# Bulgarian SAC upholds lawfulness of criminal record checks for bank legal counsel role

- Type: Case Law
- Source: Supreme Administrative Court of Bulgaria‎
- Date: 2026-07-30
- Original: https://gdprhub.eu/index.php?title=BAC_(Bulgaria)_-_8426/2026
- Canonical: https://overview.legal/posts/187486
- Topics: Liability, Legitimate Interest, Personal Data, Controllers, Processing, Processors, Representatives, Monitoring, Data Controller

## Summary

Facts — The data subject was a candidate for the position of senior legal counsel at the Bulgarian branch of the German commercial bank Flatex Degiro (the controller). As a prerequisite for entering into an employment relationship, the controller required her to submit a criminal record certificate. The data subject brought a damages claim before the Administrative Court of Sofia, seeking BGN 100 in compensation for non-material damage. She argued that the requirement to provide a criminal record certificate was unlawful and that the processing of the personal data contained in it lacked a legal basis. She alleged that this caused her psychological distress, discomfort and stress in the workplace. The controller argued that the requirement was justified by the nature of the position and the access to confidential information associated with it. It maintained that the unauthorised use of such information could lead to fraud and abuse. The Administrative Court dismissed the claim after finding that the processing of the data subject’s criminal record certificate was lawful under Article 6(1)(c) GDPR. It found that the applicable Bulgarian anti-money laundering legislation did not expressly provide for requesting a criminal record certificate at the time but rejected a formalistic approach requiring an explicit legal provision. It considered that the requirement followed from the purpose and overall framework of the anti-money laundering legislation and therefore found the processing lawful under Article 6(1)(c) GDPR. The data subject appealed this decision before the Bulgarian Supreme Administrative Court. Holding — The Bulgarian Supreme Administrative Court first noted that an Article 82 GDPR damages claim requires three cumulative conditions: an infringement of the GDPR, damage and a causal link between the infringement and the damage. It also held that the controller bore the burden of proving the lawfulness of the processing pursuant to Article 82(2) GDPR. It found that it had provided sufficient evidence that the processing was lawful. The court however did not base the lawfulness of the processing on a legal obligation under Article 6(1)(c) GDPR. The court agreed that requiring and reviewing the criminal record certificate constituted processing of personal data but found that the processing was lawful under Article 6(1)(f) GDPR. It considered that the controller had a legitimate interest in assessing the reliability of a senior legal counsel who would have access to confidential information, including client data, contracts, corporate documents and correspondence with banks and regulatory authorities. The court also considered the risk that such information could be misused for fraud or other abuses. The court found no infringement of the GDPR and upheld the dismissal of the damages claim. It further observed that the emotional distress alleged by the data subject appeared to result not from the processing of her personal data itself, but from the controller’s failure to accept her professional opinion that requesting the criminal record certificate was unlawful.

