
A new law on personal data protection takes effect in Moldova on August 23. It imposes stricter requirements on companies and institutions. They will be required to demonstrate that personal data is collected lawfully, used for clearly defined purposes, and only to the extent necessary.
Citizens will have expanded rights regarding their personal data—they will be able to request access to it, demand its correction or deletion, and restrict its processing in cases provided for by law.
An important change concerns data security incidents: in the event of a data breach that poses a risk to people’s rights and freedoms, the data controller is required to notify the personal data protection authority no later than 72 hours after becoming aware of the breach.
In addition, relationships with companies that process data on behalf of other organizations must be governed by written agreements.
As a reminder, the law was adopted two years ago and will take effect on August 23, 2026. It establishes new requirements in the area of personal data protection and expands citizens’ rights to appeal cases of unlawful use of their information. For example, companies and organizations face fines of up to 2 million lei for violating personal data processing rules.





















