Articles
Moldova's New Data Protection Law: Fines of Up to 2 Million Lei — How Businesses Can Protect Themselves. A Step-by-Step Guide
On August 23, 2026, Law No. 195/2024 on the protection of personal data comes into force in the Republic of Moldova — the national version of the European Regulation (EU) 2016/679, better known as the GDPR. For most companies working with customer, employee, or partner data, this is not a formality but a new set of real legal obligations, backed by fines of up to 2,000,000 lei or 2% of annual turnover. This article breaks down what the law requires in practice: who it applies to, what documents are needed, what rights customers and employees gain, and what happens in the event of a violation.
What GDPR is and why it has arrived in Moldova
The GDPR (General Data Protection Regulation) is the European Union regulation, in force since 2018, that established uniform rules for processing personal data across the EU. Law No. 195/2024 states directly in its preamble that it transposes Regulation (EU) 2016/679 into Moldovan law — in other words, it carries the logic and structure of the European GDPR into national law. This is part of a broader process of harmonizing Moldovan legislation with EU law as part of European integration. The law replaces the previous Law on the Protection of Personal Data No. 133/2011, which was considerably less strict and did not meet current EU standards.
Who the law applies to
The law's scope is significantly broader than one might assume. Under Article 3, it applies:
- to all operators and persons processing personal data who are physically located in the Republic of Moldova — regardless of where the actual data processing takes place;
- to foreign companies without a presence in Moldova, if they offer goods or services to data subjects located in Moldova or monitor their behavior (for example, a foreign online store that ships goods to Moldova and uses tracking tags on its site for Moldovan visitors).
In other words, the law affects not only "traditional" companies registered in Moldova, but any business that works with Moldovan customers online.
It's important to understand the difference between two key roles:
- the operator — the party that determines the purposes and means of data processing (usually the company itself);
- the person acting on the operator's instructions — a contractor that processes data according to the operator's instructions (for example, a CRM provider, a payment processor, an outsourced accounting firm).
What data the law protects
Personal data is any information about an identified or identifiable natural person: name, phone number, address, IP address, an online identifier (such as a cookie), a photograph, location data, and so on.
The law separately identifies special categories of data (Art. 9) — racial or ethnic origin, political opinions, religious beliefs, health data, biometric and genetic data, and information concerning a person's intimate life or sexual orientation. Processing such data is prohibited by default and is permitted only where one of the grounds specifically listed in the law applies — as a rule, the explicit consent of the data subject.
Legal grounds for processing data
A company cannot process personal data "simply because it needs to." Article 6 of the law sets out an exhaustive list of lawful grounds, including:
- the data subject's consent;
- necessity for the performance of a contract with the data subject;
- compliance with a legal obligation of the operator;
- protection of the data subject's vital interests;
- the legitimate interest of the operator or a third party (provided it does not override the data subject's rights).
Processing without at least one of these grounds is a direct violation of the law, regardless of how "harmless" the purpose may seem.
What rights data subjects gain
The law grants customers, employees, and any other data subjects a specific set of rights (Chapter III of the law), which the company is required to be able to fulfill within one month of the request:
- the right of access — to find out what data about them is being processed and for what purpose;
- the right to rectification of inaccurate data;
- the right to erasure ("the right to be forgotten") — in certain cases;
- the right to restriction of processing;
- the right to data portability — to receive their own data in a machine-readable format;
- the right to object to processing, including direct marketing — at any time and "in one click";
- the right not to be subject to decisions based solely on automated processing (profiling) where this produces legal effects.
Refusal or failure to act on such a request is, on its own, grounds for a complaint to the National Center for Personal Data Protection.
What the law requires of businesses in practice
Compliance with the law is not a single document but a system. The minimum practical set that most companies should have in place:
- A record of personal data processing activities (Art. 30) — a list of processes, categories of data, legal grounds, and retention periods.
- A privacy policy that meets the requirements of Articles 12–14: who the operator is, what data is processed and for what purpose, who the recipients are, and what rights the data subject has.
- Legal grounds and consent forms — separate, clearly expressed, and easy to withdraw (Art. 7).
- Technical and organizational security measures (Art. 32) — access controls, encryption, backups.
- An incident-response procedure — an obligation to notify the Center of a data security breach within 72 hours (Art. 33).
- Contracts with data processors (Art. 28) — CRM providers, payment systems, outsourced accounting, hosting, and so on.
- An assessment of whether a DPO needs to be appointed — a data protection officer (Art. 37–39, discussed in more detail below).
Does a company need a DPO (data protection officer)
One of the most common questions from businesses is whether a DPO is mandatory. The law addresses this in Article 37: a DPO is mandatory if the company is a public authority, or if its core activity consists of the systematic, large-scale monitoring of data subjects, or of large-scale processing of special categories of data (health, biometric data, and so on).
For most small and medium-sized businesses, these criteria are not met, and a DPO is not formally required — but this lack of necessity should still be documented in writing, so the company has a justification on hand in the event of an inspection.
If a DPO is needed, the law does not require that this person be a staff employee: a DPO can work under a services agreement, i.e., on an outsourced basis (Art. 37(6)). The key requirement for a DPO is professional knowledge of data protection law and practice (Art. 37(5)) and independence in carrying out their duties (Art. 38(3)).
The National Center for Personal Data Protection
Compliance with the law is overseen by the National Center for Personal Data Protection — an independent public authority (Art. 55–71).
The Center is entitled to:
- carry out investigations and on-site inspections (Art. 60, 81);
- request documents and access to data processing systems;
- issue warnings and orders;
- impose fines (Art. 86–88);
- examine complaints from data subjects (Art. 72).
Separately, the law provides for a prior-consultation mechanism with the Center (Art. 36) — if a data protection impact assessment (DPIA) reveals a high risk that the company cannot mitigate on its own, it is required to consult the Center before beginning the processing in question.
Fines for violating the law
Article 88 of the law provides for two tiers of fines:
- up to 1,000,000 lei or up to 1% of the company's annual turnover (whichever is greater) — for violations of the operator's organizational obligations (for example, inadequate documentation, the absence of a data processing agreement with processors);
- up to 2,000,000 lei or up to 2% of annual turnover — for violations of the core principles of processing, of data subjects' rights, of cross-border data transfer rules, or for failure to comply with the Center's orders.
In determining the amount of a fine, the Center takes into account (Art. 87) the nature and severity of the violation, intent or negligence, measures taken to mitigate harm, the degree of cooperation with the Center, and any prior violations — in other words, a company's good-faith conduct and a documented remediation plan significantly affect the final amount of the sanction.
When the law takes effect and what to do during the transition period
The law takes effect on August 23, 2026 — 24 months after its publication in the Official Gazette (Art. 89(1)). The transitional provisions (Art. 90) set out, among other things, a phased application of fines: in the first year after entry into force, 10% of the assessed fine amount; in the second year, 40%; and from the third year onward, the full amount. This gives businesses a certain amount of time to correct shortcomings even after the law takes effect, but it does not remove the need to prepare in advance — compliance with the other requirements (documentation, data subjects' rights, the processing record) applies in full from day one.
Frequently asked questions
Does the law apply to sole proprietors? Yes, if the sole proprietor processes personal data of customers, employees, or partners as part of a commercial activity — the law makes no exception based on legal form.
Is customer consent required for any and all data processing? No. Consent is only one of six lawful grounds (Art. 6). For example, processing data that is necessary for performing a contract with the customer does not require separate consent — but it does require clearly informing the customer of this.
What happens if a company doesn't manage to prepare by August 23, 2026? Formally, the law takes full effect from that date. The transitional provisions only ease the amount of monetary fines during the first two years; they do not remove the Center's other powers — warnings, orders, and temporary restrictions on data processing.
Is it enough to copy a privacy policy template found online? No. The privacy policy must reflect the actual processes of the specific company — the data collection forms actually used, the actual recipients (including foreign contractors), and the real retention periods. A generic template that hasn't been adapted to the realities of the business can itself become grounds for a complaint to the Center.
BAA Legitimus supports businesses in bringing themselves into compliance with Law No. 195/2024 — from auditing current processes to developing a complete set of documents and providing ongoing legal support on a retainer basis. Contact us to discuss what your company specifically needs.
Useful articles
Moldova's Personal Data Protection Law Is About to Take Effect. We Audited Several Local Companies — Here's What We Found
Moldova is catching up with European data protection standards. On August 23, 2026, Law No. 195/2024 on Personal Data Protection — the local equivalent of GDPR — takes effect, with fines of up to 2,000,000 lei or 2% of annual turnover, whichever is higher (Article 88).
Registering an SRL (LLC) in Moldova: step-by-step guide and timelines in 2026
A limited liability company (Societate cu Răspundere Limitată, SRL) is the most common form of doing business in Moldova: the minimum share capital starts at 1 leu, the standard registration timeline is 24 hours, and the expedited timeline is 4 hours
Buying Property in Moldova: Why a Complete Document File Still Doesn't Mean a Safe Deal
On 14 July 2026, INST, together with the Ministry of Economic Development and Digitalization, presented the "Buyer's Guide" — a state-issued handbook on which documents to request from a seller or developer.
Leave a request