Law / Albania

Albania

11 of 14 named instruments researched to a stage, across five of the six areas of law we track: 11 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 1
  5. Age gating law 1
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (204 words)

Albania is not a General Data Protection Regulation (GDPR) jurisdiction. Its comprehensive personal data statute is Law No. 124/2024 On the Protection of Personal Data, in force since 31 January 2025 and repealing Law No. 9887/2008 the same date. The law is closely modelled on the GDPR and the EU Law Enforcement Directive but carries its own numbering and its own phase-in schedule.

Primary text confirms a full GDPR-style lawful-basis chapter, a data-subject-rights chapter running Articles 12 through 21, biometric data as an explicit item within the special-category definition, a real adequacy-or-safeguards cross-border transfer regime, and a standalone civil damages right under Article 88, separate from the administrative complaint route to the Commissioner for the Right to Information and Personal Data Protection.

Article 29 requires notice to the Commissioner within 72 hours of becoming aware of a breach, but the parallel duty to notify the affected person at Article 29(3) does not itself bind until two years after the law's publication in the Official Gazette under Article 101(2), the same clause that delays the data protection impact assessment, the prior consultation, the codes of conduct, and the monitoring body provisions; the Commissioner may still order notice to the affected person case by case under Article 29(7) before then.

Breach notification

Law No. 124/2024, notification of a personal data breach

Law No. 124/2024, Art. 29 (notification of a personal data breach)Official statute PDF hosted by the Commissioner for the Right to Information and Personal Data Protection (idp.al)

In force since 31 January 2025. Binds public and private bodies.

What this law does

Article 29(1) requires the controller to notify the Commissioner of a personal data breach as soon as possible and no later than 72 hours after becoming aware of it, unless the breach is unlikely to endanger the rights and freedoms of data subjects, and to give the Commissioner the reasons for any later notification. Article 29(2) requires a processor to notify the controller immediately after becoming aware of any personal data breach.

Article 29(4) requires the notification to the Commissioner to describe the nature of the breach, including where possible the categories and approximate number of data subjects and personal data records concerned, the data protection officer's or other contact point's details, the likely consequences, and the measures taken or proposed, and Article 29(5) lets information that cannot all be given at once follow as soon as possible afterward.

Article 29(6) requires the controller to document every personal data breach, its facts, its effects, and the corrective measures taken, so the Commissioner can verify compliance.

Article 29(3) requires the controller to inform the data subject of a breach likely to result in a high risk to their rights and freedoms, subject to exceptions for encryption, other risk reducing measures, or a public notice where individual notice would be disproportionate, but this paragraph does not itself bind until two years after the law's publication in the Official Gazette under Article 101(2).

Article 29(7) already lets the Commissioner order the controller to notify the data subject of a high risk breach case by case, so a request that never reaches the data subject can still draw a Commissioner order before the standalone Article 29(3) duty takes effect.

What it requires

Comprehensive regime

Law No. 124/2024 On the Protection of Personal Data

Law No. 124/2024 (Ligj Nr. 124/2024) On the Protection of Personal Data Arts. 1-8, 11, 22-38, 43-46 (general provisions, lawful basis, consent, controller and processor obligations, and specific-purpose exceptions), in force 31 January 2025Official statute PDF hosted by the Commissioner for the Right to Information and Personal Data Protection (idp.al)

In force since 31 January 2025. Binds public and private bodies.

What this law does

Article 3 applies this law to processing personal data wholly or partly by automated means and to processing that forms part of a filing system, excluding only processing by a natural person for personal or family purposes. Article 4 reaches a controller or processor established in Albania as well as one abroad that targets a person in Albania with goods, services, or behavioral monitoring.

Article 6 sets the lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability principles. Article 7 lists the lawful bases for processing, running from the data subject's consent through contractual necessity, a legal obligation, vital interests, a public task, and a legitimate interest that does not override the data subject's rights.

Article 8 requires consent to be demonstrable, presented separately from other matters in plain language, and withdrawable at any time as easily as it was given. Article 22 requires appropriate technical and organizational measures and data protection by design and by default under Article 23. Article 25 requires a local representative for a foreign controller or processor that targets people in Albania, unless the processing is occasional and low risk or the controller is a public authority.

Article 26 sets the processor's obligations under a binding written contract with the controller. Article 27 requires a written and electronic record of processing activities naming the controller, the purposes, the categories of data, and the recipients. Article 28 requires security measures appropriate to the risk, including pseudonymization and encryption.

