Law / Kosovo

Kosovo

All 14 named instruments researched to a stage, across all six areas of law we track: 11 in force and 3 repealed, withdrawn or blocked. As of 19 September 2026.

When they take effect14 of 14 carry a date. Earlier is before 2014.
Before 2014: 4 instruments (1 in force, 3 repealed, withdrawn or blocked) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 8 instruments (8 in force) 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 2 instruments (2 in force) 2024: 0 instruments 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 7
  3. Scraping law 2
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (142 words)

Kosovo has not enacted a binding statute imposing an AI-transparency or output-labeling duty (a duty to disclose that content is AI-generated, to label or watermark synthetic output, or to disclose that a user is talking to a bot).

Its Criminal Code, Code No. 06/L-074 (in force since 14 April 2019), reaches AI-generated child sexual abuse material through its general child pornography prohibition: Article 225(8) defines "child pornography" to include a photograph or image created by computer and, expressly, a realistic image of a non-existent child engaged in real or simulated sexually explicit conduct, and Article 232 criminalizes producing, distributing, or possessing material meeting that definition regardless of whether a real child was involved.

No AI-risk, AI-training-data, or AI-governance statute is on the books. Kosovo's data protection statute, which reaches automated decision-making as a personal-data duty, is researched separately under the privacy topic.

AI prohibited practices

Criminal Code of the Republic of Kosovo, Articles 225 and 232 (Child Pornography, Including Computer-Generated and Non-Existent-Child Images)

Code No. 06/L-074 Criminal Code of the Republic of Kosovo, arts. 225(8), 232Official Gazette of the Republic of Kosovo (gzk.rks-gov.net)

In force since 14 April 2019. Binds public and private bodies.

What this law does

Article 232 of the Criminal Code of the Republic of Kosovo (Code No. 06/L-074, in force since 14 April 2019) criminalizes producing child pornography, using or involving a child in creating a live sexual exhibition, by five to fifteen years' imprisonment; distributing or making it available, by three to ten years; and procuring or possessing it, by a fine and one to five years, with an attempt punishable in every case.

Article 225(8), the chapter's own definitions provision, defines "child pornography" to include any photograph, film, video, image or picture created by computer, whether created electronically, mechanically or by other means. That definition expressly extends to realistic images of a non-existent child engaged in real or simulated sexually explicit conduct, so a wholly synthetic depiction with no real child involved falls within the prohibition on the same terms as an image of a real child.

What it requires

Privacy law7 instruments, 7 in force

Research summary (162 words)

Kosovo has a comprehensive, General Data Protection Regulation (GDPR)-modelled data protection statute, Law No. 06/L-082 on Protection of Personal Data, in force since 12 March 2019 under its own Article 111 rule setting entry into force fifteen days after publication in the Official Gazette.

The Official Gazette's full 111-article Albanian text sets out general provisions, special categories and children's data, a dedicated biometric-use chapter, data subject rights, cross-border transfer, breach notification, and enforcement provisions, organized below as one law family per chapter grouping.

Special categories of personal data, including biometric data used for unique identification, carry a heightened, necessity-based restriction reaching both public and private actors, and the statutory definition names visual images and facial features expressly, so an identifier derived from a photograph or video recording is squarely covered; the definition does not name voice specifically, and whether a voiceprint falls under its broader behavioural-characteristics language is not established by the law's own text. The biometric-data definition sits at Article 3, paragraph 1, item 20.

Biometric privacy

Law No. 06/L-082 on Protection of Personal Data, use of biometric characteristics

Law No. 06/L-082 on Protection of Personal Data, arts. 80-83 (use of biometric characteristics)Official Gazette of the Republic of Kosovo (gzk.rks-gov.net), act detail page, full 111-article Albanian text

In force since 12 March 2019. Binds public and private bodies.

