Bulgaria
Part of the European Union, so bloc-wide rules apply here too. Checked today.
The answer
Bulgaria is an ordinary European Union country for data. Personal data can leave, as long as you use one of the standard European transfer tools. There is no general rule forcing data to stay in Bulgaria. But online gambling is a hard exception: a control server must physically sit on Bulgarian soil. Bulgaria switched to the euro on 1 January 2026, so all fines are now in euro.
Eight questions about Bulgaria
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Bulgaria's rules apply to my company?
Yes, it can reach you with no office in Bulgaria. The European Union's privacy rulebook applies to anyone who offers goods or services to people in Europe or watches what they do online. Bulgaria's own Personal Data Protection Act sits on top of that and adds extra local duties. There is no revenue or headcount threshold, and no Bulgaria-specific representative: the European-wide requirement to name a representative in Europe is the only one, and it can be in any European country.
The Personal Data Protection Act (Закон за защита на личните данни, promulgated in State Gazette No. 1 of 4 January 2002, comprehensively rewritten by State Gazette No. 17 of 26 February 2019) states in Article 1(1) that it governs matters 'in so far as they are not governed by Regulation (EU) 2016/679'. So the General Data Protection Regulation does the heavy lifting on territorial reach (its Article 3), and the Bulgarian Act layers national rules on top. Two Bulgarian-specific scoping points matter. Article 1(7) treats the European Economic Area states AND Switzerland as equivalent to European Union member states, so a transfer to Switzerland is not a third-country transfer under Bulgarian law at all. Article 1(6) excludes data about dead people, except for the narrow case in Article 25e. Article 1(5) excludes national defence and national security processing unless a special law says otherwise. There is no registration or licensing step for controllers, but Article 25b obliges every controller and processor to notify the regulator of its data protection officer's name, Bulgarian personal identification number and contact details, and of any later change.
Sources
- Official sourceAgency for Public Enterprises and Control, Republic of BulgariaPersonal Data Protection Act (Закон за защита на личните данни), consolidated text, Articles 1 and 25b
aref.government.bg
“Този закон урежда обществените отношения, свързани със защитата на правата на физическите лица при обработване на личните им данни, доколкото същите не са уредени в Регламент (ЕС) 2016/679.”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Article 3 territorial scope
eur-lex.europa.eu
Link checked 18 August 2026
Can I store my users' data outside Bulgaria?
In general, yes. Bulgaria has no law telling ordinary businesses to keep personal data inside the country. Data moves freely to the rest of Europe, to Switzerland, and to countries Europe has approved; anywhere else needs a standard contract or a similar tool. Two industries break that pattern. Online gambling operators must keep a control server physically in Bulgaria. Telecoms operators must build interception equipment that plugs into Bulgarian state agencies, which cannot sit abroad.
Sector by sector, checked 18 August 2026. ONLINE GAMBLING — mirror The Gambling Act (Закон за хазарта) Article 6(1)(2) requires the communications equipment and the central point housing the central computer system to be located in Bulgaria or another European Union member state. Article 6(4) goes further and requires ALL data to be stored on a data storage device — a 'control local server' — located on the territory of the Republic of Bulgaria. Article 6(2) says 'territory of the Republic of Bulgaria' means only the geographic territory of the country. Article 6(1)(4) requires a system feeding session information in real time to a server of the National Revenue Agency. This is the only hard storage-in-country rule found for Bulgaria. TELECOMS — data can leave once conditions are met in law, in-country infrastructure in practice. The Electronic Communications Act (Закон за електронните съобщения) Article 251b requires providers of public electronic communications networks or services to retain six categories of connection data for six months. The Act does NOT say where that retained data must sit. However Articles 304, 305 and 307 require operators to provide, commission and maintain at their own expense interception interfaces feeding the facilities of the State Agency for Technical Operations and the State Agency for National Security, and to hand over encrypted traffic in its original form. That is a physical Bulgarian infrastructure obligation, not a data residency rule. BANKING, PAYMENTS, INSURANCE, SECURITIES — conditional No Bulgarian data-residency rule found, checked 18 August 2026. The Credit Institutions Act Article 62 imposes bank secrecy, which restricts WHO may see data, not WHERE it sits. The European Union's Digital Operational Resilience Act is the operative outsourcing regime and requires the contract to state where data is processed, but imposes no localisation. HEALTH — conditional No localisation rule found. The National Health Information System is a centralised state system run by the Ministry of Health, so state-held e-prescription and e-referral data is in Bulgaria by design, but private clinics are not told where to host their own records. GOVERNMENT — conditional The Electronic Governance Act defines a 'State hybrid private cloud' as centralised state infrastructure, and the State Agency and later the Ministry of Electronic Governance build and share it. Neither that Act nor the implementing ordinance on general requirements for information systems contains a rule that public bodies' data must stay in Bulgaria. In practice public procurement pushes systems into the state cloud. MAPPING AND GEOSPATIAL — data can leave once conditions are met with a collection permit. The Geodesy and Cartography Act Article 15(2) requires aerial photography and other remote-sensing work to be cleared in advance with the Ministry of Defence, the Ministry of the Interior, the State Agency for National Security, the Ministry of Foreign Affairs and the transport ministry. Article 20 requires state-commissioned survey material to be deposited in the state Geo-Cartographic Fund, and Article 21 keeps aerial films, digital aerial data and satellite imagery there indefinitely. EDUCATION, ECOMMERCE, SOCIAL MEDIA, DEFENCE — no separate Bulgarian localisation rule found, checked 18 August 2026. Defence and national security processing is carved out of the Personal Data Protection Act entirely and is handled under classified information law.
