Law / Bulgaria

Bulgaria

European Union law applies in Bulgaria Bulgaria is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Bulgaria, described on this page below, applies here too.

13 of 15 named instruments researched to a stage, across five of the six areas of law we track: 12 in force and 1 enacted but not yet in force. As of 15 September 2026.

When they take effect11 of 13 carry a date, 2 do not.
2018: 4 instruments (4 in force) ’18 2019: 1 instrument (1 in force) 2020: 1 instrument (1 in force) ’20 2021: 0 instruments 2022: 0 instruments 2023: 3 instruments (3 in force) 2024: 0 instruments 2025: 0 instruments 2026: 2 instruments (2 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 2

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 5 in force, 1 enacted but not yet in force

Research summary (73 words)

Bulgaria gives the General Data Protection Regulation (GDPR) domestic effect through the Personal Data Protection Act (Закон за защита на личните данни, ZZLD, English: Personal Data Protection Act, PDPA), originally promulgated 2002 and substantially amended in 2019 for GDPR alignment. The Act's own text has not been located at primary source; the account rests on commentary (CMS, DLA Piper). No distinct Bulgarian biometric restriction beyond GDPR has been located, a negative finding two commentary sources agree on.

Breach notification

GDPR Articles 33-34, Breach Notification

Regulation (EU) 2016/679, Arts. 33-34GDPR Arts. 33-34

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify KZLD within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. Commentary adds a procedural detail, that KZLD maintains non-public breach registers and approved notification templates in Bulgarian only, which is a procedural addition rather than a substantive derogation from the 72-hour standard; no primary text was read.

What it requires

Comprehensive regime

Personal Data Protection Act (Zakon za zashtita na lichnite danni, ZZLD)

Закон за защита на личните данни (ЗЗЛД) Obn. DV. br.1 ot 4 yanuari 2002 g., as amended (English: Personal Data Protection Act, State Gazette No. 1 of 4 January 2002, as amended)CMS and DLA Piper commentary only

In force since 26 February 2019. Binds public and private bodies.

What this law does

Bulgaria gives the General Data Protection Regulation (GDPR) domestic effect through the Personal Data Protection Act (Закон за защита на личните данни, PDPA), originally promulgated 4 January 2002, predating the GDPR like Hungary's act though far less substantially rewritten, and substantially amended 26 February 2019 for GDPR alignment. The Act's primary text has not been located; every finding below rests on two commentary sources (CMS, DLA Piper).

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

Regulation (EU) 2016/679, Arts. 44-49, 83(5)(c)GDPR Arts. 44-49, 83(5)(c)

In force since 25 May 2018. Binds public and private bodies.

What this law does

A transfer of personal data outside the EEA requires an adequacy decision, appropriate safeguards, or a narrow Article 49 derogation, backed by the Article 83(5)(c) top fine tier. DLA Piper's commentary states no Bulgarian derogations exist and General Data Protection Regulation (GDPR) Articles 44-49 apply directly without modification; no primary text was read.

What it requires

Enforcement supervision

KZLD Enforcement and GDPR Article 82

Regulation (EU) 2016/679, Arts. 82-83GDPR Arts. 82-83

In force since 25 May 2018. Binds public and private bodies.

What this law does

Комисия за защита на личните данни (KZLD, English: Commission for Personal Data Protection) is Bulgaria's supervisory authority; an Inspectorate with the Supreme Judicial Council holds a parallel, narrower oversight role whose exact scope is not established. General Data Protection Regulation (GDPR) Article 82 arms an individual with a direct private right of action.

Commentary describes a Bulgarian procedural avenue, a complaint to KZLD within 6 months of discovering a violation or a direct administrative court claim, mutually exclusive where Commission proceedings on the same matter are already pending; this is an administrative-enforcement and judicial-review structure rather than a distinct civil damages remedy beyond Article 82, and is recorded here as procedural rather than folded into the private-right-of-action finding's basis.

What it requires

Sensitive categories

GDPR Article 9 and PDPA Employment and National-ID-Number Rules

Regulation (EU) 2016/679, Art. 9; PDPA (ЗЗЛД), employment and ЕГН provisionsCMS and DLA Piper commentary

Commencement not set. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1) treats biometric data processed for unique identification as a special category.

