Skip to the content
Global Data RulesData governance rules, country by country

Bulgaria

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Bulgaria — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: MediumEnforcement: Active

Bulgaria is an ordinary European Union country for data. Personal data can leave, as long as you use one of the standard European transfer tools. No general rule forces data to stay in Bulgaria. Online gambling is the exception. A control server must physically sit on Bulgarian soil. Bulgaria switched to the euro on 1 January 2026, so all fines are now in euro.

Data governance in Bulgaria

The eight things that decide how you handle data about people in Bulgaria. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, it can reach you when you have no office in Bulgaria. The European Union's privacy rulebook applies to anyone who offers goods or services to people in Europe. It also applies to anyone who watches what they do online. Bulgaria's own Personal Data Protection Act sits on top and adds extra local duties. There is no revenue or staff-count threshold. Bulgaria does not demand its own local representative. The European-wide duty to name a representative in Europe is the only one, and that person can be in any European country.

What you have to do here:
Appoint a representative · Appoint a data protection officer

Where the data is allowed to live

In general, yes. Bulgaria has no law telling ordinary businesses to keep personal data inside the country. Data moves freely to the rest of Europe, to Switzerland, and to countries Europe has approved. Anywhere else needs a standard contract or a similar tool. Two industries are different. Online gambling operators must keep a control server physically in Bulgaria. Telecoms operators must build interception equipment that plugs into Bulgarian state agencies, and that cannot sit abroad.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

Bulgaria uses Europe's system, not its own. There is no Bulgarian list of banned countries and no Bulgarian permit to apply for. If the destination is inside Europe, the wider European Economic Area or Switzerland, nothing extra is needed. Otherwise you need one of three things. An official European decision that the country is safe enough. Or the standard European contract. Or approved group-wide rules. One Bulgarian point: Bulgarian law expressly puts Switzerland on the same footing as a European Union country.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · Needed for a contract · Legal claims

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Commission for Personal Data Protection is the main regulator. It is real, staffed, and it does issue formal decisions, including ones published across Europe. But it does not hit hard. In a Europe-wide check on deletion rights reported in February 2026, it contacted twenty-three organisations. It opened no formal investigations, imposed no penalties, and said it did not plan to. A separate inspectorate polices the courts and prosecutors. Cybersecurity has its own separate regulators.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

Bulgaria has strong minimum keeping periods and a few strict deletion deadlines. You must keep payroll records for fifty years. Accounting books and financial statements go ten years. Other accounting papers go three years. Telecoms firms keep connection records for six months. Going the other way, job applicants' data must be deleted within six months unless they agree otherwise. Data you were given with no legal basis must be returned or destroyed within one month.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There are at least three deadlines and they do not agree. A personal data breach must reach the privacy regulator within seventy-two hours. Under the cybersecurity law rewritten in February 2026, an early warning must reach the response team within twenty-four hours. A fuller report follows within seventy-two hours. Trust service providers get twenty-four hours for that fuller report. Financial firms answer to the separate European financial-resilience rules on top.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people out in Bulgaria. You may not photocopy someone's identity card, driving licence or residence permit unless a law lets you. Children need a parent's consent up to age fourteen, not sixteen. Job applicant files must go within six months. Your accounting software must be able to produce output in Bulgarian. And one clause of the privacy law was struck down by the Constitutional Court in 2019, but is still printed in the statute.

What you have to do here:
Get a parent's consent for children · Appoint a data protection officer · Delete data after a period

What's changing next

Two dated changes are already fixed. From 12 January 2027 every cloud provider must let customers move their data out for free. Bulgaria's new cybersecurity duties started on 13 February 2026, and enforcement is only now getting going. The biggest live risk is not Bulgarian at all. Europe's approval of United States data transfers is being challenged. Europe's own privacy board asked the Commission on 31 July 2026 to re-examine it.

What you have to do here:
Make switching cloud provider possible

What to do: Diarise 12 January 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries6 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Online gaming

Online gaming data needs a copy kept in the country

Official name: Закон за хазарта · State Gazette No. 26 of 30 March 2012; last amendment State Gazette No. 26 of 27 March 2025; Article 6 · Act of parliament

In forceA copy must stay

The one real Bulgarian rule forcing data to stay in the country. A licensed online gambling operator must keep a control server holding all its data physically inside Bulgaria. It must also stream live game session data to the tax authority.