## Full text

Decision No. 8426 of July 30, 2026, of the Supreme Administrative Court in Administrative Case No. 7494/2025, Third Division The contested decision dismissed the complaint filed by I. V. S. against “Flatex Degiro”— Bulgaria Branch, KCHT, seeking compensation for non-pecuniary damages in the amount of 100 leva for the period from February 9, 21 to January 17, 25, resulting from the unlawful requirement that she provide a criminal record certificate as a prerequisite for entering into an employment relationship. By the same decision, the plaintiff was ordered to pay the defendant’s litigation costs in the amount of 1,000 leva.The appeal alleges that the decision is incorrect and seeks its reversal. The grounds for cassation cited are all those set forth in Article 209(3) of the Administrative Procedure Code—incorrect application of substantive law, material violations of procedural rules, and lack of justification. The appellant requests that, following the reversal of the decision, the claim be granted and the costs of the proceedings be awarded.The respondent—Flatex Degiro, Bulgaria Branch KCHT—contests the cassation appeal on the grounds set forth in its written response dated July 17, 25, which was also upheld by its legal representative during the court hearing. It requests that the appeal be dismissed. It seeks reimbursement of costs.The Supreme Cassation Prosecutor’s Office, through the prosecutor representing the case, expresses the opinion that the cassation appeal is unfounded.The Supreme Administrative Court finds the cassation appeal admissible, as it was filed by a proper party to the case, against whom the judgment subject to appeal is unfavorable, and within the time limit specified in Article 211(1) of the Administrative Procedure Code. As to its merits, the Court finds as follows:The Administrative Court held that it had been seized of a claim for compensation for non-pecuniary damages consisting of negative psychological experiences, discomfort, and stress in the workplace caused by an unlawful act —specifically, the unlawful requirement that the plaintiff provide a criminal record as a prerequisite for entering into an employment relationship with the defendant, and the processing of her personal data contained in the criminal record without legal basis. The administrative court classified the claim as one based on Art. 39 of the Personal Data Protection Act (PDPA) in conjunction with Art. 1 of the Act on the Liability of the State and Municipalities for Damages (LSL).He pointed out that, in this specific case, in order for liability under Article 1 of the Law on Liability for Damages Caused by the State to be established, all elements of the factual basis must be cumulatively present: non-pecuniary damage suffered; an unlawful act by the defendant; and the harm must have resulted from the unlawful act. He also noted that, pursuant to Article 204(4) of the Administrative Procedure Code, a prerequisite for holding the defendant liable is establishing the unlawfulness of the actions taken by the defendant’s employees.The Administrative Court went on to state in its analysis that, for an act to be unlawful, the administrative authority must have taken actions that are not based on the law or on an administrative act. Liability for damages resulting from actions refers to liability for the actual actions of employees of the defendant (the data controller). Having concluded that there is no legal definition of the term “action” in positive law, the court stated that “action” or “inaction” should be understood to mean any act or omission committed by a state body or public official that is not a legal act but rather a physical manifestation thereof—not arbitrary, but rather in compliance with or, respectively, in non-compliance with a specific regulatory provisionThe court found it undisputed that Flatex DEGIRO - Bulgaria KCHT Branch is a branch of a foreign commercial bank registered and licensed under the laws of the Federal Republic of Germany, and that the plaintiff, prior to assuming the position of “senior legal counsel” at the branch effective March 1, 2021, was required to submit a criminal record certificate.The court held that, in view of the legal organizational form?and the defendant’s activities, the measures to prevent the use of the financial system for the purposes of money laundering, as provided for in Article 1 of the Law on Measures Against Money Laundering, are applicable to the defendant. It also held that, in view of the plaintiff’s duties as a senior legal counsel—which, broadly speaking, involved advising the defendant on compliance with banking legislation, including in the area of anti-money laundering measures and the fight against terrorist financing—that is, duties relevant to the control and prevention of money laundering and terrorist financing— she must undoubtedly meet the reliability requirements at the time of her hiring, which includes a clean criminal record, as evidenced by a certificate of criminal record.He pointed out that as of the date the employment contract between the plaintiff and the defendant was concluded—March 1, 2021— Article 101(2)(14) of the Law on the Protection Against Discrimination did not explicitly provide, for the purposes of verifying the reliability of hired employees, the possibility of requiring a criminal record check, since the provision was amended by State Gazette No. 60 of 2023, effective as of July 14, 2023, that is, after the employment contract with the plaintiff was concluded, and it is stipulated that internal rules for the control and prevention of money laundering and terrorist financing must include policies and procedures for verifying professional competence and reliability upon hiring and for the ongoing assessment of otherwhose job duties, in the judgment of the person referred to in Article 4 or the head of the specialized service referred to in Article 106, could be relevant to the control and prevention