Law / Moldova

Moldova

privacy

Moldova is not a General Data Protection Regulation (GDPR) jurisdiction, and its status is genuinely time-critical. Law No. 195/2024 on Personal Data Protection is dated to take effect 23 August 2026, and its own Article 90(3)(b) repeals the prior Law No. 133/2011 the same date. That date fell one day before this research (2026-08-24), and no source confirms the transition actually landed as opposed to being merely scheduled; WebSearch was unavailable to check further.

This document records Law No. 195/2024 as the operative instrument on the strength of its own stated commencement date, and the repeal of Law No. 133/2011 as dated and immediately recent rather than as independently observed fact. Primary text, read directly, confirms biometric data as an explicit special category naming facial images, a real cross-border transfer regime keyed to a National Centre-maintained adequacy list, a standalone civil damages right, and a 72-hour breach notification duty.

8 instruments named 1 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Comprehensive regime

Law No. 195/2024 on Personal Data Protection

cite Legea Nr. 195 din 25 iulie 2024 privind protectia datelor cu caracter personal, effective 23 August 2026 (Law No. 195 of 25 July 2024) stage In effect since 2026-08-23 source Official statute PDF hosted by datepersonale.md, read in full through crawler infrastructure (169,952 characters, untruncated)

Law No. 195/2024 is Moldova's General Data Protection Regulation (GDPR)-transposing replacement for Law No. 133/2011, dated to take effect 23 August 2026 under its own terms, with Article 90(3)(b) repealing Law No. 133/2011 the same date. That date is one day before this research and the transition was not independently confirmed to have actually occurred; this instrument is recorded as in effect on the strength of the statute's own stated date, not on independent confirmation the transition landed.

Primary text, read in full through crawler infrastructure, confirms biometric data as an explicit special category naming facial images as a qualifying example, a real cross-border transfer regime keyed to a National Centre for Personal Data Protection adequacy list with an approved standard-transfer-agreement alternative, a standalone civil damages right, and a breach notification duty to the National Centre within 72 hours where feasible.

Publicly available data is not generally exempted from the law's scope; only data a subject voluntarily and manifestly made public themselves is exempted from certain disclosure restrictions, a narrow exception rather than a blanket carve-out.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.