Compliance, AML & GDPR in Bulgaria

Anti-Money Laundering, Beneficial Ownership & Data Protection Compliance for Bulgarian Entities


EU AML Directives

GDPR Compliance

Beneficial Ownership

Fixed-Fee Programmes

AT A GLANCE

6th EU AML Directive — implemented in Bulgaria
€20M Max GDPR fine (or 4% global turnover)
7 days Beneficial ownership update deadline
Fixed Fee compliance packages available

Compliance, AML & GDPR for foreign-owned Bulgarian companies

Regulatory compliance is no longer optional for Bulgarian companies — it is a legal obligation with real financial consequences for non-compliance. EU anti-money laundering directives, GDPR, and beneficial ownership transparency requirements all apply to Bulgarian entities, and enforcement by Bulgarian and EU regulators has increased significantly in recent years.

Bulgaria for Business VCC provides compliance advisory and implementation services to foreign-owned Bulgarian companies — covering the three principal compliance frameworks that affect most international businesses: Anti-Money Laundering (AML), General Data Protection Regulation (GDPR), and Beneficial Ownership registration. Our compliance lawyers design, implement, and maintain compliance programmes tailored to your company’s specific business model and risk profile.

WHY COMPLIANCE MATTERS FOR FOREIGN OWNERS: Foreign-owned Bulgarian companies are frequently subject to enhanced scrutiny by banks, payment processors, and regulators — precisely because of their international ownership and management. A well-documented AML programme, a current beneficial ownership register, and a basic GDPR framework are increasingly essential not just for legal compliance but for maintaining banking relationships, winning contracts, and passing counterparty due diligence checks.

Our compliance services

We cover all three core compliance frameworks for Bulgarian entities — AML, beneficial ownership, and GDPR — as well as sector-specific regulatory compliance for regulated industries.

AML compliance programme

Design and implementation of an internal AML/CFT compliance programme for Bulgarian entities subject to the Measures Against Money Laundering Act — including risk assessment, internal policies, KYC procedures, and staff training.

Beneficial ownership register

Filing and maintenance of the Bulgarian beneficial ownership register (Регистър на действителните собственици) — identifying and registering all natural persons who ultimately own or control a Bulgarian company through any chain of ownership.

GDPR compliance programme

Full GDPR compliance implementation for Bulgarian companies processing personal data — data audit, privacy notices, consent mechanisms, data processing agreements, records of processing activities, and breach response procedures.

Data Processing Agreements (DPA)

Drafting of GDPR-compliant data processing agreements between Bulgarian controllers and processors — covering processing scope, security measures, sub-processor chains, data transfers, and breach notification.

Data Protection Officer (DPO) services

Outsourced DPO function for Bulgarian companies required to appoint a DPO — or choosing to do so voluntarily. Our DPO acts as the point of contact with the Bulgarian Commission for Personal Data Protection (CPDP).

Regulatory compliance advisory

Advice on sector-specific regulatory compliance for Bulgarian entities in regulated industries — financial services, payment institutions, virtual asset service providers (VASPs), and real estate.

Anti-money laundering (AML) — the Bulgarian framework

Bulgaria has implemented the EU’s Anti-Money Laundering Directives (AMLD) through the Measures Against Money Laundering Act (Закон за мерките срещу изпирането на пари — ZMIP). The Act was most recently updated to implement the 6th AML Directive. It imposes obligations on a defined set of ‘obliged entities’ — businesses operating in sectors considered at higher risk of money laundering and terrorist financing.

AML ENFORCEMENT: The Bulgarian State Agency for National Security (DANS — Държавна агенция Национална сигурност) is the primary AML supervisory authority for non-financial obliged entities in Bulgaria. DANS conducts on-site inspections and can impose fines of up to BGN 500,000 for serious AML breaches. The NRA also has supervisory authority over accountants, auditors, and tax advisors. Bulgaria for Business VCC recommends that all entities in scope implement a documented AML programme before a supervisory visit occurs.

Who is subject to AML obligations in Bulgaria?

The following categories of entity are ‘obliged entities’ under the Bulgarian Measures Against Money Laundering Act and must implement AML/CFT compliance programmes. If your Bulgarian company falls into any of these categories, AML compliance is mandatory — not optional.

Category of obliged entity Scope in Bulgaria
Credit institutions & payment institutions Banks, payment service providers, electronic money institutions, and currency exchange operators.
Investment firms & fund managers Investment intermediaries, collective investment scheme managers, and portfolio management companies.
Insurance companies Life insurance companies and insurance intermediaries — for investment-related products.
Auditors, accountants & tax advisors Licensed auditors, accounting firms, and tax advisors providing services to clients — including bookkeeping and company administration services.
Legal professionals (lawyers & notaries) When advising on or assisting with financial transactions, company formation, asset purchases, or acting as a trustee.
Real estate agents When acting in transactions involving the buying or selling of real property.
Virtual asset service providers (VASPs) Entities providing cryptocurrency exchange, custody, or transfer services — subject to enhanced AML obligations under the 6th AML Directive as implemented in Bulgaria.
Company formation agents Persons providing company formation, registered address, directorship, or nominee services to third parties on a professional basis.
Trust & company service providers Entities providing trust administration, company secretarial, or registered office services as a business.

