Privacy Policy & GDPR Compliance Statement

BULGARIA FOR BUSINESS
www.bulgaria-for-business.com

Document Privacy Policy & GDPR Compliance Statement
Version / Date Version 1.0 — January 2025
Controller Bulgaria For Business
Applicable law GDPR (EU) 2016/679 · Bulgarian PDPA (ЗЗЛД)

1. Introduction and scope

Bulgaria For Business (“we”, “us”, “our”) is committed to protecting the privacy and personal data of our clients, website visitors, prospective clients, and all individuals whose data we process in connection with our business activities. This Privacy Policy and GDPR Compliance Statement explains:

  • what personal data we collect and why;
  • the legal basis on which we process personal data;
  • how long we retain data;
  • with whom we share data;
  • your rights under the GDPR and Bulgarian law; and
  • how to contact us or the supervisory authority if you have concerns.

This policy applies to all personal data processed by Bulgaria For Business in connection with:

  • the use of our website at www.bulgaria-for-business.com;
  • the provision of our professional services — company formation, legal services, accounting, licensing, real estate advisory, recruitment, HR administration, payroll, salary benchmarking, and business acquisition advisory;
  • our marketing and business development activities; and
  • our employment of staff and engagement of contractors (which is addressed in separate internal HR policies).

APPLICABLE LAW: This policy is issued in compliance with the EU General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679 — and the Bulgarian Personal Data Protection Act (Закон за защита на личните данни / ЗЗЛД). As Bulgaria is an EU member state, the GDPR applies directly and with full force. References to GDPR articles in this policy are references to the directly applicable EU regulation.

2. Data controller identity and contact

Bulgaria For Business is the data controller responsible for personal data processed in connection with our website and our professional services.

Organisation name Bulgaria For Business
Registered in Bulgaria (EU member state)
Website www.bulgaria-for-business.com
Data protection contact info@bulgaria-for-business.com
Supervisory authority Commission for Personal Data Protection (КЗЛД)
Supervisory authority website www.cpdp.bg

3. What personal data we collect and why

The table below sets out the categories of personal data we collect, the specific data elements within each category, the lawful basis for processing, and the applicable retention period.

Data category What we collect Lawful basis Retention period
Client and prospective client data Name, job title, company name, email address, telephone number, postal address, correspondence history, service requirements, and financial information relevant to service delivery. Contract performance; legitimate interests; legal obligation Duration of engagement + 7 years (tax/accounting records)
Website enquiry data Name, email address, company name, country of residence, and the content of your enquiry submitted through our website contact form. Pre-contractual steps; legitimate interests (responding to enquiries) 3 years from last contact if no engagement follows
Newsletter and marketing subscribers Email address, name, and communication preferences of individuals who have subscribed to our newsletter or marketing communications. Consent Until withdrawal of consent or unsubscribe
Employment and HR service clients’ employee data Where we provide payroll and HR administration services — employee names, personal identification numbers (ЕГН), addresses, salary data, social security data, leave records, and employment contract details. Contract performance (with client); legal obligation (NRA/NOI compliance) Duration of payroll service + 5 years (employment records)
Business acquisition and real estate clients Corporate ownership structure, financial information, identity documents, source of funds documentation, and property transaction data. Contract performance; legal obligation (AML due diligence) Duration of engagement + 7 years (AML records)
Cookies and website analytics data IP addresses, browser type, pages visited, time on site, referral source. Aggregated and anonymised where possible. Consent (analytics cookies); legitimate interests (security) As set out in our Cookie Policy
AML and compliance data Identity verification documents (passport, ID card), proof of address, beneficial ownership information, source of wealth / funds information — collected for anti-money laundering compliance. Legal obligation (Bulgarian AML Act / ЗМИП) 5 years from end of business relationship (AML requirement)

We collect only data that is necessary for the stated purpose — consistent with the GDPR data minimisation principle (Article 5(1)(c)). We do not sell personal data to third parties. We do not use personal data for automated decision-making that produces legal or similarly significant effects.

