Moldova’s new personal data law has applied since 23 August 2026. Answer five questions and see where you stand and what to fix first. Nothing is sent anywhere — the answers stay in your browser.
Clients, employees, website leads, video surveillance: keep a register of which data you hold, for what purpose, on what legal basis and for how long.
A published privacy policy, an unticked consent box on every form, analytics cookies only after the visitor agrees. Consent must be as easy to withdraw as to give.
Access only for those who need it, multi-factor sign-in, encryption and backups that are actually tested.
Hosting, CRM, mailing service, outsourced accounting: if a supplier handles personal data on your instructions, there must be an agreement that says how.
A breach that puts people at risk must be reported to the National Centre for Personal Data Protection within 72 hours. That only works if roles are agreed in advance.
Anyone can ask what you hold about them and have it corrected or deleted. You have one month to answer.
or 1% of annual turnover — for organisational breaches such as a missing register or missing supplier agreements
or 2% of annual turnover — for breaching the core principles, people’s rights or the rules on transfers abroad
the fine is applied at 10% of the assessed amount in the first year, 40% in the second and in full from the third
We do the IT part of compliance. Legal documents are best prepared together with a lawyer.
Guide to the law, packages and questionnaire →
Cookie banner, consent log and forms with a consent box — the setup we run on our own sites.
Learn more →Multi-factor sign-in, access policies, encryption and audit logs for mail and files.
Learn more →See where personal data goes — USB, e-mail, cloud, messengers — and stop it leaving.
Learn more →Tested backups, monitoring and logs, so a leak is noticed in time and can be reconstructed.
Learn more →Yes. It applies to any organisation that processes personal data — of clients, employees or website visitors — whatever its size.
Up to 1,000,000 lei or 1% of annual turnover for organisational breaches, and up to 2,000,000 lei or 2% for breaching the core principles, people’s rights or the transfer rules. In the first year they are applied at 10% of the assessed amount, in the second at 40%.
It is mandatory for public bodies and for companies whose core activity is large-scale systematic monitoring of people or large-scale processing of sensitive data, such as health data. Others may appoint one voluntarily; it is worth writing down why you decided either way.
Start with the register of processing. Once you know which data you hold and where, the other steps — consent, contracts, security, incident plan — follow from it.
Nowhere. The test runs in your browser; we neither receive nor store the answers. You decide whether to send us the result.
No. It is a quick check of the basics. NQData handles the technical measures; have your documents reviewed by a lawyer.
This test is a quick self-assessment, not legal advice. Figures: Law no. 195/2024 on personal data protection, applicable from 23 August 2026.
Tell us your result — an engineer will suggest where to start on the technical side.