What this law does

Article 80 subjects the determination and use of a data subject's biometric characteristics, and their comparison to enable identification, to this chapter's dedicated rules. Article 81 lets the public sector use biometric characteristics only where strictly necessary for the safety of individuals, the protection of property or the safeguarding of confidential data and trade secrets, and only where that cannot be achieved by other means.

Article 82 lets the public sector use biometric characteristics for access control, applying the entry and exit records chapter's retention and handling rules to that use. Article 83 lets the private sector use biometric characteristics under the same necessity test, requires employees to be informed in writing in advance of the measures and their rights, and requires the controller to submit a detailed description of the proposed measures to the Agency before taking them.

Article 83(3) gives the Agency thirty days to decide whether the proposed measures comply with the law. Article 83(4) lets the controller implement biometric measures only after receiving the Agency's authorisation.

Whether a voiceprint falls inside these biometric-use rules is not established by the law's own text: the general biometric-data definition's core clause covers behavioural characteristics used for unique identification, but its illustrative list of examples names fingerprints, iris, retina, facial features and DNA and does not name voice.

What it requires

Breach notification

Law No. 06/L-082 on Protection of Personal Data, personal data breach notification

Law No. 06/L-082 on Protection of Personal Data, arts. 33-34 (personal data breach notification)Official Gazette of the Republic of Kosovo (gzk.rks-gov.net), act detail page, full 111-article Albanian text

In force since 12 March 2019. Binds public and private bodies.

What this law does

Article 33(1) requires the controller, without delay and where feasible no later than seventy-two hours after becoming aware of a personal data breach, to notify the Agency of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Article 33(1) also requires a notification made after that seventy-two-hour period to be accompanied by reasons for the delay.

Article 33(2) requires a processor to notify the controller without undue delay after becoming aware of a personal data breach. Article 33(3) fixes what the Agency notification must contain at minimum, including the nature of the breach, the categories and approximate number of data subjects and personal data records concerned where possible, a contact point's name and details, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.

Article 33(4) lets that information be given in phases without undue further delay where it cannot all be given at once. Article 33(5) requires the controller to document every personal data breach, including its facts, effects and remedial action, so the Agency can verify compliance. Article 34(1) requires the controller to communicate a personal data breach to the data subject without undue delay where the breach is likely to result in a high risk to the rights and freedoms of natural persons.

Article 34(3) excuses that communication where the controller had applied protective measures, such as encryption, that rendered the affected data unintelligible, where the controller has since eliminated the high risk, or where communication would take disproportionate effort and a public communication of equivalent effectiveness is made instead.

Article 34(4) still lets the Agency require the communication, or determine that one of the Article 34(3) conditions applies, where the controller has not itself communicated the breach to the data subject.

What it requires

Comprehensive regime

Law No. 06/L-082 on Protection of Personal Data

Law No. 06/L-082 on Protection of Personal Data (Albanian: Ligji Nr. 06/L-082 per Mbrojtjen e te Dhenave Personale) arts. 1-6, 10, 23-32, 35-43, 73, 75-90 (general provisions, lawful basis, controller and processor obligations, DPIA, the Data Protection Officer, direct marketing lawful basis, and other sector-specific processing rules)Official Gazette of the Republic of Kosovo (gzk.rks-gov.net), act detail page, full 111-article Albanian text

In force since 25 February 2019, effective 12 March 2019. Binds public and private bodies.

What this law does

Law No. 06/L-082 on Protection of Personal Data is Kosovo's general, General Data Protection Regulation (GDPR)-modelled data protection statute, and Article 1(2) states that the law aligns with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.

Article 2(3) extends the law to a controller or processor not established in Kosovo that uses automatic or other equipment there to process personal data, other than equipment used only for transit through Kosovo, and requires such a controller or processor to appoint a registered representative in Kosovo.

Article 4 sets the general processing principles of lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability, and Article 5 lists the lawful bases for processing, led by the data subject's consent.

