Self-check

What the new laws ask - in short.

No legalese: who each law covers, what it actually requires, and from when. Then check where you stand in two minutes.

ASC
Law 48/2023GD 562/2025

Cybersecurity

Moldova's NIS2-style regime: minimum security measures and incident reporting, supervised by the Cybersecurity Agency.

Who it covers

  • Essential and important entities in critical sectors - energy, transport, health, finance, digital
  • ICT and digital-infrastructure service providers

What it asks, in short

  • Minimum security measures (GD 562/2025)
  • Incident reporting to the ASC
  • A designated person responsible for security

Deadlines close in 2026–2027: 12 months (essential) / 18 months (important)

CNPDCP
Law 195/2024

Data protection

Moldova's GDPR: rules for any processing of personal data, supervised by the National Data Protection Centre.

Who it covers

  • Practically every company - customer, employee or user data
  • Online shops, clinics, hospitality, IT - regardless of size

What it asks, in short

  • A legal basis and records of processing
  • People's rights: access, deletion, rectification - answered within a month
  • Breach notification within 72 hours

Applies from 23 August 2026

General information, not legal advice. References to the ASC, CNPDCP and named frameworks are for identification only. Confirm obligations against the official texts.

Free · 2-minute self-check

Not sure which of Moldova's new laws apply to you?

Most businesses fall under at least one, and Law 195/2024 becomes binding on 23 August 2026. Answer 7 quick questions for an instant, tailored read: which laws apply to you, where your gaps are, and where to start. No email required.