This depends on whether your company is an ‘obliged entity’ under the Bulgarian Measures Against Money Laundering Act (ZMIP). Obliged entities include financial institutions, legal and accounting professionals, real estate agents, company formation agents, trust service providers, and VASPs — among others. Standard trading companies, e-commerce businesses, and IT service providers are generally not obliged entities. However, if your business model touches any regulated activity, we recommend a brief assessment to confirm your status. Contact us for a free initial assessment.
Compliance, AML & GDPR in Bulgaria
Anti-Money Laundering, Beneficial Ownership & Data Protection Compliance for Bulgarian Entities
EU AML Directives
GDPR Compliance
Beneficial Ownership
Fixed-Fee Programmes
AT A GLANCE
Compliance, AML & GDPR for foreign-owned Bulgarian companies
Regulatory compliance is no longer optional for Bulgarian companies — it is a legal obligation with real financial consequences for non-compliance. EU anti-money laundering directives, GDPR, and beneficial ownership transparency requirements all apply to Bulgarian entities, and enforcement by Bulgarian and EU regulators has increased significantly in recent years.
Bulgaria for Business VCC provides compliance advisory and implementation services to foreign-owned Bulgarian companies — covering the three principal compliance frameworks that affect most international businesses: Anti-Money Laundering (AML), General Data Protection Regulation (GDPR), and Beneficial Ownership registration. Our compliance lawyers design, implement, and maintain compliance programmes tailored to your company’s specific business model and risk profile.
Our compliance services
We cover all three core compliance frameworks for Bulgarian entities — AML, beneficial ownership, and GDPR — as well as sector-specific regulatory compliance for regulated industries.
Design and implementation of an internal AML/CFT compliance programme for Bulgarian entities subject to the Measures Against Money Laundering Act — including risk assessment, internal policies, KYC procedures, and staff training.
Filing and maintenance of the Bulgarian beneficial ownership register (Регистър на действителните собственици) — identifying and registering all natural persons who ultimately own or control a Bulgarian company through any chain of ownership.
Full GDPR compliance implementation for Bulgarian companies processing personal data — data audit, privacy notices, consent mechanisms, data processing agreements, records of processing activities, and breach response procedures.
Drafting of GDPR-compliant data processing agreements between Bulgarian controllers and processors — covering processing scope, security measures, sub-processor chains, data transfers, and breach notification.
Outsourced DPO function for Bulgarian companies required to appoint a DPO — or choosing to do so voluntarily. Our DPO acts as the point of contact with the Bulgarian Commission for Personal Data Protection (CPDP).
Advice on sector-specific regulatory compliance for Bulgarian entities in regulated industries — financial services, payment institutions, virtual asset service providers (VASPs), and real estate.
Anti-money laundering (AML) — the Bulgarian framework
Bulgaria has implemented the EU’s Anti-Money Laundering Directives (AMLD) through the Measures Against Money Laundering Act (Закон за мерките срещу изпирането на пари — ZMIP). The Act was most recently updated to implement the 6th AML Directive. It imposes obligations on a defined set of ‘obliged entities’ — businesses operating in sectors considered at higher risk of money laundering and terrorist financing.
Who is subject to AML obligations in Bulgaria?
The following categories of entity are ‘obliged entities’ under the Bulgarian Measures Against Money Laundering Act and must implement AML/CFT compliance programmes. If your Bulgarian company falls into any of these categories, AML compliance is mandatory — not optional.