4. Sources of personal data

Data you provide directly

Most personal data we process is provided to us directly by you — through:

  • completion of enquiry or contact forms on our website;
  • correspondence with us by email, telephone, or post;
  • entering into a service agreement or engagement letter with us;
  • providing documents or information required for service delivery (e.g. identity documents for AML purposes, financial statements for accounting, employee data for payroll processing);
  • subscribing to our newsletter or marketing communications.

Data we collect automatically

When you visit our website, we automatically collect certain technical data through cookies and similar technologies — including IP address, browser type, pages visited, and referral source. This is detailed in our Cookie Policy.

Data received from third parties

In limited circumstances, we may receive personal data about you from third parties, including:

  • referrals from business partners or other professional firms who have referred you to us;
  • publicly available sources — such as the Bulgarian Commercial Register, Property Registry, or Companies House of other jurisdictions — in connection with legal and due diligence services;
  • in connection with business acquisition mandates — financial information provided by sellers about their employees.

5. Lawful basis for processing

We always identify and document a lawful basis before processing personal data. The table below explains each basis we rely on and when we use it.

Lawful basis When we rely on it and for what processing
Contract performance (Art. 6(1)(b) GDPR) Processing necessary to perform a contract with you, or to take steps at your request before entering into a contract. Applies to: service delivery, client account management, invoicing, and direct correspondence relating to our services.
Legitimate interests (Art. 6(1)(f) GDPR) Processing necessary for our legitimate business interests, provided these are not overridden by your rights. Applies to: fraud prevention, network and information security, business development, improving our services, and direct marketing to existing clients.
Legal obligation (Art. 6(1)(c) GDPR) Processing necessary to comply with a legal obligation to which we are subject. Applies to: tax and accounting records, anti-money laundering (AML) obligations, regulatory compliance, and court orders.
Consent (Art. 6(1)(a) GDPR) Processing based on your freely given, specific, informed, and unambiguous consent. Applies to: marketing communications to non-clients, newsletter subscriptions, and non-essential cookies. You may withdraw consent at any time.
Vital interests (Art. 6(1)(d) GDPR) Processing necessary to protect vital interests of a person. Applied only in exceptional emergency circumstances.
Special categories of data (Art. 9 GDPR) Where we process special categories of data (e.g. for employment clients — health data related to sick leave; for regulated sector clients — criminal record data for fit and proper assessments), we rely on explicit consent (Art. 9(2)(a)) or legal obligation (Art. 9(2)(b)) as applicable.

6. Purposes for which we process personal data

Service delivery

We process personal data to provide our professional services — company formation, legal advice, accounting and tax compliance, regulatory licensing, real estate advisory, recruitment and HR administration, payroll processing, salary benchmarking, and business acquisition support. This includes: communicating with clients, preparing documents, filing with public authorities on clients’ behalf, maintaining service records, and invoicing.

Anti-money laundering (AML) compliance

As a professional services firm providing certain regulated services, we are subject to Bulgarian and EU anti-money laundering obligations (Закон за мерките срещу изпирането на пари — ЗМИП). We are required to conduct customer due diligence — verifying the identity of clients and beneficial owners, assessing the purpose of the business relationship, and monitoring for suspicious transactions. This processing is carried out on the basis of legal obligation and cannot be waived.

Marketing and business development

We may process personal data of existing clients for direct marketing purposes on the basis of legitimate interests — sending updates about relevant regulatory changes, new services, or market developments that may be of interest to them. For non-clients, marketing communications are only sent with consent. You can opt out of marketing communications at any time using the unsubscribe link in any email or by contacting us.

Legal and regulatory compliance

We process personal data to comply with our legal and regulatory obligations — including tax and accounting record-keeping requirements, court orders, regulatory investigations, and reporting obligations under applicable Bulgarian and EU law.

Security and fraud prevention

We process limited personal data — primarily IP addresses and access logs — to protect our website and systems from unauthorised access, cyberattacks, and fraud, on the basis of legitimate interests.