Two commentary sources agree Bulgaria has not adopted a distinct biometric restriction beyond GDPR; the Act's own additions described in commentary sit instead in employment data (identification-document copies only if required by law, criminal-background-check information only under explicit legal authorization rather than consent or legitimate interest, a 6-month recruitment-data retention cap) and in protecting the Bulgarian national identification number (ЕГН, Edinen grazhdanski nomer, Unified Civil Number, English: EGN): public access only if required by law, with technical measures required to prevent its use as a sole service identifier.

None of this is independently verified against the Act's own text. No commencement date is recorded for this instrument: no primary-source text was read and this rests entirely on commentary, so the status here is enacted rather than in force, rather than an asserted but unconfirmed effective date.

What it requires

Scraping law2 instruments, 2 in force

Research summary (219 words)

As an EU member state, Bulgaria's text-and-data-mining exception (Digital Single Market (DSM) Directive Article 4) is already covered at the EU level in this corpus; the operative national text is Bulgaria's own transposition, Articles 26e, 26zh and 26k of the Copyright and Neighbouring Rights Act (Zakon za avtorskoto pravo i srodnite mu prava, ZAPSP), added by the amendment promulgated 1 December 2023.

Article 26e permits reproduction and extraction of lawfully accessed works for automated text-and-data analysis without the rightsholder's consent, subject to an express, machine-readable rights reservation under Article 26e(4); Article 26zh gives universities, libraries and research institutes an unconditional exception for scientific research, and Article 26k(2) obliges a rightsholder to provide a qualifying research user access within 72 hours of a request.

Separately, Article 319a of the Criminal Code (Nakazatelen kodeks, NK) criminalizes unlawfully accessing an information system, with an escalating tier of imprisonment and fines depending on repetition, targeting of electronic-signature data, or protected or state-secret information; the provision does not on its own text require defeating a security measure, so whether it reaches ordinary public-page crawling is unsettled.

Bulgaria's treatment of terms-of-service enforceability against a scraper, sui generis database rights, personal-data reach over scraped public data, unfair competition or misappropriation, and the legal weight of a robots.txt directive is not established in Bulgarian law as of the date below.

Computer misuse

Criminal Code (Nakazatelen kodeks), Art. 319a, Unauthorized Access to an Information System

Наказателен кодекс (НК, Nakazatelen kodeks), chl. 319a, obn. DV br. 26 ot 1968 g., izm. DV br. 101 ot 2017 g.UNODC Sharing Electronic Resources and Laws on Crime (SHERLOC), Bulgaria Criminal Code, Chapter Nine A

In force. Binds public and private bodies.

What this law does

Unlawfully accessing an information system or a part of it, in a case that is not immaterial, carries imprisonment of up to two years. Where two or more people acted by prior agreement, the punishment rises to imprisonment of up to two years plus a fine of up to BGN 3,000. Where the act is repeated, or targets data for creating an electronic signature, the punishment rises to imprisonment of up to three years plus a fine of up to BGN 5,000.

Where the information is a state secret or otherwise legally protected, the punishment is imprisonment of one to three years. Where grave consequences result, the punishment is imprisonment of one to eight years. The provision's own text does not condition the offense on defeating a security measure, unlike Spain's equivalent Article 197 bis of the Codigo Penal.

What it requires

Copyright and text and data mining (TDM)

Copyright and Neighbouring Rights Act (ZAPSP), Arts. 26e, 26zh and 26k, Text-and-Data-Mining Exception for Crawling and Training

ZAPSP crawling-training TDM exception (Закон за авторското право и сродните му права, Zakon za avtorskoto pravo i srodnite mu prava) chl. 26e, 26zh i 26k, izm. i dop. DV br. 100 ot 1 dekemvri 2023 g.State Gazette (Darzhaven vestnik), Issue 100 of 1 December 2023, Act amending the Copyright and Neighbouring Rights Act

In force since 1 December 2023. Binds public and private bodies.

What this law does

A person with lawful access to a work or other protected subject matter may reproduce it, or extract or reuse a database, without the rightsholder's consent or payment, for the purposes of automated text-and-data analysis, per Article 26e(1) and (2).

A rightsholder may prohibit that use, and for content made available online the prohibition is effective only where established by technical means recognizable by the software performing the analysis, per Article 26e(4), which is the opt-out a crawler must honor.