Articles 23 to 30 set the controller's and processor's general obligations, covering accountability and data protection by design and by default, arrangements between joint controllers, a written representative-appointment duty, a written contract governing a processor's activities, a written record of processing activities, and cooperation with the Agency for Information and Privacy on request.

Article 29(4) exempts an undertaking or organisation employing fewer than two hundred and fifty people from the records-of-processing duty unless the processing risks data subjects' rights, is not occasional, or involves special categories of data or criminal-offence data.

Articles 35 and 36 require a data protection impact assessment before high-risk processing, such as systematic and extensive automated evaluation with legal or similarly significant effects, large-scale special-category processing, or large-scale systematic monitoring of a publicly accessible area.

Articles 37 to 39 require a Data Protection Officer where processing is carried out by a public authority, where core activities require regular and systematic large-scale monitoring of data subjects, or where core activities involve large-scale processing of special categories of data or criminal-offence data, and Articles 40 to 43 add internal-acts, codes-of-conduct and certification duties.

Article 73 lets a controller use personal data collected from public sources for direct marketing, limited to name, address, telephone number and email address unless the data subject has separately consented, and requires written consent before using sensitive personal data for that purpose.

Articles 75 to 90 hold this regime's remaining sector-specific processing rules, covering notice, retention and placement limits for video surveillance, an access-control cross-reference to the entry and exit records chapter, a three-year retention cap on building entry and exit logs, and restrictions on interconnecting filing systems, none of which this split gives its own family row.

Article 111 sets the law's entry into force at fifteen days after its publication in the Official Gazette of the Republic of Kosovo, which places entry into force on 12 March 2019 rather than the Gazette's own 25 February 2019 publication date.

What it requires

Cross border transfer

Law No. 06/L-082 on Protection of Personal Data, transfer of personal data to other states and international organisations

Law No. 06/L-082 on Protection of Personal Data, arts. 44-51 (transfer of personal data to other states and international organisations)Official Gazette of the Republic of Kosovo (gzk.rks-gov.net), act detail page, full 111-article Albanian text

In force since 12 March 2019. Binds public and private bodies.

What this law does

Article 44 permits transferring personal data to another state or an international organisation only in accordance with this law and only where that state or organisation ensures an adequate level of data protection.

Articles 45 and 46 let the Agency formally decide that a state or international organisation, or a specified sector within it, ensures an adequate level of protection, maintain a public list of those states and organisations, and adopt a decision the competent European Union body has already made to the same effect.

Article 47 lists the factors the Agency weighs in an adequacy decision, including the rule of law and human rights record, the existence of an effective independent supervisory authority, the third state's or organisation's international commitments, and the data subject's effective and enforceable rights and administrative and judicial redress. Article 47(3) requires the Agency to review its adequacy list at least every four years.

Article 49 lets the Agency authorise a transfer to a state or organisation that does not ensure an adequate level of protection where one of the listed conditions is met, including another law or binding international treaty, the data subject's informed consent, necessity for performing or entering a contract, an important public interest, protecting the data subject's life or body, legal claims, a public register open to consultation, or the controller's application of adequate safeguards.

Article 50 requires the Agency's transfer authorisations to be recorded under Article 29(1)(5)'s processing-register rule. Article 51 lets a foreign court judgment or administrative authority decision demanding a controller or processor transfer or disclose personal data be recognised or enforced only on the basis of an international agreement between the requesting third state and the Republic of Kosovo.

What it requires

Data subject rights

Law No. 06/L-082 on Protection of Personal Data, rights of the data subject

Law No. 06/L-082 on Protection of Personal Data, arts. 11-22, 74 (rights of the data subject)Official Gazette of the Republic of Kosovo (gzk.rks-gov.net), act detail page, full 111-article Albanian text

In force since 12 March 2019. Binds public and private bodies.

What this law does

Article 11 requires the controller to give the Article 12 and 13 information and handle an Article 14 to 21 request in a concise, transparent, intelligible and easily accessible form, free of charge and within one month of the request, extendable by a further two months for complex or numerous requests.

