[codicts-css-switcher id=”346″]

Global Law Experts Logo
cpc dawn raids bulgaria

CPC Dawn Raids in Bulgaria 2026: What to Do During Unannounced Inspections

By Global Law Experts
– posted 1 hour ago

CPC dawn raids Bulgaria have become a defining enforcement risk for companies operating in the country, and recent developments in Bulgarian competition law have raised the stakes considerably. The Commission for Protection of Competition (the CPC) can arrive unannounced at your premises, request access to servers and devices, and copy or seize evidence within minutes of walking through the door. How your organisation responds in those first fifteen minutes can determine whether it faces cooperation credit or crippling obstruction fines. This guide sets out, step by step, what inspectors can and cannot do, what your rights and obligations are, how to handle electronic evidence and privilege, and exactly what to do before, during and after an inspection.

It is written for in-house counsel and business leaders who need practical, jurisdiction-specific answers, not generic theory.

Quick summary, action checklist for in-house counsel: stop access to privileged materials, request inspector ID and the authorisation, record the inspection, designate a single liaison, preserve copies, and contact counsel immediately. This guide explains the CPC’s powers, company rights, the handling of digital devices, penalties and the correct next steps after a raid.

Quick action checklist for CPC dawn raids in Bulgaria

When inspectors arrive, the difference between a controlled response and a costly mistake is preparation. Use this bulleted checklist as your immediate reference. It is designed to be actioned in order, with each step assigned to a named individual before an inspection ever occurs.

  • Ask for and photograph identification. Request every inspector’s official ID and the authorisation permitting the inspection. Note names and the stated scope.
  • Notify your inspection response team. Alert in-house legal, external competition counsel, IT and senior management simultaneously. Every minute counts.
  • Appoint a single liaison. One trained person should accompany the lead inspector at all times; a second shadows the team searching IT systems.
  • Do not delete, alter or hide anything. Instruct staff in writing to stop deleting emails, files or messages. Destruction of evidence is the single gravest error in unannounced inspections in Bulgaria.
  • Suspend automatic deletion. Have IT immediately freeze auto-delete rules, document retention purges and inbox clean-up routines.
  • Escort inspectors and shadow every action. Assign staff to accompany inspectors room by room, recording what is examined, copied or removed.
  • Keep a contemporaneous log. Record times, rooms entered, questions asked, documents copied and devices imaged. This log protects your later rights.
  • Assert privilege at the point of contact. Where a document may be privileged, say so clearly, do not hand it over unread, and request that it be sealed pending review.

Keep a one-page Dawn Raid Checklist (Bulgaria) printed at reception and stored on every manager’s device so that the response begins before counsel arrives.

What is a CPC dawn raid? Legal basis and when it happens

A dawn raid is a surprise, on-site inspection carried out by the Commission for Protection of Competition to gather evidence of anti-competitive conduct, typically cartels, bid-rigging, information exchange or abuse of a dominant position. The inspection is “unannounced” precisely because advance notice would allow suspects to destroy or conceal evidence. The CPC derives its investigative powers from the Bulgarian Protection of Competition Act, and, where trade between EU Member States is affected, from the EU enforcement framework in Regulation (EC) No 1/2003, which coordinates inspections between national competition authorities and the European Commission.

The competition authority inspection in Bulgaria can occur at any business premises, and in certain circumstances at other locations where relevant records may be held. On-site inspections at premises other than business premises generally require prior judicial authorisation. Recent developments and amendments to Bulgarian competition law, promulgated through the State Gazette, have reinforced the CPC’s enforcement powers and sharpened the consequences of non-cooperation, which is why an up-to-date response protocol matters more than ever.

Triggers for inspections

Understanding what prompts a raid helps companies assess their exposure. Common triggers include:

  • Third-party complaints. A competitor, customer or supplier alleges anti-competitive behaviour, prompting the CPC to open a file.
  • Leniency applications. A cartel participant self-reports in exchange for immunity or reduced fines, handing the CPC a roadmap to co-conspirators.
  • Sector inquiries and market monitoring. The CPC identifies patterns, parallel pricing, suspicious tender outcomes, warranting closer examination.
  • Ex officio investigations. The authority acts on its own initiative based on market intelligence or referrals from other regulators.