Sources
- Official sourceBulgarian Institute of Metrology (official copy of the Act)Gambling Act (Закон за хазарта), Article 6 — location of equipment and control local server
bim.government.bg
“Организаторът трябва да осигури съхраняването на всички данни ... на оборудване за съхранение на данни (контролен локален сървър), разположено на територията на Република България”
Link checked 18 August 2026
- Official sourceCommunications Regulation CommissionElectronic Communications Act (Закон за електронните съобщения), Articles 251b, 304, 305, 307
crc.bg
“Предприятията, предоставящи обществени електронни съобщителни мрежи и/или услуги, съхраняват за срок от 6 месеца данни, създадени или обработени в процеса на тяхната дейност”
Link checked 18 August 2026
- Official sourceMinistry of Regional Development and Public WorksGeodesy and Cartography Act (Закон за геодезията и картографията), Articles 15, 20 and 21
mrrb.bg
“Аерозаснемането се извършва от физически или юридически лица след съгласуване с Министерството на отбраната, Министерството на вътрешните работи, Държавна агенция "Национална сигурност", Министерството на външните работи и Министерството на транспорта, информационните технологии и съобщенията.”
Link checked 18 August 2026
- Official sourceAgency for Quality of Social Services (official copy of the Act)Electronic Governance Act (Закон за електронното управление) — definition of the State hybrid private cloud
aksu.government.bg
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on the free flow of non-personal data — bans member state localisation except on public security grounds
eur-lex.europa.eu
Link checked 18 August 2026
What do I need in place before data leaves Bulgaria?
Bulgaria uses Europe's system, not its own. There is no Bulgarian list of banned countries and no Bulgarian permit to apply for. If the destination is inside Europe, the wider European Economic Area or Switzerland, nothing extra is needed. Otherwise you need either an official European approval of that country, or the standard European contract, or approved group-wide rules. One Bulgarian twist: Bulgarian law explicitly puts Switzerland on the same footing as a European Union country.
Model: allowlist, operated at European Union level and fully populated. The approved destinations as verified against the European Commission's own list on 18 August 2026 are Andorra, Argentina, Brazil (new, 26 January 2026, mutual), Canada (commercial organisations only), the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea (first review confirmed 23 July 2026), Switzerland, the United Kingdom (renewed 19 December 2025, running to 2031), Uruguay, the United States for entities self-certified under the EU-US Data Privacy Framework, and the European Patent Organisation. None has been withdrawn or suspended. Outside that list the 2021 Standard Contractual Clauses (Decision (EU) 2021/914) are the workhorse and remain unamended; the promised new clauses for importers already directly caught by the Regulation are still not adopted as of 18 August 2026. Binding Corporate Rules remain available. The Article 49 derogations are narrow and are not a route for systematic or large-scale transfers. A transfer impact assessment is still expected. The EU-US Data Privacy Framework is in force and legally valid on 18 August 2026 but under pressure: the Latombe challenge was dismissed by the General Court on 3 September 2025 and is on appeal to the Court of Justice since 31 October 2025, and on 31 July 2026 the European Data Protection Board formally asked the Commission to examine whether United States institutional changes affect the adequacy decision's validity. The Commission has not suspended or revoked it. Bulgaria adds nothing on top: the Personal Data Protection Act contains no separate transfer chapter for general processing and no residency clause. Its Article 1(7) does add that European Economic Area states and Switzerland rank equal to European Union member states.
Sources
- Official sourceEuropean CommissionAdequacy decisions — the European Commission's own list of approved destinations
commission.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceAgency for Public Enterprises and Control, Republic of BulgariaPersonal Data Protection Act, Article 1(7) — European Economic Area states and Switzerland are equal to European Union member states
aref.government.bg
“държавите, които са страни по Споразумението за Европейското икономическо пространство, и Конфедерация Швейцария са равнопоставени на държавите - членки на Европейския съюз. Всички други държави са трети държави.”
Link checked 18 August 2026
Who enforces the rules in Bulgaria, and what can they do?
The Commission for Personal Data Protection is the main regulator. It is real, staffed and it does issue formal decisions, including ones published across Europe. But it is not a heavy hitter. In a Europe-wide check on deletion rights reported in February 2026, it contacted twenty-three organisations, opened no formal investigations, imposed no penalties, and said it did not plan to. A separate inspectorate polices the courts and prosecutors. Cybersecurity has its own separate regulators.
The Commission for Personal Data Protection (Комисия за защита на личните данни) is constituted under Chapter Two of the Personal Data Protection Act and is the supervisory authority for the General Data Protection Regulation in Bulgaria. It is operational: it issues administrative acts, its decisions have been published through the European Data Protection Board's document library, and it took part in the Board's 2025 coordinated enforcement action. That action is also the clearest recent evidence of its posture. In the national report published by the Board in February 2026, Bulgaria reported contacting twenty-three controllers (six public sector, sixteen private sector, one military education body), receiving replies from all of them, and then answering 'no' both to whether it planned formal investigations and to whether the exercise would change its enforcement activity. It said it would run an information campaign instead. Enforcement acts are taken by decision of the Commission and penalty orders are issued by its chair, under Articles 84 to 87 of the Act; appeals go to the administrative courts within fourteen days. A second, separate supervisor exists: the Inspectorate to the Supreme Judicial Council supervises data processing by courts, prosecutors and investigators. Cybersecurity is supervised by the Minister of Electronic Governance together with sectoral competent authorities under the amended Cybersecurity Act. Gambling, including the local-server rule, is supervised by the National Revenue Agency. Important practical note: the Commission's own website was unreachable from our infrastructure on 18 August 2026, returning a server error on every attempt, so its 2025 annual report figures could not be read directly and are listed as unconfirmed.