7. Sharing personal data with third parties

Processors acting on our instructions

We engage certain third-party service providers (“processors”) who process personal data on our behalf and under our instructions. We enter into data processing agreements with all processors, ensuring they provide sufficient guarantees of GDPR compliance. The table below identifies the main categories of processors we use.

Recipient / processor Role and data shared Legal basis
Website hosting provider Hosts our website and stores associated website data. Located in the EU or subject to appropriate transfer safeguards. Legitimate interests / Contract performance
Email service provider Delivers transactional and marketing emails on our behalf. Data processed: email address, name, email open/click data. Contract performance / Consent (marketing)
Google Analytics (Google LLC) Provides website analytics. Data processed: anonymised/pseudonymised browsing data via cookies. Google participates in the EU-US Data Privacy Framework. Consent (analytics cookies)
CRM / practice management software Stores client contact data, correspondence, and matter records for our professional practice. Contract performance; legitimate interests
Accounting software provider Processes financial and invoicing data for our business accounting. EU-hosted or subject to appropriate transfer safeguards. Contract performance; legal obligation
Cloud storage provider Stores document and correspondence files in encrypted cloud storage. EU-hosted or subject to Standard Contractual Clauses. Legitimate interests; contract performance
Payment processing provider Processes payment card transactions where applicable. Subject to PCI DSS compliance. We do not store full payment card data. Contract performance
Bulgarian National Revenue Agency (NRA) Where we file payroll declarations and tax information on behalf of employment clients — data is transmitted to the NRA as a legal requirement, not as a processor. Legal obligation

Public authorities and regulatory bodies

We may disclose personal data to Bulgarian and EU public authorities and regulatory bodies where required by law — including the National Revenue Agency (NRA), the National Social Security Institute (NOI), the Anti-Money Laundering Directorate, the Financial Supervision Commission, the State Commission on Gambling, and Bulgarian courts. Such disclosures are made on the basis of legal obligation.

Professional advisors

Where necessary for the provision of our services, we may share personal data with other professional advisors — notaries, barristers, specialist counsel, surveyors, or other advisors engaged to support a specific client matter. All such advisors are required to maintain professional confidentiality.

Business transfers

In the event that Bulgaria For Business is involved in a merger, acquisition, or sale of all or part of its business assets, personal data held by us may be transferred to the acquiring party as part of that transaction, subject to standard confidentiality and GDPR compliance obligations.

WE DO NOT SELL YOUR DATA: Bulgaria For Business does not sell, rent, or otherwise transfer personal data to third parties for their own commercial purposes. Data shared with processors is shared strictly for the purposes described in this policy and under contractual data processing agreements.

8. International transfers of personal data

Bulgaria For Business is based in Bulgaria — an EU member state. Our primary processing activities take place within the EEA. However, some of our third-party service providers (such as cloud storage providers and analytics services) may process data outside the EEA.

Where personal data is transferred outside the EEA, we ensure that appropriate safeguards are in place, in accordance with Chapter V of the GDPR. These safeguards include:

  • Adequacy decisions by the European Commission — confirming that the recipient country provides an adequate level of protection.
  • Standard Contractual Clauses (SCCs) — approved by the European Commission — incorporated into contracts with non-EEA processors.
  • EU-US Data Privacy Framework participation — for transfers to US-based processors that participate in this framework.

A list of the countries to which data may be transferred and the applicable safeguards is available on request by contacting privacy@bulgaria-for-business.com.

9. Data retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected — and thereafter only for as long as required by applicable legal, regulatory, or contractual obligations. Our general retention principles are:

  • Client service data: retained for the duration of the client engagement plus 7 years, to comply with Bulgarian tax and accounting record-keeping requirements.
  • AML/KYC data: retained for 5 years from the end of the business relationship, as required by Bulgarian anti-money laundering law (ЗМИП).
  • Payroll and employment records: retained for the duration of the payroll service engagement plus 5 years, in accordance with Bulgarian employment and social security record-keeping requirements.
  • Website enquiry data (no engagement): retained for 3 years from last contact — to allow follow-up within a commercially reasonable timeframe.
  • Marketing subscriber data: retained until unsubscribe or withdrawal of consent.
  • Cookie and analytics data: as set out in our Cookie Policy — typically up to 26 months for analytics cookies.