Because leniency is a frequent trigger, a company that suspects it may itself be implicated should consider its own position quickly. Understanding how leniency and settlement in Bulgaria interact with a raid can materially change strategy in the hours after inspectors leave.

Notice and unannounced search, what “unannounced” means in Bulgaria

“Unannounced” is literal. Inspectors do not telephone ahead, and there is no grace period to “prepare files.” They arrive during business hours, present their authorisation, and expect immediate access. This is the essence of CPC dawn raids Bulgaria: the element of surprise is a legal feature, not an accident. Your only meaningful preparation is a standing response plan tested through simulations, because the substantive protection of the company happens through the disciplined exercise of its rights during the search itself, not before it begins.

Company rights and obligations during an inspection

Companies subject to unannounced inspections in Bulgaria have genuine rights, but they also carry firm obligations. The winning approach is neither obstruction nor passive surrender, it is active, documented, lawful cooperation that preserves every defensive position for later. Below are the immediate steps, in the order they should happen.

Verify identity and scope, what to ask for

Before granting access to anything beyond a reception area, your liaison should:

  • Ask each inspector to present official identification and record their names.
  • Request the written authorisation that empowers the inspection, and read the stated subject matter and scope carefully.
  • Note the legal basis cited, whether under the Bulgarian Protection of Competition Act, Regulation (EC) No 1/2003, or both.
  • Confirm the products, markets and time period the investigation covers.

The scope defines the boundaries of what inspectors may lawfully examine. If they stray beyond it, for example, requesting documents about an unrelated business line, the liaison should politely flag the concern, record the objection, and continue cooperating under protest rather than refusing outright. Refusal risks an obstruction finding; a recorded objection preserves the point for later challenge.

Appointing a single point of contact for inspectors

Chaos benefits no one. Designate one trained liaison who accompanies the lead inspector throughout, plus a shadow for the IT search team. This single point of contact controls the flow of information, ensures consistency, prevents well-meaning employees from volunteering unnecessary material or speculation, and maintains the contemporaneous log. Every other employee should be told to answer only what is strictly required and to route all questions through the liaison or counsel.

When to ask for a written record of seized items and inspection minutes

You are entitled to a record of what occurs. Insist on an inventory of every document copied and every device imaged or removed, and request that a protocol (minutes) of the inspection be prepared and signed. If the inspectors’ account of events differs from your own log, note your disagreement in the protocol before signing, or sign with reservations. This document seizure record from the CPC in Bulgaria becomes the foundation for any subsequent privilege dispute, appeal or complaint.

Handling on-site staff interviews

Inspectors may ask employees questions about facts and about where information is stored. Staff must not obstruct or mislead, but they are not obliged to provide self-incriminating admissions of guilt or legal conclusions. Train employees to answer factual questions truthfully and briefly, to say “I don’t know” when they genuinely do not, and to avoid guessing. Where a question strays into legal assessment or interpretation, the liaison should request that counsel be present. Never allow employees to volunteer opinions about whether conduct was lawful.

What can the CPC seize? Documents, electronic devices and limits

The CPC’s search-and-seizure powers extend well beyond paper. Inspectors may examine business records in any form, take copies, and in appropriate cases seize originals or remove and image electronic devices. Understanding the distinction between copying and seizure, and the proportionality limits that apply, is essential to protecting the business.

In practice, inspectors typically make forensic copies of hard drives, email accounts and shared drives rather than removing physical hardware, but they can do the latter where necessary. Every item taken should appear on an inventory. Proportionality is a real constraint: the CPC may collect what is relevant to the defined scope, and material plainly outside that scope should be flagged and, where possible, excluded or sealed.

Electronic devices and servers, practical steps

When inspectors turn to IT systems, your shadow liaison and IT lead should:

  • Record exactly which accounts, drives, mailboxes and devices are accessed or imaged.
  • Request that keyword searches be logged, and note the search terms used.
  • Ensure forensic images are taken transparently, ideally with a company IT witness present throughout.
  • Ask for a copy of, or access to, the seized data set so the company can review what was taken.
  • Immediately suspend any automated deletion, backup rotation or account decommissioning that could alter data mid-inspection.

Cooperation on the mechanics of access is an obligation. Refusing passwords, disabling systems, or “losing” devices during a raid is precisely the conduct that triggers obstruction fines in Bulgaria’s competition regime.