Sources
- Official sourceEuropean Data Protection BoardAnnex: National reports on the 2025 Coordinated Enforcement Framework on the right to erasure — Bulgaria section
edpb.europa.eu
“Following the results of the fact-finding exercise, do you plan to launch formal investigations relating to the right to erasure in the near future? [no]”
Link checked 18 August 2026
- Official sourceLink may be brokenCommission for Personal Data ProtectionCommission for Personal Data Protection — official site
cpdp.bg
Link checked 18 August 2026
- Official sourceAgency for Public Enterprises and Control, Republic of BulgariaPersonal Data Protection Act, Chapter Two and Articles 84–87 — the Commission, the judicial Inspectorate, and how penalties are imposed
aref.government.bg
Link checked 18 August 2026
- Official sourceState Gazette of the Republic of BulgariaAct amending the Cybersecurity Act, State Gazette No. 17 of 13 February 2026 — competent authorities
dv.parliament.bg
Link checked 18 August 2026
How long do I have to keep the data?
Bulgaria has strong minimum-keeping rules and a few sharp delete-by rules. You must keep payroll records for fifty years, accounting books and financial statements for ten years, and other accounting papers for three years. Telecoms firms keep connection records for six months. Going the other way, job applicants' data must be deleted within six months unless they agree otherwise, and data you were given with no legal basis must be returned or destroyed within one month.
FLOORS. The Accountancy Act (Закон за счетоводството, State Gazette No. 95 of 8 December 2015, last amended State Gazette No. 61 of 2025 in force 31 October 2025) Article 12(1) sets three periods, all counted from 1 January of the reporting period following the one they relate to: payroll sheets fifty years; accounting registers and financial statements, including documents for tax control, audit and subsequent financial inspections, ten years; all other carriers of accounting information three years. Article 12(1) says this information is kept 'in the enterprise' on paper and/or a technical medium; Article 12(2) permits storage in private or state archives under the National Archive Fund Act. Article 12(4) sends payroll sheets to the National Social Security Institute if a company is wound up with no successor. The Electronic Communications Act Article 251b(1) requires six months for six categories of connection data. The Gambling Act Article 6(4) requires gambling data to be kept in the form in which it was created for five years after the limitation period for public liabilities expires, and Article 6(5) sets a floor of at least twelve months from collection. The Geodesy and Cartography Act Article 21(3) requires carriers of field measurement data to be kept fifty years, and Article 21(2) keeps aerial films, digital aerial data and satellite imagery indefinitely in the state Geo-Cartographic Fund. CEILINGS. Personal Data Protection Act Article 25k(1): an employer must set a retention period for recruitment candidates' data that cannot exceed six months unless the candidate consents to longer, after which the documents must be erased or destroyed unless a special law says otherwise. Article 25k(2): originals or notarised copies of fitness, qualification and service-record documents must be returned to unsuccessful candidates within six months of the procedure closing. Article 25a: where data was handed over with no lawful basis or contrary to the principles of the European rulebook, the controller must return it within one month of finding out, or erase or destroy it if returning is impossible or disproportionate, and must document the erasure. The general storage-limitation principle of the European rulebook applies throughout. CONFLICT. Bulgarian drafting resolves the clash in favour of the specific statutory floor: Article 25k twice carries the phrase 'unless a special law provides otherwise'. In practice, keep the record for the statutory minimum, then delete.
Sources
- Official sourceAgency for Public Procurement Control (official copy of the Act)Accountancy Act (Закон за счетоводството), Articles 11–14 — retention periods for accounting information
appk.government.bg
“Счетоводната информация се съхранява на хартиен и/или на технически носител в предприятието в следните срокове: 1. ведомости за заплати – 50 години ... 2. счетоводни регистри и финансови отчети ... – 10 години ... 3. всички останали носители на счетоводна информация – три години”
Link checked 18 August 2026
- Official sourceAgency for Public Enterprises and Control, Republic of BulgariaPersonal Data Protection Act, Articles 25a and 25k — one-month return duty and the six-month recruitment ceiling
aref.government.bg
“определя срок за съхранение на лични данни на участници в процедури по набиране и подбор на персонала, който не може да е по-дълъг от 6 месеца, освен ако кандидатът е дал своето съгласие за съхранение за по-дълъг срок”
Link checked 18 August 2026
- Official sourceCommunications Regulation CommissionElectronic Communications Act, Article 251b(1) — six-month retention of connection data
crc.bg
Link checked 18 August 2026
- Official sourceBulgarian Institute of Metrology (official copy of the Act)Gambling Act, Article 6(4) and 6(5) — gambling record retention
bim.government.bg
Link checked 18 August 2026
What happens if there is a breach?
