
Dimitrov, Petrov & Co. Law Firm
INPLP member firm · Sofia, Bulgaria
Dimitrov, Petrov & Co. (DPC) is a full-service business law firm, pioneer in the dynamic field of technology law and data protection in Bulgaria, as well as in corporate and commercial law, employment, real estate, competition, banking & finance, dispute resolution, tax and many others. DPC’s data protection practice group is widely acknowledged for its broad practical experience an in-depth knowledge of the national and EU law requirements, and the lawyers are internationally recognized for the outstanding quality of the services provided to clients. The law firm’s international client base ranges from start-up companies to major blue-chip multinational and domestic companies, state authorities, municipalities, public bodies, and NGOs. Prof. Dr. George Dimitrov is a founding partner of Dimitrov, Petrov & Co. Law Firm and a chairman of its Supervisory Board. He is the first in Bulgaria to receive the academic title “Professor of Law and Information Technologies” and is a lecturer of ICT Law at all premier universities and educational institutions in Bulgaria and the Bulgarian Academy of Sciences. He holds a PhD degree from the Katholieke Universiteit Leuven, Belgium and has specialized at the Academy of American and International Law, Dallas, TX, USA. With more than 20 years professional experience, he is consistently praised as one of the world’s leading ICT and privacy & data protection law practitioners by different globally recognized legal editions and directories. For many years George has been advising blue-chip technology companies, government institutions, and key policy-making NGOs. He has been the leading expert and head of numerous working groups that have drafted the contemporary Bulgarian ICT legislation, inter alia, the Electronic Commerce Act, the Electronic Governance Act, the Electronic Communications Act, the amendments of the E-documents and E-signatures Act and the secondary legislation on its implementation, the cyber-crimes section of the Criminal Code, and many other acts of primary and secondary legislation. Desislava Krusteva is a partner at Dimitrov, Petrov & Co. Law Firm, currently heading its Technology & Data Protection Practice Group. For more than 15 years Desislava has been advising large multinational and domestic companies on complex information management and privacy issues, advanced technological and cross-border projects from consultations on the very development of their business model to their launch and day-to-day implementation. She covers a wide range of legal matters in the area of ICT law, including data protection, information security and other special regimes of information, e-Commerce, e-Payments and e-Financial services, e-Healthcare, e-Government, e-Identification, e-Signatures and telecommunications. Desislava has actively participated in drafting numerous legislative and secondary normative acts on e-governance and re-use of public sector information. She is an author of numerous reports and publications and legal expert in many projects on the implementation of the European legal framework. Desislava is a regular speaker at conferences and trainings and lectures at the most prestigious Bulgarian universities. She is also a Certified Information Privacy Professional Europe (CIPP/E) and a Certified Information Privacy Manager (CIPM) by IAPP and currently a co-chair of the Bulgarian KnowledgeNet Chapter of IAPP.
Representatives

Desislava Krusteva
partner

George Dimotrov
member
Contact
Publications
- Using Face Recognition Systems in Commercial PremisesBulgarian Data Protection Authority recently published a statement on the admissibility of using videosurveillance systems with face recognission functionalities in big commercial premises as shoping malls and hypermarkets.2 December 2025
- Further processing videosurveillance recordings for assessing performance of employees is inadmissible.Bulgarian Personal Data Protection Commission has issued an opinion on the admissibility of processing video surveillance records with sound for the purposes of assessing the personal performance of the employees and for determining their bonuses. The opinion of the commission is that such further processing of the personal data does not comply with the requirements of Art. 6, para. 4 of GDPR and therefore is inadmissible.20 March 2024
- Bulgarian DPA Introduce Deep Audits as a Standard Practice in Cases of Data BreachesBulgarian DPA is currently applying on a regular basis a new procedure in cases of data breach notifications which includes complex questionnaires covering all the data processing activities of the data controller and extensive requests for provision of documents and information within short deadlines.12 July 2023
- Bulgarian DPA on the Admissibility of Ongoing Access to Municipality’s Video SurveillanceBulgarian DPA issued an opinion on the questions from a Bulgarian City Municipality regarding requested ongoing access from the police department to the video recordings of the Municipality video surveillance system.24 January 2023
- Bulgarian PDPC adopted a list of processing operations requiring prior consultationBulgarian PDPC has adopted a list of processing operations that require prior consultation which is addressed to the authorities subject to Directive (EU) 2016/680. This list does not directly applies to the accitvities of the controllers and processors subject to GDPR, but provides an indication for operations which rise high risks and require DPIA and eventual prior consultation under GDPR as well.13 September 2022
- Bulgarian Supreme Administrative Court with Decision on Processing Data for Journalistic PurposesBulgarian Supreme Administrative Court issued a decision setting out criteria relevant for assessing the balance between the right to freedom of expression and information and the right to the protection of personal data.11 March 2022
- Request for Preliminary Rulings on Data Controllers Liability in Case of a Data BreachThe Bulgarian Supreme Administrative Court has referred several questions to the CJEU regarding preliminary rulings on the liability of the controllers in case of a data breach. The request is related to one specific administrative proceeding but affects all pending claims before the court against the Bulgarian National Revenue Agency with regards to the massive data breach at the Agency in 2019. The motive for requesting such rulings is the fact that so far the legislation has been interpreted and applied by the lower instances in the country inconsistently in all elements regarding the controller’s liability.11 August 2021
- When Can Information On Criminal Records Be Requested By EmployersA recent Opinion of the Bulgarian data protection authority and certain legislative changes lead to the conclusion that in Bulgaria information on criminal convictions and offences of present or future employees can be requested by employers in very limited number of cases.23 March 2021
- Can data protection rules affect the assignment of receivables in Bulgaria?For many years, a common practice in Bulgaria is debtors to submit complains to the Bulgarian DPA for unlawful processing of their personal data due to performed assignement of their debts to a new creditor (cession). As a result a non-consistent practice has been formed of the DPA through the years where quite often the consent of the deptor for the processing of his/her personal data is sought as a condition for the assignement of the debt/ the receivables to a new creditor. However, after GDPR Bulgarian DPA undertaken certain changes in their interpetation on whether consent is required for the processing of personal data of a debtor when a creditor assign/ transfer a debt to a new creditor (e.g. in case of cession).15 February 2021
- The Bulgarian Data Protection Authority Issued Opinions on the Processing of Personal Data by Employers During the COVID-19 PandemicIn its Newsletter 4 (85) of July 2020 the Bulgarian Commission for Personal Data Protection (CPDP) released two opinions that provide clarity on personal data processing by employees in the context of the COVID-19 pandemic.12 September 2020
Join the network
Applications from qualified privacy practices are reviewed individually by the INPLP board.