EMPIRICAL STUDY OF INCIDENT RESPONSE PRACTICES FOR PERSONAL DATA BREACHES IN BULGARIAN ORGANIZATIONS
DOI:
https://doi.org/10.68302/std2026.vol3.70Keywords:
data protection, incident management, incident response, personal data breachAbstract
This paper presents an empirical study of incident response practices related to personal data breaches in Bulgarian organizations. The study examines how organizations detect, assess, and manage incidents involving personal data in accordance with personal data protection requirements. The research is based on data collected through a survey conducted among organizations from different economic sectors in Bulgaria. The analysis focuses on the existence of internal incident response procedures, the level of organizational preparedness, and the awareness of obligations arising from personal data breach incidents. The results reveal differences among organizations in terms of organizational measures, staff training, and incident management practices. Based on the analysis, conclusions are drawn regarding the implementation of incident response procedures and the management of personal data breach incidents in an organizational environment.
Supporting Agencies
The present paper was prepared as a result of the scientific research activities conducted within the scientific project “Managing Personal Data Breach Response Processes in the Activities of Organisations in the Republic of Bulgaria,” financed by the Bulgarian National Science Fund under the “Competition for financing fundamental scientific research – 2024,” Contract No. КП-06-Н85/10 (BG-175467353-2024-11-0016-C01), dated 05.12.2024.Downloads
References
[1] European Parliament and Council of the European Union, “Regulation (EU) 2016/679 (General Data Protection Regulation),” Official Journal of the European Union, Apr. 27, 2016. [Online]. Available:
https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679
[2] European Data Protection Board, “Guidelines 9/2022 on personal data breach notification under GDPR, Version 2.0,” Mar. 28, 2023. [Online]. Available:
[3] European Data Protection Board, “Guidelines 01/2021 on examples regarding personal data breach notification, Version 2.0,” Dec. 14, 2021. [Online]. Available:
[4] Commission Nationale de l’Informatique et des Libertés, “Notify a personal data breach,” May 24, 2018. [Online]. Available:
https://www.cnil.fr/fr/services-en-ligne/notifier-une-violation-de-donnees-personnelles
[5] A. Nelson, S. Rekhi, M. Souppaya, and K. Scarfone, “Incident response recommendations and considerations for cybersecurity risk management: A CSF 2.0 community profile,” NIST Special Publication 800-61r3, Apr. 2025. [Online]. Available:
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r3.pdf
[6] European Union Agency for Cybersecurity, “ENISA threat landscape 2020 – data breach,” Oct. 20, 2020. [Online]. Available:
https://www.enisa.europa.eu/sites/default/files/publications/ETL2020%20-%20Data%20Breach%20A4.pdf
[7] I. A. Tøndel, M. B. Line, and M. G. Jaatun, “Information security incident management: Current practice as reported in the literature,” Computers & Security, vol. 45, pp. 42–57, 2014, doi: 10.1016/j.cose.2014.05.003.
[8] Supreme Court of Cassation of the Republic of Bulgaria, “Actions in case of a personal data security breach,” internal procedure, 2023. [Online]. Available:
https://www.vks.bg/dokumneti-zzld/vks-zapoved-2023-808-procedura-narushenie.pdf
[9] European Data Protection Board, “How to notify a data breach to your Data Protection Authority (DPA),” n.d. [Online]. Available:
https://www.edpb.europa.eu/notify-data-breach_en
[10] Data Protection Commission, “Breach Notification,” n.d. [Online]. Available:
https://www.dataprotection.ie/en/organisations/know-your-obligations/breach-notification
[11] Commission Nationale de l’Informatique et des Libertés, “Cybersecurity 2024,” 2024. [Online]. Available:
https://www.cnil.fr/sites/cnil/files/2024-05/cnil_cybersecurity_2024_en.pdf
[12] Agencia Española de Protección de Datos, “Notification of a personal data breach to the Supervisory Authority,” Dec. 11, 2025. [Online]. Available:
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Martin Zahariev, Daniela Pavlova, Panayot Gindev, George Dimitrov, Vyara Savova, Radoslava Makshutova

This work is licensed under a Creative Commons Attribution 4.0 International License.