Skip to main content
ServicesDevelopmentCase StudiesProductsAboutBlogCareersContact
+373 69 546 666
ENRORU

Enterprise technology partner for outsourcing, development, and consulting.

Company

  • About
  • Contact
  • Careers

Offerings

  • Services
  • Products
  • Case Studies

Legal

  • Privacy
  • Terms
  • Cookie policy
© 2026 AKDEV. All rights reserved.

GDPR in Moldova: What Website Owners Should Check Before the New Rules Take Effect

A practical checklist for Moldova website owners: forms, cookies, CRM, analytics, access controls, and the 30-day path to readiness.

2026-08-01

A website owner may not run an online store, user accounts, or even a customer database. But if a website has a contact form, web analytics, an online chat, appointment booking, or an advertising pixel, it is already processing personal data.

Moldova’s new Personal Data Protection Law No. 195/2024, applicable from 23 August 2026, brings local requirements closer to the European GDPR approach. This does not mean every business needs an expensive legal project. It does mean that its website, CRM, and lead-handling processes should be put in order in advance.

Start with the real data journey, not just the website form

Personal data is not limited to a name, phone number, and email address. Depending on the context, it can include an IP address, cookie identifier, enquiry history, online-chat content, a call recording, or a combination of information that identifies a person.

Trace every enquiry:

- a visitor submits a website form; - information is sent to email, a CRM, or a messenger; - a sales manager, marketer, contractor, or administrator can access it; - the data enters a backup and may remain there for years.

This journey—not just the wording beside a form—shows a company’s real level of readiness.

Seven common risk areas

1. The privacy policy exists only as a formality

A page copied from another website rarely reflects the actual processing. It should clearly explain who is responsible, what data is collected, why it is collected, on what basis, who receives it, how long it is retained, and how people can exercise their rights.

2. The form collects more data than necessary

If a first contact requires only a name and phone number, do not request job title, date of birth, address, or other fields “just in case.” Data minimisation reduces both risk and operational obligations.

3. One consent tries to cover everything

Requesting a consultation, subscribing to a newsletter, and using non-essential cookies are separate purposes. Visitors should understand exactly what they are agreeing to. A pre-ticked box and a vague “I agree to data processing” statement do not create a transparent process.

4. The cookie banner offers no genuine choice

If analytics or advertising cookies run before a visitor makes a choice, an “Accept” button alone does not solve the issue. Non-essential technologies should be separated from strictly necessary ones, and refusing should be as easy as accepting.

5. Leads go to personal email or shared chats

It is convenient but risky: access, retention periods, and further forwarding cannot be controlled. Route enquiries to a corporate CRM or managed mailbox with role-based permissions instead.

6. Everyone has the same CRM access

A sales manager does not always need to export the entire database, and a contractor should not have access to every customer’s history. Role-based access, least privilege, multi-factor authentication, and activity logs are basic technical hygiene.

7. There is no retention or deletion rule

“We will keep it in case it becomes useful” is not a strategy. Leads, enquiries, chat records, and marketing subscriptions need defined retention periods, deletion rules, and an accountable owner.

The minimum to implement before 23 August 2026

1. Create an inventory. Build a table listing each form or service, data collected, purpose, recipients, retention period, and owner. 2. Make the documentation transparent. Update the privacy policy and form notices. Have the legal content reviewed by a qualified privacy lawyer. 3. Manage cookies properly. Separate necessary, analytics, and marketing cookies; collect consent before non-essential categories run. 4. Secure the lead journey. Remove personal data from unmanaged chats and personal inboxes. Configure corporate CRM and email access. 5. Prepare for user requests. Define a simple internal process for receiving and responding to access, correction, and deletion requests. 6. Review vendors. Analytics, email marketing, CRM, hosting, and development providers may all take part in processing. Record what data is shared and under what terms.

A 30-day action plan

Week 1: audit the website, forms, cookies, analytics, and integrations. Week 2: update the policy, consents, and interface text. Week 3: configure roles, MFA, corporate lead channels, and retention periods. Week 4: test refusal of cookies, form submission, deletion of a test lead, and access controls.

Compliance is more than a footer document

Well-designed data protection improves visitor trust and reduces operational risk: leads do not disappear into personal chats, access is controlled, and marketing relies on clear consents.

AKDEV supports the technical side of readiness: auditing the data journey on a website, configuring forms and cookies, CRM access, and secure integrations. Legal documents and legal assessment should be prepared together with a qualified lawyer.

> This article is for general information only and is not legal advice.

Source: Republic of Moldova Law No. 195/2024 on personal data protection; National Centre for Personal Data Protection — [datepersonale.md](https://datepersonale.md/).