Vassilev & Chisuse Law Firm · 2026-09-23
The article outlines Bulgaria’s whistleblowing rules, including internal reporting channels, key deadlines, confidentiality, protection against retaliation and sanctions for non-compliance.
An internal whistleblowing channel is mandatory for private-sector employers with 50 or more employees. The obligation also applies regardless of headcount to certain employers operating in specifically regulated areas identified by law. The regime is governed by the Bulgarian Protection of Persons Who Report or Publicly Disclose Information on Breaches Act, which transposes Directive (EU) 2019/1937 into Bulgarian law.
From 13 May 2025, the previous restriction preventing proceedings in relation to breaches committed more than two years earlier was removed. The previous option allowing companies belonging to the same economic group to rely on a single group-level internal reporting channel under Article 14(5) was also removed.
What Types of Breaches Can Be Reported?The Bulgarian whistleblowing legislation applies to information on actual or potential breaches and reasonable suspicions of breaches obtained in a work-related context. Its scope covers breaches of Bulgarian law and specified European Union legislation.
The areas covered include public procurement, financial services, products and markets, prevention of money laundering and terrorist financing, product safety and compliance, transport safety, environmental protection, radiation protection and nuclear safety, food and feed safety, animal health and welfare, public health, consumer protection, privacy and personal data protection, and network and information system security.
The Act also covers breaches affecting the financial interests of the European Union, internal market rules including competition and State aid, certain cross-border tax arrangements and criminal offences prosecuted ex officio where the protected person obtained the relevant information in connection with their work or official duties. Its scope also extends to breaches of Bulgarian employment law, civil service legislation and rules concerning public State and municipal receivables.
Which Employers Must Establish an Internal Whistleblowing Channel?Private-sector employers with 50 or more employees must maintain an internal reporting channel. Employers with fewer than 50 employees are generally outside this headcount-based obligation unless their activities fall within the regulated areas referred to in Article 12(1)(3), for which the obligation applies regardless of the number of employees.
Private employers with between 50 and 249 employees may share resources for receiving reports and carrying out follow-up activities, provided that the statutory requirements concerning confidentiality, feedback and measures addressing the reported breach are observed. Employers with more than 250 employees do not have the resource-sharing option under Article 12(3).
Resource sharing should not be confused with reliance on a single group-wide whistleblowing channel. Since 13 May 2025, separate companies within an economic group can no longer satisfy their individual statutory obligations merely by using a channel established at group level. Each Bulgarian company that independently qualifies as an obliged employer must meet its own obligations and designate an employee or unit responsible for handling reports.
How Must an Internal Channel Be Organised?The internal channel must be designed and operated in a manner that protects the completeness, integrity and confidentiality of the information and prevents access by unauthorised persons. The employer must designate one or more employees responsible for handling reports, and any other functions performed by those employees must not create a conflict of interest.
A general or unsecured email inbox accessible to persons who are not authorised to handle whistleblowing reports does not by itself meet the statutory requirements. Email can form part of a compliant internal channel where access, registration, storage and handling are organised in accordance with the Act.
Private-sector employers may outsource the receipt and registration of written reports to an external natural or legal person. This does not transfer responsibility for examining the report and taking the required follow-up measures. Under the current guidance of the Bulgarian Commission for Personal Data Protection, oral reports must be received and registered by employees within the obliged entity itself.
Internal reporting rules and practices must undergo a comprehensive review and analysis at least once every three years and must be updated where necessary.
Reports may be submitted in writing or orally. A written report may also be submitted by email and is registered using the form approved by the Bulgarian Commission for Personal Data Protection together with a unique identification number. An oral report may be submitted by telephone, another voice messaging system or during an in-person meeting arranged at the reporting person's request.
An oral report is documented by the responsible employee using the prescribed form, with the reporting person being given an opportunity to review, correct and approve its contents. With the reporting person's express consent, an oral report may also be documented by a recording stored on a durable medium.
Where a report does not contain the required information, the reporting person must be instructed to remedy the deficiencies within 7 days. If the deficiencies are not remedied within that period, the report and its attachments are returned. Reports falling outside the statutory scope and reports whose contents provide no basis for treating the allegations as plausible are not examined under the statutory procedure.
Proceedings are not opened on anonymous reports. However, since 13 May 2025 there is no longer a general restriction preventing proceedings merely because the alleged breach occurred more than two years earlier. Where the applicable limitation periods for administrative or criminal proceedings have expired, the examination may be terminated under Article 17, without this automatically affecting other applicable procedures or the statutory protection of the reporting person.
What Deadlines Apply After a Report Is Received?The reporting person must receive acknowledgment of the report within 7 days of receipt. Feedback concerning planned or completed follow-up measures and the reasons for those measures must be provided within the statutory period applicable to internal reporting, which may not exceed three months.
The person affected by the allegations is entitled to be heard or to submit written explanations and evidence. The evidence collected must be made available to the affected person with an opportunity to raise objections within 7 days, while preserving the protection of the reporting person's identity.
Each obliged entity must maintain a non-public register of reports. Reports, attachments and related follow-up documentation are retained for 5 years after the examination of the report has been completed, unless criminal, civil, employment or administrative proceedings relating to the report are pending.