A separate, unconditional exception in Article 26zh(1) and (3) covers universities, libraries and research and scientific institutes performing automated text-and-data analysis for scientific research, without the Article 26e(4) opt-out. Where a research user under Article 26zh has requested access, the rightsholder must provide it within 72 hours, per Article 26k(2).

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (460 words)

Bulgaria transposed the NIS2 Directive (Directive (EU) 2022/2555) through the Act Amending and Supplementing the Cybersecurity Act (Zakon za izmenenie i dopalnenie na Zakona za kibersigurnost), adopted by the 51st National Assembly on 5 February 2026 and promulgated in the State Gazette, issue 17, on 13 February 2026, well past the Directive's 17 October 2024 transposition deadline.

The amended Cybersecurity Act (Zakon za kibersigurnost, ZKS, originally promulgated as State Gazette No. 94 of 2018) now binds every essential and important entity the competent authorities designate by sector under the Act's annexes, which the amendment expands to name, among the newly reached digital service providers, a provider of an online marketplace, an online search engine, or a social networking services platform.

Article 22 sets the risk-management measures each essential or important entity must take, transposing NIS2 Article 21, with Article 21 putting approval and oversight of those measures on the entity's own management body and requiring every management-body member to complete cybersecurity training every two years.

Article 23 sets a 24-hour early-warning, 72-hour incident-notification, and one-month final-report clock for reporting a significant incident to СЕРИКС, the sectoral Computer Security Incident Response Team, transposing NIS2 Article 23.

Chapter Three's Article 29 arms both duties with a fine or property sanction of up to EUR 10,000,000 or 2 percent of worldwide turnover for an essential entity, whichever is higher but not less than EUR 25,000, and up to EUR 7,000,000 or 1.4 percent for an important entity, not less than EUR 12,500, plus a personal fine of EUR 500 to 5,000 on a management-body member for an Article 21 governance failure; a violation committed before 1 June 2026 carried a fine reduced by half from these figures under the amending Act's own transitional provision.

No Bulgarian instrument found here sets a product-security or market-placement duty on a manufacturer independent of the directly applicable EU Cyber Resilience Act, which is documented at the European Union level and not restated here.

No general reasonable-security or information-security-programme statute with no sector gate was found; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation and the Personal Data Protection Act's breach-notification duties to the Commission for Personal Data Protection, both of which sit in the privacy topic rather than here.

Both the risk-management and incident-reporting duties bind a wider class of essential and important entity by sector and size that no activity in this vocabulary expresses; only the digital-provider slice of that class (an online marketplace, online search engine, or social networking services platform) is flagged here, and the broader sector classes the amended annex names (energy, transport, banking, health, drinking water, digital infrastructure, public administration, manufacturing, and others) are recorded here as law the lint does not yet reach rather than flagged on a guess.

Sector security regimes

Cybersecurity Act, Risk-Management Measures and Governance (Zakon za kibersigurnost, ZKS)

Закон за киберсигурност (ЗКС) чл. 21 и 22, изм. с §§ 25 и 26 от Закона за изменение и допълнение на ЗКС, обн. ДВ, бр. 17 от 13.02.2026 г. (English: Cybersecurity Act, Arts. 21 and 22, as substituted by §§ 25 and 26 of the Act Amending and Supplementing the Cybersecurity Act, State Gazette No. 17 of 13 February 2026)Act Amending and Supplementing the Cybersecurity Act

In force 7 months, effective 17 February 2026. Binds public and private bodies.

What this law does

Article 22 of the Cybersecurity Act, as substituted by Paragraph 26 of the amending Act, requires every essential and important entity to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the security of the network and information systems it uses in its core activity or in providing its services, at a level of security matched to the entity's exposure, size, and the likelihood and severity of an incident.

The measures must follow an all-hazards approach covering, at minimum, risk-analysis and information-system-security policies, incident-handling procedures, business continuity (including backup and disaster-recovery management and crisis management), supply-chain security, security in the acquisition, development and maintenance of network and information systems including vulnerability handling and disclosure, policies to evaluate the effectiveness of the risk-management measures themselves, basic cyber-hygiene practices and cybersecurity training, cryptography and encryption policies, and human-resources security and access control.

