Law 195/2024 · applies since 23 August 2026

GDPR in Moldova:
compliance with Law 195/2024

The new personal data law follows the EU GDPR and covers every company that keeps data about clients, employees or website visitors. NQData takes care of the technical measures, our legal partner prepares the documents — you get one contact and one plan.

About 10 minutes · you get an offer with scope, schedule and price

23.08.2026the law applies
72 hoursto report a data breach
1 monthto answer a person’s request
up to 2%of annual turnover — the fine ceiling
The law in one minute

What Law 195/2024 is and whom it concerns

Law no. 195/2024 on personal data protection was adopted on 25 July 2024 and has applied since 23 August 2026. It replaced Law 133/2011 and brings Moldova’s rules in line with the EU General Data Protection Regulation (GDPR).

Share of the assessed fine that is actually charged

  1. 2 yearsto prepare — this period is over
    todaythe law is adopted
  2. 10%of the fine in the first year
    todaythe law applies; obligations in full
  3. 40%in the second year
    todayfines rise to 40%
  4. 100%in full from the third year
    todayfines in full

Whom it applies to

Any company, institution or sole proprietor that processes personal data — whatever its size. Foreign companies that sell to people in Moldova or track their behaviour are covered too.

What counts as personal data

Anything that identifies a person: name, IDNP, phone, e-mail, photo, video footage, location, even an IP address or a cookie. Health, biometric and similar data form a special category with stricter rules.

Who supervises

The National Centre for Personal Data Protection (CNPDCP). It can inspect a company, order it to fix a breach, restrict or ban processing and impose a fine itself.

Obligations

Eight things every company must have in place

Next to each item — who covers it in our joint work.

Before and after

What changed compared with Law 133/2011

TopicLaw 133/2011Law 195/2024
ApproachFormal requirements. Until 2022 a company notified the Centre and was entered in the register of controllers.Accountability: at any moment you must be able to show how you comply — with a register, policies and assessments.
FinesContravention fines under the Contravention Code — small amounts that did not depend on turnover.Up to 1,000,000 or 2,000,000 lei, or 1–2% of annual turnover if that is higher. The Centre imposes the fine itself.
Whom it coversMainly organisations established in Moldova.Also foreign companies that offer goods or services to people in Moldova or monitor them; they appoint a local representative.
People’s rightsInformation, access, intervention and objection.Added: data portability and restriction of processing; erasure on wider grounds; a clear deadline for the answer — one month.
ChildrenNo separate rule on a child’s consent online.Online services may rely on a child’s consent from the age of 14; below that a parent or guardian decides.
Transfers abroadTo countries without adequate protection — under the standard clauses the Centre approved in 2022.The logic of the GDPR: freely to countries with adequate protection, including the EEA; elsewhere — standard contractual clauses or other safeguards.
Powers of the CentreRecorded the breach and sent the case to court.Inspections, binding orders, restriction or ban of processing and its own fines.

Law 133/2011 was itself updated in 2022: notification of the Centre and the register of controllers were abolished then, and the data protection officer and the impact assessment appeared. Law 195/2024 replaced it in full.

Fines

Fine calculator: the ceiling for your company

The law sets two ceilings. For organisational breaches — a missing register, weak security, an unreported breach, no agreement with a processor — up to 1,000,000 lei or 1% of last year’s turnover. For breaching the principles, the conditions for consent, people’s rights or the transfer rules, and for ignoring the Centre’s orders — up to 2,000,000 lei or 2%. The higher of the two figures applies.

A fine is not automatic. The Centre can issue a warning or order corrective measures, and it sets the amount case by case: gravity, intent, the harm done, cooperation, earlier breaches.

Type of breach
Ceiling under the law—
How much can actually be charged
  • until 22 August 2027 — 10%—
  • 23 August 2027 – 22 August 2028 — 40%—
  • from 23 August 2028 — 100%—

The figures are the legal maximum, not a forecast of a fine.

By industry

What the law means for your business

Healthcare

Typical data
  • Patient records
  • Test results
  • Online bookings
  • Insurance details
What needs attention
  • Health data is a special category: it needs its own legal ground and tighter protection.
  • Large-scale processing usually means a mandatory DPO and an impact assessment.
  • Results sent by e-mail or messenger are a typical source of leaks.
What we set up
  • Access to records by role, with a log of who opened what.
  • Encrypted mail and file exchange for results.
  • Backups and a recovery plan for the medical system.

Retail and e-commerce

Typical data
  • Orders and deliveries
  • Loyalty cards
  • Newsletter lists
  • Cookies and analytics
What needs attention
  • Orders run on the contract; newsletters, retargeting and analytics need separate consent.
  • A pre-ticked box is not consent — such a base has to be collected again.
  • Couriers, payment and mailing services are processors: each needs an agreement.
What we set up
  • Cookie banner with a real choice and a consent log.
  • Forms and checkout with a separate consent box.
  • Protection of the client database and admin accounts.

Finance

Typical data
  • Identity documents
  • Income and credit history
  • Payment data
  • Call recordings
What needs attention
  • Scoring and other automated decisions: a person may ask for human review.
  • Retention periods must satisfy both this law and the financial-sector rules.
  • Large volumes and monitoring often make a DPO and an impact assessment mandatory.
What we set up
  • Leak prevention (DLP): control of e-mail, USB, cloud and print.
  • Multi-factor sign-in and privileged-access control.
  • Audit logs and monitoring to detect an incident in time.

Manufacturing and logistics

Typical data
  • Staff files and payroll
  • Video surveillance
  • GPS on vehicles
  • Access control and time tracking
What needs attention
  • Employees must know what is monitored and why; consent is a weak ground at work.
  • Time tracking by fingerprint or face is biometric data — a special category.
  • GPS that keeps tracking after working hours is hard to justify.
What we set up
  • Retention limits and access rules for video archives.
  • Separation of HR data from the rest of the network.
  • Encrypted laptops and phones for staff in the field.

