
TL;DR
- Law No. 195/2024 entered into force on August 23, 2026, replacing the 2011 framework and transposing the EU GDPR into Moldovan law
- Depending on the infringement, fines reach up to MDL 1,000,000 or 1% of annual turnover, or MDL 2,000,000 or 2% for more serious violations, with a phased rollout (10% in year one, 40% in year two, full from year three)
- Controllers must assess high-risk processing and report qualifying breaches without undue delay and, where feasible, within 72 hours; processors must notify controllers without undue delay
- The CNPDCP (National Centre for Personal Data Protection) can conduct audits and inspections without a prior complaint
- If you process personal data through a website, CRM, email list, or office cameras, check how the law applies to those activities
Eight days ago, Moldova's Law No. 195/2024 on the Protection of Personal Data entered into force. It replaces Law No. 133/2011 and transposes the EU's GDPR into Moldovan law.
If your business collects customer names, stores employee records, runs a newsletter, or uses any kind of tracking on your website, the law applies to those processing activities, subject to the exceptions in the law, and carries real financial consequences.
What actually changed
The old law, from 2011, was based on the former EU Data Protection Directive. The new framework changes the duties of controllers and processors in several practical ways.
Accountability is now the default. You do not just have to follow the rules. You have to prove you follow them. That means documented policies, internal records, and evidence that your data handling matches what you say in your privacy notice. The CNPDCP can ask for this documentation at any time.
Data subject rights are stronger and faster. Individuals can now request access to their data, ask for corrections, demand deletion, restrict processing, and request portable copies. You have 30 days to respond to a request. That deadline is not optional.
Breach notification is mandatory when a personal data breach is likely to pose a risk to people's rights and freedoms. You must notify the CNPDCP without undue delay and, where feasible, within 72 hours of becoming aware of it. If the risk is high, affected individuals must also be informed without undue delay. A lost laptop containing personal data or a misdirected email may create a breach. A weak password is a security risk, but it becomes a personal data breach only if it leads to an incident covered by the law.
DPIA is required for high-risk processing. Systematic and extensive automated evaluation, large-scale processing of special categories of data (including health, political opinions, or biometric data), and large-scale monitoring of publicly accessible areas are the examples named in the law. If the assessment shows a high risk that cannot be mitigated, you must consult the CNPDCP before processing begins.
DPO appointment is mandatory in certain cases. Public authorities, organizations doing large-scale systematic monitoring, and those processing special categories of data or criminal-conviction data at scale must appoint a Data Protection Officer. The DPO's contact details must be published and communicated to the CNPDCP.
International data transfers are regulated. If you use AWS, Google Cloud, Mailchimp, HubSpot, or any service that processes data outside Moldova, check which transfer mechanism applies. Depending on the destination and circumstances, that may be an adequacy decision, appropriate safeguards, or standard data-protection clauses. Standard Contractual Clauses are not automatically required for every provider.
The fines are real, but you have time
Article 88 sets two fine levels. For certain infringements, the fine can reach MDL 1,000,000 or, for an undertaking, 1% of the total turnover in the year before sanctioning, whichever is higher. For breaches involving core processing principles, data-subject rights, international transfers, or failure to follow corrective measures, the ceiling is MDL 2,000,000 or 2% of that turnover, whichever is higher.
There is a transitional application of the final sanction amount. From August 23, 2026 through August 22, 2027, 10% applies. From August 23, 2027 through August 22, 2028, 40% applies. From August 23, 2028, the full amount applies.
The CNPDCP says the new framework should be understood through accountability, prevention, and clear rules for how organizations collect, use, store, and protect data, rather than through fines alone.
What a data retention audit looks like
Law No. 195/2024 does not set one universal retention period for every type of business data. It requires personal data to be kept no longer than necessary for the purpose of processing, and requires notices to state the storage period or the criteria used to determine it. Your retention and deletion rules should be documented so you can explain them during a review.
Processing records have a limited exception. An enterprise or organization with fewer than 250 employees may not have to keep the Article 30 record unless the processing is likely to create a risk, is not occasional, or involves special categories of data or criminal-conviction and offence data.