Articles 12 and 13 set the information a controller must give a data subject, whether the data came from the subject or elsewhere, covering the controller's identity, the purposes and legal basis of processing, the recipients, any transfer to a third country, the storage period, and the data subject's rights. Article 14 gives a right of access to confirmation of processing, a copy of the personal data, and the accompanying information the article lists.

Article 15 gives a right to rectification of inaccurate personal data and completion of incomplete data. Article 16 gives a right to erasure, the right to be forgotten, on the listed grounds, including withdrawal of consent, unlawful processing, and collection under Article 7's information-society-service consent rule.

Article 17 gives a right to restriction of processing where accuracy is contested, processing is unlawful, the controller no longer needs the data but the data subject does for legal claims, or an Article 20 objection is pending verification. Article 18 requires the controller to communicate any rectification, erasure or restriction to every recipient the data were disclosed to, unless that proves impossible or disproportionately difficult.

Article 19 gives a right to data portability in a structured, commonly used and machine-readable format where processing rests on consent or a contract and is carried out by automated means. Article 20 gives a right to object to processing based on the controller's or a third party's legitimate interest, and a separate, unconditional right to object to processing for direct marketing purposes, including related profiling.

Article 21 gives a right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects the data subject, subject to the listed exceptions and safeguards.

Article 74 lets a data subject demand in writing that a controller stop using their personal data for direct marketing, requires the controller to stop within eight days of receiving the objection, and requires written confirmation to the data subject within a further five days.

Article 22 lets these rights be restricted, consistently with the essence of fundamental rights and freedoms, only where necessary and proportionate to safeguard the listed public interests, including state security, defence, public safety, and the prevention, investigation, detection or prosecution of criminal offences.

What it requires

Enforcement supervision

Law No. 06/L-082 on Protection of Personal Data, remedies, the Agency, inspections and penalties

Law No. 06/L-082 on Protection of Personal Data arts. 52-72, 91-107 (remedies, the supervisory Agency, inspections, and administrative and criminal penalties)Official Gazette of the Republic of Kosovo (gzk.rks-gov.net), act detail page, full 111-article Albanian text

In force since 12 March 2019. Binds public and private bodies.

What this law does

Article 52 gives a data subject the right to complain to the Agency for Information and Privacy that processing of their personal data breaches this law, without prejudice to other administrative or judicial remedies.

Articles 53 and 54 give a person a right to an effective judicial remedy against a legally binding Agency decision, against the Agency's failure to handle or report on a complaint within three months, and against a controller or processor whose processing the person believes has violated their rights.

Article 55 lets a data subject authorise a representative body, organisation or non-profit association active in data protection to lodge a complaint, exercise judicial remedies, and claim compensation on their behalf.

Article 56 gives any person who has suffered material or non-material damage from a breach of this law the right to compensation from the controller or processor, holds every controller and processor involved in the same processing jointly liable to guarantee effective compensation, and excuses a controller or processor that proves it bears no responsibility for the damage.

Article 57 establishes the Agency for Information and Privacy as an independent authority responsible for overseeing this law, answerable to the Assembly of Kosovo, acting free from external influence and taking instructions from no one.

Article 58 places the Agency under a Commissioner elected by the Assembly of Kosovo for a five-year term, renewable once, and Article 61 lists the grounds on which the Commissioner's mandate ends, including resignation, a criminal conviction carrying more than six months' imprisonment, or dismissal by the Assembly for breaching this law.

Articles 64 and 65 give the Agency its core duties, including supervising this law's implementation, advising public and private bodies, deciding complaints, conducting inspections, and cooperating with other supervisory authorities in Kosovo and abroad. Articles 68 to 70 let the Agency conduct inspections and controls on its own initiative or on a complaint, and let inspection officers examine and seize documentation, computers and equipment relevant to personal data processing.

