Law of the Republci of Moldova No. 195/2024 on Personal Data Protection - Legal Requirements for Businesses - Company Checklist
Any organization in Moldova (regardless of size) that collects, stores, or processes data belonging to clients, employees, or partners must adjust its processes:
Subject and Required Actions
1) Documentation
Develop a clear Privacy Policy and a cookie usage policy for websites.
2) Processing Principles
Collect only the data strictly necessary for operations (data minimization) and do not retain it beyond the required period.
3) Security
Implement technical safeguards: database access controls, encryption, and regular backups.
4) Breach Notification
In the event of a cyberattack or data breach, the company is required to promptly notify regulatory authorities and the affected users.
5) DPO Appointment
Companies engaged in large-scale data processing (e.g., banks, clinics, large online retailers) are required to appoint a Data Protection Officer (DPO).
THE LEGAL BASIS OF THE REPUBLIC OF MOLDOVA
Law No. 160/2026 on the protection of personal data processed for the purposes of preventing and combating crime (info soon)
Personal data protection - the regulatory framework of the Republic of Moldova
THE LEGAL BASIS OF THE EU
- Regulation (EU) 2016/679 General Data Protection Regulation (GDPR)
- GDPR - Your rights over your personal data protection
- Regulation (EU) 2018/1725 on Personal Data Processing by EU institutions (EUDPR)
- Directive (ЕС) 2016/680 Personal Data Protection by competent authorities (GDPR-LED)
- Directive 2002/58/EC on privacy and electronic communications (ePrivacy Directive)