Article 21, as substituted by Paragraph 25 of the same amending Act, puts approval and oversight of these Article 22 measures on the entity's own management body (or, for an administrative body, its governing organ), and separately requires every management-body member of an essential or important entity to complete cybersecurity training every two years sufficient to identify risks and assess risk-management practices, and to organise the same training for the entity's staff.

Both articles transpose NIS2 Articles 20 and 21 respectively, and apply, among the sector classes the Act's annexes name, to a provider of an online marketplace, an online search engine, or a social networking services platform, which the amended annex lists among the reached digital service providers.

What it requires

Vulnerability and incident reporting

Cybersecurity Act, Incident and Cyber-Threat Reporting Obligations (Zakon za kibersigurnost, ZKS)

Закон за киберсигурност (ЗКС) чл. 23, изм. с § 27 от Закона за изменение и допълнение на ЗКС, обн. ДВ, бр. 17 от 13.02.2026 г. (English: Cybersecurity Act, Art. 23, as substituted by § 27 of the Act Amending and Supplementing the Cybersecurity Act, State Gazette No. 17 of 13 February 2026)Act Amending and Supplementing the Cybersecurity Act

In force 7 months, effective 17 February 2026. Binds public and private bodies.

What this law does

Article 23 of the Cybersecurity Act, as substituted by Paragraph 27 of the amending Act, requires every essential and important entity to notify СЕРИКС of every significant incident. СЕРИКС is the sectoral Computer Security Incident Response Team the Act defines at Art. 18(1). The notification runs on a graduated clock.

An early warning is due within 24 hours of becoming aware of the incident, stating where applicable whether the incident is suspected to result from unlawful or malicious acts and whether it could have a cross-border effect. An incident notification is due within 72 hours, updating that assessment with an initial severity and impact evaluation, or within 24 hours instead of 72 where the notifying entity is a trust service provider. An interim report is due on СЕРИКС's request.

A final report is due no later than one month after the incident notification, covering the incident's scope and impact, the likely threat type or cause, the mitigation measures applied and ongoing, and any cross-border effect. Where the entity has not resolved the incident by the one-month mark, it files an interim report instead and a final report within one month of resolving it.

Where appropriate and without undue delay, the entity must also notify the recipients of its service of a significant incident likely to adversely affect them and of any measures or safeguards they can take, and of a significant cyber threat and its nature; notification to recipients may be delayed, with the competent authority's consent, where it would jeopardise the incident's investigation. СЕРИКС must acknowledge the early warning within 24 hours, except where objectively impossible, and, on request, provide operational guidance or further technical support.

This article transposes NIS2 Article 23, and applies, among the sector classes the Act's annexes name, to a provider of an online marketplace, an online search engine, or a social networking services platform.

What it requires

Age gating law1 instrument, 1 in force

Research summary (187 words)

The EU's Audiovisual Media Services Directive (AVMSD), transposed at the EU level in this corpus, sets the baseline for protecting minors from harmful audiovisual content and for age verification on video-sharing platforms.

Bulgaria's own Radio and Television Act (Zakon za radioto i televiziyata, ZRT) carries the national transposition: Article 17a bars a media service provider from creating or distributing programs that could harm a child's physical, psychological, moral or social development, and requires the Council for Electronic Media (Savet za elektronni medii, SEM) to adopt a Code of Conduct with providers, including BNT and BNR, prescribing measures such as scheduling, age-verification tools, and encoding.

Article 19d, added for video-sharing platforms, requires a platform provider to take appropriate measures including age-verification systems for content that could harm a child's development, alongside flagging mechanisms, parental-control systems, and media-literacy tools. A violation of Article 17a(1) by a media service provider carries an administrative property sanction of BGN 15,000 to 30,000, doubled on repetition.

No adult-content age-verification statute distinct from this children's-protection regime, no social-media-specific minor-access restriction, and no app-store age-verification duty exist in Bulgarian law as of the date below.

Adult content age verification (AV)

Radio and Television Act (ZRT), Arts. 17a and 19d, Protection of Minors and Video-Sharing Platform Age Verification

Закон за радиото и телевизията (ЗРТ, Zakon za radioto i televiziyata), chl. 17a i 19d, izm. DV br. 109 ot 2020 g.Council for Electronic Media (Savet za elektronni medii), consolidated text of the Radio and Television Act

In force since 22 December 2020. Binds private bodies.