There are at least three clocks and they do not agree. A personal data breach must reach the privacy regulator within seventy-two hours. Under the cybersecurity law rewritten in February 2026, an early warning must reach the response team within twenty-four hours and a fuller report within seventy-two hours. Trust service providers get twenty-four hours for that fuller report. Financial firms answer to the separate European financial-resilience rules on top.
Clock one: the General Data Protection Regulation, Article 33. Notify the Commission for Personal Data Protection without undue delay and where feasible within 72 hours of becoming aware; tell affected individuals without undue delay where the risk to them is high. This is the clock that catches most organisations. Clock two: the Cybersecurity Act as rewritten by the Act published in State Gazette No. 17 of 13 February 2026, which transposes the European network and information security directive known as NIS2. For a significant incident an essential or important entity must send an early warning within 24 hours of establishing the incident and an incident notification within 72 hours; qualified trust service providers must send that notification within 24 hours. The old 2018 text, which demanded an early warning within two hours and a full report within five working days, has been superseded. The Minister of Electronic Governance keeps the register of covered entities and sectoral competent authorities supervise. Clock three: for financial entities, Regulation (EU) 2022/2554 (the Digital Operational Resilience Act) has applied since 17 January 2025 and adds its own initial, intermediate and final report deadlines. It is a specialist regime that takes precedence over general national information technology rules for those firms. The overlap is the operational failure point. One incident at a bank can simultaneously be a personal data breach, a significant cybersecurity incident and a major financial information and communications technology incident, with three different recipients and three different formats.
Sources
- Official sourceState Gazette of the Republic of BulgariaAct amending and supplementing the Cybersecurity Act, State Gazette No. 17 of 13 February 2026 — 24-hour early warning and 72-hour notification
dv.parliament.bg
“до 24 часа след установяването на значителен инцидент”
Link checked 18 August 2026
- Official sourceState Gazette of the Republic of BulgariaCybersecurity Act as originally promulgated, State Gazette No. 94 of 13 November 2018 — the superseded two-hour rule
dv.parliament.bg
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2022/2554 (Digital Operational Resilience Act) — incident reporting for financial entities
eur-lex.europa.eu
Link checked 18 August 2026
What trips people up in Bulgaria?
Five things bite people in Bulgaria. You may not photocopy someone's identity card, driving licence or residence permit unless a law lets you. Children need a parent's consent up to age fourteen, not sixteen. Job applicant files must go within six months. Your accounting software must be able to output in Bulgarian. And one clause of the privacy law was struck down by the Constitutional Court in 2019 but is still printed in the statute.
Trap 1 — no copying identity documents. Personal Data Protection Act Article 25g: a controller or processor may copy an identity card, a driving licence or a residence document only where a law provides for it. Foreign 'take a photo of your passport' onboarding flows walk straight into this. Breach carries the higher European fine tier under Article 85(2). Trap 2 — children's age is fourteen. Article 25c requires a parent's or guardian's consent for consent-based processing of anyone under fourteen, including direct offers of information society services. Bulgaria chose the lowest age the European rulebook permits, so a global product built to sixteen is over-compliant here, and one built to thirteen is non-compliant. Trap 3 — the six-month recruitment ceiling. Article 25k(1) caps retention of unsuccessful candidates' data at six months absent consent, and Article 25k(2) forces return of original or notarised documents within six months. Applicant tracking systems set to a two-year default breach this. Trap 4 — a disapplied clause still printed in the law. Article 25z(2) sets out ten criteria for balancing free expression against privacy in journalism. The Constitutional Court declared it unconstitutional by Decision No. 8 of 2019, published in State Gazette No. 93 of 26 November 2019. The text remains in the consolidated statute with only a bracketed note, and Article 85(2) still lists 'Article 25z, paragraphs 1 and 2' among the punishable breaches. A naive text search reads this as binding. It is not. Trap 5 — a language requirement on your systems, and named-person duties. Accountancy Act Article 11(2): where accounting software is used it must be built to this Act's requirements and must allow the data it processes and its output documents to be in the Bulgarian language. Separately, Personal Data Protection Act Article 25b requires you to notify the regulator of your data protection officer's name, Bulgarian personal identification number (or the equivalent for a foreigner) and contact details, and every later change. Article 25i requires employers to adopt and publish written rules and procedures for whistleblowing systems, restrictions on internal company resources, and any access-control, working-time or discipline-monitoring systems. Article 25zh(2) bans using the Bulgarian personal identification number as the only means of identifying a user for remote access to an online service.
Sources
- Official sourceAgency for Public Enterprises and Control, Republic of BulgariaPersonal Data Protection Act, Articles 25b, 25c, 25g, 25i, 25k, 25zh and 25z(2) with the unconstitutionality note
aref.government.bg
“(2) (Обявена за противоконституционна с РКС № 8 от 2019 г. - ДВ, бр. 93 от 2019 г.)”
Link checked 18 August 2026
- Official sourceAgency for Public Procurement Control (official copy of the Act)Accountancy Act, Article 11(2) — accounting software must be able to produce data and output documents in Bulgarian
appk.government.bg
“Когато при осъществяване на счетоводството се използва счетоводен софтуер, той трябва да е разработен при спазване на изискванията на този закон и да дава възможност обработваните чрез него данни и изходните документи да са на български език.”
Link checked 18 August 2026
What is changing soon in Bulgaria?
