Self-check

What Moldova's new laws ask - in short.

Who each law covers, what it actually requires, and since when. Then check where you stand in a few minutes.

ASC
Law 48/2023HG 562/2025

Cybersecurity

Moldova's NIS2-style regime: minimum security measures and incident reporting, supervised by the Agency for Cybersecurity.

Who it covers

  • Essential and important entities in critical sectors - energy, transport, health, finance, digital
  • ICT and digital-infrastructure service providers

What it asks, in short

  • Minimum technical and organisational measures (the HG 562/2025 annex)
  • Incident reporting to the ASC: initial notice within 24 hours
  • An external security audit at least every three years

First compliance-assessment report: 5 April 2027 (essential), 5 October 2027 (important)

CNPDCP
Law 195/2024

Data protection

Moldova's GDPR: rules for any processing of personal data, supervised by the National Center for Personal Data Protection. Replaces Law 133/2011.

Who it covers

  • Practically every company - customer, employee or user data
  • Online shops, clinics, hospitality, IT - regardless of size

What it asks, in short

  • A lawful basis and records of processing
  • People's rights: access, deletion, rectification - answered within a month
  • Breach notification within 72 hours

In force since 23 August 2026

General information, not legal advice. References to regulators and named frameworks are for identification only. Check your obligations against the official texts.

Free · 2 minutes

Not sure which of Moldova's new laws apply to you?

Most businesses fall under at least one, and Law 195/2024 has been in force since 23 August 2026. Answer 7 quick questions for an instant, tailored read: which laws apply to you, where your gaps are, and where to start. No email required.