KERNEX
RORUEN
← All posts
Moldova2026-09-21· 7 min read· by Echipa KERNEX

Law 195/2024: what your Moldovan business website needs from 23 August

The law is in force, fines reach 2 million lei, and most Moldovan websites have a cookie banner that blocks nothing. Six things to check today.

On 23 August 2026, Law No. 195/2024 on personal data protection came into force in Moldova. The old law, 133/2011, stopped applying the day before. The difference is not cosmetic: the new text transposes the GDPR, and fines went from symbolic amounts to up to 1 million lei or 1% of turnover for procedural breaches and up to 2 million or 2% for breaching the principles and people's rights.

There is one piece of good news: the law phases the penalties in — 10% of the amount in the first year, 40% in the second, the full amount from the third. Which means now is the time to sort this out, not in two years.

Below is what a Moldovan business website actually needs. No legal theory, just the checklist.

1. A privacy policy that actually says something

Not a text copied from someone else's site. The law requires you to tell people specific things: who the operator is, what data you collect, for what purpose, on what legal basis, how long you keep it, who you share it with and what rights they have.

The useful part: the law allows you to inform people by publishing on the site rather than by individual notices. One well-written page discharges the obligation for every visitor at once.

Quick check: open your policy and look for the company's full name, its IDNO, its address and an e-mail address where requests can be sent. If they are not there, the policy does not cover you.

2. The operator's name, not "the site administration"

"We reserve the right" and "the site administration" mean nothing legally. An operator is a legal entity with a name, an IDNO and an address. If several brands live on one domain, one company is still answerable — say which.

A trick that saves time: keep the company details in one place in the code and pull them into the policy, the terms, the footer and the automated e-mails. Otherwise the first change of address leaves you with four different versions on the same site.

3. A cookie banner that blocks, not just announces

The most common mistake in Moldova: the banner shows up, but Google Analytics, Meta Pixel or Yandex Metrica have already loaded. That is not consent, that is decoration.

Technically it has to be wired the other way round: everything denied by default, analytics scripts loading only after the button is pressed. With Google Tag Manager that means consent mode set to `denied` before the container loads and `update` after acceptance.

Quick check: open the site in a private window, decline cookies and watch the Network tab for requests to analytics services. If they still go out, the banner is not working.

4. Forms: a separate checkbox, not one for everything

If your contact form collects a name, a phone number and an e-mail, that is data processing. And if, on top of answering the enquiry, you also plan to send a newsletter, you need separate consent — one checkbox for handling the enquiry, another for marketing. A single "I agree to everything" box does not hold.

Consent has to be provable, so log the moment: what text was shown, when the box was ticked, from what address. Without that, there is nothing to show if someone complains.

5. A real channel for people's requests

A person has the right to ask for access to their data, for correction, for deletion, or to object to the processing. You have one month to answer, and the answer is free.

In practice that is three things: an e-mail address published specifically for this, a response template written in advance, and a log where every request and your answer are recorded. The first request always arrives at a bad moment — writing the template beforehand is cheaper.

6. The record of processing activities

The internal document stating what data you process, why, on what basis, how long you keep it and who has access. It is not published, but it is produced during an inspection.

Watch for one trap: the exemption for companies under 250 employees does not apply where processing is not occasional. A site with forms running every day is not occasional processing. In practice most companies with a website need the record.

Two expensive misconceptions

"The data is public, so we can do anything with it." Information being published in a state registry does not take it outside the law. Publication by the state and your aggregation of those records into a profile searchable by name are two different processing operations, with different legitimate-interest assessments.

"We don't collect the IDNP, so it isn't personal data." The IDNP is not the threshold. Personal data means any information about an identifiable person. A name plus a role plus a company identifies someone quite precisely, with no identification number involved.

What we do

When we build a site or a product, this part is in the project from the start rather than glued on at the end: a policy page generated from the company's real details, a banner correctly wired to the analytics container, separate checkboxes in forms with a consent log, response templates and a completed processing record.

We went through the exercise on our own products — including Datero.md, where we publish state-registry data and where the question "what is allowed, and on what basis" comes up on every screen.

If you have a site and are not sure where you stand, write to us — we will look at the six points above and tell you what is missing.

*This text is informational and does not replace legal advice. For specific situations, talk to a lawyer specialising in data protection.*

Question after reading?Write to us →

Let's talk about what you're building.

Whether you need content, software, a strategy or just a second opinion — we're one email away. We respond within 24 working hours.

Fill the form — we show up to the call already prepared, no warm-up questions.

About you

If you have a site — we'll review it before the call and show up prepared. If not — no problem.

About the project

Practice you're interested in *
At least a couple of sentences — minimum 20 characters.
Or directly at
hello@kernex.md
PHONE
+373 68 508 886
HOURS
Daily · 10:00-00:00
LEGAL ENTITY
KERNEXIT S.R.L. · IDNO 1026023040248
ADDRESS
Str. Ștefan Neaga 20, of. 4, MD-2008 Chișinău