At the end of the applicable retention period, personal data is securely deleted or anonymised. Where deletion is not immediately possible due to technical constraints, we will ensure the data is isolated from further processing and scheduled for deletion as soon as practicable.

10. Data security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures include:

  • Encryption of data in transit (TLS/SSL) on our website and in electronic communications.
  • Encrypted storage of sensitive documents and client data.
  • Access controls limiting data access to staff on a need-to-know basis.
  • Regular review of access rights when staff roles change.
  • Secure password policies and multi-factor authentication for systems containing personal data.
  • Regular data backup procedures with secure offsite storage.
  • Staff training on data protection principles and obligations.

Despite these measures, no electronic transmission or storage system is completely secure. If you have reason to believe that your interaction with us is no longer secure — for example, if you believe the security of your account has been compromised — please notify us immediately at privacy@bulgaria-for-business.com.

Data breach notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the Bulgarian Commission for Personal Data Protection (КЗЛД) within 72 hours of becoming aware of the breach, as required by Article 33 GDPR. Where the breach is likely to result in a high risk to affected individuals, we will also notify those individuals without undue delay under Article 34 GDPR.

11. Your rights under GDPR

Under the GDPR and Bulgarian data protection law, you have the following rights in relation to personal data that we hold about you. The table below explains each right, what it means, and how to exercise it.

Right What it means How to exercise it
Right of access (Art. 15 GDPR) You have the right to obtain confirmation of whether we process personal data about you, and to receive a copy of that data along with information about how it is processed. Submit a written request by email to privacy@bulgaria-for-business.com. We will respond within 30 days. First request is free of charge; reasonable fee may apply for manifestly unfounded or excessive requests.
Right to rectification (Art. 16 GDPR) You have the right to have inaccurate personal data corrected and incomplete personal data completed without undue delay. Contact us at privacy@bulgaria-for-business.com with details of the data you believe to be inaccurate or incomplete.
Right to erasure (Art. 17 GDPR) You have the right to request erasure of your personal data where: it is no longer necessary for the purpose it was collected; you withdraw consent (where processing is consent-based); you object and there are no overriding legitimate interests; it has been unlawfully processed; or erasure is required by law. Note: the right to erasure does not apply where processing is necessary for legal obligations (e.g. AML and tax retention requirements). Contact privacy@bulgaria-for-business.com. We will assess and respond within 30 days.
Right to restriction (Art. 18 GDPR) You have the right to request restriction of processing where: you contest the accuracy of the data; processing is unlawful and you request restriction rather than erasure; we no longer need the data but you require it for legal claims; or you have objected and we are assessing whether our legitimate grounds override your interests. Contact privacy@bulgaria-for-business.com.
Right to data portability (Art. 20 GDPR) Where processing is based on consent or contract performance, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format, and to transmit it to another controller. Contact privacy@bulgaria-for-business.com specifying the data you wish to receive.
Right to object (Art. 21 GDPR) You have the right to object to processing based on legitimate interests or for direct marketing purposes. Where you object to direct marketing, we will cease processing immediately. For other legitimate-interest processing, we will assess whether our interests override your rights. Contact privacy@bulgaria-for-business.com or use the unsubscribe link in any marketing communication.
Rights related to automated decision-making (Art. 22 GDPR) You have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you. We do not currently use automated decision-making or profiling for decisions that produce legal or similarly significant effects. Contact privacy@bulgaria-for-business.com if you have concerns.
Right to withdraw consent (Art. 7(3) GDPR) Where processing is based on your consent, you have the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. Use the unsubscribe link in marketing emails, adjust cookie preferences, or contact privacy@bulgaria-for-business.com.

To exercise any of the above rights, please contact us at privacy@bulgaria-for-business.com. We will respond within 30 days. Where a request is complex or numerous, we may extend this period by a further two months — in which case we will notify you within 30 days and explain the reason for the extension.