Article 30 binds every controller, processor, and employee with access to personal data to a confidentiality obligation that survives the contract or the employment relationship. Article 33 requires a data protection officer where a public authority processes data, where core activities require large scale monitoring of data subjects, or where core activities involve large scale processing of sensitive data or criminal records.

Article 31's data protection impact assessment and Article 32's prior consultation with the Commissioner, together with the codes of conduct at Article 35 and the monitoring bodies at Article 36, do not bind until two years after the law's publication in the Official Gazette under Article 101(2). Article 43 lets journalistic, academic, literary, and artistic processing depart narrowly from this law's requirements.

Article 45 treats filing for public interest, historical, research, scientific, or statistical purposes as a legitimate interest subject to safeguards. Article 46 lets direct marketing rest on a legitimate interest but requires express consent to process sensitive data for that purpose.

What it requires

Cross border transfer

Law No. 124/2024, international data transfer

Law No. 124/2024, Arts. 39-42 (international data transfer)Official statute PDF hosted by the Commissioner for the Right to Information and Personal Data Protection (idp.al)

In force since 31 January 2025. Binds public and private bodies.

What this law does

Article 39 permits transferring personal data to a third country or an international organization, and any further onward transfer, only where the data receives adequate protection at the destination or a specific safeguard covers that transfer.

Article 39(2) permits recognizing or enforcing a foreign court or administrative decision that compels a transfer or disclosure of personal data only where it rests on an international agreement, such as a mutual legal assistance treaty in force with Albania.

Article 40 lets the Commissioner declare a country, territory, sector, or international organization adequate, weighing its data protection legislation, its rule of law and human rights record, its national security and criminal law regime, the existence of an effective independent supervisory authority, and its international commitments, and Article 40(4) requires the Commissioner to monitor and revise that finding over time.

Article 41 lets a controller or processor transfer personal data absent an adequacy decision where it provides an appropriate safeguard, such as a legally binding instrument between public authorities, Commissioner approved binding company rules, a Commissioner published data protection standard, or a code of conduct or certification mechanism carrying binding commitments from the recipient.

Article 41(3) allows a transfer absent both an adequacy decision and a safeguard only on a listed condition, including the data subject's informed and explicit consent to the transfer after being told its risks, contractual necessity, or an important public interest, and Article 41(4) confines a further fallback transfer to one that is not repetitive and concerns only a limited number of data subjects.

Article 42 lets the Commissioner approve binding rules for a group of companies that confer enforceable rights on data subjects, apply the general processing principles internally, and make the Albanian group member liable for another member's breach of the rules abroad.

What it requires

Data subject rights

Law No. 124/2024, rights of the data subject

Law No. 124/2024, Arts. 12-21 (rights of the data subject)Official statute PDF hosted by the Commissioner for the Right to Information and Personal Data Protection (idp.al)

In force since 31 January 2025. Binds public and private bodies.

What this law does

Article 13 requires the controller to tell a data subject its identity and contact details, the purposes and legal basis of processing, the recipients, any transfer abroad, the retention period, and the rights available, and Article 12 requires that information to be concise, transparent, and in plain language, with particular care for information addressed to a minor.

Article 12(4) requires the controller to act on a data subject's request as soon as possible and no later than 30 days after receipt, extendable to 60 days for complex or numerous requests, and Article 12(5) makes that response free of charge unless the request is manifestly unfounded or excessive. Article 14 gives a data subject the right to access their personal data, its purpose, retention period, source, and recipients within 30 days of the request.

Article 15 gives a right to rectification of inaccurate data and to erasure on the listed grounds, both within 30 days, and requires the controller to inform every recipient the data were disclosed to of the change. Article 16 gives a right to be forgotten against search engines that continue to surface outdated and reputationally damaging results.

Article 17 gives a right to restrict processing, and Article 18 gives a right to receive personal data in a structured, commonly used, machine readable format and to have it transmitted directly to another controller where technically feasible. Article 19 gives a right to object to processing based on a public task or legitimate interest, and an unqualified right to object to direct marketing and its related profiling at any time without giving a reason.

Article 20 gives a data subject the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly serious effects, subject to listed exceptions under which the data subject may still obtain human intervention, express their view, and contest the decision.

What it requires

Enforcement supervision

Law No. 124/2024, Commissioner, remedies, liability and penalties

Law No. 124/2024, Arts. 75-95 (Commissioner, remedies, liability and penalties)Official statute PDF hosted by the Commissioner for the Right to Information and Personal Data Protection (idp.al)

In force since 31 January 2025. Binds public and private bodies.

