Doing Business In..._2026

BULGARIA Law and Practice Contributed by: Marin Sarafov, Petya Norova, Iva Georgieva and Eduard Milchev, G&P Law

8.3 Role and Authority of the Data Protection Agency The CPDP is the independent national supervisory authority responsible for monitoring and enforcing compliance with the GDPR and PDPA. It is established as an independent public authority and performs its functions free from external influence, in accordance with the requirements of the GDPR. The CPDP is entrusted with supervising the applica - tion of data protection legislation across both the pub - lic and private sectors. The CPDP exercises the full range of investigative, corrective, authorisation and advisory powers con - ferred by the GDPR. In particular, it may carry out planned or ad hoc inspections, investigate complaints submitted by data subjects, require controllers and processors to provide information and documenta - tion, conduct audits, etc, during investigations. Fol - lowing an investigation, the CPDP may issue warnings and reprimands, ordering controllers or processors to comply with the GDPR. The CPDP also has extensive enforcement powers. It may impose administrative fines in accordance with the GDPR, taking into account factors such as the nature, gravity and duration of the infringement, etc. As a member of the European Data Protection Board (EDPB), the CPDP co-operates with the supervisory authorities of other EU member states through the GDPR’s consistency and co-operation mechanisms. Decisions of the CPDP are subject to judicial review before the Bulgarian administrative courts. In addition to the supervisory proceedings before the CPDP, data subjects may seek judicial protection and compen - sation for material and non-material damages arising from infringements of data protection legislation in accordance with the GDPR and Bulgarian law. 9. Looking Forward 9.1 Upcoming Legal Reforms Since Bulgaria joined the Eurozone in January 2026, much of its legislation is being adapted.

The GDPR’s core principles – lawfulness, fairness and transparency, purpose limitation, data minimisation, storage limitation, integrity and confidentiality, and accountability – apply in full. The Commission for Personal Data Protection (CPDP) is the national supervisory authority responsible for monitoring and enforcing compliance with data pro - tection legislation. It exercises the full range of investi - gative and corrective powers conferred by the GDPR, including the power to conduct inspections, issue warnings and reprimands, order corrective measures and impose administrative fines. The PDPA supplements the GDPR by regulating mat - ters left to national law. 8.2 Geographical Scope The GDPR applies in Bulgaria on the basis of both the establishment and the targeting criteria, giving it broad extraterritorial effect. Under the establishment criterion, the GDPR applies to the processing of personal data carried out in the context of the activities of an establishment of a con - troller or processor in the EU, irrespective of whether the processing itself takes place within the EU. Under the targeting criterion, the GDPR also applies to controllers and processors not established in the EU that process the personal data of data subjects in the EU, where the processing activities relate to the offering of goods or services to those individuals – irrespective of whether payment is required – or the individuals’ behaviour is monitored, in so far as that behaviour takes place within the EU. The GDPR also applies to the processing of personal data by a controller that is not established in the EU where the law of a member state applies by virtue of public international law. Controllers and processors subject to the GDPR solely by virtue of the targeting criterion are generally required to designate a representative established in a member state of the EU, unless one of the exemptions provided for in the GDPR applies.

118 CHAMBERS.COM

Powered by