Two dated changes are already fixed. From 12 January 2027 every cloud provider must let customers move their data out for free. Bulgaria's new cybersecurity duties started on 13 February 2026 and enforcement is only now warming up. The biggest live risk is not Bulgarian at all: Europe's approval of United States data transfers is being challenged, and Europe's own privacy board asked the Commission on 31 July 2026 to re-examine it.
DATED AND CERTAIN. 12 January 2027 — the European Data Act (Regulation (EU) 2023/2854), applicable since 12 September 2025, requires all cloud switching charges and data egress fees to fall to zero. Its Chapter VII also restricts third-country government access to non-personal data held in the European Union. 13 February 2026 — Bulgaria's amended Cybersecurity Act entered into force on publication in State Gazette No. 17. Registration of essential and important entities, incident reporting and management accountability all began then. Fines reach 10 million euro or 2 percent of worldwide turnover for essential entities, and 7 million euro or 1.4 percent for important entities, with stated minimums of 25,000 euro and 12,500 euro. Supervisory practice is new and untested. 1 January 2026 — Bulgaria adopted the euro. Every monetary threshold and fine expressed in Bulgarian lev must now be read in euro at the fixed rate of 1.95583 lev to the euro. Contracts, retention schedules and accounting systems all had to be converted. 2 August 2026 — the European Union Artificial Intelligence Act's transparency obligations started applying. DORMANT SWITCHES — powers already held that could change the picture with no consultation. 1. The Electronic Communications Act's access regime keeps being widened by ordinary amendment and then trimmed by the Constitutional Court. Parliament can add a new authorised requester to the list of bodies that may pull six months of connection records in a single amending act. 2. The Gambling Act's control-local-server rule sits in primary legislation and its scope depends on what counts as a licensed online organiser. Extending the licence perimeter extends the localisation. 3. Defence and national security processing is carved out of the Personal Data Protection Act entirely by Article 1(5) 'in so far as a special law does not provide otherwise', so a special law can move a category of processing out of the general regime. AT EUROPEAN LEVEL, NOT ADOPTED — do not plan around these: the Digital Omnibus proposal of 19 November 2025 (which would extend breach notification from 72 to 96 hours), the Cloud and AI Development Act proposed 3 June 2026, and the European cloud certification scheme, deadlocked since 2020.
Sources
- Official sourceState Gazette of the Republic of BulgariaAct amending and supplementing the Cybersecurity Act, State Gazette No. 17 of 13 February 2026
dv.parliament.bg
Link checked 18 August 2026
- Official sourceCouncil of the European UnionBulgaria ready to use the euro from 1 January 2026 — Council takes final steps
consilium.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2023/2854 (Data Act) — zero switching charges from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
Bloc rules
Made by a group of countries together. Applies inside every member country.
1 rule here
Layer 2
National rules
Added by this country on top of any bloc rules.
3 rules here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
7 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
Bloc rules1 rule
Регламент (ЕС) 2016/679 (Общ регламент относно защитата на данните)
Directly binding regulation · Regulation (EU) 2016/679
Europe's privacy rulebook is the base layer in Bulgaria. It does not require data to stay in Europe. It regulates the conditions on which data leaves, and it is where almost all of the compliance work sits.
Enforced by Commission for Personal Data Protection
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Important public interest, Someone's life is at risk
What it makes you do
- Tell people what you do
- Secure the data
- Keep records of processing
- Assess high-risk projects
- Let people see their data
- Let people delete their data
- Let people take their data elsewhere
- Put a transfer safeguard in place
- Written vendor contract
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Appoint a local representativeOnly for controllers outside the European Union caught by Article 3(2). The representative may be in any member state, not specifically Bulgaria.
What it costs if you get it wrong
- Percentage of global turnover: €20,000,000 or 4% of worldwide group turnover — about $23 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Order to stopOrder to stop processing or suspend transfers outside Europe
- Claims by individualsCompensation claims by affected individuals
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 — General Data Protection Regulation
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 — free flow of non-personal data; bans member state localisation except on public security grounds
eur-lex.europa.eu
Link checked 18 August 2026
National rules3 rules
Закон за защита на личните данни
Act of parliament · State Gazette No. 1 of 4 January 2002; rewritten by State Gazette No. 17 of 26 February 2019; last amendment traced State Gazette No. 84 of 6 October 2023
Bulgaria's own privacy statute. It adds no residency rule at all, but it does add real national duties on children, employees, identity documents and the data protection officer. It also treats Switzerland as if it were a European Union country.
Enforced by Commission for Personal Data Protection
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Appoint a data protection officerArticle 25b: notify the regulator of the officer's name, Bulgarian personal identification number and contact details, and every later change.
- Get a parent's consent for children — applies at: under 14
- Delete data after a period — applies at: Unsuccessful job applicants, unless they consent to longer, 6 monthsArticle 25k.
- Delete data after a period — applies at: Data received with no lawful basis must be returned, erased or destroyed, 1 monthArticle 25a. The erasure must be documented.
- Keep records of processingArticle 25i: employers must adopt written rules for whistleblowing systems, restrictions on internal company resources and access-control, working-time or discipline-monitoring systems.
- Secure the dataArticle 25zh: the Bulgarian personal identification number may not be the sole means of identifying a user for remote access to a service.
