Dashboard / Global Laws / BG-PDPA

🇧🇬Personal Data Protection Act

← Back to laws in Bulgaria

Personal Data Protection Act

Personal Data Protection Act

Bulgaria applies this national law alongside the GDPR. The summary below concentrates on the national overlay so that the GDPR baseline is not duplicated.

Current official version

Status: Current CPDP consolidation includes amendments through State Gazette No. 70 of 20 August 2024

Citation: Personal Data Protection Act, especially arts. 12, 25a-25d, 25f-25i and 38-39

Regulator: Commission for Personal Data Protection (CPDP)

Source basis: Current official CPDP Bulgarian PDF through State Gazette No. 70/2024 downloaded and cross-checked against the CPDP English publication on 22 August 2026.

How the national law fits with GDPR

The Act supplements the GDPR, establishes the CPDP and judicial supervisory arrangements, and adds Bulgarian rules for children, unsolicited data, identity documents, monitoring, expression, public access and remedies.

National additions and variations

  • Article 25c requires parental-responsibility holder or guardian consent where consent-based processing concerns a child under 14, including directly offered information-society services.
  • Article 25a requires personal data received without a lawful basis or contrary to GDPR principles to be returned within one month or, where return is impossible or disproportionate, erased or destroyed with documentation.
  • Article 25g permits copying an identity card, driving licence or residence document only where legislation expressly provides for copying.
  • Article 25b requires notification to the CPDP of the DPO identity and contact details and later changes; Article 25d requires internal protective rules for large-scale processing or systematic large-scale monitoring of publicly accessible areas.
  • The Act contains national rules for deceased-person data, public registers and expression; journalism and expression processing requires a case-specific balance after Constitutional Court Decision No. 8 of 2019.
Implementation boundary

The controlling PDF is Bulgarian. The CPDP English page is a translation aid and must be checked against the current Bulgarian consolidation and State Gazette amendments.

Operational approach

First maintain the GDPR control set. Then document whether this country is in scope and apply the national controls to the affected people, systems and processing. Keep article-level evidence for child consent, employment, special-category or criminal data, research, electronic communications, identifiers, surveillance and any rights restriction relied upon.

What this means for you

Do not treat GDPR compliance as automatic compliance with PDPA. Record the national trigger, the responsible owner, the local procedure and the current official source reviewed.