Moldova's Law 195/2024 in plain language — a guide for businesses
A practical guide, with exact quotes from the statute. Law no. 195/2024 on the protection of personal data comes into force in the Republic of Moldova on 23 August 2026, replacing Law 133/2011. It is Moldova's transposition of the GDPR.
This is not legal advice. It is an informational guide written for business owners, not for lawyers. The quotations are reproduced verbatim from the official text, which is in Romanian (legis.md, LP195/2024, Monitorul Oficial no. 367-369 art. 574 of 23-08-2024) — they are deliberately left untranslated, because a translated "quote" is not a quote. An English rendering follows each one. For your specific situation, consult a lawyer. Text last verified: 28 July 2026.
The examples throughout come from a car-detailing studio — a concrete case is easier to follow than an abstract rule. The obligations are the same for any business that holds customer data, and where it helps, the equivalent in other trades is given in brackets.
Who has to comply
In practice, anyone holding data about identifiable individuals. Company size, turnover and whether you have a website are all irrelevant.
You have obligations if you keep, for example:
- a customer's name, phone or email (in a car studio: the client record; in a clinic:
the patient file; in a salon: the appointment book; in an online shop: the customer account);
- registration plates, addresses, details of a customer's property;
- photographs showing people or identifiable property;
- data about your own employees.
Article 2(1) applies the law to processing carried out "wholly or partly by automated means" — any spreadsheet, CRM, phone or management system — and also to paper records organised into a filing system (a folder, a register).
The exemption that will not save you: article 2(2)(b) excludes processing "by a natural person in the course of a purely personal or household activity". Your personal address book, yes. Your company's customer database, no.
The core idea: contract, not "consent"
If you take one thing from this guide, take this.
The near-universal instinct is to add an "I consent to the processing of my data" tick box to the customer record. That is a mistake, not a solution.
Almost everything you do to deliver your service has a better legal basis than consent — the contract (art. 6(1)(b)):
| What you process | The correct basis |
|---|---|
| Name, phone, details of the customer's property (car, pet, device) | Contract — art. 6(1)(b) |
| Quote, order, price | Contract |
| Condition photographs, handover signature | Contract / legitimate interest — art. 6(1)(f) |
| Invoices, accounting records | Legal obligation — art. 6(1)(c) |
| Service history for a returning customer | Contract |
Why it matters: if you ask for consent where you do not need it, you hand the customer a right of withdrawal (art. 7(3)) that destroys your own legal basis — they withdraw, and you may no longer process their order. Contract has no such fragility.
The statute says plainly, at art. 7(4), that consent extracted unnecessarily is not even valid:
_„Atunci când se evaluează dacă consimțământul este dat în mod liber se ține cont în special de faptul că, printre altele, executarea unui contract, inclusiv prestarea unui serviciu, este condiționată de consimțământul cu privire la prelucrarea datelor cu caracter personal care nu este necesară pentru executarea acestui contract.”_
_In assessing whether consent is freely given, account is taken in particular of whether performance of a contract, including the provision of a service, is made conditional on consent to processing that is not necessary for the performance of that contract._
You genuinely need consent only for:
- Publishing photographs — before/after shots on Instagram or Facebook. A car with
a visible plate, or the owner in frame, posted as advertising, is NOT covered by the contract. (The same goes for photos from a salon, a treatment room, an event.) This needs specific, separate, withdrawable consent.
- Marketing and promotional messages — newsletters, offers, promotional SMS.
- Keeping data after the relationship ends, beyond the legally required period.
The main articles
Principles (art. 5)
Article 5(1) requires that data be:
_„a) prelucrate în mod legal, echitabil și transparent în raport cu persoana vizată [...]; b) colectate în scopuri determinate, explicite și legitime [...]; c) adecvate, relevante și limitate la ceea ce este necesar în raport cu scopurile în care sunt prelucrate (principiul reducerii la minimum a datelor); d) exacte și, în cazul în care este necesar, trebuie să fie actualizate [...]; e) păstrate într-o formă care permite identificarea persoanelor vizate pe o perioadă ce nu depășește perioada necesară îndeplinirii scopurilor [...] (principiul limitării legate de stocare); f) prelucrate într-un mod care asigură securitatea adecvată a datelor cu caracter personal [...].”_
_Processed lawfully, fairly and transparently; collected for specified, explicit and legitimate purposes; adequate, relevant and limited to what is necessary (data minimisation); accurate and kept up to date; kept in identifiable form no longer than necessary (storage limitation); and processed with appropriate security._
And, most important of all for you, art. 5(2):
_„Operatorul este responsabil de respectarea alin. (1) și trebuie să poată demonstra această respectare (principiul responsabilității).”_
_The controller is responsible for, and must be able to demonstrate compliance with, paragraph (1) — the accountability principle._
It is not enough to comply. You must be able to prove you comply. That is where records, written contracts and privacy notices come from.