What this law does

A media service provider must not create or distribute programs that could harm a child's physical, psychological, moral or social development, per Article 17a(1). The Council for Electronic Media adopts a Code of Conduct with providers, including the public broadcasters BNT and BNR, prescribing measures such as scheduling, age-verification tools and encoding to assess, label and restrict access to harmful programs, per Article 17a(3) and (4).

Since the 2020 transposition of the amended AVMSD, a video-sharing platform provider must take appropriate measures, including age-verification systems, to protect children from user-generated videos and audio-visual commercial communications that could harm their development, alongside signalling, parental-control, and media-literacy measures, per Article 19d. A media service provider that violates Article 17a(1) is subject to a property sanction of BGN 15,000 to 30,000, doubled on a repeat violation.

Note and primary source

News aggregation law2 instruments, 2 in force

Research summary (197 words)

As an EU member state, Bulgaria's press-publisher neighbouring right (Digital Single Market (DSM) Directive Article 15) and text-and-data-mining exception (Article 4) are already covered at the EU level in this corpus; the operative national text is Bulgaria's own transposition act, promulgated 1 December 2023, which added Articles 90d and 90zh to the Copyright and Neighbouring Rights Act (Zakon za avtorskoto pravo i srodnite mu prava, ZAPSP) for the press-publisher right and Articles 26e, 26zh and 26k for the text-and-data-mining exception, the same articles recorded for crawling and model training under the scraping topic.

Under Article 90d(1), a press publication publisher holds the exclusive right to license an information-society service provider's online reproduction of, or the offer of electronic access to, its press publications, for two years from the January following first publication under Article 90zh. The right does not reach personal or non-commercial use, reproduction of the underlying facts, the use of single words or very short extracts, or hyperlinking, per Article 90d(2).

No compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act, and no hot-news or misappropriation doctrine distinct from ordinary unfair-competition law, exist in Bulgarian law as of the date below.

Press publishers' right

Copyright and Neighbouring Rights Act (ZAPSP), Arts. 90d and 90zh, Press Publisher Right

Закон за авторското право и сродните му права (ЗАПСП, Zakon za avtorskoto pravo i srodnite mu prava) chl. 90d i 90zh, izm. i dop. DV br. 100 ot 1 dekemvri 2023 g.State Gazette (Darzhaven vestnik), Issue 100 of 1 December 2023, Act amending the Copyright and Neighbouring Rights Act

In force since 1 December 2023. Binds private bodies.

What this law does

A press publication publisher holds the exclusive right to license, for payment, an information-society service provider's online reproduction of its press publications or parts of them, and the offer of electronic access to them, per Article 90d(1). The right does not apply to an individual's personal or non-commercial use, reproduction of the facts reported, the use of single words or very short extracts, or the creation of hyperlinks, per Article 90d(2). The right lasts two years from first publication, running from the following 1 January, per Article 90zh.

Note and primary source

Text and data mining (TDM) opt-out

Copyright and Neighbouring Rights Act (ZAPSP), Arts. 26e, 26zh and 26k, Text-and-Data-Mining Exception for News Aggregation

ZAPSP news-aggregation TDM exception (Закон за авторското право и сродните му права, Zakon za avtorskoto pravo i srodnite mu prava) chl. 26e, 26zh i 26k, izm. i dop. DV br. 100 ot 1 dekemvri 2023 g.State Gazette (Darzhaven vestnik), Issue 100 of 1 December 2023, Act amending the Copyright and Neighbouring Rights Act

In force since 1 December 2023. Binds public and private bodies.

What this law does

A person with lawful access to a work, including a press publication, may reproduce it or extract data from it for automated text-and-data analysis without the rightsholder's consent, per Article 26e(1).

A rightsholder, including a press publisher, may reserve that use by a machine-readable technical means, such as a robots.txt-style signal, which is binding once so established, per Article 26e(4); a news aggregator indexing press content must honor that reservation to remain within the exception.

A separate, unconditional exception in Article 26zh covers universities, libraries and research institutes mining for scientific research, and Article 26k(2) obliges a rightsholder to give such a research user access within 72 hours of a request.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.