[codicts-css-switcher id=”346″]

Global Law Experts Logo
debt collection gdpr bulgaria

Our Expert in Bulgaria

  • GOLD

GDPR and Debt Collection in Bulgaria (2026): What Creditors Can, and Cannot, Do

By Global Law Experts
– posted 59 minutes ago

Debt collection gdpr bulgaria compliance is now a frontline concern for every creditor, in-house legal team, finance department and recovery agency operating in or into the Bulgarian market. Personal data sits at the heart of every recovery file, names, addresses, phone numbers, account histories, payment behaviour, and in 2026 the regulatory scrutiny over how that data is used has intensified. The Bulgarian Commission for Personal Data Protection (CPDP) and the wider European Data Protection Board (EDPB) place emphasis on documented legitimate interest assessments, lawful cross-border transfers, and constraints on automated scoring of debtors.

This guide converts the General Data Protection Regulation (Regulation (EU) 2016/679) and Bulgarian regulatory practice into concrete, actionable steps, what you can do, what you cannot, and how to document it.

Who this is for: in-house counsel, creditors, CFOs, collection agencies and compliance teams operating in or into Bulgaria.

What you will get: a clear do/don’t checklist, template clauses, a retention schedule, and a decision framework for contacting, sharing and profiling debtors under GDPR.

Note on practical guidance: The examples, templates and workflows below reflect Bulgarian enforcement practice and regulator guidance current as of 2026. They are general guidance, not legal advice; high-risk matters should be reviewed by a qualified lawyer.

TL;DR, Can / Cannot:

  • You CAN process a debtor’s identity, contact and account data on a documented legitimate interest basis to recover a genuine debt.
  • You CANNOT rely on absent “consent”, harass debtors with repeated contact, or share more data than strictly necessary with agencies or bureaux.
  • You CAN use scoring models, but only with human oversight and, where risk is high, a completed Data Protection Impact Assessment (DPIA).
  • You CANNOT transfer debtor data to a non-adequate third country without an appropriate safeguard such as Standard Contractual Clauses (SCCs) and a transfer impact assessment.

Snapshot: GDPR and Bulgarian law, the legal framework

Debt collection gdpr bulgaria obligations flow from a layered legal framework. The GDPR applies directly across Bulgaria as EU law, and it is supplemented by national legislation, principally the Bulgarian Personal Data Protection Act (Закон за защита на личните данни), published in the State Gazette (Държавен вестник), and by the interpretive guidance of the CPDP, Bulgaria’s supervisory authority. Creditors must read these instruments together: the GDPR sets the baseline, the national Act and the CPDP shape how it is applied to Bulgarian collection scenarios, and the EDPB fills in the detail on cross-cutting issues such as legitimate interest, profiling and international transfers.

Key legal instruments

  • GDPR (Regulation (EU) 2016/679). The primary source for lawful bases, transparency, data subject rights, profiling and cross-border transfers.
  • Bulgarian Personal Data Protection Act. The national implementing statute, as amended; published in the State Gazette and administered by the CPDP, which issues rulings and sector guidance.
  • EDPB guidelines. Authoritative European guidance on how to construct a legitimate interest assessment, when a DPIA is required, and how transfers must be safeguarded.

For creditors, five obligations recur throughout the collection lifecycle: establish and document a lawful basis; provide clear transparency to the debtor; respect storage limitation; maintain confidentiality and security; and apply strict controls on profiling and automated decisions. Every workflow below maps back to one or more of these duties.

Lawful bases and permissible processing for creditors

The single most important question in any gdpr debt collection bulgaria file is: on what lawful basis are you processing this data? Get this wrong and every downstream act, contacting, sharing, scoring, retaining, becomes unlawful. In practice, creditors rely on two bases: legitimate interest and contract performance. Consent is rarely appropriate and almost never reliable for core recovery activity.

Legitimate interest, how to run the balancing test

Legitimate interest under Article 6(1)(f) GDPR is the workhorse basis for debt recovery. Recovering a sum lawfully owed is a recognised legitimate interest (and is expressly acknowledged as such in GDPR Recital 47). But the basis only holds where the interest is not overridden by the debtor’s rights and freedoms, and you must be able to prove you carried out that assessment. A documented Legitimate Interest Assessment (LIA) is therefore essential.