Legal basis (art. 6)
_„Prelucrarea este legală numai dacă și în măsura în care se îndeplinește cel puțin una dintre următoarele condiții: a) persoana vizată și-a dat consimțământul [...]; b) prelucrarea este necesară pentru executarea unui contract la care persoana vizată este parte [...]; c) [...] îndeplinirea unei obligații legale [...]; d) [...] interesele vitale [...]; e) [...] o sarcină efectuată în interes public [...]; f) [...] interesele legitime urmărite de operator [...].”_
_Processing is lawful only if at least one applies: consent; necessary for performance of a contract; a legal obligation; vital interests; a public-interest task; or the controller's legitimate interests._
The six bases rank equally. Pick the one that fits — usually (b).
Consent (art. 7) and children (art. 8)
Article 7(3):
_„Persoana vizată are dreptul să își retragă în orice moment consimțământul. [...] Retragerea consimțământului se realizează cu aceeași simplitate ca și acordarea acestuia.”_
_The data subject may withdraw consent at any time; withdrawal must be as easy as giving it. Withdrawal does not affect the lawfulness of processing carried out beforehand._
The practical consequence: if consent was given with a tick box, withdrawal cannot require a signed letter delivered to your premises.
Children: art. 8(1) sets the threshold at 14 for information-society services (below 14, a legal guardian must authorise it). Note that the CNPDCP's explanatory PDF contains a drafting slip stating 16; the statute says 14.
Informing the customer (art. 13)
Even where you do not need consent, informing people is mandatory. Article 13(1) requires, at the point of collection:
_„a) identitatea și datele de contact ale operatorului [...]; c) scopurile în care sunt prelucrate datele cu caracter personal, precum și temeiul juridic al prelucrării; [...] e) destinatarii sau categoriile de destinatari ai datelor cu caracter personal [...].”_
_The controller's identity and contact details; the purposes and the legal basis; the recipients or categories of recipient._
Paragraph (2) adds the retention period, the customer's rights, and the right to complain to the Centre.
In practice: a short notice at reception, printed on the quote, or reachable via a QR code. It does not need to be a ten-page document.
The customer's rights (arts. 12, 15–22)
The response deadline, art. 12(3):
_„Operatorul furnizează persoanei vizate informații privind acțiunile întreprinse [...] fără întârzieri nejustificate, dar în cel mult o lună de la primirea cererii. Această perioadă poate fi prelungită cu două luni [...].”_
_Respond without undue delay and within one month of the request; extendable by two further months where necessary._
- Access and a copy (art. 15) — _„Operatorul furnizează o copie a datelor cu caracter
personal care fac obiectul prelucrării.”_ (§3) — _the controller provides a copy of the data being processed._
- Rectification (art. 16) — correcting inaccurate or incomplete data.
- Erasure / right to be forgotten (art. 17).
- Restriction of processing (art. 18) — "freezing" data while a dispute is resolved.
- Portability (art. 20) — data _„într-un format structurat, utilizat în mod curent și
care poate fi citit automat.”_ — _in a structured, commonly used, machine-readable format._
- Objection (art. 21). Against direct marketing it is absolute, §3:
_„În cazul în care persoana vizată se opune prelucrării în scopul marketingului direct, datele cu caracter personal nu se mai prelucrează în acest scop.”_ — _if the data subject objects to processing for direct marketing, the data may no longer be processed for that purpose._ No balancing test, no discussion: you stop.
Security (art. 32)
_„[...] operatorul și persoana împuternicită de acesta implementează măsuri tehnice și organizatorice adecvate în vederea asigurării unui nivel de securitate corespunzător acestui risc, inclusiv, printre altele, după caz: a) pseudonimizarea și criptarea datelor cu caracter personal; b) capacitatea de a asigura confidențialitatea, integritatea, disponibilitatea și reziliența sistemelor [...]; d) un proces pentru testarea, evaluarea și aprecierea periodică a eficacității măsurilor [...].”_
_Appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including as appropriate: pseudonymisation and encryption; confidentiality, integrity, availability and resilience of systems; and a process for regularly testing and evaluating the effectiveness of those measures._
Note the words "după caz" — _as appropriate_. This is an illustrative list, not a checklist to tick. Measures must be proportionate to the risk. For a small business that realistically means: individual passwords (not one shared login at the front desk), access only for those who need it, backups, and an encrypted device.
Records of processing activities (art. 30)
An internal register describing what data you hold, why, who you share it with and how long you keep it. It is not your software's activity log — it is a document.
Article 30(5) exempts organisations under 250 employees, but the exemption falls away where the processing "is not occasional". A company's customer base is never occasional, so in practice most businesses must keep the register, however small they are.
