Our Expert in Bulgaria
No results available
Debt collection gdpr bulgaria compliance is now a frontline concern for every creditor, in-house legal team, finance department and recovery agency operating in or into the Bulgarian market. Personal data sits at the heart of every recovery file, names, addresses, phone numbers, account histories, payment behaviour, and in 2026 the regulatory scrutiny over how that data is used has intensified. The Bulgarian Commission for Personal Data Protection (CPDP) and the wider European Data Protection Board (EDPB) place emphasis on documented legitimate interest assessments, lawful cross-border transfers, and constraints on automated scoring of debtors.
This guide converts the General Data Protection Regulation (Regulation (EU) 2016/679) and Bulgarian regulatory practice into concrete, actionable steps, what you can do, what you cannot, and how to document it.
Who this is for: in-house counsel, creditors, CFOs, collection agencies and compliance teams operating in or into Bulgaria.
What you will get: a clear do/don’t checklist, template clauses, a retention schedule, and a decision framework for contacting, sharing and profiling debtors under GDPR.
Note on practical guidance: The examples, templates and workflows below reflect Bulgarian enforcement practice and regulator guidance current as of 2026. They are general guidance, not legal advice; high-risk matters should be reviewed by a qualified lawyer.
TL;DR, Can / Cannot:
Debt collection gdpr bulgaria obligations flow from a layered legal framework. The GDPR applies directly across Bulgaria as EU law, and it is supplemented by national legislation, principally the Bulgarian Personal Data Protection Act (Закон за защита на личните данни), published in the State Gazette (Държавен вестник), and by the interpretive guidance of the CPDP, Bulgaria’s supervisory authority. Creditors must read these instruments together: the GDPR sets the baseline, the national Act and the CPDP shape how it is applied to Bulgarian collection scenarios, and the EDPB fills in the detail on cross-cutting issues such as legitimate interest, profiling and international transfers.
For creditors, five obligations recur throughout the collection lifecycle: establish and document a lawful basis; provide clear transparency to the debtor; respect storage limitation; maintain confidentiality and security; and apply strict controls on profiling and automated decisions. Every workflow below maps back to one or more of these duties.
The single most important question in any gdpr debt collection bulgaria file is: on what lawful basis are you processing this data? Get this wrong and every downstream act, contacting, sharing, scoring, retaining, becomes unlawful. In practice, creditors rely on two bases: legitimate interest and contract performance. Consent is rarely appropriate and almost never reliable for core recovery activity.
Legitimate interest under Article 6(1)(f) GDPR is the workhorse basis for debt recovery. Recovering a sum lawfully owed is a recognised legitimate interest (and is expressly acknowledged as such in GDPR Recital 47). But the basis only holds where the interest is not overridden by the debtor’s rights and freedoms, and you must be able to prove you carried out that assessment. A documented Legitimate Interest Assessment (LIA) is therefore essential.
Sample LIA checklist, adapt for your facts:
Exemplar outcomes. For a corporate debtor owing under a signed B2B contract, the balancing test will often favour the creditor: the debt is commercial, the contact details were supplied in the course of business, and the processing is foreseeable. For a consumer debtor, the test is more finely balanced, intrusive contact, contact to a workplace, or disclosure to third parties can tip the balance against the creditor, so tighter safeguards are required.
Where the debt arises directly from a contract with the data subject, common in B2B recovery, Article 6(1)(b) (processing necessary for performance of a contract) can provide a cleaner basis for processing the debtor’s own contact and account data. For corporate debts, prefer the contract basis where the debtor is party to the agreement; fall back to legitimate interest for data about individuals who are not themselves the contracting party (such as a company director you contact).
Consent under the GDPR must be freely given, specific, informed and withdrawable. A debtor can withdraw consent at any time, which would paralyse recovery. Worse, consent is almost never “freely given” in a debtor relationship. For these reasons, consent is the wrong basis for core collection tasks. Do not assume you have consent simply because a debtor once ticked a box, and never treat the absence of objection as consent. This is one of the most common compliance failures in debt collection gdpr bulgaria practice.
This side-by-side comparison is the operational heart of the guide. Use it as a quick reference before you take any step on a recovery file. Each row maps a dimension of processing to what is permitted (with conditions), what is prohibited, and the concrete compliance action that keeps you on the right side of the line.
| Dimension | What creditors CAN do (with conditions) | What creditors CANNOT do | Compliance actions |
|---|---|---|---|
| Lawful basis | Rely on legitimate interest (documented LIA); use contract performance for B2B debts | Assume consent when absent; use consent for core collection tasks without a valid opt-in | Conduct and record an LIA; prefer the contract basis for corporate debts |
| Data categories | Process identity, contact, debt/account details, payment history and contract terms | Process unrelated special categories (health, race) or pull extraneous sensitive data | Limit fields; redact sensitive information; log access |
| Contact methods | Phone, post, email, SMS, if the LI test passes and contact is not intrusive | Repeated harassment; covert third-party disclosures; contacting the workplace without a check | Set frequency caps; maintain a central do-not-contact flag |
| Sharing with agencies | Share with agents under contract with safeguards and purpose limits | Share data publicly or sell it; disclose more than necessary to bureaux | Use processor / controller-to-controller agreements and audit rights |
| Automated scoring | Use scoring with human oversight; run a DPIA where risk is high | Make fully automated decisions with legal or similarly significant effect without review | Run a DPIA; enable human review; document the logic |
| Cross-border transfers | Transfer under adequacy or SCCs with a transfer impact assessment | Transfer without safeguards to non-adequate third countries | Use SCCs; conduct a transfer impact assessment (TIA) |
| Retention | Keep data necessary for statutory limitation periods and litigation holds | Retain indefinitely without a lawful reason | Publish a retention schedule; anonymise when possible |
| Security | Apply appropriate technical and organisational measures | Use weak or unencrypted channels for sensitive transmissions | Encrypt; apply access controls; maintain logging |
Treat each row as a gate. Before contacting a debtor, confirm the “contact methods” row. Before engaging an agency, confirm the “sharing” and “security” rows. Before deploying a prioritisation model, confirm the “automated scoring” row. If any compliance action in the final column is not yet in place, pause and remediate before proceeding. Keep the completed LIA, the signed processor agreements, the DPIA and the retention schedule together as your accountability file, these are precisely the documents the CPDP will ask for if it opens an investigation.
Contacting debtors gdpr questions dominate the day-to-day of recovery work. The GDPR does not prohibit contacting a debtor, but it governs how often, through which channels, with what content, and who else may be told. Bulgarian practice treats persistent, intrusive or deceptive contact as a serious compliance red flag.
Set internal frequency caps so that contact remains proportionate, repeated daily calls over a short period will read as harassment and can defeat your legitimate interest balance. Maintain a central do-not-contact flag so that a debtor who asks not to be called by phone is respected across your systems. Avoid contact at unreasonable hours. Never disclose the existence of a debt to the debtor’s employer, neighbours or family, covert third-party disclosure of a debt is a classic red flag and breaches confidentiality obligations. If you need to contact a workplace number, check first whether a personal channel exists and whether the debtor has objected.
Every SMS or email must be transparent: identify who you are, state the purpose, and point to where the debtor can find your privacy information. The lawful basis for the message itself is typically legitimate interest, not consent, but remember that electronic marketing rules (reflected in Bulgaria’s Electronic Commerce Act and related ePrivacy requirements) are distinct from debt recovery. A genuine debt-recovery communication to an existing debtor is not marketing; dressing up marketing as “collection” is not permitted.
Sample privacy-notice line for SMS/email, adapt for your facts: “This message concerns an outstanding balance on account [ref]. We process your data to recover sums owed; see our privacy notice at [link]. To discuss or exercise your data rights, contact [details].”
When a file escalates to legal enforcement or a private enforcement agent (частен съдебен изпълнител), share only the data necessary for that step. Court filings and enforcement documents should contain the minimum personal data required, and sensitive information should be redacted where it is not essential to the claim. The move from amicable recovery to enforcement does not suspend your data-minimisation duty, it heightens it.
Sharing debtor data with agencies is where many creditors stumble. The question is not only whether you may share, but on what terms and in what role. Getting the contractual architecture right is a prerequisite, not an afterthought.
If an agency collects strictly on your instructions, it is typically a processor and you need an Article 28 data processing agreement. If the agency determines its own means and purposes, for example, by buying the debt, it becomes a separate controller, and you need a controller-to-controller arrangement with clear purpose limitation. In both cases include: purpose limits, security obligations, sub-processor controls, breach-notification duties, audit rights, and deletion/return of data at the end of the engagement.
Credit reference checks gdpr issues require care. Reporting a debtor to a credit bureau, or querying a bureau, is processing that must have its own lawful basis, usually legitimate interest, and the debtor must be informed in your transparency notice that their data may be shared with or obtained from credit reference agencies. Disclose only what is necessary and accurate; reporting a disputed or incorrect debt creates both data-protection and reputational risk. Note that access to the Bulgarian National Bank’s Central Credit Register is restricted to defined reporting institutions and is not generally available to ordinary creditors or collection agencies.
