Articles
Moldova's Personal Data Protection Law Is About to Take Effect. We Audited Several Local Companies — Here's What We Found
Moldova is catching up with European data protection standards. On August 23, 2026, Law No. 195/2024 on Personal Data Protection — the local equivalent of GDPR — takes effect, with fines of up to 2,000,000 lei or 2% of annual turnover, whichever is higher (Article 88).
Over the past few months we've audited a range of small and mid-sized businesses — services, retail, e-commerce. We didn't just review paperwork; we went on-site and talked to the people who actually handle customer data day to day: operators, managers, IT staff.
The picture turned out to be almost identical from one company to the next. Here's what we kept finding (details changed so no specific company can be identified).
1. Customer data is leaving Moldova, and nobody planned it that way. The usual setup: a foreign CRM hosted on servers outside the European Economic Area, in a country Moldova's Data Protection Center hasn't approved as offering adequate protection. Legally, that means every single order sends customer data somewhere the law (Chapter V) doesn't allow without extra safeguards. Owners rarely see it as "exporting data abroad" — to them, it's just the software they've always used.
2. Client schedules live on employees' personal phones. Visit addresses and appointment details sit in managers' personal Google Calendars, not in any company system. The business can't control that data or guarantee it gets deleted when someone leaves — and the same goes for sharing client addresses over personal Viber or Telegram instead of one official channel.
3. The privacy policy was written for the old law — or, often, generated quickly with ChatGPT. It exists on paper mainly because the payment-processing bank asked for it. It doesn't reflect what data is actually being collected, doesn't account for the new law, and doesn't match the real forms on the site.
4. Every form on the website collects data, but none of them ask for consent. Order forms, callback requests, job applications, newsletter sign-ups — each has its own fields, but not one includes a consent checkbox or a link to a current policy. Meanwhile the same sites run Google Ads and analytics with no cookie banner, meaning they're collecting visitor identifiers with no legal basis.
5. Not a single supplier contract covers data processing. Payment processors, outsourced accounting, IT hosting, loyalty partners — these are often long-standing relationships with no agreement addressing personal data at all, as Article 28 requires. The reasoning is always the same: "we've worked with them for years."
The numbers tell the story
A typical audit of a small or mid-sized business turns up 6–9 serious gaps, each one individually fineable under the law. None of it comes from bad intent — it's just processes built up over years on an "if it works, don't touch it" basis, with no legal review along the way.
What to do about it
The good news: most of this can be fixed without pausing the business. It's not about starting over — it's about sequencing: 2-3 items that carry the real legal risk get fixed first, the rest can move in parallel over a month, and supplier contracts get renegotiated as those conversations happen.
Time is running short. From August 23, 2026, the Data Protection Center will have direct grounds to inspect and fine — and "we didn't know" won't hold up as a defense.
BAA Legitimus helps businesses get compliant with Law No. 195/2024 — from a quick audit to a full document package and ongoing legal support. Want to know how many gaps an audit would find at your company? Get in touch.
Useful articles
Registering an SRL (LLC) in Moldova: step-by-step guide and timelines in 2026
A limited liability company (Societate cu Răspundere Limitată, SRL) is the most common form of doing business in Moldova: the minimum share capital starts at 1 leu, the standard registration timeline is 24 hours, and the expedited timeline is 4 hours
Buying Property in Moldova: Why a Complete Document File Still Doesn't Mean a Safe Deal
On 14 July 2026, INST, together with the Ministry of Economic Development and Digitalization, presented the "Buyer's Guide" — a state-issued handbook on which documents to request from a seller or developer.
Moldova's New Personal Data Protection Law: What Businesses Need to Do Before End of Summer
In late August 2026, Moldova's Law No. 195/2024 on the protection of personal data comes into force — the first major overhaul of data-handling rules in 15 years, bringing the country closer to the European GDPR standard.
Leave a request