We may need to verify your identity before fulfilling a request. Identity verification is necessary to protect against unauthorised access to personal data.

12. Children’s data

Our website and services are directed at business professionals and are not intended for use by children under the age of 16. We do not knowingly collect personal data from children. If you believe that we have inadvertently collected personal data from a child, please contact us at privacy@bulgaria-for-business.com and we will take steps to delete that data promptly.

13. Special note — anti-money laundering and client due diligence

Bulgaria For Business is subject to anti-money laundering obligations under Bulgarian law (Закон за мерките срещу изпирането на пари — ЗМИП) and EU anti-money laundering directives for certain professional services it provides — in particular company formation, legal services relating to property transactions and corporate structures, accounting services, and trust and company services.

In fulfilling these obligations, we are required to:

  • verify the identity of clients and beneficial owners before establishing a business relationship;
  • collect identity documents (passport, national ID), proof of address, and information about the purpose of the business relationship;
  • assess and document the money laundering and terrorist financing risk associated with each client relationship;
  • maintain records of all customer due diligence measures taken for a minimum of 5 years; and
  • report suspicious transactions to the Bulgarian Financial Intelligence Directorate (Дирекция “Финансово разузнаване”).

The processing of personal data for AML/KYC purposes is carried out on the basis of legal obligation (Article 6(1)(c) GDPR). You cannot opt out of this processing as a condition of receiving regulated professional services from us. Failure to provide the required information will prevent us from establishing or continuing a business relationship.

AML DATA RETENTION: Identity and customer due diligence records collected under AML obligations are retained for 5 years from the end of the business relationship — as required by Bulgarian law. This retention obligation overrides any request for erasure made during this period.

14. Direct marketing and communications

Marketing to existing clients

We may send existing clients information about services, regulatory developments, and market updates that may be relevant to their business interests. This is done on the basis of our legitimate interests in maintaining a business relationship with our clients. We will only do this where we assess that clients would reasonably expect to receive such communications given our existing relationship. You can opt out at any time using the unsubscribe link in any email.

Marketing to non-clients

We only send marketing communications to individuals who are not existing clients where we have obtained their specific consent — for example, through a newsletter sign-up form. Consent records are maintained with date, source, and the specific communication consented to. You can withdraw consent and unsubscribe at any time.

No profiling for marketing

We do not use automated profiling to target marketing communications — our marketing activities are based on professional relevance and do not use automated decision-making technology.

15. Cookies

Our use of cookies is governed by our separate Cookie Policy, available at www.bulgaria-for-business.com/cookie-policy. Our Cookie Policy explains in detail what cookies we use, why, how long they are stored, and how to manage your cookie preferences. This Privacy Policy and the Cookie Policy should be read together.

16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in applicable law, our data processing practices, or our business activities. When we make material changes, we will update the version date at the top of this document and, where the change significantly affects how we process your data, we will notify you by email (where we hold your email address) or by a prominent notice on our website.

We encourage you to review this policy periodically. The current version is always available at www.bulgaria-for-business.com/privacy-policy.

17. Complaints and supervisory authority

If you have a concern about how we process your personal data, we ask that you contact us in the first instance at privacy@bulgaria-for-business.com so that we can address your concern directly. We take all privacy complaints seriously and will respond within 30 days.

If you are not satisfied with our response, or if you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the Bulgarian supervisory authority:

Authority Commission for Personal Data Protection (Комисия за защита на личните данни — КЗЛД)
Website www.cpdp.bg
Address 2 Prof. Tsvetan Lazarov Blvd, Sofia 1592, Bulgaria
Telephone +359 2 915 3523
Email kzld@cpdp.bg

If you are based in another EU member state, you also have the right to lodge a complaint with the supervisory authority in your country of residence or place of work.


This Privacy Policy and GDPR Compliance Statement was last reviewed and updated in January 2025. It applies to Bulgaria For Business and the website www.bulgaria-for-business.com. This document does not constitute legal advice. For specific data protection advice, please consult a qualified legal professional.

Menu