What this law does

Article 75 establishes the Commissioner for the Right to Information and Personal Data Protection as an independent public legal person responsible for monitoring and supervising this law.

Article 78 has the Assembly appoint the Commissioner for a 7 year renewable term on the Council of Ministers' proposal, and Article 82 gives the Commissioner authority to investigate on its own initiative or on a complaint, issue guidelines, approve codes of conduct and certification schemes, and authorize cross border transfers.

Article 83 gives the Commissioner remedial powers including warnings, notices, orders to comply with a data subject's rights, restrictions or bans on processing, orders to communicate a breach to data subjects, revocation of a certification, and suspension of a transfer, alongside its administrative sanction power.

Article 86 lets a data subject lodge a complaint with the Commissioner free of charge, and Article 87 lets any person appeal a Commissioner act, or a data subject sue, before the competent administrative court.

Article 88 gives a data subject a right to compensation for financial or non-financial damage from an infringement of this law, separate from and without prejudice to the administrative complaint route, with a controller or processor liable unless it proves it was not responsible for the event causing the damage. Article 89 lets a data subject authorize a public interest entity or association to lodge a complaint and exercise these rights on their behalf.

Article 94(2) fixes the highest administrative fine tier at 2,000,000,000 Albanian Lek or 4% of total annual worldwide turnover, whichever is higher, for failing to apply the basic lawfulness and consent principles, violating a data subject's rights, an unlawful cross border transfer, or breaching the specific purposes rules, and the same tier punishes non-compliance with a Commissioner order.

Article 94(1) fixes a lower tier at 1,000,000,000 Lek or 2% of turnover for the minors' online consent rule, the non-identification rule, and most of the controller and processor obligations chapter other than Article 22 itself. Article 95 lets a controller or processor appeal a fine to the competent court, and collected fines go to the state budget.

What it requires

Sensitive categories

Law No. 124/2024, special categories of personal data, criminal records and children's data

Law No. 124/2024, Arts. 8(6), 9, 10 (special categories, criminal records and children's data)Official statute PDF hosted by the Commissioner for the Right to Information and Personal Data Protection (idp.al)

In force since 31 January 2025. Binds public and private bodies.

What this law does

Article 5(28) defines sensitive data as a special category revealing racial or ethnic origin, political opinions, religious belief or philosophical views, trade union membership, genetic data, biometric data, health records, or a person's sexual orientation.

Article 5(24) defines biometric data as personal data from specific technical processing of a person's physical, physiological, or behavioral characteristics that allows or confirms unique identification, naming a facial image as an example, so a derived faceprint counts and the definition is not confined to a raw recording.

Article 9(1) prohibits the processing of sensitive data outright, and Article 9(2) permits it only in the listed cases, beginning with the data subject's explicit consent to a specified purpose. Article 9(3) bars processing sensitive data about race or ethnic origin unless it ensures justice and equality on that ground and carries appropriate safeguards, and Article 9(4) permits every listed exception only where appropriate technical and security safeguards are in place.

Article 10 confines the processing of criminal records to the control of the competent authority or a specific legal authorization, with adequate protection for the data subject's rights and freedoms. Article 8(6) makes consent based processing of a minor's personal data for the online delivery of goods or services legitimate only where the minor is at least 16, and where the minor is younger, requires consent given or authorized by a parent or legal custodian.

What it requires

Scraping law2 instruments, 2 in force

Research summary (202 words)

Albania has no scraping-specific statute, so general law governs each dimension separately. The Criminal Code criminalises interference, in any way, in computer transmissions and programs, with no requirement that the offender defeat a security measure to reach that offence, so no reported Albanian case confirms or excludes reading a scraper's access as interference. No Albanian court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Copyright and Related Rights Law confers a sui generis right on a database producer to authorise or prohibit the extraction or reuse of the whole or a substantial part of a database's content, enforced by an administrative fine rather than a criminal penalty, and Albania has not enacted a text-and-data-mining exception, so training a model on scraped copyrighted text rests only on narrow general exceptions for temporary reproduction and quotation.

Personal data scraped from a public Albanian website remains subject to Law No. 124/2024 On the Protection of Personal Data, which carries no general exemption for information the data subject has made public. No Albanian statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Criminal Code, Interference in the Computer Transmissions

Criminal Code of the Republic of Albania (approved by Law No. 7895/1995, as amended by Law No. 8733/2001), Art. 192/bCriminal Code of the Republic of Albania, earlier English reference translation reflecting amendments through Law No. 8733/2001, WIPO Lex

In force. Binds public and private bodies.

