
The document was drafted by the National Center for Personal Data Protection in connection with the entry into force of the Law on Personal Data Protection in Moldova on August 23, 2026. According to the document, a data controller is required to notify the center of a breach no later than 72 hours after becoming aware of it.
The only exceptions are cases where the likelihood of a risk to citizens’ rights and freedoms is extremely low. In such cases, the notification must be sent without undue delay.
Under the law, a data controller is a natural or legal person, public authority, agency, or any other body that, alone or jointly with others, determines the purposes and means of processing personal data.
In accordance with these requirements, the National Center for the Protection of Personal Data has approved a standard form for notifying data subjects of a personal data breach.
The document does not impose new obligations on data controllers but merely establishes the procedure for fulfilling the statutory obligation to provide notification in the event of a risk to the security of personal data.



