Article 71 lets an inspection officer who finds a violation order the correction of irregularities, including destruction, blocking or anonymisation of personal data, temporarily halt unlawful or non-compliant processing, order compliance with a data subject's rights request, impose a fine for violations of this law, or issue a written warning for minor violations.

Article 91 sets the criteria the Agency weighs in fixing an administrative fine, including the nature, gravity and duration of the violation, whether it was intentional or negligent, the categories of personal data affected, the degree of cooperation with the Agency, and any prior relevant violation.

Article 92 fines a legal person or independent-activity person twenty thousand to forty thousand euros for a general violation such as processing without a lawful basis or consent, unlawfully processing special categories or criminal-offence data, or failing to inform a data subject, with lower tiers set for a responsible individual within that legal person, a responsible individual within a state body, and an individual acting alone.

Articles 93 to 104 set separate fine tiers for violations of the contracted-processing, security, direct-marketing, video-surveillance, biometric, building-entry-log, filing-system-interconnection and Data Protection Officer rules, ranging from two hundred to forty thousand euros depending on the provision and the offender's category.

Article 105 lets the Agency fine a serious and large-scale violation of personal data provisions twenty thousand to forty thousand euros, or, for a company or undertaking, two to four percent of its total annual worldwide turnover of the preceding financial year, in accordance with Regulation (EU) 2016/679.

Article 106 states that imposing these penalties does not exclude other liabilities under other legislation, including a controller's or processor's liability for damage from unlawful processing and criminal liability under the Criminal Code of the Republic of Kosovo.

What it requires

Sensitive categories

Law No. 06/L-082 on Protection of Personal Data, special categories, children and criminal-offence data

Law No. 06/L-082 on Protection of Personal Data, arts. 7-9 (special categories, children and criminal-offence data)Official Gazette of the Republic of Kosovo (gzk.rks-gov.net), act detail page, full 111-article Albanian text

In force since 12 March 2019. Binds public and private bodies.

What this law does

Article 8(1) prohibits processing personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, health data, or data concerning sex life or sexual orientation.

Article 8(2) lifts that prohibition only under the listed conditions, running from the data subject's explicit consent through employment, social security and social protection law, vital interests, the legitimate activities of a non-profit body processing only its own members' data, data manifestly made public by the data subject, legal claims, substantial public interest, preventive or occupational medicine, public health, and archiving, scientific, historical or statistical purposes.

Article 8(4) requires special categories of personal data to be given heightened protection and to be classified to prevent unauthorised access and use. Article 3, paragraph 1, item 25 separately defines sensitive personal data to include ethnic or racial origin, political or philosophical views, religious affiliation, trade union membership, health data, sex life data, and any entry in or removal from a criminal or misdemeanour record.

The same item adds that biometric characteristics also count as sensitive personal data where they enable identifying a data subject in relation to any of those circumstances.

Article 3, paragraph 1, item 20 defines biometric data as all personal data resulting from specific processing relating to the physical, psychological or behavioural characteristics of a natural person that allows or confirms that person's unique identification, naming visual images and fingerprint, iris, retina, facial-feature and DNA data as examples.

Article 9 confines processing of personal data concerning criminal convictions and criminal offences, or related security measures, to the control of an official authority under the relevant law, and keeps any comprehensive register of criminal convictions solely under an official authority's control.

Article 7 sets the threshold for a child's own consent to an information-society service at sixteen years, and requires the controller to make reasonable efforts, using available technology, to verify that consent was given or authorised by the holder of parental responsibility below that age.

A separate paragraph directs continuing efforts to verify parental or guardian consent specifically between fourteen and sixteen years, without stating how that duty relates to the sixteen-year threshold the same article sets.

What it requires

Scraping law2 instruments, 2 repealed, withdrawn or blocked

Research summary (242 words)

Kosovo has no scraping-specific statute, so general law would govern each dimension separately, and several dimensions are not covered here because a source for them is not available through the official gazette site. The Criminal Code (Law No. 06/L-074) is reported to carry a computer-crime chapter addressing unauthorised access, but its text is not described here, so how it treats scraping a public, unauthenticated page is not established.

