What Is Personal Data Protection Act (PDPA)?
Bulgaria's Personal Data Protection Act (PDPA) was enacted on 21 December 2001 and entered into force on 1 January 2002. Bulgaria is an EU member state, so the GDPR applies directly, with the PDPA providing national rules and targeted modifications. The CPDP's published consolidated English text lists amendments through State Gazette 70/2024. A real currentness gap remains: State Gazette issue 69/2026 records a further amendment to Article 7(4), while the CPDP English consolidated page is not fully current. No newer CPDP English consolidated text was located in the 7 September 2026 review, so a current Bulgarian-text reconciliation is still needed for the remaining amendments. The source conflict over humanitarian or disaster processing is resolved by the official Bulgarian statutory text: the rule is Article 25o, not Article 25n, and it says GDPR Articles 12-21 and 34 do not apply in the described processing. The CPDP English HTML rendering's contrary wording appears to be a numbering and translation/rendering error; the Bulgarian statutory text controls.
At a glance
- Full name
- Personal Data Protection Act (PDPA)
- Short code
- PDPA
- Jurisdiction
- Bulgaria
- Enacted
- 2001
- Last major update
- 2026 amendments recorded in State Gazette issue 69/2026, including Article 7(4); the CPDP English consolidated text remains through State Gazette 70/2024 and is not fully current
- Regulator
- Commission for Personal Data Protection (CPDP)
- Private right of action
- Limited
- Statutory citation
- Personal Data Protection Act (PDPA)
Scope, who PDPA covers
Protected data
Data subject rights
GDPR transparency and information rights under Articles 12-14, subject to PDPA Article 37a and targeted exceptions
Right of access under Article 15, with exclusions or refusals for specified archival, statistical, journalism, expression, humanitarian, and disaster processing
Right to rectification under Article 16, subject to corresponding statutory exceptions
Right to erasure under Article 17, subject to applicable exceptions and Article 37a restrictions
Right to restriction of processing under Article 18, subject to specified archival, statistical, journalism, expression, humanitarian, and disaster rules
Right to data portability under Article 20, subject to statutory exclusions and refusals
Right to object under Article 21, subject to specified archival, statistical, journalism, expression, humanitarian, and disaster rules
For humanitarian or disaster processing under PDPA Article 25o, the official Bulgarian text states that GDPR Articles 12-21 and 34 do not apply; this controls over the conflicting CPDP English rendering
Protection concerning automated decision-making under Article 22; no express disapplication was located in the listed Article 25h, 25k, 25l, or 25n provisions
Right to complain to the CPDP within 6 months of becoming aware of an infringement and no later than 2 years after it occurred
Right to appeal a CPDP decision within 14 days of receipt under the Administrative Procedure Code
Notable features
Bulgaria combines directly applicable GDPR rights with national PDPA derogations for journalism and expression, archival processing, statistics, and humanitarian or disaster processing. The former Article 25h(2) balancing criteria were declared unconstitutional by Constitutional Court Decision No. 8/2019. The principal currentness trap is the CPDP consolidated text’s omission of identified 2026 amendments; the official Bulgarian text resolves the former CPDP HTML/PDF conflict by placing the humanitarian/disaster rule in Article 25o and disapplying GDPR Articles 12-21 and 34.
Enforcement & penalties
Regulator: Commission for Personal Data Protection (CPDP)
Penalties: GDPR Article 83 applies directly: up to €10 million or 2% of annual worldwide turnover for Article 83(4) violations, and up to €20 million or 4% of annual worldwide turnover for Article 83(5) violations. PDPA Article 85 assigns specified PDPA violations to the GDPR Article 83(4) or 83(5) amounts using Article 83(2) criteria. No separate universal Bulgarian fine schedule limited to public bodies, and no general public-body fine exemption, was located.
Private right of action: The CPDP complaint process, its three-month progress or outcome notification, and a 14-day appeal route under the Administrative Procedure Code are the identified mechanisms. A general private damages route was not described in the reviewed report.
Relevance to data brokers
Not located. No dedicated data-broker or public-record deletion route, including for data associated with the Commercial Register, was located. The identified mechanisms are the general GDPR and PDPA rights, the CPDP complaint route, and applicable restrictions concerning public or population-register data.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Is Bulgaria’s privacy-law text fully current?+
Not yet verified in English. State Gazette issue 69/2026 records a further Article 7(4) amendment, while the CPDP English consolidated page lists amendments only through State Gazette 70/2024. No newer CPDP English consolidated text was located, so a current Bulgarian-text reconciliation remains needed for the remaining amendments.
Which version applies to humanitarian or disaster processing?+
The official Bulgarian statutory text controls: PDPA Article 25o says that processing for humanitarian purposes by public authorities or humanitarian organisations, and processing in disasters, is lawful, and that GDPR Articles 12-21 and 34 do not apply in those cases. The CPDP English HTML rendering says the opposite and labels the provision Article 25n; that rendering is not treated as authoritative here.
Can I complain to Bulgaria’s data-protection regulator?+
Yes. Complaints or alerts must be submitted in Bulgarian through the stated CPDP channels, including in person, post, fax, qualified-e-signature email, or secure e-service. The filing window is 6 months after becoming aware of the infringement and no later than 2 years after it occurred.
Does Bulgaria have a dedicated data-broker deletion route?+
Not located. No dedicated data-broker or public-record deletion route was located in the reviewed materials. The identified mechanisms are the general GDPR and PDPA rights and the CPDP complaint process.
Official sources & citations
Other international privacy regimes
PDPA sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
