Moldova's Law 195/2024 Explained: What Your Website Needs So You Don't Get Fined
Moldova's Law 195/2024 applies from 23 August 2026. A technical guide: what your website needs, a compliant cookie banner, privacy policy, fines up to 2,000,000 MDL. 16-point checklist plus a real case study.

In short. Law No. 195/2024 on personal data protection applies in the Republic of Moldova from 23 August 2026, replacing Law 133/2011. It transposes the European GDPR. It covers any company that collects people's data — including through a simple contact form. Fines reach 2,000,000 MDL or 2% of annual turnover, though they are reduced to 10% in the first year. For a website, the mandatory minimum means: a working cookie banner, a complete privacy policy, active consent on forms, an internal processing record, and a 72-hour breach notification procedure.
Contents
- What Law 195/2024 is
- When it applies — the full timeline
- Who it applies to (30-second test)
- What changed compared to Law 133/2011
- The 7 mandatory elements on your website
- Cookie banner: compliant vs non-compliant
- Privacy policy: the 11 required elements
- Forms and active consent
- Internal documents nobody sees — until an inspection
- The 72-hour rule
- Fines: what it actually costs, with the maths
- Case study: we audited our own site and found 13 issues
- The 16-point checklist
- Frequently asked questions
1. What Law 195/2024 is
Law No. 195/2024 on personal data protection is Moldova's new legal framework governing how companies and institutions collect, store and use people's data.
It was adopted on 25 July 2024 with a two-year transition period and became applicable on 23 August 2026. It replaces Law No. 133/2011, which was outdated and, in practice, barely enforced.
The essence, in one sentence: Moldova has adopted the European GDPR (EU Regulation 2016/679) — the same principles, the same individual rights, the same corporate obligations and, for the first time, fines tied to turnover.
The supervisory authority is the National Centre for Personal Data Protection (NCPDP / CNPDCP), based in Chișinău, 48 Serghei Lazo Street.
Why this matters now: the transition period has ended. From 23 August 2026, a complaint from a dissatisfied customer or an inspection opened on the authority's own initiative is judged under the new rules.
2. When it applies — the full timeline
Date What happens
| 25 July 2024 | Law 195/2024 is adopted and published
| 25 July 2024 – 22 August 2026 | Two-year transition period for adaptation
| 23 August 2026 | The law becomes applicable. Law 133/2011 is repealed
| Year 1 (2026–2027) | Financial penalties apply at 10% of the amount
| Year 2 (2027–2028) | Penalties apply at 40%
| From year 3 (2028) | Penalties apply at 100%
This phase-in mechanism is the single most practically useful fact in this article. It means businesses have a window of roughly two years in which the cost of a mistake is considerably lower — exactly the window in which it pays to get things in order.