| Category of obliged entity | Scope in Bulgaria |
|---|---|
| Credit institutions & payment institutions | Banks, payment service providers, electronic money institutions, and currency exchange operators. |
| Investment firms & fund managers | Investment intermediaries, collective investment scheme managers, and portfolio management companies. |
| Insurance companies | Life insurance companies and insurance intermediaries — for investment-related products. |
| Auditors, accountants & tax advisors | Licensed auditors, accounting firms, and tax advisors providing services to clients — including bookkeeping and company administration services. |
| Legal professionals (lawyers & notaries) | When advising on or assisting with financial transactions, company formation, asset purchases, or acting as a trustee. |
| Real estate agents | When acting in transactions involving the buying or selling of real property. |
| Virtual asset service providers (VASPs) | Entities providing cryptocurrency exchange, custody, or transfer services — subject to enhanced AML obligations under the 6th AML Directive as implemented in Bulgaria. |
| Company formation agents | Persons providing company formation, registered address, directorship, or nominee services to third parties on a professional basis. |
| Trust & company service providers | Entities providing trust administration, company secretarial, or registered office services as a business. |
What an AML compliance programme must contain
Every obliged entity under Bulgarian AML law must implement a documented internal compliance programme proportionate to its size, nature of business, and ML/TF risk profile. The table below lists all mandatory components of a compliant AML programme under the ZMIP.
- Written internal AML/CFT policies — A documented set of internal rules and procedures for preventing money laundering and terrorist financing — covering customer acceptance, transaction monitoring, reporting, and staff responsibilities.
- ML/TF risk assessment — A written assessment of the entity’s exposure to money laundering and terrorist financing risk — by customer type, geography, product, and delivery channel. Forms the basis for the proportionate application of due diligence measures.
- Customer due diligence (CDD) procedures — Documented procedures for identifying and verifying customers and beneficial owners — including standard CDD, enhanced due diligence (EDD) for high-risk customers, and simplified CDD for low-risk cases.
- Politically Exposed Persons (PEP) screening — Procedures for identifying PEPs (current and former), their family members, and close associates — with enhanced due diligence applied to all PEP relationships.
- Suspicious transaction reporting (STR) procedures — Internal escalation and reporting procedures for suspicious transactions or activities — including the role of the compliance officer and reporting to DANS (State Agency for National Security) in Bulgaria.
- Transaction monitoring — Procedures for ongoing monitoring of customer transactions — identifying unusual patterns, large cash transactions, and transactions inconsistent with the customer’s known profile.
- Staff training programme — Annual AML/CFT training for all relevant staff — covering recognition of suspicious activity, customer due diligence obligations, and reporting procedures.
- Compliance officer appointment — Designation of a responsible compliance officer (or senior management member) with specific AML/CFT oversight responsibility.
- Record-keeping procedures — Procedures for retaining AML-related documentation — KYC records, transaction records, STR files, and training records — for the statutory minimum period (5 years in Bulgaria).
Beneficial ownership register — obligations & process
Bulgaria implemented mandatory beneficial ownership registration in 2019 under Directive 2018/843 (5th AML Directive). Every Bulgarian commercial entity must identify its beneficial owners and register them in the publicly accessible beneficial ownership section of the Bulgarian Commercial Register.
| Requirement | Details |
|---|---|
| Who must register | All Bulgarian commercial entities (OOD, EOOD, AD, SD, KD) and foreign company branches registered in Bulgaria. Non-profit legal entities (foundations, associations) also have registration obligations under a parallel register. |
| Who is a beneficial owner | Any natural person who ultimately owns or controls the entity — directly or indirectly — through ownership of shares, voting rights, or other means of control. The threshold is ownership or control exceeding 25% of shares or voting rights. Where no natural person meets this threshold, the senior managing official (typically the director) is registered as beneficial owner. |
| Where to register | The Bulgarian Commercial Register (Търговски регистър) maintained by the Registry Agency. Registration is made electronically using the NRA’s portal. |
| Initial registration deadline | Existing companies: by 1 May 2019 (now overdue — late registration subject to penalty). New companies: at the time of commercial registration. |
| Update deadline | Any change in beneficial ownership must be registered within 7 days of the change occurring. |
| Penalties for non-registration | Failure to register or update the beneficial ownership register carries fines of BGN 1,000–20,000 for the company and BGN 500–10,000 for the responsible director personally. |
| Public access | The beneficial ownership register is publicly accessible — any person can search the register to identify the beneficial owners of a Bulgarian company. |
GDPR — what every Bulgarian company must do
The General Data Protection Regulation (GDPR — Regulation 2016/679) applies directly in Bulgaria as an EU member state. Every Bulgarian company that processes personal data — of employees, customers, suppliers, or any other individuals — is subject to GDPR. The Bulgarian supervisory authority is the Commission for Personal Data Protection (CPDP — Комисия за защита на личните данни).