of money laundering and terrorist financing, as well as rules for the training of such employees; for the purposes of the verification, a certificate may also be required a criminal record or other equivalent document for individuals who are not Bulgarian citizens.The court held that, given the position held by the plaintiff, there were grounds to verify her reliability prior to her appointment, including whether she had a clean criminal record, by means of a criminal record certificate. The court cited Article 1, paragraph 1, item 5 of Regulation No. 4 on the documents required for entering into an employment contract, according to which the following are required for entering into an employment contract: a criminal record certificate, when a law or regulatory act requires verification of a criminal record. The court also noted that a formalistic approach of searching for an explicit legal provision that would provide the opportunity /require the defendant to request a criminal record certificate, provided that it is indisputable that employees hired at the bank’s branch whose duties will be related to and relevant to monitoring and ensuring that the company has implemented regulatory requirements for the prevention of money laundering and terrorist financing, be subject to verification for reliability. This stemmed from the objectives of the Anti-Money Laundering Act (AMLA), which applies to the defendant and sets forth measures to prevent the use of the financial system for money laundering purposes, as well as the organization and oversight of their implementation. The court held that, since the plaintiff was about to be assigned work duties that would require her to have access to information relevant to money laundering, the employer was obligated, pursuant to the AML Act and German law, to require her to provide a criminal record check, for the sole purpose of verifying her reliability. The court relied on the general rationale of the AML Act.The court noted that, in the case at hand, this verification was carried out through the criminal record certificate requested by the plaintiff, and no action was taken that was not in accordance with the law. The court held that the defendant’s action was based on a legal provision and was therefore not unlawful. The court also held that, through the criminal record requested from the plaintiff, the defendant—who is a data controller—undoubtedly processes her personal data, but that processing is for the purpose of concluding an employment contract pursuant to Article 6(1)(c) of Regulation (EU) 2016/679, namely, “processing is necessary for compliance with a legal obligation to which the controller is subject.”It found that the defendant’s actions were not inconsistent with the Opinion of the Commission for Personal Data Protection, Reg. No. PNMD-01-5/January 16, 2020, of the Commission for Personal Data Protection, on which the plaintiff relies. The administrative court’s decisive conclusion is that the actions of the personal data controller—specifically, requiring the plaintiff to provide a criminal record certificate prior to entering into her employment contract as a senior legal counsel—have a legal basis and are therefore not unlawful.Based on this conclusion, the court held that the first prerequisite for granting the claim was not met. It determined that, since the first element of the factual basis for liability under Article 39 of the Personal Data Protection Act in conjunction with Article 1 of the State Liability for Damages Act had not been established, it was pointless to provide reasoning regarding its remaining elements.The Supreme Administrative Court, sitting in its current composition, finds that the appealed decision is correct in its final outcome.This case falls within the scope of the Personal Data Protection Act and Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the “Regulation” for brevity).The claim is based on Art. 39 of the Personal Data Protection Act in conjunction with Art. 82 of the Regulation. Under national law, the claim falls within the jurisdiction of the administrative court. The conditions for granting the claim for compensation are set forth in Article 82 of the Regulation and are as follows: - a violation of the Regulation committed by the controller or processor; harm suffered by the individual whose data was unlawfully processed; and a causal link between such harm and the violation. These conditions are cumulative. Pursuant to Article 82(2) of the Regulation, the burden of proof to establish that the processing of personal data was lawful rests with the defendant—the controller or processor.In this particular case, the administrative court correctly determined that the defendant is a data controller, as it meets the definition set forth in Article 4, paragraph 7 of the Regulation. The Administrative Court’s conclusion that the requirement to provide a criminal record and to review its contents constitutes “processing of personal data” within the meaning of the Regulation is correct.The appellate court also finds correct the administrative court’s conclusion that, in this specific case, the processing of the plaintiff’s personal data contained in her criminal record was lawful, but for reasons different from those set forth by the court of first instance.The defendant has met the burden of proof to establish that the processing was in accordance with the law. Pursuant to Article 288, paragraph 2, of the Treaty on the Functioning of the European Union, a regulation is an act of general application, binding in its entirety and directly applicable in all Member States. Article 6 of the applicable Regulation sets forth the grounds for lawful processing of personal data. One such case is Article 6(1)(f). This provision stipulates that the processing of personal data is lawful when it is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, unless the interests or fundamental rights and freedoms of the data