Data Protection · Bulgaria
GDPR and Data Protection Lawyer in Bulgaria
GDPR compliance is not a template — it is a set of documents that must match how your business actually processes data. We build practical compliance programmes for Bulgarian companies and foreign groups operating here, and we represent clients in inspections and proceedings before the Commission for Personal Data Protection.
How we can help
Compliance audit and documentation
Data mapping, records of processing activities, lawful bases, retention schedules, internal policies, privacy notices and staff instructions adapted to your actual operations.
Contracts and international transfers
Data processing agreements with suppliers, joint controller arrangements, standard contractual clauses and transfer impact assessments for data sent outside the EEA.
DPIA and high-risk processing
Data protection impact assessments for video surveillance, profiling, biometrics, HR monitoring and marketing databases, with concrete measures to bring risk down.
Data subject requests and breaches
Procedures for handling access, erasure and objection requests within the statutory deadlines, and a 72-hour breach response plan including notification of the CPDP and affected individuals.
Inspections, complaints and appeals
Representation during CPDP inspections, responses to complaints, defence in sanction proceedings and appeals against penal decrees before the administrative court.
Fees
Initial legal consultation – €50, deductible from subsequent legal fees. After the consultation you receive a written scope of work and a fixed-fee proposal.
Book a Consultation
Describe your case briefly and we will come back to you with available times.