Skip to main content
ServicesDevelopmentCase StudiesProductsAboutBlogCareersContactGDPR Scanner
+373 69 546 666
ENRORU

Enterprise technology partner for outsourcing, development, and consulting.

Company

  • About
  • Contact
  • Careers

Offerings

  • Services
  • Products
  • Case Studies

Legal

  • Privacy
  • Terms
  • Cookie policy
© 2026 AKDEV. All rights reserved.

GDPR and Law 195/2024 in Moldova: a practical checklist for business

Law 195/2024 applies from 23 Aug 2026. Who must comply, a practical checklist, risks, and how AKDEV helps with website audit, policies and processes.

2. Full page body (EN)

Intro (under H1)

Since 23 August 2026, the Republic of Moldova applies Law No. 195/2024 on the protection of personal data. It transposes the logic of the European GDPR (Regulation (EU) 2016/679) into national law and replaces the previous regime under Law No. 133/2011.

For business this is not “another Privacy Policy page in the footer”. It means understanding: what data you process, why, on what legal basis, where you store it, who you share it with, and how you respond to people’s requests. Below is a practical checklist for companies in Moldova (Chișinău and the region) — without panic and without marketing fluff.

This material is informational and is not legal advice. For contested issues (fines, DPO, cross-border transfers, sensitive data) engage a qualified lawyer and check the texts on datepersonale.md and the official law.


What the law requires of business in Moldova

Law No. 195/2024 sets the framework for processing personal data of individuals. Guidance from the National Center for Personal Data Protection (CNPDCP) and official materials reduce the requirements to a clear logic:

  1. Lawfulness, fairness and transparency — every processing activity has a legal basis (Art. 6; for special categories — Arts. 9/10) and clear information for the person.
  2. Purpose limitation — data is collected for specific, legitimate purposes, not “just in case”.
  3. Data minimisation — only what is actually needed.
  4. Accuracy — data is kept up to date; errors are corrected.
  5. Storage limitation — there is a retention period; after that — deletion or anonymisation.
  6. Integrity and confidentiality — technical and organisational security measures (Art. 32).
  7. Accountability — you must be able to demonstrate compliance: processing records, processor contracts, procedures, consent logs, etc.

In practice, for a typical business this means:

  • inventory of customer, employee, candidate and individual-partner data;
  • clear privacy policies and notices next to website forms;
  • management of cookies and trackers (analytics/ads — after consent where required);
  • a record of processing activities (Art. 30);
  • contracts/clauses with processors (IT, cloud, accounting, marketing) — Art. 28;
  • a procedure to answer data-subject rights (access, rectification, erasure, etc. — Arts. 13–22);
  • readiness for incidents (Arts. 33–34);
  • where required — appointment of a Data Protection Officer (DPO) (Arts. 37–39).

The supervisory authority is the National Center for Personal Data Protection (CNPDCP), datepersonale.md.


Who must comply

The law is not limited to IT companies or those with a “large website”.

As a rule, it covers:

  • controllers and processors established in the Republic of Moldova;
  • organisations without a local presence if processing relates to offering goods/services to people in Moldova or to monitoring their behaviour (a model close to GDPR);
  • public bodies and private businesses that process personal data of customers, employees, candidates, subscribers, website visitors, CCTV, and similar.

Simple test: if you have customers, employees or partners who are individuals, you already process personal data.

Exceptions (simplified; details are in the law): purely personal/household processing; separate national security/defence regimes; processing by competent authorities for preventing and combating crime — a separate law (No. 160/2026). Do not assume you “fall outside” 195/2024 merely because you are a small business or have no e-commerce store.

Separately on EU GDPR: if you offer services to people in the EU or monitor their behaviour, European GDPR may apply in addition. That is a parallel risk for export and SaaS companies — assess it with a lawyer.


Practical checklist for business in MD

Based on CNPDCP’s “10 essential steps” and operational practice for websites/CRM. Tick items on facts, not “on paper”.

A. Data and purposes

  • A simple data map exists: customers / HR / marketing / support / CCTV / accounting.
  • For each category it is clear: what data, why, where stored, who has access, who receives it, retention period.
  • “For later” fields have been removed from forms and CRM (minimisation).
  • Each purpose has a legal basis (contract, legal obligation, consent, legitimate interest, etc.) — not “consent to everything”.

B. Transparency and website

  • The current privacy policy reflects actual processing (not a copy from another site).
  • Forms state: who the controller is, what is collected, why, where the lead goes, how to contact you about data.
  • Consents are separated by purpose (enquiry ≠ newsletter ≠ optional cookies).
  • No pre-ticked checkboxes or vague “I agree to processing” wording.

C. Cookies, analytics, pixels

  • Categories are separated: strictly necessary / analytics / marketing (and others as applicable).
  • Optional scripts (Google Analytics, Meta Pixel, Hotjar and similar) do not load before the user’s choice.
  • Refusing optional cookies is as easy as accepting them.
  • A cookie policy exists and users can change their choice later.
  • A method to store proof of consent is documented (where consent is used).

D. Organisational measures

  • A record of processing activities is kept (Art. 30 register) — even as a table.
  • An internal owner for personal-data questions is appointed (even if a formal DPO is not mandatory).
  • Whether a mandatory DPO is required under Arts. 37–39 has been checked (lawyer).
  • Processors (hosting, CRM, email, IT, accounting, marketing) have an Art. 28 contract/clause.
  • Retention periods and deletion/anonymisation procedures are described.

