
Commissioned by the Delegation of the European Union to Moldova, a group of Moldovan lawyers has prepared a detailed guide explaining the importance of personal data protection and how the new law ensures this.
Why is such a law needed?
The concept of personal data is not limited to the information contained in your identity card. Your name, telephone number, email address, photograph, location data, purchase history, medical records or payment details can be used to identify you — and such information must be protected.
The simplest example is the wave of personal data thefts that swept through Moldova, carried out with the aim of taking out loans. Law enforcement agencies struggled to tackle this, although repeat offences still occur to this day.
And there are thousands of other scenarios in which personal data can be used to the detriment of its owner. The aforementioned law was drafted with the aim of fully regulating the methods for protecting such data.
What is changing?
Organisations are obliged to explain how they use personal data.
Companies and organisations that collect personal data must clearly inform people of the following:
– what information they collect;
– the purpose for which they collect and use it;
– to whom they pass it on;
– how long they keep it;
– what rights the individual in question has.
At present, none of the Moldovan organisations, including banks, provide such explanations. At best, they are set out in small print in the contract.
The law does not set a single retention period for all types of data. Each organisation must determine a reasonable retention period for each category of information. As soon as the purpose of data processing ceases to be relevant and the legal obligation to retain the data no longer applies, the data must be deleted or anonymised.
For example, information required to deliver an order may be retained for the time necessary to fulfil the contract and comply with accounting standards. A CV may be deleted once the recruitment process is complete, unless the candidate has consented to its retention for consideration for other vacancies.
Individuals may request access to their data, or request that it be corrected or deleted
The new law reinforces every individual’s right to know what personal data an organisation holds about them and how it is used.
Citizens may request:
– access to their personal data;
– the rectification of inaccurate information;
– the deletion of their data in cases provided for by law;
– a restriction on the use of their data;
– a copy of their data in an accessible format;
– the right to stop your data being used for direct marketing purposes.
As a rule, the organisation is obliged to respond within one month. In the event of complex or numerous requests, this period may be extended, but the applicant must be informed of this.
Greater protection against unsolicited advertising
When sending out information and advertising materials, companies and organisations are obliged to confirm that the user has given their consent voluntarily, unambiguously and for a specific purpose.
Users must be able to withdraw their consent just as easily as they gave it. They also have the right to object at any time to the use of their data for direct marketing purposes. Once a user has unsubscribed from a mailing list or withdrawn their consent, the company is obliged to stop sending advertising messages.
Example: purchasing a product or registering for an event does not automatically constitute consent to receive advertising.
What happens if personal data ends up in the wrong hands?
A letter sent to the wrong person, the loss of a laptop, unauthorised access to an account or the accidental publication of a database may be considered information security incidents, also known as data breaches.
Organisations must contain the incident, assess its consequences and mitigate the associated risks. If the incident is likely to affect people’s rights and freedoms, the National Centre for the Protection of Personal Data must be notified without delay and, where possible, no later than 72 hours after the incident.
If the risk to those affected is high, they must also be clearly informed so that they can take protective measures — for example, changing their passwords or blocking their bank cards.
Protection also extends to automated decisions
The law also applies in cases where personal data is analysed using artificial intelligence tools, profiling or other automated systems.
In certain cases, if a decision is made exclusively by automated means, has legal consequences or significantly affects an individual, that person may request human intervention, present their point of view and challenge the decision.
Act No. 195/2024 is not a general law on artificial intelligence. However, it protects citizens when such technologies use their personal data.
Trust begins with respect for personal data
Bringing the Republic of Moldova’s legislation into line with European standards means greater transparency for citizens and greater accountability for organisations.
If a person believes that their personal data is being used unlawfully, they can first contact the relevant company or organisation. If the issue is not resolved, they can lodge a complaint with the National Centre for the Protection of Personal Data or take the matter to court.
The protection of personal data is, above all, about respect for people, their choices and their right to retain control over the information that concerns them.
10 tips on how to protect your personal data
- Find out why your data is needed
Before filling in a form, check who is collecting the information, for what purpose and for how long it will be stored.
- Provide only the necessary data
If you are asked for information that, at first glance, does not seem necessary to receive a service, ask for an explanation of why it is required.
- Read the terms and conditions before giving your consent
Don’t automatically tick all the boxes. Consent to receive advertising must be clear and separate from consent to receive the service itself.
- Use different passwords
Choose long and unique passwords for important accounts. If two-factor authentication is available, enable it.
- Do not send confidential data via unsecure channels
Where possible, do not send photos of documents, bank details or medical information via standard messages if there is a more secure way to do so.
- Check messages and links
Do not provide personal details simply because a message appears to be urgent. Check the sender and the website address before entering any information.
- Check app permissions
Regularly check apps’ access to your location, contacts, camera and microphone. Disable any permissions they do not need.
- Unsubscribe from unwanted newsletters
You can withdraw your consent or object to the use of your data for direct marketing at any time.
- Request information about your data
You can ask a company what data it holds about you, why it uses it, who it shares it with and how long it will keep it. As a rule, a response must be provided within one month at the latest.
- Take action if you notice a problem
First, contact the relevant organisation and keep a record of your enquiry and the response you receive. If the issue is not resolved, you can lodge a complaint with the National Centre for the Protection of Personal Data or take the matter to court.
A simple rule: Only provide the necessary data, check where it ends up, and exercise your rights if anything is unclear.
Comment from the National Centre for Data Protection
According to the National Centre for Data Protection, the new rules are centred on the individual and their rights. Data controllers must know what information they are collecting, for what purpose they are using it, how long they are storing it for, and what measures they are taking to protect it.
‘The new provisions emphasise the principle of data minimisation. Organisations must collect only the information they need, use it for specifically defined purposes and protect it accordingly. In this regard, measures that may seem simple at first glance – strong passwords, restricting access to information, updating information systems and training staff – can significantly reduce risks,” explains the National Centre for Data Protection.
At the same time, the agency emphasises that the new legislation is not centred on fines.
“Penalties are a mechanism of accountability, not the aim of the law,” notes the NCPDP, emphasising that the primary objective is to ensure that personal data is processed lawfully, transparently, securely and responsibly.
In this regard, the centre reaffirms its role as an institution that informs, guides and supports organisations and citizens in applying the new rules.
This story was translated with the assistance of artificial intelligence.The translation was also reviewed by the Logos Press editorial team.
Follow our updates
Have information for the newsroom? Share it with Logos-Press























Comments
0No comments yet. You can start the conversation.
Comments are open to readers with a Logos Press account.
Sign in to comment