Does your company need a DPO? Responsibility for personal data in Moldova

A DPO vacancy or an internal appointment should follow an assessment of how your company actually works. Start with the data you process, the scale of those operations and who can independently monitor them.

The need for a DPO depends on processing, not headcount

  • Having customers, employees or a CRM does not automatically make a DPO mandatory. You need to check the legal grounds and the nature of your processing.
  • A DPO may be an employee or an external specialist working under a service contract. Both arrangements require expertise, resources and independence.
  • Other duties may be combined with the role only without conflicts of interest: a person cannot independently monitor their own decisions about processing.
  • Appointing a DPO does not remove the organisation's data protection obligations.

A DPO is a data protection officer, known in Romanian as responsabil cu protecția datelor. The officer advises the organisation and monitors compliance. Moldova applies Law No. 195/2024, in force since 23 August 2026. The date is confirmed by CNPDCP, the National Centre for Personal Data Protection.

A data protection specialist checks documents against information on a laptop
Deciding whether to appoint a DPO starts with assessing data processing and internal responsibilities.Colenco Legal

When appointing a DPO is mandatory

Article 37 sets out three main grounds. The rule covers both the controller, which determines the purposes and means of processing, and the processor, which processes data on the controller's behalf.

  1. A public authority or institution carries out the processing. The exception concerns courts when administering justice.
  2. Core activities require regular and systematic monitoring of people on a large scale. For example, this ground needs assessing for a service built around continuous profiling of a large audience.
  3. Core activities involve large-scale processing of special categories of data or data relating to criminal convictions and offences. Special categories include health data and biometric data used to uniquely identify a person.

For the second and third grounds, both the nature of the activity and its scale matter. A few medical documents in personnel files do not, on their own, establish that the company falls within the third case. Article 37(4) also allows other normative acts to require an appointment: sector-specific requirements need a separate check. Appointment grounds and conditions published by CNPDCP.

There is no universal employee threshold for a DPO. The number 250 appears in Article 30 in a separate rule on records of processing activities; it is not a criterion in Article 37. Saying “we have a small team” therefore cannot replace an assessment. Text of Law No. 195/2024.

How to assess scale: four business scenarios

Consider the number and proportion of people affected, the volume and range of data, the duration of processing and its geographical reach. These factors appear in European WP29 guidelines published by CNPDCP. They help interpret similar concepts; they are not a numerical test established for Moldova.

The following hypothetical situations illustrate the assessment:

  • A small shop with personnel records and customer contact details. These facts alone do not establish a duty to appoint a DPO. You also need to examine loyalty programmes, profiling, cameras and other processes. A conclusion about personnel records cannot automatically cover the whole business.
  • A network of clinics with a shared patient database. Health data are connected to the core service. If processing is large-scale, Article 37(1)(c) applies. Branch and patient numbers, together with the contents of the database, help assess scale; the word “clinic” alone does not settle the question.
  • A behavioural analytics platform. Continuous tracking and profiling of a large audience as the basis of the service call for an assessment of the regular and systematic monitoring ground. An ordinary website or CRM does not, by itself, demonstrate such activity.
  • A provider processing data for many clients. A small workforce does not reflect the volume of processing. The assessment needs to cover the provider's core activities and the individuals' data it handles under client contracts, including special categories.

Prepare a map showing where data come from, who uses them, for what purpose, for how long and to whom they are disclosed. Distinguish core activities from supporting functions: payroll, for example, usually supports the business. CNPDCP explains this distinction in paragraph 96 of its explanatory considerations on the law.

Unsure whether your company needs a DPO?

Colenco Legal can help assess the grounds for appointment, check conflicts of interest and determine how to organise the DPO role around your company's processes.

What the DPO does and what remains the company's responsibility

The DPO helps the organisation comply with the law and monitors how data protection is organised. Under Article 39, the role includes:

  • informing and advising the organisation and employees;
  • monitoring compliance with the law and internal rules, including the allocation of responsibilities, training and related audits;
  • providing advice on request about data protection impact assessments and monitoring their performance;
  • cooperating with CNPDCP and acting as a contact point for the regulator.