E. People’s rights and incidents

  • A channel for requests (email/form) and an internal playbook exist: who receives, how identity is verified, who replies.
  • Response time to a data-subject request — no more than one month from receipt (per CNPDCP guidance).
  • A short incident procedure exists: contain access → assess scope → decide whom to notify (CNPDCP / data subjects) → document the decision.
  • The team knows the basics: do not send databases “anywhere”, do not share passwords, do not keep clients in personal messengers without control.

F. Technical hygiene (often IT/web)

  • Leads go to a managed corporate inbox or CRM, not employees’ personal email.
  • CRM/admin panels use roles and least privilege, ideally MFA and an action log.
  • Software updates, backups, restricted access to servers and admin panels.
  • Website integrations are reviewed: where forms go, which third-party scripts are loaded, what leaves to foreign cloud.

Quick technical check of the public site: GDPR readiness scanner. Deeper website checklist: blog article for site owners (if the EN blog mirror exists; otherwise fall back to /ru/blog/... until localised).


Fines and risks: no panic, no illusions

CNPDCP stresses that the law is not about fines as an end, but about accountability, transparency and prevention. Finding a breach does not equal an automatic fine: corrective measures are available, including warnings, with individualised sanctions.

At the same time, the liability regime has changed: the Centre has administrative sanction tools. Per CNPDCP’s official clarification, a phased mechanism applies to the final calculated monetary sanction:

Period after entry into force Share of calculated sanction
First year (from 23 Aug 2026) up to 10%
Second year up to 40%
From the third year up to 100%

On maximum amounts. Media and law-firm overviews cite ballpark figures of up to MDL 1,000,000 / up to 1% of annual turnover and up to MDL 2,000,000 / up to 2% for more serious breaches (often referring to Art. 88). CNPDCP has publicly warned against alarmist phrasing such as “fines up to 2 million”. Exact thresholds, formulas and offence lists must be verified with the current law text and a lawyer before publication — the figures above are frequently cited orientation points, not an interpretive guarantee.

Other risks that often cost more than an “abstract fine”:

  • customer complaints and Centre-initiated inspections;
  • orders to stop unlawful processing / delete data;
  • reputational damage and loss of trust;
  • marketing and CRM disruption from chaotic consents;
  • demands from EU counterparties who need predictable data protection;
  • civil claims for damages (mentioned in public overviews of the regime).

For leadership: calmly closing gaps now is cheaper than fixing processes after a complaint or incident.


What AKDEV does

AKDEV is an IT company in Chișinău. We do not replace a lawyer and we do not sell a “GDPR certificate”. We cover the technical and process side of readiness — where compliance most often breaks in practice.

We can help with:

  1. Compliance audit at website and integration level — forms, cookies/trackers, on-site policies, lead path into CRM/email, third-party scripts.
  2. Fast technical diagnostics — website GDPR readiness scanner: public pages, forms, trackers, cookies and related headers.
  3. Process setup — consent mode / cookie banner, category separation, safe lead routing, access roles, MFA, logs.
  4. Documents together with your lawyer — draft privacy and cookie policies matched to the real site architecture (legal finalisation stays with a specialised lawyer).
  5. Related IT services if infrastructure gaps exist: IT support, web development and project stabilisation, cloud, cybersecurity — see services.

What we do not do: issue a legal opinion of full compliance with Law 195/2024; appoint a DPO “for show”; promise “zero fine risk”.

If you only need a website overview — start with the scanner and the readiness article; for systemic work — request an audit.


FAQ

1. Is Law 195/2024 already in force?
Yes. Per CNPDCP communications and official clarifications, from 23 August 2026 personal-data protection is governed by Law No. 195/2024. Law No. 133/2011 is no longer the general applicable framework.

2. Are GDPR and Law 195/2024 the same thing?
The law transposes Regulation (EU) 2016/679 (GDPR) into Moldovan law. For business in MD the baseline local act is 195/2024. European GDPR may apply in addition if you target data subjects in the EU.

3. Do we need a separate cookie policy?
In practice — yes, if the site uses cookies/similar technologies. Minimum: explain categories, purposes, retention and offer a choice for optional ones. Technically, optional scripts must not start before consent (if consent is your basis). Align legal wording with a lawyer.

4. Must every business appoint a DPO?
No. Per CNPDCP materials, appointment is mandatory in certain cases; if not mandatory, appointing an internal owner is still useful. Leave the “are we in scope?” check to a lawyer (Arts. 37–39).

5. How long do we have to answer a person’s data request?
Per CNPDCP practical guidance — no more than one month from receipt. Requests must not be ignored: register and process them under a procedure.

6. Is every mistake automatically fined?
No. CNPDCP states that finding a breach does not mean an automatic fine; corrective measures and warnings are possible, and monetary sanctions are individualised. In the early years a phased share of the calculated amount applies (10% / 40% / 100%).

7. Where should a small company without in-house counsel start?
(1) Data and form map. (2) Update the policy and form notices. (3) Configure cookies/analytics. (4) Remove personal data from personal chats. (5) Appoint an internal owner and keep a simple register. (6) In parallel — legal advice on bases, DPO and processor contracts. Technical website work can start with the scanner.


Soft CTA

Need calm order in website data and processes — without panic and without paperwork for its own sake.

AKDEV will run a technical compliance audit (site, forms, cookies, integrations, access), help set up policies and workflows, and hand legal wording to your lawyer for finalisation.

  • Request an audit: contact · hello@akdev.md · +373 68 733 331
  • Quick site check: GDPR readiness scanner

Request an audit or check your site

Technical compliance audit: site, forms, cookies, integrations, access control. We help with policies and processes together with your lawyer.

Request an auditCheck your site