Law note · Moldova

Law No. 195/2024 on Personal Data Protection

cite Legea Nr. 195 din 25 iulie 2024 privind protectia datelor cu caracter personal, effective 23 August 2026 (Law No. 195 of 25 July 2024) stage In effect since 2026-08-23 reviewed 2026-08-24

Law No. 195/2024 is Moldova's General Data Protection Regulation (GDPR)-transposing replacement for Law No. 133/2011, dated to take effect 23 August 2026 under its own terms, with Article 90(3)(b) repealing Law No. 133/2011 the same date. That date is one day before this research and the transition was not independently confirmed to have actually occurred; this instrument is recorded as in effect on the strength of the statute's own stated date, not on independent confirmation the transition landed.

Primary text, read in full through crawler infrastructure, confirms biometric data as an explicit special category naming facial images as a qualifying example, a real cross-border transfer regime keyed to a National Centre for Personal Data Protection adequacy list with an approved standard-transfer-agreement alternative, a standalone civil damages right, and a breach notification duty to the National Centre within 72 hours where feasible.

Publicly available data is not generally exempted from the law's scope; only data a subject voluntarily and manifestly made public themselves is exempted from certain disclosure restrictions, a narrow exception rather than a blanket carve-out.

What it asks of an app

  • Establish a lawful basis and allocate controller and processor duties before processing personal data of a person in Moldova.
  • Obtain explicit consent or another enumerated exception before processing biometric data, including facial images, of a person in Moldova for unique identification.
  • Rely on the National Centre for Personal Data Protection's adequacy list or an approved standard transfer agreement before transferring personal data of a person in Moldova outside the country.
  • Notify the National Centre for Personal Data Protection without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Moldova, unless the breach is unlikely to risk their rights and freedoms.
  • Expect a person in Moldova to have a court-enforceable damages claim for material or non-material harm from an infringement of this law, separate from a complaint to the National Centre.

When LexLint raises it

Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics

Primary source: Official statute PDF hosted by datepersonale.md, read in full through crawler infrastructure (169,952 characters, untruncated)

← Back to the example  ·  Lint your app →