What it costs if you get it wrong
- Percentage of global turnover: The lev equivalent of the European caps in Article 83(4) and 83(5) of Regulation (EU) 2016/679, now read in euro — about $23 millionBreach of the national add-on articles, including the ban on copying identity documents and the children's rule
- Fixed maximum fine: 5,000 Bulgarian lev (about 2,600 euro, roughly $3,000), doubled on repeat — about $3 thousandAny other breach of this Act (Article 86)
Sources
- Official sourceAgency for Public Enterprises and Control, Republic of BulgariaPersonal Data Protection Act (Закон за защита на личните данни), consolidated text
aref.government.bg
“Обработването на данни на субект на данни - лице, ненавършило 14 години, въз основа на съгласие ... е законосъобразно само ако съгласието е дадено от упражняващия родителски права родител или от настойника на субекта на данните.”
Link checked 18 August 2026
Решение № 8 от 2019 г. на Конституционния съд на Република България
court decision · Published in State Gazette No. 93 of 26 November 2019; declares Article 25z(2) of the Personal Data Protection Act unconstitutional
The privacy law still prints ten criteria for balancing journalism against privacy. The Constitutional Court declared that paragraph unconstitutional in 2019 and it cannot be enforced. The penalty article was never tidied up and still lists it.
Enforced by Constitutional Court of the Republic of Bulgaria
Sources
- Official sourceAgency for Public Enterprises and Control, Republic of BulgariaPersonal Data Protection Act, Article 25z(2) carrying the unconstitutionality note, and Article 85(2) which still penalises it
aref.government.bg
“(2) (Обявена за противоконституционна с РКС № 8 от 2019 г. - ДВ, бр. 93 от 2019 г.) При разкриване чрез предаване, разпространяване или друг начин ... балансът между свободата на изразяване и правото на информация и правото на защита на личните данни се преценява въз основа на следните критерии”
Link checked 18 August 2026
- Official sourceConstitutional Court of the Republic of BulgariaConstitutional Court of the Republic of Bulgaria — acts database
constcourt.bg
Link checked 18 August 2026
Закон за киберсигурност, изменен и допълнен
Act of parliament · Original: State Gazette No. 94 of 13 November 2018. Transposing amendment: State Gazette No. 17 of 13 February 2026, in force on publication
Bulgaria's cybersecurity law was rewritten in February 2026 to bring in Europe's network and information security directive. It imposes no data localisation, but it does impose new reporting clocks and turnover-based fines, and it replaced the old two-hour reporting rule.
Enforced by Ministry of Electronic Governance
What it makes you do
- Report cyber incidents — within 24 hours, from 13 February 2026Early warning within 24 hours of establishing a significant incident.
- Report cyber incidents — within 72 hours, from 13 February 2026Full incident notification within 72 hours; 24 hours for qualified trust service providers.
- Register or notify — from 13 February 2026The Minister of Electronic Governance creates and maintains the register of essential and important entities.
- Secure the data — from 13 February 2026
- Independent audit — from 13 February 2026
What it costs if you get it wrong
- Percentage of global turnover: €10,000,000 or 2% of worldwide annual turnover, whichever is higher, minimum €25,000 — about $12 millionEssential entities
- Percentage of global turnover: €7,000,000 or 1.4% of worldwide annual turnover, whichever is higher, minimum €12,500 — about $8 millionImportant entities
Sources
- Official sourceState Gazette of the Republic of BulgariaAct amending and supplementing the Cybersecurity Act, State Gazette No. 17 of 13 February 2026
dv.parliament.bg
“до 24 часа след установяването на значителен инцидент”
Link checked 18 August 2026
- Official sourceMinistry of Labour and Social Policy (official copy of the Act)Cybersecurity Act (Закон за киберсигурност), pre-2026 consolidated text showing the superseded two-hour reporting rule
mlsp.government.bg
Link checked 18 August 2026
Industry rules7 rules
Закон за хазарта
Act of parliament · State Gazette No. 26 of 30 March 2012; last amendment State Gazette No. 26 of 27 March 2025; Article 6 · Online gaming
The one genuine Bulgarian data-residency wall. A licensed online gambling operator must keep a control server holding all its data physically inside Bulgaria and stream live game session data to the tax authority.
Enforced by National Revenue Agency
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Keep the data in the countryArticle 6(4): all data must be stored on a data storage device — a control local server — located on the territory of the Republic of Bulgaria. Article 6(2) says that means only the geographic territory of the country.
- Register or notifyArticle 6(1)(2): the communications equipment and the central point housing the central computer system must be in Bulgaria or another European Union member state.
- Keep data for a minimum period — 1 yearArticle 6(5): at least twelve months from collection. Article 6(4) adds five years after the limitation period for public liabilities expires.
- Independent auditArticle 6(1)(4): a system feeding session information in real time to a server of the National Revenue Agency.
What it costs if you get it wrong
- Loss of your licenceOperating outside the licence conditions, including the equipment location requirements
Sources
- Official sourceBulgarian Institute of Metrology (official copy of the Act)Gambling Act (Закон за хазарта), Article 6
bim.government.bg
“комуникационното оборудване и централният пункт, в който се намира централната компютърна система ... да са разположени на територията на Република България или на територията на друга държава - членка на Европейския съюз”
Link checked 18 August 2026
Закон за електронните съобщения, чл. 251б – 251и, чл. 304 – 307
Act of parliament · State Gazette No. 41 of 22 May 2007; retention chapter inserted by State Gazette No. 24 of 2015, in force 31 March 2015 · Telecoms
Telecoms operators must keep six months of connection records and build interception equipment wired into two Bulgarian state agencies. The law does not say where the retained records must physically sit, but the interception equipment cannot be run from abroad.
Enforced by Communications Regulation Commission
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Keep data for a minimum period — 6 monthsArticle 251b(1): six categories of connection data — source, destination, date, time and duration, type, user device, and cell identifier.
- Keep logsArticle 251g(7): a non-public register of every access order must be kept.
- Secure the dataArticles 304, 305 and 307: operators must provide, commission and maintain at their own expense interception interfaces feeding the State Agency for Technical Operations and the State Agency for National Security, and must hand over encrypted traffic in its original form.
What it costs if you get it wrong
- Fixed maximum fineFailure to retain or to provide access on a valid court order
Sources
- Official sourceCommunications Regulation CommissionElectronic Communications Act (Закон за електронните съобщения), Articles 251b to 251i and 304 to 307
crc.bg
“Предприятията, предоставящи обществени електронни съобщителни мрежи и/или услуги, предоставят, въвеждат в експлоатация и поддържат за своя сметка прихващащи интерфейси”
Link checked 18 August 2026
Решение № 8 от 23 юни 2026 г. на Конституционния съд по к.д. № 19/2025 г.
court decision · Published in State Gazette No. 60 of 1 July 2026 · Telecoms
In June 2026 the Constitutional Court struck down the parts of the telecoms law that let the competition regulator pull six months of people's connection records for ordinary competition investigations. The wording is still in the printed statute but cannot be used.
Enforced by Constitutional Court of the Republic of Bulgaria
Sources
- Official sourceState Gazette of the Republic of BulgariaConstitutional Court Decision No. 8 of 23 June 2026 in case No. 19/2025, State Gazette No. 60 of 1 July 2026
dv.parliament.bg
“Обявява за противоконституционни разпоредбите на чл. 251б, ал. 2, изречение първо ... чл. 251в, ал. 1, т. 6 ... и чл. 251г, ал. 9 от Закона за електронните съобщения”
Link checked 18 August 2026
- Official sourceConstitutional Court of the Republic of BulgariaConstitutional Court case file No. 19/2025 — submissions on access to traffic data
constcourt.bg
Link checked 18 August 2026
Закон за счетоводството
Act of parliament · State Gazette No. 95 of 8 December 2015, in force 1 January 2016; last amendment State Gazette No. 61 of 2025, in force 31 October 2025; Articles 11 to 14 · Finance
Bulgaria's longest retention floors sit in the accounting law: fifty years for payroll, ten for the books, three for everything else. The law says records are kept at the enterprise, and your accounting software must be able to produce output in Bulgarian.
Enforced by National Revenue Agency
What it makes you do
- Keep data for a minimum period — 50 yearsPayroll sheets: fifty years, counted from 1 January of the reporting period following the one they relate to.
- Keep data for a minimum period — 10 yearsAccounting registers and financial statements, including documents for tax control, audit and subsequent financial inspections: ten years.
- Keep data for a minimum period — 3 yearsAll other carriers of accounting information: three years.
- Keep records of processingArticle 11(2): where accounting software is used, it must allow the data it processes and its output documents to be in the Bulgarian language.
What it costs if you get it wrong
- Fixed maximum fineFailure to keep accounting information for the statutory period
Sources
- Official sourceAgency for Public Procurement Control (official copy of the Act)Accountancy Act (Закон за счетоводството), Articles 11 to 14
appk.government.bg
“Счетоводната информация се съхранява на хартиен и/или на технически носител в предприятието”
Link checked 18 August 2026
Закон за геодезията и картографията
Act of parliament · State Gazette No. 29 of 7 April 2006; Articles 6, 15, 20 and 21 · Mapping and location
You cannot simply fly a survey over Bulgaria. Aerial photography needs advance sign-off from five state bodies, and state-commissioned survey material has to be deposited in a national fund, some of it permanently.
Enforced by Agency for Geodesy, Cartography and Cadastre
What it makes you do
- Register or notifyArticle 15(2): aerial photography and other remote-sensing methods require prior clearance with the Ministry of Defence, the Ministry of the Interior, the State Agency for National Security, the Ministry of Foreign Affairs and the transport ministry.
- Keep data for a minimum period — 50 yearsArticle 21(3): carriers of field measurement and computation data, fifty years. Article 21(2) keeps aerial films, digital aerial data and satellite imagery indefinitely.
- Keep the data in the countryArticle 20: state-commissioned survey material is deposited in the state Geo-Cartographic Fund held by the Agency for Geodesy, Cartography and Cadastre. Article 6(1) makes such material public except where it is classified.
What it costs if you get it wrong
- Fixed maximum fineAerial survey without clearance
- Criminal liabilityUnauthorised handling of classified geodetic material under the Classified Information Protection Act
Sources
- Official sourceMinistry of Regional Development and Public WorksGeodesy and Cartography Act (Закон за геодезията и картографията), Articles 6, 15, 20 and 21
mrrb.bg
“На съхраняване за срок 50 години подлежат носителите с данни от полските измервания и изчисления”
Link checked 18 August 2026
Закон за електронното управление; Наредба за общите изисквания към информационните системи, регистрите и електронните административни услуги
Act of parliament · Act: State Gazette No. 46 of 12 June 2007, state cloud definition added by State Gazette No. 50 of 2016. Ordinance: Council of Ministers Decree No. 3 of 9 January 2017, State Gazette No. 5 of 17 January 2017 · Government
Bulgaria runs a shared state cloud for public bodies, but neither the e-government law nor its implementing ordinance actually says government data must stay in Bulgaria. The pressure to use it comes from procurement and funding, not a residency ban. No localisation rule found, checked 18 August 2026.