3. Who it applies to (30-second test)
Most business owners' first reaction is "I'm small, this doesn't concern me." The law doesn't distinguish by size. It distinguishes by what you do with people's data.
Answer honestly. Tick even one and you are a data controller:
- [ ] Your website has a contact form
- [ ] You run an online store with delivery addresses
- [ ] You send newsletters or offers by email
- [ ] You have Google Analytics, Meta Pixel or any other tracking tool
- [ ] You have a booking or appointment system
- [ ] You keep employee records
- [ ] You have CCTV in your shop or office
- [ ] You record phone calls
- [ ] You keep a CRM or customer database, even in a spreadsheet
In practice: if your website does anything more than display a phone number, you are a data controller.
Foreign companies too
The law also applies to companies with no presence in Moldova if they offer goods or services to people located in Moldova or monitor their behaviour. A Romanian online store shipping to Chișinău falls within its scope.
4. What changed compared to Law 133/2011
Aspect Law 133/2011 Law 195/2024
| Fines | Symbolic, rarely applied | Up to 2,000,000 MDL or 2% of turnover
| Prior notification | Registration with the authority | Abolished, replaced by accountability
| Core principle | Formal compliance | Accountability — you must be able to prove compliance
| Processing record | Not required | Mandatory
| Impact assessment (DPIA) | Did not exist | Mandatory for high-risk processing
| Data Protection Officer | Did not exist | Mandatory in defined cases
| Breach notification | Not clearly regulated | 72 hours
| Individual rights | 4 basic rights | 7 rights, with clear deadlines
| Extraterritorial reach | No | Yes
| Data portability | Did not exist | Exists
The fundamental shift is accountability: complying is no longer enough — you must be able to prove, with documents and logs, that you comply. The burden of proof sits with you.
5. The 7 mandatory elements on your website
If you remember one thing from this article, remember this list. These are the seven things anyone opening your website should see:
- A working cookie banner — with a genuine refusal option, not just "Accept"
- A complete privacy policy — not a template copied in 2019
- A separate cookie policy, naming the individual cookies
- Active consent on forms — an unticked checkbox, not text under the button
- A permanent "Cookie settings" link in the footer, for withdrawing consent
- Full identification of the controller — legal name, company number, address
- Terms and conditions — separate from the privacy policy
The first four are what generate fines. The last three are what tell an inspector the company is serious.
6. Cookie banner: compliant vs non-compliant
If we had to pick a single point where websites in Moldova fall short, this is it.
Element ❌ Non-compliant ✅ Compliant
| Buttons | Only a large green "Accept" | "Accept", "Reject", "Customise" — equally prominent
| Refusal | Hidden in a small grey link | A button of the same size and contrast as "Accept"
| Scripts | GA and Pixel load immediately | Blocked until "Accept" is clicked
| Categories | A single "accept all" | Separate: essential, analytics, marketing
| Withdrawal | "Delete cookies in your browser" | Permanent "Cookie settings" link in the footer
| Proof | Nothing | A log with version, date, time, action
| Pre-ticking | Pre-ticked boxes | All unticked except the essential ones
The 10-second test you can run right now
Open your site in an incognito window. Press F12 → the Network tab → type google-analytics in the filter. Reload the page and don't click anything on the banner.
- Zero requests — you're fine
- Requests appear — you are breaking the law right now
Repeat with the facebook.net filter for Meta Pixel.
A banner that appears on screen while the Pixel has already fired behind it protects you from nothing. On the contrary: it proves you knew about the obligation and didn't meet it.
→ Before you read on: check your website security for free — a report in 30 seconds, no signup.


7. Privacy policy: the 11 required elements
- Controller identity — full legal name, company number, address, contact details
- Purposes of processing — why you collect each category of data
- Legal basis for each purpose — contract, legal obligation, consent or legitimate interest
- Categories of data collected, listed specifically
- Recipients — named, not "service providers": Google LLC, Meta Platforms, your hosting company, your courier
- International transfers — if you use Google Analytics or Meta Pixel, data leaves for the United States and that must be declared, with the transfer's legal ground
- Retention periods — by category, not "as long as necessary"
- The 7 data subject rights, explained
- How rights are exercised — a dedicated contact address and the one-month response deadline
- The right to complain to the NCPDP — with the authority's address and a reference to the procedure
- Date of last update and document version
The 7 rights, briefly
Right What a person can ask for
| Access | "What data do you hold about me?"
| Rectification | Correction of inaccurate data
| Erasure | The "right to be forgotten"
| Restriction | Temporary suspension of processing
| Portability | Their data in a format transferable to another provider
| Objection | Particularly to direct marketing
| Automated decisions | Not to be subject to profiling with significant effects
Response deadline: one month from receipt of the request. In complex cases it can be extended by two months, but the extension must be communicated within the first month.
8. Forms and active consent
Valid consent has three characteristics. It must be:
- active — the person takes an action; pre-ticked boxes are not valid;
- specific — separate for each purpose;
- demonstrable — you must be able to show who consented, when, and to what.
The most common mistake
The line "By submitting this form you accept the privacy policy", placed under the button, is not consent. It is passive consent — which, as far as the law is concerned, is no consent at all.
The correct version is an unticked checkbox with explicit wording:
☐ I agree to my data being processed so that I can receive a reply to my enquiry. [Privacy policy]
Careful with the legal basis
Many businesses use consent as the basis for everything. That backfires: if the basis is consent, the person can withdraw it at any time and you must delete immediately.
Processing Correct legal basis
| Delivering an order | Performance of a contract
| Replying to a quote request | Pre-contractual steps
| Invoices, accounting records | Legal obligation
| Newsletter | Consent
| Meta Pixel, remarketing | Consent
| Site security, fraud prevention | Legitimate interest
Minimise your fields
Every extra field in a form is an extra obligation. Selling a digital product? You don't need a physical address. Taking a booking? You don't need an ID number. Delete the fields you don't actually use.
9. Internal documents nobody sees — until an inspection
- Record of processing activities — what data you collect, why, on what basis, who you share it with, how long you keep it. The first document requested.
- Contracts with processors — hosting, email marketing platform, courier, external accountant. Every third party that "touches" your customers' data needs a contract setting out how they protect it.
- Security incident procedure.
- Internal policies and evidence of staff training — who has access to what.
- Data protection impact assessment (DPIA) — mandatory for high-risk processing: large-scale monitoring, special categories of data, profiling with significant effects.
- Consent logs — version, date, time, action.
- An assessment of whether you need a DPO — even if the answer is no, document why.
Do you need a DPO?
Probably not, if you're an ordinary business. Appointment is mandatory mainly for:
- public authorities and institutions;
- controllers whose core activity is systematic, large-scale monitoring of individuals;
- controllers processing special categories of data on a large scale (health, biometrics, religious or political beliefs, trade union membership, sexual life, racial or ethnic origin).
A typical online store, agency, restaurant or small practice generally isn't covered.
→ No time for maintenance? Website maintenance & support — we handle updates, backups and security.
10. The 72-hour rule
If you suffer a breach — a hacked site, a leaked database, a stolen laptop with the customer file, an email with personal data sent to the whole list by mistake — you must notify the NCPDP within 72 hours of becoming aware of it.
If the risk to affected individuals is high, you must notify them as well.
Three things people learn too late:
- The 72 hours include the weekend.
- The clock starts when you found out, not when you finished investigating.
- Without logs and backups, you often can't even establish what leaked. And a notification saying "we don't know which data was affected" is, to the authority, an aggravating circumstance.
This is why the procedure is written before anything happens: who notifies whom, who decides, what gets documented, where the logs are.
→ Step-by-step technical details: Website security: 13 mandatory checks in 2026.