Sample LIA checklist, adapt for your facts:

  1. Purpose test. Identify the specific interest, e.g. “recovery of an unpaid invoice of BGN 4,200 under a supply contract.” Vague purposes fail.
  2. Necessity test. Confirm the processing is necessary and proportionate. Could you achieve recovery with less data? If yes, reduce the dataset.
  3. Balancing test. Weigh your interest against the debtor’s reasonable expectations and the intrusiveness of the processing. Consider whether the debtor would reasonably expect this contact.
  4. Safeguards. Record the safeguards applied, frequency caps, do-not-contact flags, data minimisation, secure channels.
  5. Record and date. Store the completed LIA with the file and review it if circumstances change.

Exemplar outcomes. For a corporate debtor owing under a signed B2B contract, the balancing test will often favour the creditor: the debt is commercial, the contact details were supplied in the course of business, and the processing is foreseeable. For a consumer debtor, the test is more finely balanced, intrusive contact, contact to a workplace, or disclosure to third parties can tip the balance against the creditor, so tighter safeguards are required.

Contract performance and contractual pre-requisites

Where the debt arises directly from a contract with the data subject, common in B2B recovery, Article 6(1)(b) (processing necessary for performance of a contract) can provide a cleaner basis for processing the debtor’s own contact and account data. For corporate debts, prefer the contract basis where the debtor is party to the agreement; fall back to legitimate interest for data about individuals who are not themselves the contracting party (such as a company director you contact).

Consent, why it is rarely the practical basis in collections

Consent under the GDPR must be freely given, specific, informed and withdrawable. A debtor can withdraw consent at any time, which would paralyse recovery. Worse, consent is almost never “freely given” in a debtor relationship. For these reasons, consent is the wrong basis for core collection tasks. Do not assume you have consent simply because a debtor once ticked a box, and never treat the absence of objection as consent. This is one of the most common compliance failures in debt collection gdpr bulgaria practice.

Comparison table, what creditors CAN do vs CANNOT do under debt collection GDPR Bulgaria rules

This side-by-side comparison is the operational heart of the guide. Use it as a quick reference before you take any step on a recovery file. Each row maps a dimension of processing to what is permitted (with conditions), what is prohibited, and the concrete compliance action that keeps you on the right side of the line.

Dimension What creditors CAN do (with conditions) What creditors CANNOT do Compliance actions
Lawful basis Rely on legitimate interest (documented LIA); use contract performance for B2B debts Assume consent when absent; use consent for core collection tasks without a valid opt-in Conduct and record an LIA; prefer the contract basis for corporate debts
Data categories Process identity, contact, debt/account details, payment history and contract terms Process unrelated special categories (health, race) or pull extraneous sensitive data Limit fields; redact sensitive information; log access
Contact methods Phone, post, email, SMS, if the LI test passes and contact is not intrusive Repeated harassment; covert third-party disclosures; contacting the workplace without a check Set frequency caps; maintain a central do-not-contact flag
Sharing with agencies Share with agents under contract with safeguards and purpose limits Share data publicly or sell it; disclose more than necessary to bureaux Use processor / controller-to-controller agreements and audit rights
Automated scoring Use scoring with human oversight; run a DPIA where risk is high Make fully automated decisions with legal or similarly significant effect without review Run a DPIA; enable human review; document the logic
Cross-border transfers Transfer under adequacy or SCCs with a transfer impact assessment Transfer without safeguards to non-adequate third countries Use SCCs; conduct a transfer impact assessment (TIA)
Retention Keep data necessary for statutory limitation periods and litigation holds Retain indefinitely without a lawful reason Publish a retention schedule; anonymise when possible
Security Apply appropriate technical and organisational measures Use weak or unencrypted channels for sensitive transmissions Encrypt; apply access controls; maintain logging

How to use the table, practical next steps

Treat each row as a gate. Before contacting a debtor, confirm the “contact methods” row. Before engaging an agency, confirm the “sharing” and “security” rows. Before deploying a prioritisation model, confirm the “automated scoring” row. If any compliance action in the final column is not yet in place, pause and remediate before proceeding. Keep the completed LIA, the signed processor agreements, the DPIA and the retention schedule together as your accountability file, these are precisely the documents the CPDP will ask for if it opens an investigation.