Cloud data and third-party providers

Much corporate data now lives in the cloud or on third-party servers, and inspectors may seek access to data the company controls even where it is physically hosted elsewhere. This raises practical and cross-border considerations, including the interplay with data protection obligations. The company should facilitate access to data within its control while documenting the location and provider of any data held abroad, and should involve counsel early where cross-border transfer or third-party contractual restrictions are implicated. Do not use hosting arrangements as a pretext to delay lawful access, but do record the technical realities accurately.

Preserving privileged or confidential materials

Some documents will be legally privileged, and others will be commercially sensitive without being privileged. The two must be handled differently. For genuinely privileged material, assert the claim at the moment the document surfaces, decline to allow it to be read, and request that it be sealed in an envelope for separate determination. For merely confidential material within scope, cooperation is required, but you may ask that confidentiality be respected in the CPC’s later handling of the file.

The table below summarises, at a glance, what the CPC can typically access during CPC dawn raids Bulgaria.

Item Can the CPC access it? Practical note
Paper business records within scope Yes May copy or, where justified, seize originals; demand an inventory.
Emails and shared drives Yes Usually forensically imaged; log accounts and search terms.
Company-issued mobile devices Yes May be imaged or examined; record which devices and when.
Cloud data under company control Yes Facilitate access; document location and provider; flag cross-border issues.
Privileged lawyer–client communications Limited / protected Assert privilege, do not disclose contents, request sealing.
Purely private personal data unrelated to scope Contested Flag as out of scope; record objection; involve counsel.

Legal privilege, confidentiality and in-house counsel in Bulgaria

Legal privilege in Bulgaria’s competition context is narrower than many multinational executives expect, and misunderstanding it is a common and costly error. The practical treatment of privilege in inspections is heavily informed by EU practice, under which the protection attaches most clearly to communications with independent external lawyers made for the purpose of the client’s rights of defence.

Privilege test, Bulgarian practice and EU guidance

Under EU enforcement practice, which the CPC’s approach broadly reflects, the strongest privilege protection covers written communications between a client and an independent, qualified external lawyer, connected to the subject matter of the investigation and made for the client’s defence. Communications with in-house counsel are far more vulnerable. Multinationals accustomed to broad in-house privilege in other jurisdictions should assume that internal legal memoranda may not be protected in the same way during a Bulgarian or EU-framed inspection. Where a privilege claim is disputed, the correct course is to insist the material is sealed and its status determined separately, rather than allowing inspectors to read it on the spot.

How to instruct staff, what to disclose and what not to disclose

Give clear, calm instructions to employees. They should:

  • Cooperate with lawful access requests and never destroy, hide or alter anything.
  • Answer factual questions about where information is stored truthfully.
  • Route any document that might be privileged to the liaison before it is handed over.
  • Refrain from offering opinions on the legality of the company’s conduct.
  • Avoid speculation and admissions; stick to facts within their direct knowledge.

Mark genuinely privileged documents clearly in advance as part of good compliance hygiene, so that they can be identified quickly under pressure. Guidance from the Bulgarian Bar Association on lawyers’ duties and confidentiality can inform how privileged relationships are structured and documented before any inspection arises.

During a raid: a minute-by-minute procedural playbook for CPC dawn raids Bulgaria

Preparation turns panic into process. The following chronological playbook assigns responsibilities across the first two hours and the following forty-eight, so that everyone knows their role the moment inspectors arrive. Adapt it to your organisation and rehearse it through dawn-raid simulations.

First 15 minutes, verification and containment

  • Reception: greet inspectors politely, ask them to wait in a controlled area, and immediately alert the inspection response team and reception’s designated backup.
  • Liaison: verify identity, obtain and read the authorisation, and record scope, names and legal basis.
  • IT: suspend all automated deletion, backup purges and account decommissioning across the network.
  • Management: send a short written instruction to all staff: do not delete anything, do not obstruct, route questions through the liaison.
  • Everyone: begin the contemporaneous log with a precise timestamp of arrival.

First hour, document and device control

  • External counsel: confirmed en route; if inspectors are willing to wait a short, reasonable period for counsel to arrive, request it, but do not use it to delay lawful cooperation.
  • Liaison and shadow: accompany every inspector; one shadows the physical search, one shadows the IT search.
  • Inventory: insist that each copied document and imaged device is listed; keep a parallel company inventory.
  • Privilege: as documents surface, screen for privilege; seal disputed items rather than surrendering them.
  • Communications discipline: restrict internal chatter about the investigation to legally advised channels; assume nothing is confidential.