No Kosovar court decision on the enforceability of a browsewrap or clickwrap terms of service against a scraper is described here. Kosovo's personal-data protection statute, Law No. 06/L-082 (2019), is covered separately under Kosovo's privacy topic entry and reaches scraped personal data without a general public-availability carve-out.

Kosovo's copyright statute, Law No. 04/L-065 (2011, repealed 2023), set narrow, enumerated limitations on an author's economic rights rather than a general fair-use or text-and-data-mining exception, expressly excluded a full electronic database from its private-copying allowance, and separately created a sui generis database right barring extraction or re-utilisation of a database's substantial contents, or repeated systematic extraction of insubstantial parts, without the producer's authorisation.

That Act was repealed by Law No. 08/L-205 on 12 October 2023, whose own text is not available through the official gazette site, so Kosovo's current copyright and database-right position is not confirmed. No Kosovar statute or reported case described here establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Copyright and text and data mining (TDM)

Law No. 04/L-065 on the Right of the Author and Related Rights, Limitations on Economic Rights

Law No. 04/L-065, ch. IV (limitations of the right of the author)Official Gazette of the Republic of Kosovo (gzk.rks-gov.net), act document page, confirmed live directly (206 articles, Albanian text)

Repealed: no longer in force, effective 15 December 2011. Binds public and private bodies.

What this law does

Kosovo's copyright statute listed narrow, enumerated limitations on an author's economic rights rather than a general fair-use or text-and-data-mining exception. Article 44 permitted a natural person to reproduce up to three copies of a published work for private, non-commercial use, but expressly excluded a full electronic database from that private-copying allowance unless the Act or a contract provided otherwise.

Article 51 permitted free adaptation of a work into parody or caricature that created no confusion with the source, or an adaptation that otherwise fell within a permitted use and a lawful purpose. Article 55 let a database's lawful user freely reproduce or adapt it only to the extent necessary to access its content and to its normal exploitation, voiding any contrary contractual term.

No provision in this chapter created a text-and-data-mining exception or a general privilege to reproduce a work for automated or systematic collection. Law No. 08/L-205 repealed this Act on 12 October 2023; its own text is not available through the official gazette site, so it is not established whether Kosovo's current copyright exceptions differ.

What it requires

Database right

Law No. 04/L-065 on the Right of the Author and Related Rights, Sui Generis Database Right

Law No. 04/L-065, arts. 147-153 (database right)Official Gazette of the Republic of Kosovo (gzk.rks-gov.net), act document page, confirmed live directly (206 articles, Albanian text)

Repealed: no longer in force, effective 15 December 2011. Binds public and private bodies.

What this law does

Kosovo's copyright statute created a sui generis right for a database producer, protected independently of any copyright in the database's contents. Article 148 extended that protection to the whole of a database's contents, to any qualitatively or quantitatively substantial part of it, and to a repeated and systematic extraction or re-utilisation of insubstantial parts that conflicted with the database's normal exploitation or unreasonably prejudiced the producer's legitimate interests.

Article 149 gave the producer the exclusive right to authorise or prohibit reproducing, distributing, renting out, making available, or otherwise communicating the database to the public. Article 150 limited a lawful user to freely using only insubstantial parts of a database's contents and barred any act conflicting with its normal exploitation.

Article 153 set the right's term at fifteen years from the database's completion, or from its first lawful publication within that period, restarting on a substantial new investment in the database's content. Law No. 08/L-205 repealed this Act on 12 October 2023, and its own text is not available through the official gazette site, so it is not established whether Kosovo's current database right differs.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (249 words)

Kosovo's Assembly adopted Law No. 08/L-173 on Cyber Security on 2 February 2023, published in the Official Gazette of the Republic of Kosovo, No. 4/2023, on 27 February 2023, and the law names EU Directive (EU) 2016/1148, the original NIS Directive, as one of the instruments it aligns with.