subject, which require the protection of personal data, take precedence over such interests, in particular where the data subject is a child.The rationale for adopting the aforementioned provision is set forth in paragraph 47 of the recitals to the Regulation. It follows from their content that the requirement is to strike a balance between the legitimate interests of the controller in processing personal data and the rights and freedoms of the data subject whose data is being processed. As a criterion for maintaining this balance, the Regulation cites a situation where the data subject would have a legitimate expectation that, upon entering into a relationship with the data controller—under which the data subject becomes the controller’s employee— their personal data would be processed. This is precisely the case at hand. The reasoning also states that the processing of personal data strictly necessary for the purposes of fraud prevention constitutes a legitimate interest.In the answer to the complaint, the defendant, through its legal representative, stated that the decision to obtain the plaintiff’s criminal record was based on the nature of her position and the scope of information to which that position grants her access. It is noted that the information to which employees holding the position of “senior legal counsel” in the Branch’s legal department have access is confidential, and its unauthorized use could lead to a number of instances of fraud and abuse. The defendant’s claims are well-founded, as they are substantiated by the job description for the position of senior legal counsel (pages 110–112 of the first-instance case file) and by the documents proving the plaintiff’s performance of specific tasks under her employment contract with the defendant, submitted by the defendant with a motion dated April 23, 25 (pages 289 et seq. of the case file), as well as by the employee’s duties described in the employment contract dated March 1, 21.The conclusion that must be drawn is that when applying for the position of “senior legal counsel” with an employer whose primary business is the maintenance and operation of an online e-commerce platform, it is reasonable to expect that, given the candidate’s prior handling of sensitive information—such as client data, contracts, corporate documents, and correspondence with banks and regulatory authorities— the employer will require, when hiring a lawyer to assist with its operations, the submission of a criminal record check to ensure the candidate’s reliability and responsibility, as required for the position. The employer’s legitimate interest stems from the need to ensure that, when selecting an employee, there is a basis for concluding that the employee would not misuse the sensitive information provided by partners and clients in the course of the employer’s business operations. In this specific case, the employer’s request for the plaintiff’s criminal record does not constitute a violation of the provisions of the Regulation.With regard to the harm the plaintiff claims to have suffered, it should be noted that, based on the manner in which it is described, the conclusion is drawn that the claimant’s emotional distress did not result from the processing of personal data from her criminal record, but rather from the failure to take her professional opinion on the matter into account.For these reasons, the Supreme Administrative Court finds that the appealed decision is correct in its final outcome and should therefore be upheld.Regarding costs:In view of the outcome of the case, the appellant is not entitled to reimbursement of costs.The respondent in the cassation proceedings is entitled to reimbursement of costs, which he timely claimed and substantiated with the documents on pages 112–114 of the cassation case file.The appellant’s objection regarding the excessive nature of the respondent’s costs in the cassation proceedings is well-founded, given the scope and complexity of the legal work performed in defense of the respondent in these proceedings, as well as the amount of the claim. An objective benchmark for the reasonableness of attorneys’ fees at this amount of the claim is the Regulation on Fees for Legal Services—Article 7, paragraph 2, item 1 of the Regulation. Assessed in this manner, the amount of the attorney’s fee for the cassation proceedings should be the same as for the first-instance proceedings—1,000 leva or 511.29 euros.Guided by the foregoing considerations and pursuant to Article 221(2) of the Administrative Procedure Code, the Supreme Administrative CourtRESOLVED:UPHOLDS Decision No. 18795 of June 2, 2025, rendered in Administrative Case No. 584/25 by the Sofia City Administrative Court.I. V. S. is ORDERED to pay Flatex DEGIRO—Bulgaria Branch KCHT the legal fees incurred before the court of cassation in the amount of 511.29 euros.The decision is final.

## Cited law provisions (9)

### GDPR — gdpr-art-6-par-1-pnt-c-en

processing is necessary for compliance with a legal obligation to which the controller is subject;

### GDPR — gdpr-art-6-par-1-pnt-f-en

processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

### GDPR — gdpr-art-82-par-2-en

Any controller involved in processing shall be liable for the damage caused by processing which infringes this Regulation. A processor shall be liable for the damage caused by processing only where it has not complied with obligations of this Regulation specifically directed to processors or where it has acted outside or contrary to lawful instructions of the controller.

### GDPR — gdpr-art-1-en

Subject-matter and objectives

### GDPR — gdpr-art-4-en

For the purposes of this Regulation:

### GDPR — gdpr-art-6-en

Lawfulness of processing

### GDPR — gdpr-art-7-en

Conditions for consent

### GDPR — gdpr-art-39-en

Tasks of the data protection officer

### GDPR — gdpr-art-82-en

Right to compensation and liability

---
Generated by overview.legal · https://overview.legal/posts/187486 · 2026-08-22