Contacting debtors, phone, SMS, email, post and third-party contact

Contacting debtors gdpr questions dominate the day-to-day of recovery work. The GDPR does not prohibit contacting a debtor, but it governs how often, through which channels, with what content, and who else may be told. Bulgarian practice treats persistent, intrusive or deceptive contact as a serious compliance red flag.

Frequency, time-of-day, do-not-contact lists and harassment red flags

Set internal frequency caps so that contact remains proportionate, repeated daily calls over a short period will read as harassment and can defeat your legitimate interest balance. Maintain a central do-not-contact flag so that a debtor who asks not to be called by phone is respected across your systems. Avoid contact at unreasonable hours. Never disclose the existence of a debt to the debtor’s employer, neighbours or family, covert third-party disclosure of a debt is a classic red flag and breaches confidentiality obligations. If you need to contact a workplace number, check first whether a personal channel exists and whether the debtor has objected.

SMS and email, content rules and the consent vs LI analysis

Every SMS or email must be transparent: identify who you are, state the purpose, and point to where the debtor can find your privacy information. The lawful basis for the message itself is typically legitimate interest, not consent, but remember that electronic marketing rules (reflected in Bulgaria’s Electronic Commerce Act and related ePrivacy requirements) are distinct from debt recovery. A genuine debt-recovery communication to an existing debtor is not marketing; dressing up marketing as “collection” is not permitted.

Sample privacy-notice line for SMS/email, adapt for your facts: “This message concerns an outstanding balance on account [ref]. We process your data to recover sums owed; see our privacy notice at [link]. To discuss or exercise your data rights, contact [details].”

When to involve lawyers or bailiffs, and data minimisation

When a file escalates to legal enforcement or a private enforcement agent (частен съдебен изпълнител), share only the data necessary for that step. Court filings and enforcement documents should contain the minimum personal data required, and sensitive information should be redacted where it is not essential to the claim. The move from amicable recovery to enforcement does not suspend your data-minimisation duty, it heightens it.

Sharing debtor data, collection agencies, credit bureaus and third parties

Sharing debtor data with agencies is where many creditors stumble. The question is not only whether you may share, but on what terms and in what role. Getting the contractual architecture right is a prerequisite, not an afterthought.

Contracts and processor vs controller roles

If an agency collects strictly on your instructions, it is typically a processor and you need an Article 28 data processing agreement. If the agency determines its own means and purposes, for example, by buying the debt, it becomes a separate controller, and you need a controller-to-controller arrangement with clear purpose limitation. In both cases include: purpose limits, security obligations, sub-processor controls, breach-notification duties, audit rights, and deletion/return of data at the end of the engagement.

Sharing with credit reference agencies

Credit reference checks gdpr issues require care. Reporting a debtor to a credit bureau, or querying a bureau, is processing that must have its own lawful basis, usually legitimate interest, and the debtor must be informed in your transparency notice that their data may be shared with or obtained from credit reference agencies. Disclose only what is necessary and accurate; reporting a disputed or incorrect debt creates both data-protection and reputational risk. Note that access to the Bulgarian National Bank’s Central Credit Register is restricted to defined reporting institutions and is not generally available to ordinary creditors or collection agencies.

Cross-border sharing, adequacy, SCCs and transfer impact assessments

Where debtor data leaves the European Economic Area, for instance, to a group collection hub or an agency in a non-EEA country, you must secure the transfer. If the destination benefits from an adequacy decision, the transfer may proceed on that basis. Otherwise, use an appropriate safeguard such as Standard Contractual Clauses and, following the reasoning in the Court of Justice’s Schrems II judgment, carry out a transfer impact assessment to check whether local laws in the destination undermine the SCC protections. Document both the mechanism and the assessment; unsecured transfers to non-adequate countries are prohibited.

Automated decision-making, scoring and profiling in debt collection GDPR Bulgaria files

Automated decision making debt collection practices, scorecards that prioritise files, segment debtors or trigger escalation, are increasingly common and increasingly scrutinised. The GDPR does not ban profiling, but it draws a hard line at solely automated decisions that produce legal effects or similarly significant effects on the individual without human involvement.

What triggers the requirement for human oversight

If a model’s output, acting alone, materially affects the debtor, for example, automatically triggering legal action or a negative credit listing, you cross into Article 22 territory and must build in meaningful human review. A genuine human-in-the-loop means a person with authority to override the model actually assesses the case, not merely rubber-stamps it. High-risk processing of this kind will usually require a DPIA before deployment.

