The new personal data law follows the EU GDPR and covers every company that keeps data about clients, employees or website visitors. NQData takes care of the technical measures, our legal partner prepares the documents — you get one contact and one plan.
About 10 minutes · you get an offer with scope, schedule and price
Law no. 195/2024 on personal data protection was adopted on 25 July 2024 and has applied since 23 August 2026. It replaced Law 133/2011 and brings Moldova’s rules in line with the EU General Data Protection Regulation (GDPR).
Share of the assessed fine that is actually charged
Any company, institution or sole proprietor that processes personal data — whatever its size. Foreign companies that sell to people in Moldova or track their behaviour are covered too.
Anything that identifies a person: name, IDNP, phone, e-mail, photo, video footage, location, even an IP address or a cookie. Health, biometric and similar data form a special category with stricter rules.
The National Centre for Personal Data Protection (CNPDCP). It can inspect a company, order it to fix a breach, restrict or ban processing and impose a fine itself.
Next to each item — who covers it in our joint work.
Each purpose needs a ground: a contract, a legal duty, a legitimate interest or consent. Consent must be separate, clear, provable and as easy to withdraw as to give.
Legal partnerA privacy notice that says what you collect, why, on what basis, how long you keep it, to whom you pass it and how a person can exercise their rights.
Legal partner + NQDataAn internal register: which data, for what purpose, on what basis, who receives it, how long it is kept. The exemption for companies under 250 employees rarely applies, because regular processing of client or staff data cancels it.
Legal partner + NQDataAccess by role, multi-factor sign-in, encryption, tested backups, logs. The law does not demand expensive systems — it demands measures that match the risk.
NQDataHosting, CRM, mailing service, outsourced accounting or IT: whoever handles data on your instructions must be bound by a written agreement.
Legal partnerA breach that puts people at risk is reported to the Centre within 72 hours; if the risk is high, the people affected are told as well.
Legal partner + NQDataAccess, rectification, erasure, restriction, portability, objection. You answer within one month; complex requests allow two more.
Legal partner + NQDataHigh-risk processing — large-scale sensitive data, systematic monitoring, profiling — needs an impact assessment (DPIA) first. Public bodies and companies doing such processing at scale must appoint a DPO.
Legal partner| Topic | Law 133/2011 | Law 195/2024 |
|---|---|---|
| Approach | Formal requirements. Until 2022 a company notified the Centre and was entered in the register of controllers. | Accountability: at any moment you must be able to show how you comply — with a register, policies and assessments. |
| Fines | Contravention fines under the Contravention Code — small amounts that did not depend on turnover. | Up to 1,000,000 or 2,000,000 lei, or 1–2% of annual turnover if that is higher. The Centre imposes the fine itself. |
| Whom it covers | Mainly organisations established in Moldova. | Also foreign companies that offer goods or services to people in Moldova or monitor them; they appoint a local representative. |
| People’s rights | Information, access, intervention and objection. | Added: data portability and restriction of processing; erasure on wider grounds; a clear deadline for the answer — one month. |
| Children | No separate rule on a child’s consent online. | Online services may rely on a child’s consent from the age of 14; below that a parent or guardian decides. |
| Transfers abroad | To countries without adequate protection — under the standard clauses the Centre approved in 2022. | The logic of the GDPR: freely to countries with adequate protection, including the EEA; elsewhere — standard contractual clauses or other safeguards. |
| Powers of the Centre | Recorded the breach and sent the case to court. | Inspections, binding orders, restriction or ban of processing and its own fines. |
Law 133/2011 was itself updated in 2022: notification of the Centre and the register of controllers were abolished then, and the data protection officer and the impact assessment appeared. Law 195/2024 replaced it in full.
The law sets two ceilings. For organisational breaches — a missing register, weak security, an unreported breach, no agreement with a processor — up to 1,000,000 lei or 1% of last year’s turnover. For breaching the principles, the conditions for consent, people’s rights or the transfer rules, and for ignoring the Centre’s orders — up to 2,000,000 lei or 2%. The higher of the two figures applies.
A fine is not automatic. The Centre can issue a warning or order corrective measures, and it sets the amount case by case: gravity, intent, the harm done, cooperation, earlier breaches.
The figures are the legal maximum, not a forecast of a fine.
Compliance is half documents and half technology. The documents are prepared by our legal partner; NQData makes the systems match what the documents promise. You talk to one project manager at NQData.
The price depends on the size of the company and the systems involved — we name it after the questionnaire.
You want to know where you stand
You need everything put in place
You want to stay compliant
About ten minutes, no confidential details. It lets us size the work.
Scope, schedule and price for your case.
We look at documents and systems and agree on the action plan.
Documents and technical measures move in parallel.
Training, monitoring and a yearly review.

24 points on two pages: print it, tick what is done and see what is left.
Six short steps. The answers go to NQData and our legal partner and are used only to estimate the work and prepare an offer.
Yes. The law makes no exception for size or legal form: if you keep data about clients, employees or website visitors, it applies to you.
It transposes the EU regulation, so the logic and most rules are the same; the differences are local — the supervisory authority, the fine ceilings, the age of consent of 14. If you sell to people in the EU, the EU GDPR applies to you directly as well.
There is no general registration: the register of controllers was abolished back in 2022. You contact the Centre in specific cases — to report a breach, to pass on the contact details of your data protection officer, or to consult it when an impact assessment shows a high risk you cannot reduce.
It is mandatory for public bodies and for companies whose core activity is large-scale systematic monitoring of people or large-scale processing of sensitive data, such as health data. Others may appoint one voluntarily, including an external one; it is worth writing down why you decided either way.
Cookies and marketing e-mails are also governed by Law 284/2004 on information society services: analytics and advertising cookies and commercial mailings need prior consent. Law 195/2024 defines what valid consent is — active, separate, provable and easy to withdraw.
No. The Centre can start with a warning or an order to fix the breach, and any fine is set individually. During the first two years the amount is also reduced — to 10% and then 40%. But the obligations themselves already apply in full.
The legal partner assesses your processing and prepares the documents: register, policies, agreements, procedures. NQData handles the technical side: inventory of systems, website and consent, access, encryption, backups, leak prevention and monitoring. You have one contact — at NQData.
With the questionnaire on this page: it takes about ten minutes and lets us prepare an offer for your case. If you first want a quick picture, take the two-minute test.
This page is an overview, not legal advice. Figures and article numbers: Law no. 195/2024 on personal data protection.
Fill in the questionnaire or call us: we will explain where to start in your case.