What an AML compliance programme must contain

Every obliged entity under Bulgarian AML law must implement a documented internal compliance programme proportionate to its size, nature of business, and ML/TF risk profile. The table below lists all mandatory components of a compliant AML programme under the ZMIP.

  • Written internal AML/CFT policies — A documented set of internal rules and procedures for preventing money laundering and terrorist financing — covering customer acceptance, transaction monitoring, reporting, and staff responsibilities.
  • ML/TF risk assessment — A written assessment of the entity’s exposure to money laundering and terrorist financing risk — by customer type, geography, product, and delivery channel. Forms the basis for the proportionate application of due diligence measures.
  • Customer due diligence (CDD) procedures — Documented procedures for identifying and verifying customers and beneficial owners — including standard CDD, enhanced due diligence (EDD) for high-risk customers, and simplified CDD for low-risk cases.
  • Politically Exposed Persons (PEP) screening — Procedures for identifying PEPs (current and former), their family members, and close associates — with enhanced due diligence applied to all PEP relationships.
  • Suspicious transaction reporting (STR) procedures — Internal escalation and reporting procedures for suspicious transactions or activities — including the role of the compliance officer and reporting to DANS (State Agency for National Security) in Bulgaria.
  • Transaction monitoring — Procedures for ongoing monitoring of customer transactions — identifying unusual patterns, large cash transactions, and transactions inconsistent with the customer’s known profile.
  • Staff training programme — Annual AML/CFT training for all relevant staff — covering recognition of suspicious activity, customer due diligence obligations, and reporting procedures.
  • Compliance officer appointment — Designation of a responsible compliance officer (or senior management member) with specific AML/CFT oversight responsibility.
  • Record-keeping procedures — Procedures for retaining AML-related documentation — KYC records, transaction records, STR files, and training records — for the statutory minimum period (5 years in Bulgaria).

Beneficial ownership register — obligations & process

Bulgaria implemented mandatory beneficial ownership registration in 2019 under Directive 2018/843 (5th AML Directive). Every Bulgarian commercial entity must identify its beneficial owners and register them in the publicly accessible beneficial ownership section of the Bulgarian Commercial Register.

Requirement Details
Who must register All Bulgarian commercial entities (OOD, EOOD, AD, SD, KD) and foreign company branches registered in Bulgaria. Non-profit legal entities (foundations, associations) also have registration obligations under a parallel register.
Who is a beneficial owner Any natural person who ultimately owns or controls the entity — directly or indirectly — through ownership of shares, voting rights, or other means of control. The threshold is ownership or control exceeding 25% of shares or voting rights. Where no natural person meets this threshold, the senior managing official (typically the director) is registered as beneficial owner.
Where to register The Bulgarian Commercial Register (Търговски регистър) maintained by the Registry Agency. Registration is made electronically using the NRA’s portal.
Initial registration deadline Existing companies: by 1 May 2019 (now overdue — late registration subject to penalty). New companies: at the time of commercial registration.
Update deadline Any change in beneficial ownership must be registered within 7 days of the change occurring.
Penalties for non-registration Failure to register or update the beneficial ownership register carries fines of BGN 1,000–20,000 for the company and BGN 500–10,000 for the responsible director personally.
Public access The beneficial ownership register is publicly accessible — any person can search the register to identify the beneficial owners of a Bulgarian company.
COMPLEX OWNERSHIP STRUCTURES: Where a Bulgarian company is owned through a chain of holding companies across multiple jurisdictions, identifying the ultimate beneficial owner(s) can be complex. The 25% threshold applies at each level of the chain — meaning that a person owning 50% of a company that owns 60% of the Bulgarian entity (effective 30%) is a beneficial owner. Bulgaria for Business VCC conducts beneficial ownership analysis for complex structures and files the correct registration, including where nominee arrangements or trust structures are involved.

GDPR — what every Bulgarian company must do

The General Data Protection Regulation (GDPR — Regulation 2016/679) applies directly in Bulgaria as an EU member state. Every Bulgarian company that processes personal data — of employees, customers, suppliers, or any other individuals — is subject to GDPR. The Bulgarian supervisory authority is the Commission for Personal Data Protection (CPDP — Комисия за защита на личните данни).