Next 24–48 hours, internal investigation and cooperation strategy

  • Debrief: reconstruct the inspection from the log, secure signed minutes, and obtain the CPC’s inventory of seized materials.
  • Data review: begin reviewing the copied data set (where available) to understand the authority’s likely focus.
  • Privilege follow-up: formalise any privilege claims over sealed material and prepare to defend them.
  • Strategic assessment: with counsel, assess exposure, the merits of a leniency or settlement approach, and any grounds to challenge procedural overreach.
  • People: agree consistent internal and external messaging; brief affected employees appropriately.

This playbook answers the practical question at the heart of every raid, what is a dawn raid by the Bulgarian CPC and how do we survive it, by converting an intimidating event into a sequence of controlled, defensible actions.

Obstruction, enforcement sanctions and penalties

Obstruction is where cooperative companies most often stumble into serious trouble. The CPC can impose administrative fines for failing to submit to an inspection, for supplying incorrect, incomplete or misleading information, and for refusing lawful access. In serious cases involving deliberate destruction or concealment of evidence, individuals may face additional exposure. Recent amendments, published through the State Gazette, have reinforced the sanctions regime, making the cost of non-cooperation higher than ever. Obstruction fines in Bulgaria’s competition framework are designed to deter precisely the instinctive reactions, deleting a message, “misplacing” a laptop, warning a colleague, that feel protective in the moment but are catastrophic in consequence.

The precise amounts and thresholds of fines are set out in the Protection of Competition Act and applied by the CPC; confirm the current figures with counsel rather than relying on any specific number.

Common obstruction mistakes to avoid

  • Deleting emails, files or chat messages after inspectors have arrived, or once you learn a raid is imminent.
  • Refusing to provide passwords or disabling systems to slow the search.
  • Tipping off other individuals or companies under investigation.
  • Providing false, incomplete or misleading answers to factual questions.
  • Breaking seals placed by inspectors on rooms, cabinets or devices.

Managerial liability and worst-case scenarios

Liability is not confined to the corporate entity. Managers and individual employees who direct or carry out obstruction can attract personal sanctions. The worst-case scenario combines the underlying competition infringement, aggravated by an obstruction finding, with reputational damage and personal exposure for those involved. The mitigation strategy is consistent throughout this guide: cooperate lawfully, document everything, assert rights properly rather than by obstruction, and consider self-reporting through leniency where the underlying conduct warrants it.

After the raid, preserving rights and next steps

The inspection ending is not the end of the matter; it is the start of the defence phase. The quality of the record you built during the raid now determines the strength of your position.

Getting copies, inventories and exercising appeal rights

Obtain the signed inspection protocol and the full inventory of seized and copied materials, and reconcile them against your own contemporaneous log. Where you disagree, ensure your objections are recorded. The procedures for obtaining copies, challenging the handling of privileged material, and appealing CPC acts are governed by Bulgarian administrative procedure and CPC rules, with CPC decisions on the merits generally appealable to the Administrative Court – Sofia City and onward to the Supreme Administrative Court. Preserve every deadline and consult counsel promptly, because rights to challenge are time-limited. Maintain a clear chain of custody over any material you retain.

When to trigger internal remediation and compliance review

Use the raid as the catalyst for an internal review. Assess what the authority is likely investigating, identify any conduct that requires remediation, and consider whether a leniency or settlement approach improves your position. This is also the moment to strengthen future readiness, refreshing your dawn-raid protocol, retraining staff, and closing the compliance gaps the inspection exposed. Where cross-border or cloud data was involved, review your data-handling arrangements so that the next inspection finds a better-prepared organisation.

Comparison table, CPC dawn raid vs. European Commission inspection

Multinational groups often need to calibrate expectations between a national CPC raid and a European Commission inspection. While both are grounded in the shared EU enforcement architecture of Regulation (EC) No 1/2003, there are practical differences in reach and framing. The table below offers a high-level comparison.

