Moldova
SubstantialLaw No. 133 on the Protection of Personal Data (2011)
Authority: National Centre for Personal Data Protection (NCPDP) | Enforcement: Active | Enacted: April 2012
Overview
Moldova enacted data protection legislation in 2011. The NCPDP oversees compliance. Moldova ratified Convention 108+ and is working on EU alignment as an EU candidate country. The framework provides data subject rights and cross-border transfer rules.
14-Topic Coverage
Data Protection Authority
Fully AddressedNCPDP oversees compliance, handles complaints, and registers data operators.
Consent Requirements
Fully AddressedConsent required. Must be free, specific, informed, and unambiguous.
Data Subject Rights
Fully AddressedRights to access, rectification, erasure, and objection.
Cross-Border Transfer
Fully AddressedTransfers to countries with adequate protection or with appropriate safeguards.
Breach Notification
Partially AddressedNo explicit statutory requirement. Reform developing.
DPO Requirements
Partially AddressedMust register with NCPDP. DPO designation encouraged.
Children's Data
Partially AddressedGeneral provisions apply.
Penalties & Enforcement
Fully AddressedAdministrative fines. Active enforcement by NCPDP.
Sector-Specific Rules
Partially AddressedBNM financial data rules, health data regulations.
Cookie/Tracking
Not AddressedNo specific cookie regulation.
AI & Automated Decisions
Partially AddressedRight to not be subject to automated decisions.
Data Localisation
Not AddressedNo general data localisation requirement.
Significant Data Fiduciary
Not AddressedNo equivalent concept.
Government Data
Fully AddressedLaw applies to government processing.
Coverage Summary
Quick Navigation
Need Compliance Help?
Our data privacy team can help you navigate Moldova's regulations.
Book a Consultation