What this law does

Article 192/b of the Criminal Code makes interference, in any way, in computer transmissions and programs a penal contravention, punished by a fine or imprisonment of up to three years, rising to imprisonment of up to seven years where the act brings about serious consequences.

The consolidated Albanian text currently in force is amended through Law No. 146/2020, but the World Intellectual Property Organization holds no English rendering of that current text; the earlier English reference translation of the Code available there, amended through Law No. 8733/2001, is the version that carries this article.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (746 words)

Albania enacted Law No. 25/2024 (Ligj Nr. 25/2024) "On Cybersecurity" ("Për sigurinë kibernetike"), adopted by the Assembly on 21 March 2024, promulgated by presidential decree on 16 April 2024, and published in the Official Gazette (Fletorja Zyrtare) No. 67 of 18 April 2024 at page 7767. The law's own text states that it partially transposes Directive (EU) 2022/2555 (NIS2).

Article 1 sets the law's subject matter as the rights and duties of public and private subjects that administer information infrastructure, communication networks and their systems, and names as its further contents the responsible cybersecurity authority and single point of contact, the incident response teams (the National CSIRT, CERT, and sectoral CSIRTs), the authority that drafts the National Cybersecurity Strategy, the security and risk management measures binding on subjects named in Annexes I and II, the duty of those subjects to report cybersecurity incidents, and the rules for sharing cybersecurity information.

Article 3 confines the law's application to public and private subjects that administer information systems and networks as defined in Annexes I and II. The National Authority for Cybersecurity (Autoriteti Kombëtar për Sigurinë Kibernetike, AKSK) presents itself as the law's designated regulator, national single point of contact, and national CSIRT and CERT.

AKSK's own presentation of the law's Annexes lists energy, transport, banking, financial market infrastructure, health, classified information handling tied to public security, drinking water supply, wastewater, digital infrastructure, business to business ICT service management, public administration, space, education and tourism as high criticality sectors, and postal and courier services, waste management, chemicals, food, manufacturing, and digital service providers as further critical sectors.

Per AKSK's and PwC's published accounts, a bound operator must register its critical or important information infrastructure with AKSK, establish a Computer Security Incident Response Team and a point of contact for AKSK and other CSIRTs, implement the technical, organisational and operational risk management measures a Council of Ministers methodology sets, report a significant or substantial cybersecurity incident to AKSK and the relevant CSIRTs and inform affected users where the incident reaches them, and cooperate with AKSK and other operators on sharing cybersecurity information.

PwC's client alert reports an administrative fine of 200,000 to 10,000,000 Albanian Lek for a violation of the law, varying with the type and severity of the violation, though the penalty article's own text was not confirmed to verify that figure or name the enabling article.

The law entered into force on 3 May 2024, fifteen days after publication, a date AKSK's own presentation and PwC's client alert both state, and PwC reports operators had a 24 month period from that date, ending in May 2026, to bring their practices into compliance.

PwC's client alert also reports that the law provides criminal sanctions for unauthorised access, interception, interference, damage or destruction directed against a network or information system, a duty on an intruder rather than on the operator, which stays with this jurisdiction's scraping topic computer misuse family and Criminal Code Article 192/b, already filed there, rather than being restated here.

Article 4 requires that personal data processing under the law follow Albania's data protection legislation, and Law No. 124/2024 On the Protection of Personal Data, this jurisdiction's privacy topic comprehensive regime, is the kind of General Data Protection Regulation (GDPR) style act that ordinarily carries its own security of processing article as that regime's own clause, though neither topic's research has independently confirmed such an article's text, so nothing is restated here. qbz.gov.al's own document viewer serves the Official Gazette through a paginated component, and the copy available showed only Chapter I (Articles 1 through 5), general provisions on subject matter, purpose, scope and principles, and did not advance to later pages despite several page-target attempts, so the full text of Annexes I and II and the operative chapters on security measures, incident reporting and penalties are not confirmed against the statute's own text here.

AKSK's separate certificate authority domain, cesk.gov.al, answered with an expired TLS certificate rather than any content.

AKSK's presentation also names three subordinate acts already issued under the law: a Council of Ministers methodology for identifying critical and important information infrastructure operators, VKM No. 683 of 6 November 2024; a Director General regulation categorising cybersecurity incidents, Order No. 299 of 21 August 2024; and a Director General regulation on retention periods for cybersecurity incident logs, Order No. 408 of 7 November 2024, none of which were located in full text. AKSK further reports a National Cybersecurity Strategy and Action Plan 2025 to 2030 as still in preparation.