The register must also show who the data goes to. Article 30(1)(d) requires:
_„categoriile de destinatari cărora le-au fost sau le vor fi divulgate datele cu caracter personal [...]”_
In practice: every supplier you signed a processing contract with (see step 7 below) — your management software, your accountant, your agency — belongs in the register. You do not need to list your supplier's own suppliers: those are its sub-processors, and it is responsible for recording them. You list the supplier.
Personal-data breaches (art. 33)
_„În cazul în care are loc o încălcare a securității datelor cu caracter personal, operatorul notifică Centrul despre acest lucru fără întârzieri nejustificate și, dacă este posibil, în termen de cel mult 72 de ore de la data la care a luat cunoștință de aceasta [...].”_
_Where a personal-data breach occurs, the controller notifies the Centre without undue delay and, where feasible, within 72 hours of becoming aware of it._
In practice: a lost laptop, a compromised database, an email with customer data sent to the wrong person — you have roughly 72 hours to notify the CNPDCP. Decide in advance who makes the call and through which channel you report. A crisis is the wrong moment to improvise.
Penalties (art. 88) and the phase-in (art. 90)
Two tiers: up to 1,000,000 MDL or 1% of turnover (art. 88(1) — security, records, processor contracts), and up to 2,000,000 MDL or 2% (art. 88(2)):
_„[...] se aplică amenzi de până la 2 000 000 de lei sau, în cazul unei întreprinderi, de până la 2% din cifra totală de afaceri [...], pentru încălcarea următoarelor dispoziții: a) principiile de bază pentru prelucrare, inclusiv condițiile privind consimțământul [...].”_
Fines phase in — art. 90(4): _„din primul an – 10% [...]; din al doilea an – 40% [...]; din al treilea an – 100% [...]”_ — 10% of the assessed fine in year one, 40% in year two, 100% from year three. Liability itself starts on day one; only the amount is scaled.
Where to start: 8 realistic steps
- Take inventory. What data you hold, where (spreadsheet, CRM, phone, paper), and
who can reach it. You cannot protect what you do not know you have.
- Delete what you do not need (art. 5(1)(c)). The cheapest way to reduce risk is not
to hold the data at all.
- Write down the basis for each category: contract, legal obligation, consent.
- Draft the privacy notice and make it reachable (reception, quote, QR code).
- Set retention periods and honour them. "Forever" is not a period.
- Tidy up access: individual passwords, least privilege, backups, encryption.
- Sign contracts with everyone who sees your data: your software vendor, your
accountant, your marketing agency.
- Keep the register (art. 30) and prepare your 72-hour procedure (art. 33).
What stays with you, and what software can cover
If you use a management system (CRM, booking tool, invoicing app), two distinct roles appear:
- You are the controller. You decide what data is collected, why, and how long it is
kept.
- The software vendor is the processor. It processes the data on your behalf, on your
instructions.
Article 28(1) requires you to use only processors who:
_„[...] oferă garanții suficiente pentru punerea în aplicare a unor măsuri tehnice și organizatorice adecvate, astfel încât prelucrarea să respecte cerințele prevăzute de prezenta lege și să asigure protecția drepturilor persoanei vizate.”_
_...provide sufficient guarantees to implement appropriate technical and organisational measures, so that processing meets the requirements of the law and protects the rights of the data subject._
It also requires a written contract (a data-processing agreement, or DPA) between you and the vendor. Good software can give you the tools — the notice, export, erasure, retention periods, security, records — but the relationship with the customer, and the decisions, remain yours.
One piece of good news about hosting: if your data sits in the EU/EEA, no special authorisation is needed at all. Article 44(2):
_„Prezentul capitol nu se aplică transferurilor de date cu caracter personal către statele membre ale Spațiului Economic European. În cazul acestor transferuri nu sunt necesare autorizări speciale.”_
_This chapter does not apply to transfers to member states of the European Economic Area; no special authorisation is required for such transfers._
Three myths
"We're too small for this to apply." There is no size threshold. The art. 30(5) exemption covers only the register, and it falls away for non-occasional processing anyway.
"If everyone signs a consent form, I'm covered." Usually the opposite: unnecessary consent is invalid (art. 7(4)) and leaves you weaker than contract would.
"We have to register with the CNPDCP." No. The old registration duty under Law 133/2011 is abolished. The new law asks for accountability and your own records, not a filing. There is nothing to submit before 23 August 2026.
Sources
- Official text: Law no. 195/2024, legis.md (LP195/2024), MO no. 367-369 art. 574,
23-08-2024 — https://www.legis.md/cautare/getResults?doc_id=144681&lang=ro
- CNPDCP, main provisions:
https://datepersonale.md/legea-nr-195-2024-privind-protectia-datelor-cu-caracter-personal-principalele-prevederi-si-noutati-legislative/
- CNPDCP: (022) 820 801 · [email protected]