Disclosure obligations and opt-out myths

You must tell debtors, in your privacy information, that you use profiling or automated scoring, explain the logic in meaningful terms, and describe the significance and consequences. A persistent myth is that a blanket “opt-out” line cures everything, it does not. Transparency and human oversight are obligations in their own right.

Scoring-model checklist, adapt for your facts:

  • Document the model’s purpose, inputs and logic.
  • Assess whether outputs have legal or similarly significant effect, if so, build in human review.
  • Run a DPIA where the processing is high risk.
  • Test for bias and keep accuracy under review.
  • Record the governance: who owns the model, who reviews overrides, how often it is audited.

Retention, archiving and deletion, a practical schedule for creditors

Retention of debtor data Bulgaria obligations are governed by the storage-limitation principle: keep data only as long as necessary for the purpose, with that period justified by statutory limitation periods and active litigation holds. Indefinite retention “just in case” is unlawful. Note that general limitation periods under the Bulgarian Obligations and Contracts Act are typically five years, with a shorter three-year period for certain claims; confirm the applicable period for the specific claim before fixing a retention ceiling.

Recommended retention logic

  • Pre-litigation / amicable phase. Retain while active recovery is realistically pursued.
  • Litigation phase. Apply a litigation hold, retain for the duration of proceedings and any appeal window.
  • Post-judgment / enforcement. Retain for the enforcement and limitation period applicable to the judgment debt.
  • Statutory limitation. Align the overall retention ceiling with the applicable Bulgarian limitation periods, then delete or anonymise.

Deletion vs anonymisation

Once the lawful retention period ends, either delete the data or irreversibly anonymise it. Anonymisation lets you keep statistical or portfolio-level insight without holding identifiable debtor records. Whichever route you take, record the action: maintain a deletion log capturing what was deleted, when and by whom, so you can demonstrate accountability to the CPDP.

Responding to data subject rights and regulator interactions

Debtors are data subjects with full GDPR rights, and how you handle their requests is itself a compliance signal. Debt collection gdpr bulgaria operations must have a tested process for both subject access requests and regulator contact.

Handling DSARs in a collections context

When a debtor makes a subject access request, verify their identity proportionately, then provide the personal data you hold within the GDPR’s response timeframe (generally one month, extendable by up to two further months for complex requests). You may withhold data covered by a valid exemption, for example, legally privileged material or information that would reveal third parties, but apply exemptions narrowly and document your reasoning. A DSAR is not a reason to pause recovery, but it must be answered on time.

What to do if the CPDP opens an investigation

Have an internal incident rota ready. The moment the CPDP makes contact, assemble the accountability file: the LIA, processor and transfer agreements, the DPIA, the retention schedule, contact logs, and breach records. Nominate a responsible contact, respond within the stated deadlines, and avoid altering records after the fact. Preparedness is the difference between a manageable inquiry and an escalated enforcement action.

Practical compliance checklist and templates

Use these snippets as starting points, each is a sample; adapt for your facts and have them reviewed before reliance.

Minimum contract clauses for client-to-agency transfers

  • Purpose limitation. “The processor shall process personal data only for debt recovery on the controller’s documented instructions.”
  • Security. “The processor shall implement appropriate technical and organisational measures, including encryption of data in transit and at rest.”
  • Sub-processing. “No sub-processor shall be engaged without prior written authorisation and equivalent contractual terms.”
  • Audit. “The controller may audit the processor’s compliance on reasonable notice.”
  • Return/deletion. “On termination, the processor shall return or irreversibly delete all personal data and certify deletion.”

Contact privacy-notice snippets

  • Phone script line. “This call concerns an outstanding balance. We process your data to recover sums owed; our privacy notice is available at [link], and you can exercise your data rights at [contact].”
  • Email/SMS line. See the sample privacy-notice line above under contacting debtors.

LIA and DPIA quick templates

Keep a one-page LIA template structured around the purpose, necessity and balancing tests with a safeguards box and a dated sign-off. Keep a DPIA template that records the processing description, the necessity and proportionality assessment, the risks to data subjects, and the mitigations, triggered whenever scoring, large-scale profiling or high-risk transfers are involved.

