Skip to content
NewOFAC Watcher checks your watchlist each day and emails you when a sanctions-list change looks like a possible match.See OFAC Watcher · $29 / month
Covered
  • OFAC SDN list
  • UN sanctions list
  • EU sanctions list
  • Public on-chain data
  • MiCA
  • EU AI Act
  • GDPR
  • DORA
  • FinCEN BOI
  • VARA
  • SOC 2
  • AML / KYC

CCPA / CPRA compliance in Bulgaria: who is in scope and what is owed

How CCPA / CPRA applies to companies operating in or serving Bulgaria — scope tests, the obligations that follow, and the primary sources to verify each one against.

Organizations established in or operating from Bulgaria may fall within the scope of California privacy regulations if they collect personal information from California residents and meet specific statutory thresholds. Supervised by the California Privacy Protection Agency and the California Attorney General, entities subject to the regime must provide statutory notices, respect consumer rights, and manage opt-out preferences. Compliance-operations teams must evaluate their extraterritorial exposure against statutory revenue and data-processing counts.

Extraterritorial Scope and Applicability to Entities in Bulgaria

The California Consumer Privacy Act and the California Privacy Rights Act apply to for-profit legal entities that do business in California and collect consumers' personal information, or on behalf of which such information is collected, and that satisfy one or more jurisdictional criteria set out in the statute. For a business located in Bulgaria, physical presence in California is not required; selling goods or services to residents of California or processing their data can establish nexus. Organizations should review the statutory provisions available through the California Civil Code §1798.100 et seq. (CCPA/CPRA text) to determine their exact standing. This extraterritorial reach means Bulgarian software vendors, e-commerce platforms, and service providers must assess whether their digital touchpoints interact with California consumers. When conducting this assessment, entities should review the regulatory framework detailed by the California Privacy Protection Agency — regulations to align with enforcement expectations. Managing cross-border data flows requires careful mapping of data collection practices to verify whether statutory thresholds are met. Teams can consult the regulations hub for foundational reference materials on statutory obligations. Jurisdictional triggers depend heavily on annual gross revenues, the volume of consumers whose data is processed, and whether a business derives revenue from sharing personal information.

Specific Thresholds Governing Scope and Applicability

To be covered by the California framework, a business must typically exceed certain statutory criteria relating to revenue or data volume. These thresholds include generating a specific level of gross annual revenue, buying, receiving, selling, or sharing the personal information of a threshold number of consumers, households, or devices annually, or deriving a significant percentage of annual revenue from selling or sharing personal information. Bulgarian companies must evaluate their global revenue alongside transactions originating from California residents. The California Civil Code §1798.100 et seq. (CCPA/CPRA text) outlines these precise figures and parameters. Entities that control or are controlled by a business that shares common branding may also be pulled into scope. Organizations can examine broader regulatory structures via the regulations hub to understand how these criteria are interpreted. Businesses that do not meet revenue thresholds might still be subject to the law if they voluntarily certify compliance or process data on behalf of covered entities under specific contractual terms. Detailed information regarding the oversight body can be found via the California Privacy Protection Agency portal.

| Statutory Factor | Assessment Metric | Jurisdictional Impact | | :--- | :--- | :--- | | Annual Gross Revenue | Statutory threshold in USD | Establishes primary financial nexus | | Consumer Data Volume | Annual count of consumers whose data is processed | Triggers applicability based on scale | | Revenue from Sharing | Percentage of revenue derived from data sharing | Captures data-broker business models |

Obligations Owed to California Residents by Bulgarian Entities

Covered organizations owe specific transparency and operational duties to California residents whose personal information is collected. At or before the point of collection, businesses must provide notice detailing the categories of personal information collected and the purposes for which it is used. Consumers possess rights to know, delete, correct, and restrict the use of their personal information, including sensitive personal information. When a business sells or shares personal information, or engages in cross-context behavioral advertising, consumers hold an absolute right to opt-out. Bulgarian entities must operationalize mechanisms to process these requests without discrimination. Operational guidance for handling these workflows is available through the guides directory and the specialized ccpa-cpra-data-subject-request-operations-guide resource. Businesses must recognize and process user opt-out preference signals, such as the global privacy control, sent by consumer browsers or devices. Failure to honor these preferences can result in regulatory inquiry by the California Attorney General — CCPA enforcement division.

Contractual Requirements for Service Providers and Contractors

When Bulgarian organizations process personal information on behalf of other businesses as a service provider-ccpa or a contractor-ccpa, specific statutory restrictions apply to their data use. Service providers and contractors are prohibited from retaining, using, or disclosing personal information for any purpose other than the business purposes specified in the written contract. This includes commercial purposes outside of the direct business relationship. The governing rules set forth in the California Civil Code §1798.100 et seq. (CCPA/CPRA text) require explicit contractual clauses certifying that the service provider understands and will comply with these limitations. Compliance teams in Bulgaria must audit their vendor agreements to ensure that downstream data processing aligns with statutory definitions. Guidance on broader regulatory compliance obligations can be reviewed through the regulations page. Entities acting in these capacities must permit the business that transferred the data to monitor and audit compliance upon reasonable notice. Establishing these robust contractual safeguards helps mitigate liability when handling California resident data across international borders.

Evidencing Compliance and Managing Operational Risk in Bulgaria

Compliance-operations teams in Bulgaria must establish documented procedures to evidence adherence to California privacy mandates. This involves maintaining records of consumer privacy requests, keeping privacy policies updated with required statutory disclosures, and testing opt-out mechanisms regularly. Organizations can utilize resources within the tools and risk-engine sections to structure their compliance assessments. Because enforcement is actively pursued by the California Attorney General — CCPA and the California Privacy Protection Agency, maintaining audit-ready documentation is essential for demonstrating good faith efforts. Teams should also consult the snapshot and calculators utilities to evaluate exposure levels across different business units. Uncertainty surrounding data flows and extraterritorial interpretation should be verified against primary statutory texts and professional legal counsel. Organizations seeking tailored assistance can reach out via the contact page to discuss technical compliance infrastructure.

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Frequently asked questions

Does a Bulgarian company need a physical office in California to be subject to the law?

No physical office is required. Jurisdiction is established if the entity does business in California, collects consumer personal information, and meets statutory revenue or data-processing thresholds regardless of its geographic location.

How must Bulgarian entities handle browser-based opt-out signals?

Covered businesses must configure their systems to automatically recognize and process opt-out preference signals, such as the Global Privacy Control, without requiring the consumer to make a manual request.

What categories of data receive heightened protection under the statute?

Sensitive personal information, including precise geolocation, financial account details, social security numbers, and health data, receives specific restrictions regarding use and consumer limitation rights.

Which regulatory bodies supervise and enforce these California privacy rules?

Enforcement responsibilities are shared between the California Privacy Protection Agency and the California Attorney General, both of which possess authority to investigate violations and initiate enforcement actions.

Sources

BizLegal AI is regulatory research software, not a law firm. This page is general information, not legal advice, and does not create a lawyer-client relationship. Verify every deadline, threshold and obligation against the primary source cited before you act on it, and consult qualified counsel in the relevant jurisdiction.

Last reviewed 2026-10-08.

Contact