It binds an operator of essential services, a public or private holder of Kosovo's designated national critical infrastructure, and separately a digital service provider, defined as an online marketplace, an online search engine, or a cloud computing service, each with its own security-measures duty and its own cyber-incident notification duty to the Agency for Cyber Security (ASK), a body the law establishes inside the Ministry of Internal Affairs together with a National CERT.

No product-security-before-market regime comparable to the EU Cyber Resilience Act, and no general reasonable-security baseline statute reaching a business with no sector gate, was found in Kosovo; the exposed-personal-data breach notice duty sits instead in Law No. 06/L-082 on Protection of Personal Data, the privacy topic's own row for this jurisdiction.

Confidence is medium: the Official Gazette's own document viewer for this law serves only a JavaScript-driven shell, so the findings below rest on the government-approved draft that preceded Assembly adoption (Government Decision No. 07/96 of 14 September 2022), corroborated for its institutional facts, the Agency's name, its Ministry placement, and the National CERT, by the enacted law's own Official Gazette metadata page, which lists the same institutions across nine implementing regulations issued between 2023 and 2025.

Sector security regimes

Law No. 08/L-173 on Cyber Security, Security Measures

Law No. 08/L-173 on Cyber Security, Arts. 2, 3, 5 and 7Official Gazette of the Republic of Kosovo, act detail page

In force since 14 March 2023. Binds public and private bodies.

What this law does

Law No. 08/L-173 on Cyber Security requires an operator of essential services, a public or private entity that possesses Kosovo's designated national critical infrastructure, to permanently apply organizational, physical and information-technology security measures to prevent a cyber incident, resolve one, and prevent or mitigate its impact, with the sector-specific measures set by a sub-legal act of the Ministry of Internal Affairs.

A digital service provider, defined as the operator of an online marketplace, an online search engine, or a cloud computing service established or registered in Kosovo, carries a separate duty to identify the risks to its network and information system's security, analyze them, and take adequate organizational and technical measures to manage that risk.

Both duties, and the digital-service definition itself, track the equivalent provisions of the EU's original NIS Directive, (EU) 2016/1148, which the law's own preamble names as an instrument it aligns with. Non-compliance by either class of entity is an administrative infraction (kundërvajtje in the law's own term) rather than a criminal offense, and is enforced by the Agency for Cyber Security's own supervision of compliance.

What it requires

Vulnerability and incident reporting

Law No. 08/L-173 on Cyber Security, Incident Reporting and Enforcement

Law No. 08/L-173 on Cyber Security, Arts. 6, 8 and 24Official Gazette of the Republic of Kosovo, act detail page

In force since 14 March 2023. Binds public and private bodies.

What this law does

An operator of essential services must inform the Agency for Cyber Security of a cyber incident immediately, and no later than twenty-four hours after becoming aware of it, where the incident has a significant impact on system security or service continuity, or where such an impact cannot be ruled out reasonably.

A digital service provider carries a parallel duty to notify the Agency of a cyber incident with a significant impact on its digital service, immediately upon becoming aware of it, without the essential-service operator's explicit twenty-four-hour figure attached to it.

For failing to carry out the Agency's ordered corrective measures after a written warning, the government-approved draft that preceded Assembly adoption set an administrative fine of EUR 15,000 to EUR 30,000 on the non-complying legal entity, a figure stated identically in the draft's Albanian and Serbian text. The fine on the responsible individual within that entity is stated as EUR 1,000 to EUR 1,500 in the draft's Albanian text.

The same provision's Serbian text states EUR 10,000 to EUR 15,000 instead, a discrepancy not resolved against the enacted Official Gazette publication.

What it requires

Age gating law1 instrument, 1 in force

Research summary (138 words)

Kosovo has no social-media minor-access statute, app-store age-verification requirement, or age-appropriate design code.