An impact assessment examines the risks that planned processing poses to people's rights. Where the company needs such an assessment, the DPO advises on it and monitors its performance; appointing a DPO does not replace the analysis. The officer must consider the risks of the particular processing when performing their tasks. Articles 38–39.

For example, before a new CRM is launched, the DPO must be involved in data protection issues in good time: access, retention periods and customer rights. Management provides resources and makes organisational decisions, IT implements technical measures, and employees follow procedures. The monitoring specialist should not become the sole person carrying out all these tasks.

The organisation retains its duties to comply with the law and demonstrate compliance. Writing “the DPO is responsible for everything” in an appointment document does not transfer all the controller's or processor's responsibility to that person. This follows from the allocation of duties in Articles 5, 24 and 39 of the law.

Whom to appoint: an employee or an external specialist

Article 37(6) permits both options. The choice depends on processing complexity, available time and the ability to work independently. The law requires professional qualities, expert knowledge of data protection legislation and practices, and the ability to perform the DPO's tasks. A certificate alone does not demonstrate that all these requirements are met. Article 37.

Check whether the candidate can explain your data flows, assess contracts with providers, handle individuals' requests and communicate effectively with the IT team. Ask for examples of their approach to similar processes without disclosure of anyone else's confidential information.

The main risk of combining roles is monitoring one's own decisions. If the head of IT determines essential means of processing, appointing that person as DPO may create a conflict. The same question arises for a director or head of HR or marketing who determines processing purposes and means within their area. Assess actual powers, not just the job title. Article 38(6) prohibits conflicts; the approach to assessing them is explained in section 3.5 of the WP29 guidelines.

For an external DPO, agree in advance on access to necessary information, consultation arrangements, availability and communication with management. An external contract alone neither rules out conflicts nor guarantees sufficient resources. The law allows a group of undertakings to appoint a single DPO if the officer is easily accessible from each establishment.

How to formalise the appointment and ensure independence

An effective appointment needs defined tasks, access to information and clear reporting arrangements. Practical steps:

  1. Record the grounds and the arrangement. Prepare an employee appointment decision or service contract; define the tasks in writing and check for potential conflicts.
  2. Provide resources. Allow working time, training and access to the data and processing operations needed for the DPO's tasks.
  3. Set up direct reporting to the highest management level. Department managers must involve the DPO in data protection issues in good time.
  4. Publish contact details and communicate them to CNPDCP. Article 37(7) requires this. Provide a working contact channel, such as a dedicated email address; you do not need to publish the employee's personal phone number instead.
  5. Test the channel in practice. Who receives requests, how do they reach the DPO and how is confidentiality maintained? Retain evidence of communicating the contact details to the regulator.

This checklist helps organise the work; it is not a government-approved form. Articles 37–38 establish mandatory safeguards: the DPO must not receive instructions about the exercise of their tasks and must not be dismissed or penalised for performing them. This protects the role's independence; it does not provide immunity for any kind of conduct.

An appointment document without time, access or the ability to report concerns to management does not provide the position required by law. The officer must also keep information obtained through the role confidential.

What to do if a mandatory DPO is not currently required

Record which processes you examined and why you found no grounds for a mandatory appointment. This is a practical recommendation: a written assessment helps explain the decision and revisit it after changes. Do not stop at “the company is small”. The WP29 guidelines recommend documenting this analysis.

Reassess when you introduce profiling, expand medical services, combine customer databases or take on a significant new processing contract. The absence of a mandatory DPO does not remove other requirements: lawful grounds for processing, informing individuals, protecting access and handling requests and incidents.

You can appoint an internal data protection coordinator with clearly defined duties. If the company voluntarily appoints a DPO, however, it needs to take account of the role's position under Articles 37–39, including independence and the absence of conflicts. Voluntary appointment does not make the DPO a nominal role without the necessary conditions.

Start by assessing processing and the allocation of responsibilities. The result will show whether a DPO is mandatory, who can perform the role and what organisational changes are needed.

Let’s discuss your matter

Briefly describe your situation. We’ll get in touch.

We use your data to respond to your enquiry. See our privacy policy.