11. Fines: what it actually costs
Tier Maximum For what
| Tier 1 | 1,000,000 MDL or 1% of annual turnover | Organisational breaches: no processing record, no processor contracts, no DPO where required, failure to notify a breach
| Tier 2 | 2,000,000 MDL or 2% of annual turnover | Breaches of the fundamental principles, of legal bases, of data subject rights, or of cross-border transfer rules
The higher of the two figures applies. For a company with substantial turnover, the real ceiling is the percentage.
Concrete calculation for year 1 (2026–2027)
You have no cookie banner and Meta Pixel loads without consent. That's a Tier 2 breach — processing without a legal basis.
Tier 2 maximum: 2,000,000 MDL Year 1 phase-in: × 10% ──────────────────────────────────────────── Maximum exposure: 200,000 MDL
Add a missing processing record (Tier 1) and that's up to 100,000 MDL more.
Two years from now, the same breach costs 2,000,000 MDL.
Not every breach means an automatic fine
The authority takes into account whether you took preventive measures, whether you cooperated, whether you documented your processes. A company with a record, a policy and a procedure — even imperfect ones — is treated completely differently from a company with nothing at all.

12. Case study: we audited our own site and found 13 issues
We're not writing this from textbooks. In September 2026 we ran on ourselves the audit we sell to clients. The result was uncomfortable.
Initial score: 2.5 out of 16.
What we found on websupport.md:
# Issue Tier
| 1 | Google Analytics and Meta Pixel loading without consent | 🔴 Tier 2
| 2 | No cookie banner at all | 🔴 Tier 2
| 3 | Passive consent on the form ("by submitting you accept") | 🔴 Tier 2
| 4 | Wrong legal basis — consent where pre-contractual steps applied | 🔴 Tier 2
| 5 | Withdrawal "via browser settings" | 🟠 Tier 1
| 6 | The policy cited no law at all | 🟠 Tier 1
| 7 | The NCPDP was not mentioned | 🟠 Tier 1
| 8 | Only 4 of the 7 rights listed | 🟠 Tier 1
| 9 | Transfers to the US undeclared | 🟠 Tier 1
| 10 | Vague recipients — "service providers" | 🟠 Tier 1
| 11 | Company number and legal name missing | 🟠 Tier 1
| 12 | No update date on the policies | 🟡 Minor
| 13 | No terms and conditions | 🟡 Minor
What we did in 24 hours: a banner with three equal options and genuine script blocking, a server-side consent log, an active checkbox on forms, both policies rewritten against Law 195/2024, terms and conditions, full legal identification in the footer, policies added to the sitemap with hreflang in three languages.
Final score: 15 out of 16.
The most useful lesson: one of those 24 hours went on a mundane problem — the page cache was serving the old version to the public even though the code was correct. If you fix your site and don't purge, an inspector still sees the old version.
👉 Want the same result for your website? Write to us — a compliance audit with an answer within 24 hours.

