Law 195/2024 art. 22 — GDPR art. 22 transposed verbatim, in force since 23 August 2026, with the fine phased in over three years
Binds Controllers and processors, with the GDPR's own reach. Art. 2(1) applies the Law to processing wholly or partly by automated means and to non-automated processing of personal data forming part of a filing system. Art. 3(1) catches processing in the context of the activities of an establishment of a controller or processor in Moldova regardless of where the processing happens; art. 3(2) reaches a controller or processor with no establishment in Moldova where the processing relates to offering goods or services to data subjects in Moldova, whether or not payment is required, or to monitoring their behaviour in Moldova; art. 3(3) adds Moldovan diplomatic missions and consular offices. There is no small-entity threshold, no turnover floor and no public/private split — art. 88(4) states that the fines apply to public authorities and institutions as well. Four carve-outs sit at art. 2(2): state secrets under Law no. 245/2008, purely personal or household activity, processing by competent authorities for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, which Law no. 160/2026 governs instead, and data on deceased persons except in the art. 52 case. Hiring is squarely covered: the art. 4 definition of profiling names «performanța la locul de muncă» first, and an automated sift producing a hiring outcome at least similarly significantly affects the candidate. Credit scoring and insurance pricing fall the same way. A decision with a human materially in the loop is outside art. 22(1), which reaches only decisions based «exclusiv» on automated processing; the Law supplies no gloss on what degree of human involvement defeats that.. Art. 22 of Law no. 195 of 25 July 2024 on the protection of personal data gives the data subject «dreptul de a nu fi supusă unei decizii bazate exclusiv pe prelucrarea automatizată, inclusiv pe crearea de profiluri, care produce efecte juridice pentru persoana vizată sau o afectează în mod similar într-o măsură semnificativă» — the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning the data subject or similarly significantly affects them. The three exceptions at art. 22(2) are the GDPR set unchanged: (a) necessary for entering into or performing a contract between the data subject and a controller; (b) authorised by normative acts that also lay down suitable measures to safeguard the data subject's rights, freedoms and legitimate interests; (c) based on the data subject's explicit consent. In the contract and consent cases art. 22(3) requires the controller to implement suitable measures safeguarding rights, freedoms and legitimate interests, «cel puțin dreptul acesteia de a obține intervenție umană din partea operatorului, de a-și exprima punctul de vedere și de a contesta decizia» — at minimum the right to obtain human intervention from the controller, to express a point of view and to contest the decision. Art. 22(4) bars such decisions from resting on the special categories at art. 9(1) unless art. 9(2)(a) or (g) applies and safeguards are in place. The transparency limb is proactive rather than reactive: arts. 13(2)(f), 14(2)(g) and 15(1)(h) each require the controller to disclose «existența unui proces decizional automatizat, inclusiv crearea de profiluri, menționat la art. 22 alin. (1) și (4)» together with meaningful information about the logic involved and about the significance and envisaged consequences of the processing — on collection from the data subject, on collection from a third party, and again on a subject access request. Art. 35(3)(a) makes a data protection impact assessment mandatory where a systematic and extensive evaluation of personal aspects rests on automated processing, including profiling, and forms the basis of decisions producing legal effects or similarly significantly affecting the person. «Creare de profiluri» is defined at art. 4 in GDPR terms and names performance at work first among the aspects it covers.
In force since 23 August 2026, and the date is derived rather than stated on the face of the article. Art. 89(1) reads «Prezenta lege intră în vigoare la expirarea a 24 de luni de la data publicării în Monitorul Oficial al Republicii Moldova»; the Law was published in Monitorul Oficial nr. 367-369 (9305-9307) of 23 August 2024 at art. 574, having been promulgated by Presidential Decree no. 1592-IX of 21 August 2024, so the 24 months expire on 23 August 2026. The National Centre for Personal Data Protection states the same date. The 24-month figure is itself a change from the drafting stage — the Ministry of Justice draft carried 12 months — so the draft text circulating on the government consultation portal is not a safe source for this date. Art. 90(3) repealed, on the same day, Law no. 182/2008 on the Centre's regulations, Law no. 133/2011 on the protection of personal data, and arts. 74-1 to 74-3 and 42-3-4 of the Contravention Code no. 218/2008 — so the automated-decision rule that Moldova had carried since 2011 is superseded rather than supplemented, and data-protection enforcement has moved from contravention proceedings to administrative fines imposed by the Centre. Art. 90(8) preserves consents given under Law 133/2011 where the manner of giving them meets the conditions of the new Law. Law no. 160 of 30 July 2026 amended arts. 63(3), 86(1) and 87(3) of this Law with effect from the same 23 August 2026, extending the fining power to processors as well as controllers. Moldova ratified Protocol CETS 223 amending Convention 108 by Law no. 36 of 20 March 2026 and consented on 15 May 2026, but that Protocol has not entered into force — 33 to 34 ratifications against the 38 that art. 37(2) requires — so its art. 9(1)(a) adds nothing here and the operative rule is the domestic one.
Stated maximum penalty — Up to 2 000 000 Moldovan lei or, in the case of an undertaking, up to 2 per cent of total annual turnover for the year preceding the sanction, whichever is the higher. Art. 88(2)(b) places «drepturile persoanelor vizate, în conformitate cu art. 12-22» in the higher of the Law's two fine bands, and art. 22 sits inside that range; the lower band at art. 88(1), 1 000 000 lei or 1 per cent, covers controller and processor obligations under arts. 8, 11, 25-39, 42 and 43 and does not reach art. 22. Art. 87(4) caps the total at the amount set for the gravest breach where several provisions are infringed in one or connected processing operations, and art. 87(3) requires intent or negligence. The money is phased in: art. 90(4) applies 10 per cent of the fine set by the Centre in the first year, 40 per cent in the second and 100 per cent from the third, so the ceiling in the year to 23 August 2027 is effectively 200 000 lei or 0.2 per cent of turnover. Enforcement runs through the National Centre for Personal Data Protection, which under art. 87(2) may issue a warning instead of a fine for a minor infringement or where a fine would be a disproportionate burden on a natural person, and which publishes summaries of its decisions under art. 84(3). Art. 85(2) gives at least two months for voluntary payment, and decisions are enforced under the Execution Code. Impact tier: all entities.