GDPR Moldova and Law 195/2024: what businesses should check

What Moldova businesses should check under Law 195/2024 and GDPR: data, policies, cookies, processors, people’s rights. A practical checklist and next step.

2026-09-30

From 23 August 2026, the Republic of Moldova applies Law No. 195/2024 on the protection of personal data. For companies in Chisinau and across the country, that is not “one more policy in the footer”, but a clear answer to: which data you process, why, on what legal basis, where you store it, and how you respond to people.

Below is a practical business checklist under GDPR Moldova and Law 195/2024. The angle is organisational: inventory, policies, cookies, processors, data-subject rights and accountability. Website technical readiness (forms, trackers, headers) is covered separately in our article on website readiness for GDPR Moldova.

This material is informational and is not legal advice. Contested issues — fines, appointing a DPO, cross-border transfers, special categories of data — should be checked with a qualified lawyer and with official sources from the National Center for Personal Data Protection (CNPDCP) at datepersonale.md.

1. Understand what you already process

Build a simple record of processing activities. Typical categories for a Moldova business:

  • customers and individual counterparties (CRM, invoices, enquiries);
  • employees and candidates (HR, payroll, CVs);
  • newsletter subscribers and campaign participants;
  • website visitors and account users;
  • CCTV on the premises, if any.

For each category note: purpose, legal basis, retention period, storage location, and who else receives the data (cloud, accounting, marketing, support, bank).

If your CRM, mailbox or website forms hold names, phone numbers, e-mail addresses or other identifiers of natural persons — personal data is already in play. The record does not need to be a legal treatise: a maintained spreadsheet is enough.

2. Policies and copy next to forms

The privacy policy must match reality: which fields you collect, why, where enquiries go, how long you keep them, who else receives the data. If the website says one thing and the CRM and mailing tools do another — that is a risk for both supervision and customer trust.

On forms (contact, order, subscribe, careers) — clear information before submit, not fine print after the fact. Check e-mail campaigns and lead magnets: consent where the legal basis requires it, and a clear way to opt out.

Update the policy when providers, purposes or retention periods change — a “write once, forget” document ages quickly.

3. Cookies, analytics and advertising tags

Separate necessary cookies (site function, security, cart) from marketing / analytics ones (ad pixels, extended analytics, retargeting). If the second group needs consent — do not load trackers before the user’s choice.

Align three layers: banner copy, consent settings, and the actual code on the site. An “accept all” banner without real tracker blocking is a common gap. The same applies to GTM tags, social pixels and third-party chat widgets.

4. Processors and the cloud

Who else holds your data: hosting, CRM, e-mail tools, outsourced IT, accounting, call centre, cloud drives. With processors you need contracts or clauses covering data-protection duties, incidents and sub-processors.

Keep the processor list current. When you switch a provider — update the contract and, if needed, the notice in the policy. For cloud services with servers outside Moldova, assess cross-border transfer separately — that is often a lawyer’s zone.

5. People’s rights and incidents

Decide in advance who answers data-subject requests: access, rectification, erasure, restriction of processing and other rights under the law. Fix the channel (e-mail / form), response deadline and internal flow: how IT and sales pull data from the CRM and mailbox.

Separately describe an incident: breach, wrong mailing, unauthorised access. Who raises the alert, whom you notify internally, when you contact CNPDCP and affected people. Even a small company needs a short “first hours” playbook — not improvisation in a crisis.

6. Accountability: can you show that you comply

A record of processing, consent logs (where applicable), role-based access, backups, basic security measures, contracts with processors — that is what partners from the EU, due diligence or a supervisory check usually ask for. “We sort of have a policy” without artefacts is a weak position.

Start with what you already have: spreadsheets, a folder of contracts, a CRM access log. What matters is not a perfect template, but the ability to explain the process and show evidence.

Typical gaps in Moldova businesses

  • website forms without a clear purpose and retention period;
  • the same client file circulating between departments and vendors with no contract;
  • analytics and ads enabled by default, before consent;
  • no process owner: “ask legal” / “ask IT” — and nobody keeps the record;
  • a policy copied from another site that does not match your CRM and mailings;
  • no channel or deadline to answer a person’s request about their data.

What to do next

  1. Walk the checklist across your systems: website, CRM, e-mail, HR, cloud.
  2. Close the obvious gaps: forms, cookies, access, contracts with key processors.
  3. If you need a structured review of the site, policies and processes — start on the commercial page GDPR and Law 195/2024 in Moldova: full checklist and a light-touch audit format with the AKDEV team in Chisinau.

Website owners who need a technical cut (forms, trackers, front-end policies) can also see website readiness for GDPR Moldova.

FAQ

How does Law 195/2024 differ from “just GDPR”?

Law 195 is Moldova’s national framework, built on the logic of the European GDPR. What matters for business is your real processing in MD and CNPDCP supervision — not only a “European” phrasing in the policy.

Does every company need a DPO?

Not every one. Appointing a data protection officer depends on the scale and nature of processing. If you are unsure — document the processing and consult a lawyer; an IT process review helps gather the facts for that decision.

Where should we start with limited resources?

With a data inventory plus website forms and cookies. Those are fast risk zones with fast impact. Then processors and the procedure for answering people’s requests.

Is this legal advice?

No. This article is a practical guide from the AKDEV IT team. Legal conclusions on fines, DPOs and cross-border transfers belong to a qualified lawyer and official materials at datepersonale.md.

Website readiness for GDPR Moldova