| GDPR obligation | What it means for your Bulgarian company |
|---|---|
| Lawful basis for processing | Every processing activity must have a lawful basis under GDPR Art. 6 — consent, contract, legal obligation, vital interests, public task, or legitimate interests. Reliance on the wrong basis makes processing unlawful. |
| Privacy notice / fair processing notice | Individuals must be informed about how their data is processed — who processes it, for what purpose, the legal basis, retention period, and their rights. Failure to provide a compliant notice is a common GDPR violation. |
| Records of processing activities (ROPA) | Most organisations must maintain an internal record of all data processing activities — Article 30 GDPR. Serves as the foundation for GDPR accountability and is the first document requested in a supervisory authority inspection. |
| Data Processing Agreements (DPA) | Where personal data is processed by a third party on behalf of the company (a processor), a written DPA must be in place — Article 28 GDPR. Common examples: cloud providers, payroll processors, accounting firms, CRM providers. |
| International data transfers | Transfer of personal data outside the EU/EEA requires an approved transfer mechanism — adequacy decision, Standard Contractual Clauses (SCCs), or Binding Corporate Rules. Transfers to non-adequate third countries without a mechanism are unlawful. |
| Data subject rights | Individuals have rights to access, rectify, erase, restrict, and port their data, and to object to processing. Organisations must have procedures to respond to these requests within 30 days. |
| Data breach notification | Personal data breaches must be assessed immediately. Where the breach is likely to result in risk to individuals, it must be notified to the CPDP within 72 hours. High-risk breaches must also be notified to affected individuals. |
| Data Protection Officer (DPO) | A DPO must be appointed where the organisation processes data on a large scale as its core activity, conducts large-scale monitoring of individuals, or processes special category data on a large scale. The DPO acts as the point of contact with the supervisory authority. |
Compliance services — fees & pricing
All compliance services are available on a fixed-fee basis for standard engagements. Complex or regulated-entity programmes are quoted following an initial assessment. All fees exclude Bulgarian VAT (20%).
| Service | What is included | Price (excl. VAT) |
|---|---|---|
| Beneficial ownership register — initial filing | Identification of beneficial owners, preparation of declarations, and electronic filing with the Bulgarian Commercial Register. | From €150 |
| Beneficial ownership register — update filing | Filing of a change in beneficial ownership within the statutory 7-day deadline. | From €100 |
| AML risk assessment (basic) | Written ML/TF risk assessment for a standard low-to-medium risk Bulgarian entity — by customer type, geography, and product. | From €400 |
| AML compliance programme (basic) | Full written AML/CFT programme for a standard obliged entity — policies, CDD procedures, PEP screening, STR procedures, and record-keeping policy. | From €800 |
| AML compliance programme (enhanced) | Enhanced AML programme for higher-risk entities — VASPs, financial intermediaries, or entities with complex customer profiles or international exposure. | From €1,500 |
| Annual AML review & update | Annual review and update of the AML programme — reflecting regulatory changes, business model changes, and supervisory authority guidance. | From €400/yr |
| GDPR compliance audit | Review of the company’s current data processing activities and identification of gaps against GDPR requirements. | From €500 |
| GDPR compliance package (basic) | Records of processing activities (ROPA), privacy notice, cookie policy, and internal data protection policy for a standard Bulgarian company. | From €800 |
| GDPR compliance package (full) | Full GDPR implementation: ROPA, all privacy notices, DPA templates, consent mechanisms, data breach response procedure, and DPO appointment letter. | From €1,500 |
| Data Processing Agreement (DPA) | GDPR-compliant DPA between controller and processor — covering all Article 28 requirements. | From €250 |
| International data transfer assessment | Assessment of cross-border data transfers and implementation of appropriate transfer mechanism (SCCs, adequacy, BCRs). | From €400 |
| Outsourced DPO service | Monthly outsourced DPO function — point of contact with CPDP, incident response, staff queries, and annual compliance review. | From €200/mo |
| Ad-hoc compliance advisory | Hourly advice on specific AML, GDPR, or regulatory compliance questions. | From €150/hr |
Annual compliance review and maintenance packages are available for clients requiring ongoing AML and GDPR support. Contact us for a tailored annual compliance retainer proposal.