By 31 January each year, obliged entities that registered reports during the preceding calendar year must provide the required statistical information to the Bulgarian Commission for Personal Data Protection. The Commission's current instructions state that no statistical submission is required where no reports were registered during the reporting period.
How Is the Reporting Person's Identity Protected?Confidentiality is a core requirement of the whistleblowing framework. The reporting person's identity and any other information from which that identity may be directly or indirectly inferred must be protected against access by unauthorised persons.
Disclosure is permitted under the statutory conditions where it constitutes a necessary and proportionate obligation in connection with an investigation by a competent authority or judicial proceedings, including where necessary to safeguard defence rights. Before disclosure, the reporting person must receive a reasoned written notice unless such notification would jeopardise the investigation or judicial proceedings.
Where a report contains production or trade secrets, that information must not be used or disclosed for purposes extending beyond what is necessary for the relevant follow-up action.
What Protection Applies Against Retaliation?The Act prohibits retaliation where an adverse measure is triggered by a report or public disclosure and causes or may cause harm to a protected person. Depending on the circumstances, retaliation may include dismissal, suspension, demotion, delayed promotion, detrimental changes in employment conditions, reduction of remuneration, disciplinary measures, negative performance assessments, refusal of training and other adverse treatment where the required causal connection with the report exists.
An employer act that constitutes retaliation within the meaning of the Act and is connected with the report is invalid. The protected person may seek restoration of the position existing before the retaliatory action and compensation for pecuniary and non-pecuniary damage. The Act also provides for interim judicial protection against retaliatory measures.
Submitting a report does not prevent an employer from exercising lawful employment or management powers for reasons unrelated to the report. In judicial or administrative proceedings where a protected person claims that an adverse measure constituted retaliation in response to a report, the person who imposed that measure must prove that it was not connected in any way with the report or public disclosure.
What Sanctions Apply for Non-Compliance?Failure to comply with the obligations under Article 13(1) and (2), including the internal-channel requirements and the periodic review obligation, may result in a pecuniary sanction of BGN 5,000 to BGN 20,000 for a legal entity or sole trader. A repeated infringement carries a pecuniary sanction of BGN 10,000 to BGN 30,000. For a natural person, the statutory fine is BGN 1,000 to BGN 5,000, increasing to BGN 5,000 to BGN 10,000 for a repeated infringement.
Following the introduction of the euro in Bulgaria on 1 January 2026, monetary amounts expressed in Bulgarian lev are converted at the official rate of EUR 1 = BGN 1.95583. Accordingly, BGN 5,000 to BGN 20,000 corresponds to EUR 2,556.46 to EUR 10,225.84, while BGN 10,000 to BGN 30,000 corresponds to EUR 5,112.92 to EUR 15,338.76.
Obstructing or attempting to obstruct a report, failing to take the necessary follow-up action within the statutory period or deliberately delaying such action, and failing to provide feedback within the statutory period may result in a fine of BGN 400 to BGN 4,000 for the responsible natural person. Where a legal entity or sole trader fails to take the necessary follow-up measures under Article 17(1)(1) to (3) within the statutory period, the pecuniary sanction ranges from BGN 1,000 to BGN 7,000.
Retaliation against a reporting person or a person connected with them, as well as initiating proceedings solely with the intention of harming the reporting person, may result in a fine of BGN 2,000 to BGN 8,000. Breach of the statutory confidentiality obligations may result in a fine of BGN 400 to BGN 4,000 for a natural person, while a legal entity or sole trader may be subject to a pecuniary sanction of BGN 1,000 to BGN 7,000.
Administrative offence statements are drawn up by officials designated by the Chair of the Bulgarian Commission for Personal Data Protection, while penalty decrees are issued by the Chair of the Commission.
How Can a Business Organise Whistleblowing Compliance?The first step is to determine whether the company qualifies as an obliged entity because of its employee headcount or the regulated nature of its activities. In corporate groups, each Bulgarian company should be assessed independently because membership of the same economic group does not replace the individual company's statutory obligations.
The employer should maintain internal rules clearly governing the submission, receipt, registration, examination and closure of reports, the persons responsible for handling them, conflict-of-interest safeguards, confidentiality requirements, applicable deadlines and the provision of feedback.
The technical reporting arrangements must support secure written and oral reporting and restrict access to authorised persons. The employer must also maintain the non-public register and related documentation and ensure that records are retained for the applicable statutory period.
Clear and easily accessible information on the conditions and procedure for submitting reports must be published on the obliged entity's website and displayed prominently in its offices and workplaces.
Management, HR and compliance teams should be familiar with the confidentiality requirements and the prohibition on retaliation. Internal policies should be reviewed not only formally but also in light of actual reporting practice and any organisational risks identified through the operation of the channel.
Legal Assistance with Whistleblowing SystemsVassilev & Chisuse Law Firm provides legal assistance in connection with the Bulgarian whistleblowing framework and the establishment of internal reporting systems. The assistance may include assessing whether the statutory obligations apply to a company, preparing and updating internal rules and procedures, structuring legally permissible arrangements for external receipt and registration of written reports, and representation in inspections and disputes before the Bulgarian Commission for Personal Data Protection and the courts.
This material is provided for general information purposes only. It does not constitute individual legal advice or a binding recommendation. The specific obligations applicable to an organisation should be determined by reference to its employee headcount, activities, organisational structure and any applicable sector-specific regulatory requirements.