What Is Law no. 195/2024 on personal data protection?
The Republic of Moldova’s operative general privacy statute is Law no. 195/2024 on personal data protection. It was adopted on 25 July 2024, published on 23 August 2024, and became effective on 23 August 2026 after a 24-month commencement period. It repealed Law no. 133/2011 and related former contravention provisions. Moldova remains an EU-candidate country, not an EU member, and the law expressly transposes GDPR domestically as a national alignment reform rather than applying GDPR directly. The independent National Center for Personal Data Protection (CNPDCP) is the supervisory authority. A separate Law no. 160/2026 governs competent-authority processing for crime prevention, investigation, prosecution, and sanctions, and the official legislative trail identifies it as affecting Article 86(1) of Law no. 195/2024. The framework has an unusually detailed complaint timeline, including a 30-day preliminary examination, an investigation period of up to six months with justified extensions capped at 12 months, and final-decision communication within 10 working days. No Moldova-specific data-broker route, broker registry, public-record deletion process, or dedicated broker complaint channel was located, so the current general route is through controller rights and CNPDCP complaints.
At a glance
- Full name
- Law no. 195/2024 on personal data protection
- Short code
- Law no. 195/2024
- Jurisdiction
- Republic of Moldova
- Enacted
- 2024
- Last major update
- Became effective on 23 August 2026 after its 24-month commencement period; Law no. 160/2026 affects Article 86(1); no later amendment was located in the reviewed materials
- Regulator
- National Center for Personal Data Protection (CNPDCP)
- Private right of action
- Yes
- Statutory citation
- Law no. 195/2024 on personal data protection
Scope, who Law no. 195/2024 covers
Protected data
Data subject rights
Right to transparent and accessible communications
Right to information about processing and processing details
Right of access and copy
Right to rectification
Right to erasure and to be forgotten, subject to statutory exceptions
Right to restriction of processing
Right to notification of recipients
Right to data portability for qualifying automated consent- or contract-based processing
Right to object, including an unconditional objection to direct marketing
Right to protection against specified automated decisions
Right to withdraw consent at any time without making prior processing unlawful retroactively
Right to complain to the CNPDCP
Right to bring court action against a controller or processor and seek compensation
Controller response period of one month, extendable by two months for complexity or volume with reasons communicated within the first month
Notable features
The law became operative on 23 August 2026, making currentness an unusually sensitive issue. It provides a GDPR-aligned rights framework, a detailed multi-stage CNPDCP complaint procedure, and a genuine phased-fine schedule of 10%, 40%, and 100% across the first three years. Moldova-specific data-broker and public-record deletion mechanisms were not located.
Enforcement & penalties
Regulator: National Center for Personal Data Protection (CNPDCP)
Penalties: Specified controller, processor, certification-body, and monitoring-body violations may attract up to 1,000,000 lei, or 1% of prior-year turnover for an enterprise, whichever is higher. Breaches of processing principles, consent requirements, data-subject rights, international-transfer rules, Chapter VI duties, access failures, or CNPDCP orders and restrictions may attract up to 2,000,000 lei, or 2% of prior-year turnover, whichever is higher. Under Article 90(4), fines apply at 10% in year 1, 40% in year 2, and 100% from year 3; because the law became effective on 23 August 2026, current enforcement is likely still in the reduced-fine window. Warnings may be used for minor or disproportionate cases.
Private right of action: Article 74 provides court action against a controller or processor, and Article 76 provides compensation. Article 73 provides a direct court-challenge trigger after three months without examination or progress information from the CNPDCP. No special fixed filing deadline for the court action was located.
Relevance to data brokers
No Moldova-specific "data broker" route, broker registry, public-record deletion process, or dedicated broker complaint channel was located. The general route is to exercise Articles 15-18 rights against the controller and then complain to the CNPDCP under Article 72. Article 52 addresses public-document processing, but no dedicated public-record-specific deletion or complaint mechanism was located.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Is Moldova’s personal-data law currently in force?+
Yes. Law no. 195/2024 became effective on 23 August 2026 after its 24-month commencement period. It repealed Law no. 133/2011, and its current text should be checked against the live official materials because its commencement date was 23 August 2026.
How long does the CNPDCP have to examine a complaint?+
The preliminary examination period is 30 days from registration. An investigation may last up to six months, with justified monthly extensions capped at 12 months from initiation, and the final decision must be communicated within 10 working days after issuance.
Does Moldova have a dedicated data-broker deletion route?+
Not located. The reviewed materials identify the general Articles 15-18 rights against a controller and a complaint to the CNPDCP, but no Moldova-specific data-broker route, broker registry, public-record deletion process, or dedicated broker complaint channel.
Official sources & citations
Other international privacy regimes
Law no. 195/2024 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
