Law No. 195/2024 on Personal Data Protection
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force 31 days, effective 23 August 2026.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Establish a lawful basis and allocate controller and processor duties before processing personal data of a person in Moldova.
- Take consent only on the conditions article 7 sets, and be able to demonstrate the data subject gave it.
- Build data protection into the design of your processing and make it the default, and keep records of your processing activities.
- Implement technical and organisational measures giving a level of security appropriate to the risk.
- Carry out a data protection impact assessment before processing likely to result in a high risk, and consult the National Centre for Personal Data Protection beforehand where that risk remains.
- Designate a data protection officer where the law requires one, give them the position article 38 prescribes, and let them carry out the tasks article 39 lists.
- Where you engage a processor, govern the engagement as article 28 requires, and settle each party's responsibilities in an arrangement where you are a joint controller.
What it reaches
Obligation class
Consent, Security, DPIA, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Articles 2 and 3 fix the law's material and territorial scope. Article 5 carries the processing principles, article 6 the lawful bases and article 7 the conditions for valid consent. Article 11 governs processing which does not require identification. Article 24 places responsibility on the controller, article 25 requires data protection by design and by default, article 26 governs joint controllers and article 28 the engagement of a processor.
Article 30 requires records of processing activities and article 32 technical and organisational measures giving a level of security appropriate to the risk. Article 35 requires a data protection impact assessment where processing is likely to result in a high risk, and article 36 prior consultation of the National Centre for Personal Data Protection where it shows that risk remains.
Articles 37 to 39 govern the designation, position and tasks of the data protection officer, and articles 40 to 43 the codes of conduct, their monitoring, certification and certification bodies. Article 89(1) enters the Law into force on the expiry of 24 months from the date of its publication in the Official Gazette of the Republic of Moldova. The Law's front matter dates that publication 23 August 2024, so these provisions bind from 23 August 2026.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachgenerates_content
Read the law
Official statute PDF hosted by datepersonale.md, read in full (169,952 characters, untruncated)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.