en

 

Society
07 October, 2026 / 01:32
/ 23 August, 2026

New rules on personal data protection enter into force in Moldova as of August 23

Moldova will apply, starting on August 23, 2026, a new legal framework in the field of personal data protection, based on Law No. 195/2024 on the protection of personal data and Law No. 160/2026 on data processed on the purpose of preventing and combating crimes. According to the National Center for Personal Data Protection, the new legislation should not be viewed primarily through the lens of sanctions, but rather through responsibility, caution and risks’ prevention.

According to the institution, the new rules put the natural person and his/her rights at the center. Data controllers must know what information they collect, for what purpose they use it, how long they keep it and what measures they apply to protect it.

Responsibility begins before an inspection

One of the fundamental principles of the new framework is the principle of accountability. Organizations and institutions must know their data processing procedures, identify potential risks and establish internal rules and procedures to mitigate them.

The authorities draw attention to the fact that compliance with legislation should not start after a complaint, an inspection or a security incident occurs. Prevention must be the first step.

Law No. 195/2024 was adopted in July 2024 and provided for a two-year transition period, giving organizations the necessary time to adapt their internal procedures and measures.

No more data should be collected than necessary

“The new provisions also emphasize the principle of data minimization. Organizations must collect only the information they need, use it for specific purposes and protect it appropriately. In this regard, seemingly simple measures – strong passwords, limiting access to information, updating IT systems and training employees – can significantly reduce risks,” says the National Center for Personal Data Protection.

According to the supervisory authority, the law does not require every organization to make costly investments in sophisticated systems. What matters is that controllers know what data they hold, the purpose for which they use it and how it must be protected.

People must know what happens to their data

Another important element is informing the individuals whose data is processed.

They must receive clear and accessible information about the data collected, the purposes of processing, the storage period and the rights they have.

Thus, data protection becomes not only a legal obligation, but also an element of trust between institutions, companies and citizens.

Fines are not the purpose of the law

The National Center for Personal Data Protection underlines that the new legislation is not built around fines.

The law provides for corrective measures and sanctions in case of infringements, but the finding of a violation does not automatically mean that a fine will be imposed. The legal framework allows, among other things, the issuance of corrective prescriptions and establishes a gradual mechanism, as well as criteria for determining the amount of any sanctions.

“Sanctions represent a liability mechanism, not the purpose of the law,” the authority notes, emphasizing that the main goal is for personal data to be processed lawfully, transparently, securely and responsibly.

In the context, the Center also reaffirms its role as an institution that informs, guides and supports organizations and citizens in applying the new rules.

The authority announces that it provides explanatory materials, organizes training sessions and events dedicated to the new provisions and promotes a risk-based approach.

In essence, the new data protection framework shifts the focus from reacting after a problem occurs to preventing it. And the message from the authorities is clear: data protection should not be seen as an administrative burden, but as an investment in safety and in people’s trust.