October 2, 2026:


Bulgaria’s November 2025 Electronic Communications Act amendment — celebrated by the country’s legal community as the completion of its Digital Services Act (DSA) obligations — has been found by the European Commission to be doubly deficient: two of its three required enforcement bodies remain operationally unempowered, and the penalty provisions it introduced are non-conforming with EU law.
The Commission on October 1, 2026, issued an additional letter of formal notice to Bulgaria under infringement case INFR(2024)2241, restarting the compliance clock and signaling that Sofia’s partial legislative response has not satisfied Brussels — and may have made one dimension of the problem worse. Bulgaria now has two months to respond; failure to do so may trigger a further reasoned opinion and, ultimately, a referral to the Court of Justice of the European Union (CJEU).
When the Bulgarian National Assembly adopted amendments to the Electronic Communications Act on November 6, 2025, and those amendments entered into force on November 21, 2025, the country’s legal and regulatory community responded with something approaching relief. A Sofia-based law firm published Kinstellar’s November 2025 assessment in December 2025 characterizing Bulgaria as having “finally aligned its national framework with DSA provisions” — the legislative delay that had triggered infringement proceedings, it suggested, was “now behind us.”
That characterization has not held. The Commission’s October 2026 finding is that the law accomplished one of three required tasks — empowering the Communications Regulation Commission (CRC) as Digital Services Coordinator — while leaving the other two incomplete, and introducing a third problem the law did not previously have.
The DSA requires member states to designate Digital Services Coordinators, which are national authorities responsible for enforcing the regulation within their territory. Under Bulgaria’s multi-authority model, that task is distributed across three bodies: the CRC as lead coordinator, the Electronic Media Council (CEM) as supervisor for video-sharing platform providers, and the Personal Data Protection Commission (CPDP) as supervisor of data-processing activities under DSA Article 49 requirements. The November 2025 law formally named all three. The Commission’s position is that formally naming them and operationally empowering them are two different things — and that only the CRC has cleared the second hurdle.
The Commission identified two categories of remaining deficiency in its October 1, 2026 press release.
The first concerns the CEM and CPDP. Despite being named as competent authorities in the November 2025 law, neither body has been operationally empowered under DSA to carry out its assigned DSA duties, according to the Commission. The distinction between designation and empowerment is not a technicality. An authority that exists on paper but cannot receive complaints, conduct investigations, or impose sanctions provides no practical protection to the users it is meant to serve.
The CRC’s Article 55 annual report, submitted under Article 55 of the DSA, confirms the practical reality. The CRC received 30 complaints assessable under Article 53 of the DSA in 2025 — progress from zero in 2024, when the CRC was prevented from fully operating “due to the lack of a law that would impose specific obligations.” The CEM, for its part, received and handled zero DSA complaints in 2025. The CPDP received zero DSA complaints in 2025. Of the CRC’s 30 complaints, zero resulted in a formal investigation being opened. Eleven were forwarded to Ireland’s Coimisiún na Meán; one to Romania’s ANCOM — meaning Bulgarian users whose complaints fell under video-sharing or data-advertising enforcement had their cases handled by foreign regulators.
The second category of deficiency is the one the draft declared complete but failed to notice: the penalty provisions. The Commission’s October 2026 finding explicitly states that Bulgaria “wrongfully implemented the powers to sanction foreseen by the DSA, as the law does not always respect the maximum fine limits, nor does it ensure that all penalties are effective, proportionate, and dissuasive, also in view of the distinct treatment of natural and legal persons, which is not established under the Regulation.” The DSA’s penalty architecture does not draw a distinction between sanctions on natural persons and legal entities of the type Bulgaria’s ECA amendment introduced; the Commission’s reading is that Bulgaria’s framework creates a non-conforming penalty regime even in the one domain — the CRC — where the empowerment challenge was otherwise met.
This matters for a reason beyond procedural scoring. Even if the CEM and CPDP were fully empowered tomorrow, Bulgaria’s sanctions framework would need to be corrected before enforcement actions in those domains could withstand legal challenge.
The timeline of infringement case INFR(2024)2241 stretches nearly two years. The Commission issued the first letter of formal notice to Bulgaria on December 16, 2024, for failing to empower a national DSC and for failure to establish penalty rules. A reasoned opinion sent May 2025 followed on May 7, 2025 — the same day the Commission referred five states referred to CJEU (Czechia, Spain, Cyprus, Poland, and Portugal) for similar failures. Bulgaria avoided referral at that stage, a decision contingent on legislative action.
That legislative action arrived in November 2025. But the Commission’s October 2026 assessment is that it resolved only the CRC empowerment question — while introducing the penalty provision flaw and leaving the CEM and CPDP question open.
The procedural term “additional letter of formal notice” signals an unusual development: the Commission has found new or different deficiencies after the initial notice/reasoned-opinion sequence had begun. Rather than moving the existing case to CJEU referral on the original grounds, the Commission has reset part of the clock to allow Bulgaria to address the newly identified deficiencies, including the penalty provisions, before further escalation.
Under the Article 258 TFEU infringement procedure, the standard infringement sequence is: letter of formal notice → reasoned opinion → CJEU referral. Today’s action is an additional letter of formal notice, which may be followed by a further reasoned opinion before referral becomes possible. If Bulgaria does not respond satisfactorily by approximately December 1, 2026, that escalation may begin.
For platform operators active in Bulgaria, the ongoing enforcement gap creates legal uncertainty about who is actually empowered to receive complaints, investigate violations, and impose penalties in the CPDP and CEM domains. Compliance planning that assumes all three Bulgarian authorities are operational is not currently accurate.