Frequently asked questions — compliance, AML & GDPR
Yes. Every registered Bulgarian commercial entity — OOD, EOOD, AD, SD, KD — must register its beneficial owners in the Bulgarian Commercial Register. This obligation applies regardless of the company’s business activity or size. The register is publicly accessible. Failure to register carries fines of up to BGN 20,000 for the company and BGN 10,000 for the director personally. Bulgaria for Business VCC files and maintains beneficial ownership registrations for all client companies as a standard service.
GDPR applies to any organisation that processes personal data of individuals located in the EU — regardless of whether the organisation itself is EU-based. A Bulgarian company processing data of Bulgarian employees, customers, or suppliers is subject to GDPR. Even a purely domestic Bulgarian operation processing only Bulgarian residents’ data is subject to GDPR, as Bulgaria is an EU member state. The Bulgarian supervisory authority is the Commission for Personal Data Protection (CPDP — Комисия за защита на личните данни).
GDPR provides for two tiers of administrative fines: up to €10 million or 2% of global annual turnover (whichever is higher) for less serious infringements; and up to €20 million or 4% of global annual turnover for more serious infringements — including unlawful processing, violation of data subject rights, and unlawful international transfers. The Bulgarian CPDP has issued fines to Bulgarian entities — enforcement has increased significantly since 2021. Bulgaria for Business VCC recommends implementing basic GDPR compliance as a priority for all client companies.
A Data Protection Officer (DPO) must be appointed where: (1) the company is a public authority; (2) the core activities consist of large-scale, regular, and systematic monitoring of individuals; or (3) the core activities involve large-scale processing of special categories of data. Most standard trading companies, IT service providers, and consultancy firms do not meet these thresholds and are not required to appoint a DPO. However, many choose to appoint an external DPO voluntarily as a demonstration of accountability. Our outsourced DPO service provides this function from €200/month.
A DPA is a contract required under Article 28 GDPR between a ‘controller’ (the entity that determines the purpose and means of processing) and a ‘processor’ (a third party that processes data on the controller’s behalf). Common processor relationships include: cloud hosting providers, payroll bureaus, accounting firms, CRM software providers, and email marketing platforms. Every such relationship must be governed by a compliant DPA. Bulgaria for Business VCC drafts DPAs from €250 per agreement.
You must assess the breach immediately. If the breach is likely to result in a risk to the rights and freedoms of individuals, you must notify the Bulgarian CPDP within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk, you must also notify the affected individuals without undue delay. Failure to notify within 72 hours is itself a GDPR violation carrying potential fines. Bulgaria for Business VCC provides breach response support as part of our GDPR compliance service and outsourced DPO function.
A natural person is considered a beneficial owner if they directly or indirectly own or control more than 25% of the shares, voting rights, or other means of control of a Bulgarian entity. Where no natural person meets this threshold through direct or indirect ownership, the individual exercising control through other means (e.g. a right to appoint the majority of directors) is the beneficial owner. Where no natural person can be identified, the senior managing official — typically the director — is registered as the beneficial owner.
Get your compliance in order today
Free initial compliance assessment for all new enquiries. We identify your obligations and provide a fixed-fee proposal for the work needed.
AML programme from €800
GDPR package from €800
DPO from €200/mo
Bulgaria for Business VCC — Your Trusted Partner for Business Expansion into Bulgaria and the European Union. All legal services are provided by lawyers qualified and registered with the Bulgarian Bar Association. Regulatory requirements are correct as of 2024–2025 and are subject to legislative change. This document is for general information only and does not constitute legal advice.
