Law / Moldova

Moldova Law No. 195/2024, personal data breach notification

Legea Nr. 195 din 25 iulie 2024, articolele 33-34 (notificarea incalcarii securitatii datelor)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force 28 days, effective 23 August 2026.

A breach notification rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • Notify the National Centre for Personal Data Protection without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Moldova, unless the breach is unlikely to risk their rights and freedoms.
  • Communicate the breach to the affected data subject without undue delay where it is likely to result in a high risk to their rights and freedoms, in clear and plain language.
  • As a processor, notify the controller without undue delay after becoming aware of a personal data breach.
  • Put in the notification the nature of the breach, including where possible the categories and approximate number of data subjects and of records concerned, the contact point, the likely consequences and the measures taken to address it and mitigate its effects.

What it reaches

Obligation class

Breach notice, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 33(1) requires the controller, in the case of a personal data breach, to notify it to the National Centre for Personal Data Protection without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons, and to accompany a later notification with reasons for the delay.

Article 33(2) requires the processor to notify the controller without undue delay after becoming aware of a breach.

Article 33(3) fixes what the notification must contain: the nature of the breach including, where possible, the categories and approximate number of data subjects and of personal data records concerned, the name and contact details of the data protection officer or other contact point, the likely consequences, and the measures taken or proposed to address it and mitigate its adverse effects.

Article 34(1) requires the controller to communicate the breach to the data subject without undue delay where it is likely to result in a high risk to the rights and freedoms of natural persons, in clear and plain language, and article 34(3) excuses that communication only where protective measures such as encryption render the affected data unintelligible, where subsequent measures make the high risk no longer likely, or where it would involve a disproportionate effort and a public communication of equal effect is made instead.

Article 89(1) enters the Law into force on the expiry of 24 months from the date of its publication in the Official Gazette of the Republic of Moldova. The Law's front matter dates that publication 23 August 2024, so these provisions bind from 23 August 2026.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • operates_essential_service

Read the law

Official statute PDF hosted by datepersonale.md, read in full (169,952 characters, untruncated)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app