Decision framework, choose A when… choose B when…

When you weigh in-house recovery against outsourcing or litigation, score the file across five factors: risk, data sensitivity, cross-border exposure, volume and whether this is a repeat debtor. Then apply a clear recommendation rather than hedging.

Choose A, in-house collection on legitimate interest, when:

  • Contact details are recent and accurate.
  • The debt is commercial or low-sensitivity.
  • Volumes are low and manageable internally.
  • There are no cross-border transfers.
  • Your internal compliance (LIA plus contact logging) is robust.

Choose B, outsource to a contracted agency or commence legal enforcement, when:

  • Volumes are high or local enforcement expertise is needed, and the agency can process under a clear contract with technical safeguards and audit rights; or
  • The claim is undisputed and rapid preservation of assets is necessary, or contacting the debtor risks evidence destruction, in which case proceed to enforcement using only the necessary data and with court-filing confidentiality protections in place.

In short: keep it in-house when the file is clean, low-volume and domestic; outsource or litigate when scale, enforcement expertise or urgency outweigh the control you lose, but never let either route erode your data-minimisation and security duties.

Conclusion

Debt collection gdpr bulgaria compliance is not a brake on recovery, it is the framework that lets you recover debts lawfully, defensibly and at scale through 2026 and beyond. The creditors who succeed are those who document their legitimate interest assessments, contact debtors proportionately, contract carefully with agencies and bureaux, secure every cross-border transfer, keep human oversight over scoring models, and retain data only as long as the law allows. Build the accountability file, LIA, processor agreements, DPIA, retention schedule and contact logs, and keep it current. Do that, and a CPDP inquiry becomes a manageable formality rather than an existential risk.

When a file is high-value, cross-border or dependent on profiling, have it reviewed by a specialist before you act.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Vladislav Bozhikov at Bozhikov & Vatev Law Firm, a member of the Global Law Experts network.

Sources

  1. EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679)
  2. European Data Protection Board, Guidelines and resources
  3. Commission for Personal Data Protection (Bulgaria)
  4. European Commission, Data protection overview
  5. State Gazette (Държавен вестник), Republic of Bulgaria
  6. Council of Europe / European Court of Human Rights, case law database

FAQs

What personal data can a creditor lawfully process when collecting a debt?
You may process the data genuinely necessary to recover the debt: identity, contact details, account and debt information, payment history and relevant contract terms. You must not pull in unrelated special-category data such as health or ethnicity. Limit the fields, document your lawful basis (usually legitimate interest, supported by an LIA), and log who accesses the record.
Yes, debt collection gdpr bulgaria rules permit phone, SMS, email and postal contact where your legitimate interest test passes and the contact is not intrusive. Every message must identify you, state the purpose and point to your privacy notice. Set frequency caps, respect do-not-contact requests through a central flag, and never disclose the debt to third parties such as the debtor’s employer.
You can share once the agency is bound by a proper contract. If it acts on your instructions it is a processor under an Article 28 agreement; if it determines its own purposes it is a separate controller. Either way, limit data to what is necessary, impose security and audit obligations, and never sell or publicly disclose debtor data.
Keep records only as long as necessary, justified by the applicable statutory limitation periods (commonly five years, or three years for certain claims, under the Obligations and Contracts Act) and any active litigation hold. Once that period ends, delete or irreversibly anonymise the data and record the action in a deletion log. Indefinite retention without a lawful reason is prohibited.
Yes, with safeguards. You can use scoring to prioritise files, but a decision that has a legal or similarly significant effect on the debtor must not be made by the model alone, you need meaningful human review. Disclose the profiling in your privacy information and run a DPIA where the processing is high risk.
Transfers outside the EEA need a valid mechanism. Rely on an adequacy decision where one exists; otherwise use an appropriate safeguard such as Standard Contractual Clauses and complete a transfer impact assessment to confirm the destination’s laws do not undermine those protections. Document both the mechanism and the assessment before any data leaves the EEA.
The GDPR applies to living individuals, so a deceased debtor’s own data falls outside its direct scope, but national rules and the privacy of living third parties (such as heirs or guarantors) still apply. Continue to minimise data, protect any living individuals’ information in the file, and follow Bulgarian succession and confidentiality requirements when pursuing the estate.
remote work visa uae
By Global Law Experts

posted 2 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

GDPR and Debt Collection in Bulgaria (2026): What Creditors Can, and Cannot, Do

Send welcome message

Custom Message