Law / Albania

Law No. 124/2024, notification of a personal data breach

Law No. 124/2024, Art. 29 (notification of a personal data breach)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 31 January 2025.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Notify the Commissioner of a personal data breach as soon as possible and no later than 72 hours of becoming aware of the breach, unless the breach is unlikely to endanger the rights and freedoms of data subjects, and give the Commissioner your reasons for any later notification.
  • As a processor, notify the controller immediately after becoming aware of any personal data breach.
  • Describe in the notification to the Commissioner the nature of the breach, including where possible the categories and approximate number of data subjects and personal data records concerned, the data protection officer's or other contact point's details, the likely consequences, and the measures taken or proposed, supplying anything you cannot give at once as soon as possible afterward.
  • Document every personal data breach, its facts, its effects, and the corrective measures taken, so the Commissioner can verify compliance.
  • From two years after the law's publication in the Official Gazette, inform the data subject of a personal data breach likely to result in a high risk to their rights and freedoms, unless an exception for encryption, other risk reducing measures, or a disproportionate-effort public notice applies; until then this Article 29(3) duty does not itself bind, though the Commissioner may already order you to notify the data subject case by case under Article 29(7).

What it reaches

Obligation class

Breach notice, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 29(1) requires the controller to notify the Commissioner of a personal data breach as soon as possible and no later than 72 hours after becoming aware of it, unless the breach is unlikely to endanger the rights and freedoms of data subjects, and to give the Commissioner the reasons for any later notification. Article 29(2) requires a processor to notify the controller immediately after becoming aware of any personal data breach.

Article 29(4) requires the notification to the Commissioner to describe the nature of the breach, including where possible the categories and approximate number of data subjects and personal data records concerned, the data protection officer's or other contact point's details, the likely consequences, and the measures taken or proposed, and Article 29(5) lets information that cannot all be given at once follow as soon as possible afterward.

Article 29(6) requires the controller to document every personal data breach, its facts, its effects, and the corrective measures taken, so the Commissioner can verify compliance.

Article 29(3) requires the controller to inform the data subject of a breach likely to result in a high risk to their rights and freedoms, subject to exceptions for encryption, other risk reducing measures, or a public notice where individual notice would be disproportionate, but this paragraph does not itself bind until two years after the law's publication in the Official Gazette under Article 101(2).

Article 29(7) already lets the Commissioner order the controller to notify the data subject of a high risk breach case by case, so a request that never reaches the data subject can still draw a Commissioner order before the standalone Article 29(3) duty takes effect.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics

Read the law

Official statute PDF hosted by the Commissioner for the Right to Information and Personal Data Protection (idp.al)
read in full (169,825 characters, untruncated)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app