GDPR obligation What it means for your Bulgarian company
Lawful basis for processing Every processing activity must have a lawful basis under GDPR Art. 6 — consent, contract, legal obligation, vital interests, public task, or legitimate interests. Reliance on the wrong basis makes processing unlawful.
Privacy notice / fair processing notice Individuals must be informed about how their data is processed — who processes it, for what purpose, the legal basis, retention period, and their rights. Failure to provide a compliant notice is a common GDPR violation.
Records of processing activities (ROPA) Most organisations must maintain an internal record of all data processing activities — Article 30 GDPR. Serves as the foundation for GDPR accountability and is the first document requested in a supervisory authority inspection.
Data Processing Agreements (DPA) Where personal data is processed by a third party on behalf of the company (a processor), a written DPA must be in place — Article 28 GDPR. Common examples: cloud providers, payroll processors, accounting firms, CRM providers.
International data transfers Transfer of personal data outside the EU/EEA requires an approved transfer mechanism — adequacy decision, Standard Contractual Clauses (SCCs), or Binding Corporate Rules. Transfers to non-adequate third countries without a mechanism are unlawful.
Data subject rights Individuals have rights to access, rectify, erase, restrict, and port their data, and to object to processing. Organisations must have procedures to respond to these requests within 30 days.
Data breach notification Personal data breaches must be assessed immediately. Where the breach is likely to result in risk to individuals, it must be notified to the CPDP within 72 hours. High-risk breaches must also be notified to affected individuals.
Data Protection Officer (DPO) A DPO must be appointed where the organisation processes data on a large scale as its core activity, conducts large-scale monitoring of individuals, or processes special category data on a large scale. The DPO acts as the point of contact with the supervisory authority.
GDPR ENFORCEMENT IN BULGARIA: The CPDP has significantly increased its enforcement activity. It has issued fines to Bulgarian companies across multiple sectors including healthcare, financial services, and e-commerce. The most common violations leading to fines are: failure to provide a compliant privacy notice, lack of a written data processing agreement with processors, and failure to notify data breaches within 72 hours. Bulgaria for Business VCC recommends implementing at minimum a basic GDPR package (ROPA + privacy notices + DPA templates) for every client company.

Compliance services — fees & pricing

All compliance services are available on a fixed-fee basis for standard engagements. Complex or regulated-entity programmes are quoted following an initial assessment. All fees exclude Bulgarian VAT (20%).

Service What is included Price (excl. VAT)
Beneficial ownership register — initial filing Identification of beneficial owners, preparation of declarations, and electronic filing with the Bulgarian Commercial Register. From €150
Beneficial ownership register — update filing Filing of a change in beneficial ownership within the statutory 7-day deadline. From €100
AML risk assessment (basic) Written ML/TF risk assessment for a standard low-to-medium risk Bulgarian entity — by customer type, geography, and product. From €400
AML compliance programme (basic) Full written AML/CFT programme for a standard obliged entity — policies, CDD procedures, PEP screening, STR procedures, and record-keeping policy. From €800
AML compliance programme (enhanced) Enhanced AML programme for higher-risk entities — VASPs, financial intermediaries, or entities with complex customer profiles or international exposure. From €1,500
Annual AML review & update Annual review and update of the AML programme — reflecting regulatory changes, business model changes, and supervisory authority guidance. From €400/yr
GDPR compliance audit Review of the company’s current data processing activities and identification of gaps against GDPR requirements. From €500
GDPR compliance package (basic) Records of processing activities (ROPA), privacy notice, cookie policy, and internal data protection policy for a standard Bulgarian company. From €800
GDPR compliance package (full) Full GDPR implementation: ROPA, all privacy notices, DPA templates, consent mechanisms, data breach response procedure, and DPO appointment letter. From €1,500
Data Processing Agreement (DPA) GDPR-compliant DPA between controller and processor — covering all Article 28 requirements. From €250
International data transfer assessment Assessment of cross-border data transfers and implementation of appropriate transfer mechanism (SCCs, adequacy, BCRs). From €400
Outsourced DPO service Monthly outsourced DPO function — point of contact with CPDP, incident response, staff queries, and annual compliance review. From €200/mo
Ad-hoc compliance advisory Hourly advice on specific AML, GDPR, or regulatory compliance questions. From €150/hr

Annual compliance review and maintenance packages are available for clients requiring ongoing AML and GDPR support. Contact us for a tailored annual compliance retainer proposal.

Frequently asked questions — compliance, AML & GDPR

Get your compliance in order today

Free initial compliance assessment for all new enquiries. We identify your obligations and provide a fixed-fee proposal for the work needed.

Beneficial ownership from €150
AML programme from €800
GDPR package from €800
DPO from €200/mo

Bulgaria for Business VCC — Your Trusted Partner for Business Expansion into Bulgaria and the European Union. All legal services are provided by lawyers qualified and registered with the Bulgarian Bar Association. Regulatory requirements are correct as of 2024–2025 and are subject to legislative change. This document is for general information only and does not constitute legal advice.

Menu