Sector security regimes

Law No. 25/2024, On Cybersecurity

Law No. 25/2024 (Ligj Nr. 25/2024), 21 March 2024, "Për sigurinë kibernetike" ("On Cybersecurity"), Fletorja Zyrtare No. 67/2024, p. 7767Primary text: Fletorja Zyrtare (Albania's Official Gazette) via qbz.gov.al

In force since 3 May 2024. Binds public and private bodies.

What this law does

Law No. 25/2024 sets the rights and duties of public and private subjects that administer information infrastructure, communication networks and their systems whose compromise would affect the health, safety or economic wellbeing of the public or the effective functioning of the economy.

The law also names the National Authority for Cybersecurity as the single point of contact for cybersecurity matters, establishes the National CSIRT, CERT and sectoral CSIRTs, and requires a subject named in Annexes I or II to comply with mandatory cybersecurity risk management measures and to report cybersecurity incidents.

Per PwC's published account of the law, a bound operator must register its critical or important information infrastructure with the Authority, establish its own Computer Security Incident Response Team, implement the technical, organisational and operational risk management measures the Council of Ministers sets, report a significant or substantial incident to the Authority and the relevant CSIRTs, inform affected users, and cooperate with the Authority and other operators on sharing threat and incident information.

The National Authority for Cybersecurity's own presentation of the law's Annexes lists digital service providers among the sectors it reaches, alongside energy, transport, banking, financial market infrastructure, health, water supply, digital infrastructure, public administration and several other named sectors. PwC's client alert reports an administrative fine of 200,000 to 10,000,000 Albanian Lek for a violation of the law, varying with the type and severity of the violation.

The law entered into force on 3 May 2024, fifteen days after its publication, and PwC reports a 24 month period from that date for operators to bring their practices into compliance. The measures, reporting and penalty articles themselves are not confirmed against the primary Fletorja Zyrtare text here, whose paginated viewer rendered only the law's opening chapter, so this instrument's operative content beyond Article 1 rests on the Authority's own presentation and on PwC's client alert.

What it requires

Age gating law1 instrument, 1 in force

Research summary (118 words)

Albania has no social-media minor-access statute, app-store age-verification requirement, or age-appropriate design code.

Its one age-related duty sits in Article 32/1 of Law No. 97/2013 On the Audiovisual Media in the Republic of Albania, added by Law No. 30/2023, which requires an audiovisual media service provider to schedule, restrict, or apply age verification tools or other technical measures to a program that may harm a child's physical, mental, or moral development, and separately requires a video-sharing platform provider to take measures protecting children from harmful user-generated content and commercial communications.

The Audiovisual Media Authority (AMA) may fine a video-sharing platform provider ALL 200,000 to ALL 2,000,000 for a violation of these obligations, an administrative rather than criminal sanction.

Adult content age verification (AV)

Audiovisual Media Law, Minor Protection and Age Verification

Law No. 97/2013 On the Audiovisual Media in the Republic of Albania, Art. 32/1 (added by Law No. 30/2023)Law No. 97/2013 On the Audiovisual Media in the Republic of Albania

In force. Binds private bodies.

What this law does

Article 32/1, added to Law No. 97/2013 by Law No. 30/2023, requires that a program which may harm a child's physical, mental, or moral development be broadcast only in a way that ensures children do not normally hear or see it, by choosing the broadcast time, applying age verification tools, or other technical measures, with the strictest measures required for the most harmful content such as violence and pornography.

The same article bars processing a child's personal data collected by an audiovisual media service provider for commercial purposes such as direct marketing, profiling, or behavioural advertising, and separately requires a video-sharing platform provider to take measures protecting children from harmful programs, user-generated videos, and commercial communications, and protecting the general public from content that incites violence or hatred or constitutes a criminal offence such as child pornography, racism, or xenophobia.

The Audiovisual Media Authority (AMA) may fine a video-sharing platform provider ALL 200,000 to ALL 2,000,000 for a violation of these obligations, an administrative rather than criminal sanction.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (139 words)

Albania has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining code, no hot-news or misappropriation doctrine distinct from ordinary copyright law, and no statute or reported decision addressing whether a hyperlink is a communication to the public or whether framing changes the answer.

Its general copyright statute, Law No. 35/2016 On Copyright and Related Rights, permits reproducing newspaper articles and photos for public information about current events, including online, and separately permits quoting fragments of a published work for criticism, teaching, or review, both subject to source-citation and fair-practice limits; the 2022 amendments to this law left both provisions untouched, and no reported Albanian decision applies either provision to a systematic news aggregator rather than an individual quoting a published work.

The law predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.