Court case 8426/2026 – Court Ruling (Bulgaria, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
A Bulgarian court dismissed a claim from a job candidate who argued that requiring a criminal record certificate was unlawful. The court found that the bank's request for this information was justified due to the nature of the job. This case is important as it clarifies that certain job roles may require background checks to ensure safety and compliance.
What happened
The bank required a job candidate to submit a criminal record certificate as part of the hiring process.
Who was affected
A job candidate applying for a senior legal counsel position at a bank in Bulgaria.
What the authority found
The court ruled that the bank's requirement for a criminal record certificate was lawful under existing regulations.
Why this matters
This decision highlights the balance between employer rights to ensure safety and employee privacy. It shows that companies can require background checks for certain positions, but they must ensure compliance with data protection laws.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
The data subject was a candidate for the position of senior legal counsel at the Bulgarian branch of the German commercial bank Flatex Degiro (the controller). As a prerequisite for entering into an employment relationship, the controller required her to submit a criminal record certificate. The data subject brought a damages claim before the Administrative Court of Sofia, seeking BGN 100 in compensation for non-material damage. She argued that the requirement to provide a criminal record certificate was unlawful and that the processing of the personal data contained in it lacked a legal basis. She alleged that this caused her psychological distress, discomfort and stress in the workplace. The controller argued that the requirement was justified by the nature of the position and the access to confidential information associated with it. It maintained that the unauthorised use of such information could lead to fraud and abuse. The Administrative Court dismissed the claim after finding that the processing of the data subject’s criminal record certificate was lawful under Article 6(1)(c) GDPR. It found that the applicable Bulgarian anti-money laundering legislation did not expressly provide for requesting a criminal record certificate at the time but rejected a formalistic approach requiring an explicit legal provision. It considered that the requirement followed from the purpose and overall framework of the anti-money laundering legislation and therefore found the processing lawful under Article 6(1)(c) GDPR. The data subject appealed this decision before the Bulgarian Supreme Administrative Court. The Bulgarian Supreme Administrative Court first noted that an Article 82 GDPR damages claim requires three cumulative conditions: an infringement of the GDPR, damage and a causal link between the infringement and the damage. It also held that the controller bore the burden of proving the lawfulness of the processing pursuant to Article 82(2) GDPR. It found that it had pr
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (0)
No other cases found for Court case 8426/2026 in BG
This is the only recorded case for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. Court case 8426/2026 - Bulgaria (2026). Retrieved from cookiefines.eu
Last updated: