European Union law. Bulgaria's own Constitutional Court has trimmed the access rules three times. Operators still keep the data for six months. Whether and when the duty itself falls is not something we can state.
The exact date on which Constitutional Court decisions take legal effect
We could not confirm the exact date on which Constitutional Court decisions take legal effect. Bulgarian constitutional practice is that a decision takes effect a short fixed period after publication in the State Gazette. We recorded the publication dates, 26 November 2019 and 1 July 2026, rather than state an effective date we could not read in an official text.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.