Free self-check · 2 minutes

Is your company ready for
Law 195/2024 on personal data?

Moldova’s new personal data law has applied since 23 August 2026. Answer five questions and see where you stand and what to fix first. Nothing is sent anywhere — the answers stay in your browser.

23.08.2026the law applies
2,000,000 leior 2% of turnover — the top fine
72 hoursto report a data breach
The basics

What the law expects from a company

A record of what you process

Clients, employees, website leads, video surveillance: keep a register of which data you hold, for what purpose, on what legal basis and for how long.

Honest consent on the website

A published privacy policy, an unticked consent box on every form, analytics cookies only after the visitor agrees. Consent must be as easy to withdraw as to give.

Security that matches the risk

Access only for those who need it, multi-factor sign-in, encryption and backups that are actually tested.

Contracts with those who process for you

Hosting, CRM, mailing service, outsourced accounting: if a supplier handles personal data on your instructions, there must be an agreement that says how.

A plan for the day data leaks

A breach that puts people at risk must be reported to the National Centre for Personal Data Protection within 72 hours. That only works if roles are agreed in advance.

People’s rights: one month to answer

Anyone can ask what you hold about them and have it corrected or deleted. You have one month to answer.

Fines

What non-compliance costs

up to 1,000,000 lei

or 1% of annual turnover — for organisational breaches such as a missing register or missing supplier agreements

up to 2,000,000 lei

or 2% of annual turnover — for breaching the core principles, people’s rights or the rules on transfers abroad

10% → 40% → 100%

the fine is applied at 10% of the assessed amount in the first year, 40% in the second and in full from the third

The technical side

Where NQData helps

We do the IT part of compliance. Legal documents are best prepared together with a lawyer.

Guide to the law, packages and questionnaire →

Frequently asked questions

Does the law apply to a small company?

Yes. It applies to any organisation that processes personal data — of clients, employees or website visitors — whatever its size.

What are the fines?

Up to 1,000,000 lei or 1% of annual turnover for organisational breaches, and up to 2,000,000 lei or 2% for breaching the core principles, people’s rights or the transfer rules. In the first year they are applied at 10% of the assessed amount, in the second at 40%.

Do we need a data protection officer?

It is mandatory for public bodies and for companies whose core activity is large-scale systematic monitoring of people or large-scale processing of sensitive data, such as health data. Others may appoint one voluntarily; it is worth writing down why you decided either way.

What should we do first?

Start with the register of processing. Once you know which data you hold and where, the other steps — consent, contracts, security, incident plan — follow from it.

Where do my answers go?

Nowhere. The test runs in your browser; we neither receive nor store the answers. You decide whether to send us the result.

Is this test legal advice?

No. It is a quick check of the basics. NQData handles the technical measures; have your documents reviewed by a lawyer.

This test is a quick self-assessment, not legal advice. Figures: Law no. 195/2024 on personal data protection, applicable from 23 August 2026.

Close the gaps before an inspection finds them

Tell us your result — an engineer will suggest where to start on the technical side.

Nicu — AI Consultant
NQData