For Bulgarian users, the gap is not abstract. A Bulgarian user of a video-sharing platform who believes that platform has violated its transparency obligations under the DSA — for instance, concerning the algorithmic recommendation system or advertising targeting — has no operationally empowered national body to receive that complaint in the CEM domain. A Bulgarian user concerned about a platform’s use of personal data for targeted advertising in the context of DSA obligations under Articles 51 and 56 has no operationally empowered CPDP to address the national-level complaint. Both categories of complaint are currently handled — if at all — by foreign DSCs or routed to the European Commission directly.
The broader EU enforcement context makes this gap more consequential, not less. The Commission imposed the first DSA fine against X in December 2025: €120 million (approximately $138 million at current rates) against X (formerly Twitter) for breaching transparency obligations, including deceptive design of its paid blue-checkmark verification system and failures in its advertising repository. In May 2026, the Commission imposed Temu’s €200 million DSA fine for systemic risk assessment violations. These cases were handled through the Commission’s direct enforcement track, which covers very large online platforms. The national enforcement track — the one whose gaps in Bulgaria the Commission is addressing today — handles the broader population of intermediary services for which no equivalent EU-level enforcement exists.
The five member states referred to the CJEU in May 2025 — Czechia, Spain, Cyprus, Poland, and Portugal — had taken no adequate compliance action during the first two stages of the infringement procedure. Bulgaria did act: it passed a law and empowered one of its three required bodies. That partial action was sufficient to keep the case short of CJEU referral in May 2025.
The October 2026 finding suggests partial action has run its course as a shield. The Commission’s assessment is that Bulgaria now has an operationally empowered CRC and two unempowered subsidiary bodies, plus a non-conforming penalty framework — a more legally complex situation than simple non-implementation. Whether this complexity will delay or accelerate CJEU referral depends on how Bulgaria responds by December 2026.
There is a narrow irony in the enforcement gap the Commission is documenting. The DSA’s complaint mechanism under Article 53 grants users the right to submit complaints against intermediary service providers to the DSC of the member state where the user is located. Bulgaria’s CRC can receive such complaints; it received 30 in 2025. However, complaints that fall within the CEM’s domain (video-sharing platforms) or the CPDP’s domain (data processing under DSA Articles 51 and 56) cannot be effectively handled by the CRC alone — they must be forwarded to the competent authority, which remains operationally inert. As the 2025 annual report shows, zero such complaints were handled by the CEM or CPDP.
The three regulators signed coordination instruction establishing inter-agency cooperation procedures. The Commission’s position is that signing an instruction setting up cooperation procedures is not the same as having the legal tools, jurisdiction, and operational capacity to exercise enforcement powers independently.
| Detail | Information |
|---|---|
|
Infringement case |
INFR(2024)2241 |
|
Stage |
Additional letter of formal notice |
|
Date of action |
October 1, 2026 |
|
Deadline for Bulgaria |
Two months (approximately December 1, 2026) |
|
Authorities still at issue |
Personal Data Protection Commission (CPDP); Electronic Media Council (CEM) |
|
New finding |
Penalty provisions in November 2025 law also non-conforming |
|
Next escalation risk |
Further reasoned opinion → CJEU referral |
|
Legal basis |
Regulation (EU) 2022/2065 (DSA); Article 258 TFEU |
|
Complaints handled by CEM in 2025 |
Zero |
|
Complaints handled by CPDP in 2025 |
Zero |
|
Formal DSA investigations opened in Bulgaria in 2024–2025 |
Zero |
Designation means a national government formally names an authority as responsible for DSA enforcement. Empowerment means that authority has the legal tools, jurisdiction, investigative powers, and operational infrastructure to actually exercise those responsibilities — including receiving complaints, conducting investigations, and imposing sanctions. Bulgaria’s November 2025 law formally designated the Electronic Media Council and the Personal Data Protection Commission as DSA competent authorities, but the European Commission’s assessment is that neither body has been given the operational powers to function. A named authority that cannot investigate or sanction is, for practical enforcement purposes, the same as no authority at all.
The DSA requires national penalties to be effective, proportionate, and dissuasive — a standard derived from decades of EU case law. Bulgaria’s Electronic Communications Act amendment introduced distinctions between sanctions on natural persons and legal entities that the DSA’s penalty framework does not establish. If that mismatch is not corrected, enforcement actions taken by Bulgarian authorities — even once they are fully empowered — could be vulnerable to legal challenge on the grounds that the penalties imposed are not valid under EU law. This means the penalty provision flaw is not a minor technicality; it is a structural problem that must be resolved before Bulgaria’s DSA enforcement apparatus can function reliably end to end.
Bulgarian users can submit a complaint to the Communications Regulation Commission (CRC) under DSA Article 53. The CRC is operationally empowered and received 30 such complaints in 2025. For complaints that fall under the Electronic Media Council’s domain (video-sharing platform transparency and algorithmic obligations) or the Personal Data Protection Commission’s domain (personal data use in advertising under DSA Articles 51 and 56), the CRC will forward the complaint to the relevant competent authority or, as happened in 2025, to the DSC of another member state where the platform is established — typically Ireland for most major platforms. Users with urgent cross-border complaints may also contact the European Commission directly, which has direct enforcement jurisdiction over very large online platforms such as TikTok, Meta, and X.
Bulgaria is at the “additional letter of formal notice” stage, which means the Commission has found new or altered deficiencies after the initial formal notice/reasoned opinion sequence had already run. The typical next step — if Bulgaria’s response in the two-month window is unsatisfactory — is a further reasoned opinion, which would then set the stage for CJEU referral. Bulgaria’s situation is not identical to the five member states referred in May 2025 (which had taken no meaningful compliance action at all), but the October 2026 finding makes clear that partial compliance is no longer shielding the case from escalation.