Feature CPC (Bulgaria) European Commission (EU)
Legal basis Bulgarian Protection of Competition Act; Regulation (EC) No 1/2003 where cross-border trade is affected Regulation (EC) No 1/2003
Scope of powers Enter premises, examine and copy records, image/seize electronic data within the authorised scope Enter premises, examine and copy records, take digital evidence, seal premises
Privilege treatment Follows EU practice; strongest for external lawyer communications, limited for in-house counsel Protection strongest for independent external lawyer communications; in-house counsel largely excluded
Cross-border reach National focus, coordinated with the Commission and other national authorities under Regulation 1/2003 EU-wide reach across Member States
Penalties for obstruction Administrative fines under the Protection of Competition Act Substantial fines for obstruction and broken seals under EU rules

Practical templates and tools

A prepared organisation moves faster and makes fewer mistakes. Every company operating in a competition-sensitive sector should maintain, and periodically test, a suite of ready-to-use tools. Treat each as a labelled sample or template to be adapted with legal review before deployment:

  • Dawn Raid Checklist (Bulgaria). A one-page printed reference kept at reception and on managers’ devices.
  • Liaison script. A sample script covering identity verification, scope confirmation and the language for asserting privilege and recording objections.
  • Inventory template. A parallel company log for documents copied and devices imaged.
  • Employee interview template. Guidance for staff on answering factual questions truthfully while avoiding speculation and legal conclusions.
  • Incident report template. A structured contemporaneous log with timestamps, rooms, search terms and inspector names.

These tools are most effective when rehearsed through a dawn-raid simulation, so that the response is muscle memory rather than improvisation.

Conclusion

CPC dawn raids Bulgaria test an organisation’s preparedness in real time, and as enforcement powers have been reinforced the margin for error is thinner than ever. The companies that emerge well are those that verify, document, cooperate lawfully and assert their rights with discipline, never those that panic, delete or obstruct. Build and rehearse your response plan now, train your liaison and staff, keep the checklist within reach, and know exactly whom to call the moment inspectors appear.

If you need to assess your readiness for CPC dawn raids Bulgaria or respond to an inspection already under way, seek qualified Bulgarian competition counsel without delay, and prepare your one-page Dawn Raid Checklist (Bulgaria) so your team is ready before the doorbell rings.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Ivelina Cherneva at Dinova Rusev & Partners, a member of the Global Law Experts network.

Sources

  1. Commission for Protection of Competition (CPC), official site
  2. Regulation (EC) No 1/2003
  3. European Commission, inspections guidance
  4. State Gazette (DV), promulgation of Bulgarian legislation
  5. Republic of Bulgaria, National Assembly / legislation portal
  6. Supreme Administrative Court of Bulgaria
  7. OECD, Competition

FAQs

What is a dawn raid by the Bulgarian CPC?
It is a surprise, on-site inspection by the Commission for Protection of Competition to collect evidence of anti-competitive conduct, authorised under the Bulgarian Protection of Competition Act and, where cross-border trade is affected, the EU enforcement rules in Regulation (EC) No 1/2003.
Verify identity and read the authorisation to confirm scope, appoint a single company liaison, instruct staff not to destroy or alter any materials, suspend automated deletion, contact counsel, and start a contemporaneous log and inventory of everything examined or seized.
Yes. During CPC dawn raids Bulgaria the authority may examine, copy or image electronic devices and request access to servers and cloud data under the company’s control. Preserve all data, log the accounts and search terms used, obtain inventories, and assert privilege where it applies.
Protection is limited. Following EU practice, communications with independent external lawyers made for the defence are most likely protected, while in-house counsel materials are far more vulnerable. Assert privilege clearly, decline to disclose contents, request sealing, and seek separate determination if disputed.
Obstruction can lead to administrative fines for non-cooperation, false or incomplete information and refusing access. The precise amounts are set by the Protection of Competition Act and applied by the CPC, so lawful cooperation is always the safer course; confirm current levels with counsel.
No. Refusing lawful entry to inspectors acting under a valid authorisation is itself obstruction and risks significant fines. You may verify identity and scope and record objections to any overreach, but you should permit lawful access while preserving your rights through documentation.
If your company may be implicated in a cartel, a leniency or settlement approach to the CPC can reduce or eliminate fines, but timing is critical. Consult competition counsel immediately after the raid to assess eligibility and prepare an application.
register company turkey as foreign investor
By Global Law Experts

posted 43 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

CPC Dawn Raids in Bulgaria 2026: What to Do During Unannounced Inspections

Send welcome message

Custom Message