Law / Bulgaria

GDPR Articles 33-34, Breach Notification

Regulation (EU) 2016/679, Arts. 33-34

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018.

A breach notification rule binding public and private bodies.

As of 24 August 2026.

What it requires

  • Notify KZLD within 72 hours of becoming aware of a personal-data breach affecting a person in Bulgaria, and notify affected individuals without undue delay where the breach is likely to result in a high risk to them, using KZLD's own Bulgarian-language notification template.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A controller must notify KZLD within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. Commentary adds a procedural detail, that KZLD maintains non-public breach registers and approved notification templates in Bulgarian only, which is a procedural addition rather than a substantive derogation from the 72-hour standard; no primary text was read.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics

Read the law

GDPR Arts. 33-34
DLA Piper commentary

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app