Law note · Kosovo

Law No. 06/L-082 on Protection of Personal Data

cite Law No. 06/L-082 on Protection of Personal Data (Albanian: Ligji Nr. 06/L-082 per Mbrojtjen e te Dhenave Personale) stage In effect since 2019-02-25 reviewed 2026-08-24

Kosovo has a comprehensive, General Data Protection Regulation (GDPR)-modeled data protection statute, Law No. 06/L-082 on Protection of Personal Data, published in the Official Gazette of the Republic of Kosovo, No. 6, on 25 February 2019 and confirmed still operative with no repeal or supersession found. Lawful bases for processing mirror the GDPR six grounds per secondary commentary, though the specific enabling articles were not independently confirmed against primary text in this research.

The law binds private and public bodies alike, with extraterritorial reach to controllers outside Kosovo using automated means located in Kosovo.

Practitioner sources state the law became applicable on 13 February 2019, eight days before the Gazette's own publication date; this discrepancy could not be reconciled against the law's own final-provisions article in this research, and `effective_date` is recorded as the independently confirmed 25 February 2019 Gazette publication date rather than the uncorroborated 13 February figure, pending confirmation of the final article against the Gazette text.

Article 8 of the law restricts processing of special categories of personal data, including biometric data used for unique identification, on a lead from general search rather than a page this research quoted directly; the article number should be treated as unconfirmed pending a primary-text re-read.

Data subject rights of access, rectification, erasure and restriction of processing, and objection to direct marketing, are confirmed present, exercisable against controllers, with a right to complain to the Information and Privacy Agency (IPA) and a right to effective judicial remedy against controllers or processors.

Cross-border transfer to IPA-assessed adequate countries, an approved list reported to include the EU/EEA states plus Canada, Israel, Switzerland, Japan, and the United Kingdom, proceeds without special authorization if data subjects are informed; transfers elsewhere require safeguards, though the specific enabling article was not confirmed against primary text.

Controllers must notify the IPA within 72 hours of discovering a breach unless there is no risk to data subjects, and notify data subjects without undue delay for high-risk breaches, per practitioner-tracker reporting not yet pinned to primary text.

The IPA is Kosovo's independent supervisory authority for both data protection and access-to-documents law; fines are reported to range from EUR 400 to EUR 40,000 depending on severity and offender type, reaching up to 2 percent of annual turnover for companies in serious cases, also not yet confirmed against primary text. Whether the regime covers or carves out publicly available personal data outside the special-category context was not established by any source found in this research.

The law's own biometric data definition, Article 1.20, reads in Albanian "si dhe imazhet pamore" ("as well as visual images"), confirmed by direct crawler fetch of the Official Gazette's own act text: an identifier derived from a photograph or video recording falls squarely inside the definition, and nothing in it excludes a recording-derived identifier.

What it asks of an app

  • Establish a lawful basis before processing personal data of a person in Kosovo, and expect the law to reach a controller outside Kosovo that uses automated means located in Kosovo.
  • Where you deploy a biometric device or system in Kosovo, public or private sector, use it only where essential for the security of individuals, the protection of property, or the safeguarding of confidential or business secrets, and only if that cannot be achieved by other means, informing data subjects in writing beforehand.
  • Treat an identifier your system derives from a photograph or video of a person in Kosovo, such as a faceprint, as covered biometric data under Article 1.20's definition, which names visual images expressly and excludes nothing recording-derived.
  • Honor a person's request for access, rectification, erasure, restriction of processing, or objection to direct marketing, and expect them to be able to complain to the Information and Privacy Agency or pursue judicial remedy.

When LexLint raises it

Declared activities: processes_biometrics, high_risk_decisions, deploys_chatbot, automated_outreach

Primary source: Official Gazette of the Republic of Kosovo (gzk.rks-gov.net), act detail page, confirmed live via direct crawler fetch (111 articles, Albanian text)
DLA Piper Data Protection Laws of the World tracker and Kosovo law-firm commentary as corroborating leads

← Back to the example  ·  Lint your app →