13. The 16-point checklist
Ten minutes, honest ticks. Fewer than 8 means a real problem.
On the site (public)
- [ ] Cookie banner where "Reject" is as prominent as "Accept"
- [ ] Analytics and marketing scripts don't load before consent (verified in DevTools)
- [ ] Permanent "Cookie settings" link in the footer
- [ ] Privacy policy with all 11 elements
- [ ] Separate cookie policy, naming individual cookies
- [ ] Law 195/2024 explicitly cited
- [ ] NCPDP named, with address and complaint procedure
- [ ] All 7 rights listed
- [ ] International transfers declared (Google, Meta)
- [ ] Recipients named, not generic
- [ ] Legal name and company number in the footer
- [ ] Unticked checkbox on every form
- [ ] Terms and conditions published
- [ ] Update date and version on each policy
Internal (invisible, but it counts)
- [ ] Record of processing activities
- [ ] Contracts with hosting, email platform and other vendors
- [ ] Written security incident procedure

14. Frequently asked questions
When did Law 195/2024 come into force? The law was adopted on 25 July 2024 and became applicable on 23 August 2026, after a two-year transition period.
Does Law 195/2024 apply to small businesses? Yes. The law doesn't distinguish by headcount or turnover — what matters is that you process personal data. A contact form is enough.
How large are the fines under Law 195/2024? Up to 1,000,000 MDL or 1% of turnover for organisational breaches, and up to 2,000,000 MDL or 2% for breaches of the fundamental principles. In the first year of application 10% of the amount applies, in the second 40%, and 100% thereafter.
Is a cookie banner mandatory? Yes, if you use analytics or marketing cookies — including Google Analytics and Meta Pixel. Strictly necessary cookies don't require consent.
Is Google Analytics banned in Moldova? No, but it requires prior consent and the transfer of data to the United States must be declared in your privacy policy.
Do I need a DPO? Only if you are a public authority, systematically monitor individuals on a large scale, or process special categories of data on a large scale. Most SMEs have no such obligation, but it is prudent to document how you reached that conclusion.
How long do I have to respond to a deletion request? One month from receipt. In complex cases the deadline can be extended by two months, provided the extension is communicated within the first month.
What do I do if my site is hacked and data leaks? Notify the NCPDP within 72 hours of becoming aware. If the risk to affected individuals is high, notify them as well.
Do I need to register with the NCPDP? Prior notification under the old law has been abolished and replaced by the accountability principle: you no longer register, but you must be able to demonstrate compliance at any time.
Is a privacy policy copied from another website good enough? No. It must reflect the data you collect, the tools you use, the vendors involved and the legal bases you rely on. A generic policy is itself evidence that the analysis the law requires was never done.

How WebSupport helps
We're not a law firm and we don't pretend to be. We handle the technical side — exactly the part where a legal adviser tells you what is required but can't configure how.
- Website compliance audit — we inventory every point where your site collects data: forms, cookies, third-party scripts, integrations, pixels. You get a prioritised report.
- A compliant cookie banner — separate categories, genuine script blocking until consent, withdrawal from the footer, logs as proof.
- Policies written for your actual situation, in Romanian, Russian and English, correctly published and indexed.
- Rebuilt forms — minimised fields, active checkbox, stored proof.
- Record of processing activities, completed together with you.
- Technical hardening — HTTPS, updates, tested backups, logs that are actually useful when you need them.
We work with what you already have. You don't need to rebuild your website to be compliant.
👉 Request a compliance audit — we'll tell you, point by point, where you stand.
This article is informational and does not constitute legal advice. For interpretation of the law in your specific circumstances, consult a lawyer specialising in data protection. WebSupport provides the technical implementation of compliance measures.
Last updated: 22 September 2026