Where debtor data leaves the European Economic Area, for instance, to a group collection hub or an agency in a non-EEA country, you must secure the transfer. If the destination benefits from an adequacy decision, the transfer may proceed on that basis. Otherwise, use an appropriate safeguard such as Standard Contractual Clauses and, following the reasoning in the Court of Justice’s Schrems II judgment, carry out a transfer impact assessment to check whether local laws in the destination undermine the SCC protections. Document both the mechanism and the assessment; unsecured transfers to non-adequate countries are prohibited.
Automated decision making debt collection practices, scorecards that prioritise files, segment debtors or trigger escalation, are increasingly common and increasingly scrutinised. The GDPR does not ban profiling, but it draws a hard line at solely automated decisions that produce legal effects or similarly significant effects on the individual without human involvement.
If a model’s output, acting alone, materially affects the debtor, for example, automatically triggering legal action or a negative credit listing, you cross into Article 22 territory and must build in meaningful human review. A genuine human-in-the-loop means a person with authority to override the model actually assesses the case, not merely rubber-stamps it. High-risk processing of this kind will usually require a DPIA before deployment.
You must tell debtors, in your privacy information, that you use profiling or automated scoring, explain the logic in meaningful terms, and describe the significance and consequences. A persistent myth is that a blanket “opt-out” line cures everything, it does not. Transparency and human oversight are obligations in their own right.
Scoring-model checklist, adapt for your facts:
Retention of debtor data Bulgaria obligations are governed by the storage-limitation principle: keep data only as long as necessary for the purpose, with that period justified by statutory limitation periods and active litigation holds. Indefinite retention “just in case” is unlawful. Note that general limitation periods under the Bulgarian Obligations and Contracts Act are typically five years, with a shorter three-year period for certain claims; confirm the applicable period for the specific claim before fixing a retention ceiling.
Once the lawful retention period ends, either delete the data or irreversibly anonymise it. Anonymisation lets you keep statistical or portfolio-level insight without holding identifiable debtor records. Whichever route you take, record the action: maintain a deletion log capturing what was deleted, when and by whom, so you can demonstrate accountability to the CPDP.
Debtors are data subjects with full GDPR rights, and how you handle their requests is itself a compliance signal. Debt collection gdpr bulgaria operations must have a tested process for both subject access requests and regulator contact.
When a debtor makes a subject access request, verify their identity proportionately, then provide the personal data you hold within the GDPR’s response timeframe (generally one month, extendable by up to two further months for complex requests). You may withhold data covered by a valid exemption, for example, legally privileged material or information that would reveal third parties, but apply exemptions narrowly and document your reasoning. A DSAR is not a reason to pause recovery, but it must be answered on time.
Have an internal incident rota ready. The moment the CPDP makes contact, assemble the accountability file: the LIA, processor and transfer agreements, the DPIA, the retention schedule, contact logs, and breach records. Nominate a responsible contact, respond within the stated deadlines, and avoid altering records after the fact. Preparedness is the difference between a manageable inquiry and an escalated enforcement action.
Use these snippets as starting points, each is a sample; adapt for your facts and have them reviewed before reliance.
Keep a one-page LIA template structured around the purpose, necessity and balancing tests with a safeguards box and a dated sign-off. Keep a DPIA template that records the processing description, the necessity and proportionality assessment, the risks to data subjects, and the mitigations, triggered whenever scoring, large-scale profiling or high-risk transfers are involved.
When you weigh in-house recovery against outsourcing or litigation, score the file across five factors: risk, data sensitivity, cross-border exposure, volume and whether this is a repeat debtor. Then apply a clear recommendation rather than hedging.
Choose A, in-house collection on legitimate interest, when:
Choose B, outsource to a contracted agency or commence legal enforcement, when:
In short: keep it in-house when the file is clean, low-volume and domestic; outsource or litigate when scale, enforcement expertise or urgency outweigh the control you lose, but never let either route erode your data-minimisation and security duties.
Debt collection gdpr bulgaria compliance is not a brake on recovery, it is the framework that lets you recover debts lawfully, defensibly and at scale through 2026 and beyond. The creditors who succeed are those who document their legitimate interest assessments, contact debtors proportionately, contract carefully with agencies and bureaux, secure every cross-border transfer, keep human oversight over scoring models, and retain data only as long as the law allows. Build the accountability file, LIA, processor agreements, DPIA, retention schedule and contact logs, and keep it current. Do that, and a CPDP inquiry becomes a manageable formality rather than an existential risk.
When a file is high-value, cross-border or dependent on profiling, have it reviewed by a specialist before you act.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Vladislav Bozhikov at Bozhikov & Vatev Law Firm, a member of the Global Law Experts network.
posted 19 minutes ago
posted 39 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message