September 11, 2026

Understanding Moldova beyond the headlines

September 11, 2026

Understanding Moldova beyond the headlines

Moldova Explained

Moldova’s GDPR moment: what Law 195/2024 means for business

On 23 August 2026, Moldova’s new personal data protection law — Law No. 195/2024 — enters into force. It replaces the older 2011 law and brings Moldova much closer to the EU’s GDPR rules.

For businesses, this is more than a legal update. It means new duties, new costs, and new risks — but also a clearer and more familiar rulebook for companies that already work under GDPR-style standards.

What changes

The new law applies to personal data processing in Moldova, and in some cases to foreign companies too. If a company outside Moldova offers goods or services to people in Moldova, or monitors their behavior online, it can fall under the law.

The main idea is simple: companies must now show that they are handling data properly. That means keeping records, checking high-risk processing, protecting data, and answering requests from individuals in a set time.

The law also gives people stronger rights. They can ask to see, correct, delete, or move their data. Companies must also report many breaches to the National Center for Personal Data Protection, usually within 72 hours.

Consent rules are stricter too. Consent must be clear, specific, informed, and freely given. Pre-ticked boxes and bundled consent are no longer enough.

Fines and transition

The law is being introduced in stages. That gives businesses time to adjust before the full penalty regime applies.

Period Maximum applicable fine
23 Aug 2026 – 22 Aug 2027 Up to 10% of calculated fine
23 Aug 2027 – 22 Aug 2028 Up to 40% of calculated fine
From 23 Aug 2028 Up to 100% of calculated fine

The full fines are not small. Standard violations can reach MDL 1,000,000, or 1% of annual turnover. More serious breaches can reach MDL 2,000,000, or 2% of turnover, whichever is higher.

Who should pay attention

Almost every business that handles personal data should check this law. That includes companies with employees, customer databases, websites, cookies, newsletters, or video surveillance.

Foreign companies should also pay attention. If you sell to Moldovan customers online, work with Moldovan staff, or use Moldovan service providers, this may affect you too.

Moldova’s IT sector is already more prepared than most local businesses, since many firms already work under GDPR for EU clients. But internal HR data, subcontractors, and employee monitoring still need review.

Small and medium-sized companies are the least prepared. Many still do not have a data protection lead, a processing register, or a breach response plan. The transition period was meant to give them time, but many have not started yet.

Why investors should care

For foreign investors, the law is a sign that Moldova is moving closer to EU rules. That makes the market more predictable for companies that already follow GDPR.

It also changes due diligence. If you buy or partner with a Moldovan company, data protection should now be part of the review. Weak data handling can create both financial and reputational risk.

The law may also help Moldova in the long run when it comes to EU data transfer rules. Moldova is not yet considered “adequate” by the EU, but this law is a step in that direction.

The bigger picture: regulatory convergence

Law 195/2024 does not exist in isolation. It is one element of a broader regulatory convergence with the EU that includes:

  • EUDR (EU Deforestation Regulation) — applicable from December 2026 for large operators, affecting Moldova’s timber and agricultural exports
  • Cybersecurity Law No. 48/2023 — already in force since January 2025, imposing requirements on providers in critical sectors
  • Electronic identification and trust services — aligned with the EU’s eIDAS framework

For businesses, the cumulative effect is significant. Moldova’s regulatory environment is moving — quickly and irreversibly — toward EU standards. Companies that treat each regulation as an isolated compliance exercise will find themselves perpetually catching up. Those that build compliance infrastructure once, aligned with EU frameworks, will be better positioned as Moldova progresses toward accession.

What to do now

If your company has not started, the minimum step is to prepare before 23 August 2026.

  • Map what personal data you collect and where it is stored
  • Check your legal basis for processing
  • Update your privacy policy
  • Assign someone to handle data protection, even if a formal DPO is not required
  • Create a breach response process
  • Review contracts with third-party providers
  • Train staff who work with personal data

Bottom line

Law 195/2024 is not just a compliance update. It is part of Moldova’s broader move toward EU standards.

The transition period gives businesses time. The real question is whether they will use it.

This analysis is based on publicly available legal texts and regulatory guidance. It is not legal advice. Businesses should speak with qualified legal counsel about their own situation.

Sources: DataGuidance, DLA Piper, ACI Partners, EU4Digital, National Center for Personal Data Protection of the Republic of Moldova (NCPDP), CIS Legislation database.