Its one age-related duty sits in Law No. 04/L-044 on the Independent Media Commission (2012), Article 33, which directs the Independent Media Commission (KPM) to ensure that a program capable of seriously harming a minor's physical, mental or moral development, particularly one with pornographic content or extreme violence, reaches minors only through scheduling or a technical measure, and separately requires a paid audiovisual media service carrying such content to be offered only in a way that ordinarily prevents a minor from seeing or hearing it.

A breach of this duty, like any breach of a broadcaster's license conditions or code of conduct, draws a KPM sanction ranging from a written warning to a fine of EUR 1,000 to EUR 100,000, program suspension, or license revocation.

Adult content age verification (AV)

Independent Media Commission Law, Minor Protection and Age Verification

Law No. 04/L-044 on the Independent Media Commission, arts. 30, 33, 49Official Gazette of the Republic of Kosovo (gzk.rks-gov.net)

In force since 20 April 2012. Binds private bodies.

What this law does

Article 33 of Law No. 04/L-044 on the Independent Media Commission requires the Independent Media Commission (KPM) to take appropriate measures to ensure that broadcasters under its jurisdiction carry no program that could seriously harm a minor's physical, mental or moral development, particularly a program with pornographic content or extreme violence, and to secure the same protection for other potentially harmful programs by choosing the broadcast time or by a technical measure, with an unencoded broadcast of such material required to carry an acoustic warning or a visual symbol for its whole duration.

A paid audiovisual media service that could seriously harm a minor's development is to be made available only in a way that ensures a minor will not, in normal circumstances, see or hear it.

Breach of this or any other license condition or code of conduct draws a KPM sanction under Article 30: a written warning, or one or more of an order to broadcast the nature and extent of the breach, an order to broadcast a correction or apology, a fine of not less than EUR 1,000 and not more than EUR 100,000, suspension of part or all of the licensee's programming for a set period, a change to the license conditions, or non-renewal or revocation of the broadcast license, with the last three not available against the public broadcaster.

Note and primary source

News aggregation law1 instrument, 1 repealed, withdrawn or blocked

Research summary (177 words)

Kosovo has no press-publisher neighbouring right and no compelled platform-to-publisher bargaining code; no statute or reported case addresses whether hyperlinking, framing, or inline display is itself a communication to the public, and no hot-news or misappropriation doctrine distinct from ordinary copyright law exists. The copyright statute predates any machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists either.

The only mechanism reaching an aggregator's reproduction of news content sat in Law No. 04/L-065 on the Right of the Author and Related Rights (2011), which permitted quoting excerpted or complete parts of another's published work for criticism or commentary consistent with good faith and fair dealing, and separately required that the press be permitted to reproduce, communicate, or make available published articles on current economic, political, or religious topics after payment of compensation, unless the rights holder had expressly reserved that use.

Law No. 08/L-205 repealed that Act on 12 October 2023; its own text is not available through the official gazette site, so whether either mechanism survived into the current Act is not established here.

Snippet reproduction

Law No. 04/L-065 on the Right of the Author and Related Rights, Quotation and Press-Article Exceptions

Law No. 04/L-065, arts. 50, 57 (quotations and press articles)Official Gazette of the Republic of Kosovo (gzk.rks-gov.net), act document page, confirmed live directly (206 articles, Albanian text)

Repealed: no longer in force, effective 15 December 2011. Binds public and private bodies.

What this law does

Article 50 permitted using, in one's own work, excerpted parts of another's published work, or the complete published work of another person in the fields of photography, fine arts, industrial design, architecture, applied arts, or cartography, where this concerned criticism or commentary in the user's own work and accorded with the principles of good faith and fair dealing.

Article 57 required that reproduction by the press, communication to the public, or making available to the public of published articles on current economic, political, or religious topics, or of broadcast works, be permitted after payment of appropriate compensation, unless the rights holder had expressly reserved that use.

Law No. 08/L-205 repealed this Act on 12 October 2023; its own text is not available through the official gazette site, so it is not established whether either mechanism continues in the same form.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.