In force since 1 July 2012

Enforced by National Revenue Agency

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

Telecoms

Telecoms rules

Official name: Закон за електронните съобщения, чл. 251б – 251и, чл. 304 – 307 · State Gazette No. 41 of 22 May 2007; retention chapter inserted by State Gazette No. 24 of 2015, in force 31 March 2015 · Act of parliament

Partly in forceYes, with paperwork

Telecoms operators must keep six months of connection records and build interception equipment wired into two Bulgarian state agencies. The law does not say where the retained records must physically sit, but the interception equipment cannot be run from abroad.

In force since 31 March 2015

Enforced by Communications Regulation Commission

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

Finance

Record-keeping rules for tax and accounts

Official name: Закон за счетоводството · State Gazette No. 95 of 8 December 2015, in force 1 January 2016; last amendment State Gazette No. 61 of 2025, in force 31 October 2025; Articles 11 to 14 · Act of parliament

In forceYes, with paperwork

Bulgaria's longest minimum keeping periods sit in the accounting law. Payroll goes fifty years, the books ten years, and everything else three years. The law says records are kept at the enterprise. Your accounting software must also be able to produce output in Bulgarian.

In force since 1 January 2016

Enforced by National Revenue Agency

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Children's data rules

Official name: Закон за защита на личните данни · State Gazette No. 1 of 4 January 2002; rewritten by State Gazette No. 17 of 26 February 2019; last amendment traced State Gazette No. 84 of 6 October 2023 · Act of parliament

In forceYes — store it anywhere

Bulgaria's own privacy statute. It has no rule forcing data to stay in the country. But it does add real national duties on children, employees, identity documents and the data protection officer. It also treats Switzerland as if it were a European Union country.

In force since 1 January 2002Enforced from 2 March 2019

Enforced by Commission for Personal Data Protection

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Cyber security rules

Official name: Закон за киберсигурност, изменен и допълнен · Original: State Gazette No. 94 of 13 November 2018. Transposing amendment: State Gazette No. 17 of 13 February 2026, in force on publication · Act of parliament

In forceYes — store it anywhere

Bulgaria's cybersecurity law was rewritten in February 2026 to bring in Europe's network and information security directive. It has no rule forcing data to stay in the country. It does add new reporting deadlines and fines based on turnover, and it replaced the old two-hour reporting rule.

In force since 13 February 2026

Enforced by Ministry of Electronic Governance

Applies across the European Union1 rule

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Регламент (ЕС) 2016/679 (Общ регламент относно защитата на данните) · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

Europe's privacy rulebook is the base layer in Bulgaria. It does not require data to stay in Europe. It regulates the conditions on which data leaves, and it is where almost all of the compliance work sits.

In force since 25 May 2018

Enforced by Commission for Personal Data Protection

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Important public interest, To save someone’s life

On the books, but not enforceable2 rules

These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.

General data protection law

Official name: Решение № 8 от 2019 г. на Конституционния съд на Република България · Published in State Gazette No. 93 of 26 November 2019; declares Article 25z(2) of the Personal Data Protection Act unconstitutional · Court decision

UnenforceableYes — store it anywhere

The privacy law still prints ten criteria for balancing journalism against privacy. The Constitutional Court declared that paragraph unconstitutional in 2019 and it cannot be enforced. The penalty article was never tidied up and still lists it.

In force since 26 November 2019

Enforced by Constitutional Court of the Republic of Bulgaria

Not fully verified — see “What we're not sure about” below.
Telecoms

Telecoms rules (Telecoms)

Official name: Решение № 8 от 23 юни 2026 г. на Конституционния съд по к.д. № 19/2025 г. · Published in State Gazette No. 60 of 1 July 2026 · Court decision

UnenforceableYes, with paperwork

In June 2026 the Constitutional Court struck down part of the telecoms law. That part let the competition regulator pull six months of people's connection records for ordinary competition investigations. The wording is still in the printed statute, but it cannot be used.

In force since 1 July 2026

Enforced by Constitutional Court of the Republic of Bulgaria

Who you would hear from

  • Комисия за защита на личните данни

    General privacy law supervision under the European rulebook and the Personal Data Protection Act

    Staffed and issuing formal decisions. Its decisions appear in the European Data Protection Board's document library, and it took part in the Board's 2025 coordinated enforcement action. It is cautious. In that action, reported in February 2026, it contacted 23 companies. It opened no formal investigations, imposed no corrective measures or fines, and said it did not plan to. Its own website returned a server error on every attempt from our infrastructure on 18 August 2026. So we could not verify its 2025 annual report figures or the current membership of the commission.

  • Инспекторат към Висшия съдебен съвет

    Supervises personal data processing by courts, prosecutors and investigating bodies acting in their judicial capacity

    A second, separate data protection supervisor created by Article 1(4)(2) of the Personal Data Protection Act. Its chief inspector issues penalty orders in its own right.