Public sector and education

Typical data
  • Citizens’ applications
  • Registers and records
  • Pupils and students
  • Staff data
What needs attention
  • A data protection officer is mandatory for public authorities and institutions.
  • Public bodies cannot rely on legitimate interest for their official tasks — the ground is the law.
  • Children’s data needs special care; online consent is valid from the age of 14.
What we set up
  • Secure e-mail and document exchange on Microsoft 365.
  • Access policies and audit logs for registers.
  • Backups stored separately from the main systems.

IT and outsourcing

Typical data
  • Clients’ databases
  • Test and support access
  • Users of your product
  • Staff and contractors
What needs attention
  • For your clients you are a processor: they will ask for an agreement and proof of security.
  • Working with clients or users in the EU brings the EU GDPR into play as well.
  • Real personal data in test environments is a frequent and avoidable breach.
What we set up
  • Separate environments and access with multi-factor sign-in.
  • Activity logs for administrators and developers.
  • Device encryption and control of data leaving the company.
Not sure where you stand?Five questions, two minutes — and you see your gaps. Nothing is sent anywhere.Take the test
How we work

Two teams, one contact

Compliance is half documents and half technology. The documents are prepared by our legal partner; NQData makes the systems match what the documents promise. You talk to one project manager at NQData.

Your company

Legal partner

documents and legal assessment
  • Audit of processing and a list of gaps
  • Record of processing activities
  • Privacy notices, policies and consent wording
  • Agreements with processors and partners
  • Impact assessments and advice on a DPO
  • Incident and request procedures, staff training
NQData project managerOne contact, one plan, one schedule

NQData engineers

systems and security
  • Inventory: where personal data actually lives
  • Website: cookie banner, consent log, forms
  • Access by role and multi-factor sign-in
  • Encryption of devices, mail and storage
  • Backups that are tested by restoring
  • Leak prevention (DLP), logs and monitoring
Packages

Three ways to start

The price depends on the size of the company and the systems involved — we name it after the questionnaire.

Audit

You want to know where you stand

  • Review of processing and documentsLegal
  • Inventory of systems and data flowsNQData
  • Technical security checkNQData
  • Gap report and a corrective action planTogether
Price on request
Request an offer →
Full cycle

Compliance

You need everything put in place

  • Everything in “Audit”
  • Register, policies, notices, agreementsLegal
  • Incident and request proceduresLegal
  • Website, access, encryption, backupsNQData
  • Staff trainingLegal
Price on request
Request an offer →

Ongoing support

You want to stay compliant

  • Everything in “Compliance”
  • Periodic legal assistance and document updatesLegal
  • Monitoring, logs and leak prevention (DLP)NQData
  • Help during an incident or an inspectionTogether
  • Annual reviewTogether
Price on request
Request an offer →
Steps

From questionnaire to compliance

  1. Questionnaire

    About ten minutes, no confidential details. It lets us size the work.

  2. Offer

    Scope, schedule and price for your case.

  3. Audit

    We look at documents and systems and agree on the action plan.

  4. Implementation

    Documents and technical measures move in parallel.

  5. Support

    Training, monitoring and a yearly review.

Compliance checklist for Law 195/2024

Compliance checklist for Law 195/2024

24 points on two pages: print it, tick what is done and see what is left.

Download PDFPDF · no sign-up
Questionnaire

Pre-contract questionnaire

Six short steps. The answers go to NQData and our legal partner and are used only to estimate the work and prepare an offer.

Please do not enter personal data other than your contact details, internal documents or confidential information.

Frequently asked questions

Does the law apply to a small company or a sole proprietor?

Yes. The law makes no exception for size or legal form: if you keep data about clients, employees or website visitors, it applies to you.

Is Law 195/2024 the same as the GDPR?

It transposes the EU regulation, so the logic and most rules are the same; the differences are local — the supervisory authority, the fine ceilings, the age of consent of 14. If you sell to people in the EU, the EU GDPR applies to you directly as well.

Do we have to register with the Centre or notify it?

There is no general registration: the register of controllers was abolished back in 2022. You contact the Centre in specific cases — to report a breach, to pass on the contact details of your data protection officer, or to consult it when an impact assessment shows a high risk you cannot reduce.

Do we need a data protection officer?

It is mandatory for public bodies and for companies whose core activity is large-scale systematic monitoring of people or large-scale processing of sensitive data, such as health data. Others may appoint one voluntarily, including an external one; it is worth writing down why you decided either way.

What about cookies and newsletters?

Cookies and marketing e-mails are also governed by Law 284/2004 on information society services: analytics and advertising cookies and commercial mailings need prior consent. Law 195/2024 defines what valid consent is — active, separate, provable and easy to withdraw.

Is a fine inevitable if something is missing?

No. The Centre can start with a warning or an order to fix the breach, and any fine is set individually. During the first two years the amount is also reduced — to 10% and then 40%. But the obligations themselves already apply in full.

What exactly does NQData do, and what does the lawyer do?

The legal partner assesses your processing and prepares the documents: register, policies, agreements, procedures. NQData handles the technical side: inventory of systems, website and consent, access, encryption, backups, leak prevention and monitoring. You have one contact — at NQData.

Where do we start?

With the questionnaire on this page: it takes about ten minutes and lets us prepare an offer for your case. If you first want a quick picture, take the two-minute test.

This page is an overview, not legal advice. Figures and article numbers: Law no. 195/2024 on personal data protection.

Bring your company into compliance — without stopping the business

Fill in the questionnaire or call us: we will explain where to start in your case.

Nicu — AI Consultant
NQData