Skip to content
Ceci est une traduction de commodite. La version anglaise est la version officielle et juridiquement contraignante. Voir la version anglaise
EUMEDIUM coverage1 enforcement action

Bulgaria — GDPR + EU AI Act + National Digital Transformation Programme: AI Compliance Requirements

Bulgaria's Commission for Personal Data Protection (CPDP / Комисия за защита на личните данни) supervises data protection. Bulgaria's National Programme for Accelerated Digital Transformation 2022-2024 and subsequent Digital Decade participation plan include AI governance. Bulgaria is investing in AI for e-government, healthcare, and the automotive supply chain sector.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

May 25, 2018

Enforcement Begins

August 2, 2026

Maximum Penalty

€20,000,000 or 4% of global turnover for GDPR violations (Bulgaria adopted the euro 2026-01-01; historical fines pre-2026 were BGN-denominated); EU AI Act: €35M or 7%

What Your Business Must Do

2 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

GDPR AI Compliance — CPDP Supervision

Critical

CPDP supervises GDPR compliance for AI systems processing Bulgarian residents' data. Required: lawful basis documentation for AI training datasets, DPIA for high-risk AI (profiling, automated decisions, biometric systems), DPO appointment for public authorities and large-scale processors, and data subject rights implementation for AI-generated decisions.

GDPR Art. 22 (automated decisions); Art. 35 (DPIA)

EU AI Act Compliance — Priority Sectors

High Priority

Bulgaria's digital transformation plan focuses on AI in healthcare (telemedicine, diagnostic AI) and automotive manufacturing (AI-driven quality control). EU AI Act Annex III classifies medical diagnostic AI and safety-critical industrial AI as high-risk. Conformity assessment and CE marking readiness required before deployment. NOTE: the "Digital Omnibus" amendment (Regulation (EU) 2026/1744, in force 2026-07-27) deferred stand-alone high-risk (Annex III) conformity obligations from 2026-08-02 to 2027-12-02.

Deadline: December 2, 2027

EU AI Act Art. 6, Annex III (high-risk classification); Art. 16 (provider obligations); Art. 43 (conformity assessment); Art. 26 (deployer obligations)

Who Does This Apply To?

Applies to: any organisation established in Bulgaria, and any organisation outside Bulgaria processing the personal data of Bulgarian residents through AI systems — GDPR applies with extraterritorial reach (Art. 3), obligations attaching to the processing activity rather than company size, with no general small-business exemption. As an EU member state, Bulgaria is fully subject to the EU AI Act: medical diagnostic AI (telemedicine, diagnostic support) and safety-critical industrial/automotive AI are classified high-risk under Annex III, requiring conformity assessment and CE-marking readiness before deployment. The Commission for Personal Data Protection (CPDP / Комисия за защита на личните данни) requires a documented lawful basis for AI training datasets, a DPIA for high-risk AI (profiling, automated decisions, biometric systems), DPO appointment for public authorities and large-scale processors, and Article 22 human review for AI decisions in employment, credit and healthcare — CPDP, as an EDPB member, applies EDPB Opinion 28/2024 (adopted 2024-12, on personal data in AI model development/deployment) as its operative AI/GDPR framework. Penalties reach €20M / 4% of global turnover under GDPR (EUR since Bulgaria's 2026-01-01 euro adoption) and €35M / 7% under the EU AI Act.

Recent Enforcement Actions

2019Source verified· as of 2026-08-22

Against:

Recent Regulatory Guidance

guidance2024-12

EDPB Opinion 28/2024 on AI Models and Personal Data (applied by CPDP as an EDPB member)

The European Data Protection Board adopted Opinion 28/2024 (2024-12, published in full early 2025) on data-protection aspects of personal data processing in AI model development, training, and deployment — the most comprehensive EU-wide statement on how GDPR applies to AI systems. As a CPDP is an EDPB member, this is Bulgaria's operative framework for AI/GDPR compliance absent Bulgaria-specific guidance. Separately, Bulgaria published a 2025 Draft National Strategy for AI and opened the INSAIT (Institute for Computer Science, AI and Technology) research institute; a private member's draft national AI Act (proposed by the "Da, Bulgaria" party, late 2025) remains a pending bill, not enacted law, as of this cycle.

Frequently Asked Questions

Does Bulgaria — GDPR + EU AI Act + National Digital Transformation Programme apply to my business?

Bulgaria's Commission for Personal Data Protection (CPDP / Комисия за защита на личните данни) supervises data protection. Bulgaria's National Programme for Accelerated Digital Transformation 2022-2024 and subsequent Digital Decade participation… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Bulgaria — GDPR + EU AI Act + National Digital Transformation Programme is: €20,000,000 or 4% of global turnover for GDPR violations (Bulgaria adopted the euro 2026-01-01; historical fines pre-2026 were BGN-denominated); EU AI Act: €35M or 7%. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Bulgaria — GDPR + EU AI Act + National Digital Transformation Programme?

The 2 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.cpdp.bg/en

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan