The new data protection system is not just a policy on a website. It requires order across CRM, HR, marketing, contracts and access controls. The sooner a business sees the whole perimeter, the less it will need to fix under pressure.
Rules change on 23 August: what business leaders need to know
- Law No. 195/2024 on personal data protection takes effect on 23 August 2026 and replaces Law No. 133/2011.
- The requirements do not apply only to banks, clinics and IT companies. A business with employees, customers, a CRM, mailing lists, cameras or an outsourced accountant already handles personal data.
- The maximum financial penalty may reach MDL 2,000,000 or 2% of an undertaking’s total turnover, but this is a ceiling rather than an automatic fine for every mistake.
- One privacy policy is not enough. A company needs working processes and evidence that the rules are actually followed.
The new regime is often called “Moldova’s GDPR”. That phrase makes the approach easier to understand, but Moldovan businesses are legally governed by national Law No. 195/2024, which transposes GDPR standards into the law of the Republic of Moldova. The Ministry of Justice confirms that the law takes effect on 23 August 2026.
How serious is it? A fine is only one part of the risk
Treating the law as a formality is risky. Its central idea is accountability: a company must not only protect data but also show why it collects it, who has access, how long it keeps it and which safeguards it uses.
The maximum penalty is significant: up to MDL 2,000,000 or 2% of an undertaking’s total turnover. The regulator does not, however, have to impose the maximum for a first inaccuracy in a document. According to CNPDCP guidance, the choice between a warning and a fine and the amount imposed take account of the seriousness of the infringement, the measures implemented, the harm caused to individuals and the company’s efforts to limit the consequences.
That is not a reason to dismiss the risk. After a complaint from a customer or employee, the business may need to reconstruct the facts quickly: the legal basis for processing, the recipients, why data was not deleted on time and who dealt with the request. Individuals may also seek compensation in court.
The weakest position is: “We tried, but we documented nothing.” The strongest is the ability to present a data map, recorded decisions, contracts, request and incident logs, staff training and completed technical measures. An early audit is therefore meant to produce evidence of a controlled process, not a thick compliance binder.
Implementation starts with a data map, not a policy template
Buying a document pack before an analysis is like ordering a key before inspecting the lock. The wording may look impressive while having little to do with how the company really works.
Start with the processes in which people’s data appears:
- sales and CRM;
- website forms, cookies and analytics;
- deliveries and payments;
- recruitment, employee files and payroll;
- mailing lists, loyalty schemes and advertising;
- CCTV and physical access controls;
- customer communications and call recordings;
- accounting, IT support and cloud services.
Ask eight simple questions about each process: whose data is used, what data, for what purpose, on which legal basis, where it is stored, who has access, who receives it and when it is deleted. Mark foreign services and any process involving children, health, biometrics, continuous monitoring or automated assessment separately.
The map quickly reveals real problems. A form may request a date of birth without a clear purpose; a former employee may retain CRM access; candidate CVs may be kept indefinitely; a customer list may be exported to a personal Google Drive; the accountant may receive documents through ordinary email; or the marketing agency may use contact details without data protection terms.
Everything does not need to be repaired at once. Start with processes that involve many people, sensitive data, broad access or costly consequences. Standard documents and everyday rules can then be updated in a controlled sequence.
Unsure which requirements apply to your business?
Colenco Legal can analyse your processes, website, CRM, HR, vendors and cloud services, identify gaps and help implement the documents and working procedures required by Law No. 195/2024.
Which documents and working processes need to be in place
Good implementation links every document to a specific action and an accountable person. If a policy says that data is “deleted once the purpose has been fulfilled” but nobody knows who performs the deletion or when, the rule does not work.
A basic package will usually include:
- Records of processing activities. These record the purposes, categories of people and data, recipients, foreign transfers, deletion periods and general security measures. The exemption for organisations with no more than 250 employees is limited: records are still required if processing is regular, risky or includes special-category data. CNPDCP notes that processing in most companies is not occasional.
- Clear privacy notices. A customer, employee or candidate should understand what data the company receives, why it is used, how long it is kept, who receives it and what rights the individual has. Consent is not required for every use: the legal basis may instead be a contract, a legal duty or another basis provided by law.
- Retention and deletion rules. CRM records, employee documents, CCTV footage, enquiries and marketing lists need justified retention periods. “We keep it forever in case it is useful” is not a proper purpose.
- Vendor contracts. If an accountant, IT company, HR service, marketing agency or cloud provider processes data for the business, the relationship must be documented in writing. The agreement should define the subject, duration and purpose of processing, safeguards and what happens when the services end.
- A procedure for individual requests. An access, correction or deletion request may arrive through a shared mailbox, chat or Instagram. It needs to be recognised and recorded, the requester’s identity may need to be verified, and a response will normally be required within one month.
- Access and incident management. The business needs rules for granting and closing access, backups, updates, file transfers and incident records. When an employee leaves, access should be closed through a controlled process instead of relying on a manager’s memory.
Once the documents are ready, the team should test them: handle a sample customer request, close a test account, locate a processing record and run a short breach exercise. This is where the difference between an implemented system and drafted text becomes visible.
DPOs, impact assessments and breaches do not apply equally to everyone
Three requirements most often cause either panic or dangerous oversimplification. Each depends on statutory criteria and the level of risk.
When a DPO is required
A data protection officer, or DPO, independently monitors compliance and acts as a contact point with CNPDCP. A DPO is required for public bodies and, in the private sector, when core activities involve large-scale regular and systematic monitoring of people or large-scale processing of sensitive data or information about criminal convictions and offences.
An ordinary shop or small service business may not be legally required to appoint a DPO. Someone must still own the process: receive requests, update the records and involve legal and IT teams when an incident occurs. A DPO may be an employee or an external specialist if the requirements for the role and its independence are met.
When an impact assessment is required
A data protection impact assessment, or DPIA, examines how a high-risk process may affect people’s rights and how that risk can be reduced before launch. It is particularly relevant to significant automated decisions and profiling, large-scale processing of sensitive data and large-scale systematic monitoring of a publicly accessible area.
Not every camera or HR spreadsheet automatically requires a DPIA. The scale, regularity, data types, technology and potential effects need to be assessed. An existing high-risk system may also require an assessment if one has not previously been carried out.
What the 72-hour deadline means
If a personal data breach creates a risk to people’s rights and freedoms, the company must, where feasible, notify CNPDCP within 72 hours after becoming aware of the incident. If the risk is high, affected individuals must also be informed without undue delay. Every incident should be documented, even when the assessment concludes that notice to the regulator was not required.
The decision should not be discussed for the first time on the third day after a breach. Decide in advance who stops access, preserves evidence, assesses risk and prepares a notification.
If time is short, implement in the right order
Little time remains before the law takes effect, but rewriting every document at random is less useful than working according to risk.
Stage one: define the perimeter. Identify the processes and systems, appoint a project lead and find critical access rights and data transfers. Stop clearly dangerous practices immediately: shared passwords, access retained by former employees, public spreadsheets, uncontrolled exports and collection without a purpose.
Stage two: close mandatory gaps. Select the correct legal bases, prepare processing records, notices and retention periods, and update agreements with key vendors. Make and record separate decisions about a DPO, impact assessments and foreign services.
Stage three: put the system into operation. Assign owners, train staff, test a request and a breach response, and collect evidence of completed measures. The work continues after 23 August: records and documents must be updated whenever new products, services or uses of data are introduced.
Colenco Legal can take responsibility for the legal and organisational part of the project: interview teams, map the data, identify requirements and risks, prepare a roadmap, processing records, notices, internal procedures and contractual terms. We can also assess the need for a DPO and impact assessments, review foreign services, run a working session for the team and support the launch of the new rules.
Implementation also needs input from the business. IT configures access and logs; HR changes employee processes; marketing corrects forms and campaigns; and management assigns owners. Our role is to connect those actions to the law, set priorities and take the project through to a working system rather than leave the client with a folder of files and no instructions.
Preparation can still be managed
Law No. 195/2024 is serious, but it does not require an equally complex project from every company. Start with real data flows, close the highest-risk gaps and document decisions. Colenco Legal can analyse your operating model, separate mandatory measures from unnecessary bureaucracy and help implement the rules in the company’s daily work.
Unsure which requirements apply to your business?
Colenco Legal can analyse your processes, website, CRM, HR, vendors and cloud services, identify gaps and help implement the documents and working procedures required by Law No. 195/2024.