Skip to main content
Since 23 August 2026, Law No. 195/2024 on the Protection of Personal Data has been in force in the Republic of Moldova.

More Control Over Your Personal Data: What Moldova’s New Data Protection Law Means for Citizens

22/09/2026

Since 23 August 2026, Law No. 195/2024 on the Protection of Personal Data has been in force in the Republic of Moldova. The new law aligns Moldova’s data protection framework with the standards of the European Union’s General Data Protection Regulation (GDPR) giving citizens greater control over how their personal information is collected, stored and used.

Personal data is not limited to the information on your ID card. Your name, phone number, email address, photo, location, purchase history, medical records or payment information can be used to identify you — and this information must be protected.

What is changing?

Organisations must explain how they use personal data

Companies and institutions that collect personal data must clearly inform people:

  • what information they collect;
  • why they collect and use it;
  • who they share it with;
  • how long they keep it;
  • what rights the person concerned has.

The law does not set one standard retention period for all types of data. Each organisation must establish a justified retention period for each category of information. Once the purpose for processing the data no longer exists and there is no legal obligation to retain it, the data must be deleted or anonymised.

For example, information needed to deliver an order may be kept for as long as necessary to fulfil the contract and meet accounting requirements. A CV may be deleted after the recruitment process if the person has not agreed to have it kept for consideration for other positions.

Citizens can request access, correction or deletion

The new law strengthens every person’s right to know what personal data an organisation holds about them and how it is being used.

Citizens can request:

  • access to their personal data;
  • correction of inaccurate information;
  • deletion of their data where provided for by law;
  • restriction of how their data is used;
  • a copy of their data in an accessible format;
  • an end to the use of their data for direct marketing.

As a rule, an organisation must respond within one month. For complex or numerous requests, the deadline may be extended, but the person must be informed.

Greater protection from unwanted advertising

For email newsletters and advertising, companies and organisations must be able to demonstrate that a person gave their consent freely, clearly and for a specific purpose.

People must be able to withdraw their consent as easily as they gave it. They can also object at any time to the use of their data for direct marketing. Once someone unsubscribes or withdraws their consent, the company must stop sending commercial messages.

Buying a product or registering for an event does not automatically mean that a person has agreed to receive advertising.

What happens if personal data ends up where it shouldn’t?

An email sent to the wrong person, a lost laptop, unauthorised access to an account or the accidental publication of a database can all constitute security incidents, also known as data breaches.

Organisations must contain the incident, assess its impact and reduce the associated risks. If the incident could affect people’s rights and freedoms, it must be reported to the National Centre for Personal Data Protection without undue delay and, where possible, within 72 hours.

Where the risk to affected individuals is high, they must also be informed clearly so that they can take protective measures, such as changing their passwords or blocking a bank card.

Protection also applies to automated decision-making

The law also applies when personal data is analysed using artificial intelligence tools, profiling or other automated systems.

In certain cases, if a decision is made solely by automated means, produces legal effects or significantly affects a person, they may request human intervention, express their point of view and challenge the decision.

Law No. 195/2024 is not a general law on artificial intelligence. However, it protects citizens when such technologies process their personal data.

Trust starts with respecting personal data

Bringing Moldova’s data protection framework in line with European standards means greater transparency for citizens and greater accountability for organisations.

People who believe their personal data is being used improperly can first contact the company or institution responsible. If the issue is not resolved, they can file a complaint with the National Centre for Personal Data Protection or take the matter to court.

Protecting personal data is, above all, about respecting people, their choices and their right to remain in control of information about them.

10 tips for protecting your personal data

1. Ask why your data is needed

Before filling in a form, check who is collecting the information, why they need it and how long they will keep it.

2. Provide only the information that is necessary

If you are asked for information that does not appear necessary for the service being provided, ask why it is needed.

3. Read before giving your consent

Don’t automatically tick every box. Consent to receive advertising should be clear and separate from accepting a service.

4. Use different passwords

Choose long, unique passwords for important accounts. Turn on two-factor authentication where available.

5. Don’t send sensitive data through insecure channels

Avoid sending photos of identity documents, banking details or medical information through ordinary messaging services if there is a safer way to share them.

6. Check the messages and links you receive

Don’t provide personal information just because a message seems urgent. Check the sender and website address before entering any information.

7. Review app permissions

Regularly check which apps have access to your location, contacts, camera and microphone. Disable permissions they do not need.

8. Unsubscribe from unwanted messages

You can withdraw your consent or object at any time to the use of your data for direct marketing.

9. Ask what data is held about you

You can ask a company what personal data it stores, why it uses it, who it shares it with and how long it will keep it. As a rule, you should receive a response within one month.

10. Take action if you spot a problem

First contact the organisation concerned and keep a record of your request and their response. If the issue is not resolved, you can file a complaint with the NCPDP or take the matter to court.

The simple rule: Provide only the data you need to, check where it goes, and use your rights whenever something is unclear.

Latest opportunities