Law No. 195/2024 on Personal Data Protection
Moldova is replacing its 2011 framework with Law No. 195/2024, a substantially GDPR-aligned regime that takes effect on 23 August 2026 and reshapes the obligations of sponsors, CROs and vendors processing health data in the country.
Our Experts Are Here To Help You!
Prepare for Moldova’s new GDPR-aligned Law No. 195/2024, in force from 23 August 2026.
Key Requirements:
- Establish a lawful basis for each processing activity under GDPR-aligned grounds (consent, contract, legal obligation, vital interest, public interest, legitimate interest); processing of health data and other special categories generally requires a specific legal ground.
- Honour reinforced data subject rights: information, access, rectification, erasure, restriction, objection, limitation of automated decision making, and data portability.
- Notify the National Center for Personal Data Protection (NCPDP) of a personal data breach without undue delay and, where feasible, within 72 hours, where the breach is likely to result in a high risk to their rights and freedoms.
- Frame international transfers on a recognised mechanism: transfers to countries offering an adequate level of protection (per the NCPDP list) require no authorisation, while other transfers rely on other safeguards provided by law.
- Meet accountability obligations, including records of processing activities, data protection by design and by default, and data protection impact assessments for high-risk processing.
- Appoint a Data Protection Officer where processing involves regular and systematic monitoring of data subjects on a large scale, or in case of large-scale processing of special categories of data such as health data.
- Apply heightened safeguards to special categories of data (health, genetic and biometric data) that are central to clinical trials, pharmacovigilance and patient support programmes.
How MyData-TRUST Can Support You:
- Build a tailored compliance roadmap for your Moldova operations
- Support DPO and, where required, local representative appointment and governance
- Deliver training and awareness programmes for clinical and research teams
- Review contracts, informed consent forms and clinical trial documentation
Why Compliance Matters for Life Sciences:
- Builds trust in clinical trials and research projects
- Implements safeguards for sensitive health and genetic data
- Mitigates reputational and regulatory risks
Why Choose MyData-TRUST?
- Legal expertise dedicated to data protection compliance
- Proven experience integrating privacy into Life Sciences projects
- Practical support for research and patient data use
- Guidance for cross-border clinical trial data transfers
Frequently asked questions
Does Moldova require foreign sponsors to appoint a local representative?
Yes, subject to conditions. Under the extraterritorial application of Law No. 195/2024, controllers or processors not established in Moldova must appoint a local representative in writing where processing relates to offering goods or services to individuals in Moldova, or monitoring their behaviour within Moldova.
Is personal data breach notification mandatory in Moldova?
Yes. Under Law No. 195/2024, a controller must notify the NCPDP without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to individuals. Breaches likely to result in a high risk must also be communicated without undue delay to the affected data subjects in clear and plain language.
Can clinical trial data be transferred out of Moldova?
Yes, subject to conditions. Law No. 195/2024 permits transfers to countries recognised by the NCPDP as offering an adequate level of protection, or, failing that, on the basis of standard contractual clauses or other safeguards provided by law. This mirrors the GDPR transfer regime and should be documented in the trial’s data governance framework.
Need more information about MyData-TRUST? Get in touch with our experts.
MyData-TRUST offers global coverage