Enforced by Ministry of Electronic Governance
What it makes you do
- Hold a security certificateThe State hybrid private cloud is defined as centralised state infrastructure spread over several sites meeting protected-data-centre criteria, providing isolated physical and virtual resources to state bodies.
- Keep records of processingArticle 7e requires a public register of e-government projects and Article 7f a register of information resources held by administrative bodies.
Sources
- Official sourceAgency for Quality of Social Services (official copy of the Act)Electronic Governance Act (Закон за електронното управление), Articles 7c to 7f and the definition of the State hybrid private cloud
aksu.government.bg
“"Държавен хибриден частен облак" е централизирана държавна информационна инфраструктура (сървъри, средства за съхранение на данни, комуникационно оборудване, съпътстващо оборудване и системен софтуер), разпределена в няколко локации”
Link checked 18 August 2026
- Official sourceAgency for Quality of Social Services (official copy of the Ordinance)Ordinance on the general requirements for information systems, registers and electronic administrative services
aksu.government.bg
Link checked 18 August 2026
Закон за кредитните институции, чл. 62
Act of parliament · Credit Institutions Act, Article 62 (bank secrecy) · Banking
Bulgarian banking law contains no rule about where data lives, but bank secrecy limits who may see it. That is a contract problem, not a hosting problem: a normal supplier data agreement is not enough for a bank's cloud provider.
Enforced by Bulgarian National Bank
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Extra vendor secrecy termsBank secrecy binds staff and anyone who learns the information in the course of their work. A standard data processing agreement does not discharge it; cloud contracts need explicit secrecy undertakings.
- Written vendor contractOutsourcing policy is a required element of a bank's internal governance. For financial entities Regulation (EU) 2022/2554 additionally requires the contract to state where data is processed and stored.
What it costs if you get it wrong
- Criminal liabilityUnlawful disclosure of bank secrecy
- Loss of your licenceSerious supervisory breach
Sources
- Official sourceBulgarian National BankCredit Institutions Act (Закон за кредитните институции), Article 62 and internal governance requirements
bnb.bg
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2022/2554 (Digital Operational Resilience Act)
eur-lex.europa.eu
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The Commission for Personal Data Protection's 2025 enforcement statistics — number of complaints, inspections, fines and their total value
The regulator's own website, cpdp.bg, returned an HTTP 503 server error on every attempt from our infrastructure on 18 August 2026, including its published 2025 annual report. We therefore relied on the European Data Protection Board's February 2026 coordinated-enforcement annex for its posture instead. Enforcement is rated active on that basis, but the rating is one notch less certain than usual.
The current composition of the Commission for Personal Data Protection — whether the chair and members are within a valid mandate or serving on after expiry
Secondary Bulgarian media reporting suggests a selection procedure for new leadership has been running. The National Assembly's own appointments page is rendered by JavaScript and returned no readable content, and the regulator's site was unreachable. We could not verify this from a government source and do not assert it.
Whether the Personal Data Protection Act has been amended after State Gazette No. 84 of 6 October 2023, in particular for the euro changeover on 1 January 2026
The consolidated text we verified carries amendments only to October 2023. Bulgaria's adoption of the euro means lev amounts in statutes are now read in euro at the fixed rate, but we could not confirm whether the Act's own text was formally amended.
Retention periods for medical records held by Bulgarian healthcare providers
The National Health Insurance Fund's guidance pages were protected by an anti-bot challenge and returned HTTP 403, and the Ministry of Health e-health page carries no ordinance references. We did not want to assert periods we could not read in an official text.
Bulgaria's Standard Audit File for Tax (SAF-T) phase-in dates and scope
The National Revenue Agency's SAF-T pages and question-and-answer documents refused connections from our infrastructure. Bulgaria clearly has a SAF-T programme, with the Agency writing to around 470 large taxpayers about a first reporting period, but we could not read the official dates and thresholds, so we have not stated them as fact.
The five-year record-keeping period under Bulgaria's anti-money-laundering law
This is a standard European requirement and almost certainly applies, but we did not fetch the operative Bulgarian article from a government source within this run, so it is not asserted in the retention answer.
Whether any Bulgarian banking, insurance or securities regulator circular imposes a data location or in-country hosting condition
We searched the Bulgarian National Bank's and the Financial Supervision Commission's own legal frameworks and found no such requirement, but their ordinance libraries are large and we did not read every circular. Recorded as 'no rule found, checked 18 August 2026', not as 'there is no rule'.
Whether the six-month telecoms retention regime survives European Union law challenge in its current form
The Court of Justice has repeatedly held general and indiscriminate retention incompatible with European Union law, and Bulgaria's own Constitutional Court has trimmed the access rules three times. Operators still retain for six months. Whether and when the underlying obligation itself falls is not something we can state.
The exact date on which Constitutional Court decisions take legal effect
Bulgarian constitutional practice is that a decision takes effect a short fixed period after publication in the State Gazette. We recorded the publication dates (26 November 2019 and 1 July 2026) rather than assert an effective date we did not read in an official text.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.