Law / Kosovo

Kosovo

privacy

Kosovo has a comprehensive, General Data Protection Regulation (GDPR)-modeled data protection statute, Law No. 06/L-082 on Protection of Personal Data (2019), with no prior privacy-topic research on record for this jurisdiction before this research.

Special categories of personal data, including biometric data used for unique identification, carry a heightened, necessity-based restriction reaching both public and private actors: the statutory definition names visual images and facial features expressly, so an identifier derived from a photograph or video recording is squarely covered, while no source names voice or audio-derived identifiers specifically, an open question this research narrows but does not resolve.

Confidence is medium, not high: most article-level findings below rest on secondary commentary rather than an independently read primary quote, though the Official Gazette's own act-detail page was confirmed live and readable in full (111 articles) through a direct crawler fetch, unlike the PDF mirrors that defeated earlier attempts, so a deeper primary-text read remains possible for a future pass.

1 instruments named 1 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Comprehensive regime

Law No. 06/L-082 on Protection of Personal Data

cite Law No. 06/L-082 on Protection of Personal Data (Albanian: Ligji Nr. 06/L-082 per Mbrojtjen e te Dhenave Personale) stage In effect since 2019-02-25 source Official Gazette of the Republic of Kosovo (gzk.rks-gov.net), act detail page, confirmed live via direct crawler fetch (111 articles, Albanian text)

Kosovo has a comprehensive, General Data Protection Regulation (GDPR)-modeled data protection statute, Law No. 06/L-082 on Protection of Personal Data, published in the Official Gazette of the Republic of Kosovo, No. 6, on 25 February 2019 and confirmed still operative with no repeal or supersession found. Lawful bases for processing mirror the GDPR six grounds per secondary commentary, though the specific enabling articles were not independently confirmed against primary text in this research.

The law binds private and public bodies alike, with extraterritorial reach to controllers outside Kosovo using automated means located in Kosovo.

Practitioner sources state the law became applicable on 13 February 2019, eight days before the Gazette's own publication date; this discrepancy could not be reconciled against the law's own final-provisions article in this research, and `effective_date` is recorded as the independently confirmed 25 February 2019 Gazette publication date rather than the uncorroborated 13 February figure, pending confirmation of the final article against the Gazette text.

Article 8 of the law restricts processing of special categories of personal data, including biometric data used for unique identification, on a lead from general search rather than a page this research quoted directly; the article number should be treated as unconfirmed pending a primary-text re-read.

Data subject rights of access, rectification, erasure and restriction of processing, and objection to direct marketing, are confirmed present, exercisable against controllers, with a right to complain to the Information and Privacy Agency (IPA) and a right to effective judicial remedy against controllers or processors.

Cross-border transfer to IPA-assessed adequate countries, an approved list reported to include the EU/EEA states plus Canada, Israel, Switzerland, Japan, and the United Kingdom, proceeds without special authorization if data subjects are informed; transfers elsewhere require safeguards, though the specific enabling article was not confirmed against primary text.

Controllers must notify the IPA within 72 hours of discovering a breach unless there is no risk to data subjects, and notify data subjects without undue delay for high-risk breaches, per practitioner-tracker reporting not yet pinned to primary text.

The IPA is Kosovo's independent supervisory authority for both data protection and access-to-documents law; fines are reported to range from EUR 400 to EUR 40,000 depending on severity and offender type, reaching up to 2 percent of annual turnover for companies in serious cases, also not yet confirmed against primary text. Whether the regime covers or carves out publicly available personal data outside the special-category context was not established by any source found in this research.

The law's own biometric data definition, Article 1.20, reads in Albanian "si dhe imazhet pamore" ("as well as visual images"), confirmed by direct crawler fetch of the Official Gazette's own act text: an identifier derived from a photograph or video recording falls squarely inside the definition, and nothing in it excludes a recording-derived identifier.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.