Law No. 06/L-082 on Protection of Personal Data, remedies, the Agency, inspections and penalties
Law No. 06/L-082 on Protection of Personal Data arts. 52-72, 91-107 (remedies, the supervisory Agency, inspections, and administrative and criminal penalties)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 12 March 2019.
An enforcement supervision rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Expect a data subject to be able to complain to the Agency for Information and Privacy that your processing breaches this law, and to pursue judicial remedy against you, against the Agency's decision, or against the Agency's failure to act within three months.
- Expect a representative body, organisation or non-profit association active in data protection to be able to lodge a complaint, pursue judicial remedy, or claim compensation on a data subject's behalf.
- Expect joint and several liability with every other controller or processor involved in the same processing for compensating a person's material or non-material damage from a breach of this law, unless you prove you bear no responsibility for it.
- Cooperate with an Agency inspection, including giving inspection officers access to documentation, computers, equipment and premises relevant to personal data processing.
- Comply with a corrective order an inspection officer issues, which can require correcting irregularities, destroying, blocking or anonymising personal data, temporarily halting unlawful processing, or fulfilling a data subject's rights request.
- Expect an administrative fine set according to the nature, gravity and duration of a violation, whether it was intentional or negligent, the categories of data affected, and your degree of cooperation with the Agency, ranging up to forty thousand euros for a general violation or, for a serious and large-scale violation by a company, up to four percent of your total annual worldwide turnover.
- Expect the total fine for several violations arising from the same or related processing to be capped at double the highest single fine this law sets.
- Expect criminal liability under the Criminal Code of the Republic of Kosovo on top of any administrative fine, since Article 106 preserves it separately.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
This law's own Chapter XXI (arts. 91-105) sets administrative fines only, from EUR 200 up to EUR 40,000, or up to 4 percent of a company's total worldwide annual turnover for a serious and large-scale violation (art. 105). Article 106 separately preserves criminal liability for the same conduct under the Criminal Code of the Republic of Kosovo, without stating the offences or penalties itself.
Penalty structure
Article 105 lets the Agency fine a serious, large-scale violation EUR 20,000 to 40,000, or for a company or undertaking, 2 to 4 percent of total annual worldwide turnover of the preceding financial year, referencing Regulation (EU) 2016/679. Articles 92 to 104 set narrower, provision-specific fine tiers for legal persons, responsible individuals, state-body officials and individuals ranging from EUR 200 to 40,000, capped at double the highest single fine where several provisions are violated by the same conduct (art. 91(2)). Article 106 preserves separate criminal liability under the Criminal Code of the Republic of Kosovo, not detailed in this Law.
- Rule
- Higher of
- As of
- 19 September 2026
- Currency
- EUR
- Fixed cap
- 40,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
Information and Privacy Agency (Agjencia per Informim dhe Privatesi), led by a Commissioner elected by the Assembly of Kosovo
What it reaches
Obligation class
Governance, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 52 gives a data subject the right to complain to the Agency for Information and Privacy that processing of their personal data breaches this law, without prejudice to other administrative or judicial remedies.
Articles 53 and 54 give a person a right to an effective judicial remedy against a legally binding Agency decision, against the Agency's failure to handle or report on a complaint within three months, and against a controller or processor whose processing the person believes has violated their rights.
Article 55 lets a data subject authorise a representative body, organisation or non-profit association active in data protection to lodge a complaint, exercise judicial remedies, and claim compensation on their behalf.
Article 56 gives any person who has suffered material or non-material damage from a breach of this law the right to compensation from the controller or processor, holds every controller and processor involved in the same processing jointly liable to guarantee effective compensation, and excuses a controller or processor that proves it bears no responsibility for the damage.
Article 57 establishes the Agency for Information and Privacy as an independent authority responsible for overseeing this law, answerable to the Assembly of Kosovo, acting free from external influence and taking instructions from no one.
Article 58 places the Agency under a Commissioner elected by the Assembly of Kosovo for a five-year term, renewable once, and Article 61 lists the grounds on which the Commissioner's mandate ends, including resignation, a criminal conviction carrying more than six months' imprisonment, or dismissal by the Assembly for breaching this law.
Articles 64 and 65 give the Agency its core duties, including supervising this law's implementation, advising public and private bodies, deciding complaints, conducting inspections, and cooperating with other supervisory authorities in Kosovo and abroad. Articles 68 to 70 let the Agency conduct inspections and controls on its own initiative or on a complaint, and let inspection officers examine and seize documentation, computers and equipment relevant to personal data processing.
Article 71 lets an inspection officer who finds a violation order the correction of irregularities, including destruction, blocking or anonymisation of personal data, temporarily halt unlawful or non-compliant processing, order compliance with a data subject's rights request, impose a fine for violations of this law, or issue a written warning for minor violations.
Article 91 sets the criteria the Agency weighs in fixing an administrative fine, including the nature, gravity and duration of the violation, whether it was intentional or negligent, the categories of personal data affected, the degree of cooperation with the Agency, and any prior relevant violation.
Article 92 fines a legal person or independent-activity person twenty thousand to forty thousand euros for a general violation such as processing without a lawful basis or consent, unlawfully processing special categories or criminal-offence data, or failing to inform a data subject, with lower tiers set for a responsible individual within that legal person, a responsible individual within a state body, and an individual acting alone.
Articles 93 to 104 set separate fine tiers for violations of the contracted-processing, security, direct-marketing, video-surveillance, biometric, building-entry-log, filing-system-interconnection and Data Protection Officer rules, ranging from two hundred to forty thousand euros depending on the provision and the offender's category.
Article 105 lets the Agency fine a serious and large-scale violation of personal data provisions twenty thousand to forty thousand euros, or, for a company or undertaking, two to four percent of its total annual worldwide turnover of the preceding financial year, in accordance with Regulation (EU) 2016/679.
Article 106 states that imposing these penalties does not exclude other liabilities under other legislation, including a controller's or processor's liability for damage from unlawful processing and criminal liability under the Criminal Code of the Republic of Kosovo.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbothigh_risk_decisionsis_listed_company
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.