Law note · Albania
Law No. 124/2024 On the Protection of Personal Data
Law No. 124/2024 replaced the pre-General Data Protection Regulation (GDPR) Law No. 9887/2008 and, per IAPP, KPMG, ARS Firm and EY commentary, transposes GDPR-style lawful bases and controller and processor duties, though this research did not independently confirm the lawful-basis article against primary text.
Primary text confirms biometric data, including facial images, as an explicit special category, a real cross-border transfer regime requiring adequate protection or specific safeguards, and a standalone civil damages right under Article 88, separate from the administrative complaint route to the Commissioner for the Right to Information and Personal Data Protection.
A breach notification deadline and the full data-subject-rights response timeline were not located in this research; KPMG reports some articles phase in over up to two years from the effective date, without naming which.
What it asks of an app
- Establish a lawful basis and allocate controller and processor duties before processing personal data of a person in Albania under Law No. 124/2024.
- Obtain a lawful basis, such as explicit consent, before capturing or storing a biometric identifier, including a faceprint, of a person in Albania; the law names biometric data an explicit special category.
- Rely on an adequacy finding or a specific safeguard, and appoint a local representative if you are a foreign controller or processor, before transferring personal data of a person in Albania out of the country.
- Expect a person in Albania to have both an administrative complaint route to the Commissioner and a separate civil damages claim under Article 88 for any infringement of this law.
When LexLint raises it
Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics