Policy on Transparency and Personal Data Protection
Pursuant to the regulatory requirements, the Bulgarian National Audit Office is obliged to inform you what to expect when we process your personal data.
Who is the controller of processed personal data?
The National Audit Office of the Republic of Bulgaria is the Supreme Audit Institution tasked to control the reliability and authenticity of the financial statements of budget organizations and the lawful, effective, efficient and economical management of public resources and activities. Within the meaning of the Regulation on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), the National Audit Office is the controller of personal data, because:
“Personal data”
means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, psychological, genetic, mental, economic, cultural or social identity of that natural person;
“Processing”
means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
“Controller”
means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by the Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
What type of personal data do we process?
In enforcing our statutory role, we need to collect, use, store and transfer various personal data, which we have grouped as follows:
In the course of the audits, special categories of personal data may need to be processed as part of administrative-penal proceedings or following other regulatory obligations, as set in Art. 9 of the General Data Protection Regulation. This may happen in rare cases, such as:
How do we process your personal data?
We process your personal data:
To whom do we disclose your personal data?
We disclose your personal data to:
We require all third parties to comply with the security rules concerning your personal data, to process them in accordance with the law and only pursuant to the agreed conditions and purposes.
How do we ensure data security?
We have introduced appropriate measures for the organizational and technical protection of your personal data, in order to prevent the accidental loss, use or access to your personal data from unlawful use or disclosure. Moreover, we limit the access to your personal data for other employees, in strict compliance with the “need to know” principle. They process your personal data only subject to a legitimate basis and in compliance with the obligation of confidentiality.
We have adopted a procedure to deal with breaches of your personal data. In case of risk to your rights and freedoms, you and the competent supervisory authority (the Commission for Personal Data Protection) will be duly informed.
How long do we store your personal data?
We process your personal data for as long as it is necessary to fulfil the purposes for which they were collected, including for legal, accounting or reporting purposes.
In determining the appropriate period for storage of your personal data, we take into account:
What are your rights?
In accordance with the provisions of the General Data Protection Regulation and the Personal Data Protection Act, you have:
If you wish to exercise any of these rights, please contact us at the following address:
37, Ekzarh Yosif St., Sofia
Office of the President:
phone number: +359 2 980 36 90
е-mail: president@bulnao.government.bg
Data Protection Officer:
phone number: +359 2 935 74 08
e-mail: g.nikolova@bulnao.government.bg
The applications to exercise individual rights are submitted in person or by an expressly authorized person who has a certified authorization. The applications could also be submitted electronically following the procedure on completion and submission of electronic documents as laid down by the legislation in force.
The application must contain:
а) name, address and other data required for the identification of the natural person;
b) description of the request;
c) preferred form of communication and actions within the meaning of Art. 15 – 22 of Regulation (EU) 2016/679;
d) signature, date of submission of the application and address for correspondence;
e) if the application is submitted by an authorized person, a copy of the certified authorization must be attached.
You will not be charged any fee for access to your personal data (or for the exercise of any of your rights). If your request is manifestly unfounded, repetitive or excessive, it may be denied under these circumstances.
We may ask you for specific information required to confirm your identity and to guarantee your right of access to personal data. This is a security measure which guarantees that personal data is not disclosed to a person who does not have the right to receive them.
We try to respond to all legitimate requests within one month. In certain cases, more than one month is required, if your request is particularly complex or you have submitted several requests. When an extended period is objectively necessary – in order to collect all necessary data or in case of serious impediment to our work, this period could be extended, but for a maximum of 60 days. In this case you will be duly notified.
You have the right to submit your complaint to the competent supervisory authority at any time:
Commission for Personal Data Protection of the Republic of Bulgaria:
Address: 2, Prof. Tsvetan Lazarov Blvd., Sofia 1592
email: kzld@cpdp.bg
We would wish, however, to examine the possibility of satisfying your request before you approach the Commission for Personal Data Protection, so please, contact us first.
The Policy on Transparency and Personal Data Protection was adopted in 2019.