Bulgaria — GDPR + EU AI Act + National Digital Transformation Programme: AI Compliance Requirements
Bulgaria's Commission for Personal Data Protection (CPDP / Комисия за защита на личните данни) supervises data protection. Bulgaria's National Programme for Accelerated Digital Transformation 2022-2024 and subsequent Digital Decade participation plan include AI governance. Bulgaria is investing in AI for e-government, healthcare, and the automotive supply chain sector.
Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.
Key Facts
May 25, 2018
August 2, 2026
€20,000,000 or 4% of global turnover for GDPR violations (Bulgaria adopted the euro 2026-01-01; historical fines pre-2026 were BGN-denominated); EU AI Act: €35M or 7%
What Your Business Must Do
2 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.
GDPR AI Compliance — CPDP Supervision
CriticalCPDP supervises GDPR compliance for AI systems processing Bulgarian residents' data. Required: lawful basis documentation for AI training datasets, DPIA for high-risk AI (profiling, automated decisions, biometric systems), DPO appointment for public authorities and large-scale processors, and data subject rights implementation for AI-generated decisions.
EU AI Act Compliance — Priority Sectors
High PriorityBulgaria's digital transformation plan focuses on AI in healthcare (telemedicine, diagnostic AI) and automotive manufacturing (AI-driven quality control). EU AI Act Annex III classifies medical diagnostic AI and safety-critical industrial AI as high-risk. Conformity assessment and CE marking readiness required before deployment. NOTE: the "Digital Omnibus" amendment (Regulation (EU) 2026/1744, in force 2026-07-27) deferred stand-alone high-risk (Annex III) conformity obligations from 2026-08-02 to 2027-12-02.
Deadline: December 2, 2027
EU AI Act Art. 6, Annex III (high-risk classification); Art. 16 (provider obligations); Art. 43 (conformity assessment); Art. 26 (deployer obligations)Who Does This Apply To?
Applies to: any organisation established in Bulgaria, and any organisation outside Bulgaria processing the personal data of Bulgarian residents through AI systems — GDPR applies with extraterritorial reach (Art. 3), obligations attaching to the processing activity rather than company size, with no general small-business exemption. As an EU member state, Bulgaria is fully subject to the EU AI Act: medical diagnostic AI (telemedicine, diagnostic support) and safety-critical industrial/automotive AI are classified high-risk under Annex III, requiring conformity assessment and CE-marking readiness before deployment. The Commission for Personal Data Protection (CPDP / Комисия за защита на личните данни) requires a documented lawful basis for AI training datasets, a DPIA for high-risk AI (profiling, automated decisions, biometric systems), DPO appointment for public authorities and large-scale processors, and Article 22 human review for AI decisions in employment, credit and healthcare — CPDP, as an EDPB member, applies EDPB Opinion 28/2024 (adopted 2024-12, on personal data in AI model development/deployment) as its operative AI/GDPR framework. Penalties reach €20M / 4% of global turnover under GDPR (EUR since Bulgaria's 2026-01-01 euro adoption) and €35M / 7% under the EU AI Act.
Recent Enforcement Actions
Against:
Recent Regulatory Guidance
EDPB Opinion 28/2024 on AI Models and Personal Data (applied by CPDP as an EDPB member)
The European Data Protection Board adopted Opinion 28/2024 (2024-12, published in full early 2025) on data-protection aspects of personal data processing in AI model development, training, and deployment — the most comprehensive EU-wide statement on how GDPR applies to AI systems. As a CPDP is an EDPB member, this is Bulgaria's operative framework for AI/GDPR compliance absent Bulgaria-specific guidance. Separately, Bulgaria published a 2025 Draft National Strategy for AI and opened the INSAIT (Institute for Computer Science, AI and Technology) research institute; a private member's draft national AI Act (proposed by the "Da, Bulgaria" party, late 2025) remains a pending bill, not enacted law, as of this cycle.
Frequently Asked Questions
Does Bulgaria — GDPR + EU AI Act + National Digital Transformation Programme apply to my business?
Bulgaria's Commission for Personal Data Protection (CPDP / Комисия за защита на личните данни) supervises data protection. Bulgaria's National Programme for Accelerated Digital Transformation 2022-2024 and subsequent Digital Decade participation… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.
What is the penalty for non-compliance?
The maximum penalty under Bulgaria — GDPR + EU AI Act + National Digital Transformation Programme is: €20,000,000 or 4% of global turnover for GDPR violations (Bulgaria adopted the euro 2026-01-01; historical fines pre-2026 were BGN-denominated); EU AI Act: €35M or 7%. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.
How do I comply with Bulgaria — GDPR + EU AI Act + National Digital Transformation Programme?
The 2 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.
Official Source
https://www.cpdp.bg/enLast updated: 2026-08-22 — verify at source before relying on this information.
Don't leave compliance to chance
Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.
Start your free compliance scan