Law 195/2024 applies from 23 Aug 2026. Who must comply, a practical checklist, risks, and how AKDEV helps with website audit, policies and processes.
Since 23 August 2026, the Republic of Moldova applies Law No. 195/2024 on the protection of personal data. It transposes the logic of the European GDPR (Regulation (EU) 2016/679) into national law and replaces the previous regime under Law No. 133/2011.
For business this is not “another Privacy Policy page in the footer”. It means understanding: what data you process, why, on what legal basis, where you store it, who you share it with, and how you respond to people’s requests. Below is a practical checklist for companies in Moldova (Chișinău and the region) — without panic and without marketing fluff.
This material is informational and is not legal advice. For contested issues (fines, DPO, cross-border transfers, sensitive data) engage a qualified lawyer and check the texts on datepersonale.md and the official law.
Law No. 195/2024 sets the framework for processing personal data of individuals. Guidance from the National Center for Personal Data Protection (CNPDCP) and official materials reduce the requirements to a clear logic:
In practice, for a typical business this means:
The supervisory authority is the National Center for Personal Data Protection (CNPDCP), datepersonale.md.
The law is not limited to IT companies or those with a “large website”.
As a rule, it covers:
Simple test: if you have customers, employees or partners who are individuals, you already process personal data.
Exceptions (simplified; details are in the law): purely personal/household processing; separate national security/defence regimes; processing by competent authorities for preventing and combating crime — a separate law (No. 160/2026). Do not assume you “fall outside” 195/2024 merely because you are a small business or have no e-commerce store.
Separately on EU GDPR: if you offer services to people in the EU or monitor their behaviour, European GDPR may apply in addition. That is a parallel risk for export and SaaS companies — assess it with a lawyer.
Based on CNPDCP’s “10 essential steps” and operational practice for websites/CRM. Tick items on facts, not “on paper”.
Quick technical check of the public site: GDPR readiness scanner. Deeper website checklist: blog article for site owners (if the EN blog mirror exists; otherwise fall back to /ru/blog/... until localised).
CNPDCP stresses that the law is not about fines as an end, but about accountability, transparency and prevention. Finding a breach does not equal an automatic fine: corrective measures are available, including warnings, with individualised sanctions.
At the same time, the liability regime has changed: the Centre has administrative sanction tools. Per CNPDCP’s official clarification, a phased mechanism applies to the final calculated monetary sanction:
| Period after entry into force | Share of calculated sanction |
|---|---|
| First year (from 23 Aug 2026) | up to 10% |
| Second year | up to 40% |
| From the third year | up to 100% |
On maximum amounts. Media and law-firm overviews cite ballpark figures of up to MDL 1,000,000 / up to 1% of annual turnover and up to MDL 2,000,000 / up to 2% for more serious breaches (often referring to Art. 88). CNPDCP has publicly warned against alarmist phrasing such as “fines up to 2 million”. Exact thresholds, formulas and offence lists must be verified with the current law text and a lawyer before publication — the figures above are frequently cited orientation points, not an interpretive guarantee.
Other risks that often cost more than an “abstract fine”:
For leadership: calmly closing gaps now is cheaper than fixing processes after a complaint or incident.
AKDEV is an IT company in Chișinău. We do not replace a lawyer and we do not sell a “GDPR certificate”. We cover the technical and process side of readiness — where compliance most often breaks in practice.
We can help with:
What we do not do: issue a legal opinion of full compliance with Law 195/2024; appoint a DPO “for show”; promise “zero fine risk”.
If you only need a website overview — start with the scanner and the readiness article; for systemic work — request an audit.
1. Is Law 195/2024 already in force?
Yes. Per CNPDCP communications and official clarifications, from 23 August 2026 personal-data protection is governed by Law No. 195/2024. Law No. 133/2011 is no longer the general applicable framework.
2. Are GDPR and Law 195/2024 the same thing?
The law transposes Regulation (EU) 2016/679 (GDPR) into Moldovan law. For business in MD the baseline local act is 195/2024. European GDPR may apply in addition if you target data subjects in the EU.
3. Do we need a separate cookie policy?
In practice — yes, if the site uses cookies/similar technologies. Minimum: explain categories, purposes, retention and offer a choice for optional ones. Technically, optional scripts must not start before consent (if consent is your basis). Align legal wording with a lawyer.
4. Must every business appoint a DPO?
No. Per CNPDCP materials, appointment is mandatory in certain cases; if not mandatory, appointing an internal owner is still useful. Leave the “are we in scope?” check to a lawyer (Arts. 37–39).
5. How long do we have to answer a person’s data request?
Per CNPDCP practical guidance — no more than one month from receipt. Requests must not be ignored: register and process them under a procedure.
6. Is every mistake automatically fined?
No. CNPDCP states that finding a breach does not mean an automatic fine; corrective measures and warnings are possible, and monetary sanctions are individualised. In the early years a phased share of the calculated amount applies (10% / 40% / 100%).
7. Where should a small company without in-house counsel start?
(1) Data and form map. (2) Update the policy and form notices. (3) Configure cookies/analytics. (4) Remove personal data from personal chats. (5) Appoint an internal owner and keep a simple register. (6) In parallel — legal advice on bases, DPO and processor contracts. Technical website work can start with the scanner.
Need calm order in website data and processes — without panic and without paperwork for its own sake.
AKDEV will run a technical compliance audit (site, forms, cookies, integrations, access), help set up policies and workflows, and hand legal wording to your lawyer for finalisation.
Technical compliance audit: site, forms, cookies, integrations, access control. We help with policies and processes together with your lawyer.