Непознаването на закона не е извинение.
(Латинска сентенция)

Article 319e of the Criminal Code – Criminal Liability for Violations of Electronic Trust Services

What does Article 319e of the Criminal Code regulate?

Article 319e of the Bulgarian Criminal Code focuses on a specific field of cybersecurity — the provision of information services, particularly those related to electronic signatures, electronic identification, and trust services.

The crime consists of violating Article 6, paragraph 2, item 5 of the Electronic Document and Electronic Trust Services Act (EDEUTSA), with punishable conduct including failure to comply with the requirements for data protection and security of the electronic signature.

This is a type of “delicate cybercrime”, where the violation may not be obvious to the ordinary user but has the potential to cause serious consequences for the integrity of the legal system — especially when it concerns electronic identification or digital transactions.

What does Article 6, paragraph 2, item 5 of the EDEUTSA say?

According to this provision, trust service providers are obliged to implement technical and organizational measures to protect electronic signatures, electronic seals, and trust service credentials.

This includes preventing:

  • unauthorized access to certificates;

  • the use of fake identities;

  • compromise of cryptographic keys;

  • security weaknesses in the infrastructure.

Violating this rule, when it creates a risk for the legal validity of electronic services or for citizens’ data, constitutes a crime under Article 319e CC.

Penalties

The penalty under Article 319e is:

  • imprisonment of up to 6 years, and

  • a fine of up to 5,000 BGN,
    unless the act is subject to a heavier penalty under another article of the Criminal Code (e.g. fraud, personal data misuse, or document-related crimes).

What crimes does it cover?

Typical examples of violations under Article 319e include:

  • A trust service provider does not properly encrypt clients’ private keys, thus exposing them to theft and misuse.

  • Issuing electronic signatures without adequate identity verification, allowing the creation of false authorizations.

  • A compromised trust service system where third parties gain access to certificates and sign documents on behalf of others.

Examples from practice

Although case law under Article 319e is limited, in recent years there has been increasing prosecutorial interest, especially after the introduction of mass electronic administrative services.

For example, in 2023 an investigation was conducted against a trust service provider whose system was compromised, allowing electronic signatures to be issued without valid identification. Although no direct damages were initially caused, the prosecution acted due to the serious risk to the public interest.

Conclusion

Article 319e CC serves as a safeguard against abuse in one of the most sensitive areas of the digital age — electronic identity and authentication. It sets a high standard of responsibility for trust service providers, who not only manage data but guarantee the legal effect of actions performed in electronic form.

If you have been affected by misuse of an electronic signature, an unauthorized signed document, or lack of protection of your personal electronic data, do not hesitate to contact a criminal law attorney to defend your rights and file a complaint with the competent authorities.