Data Protection · Bulgaria

GDPR and Data Protection Lawyer in Bulgaria

GDPR compliance is not a template — it is a set of documents that must match how your business actually processes data. We build practical compliance programmes for Bulgarian companies and foreign groups operating here, and we represent clients in inspections and proceedings before the Commission for Personal Data Protection.

How we can help

Compliance audit and documentation

Data mapping, records of processing activities, lawful bases, retention schedules, internal policies, privacy notices and staff instructions adapted to your actual operations.

Contracts and international transfers

Data processing agreements with suppliers, joint controller arrangements, standard contractual clauses and transfer impact assessments for data sent outside the EEA.

DPIA and high-risk processing

Data protection impact assessments for video surveillance, profiling, biometrics, HR monitoring and marketing databases, with concrete measures to bring risk down.

Data subject requests and breaches

Procedures for handling access, erasure and objection requests within the statutory deadlines, and a 72-hour breach response plan including notification of the CPDP and affected individuals.

Inspections, complaints and appeals

Representation during CPDP inspections, responses to complaints, defence in sanction proceedings and appeals against penal decrees before the administrative court.

Fees

Initial legal consultation – €50, deductible from subsequent legal fees. After the consultation you receive a written scope of work and a fixed-fee proposal.

Book a Consultation

Describe your case briefly and we will come back to you with available times.