  • Министерство на електронното управление

    E-government, the shared state cloud, and the register of essential and important entities under the cybersecurity law

  • Комисия за регулиране на съобщенията

    Electronic communications networks and services

  • Национална агенция за приходите

    Tax, accounting records, and since 2020 the licensing and supervision of gambling including the local-server rule

  • Българска народна банка

    Banking supervision and payment systems; part of the euro area since 1 January 2026

  • Комисия за финансов надзор

    Insurance, pensions and securities markets

  • Държавна агенция "Национална сигурност"

    National security, anti-money-laundering financial intelligence, and clearance for aerial survey work

  • Агенция по геодезия, картография и кадастър

    Cadastre and the state Geo-Cartographic Fund

  • Конституционен съд на Република България

    Constitutional review; has repeatedly struck down parts of the telecoms data retention and access regime

    Active in this field. Decision No. 2 of 2015 struck down the earlier retention chapter, Decision No. 15 of 2020 struck down pandemic-era access wording, and Decision No. 8 of 23 June 2026 struck down competition-regulator access to retained traffic data.

  • Министерство на здравеопазването

    Health policy and the National Health Information System, which centrally holds electronic referrals and prescriptions

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The Commission for Personal Data Protection's 2025 enforcement statistics — number of complaints, inspections, fines and their total value

    We could not confirm the regulator's 2025 enforcement numbers. Its website, cpdp.bg, returned a server error on every attempt on 18 August 2026, including its published 2025 annual report. We used the European Data Protection Board's February 2026 coordinated-enforcement annex instead. Enforcement is rated active on that basis, but with less certainty than usual.

  • The current composition of the Commission for Personal Data Protection — whether the chair and members are within a valid mandate or serving on after expiry

    We could not confirm who currently sits on the Commission, or whether their terms have expired. Bulgarian media reporting suggests a selection procedure for new leadership has been running. The National Assembly's appointments page returned no readable content, and the regulator's site was down. We do not assert this either way.

  • Whether the Personal Data Protection Act has been amended after State Gazette No. 84 of 6 October 2023, in particular for the euro changeover on 1 January 2026

    We could not confirm whether the Act has been amended since State Gazette No. 84 of 6 October 2023. The consolidated text we checked carries amendments only to October 2023. Bulgaria's move to the euro means lev amounts in statutes are now read in euro at the fixed rate. Whether the Act's own text was formally amended for that, we do not know.

  • Retention periods for medical records held by Bulgarian healthcare providers

    We could not confirm how long Bulgarian healthcare providers must keep medical records. The National Health Insurance Fund's guidance pages blocked our checks, and the Ministry of Health's electronic health page gives no ordinance references. We did not want to state periods we could not read in an official text. If you handle medical records, check before you delete.

  • Bulgaria's Standard Audit File for Tax (SAF-T) phase-in dates and scope

    We could not confirm the dates and thresholds for Bulgaria's Standard Audit File for Tax (SAF-T). The National Revenue Agency's pages on it would not load for us. Bulgaria clearly has such a programme, and the Agency wrote to around 470 large taxpayers about a first reporting period. We have not stated the official dates and thresholds as fact.

  • The five-year record-keeping period under Bulgaria's anti-money-laundering law

    We could not confirm the five-year record-keeping period under Bulgaria's anti-money-laundering law. It is a standard European requirement and almost certainly applies. But we did not read the operative Bulgarian article on a government source, so we do not state it in the retention answer.

  • Whether any Bulgarian banking, insurance or securities regulator circular imposes a data location or in-country hosting condition

    We found no Bulgarian banking, insurance or securities rule about where data must be held. We searched the Bulgarian National Bank's and the Financial Supervision Commission's own legal pages. Their libraries are large and we did not read every circular. Treat this as 'no rule found, checked 18 August 2026', not as 'there is no rule'.

  • Whether the six-month telecoms retention regime survives European Union law challenge in its current form

    We cannot say whether the six-month telecoms retention rule will survive challenge under European Union law. The Court of Justice has repeatedly held general and indiscriminate retention incompatible with European Union law. Bulgaria's own Constitutional Court has trimmed the access rules three times. Operators still keep the data for six months. Whether and when the duty itself falls is not something we can state.

  • The exact date on which Constitutional Court decisions take legal effect

    We could not confirm the exact date on which Constitutional Court decisions take legal effect. Bulgarian constitutional practice is that a decision takes effect a short fixed period after publication in the State Gazette. We recorded the publication dates, 26 November 2019 and 1 July 2026, rather than state an effective date we could not read in an official text.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.