Bulgaria — Закон за защита на личните данни (ЗЗЛД)
Bulgaria's data-protection act — originally 2002, comprehensively rewritten by the 2019 GDPR-implementation amendment (ДВ, бр. 17 от 2019 г.). It regulates only what GDPR leaves to Member States (чл. 1, ал. 1).
Statute text is Bulgarian (the authentic language); this README is curation.
Applicability to EdTech
- Digital-consent age is 14 (чл. 25в) — Bulgaria took the GDPR Art. 8 derogation to the floor: information-society services offered directly to a child under 14 need consent from the parent exercising parental rights or the guardian. (Compare Italy 14, Czechia 15, Poland 16.)
- Breaching чл. 25в is priced at the GDPR Art. 83(4) scale (чл. 85, ал. 1); other national-rule breaches map to Art. 83(5) (ал. 2–5), and residual violations carry fines up to 5,000 лв., doubled on repetition (чл. 86).
- The КЗЛД's supervisory status and the special processing cases are anchored in чл. 1, ал. 4.
Contents
| Document | Covers |
|---|---|
| SUGLASIE-I-SANKTSII.md | чл. 1 (предмет), чл. 25в (съгласие на дете — 14 г.), чл. 85–86 (санкции) |
Enforcement
Комисия за защита на личните данни (КЗЛД, cpdp.bg); Инспекторат към ВСС for the judiciary.
Related
- EU GDPR — the directly applicable regime this act supplements
- BG ЗПУО — the school-education act (remote learning, school data)
Sources
Meta
Statute text in SUGLASIE-I-SANKTSII.md is reproduced verbatim in Bulgarian from the lex.bg consolidated text by tools/lex-bg/build_bg.py. Bulgaria has no official machine-readable consolidation (the Държавен вестник publishes originals only); lex.bg is the consolidation used in practice. verify re-fetches and fails as soon as a newer ДВ amendment appears in the act's history (currently through изм. ДВ. бр. 51/2026).