Here is what that means in practice:
Map your data. What personal data do you collect? Customer names, emails, phone numbers, delivery addresses, order history, employee records, candidate CVs, camera footage, CRM entries, payment information. List it all.
Check where it lives. Website database, CRM, Google Drive, accounting software, cloud storage, cameras, paper archives, personal devices. Every location counts.
Set retention periods or criteria. Each category of data needs a documented period, or documented criteria for setting one, tied to its purpose and legal basis. Customer data kept for contract performance may have a different timeline than marketing data. Separate sector-specific or legal recordkeeping duties may also apply.
Delete what you no longer need. Indefinite retention without justification is now a compliance risk. If you collected a phone number for a one-time delivery and still have it three years later, that is a problem.
Document the rules. Write down your retention schedule. It should specify what data you keep, how long you keep it, why you keep it that long, and how you delete it when the time comes.
Where businesses typically fail
Several practical gaps appear often when businesses review their data practices.
Vague or copied privacy notices. A privacy policy that is a copy of another company's template, or one that references repealed legislation, does not satisfy the law. Your notice must identify you as the controller, name your processors, specify what data you collect and why, state retention periods or the criteria used to set them, explain data-subject rights, and provide your DPO's contact details where applicable.
Consent as a catch-all. Many businesses use consent as the legal basis for everything. That is wrong. Data needed to perform a contract (shipping an order, processing payment) has a different legal basis than data used for marketing. Using consent when it is not appropriate creates a weak foundation that can be challenged.
No internal response process. When a customer emails asking to delete their data, who handles it? If the answer is "nobody in particular," you may miss the one-month response deadline. The law allows an extension of up to two more months in complex cases, but the person must be told about the extension within the first month. Businesses need a clear process: which email or address receives data requests, who reviews them, how identity is verified, where dates are recorded, and who decides on refusal or partial response.
Ignoring vendor compliance. Your accountant, IT provider, cloud service, and marketing agency all process personal data on your behalf. If they are not compliant, you are still responsible. Contracts with processors must include data protection clauses, and you need to verify their practices.
What to do right now
If you have not started preparing, use this practical sequence.
Week 1. Create a data map. List every type of personal data you hold, where it is stored, who has access, and which external providers receive it. This does not need to be a massive audit. A simple table covering sales, delivery, HR, newsletters, surveillance, and customer support is enough.
Week 2. Update your privacy notice. Make sure it covers all the required elements. Update consent forms so they are explicit, purpose-separated, and easy to withdraw. No pre-ticked boxes.
Week 3. Review your data processing agreements with vendors. Sign or update Data Processing Agreements with every provider that handles personal data on your behalf. Check where their services are hosted and which cross-border transfer mechanism applies. Do not assume that one type of clause fits every transfer.
Week 4. Set up your incident response plan. Define who receives an incident report, how access is quickly restricted, who determines what data was affected, when the CNPDCP and individuals must be notified, and how the decision is documented.
Ongoing. Keep the register up to date, refresh documents, conduct periodic audits, and monitor CNPDCP decisions and guidance.
Why this matters beyond compliance
Law No. 195/2024 is Moldova's GDPR-based national framework for personal data protection.
For businesses, this creates both risk and opportunity. Companies that meet data protection standards can build trust with EU partners and investors. Those that ignore it will find themselves locked out of partnerships with EU-facing businesses that require compliance from their supply chain.
The Centre can open an investigation on its own initiative, conduct data-protection audits, request information, and access relevant premises and equipment within the limits set by the law. A complaint is not the only route to an investigation.
Start with the basics. Map your data, write your policies, train your team, and set up the processes that let you respond to requests and incidents within the required timeframes. It is cheaper to do this now than to explain to an auditor why you did not.
Sources
- Law No. 195/2024 on personal data protection
- CNPDCP guidance on applying Law No. 195/2024
- CNPDCP information on records of processing activities
This article is for general information and does not replace advice from a qualified legal professional.
ShiftIT is a custom software and AI automation agency based in Chișinău, Moldova. We help businesses automate operations and scale their digital presence.