AI LAW RADAR · Daily Last verified 25 Aug 2026

Jurisdiction dossier

Moldova: AI regulation & deadlines

Two GDPR-family automated-decision rules, both in force since 23 August 2026; no AI-specific statute. 2 obligations tracked — 2 in force.

Binding — Binding sectoral Flagship law: Law 195/2024 art. 22 and Law 160/2026 art. 11

Two GDPR-family automated-decision rules, both in force since 23 August 2026; no AI-specific statute.

checked 25 Aug 2026 primary source ↗

The Register

2 obligations
Moldova Binding

Law 195/2024 art. 22 — GDPR art. 22 transposed verbatim, in force since 23 August 2026, with the fine phased in over three years

Binds Controllers and processors, with the GDPR's own reach. Art. 2(1) applies the Law to processing wholly or partly by automated means and to non-automated processing of personal data forming part of a filing system. Art. 3(1) catches processing in the context of the activities of an establishment of a controller or processor in Moldova regardless of where the processing happens; art. 3(2) reaches a controller or processor with no establishment in Moldova where the processing relates to offering goods or services to data subjects in Moldova, whether or not payment is required, or to monitoring their behaviour in Moldova; art. 3(3) adds Moldovan diplomatic missions and consular offices. There is no small-entity threshold, no turnover floor and no public/private split — art. 88(4) states that the fines apply to public authorities and institutions as well. Four carve-outs sit at art. 2(2): state secrets under Law no. 245/2008, purely personal or household activity, processing by competent authorities for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, which Law no. 160/2026 governs instead, and data on deceased persons except in the art. 52 case. Hiring is squarely covered: the art. 4 definition of profiling names «performanța la locul de muncă» first, and an automated sift producing a hiring outcome at least similarly significantly affects the candidate. Credit scoring and insurance pricing fall the same way. A decision with a human materially in the loop is outside art. 22(1), which reaches only decisions based «exclusiv» on automated processing; the Law supplies no gloss on what degree of human involvement defeats that.. Art. 22 of Law no. 195 of 25 July 2024 on the protection of personal data gives the data subject «dreptul de a nu fi supusă unei decizii bazate exclusiv pe prelucrarea automatizată, inclusiv pe crearea de profiluri, care produce efecte juridice pentru persoana vizată sau o afectează în mod similar într-o măsură semnificativă» — the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning the data subject or similarly significantly affects them. The three exceptions at art. 22(2) are the GDPR set unchanged: (a) necessary for entering into or performing a contract between the data subject and a controller; (b) authorised by normative acts that also lay down suitable measures to safeguard the data subject's rights, freedoms and legitimate interests; (c) based on the data subject's explicit consent. In the contract and consent cases art. 22(3) requires the controller to implement suitable measures safeguarding rights, freedoms and legitimate interests, «cel puțin dreptul acesteia de a obține intervenție umană din partea operatorului, de a-și exprima punctul de vedere și de a contesta decizia» — at minimum the right to obtain human intervention from the controller, to express a point of view and to contest the decision. Art. 22(4) bars such decisions from resting on the special categories at art. 9(1) unless art. 9(2)(a) or (g) applies and safeguards are in place. The transparency limb is proactive rather than reactive: arts. 13(2)(f), 14(2)(g) and 15(1)(h) each require the controller to disclose «existența unui proces decizional automatizat, inclusiv crearea de profiluri, menționat la art. 22 alin. (1) și (4)» together with meaningful information about the logic involved and about the significance and envisaged consequences of the processing — on collection from the data subject, on collection from a third party, and again on a subject access request. Art. 35(3)(a) makes a data protection impact assessment mandatory where a systematic and extensive evaluation of personal aspects rests on automated processing, including profiling, and forms the basis of decisions producing legal effects or similarly significantly affecting the person. «Creare de profiluri» is defined at art. 4 in GDPR terms and names performance at work first among the aspects it covers.

In force since 23 August 2026, and the date is derived rather than stated on the face of the article. Art. 89(1) reads «Prezenta lege intră în vigoare la expirarea a 24 de luni de la data publicării în Monitorul Oficial al Republicii Moldova»; the Law was published in Monitorul Oficial nr. 367-369 (9305-9307) of 23 August 2024 at art. 574, having been promulgated by Presidential Decree no. 1592-IX of 21 August 2024, so the 24 months expire on 23 August 2026. The National Centre for Personal Data Protection states the same date. The 24-month figure is itself a change from the drafting stage — the Ministry of Justice draft carried 12 months — so the draft text circulating on the government consultation portal is not a safe source for this date. Art. 90(3) repealed, on the same day, Law no. 182/2008 on the Centre's regulations, Law no. 133/2011 on the protection of personal data, and arts. 74-1 to 74-3 and 42-3-4 of the Contravention Code no. 218/2008 — so the automated-decision rule that Moldova had carried since 2011 is superseded rather than supplemented, and data-protection enforcement has moved from contravention proceedings to administrative fines imposed by the Centre. Art. 90(8) preserves consents given under Law 133/2011 where the manner of giving them meets the conditions of the new Law. Law no. 160 of 30 July 2026 amended arts. 63(3), 86(1) and 87(3) of this Law with effect from the same 23 August 2026, extending the fining power to processors as well as controllers. Moldova ratified Protocol CETS 223 amending Convention 108 by Law no. 36 of 20 March 2026 and consented on 15 May 2026, but that Protocol has not entered into force — 33 to 34 ratifications against the 38 that art. 37(2) requires — so its art. 9(1)(a) adds nothing here and the operative rule is the domestic one.

Stated maximum penalty — Up to 2 000 000 Moldovan lei or, in the case of an undertaking, up to 2 per cent of total annual turnover for the year preceding the sanction, whichever is the higher. Art. 88(2)(b) places «drepturile persoanelor vizate, în conformitate cu art. 12-22» in the higher of the Law's two fine bands, and art. 22 sits inside that range; the lower band at art. 88(1), 1 000 000 lei or 1 per cent, covers controller and processor obligations under arts. 8, 11, 25-39, 42 and 43 and does not reach art. 22. Art. 87(4) caps the total at the amount set for the gravest breach where several provisions are infringed in one or connected processing operations, and art. 87(3) requires intent or negligence. The money is phased in: art. 90(4) applies 10 per cent of the fine set by the Centre in the first year, 40 per cent in the second and 100 per cent from the third, so the ceiling in the year to 23 August 2027 is effectively 200 000 lei or 0.2 per cent of turnover. Enforcement runs through the National Centre for Personal Data Protection, which under art. 87(2) may issue a warning instead of a fine for a minor infringement or where a fine would be a disproportionate burden on a natural person, and which publishes summaries of its decisions under art. 84(3). Art. 85(2) gives at least two months for voluntary payment, and decisions are enforced under the Execution Code. Impact tier: all entities.

In force · 23 Aug 2026 checked 25 Aug 2026 Law 195/2024 art. 22 ↗ high confidence
Moldova Binding

Law 160/2026 art. 11 — a flat ban on solely automated decisions by police, prosecutors, courts and prisons

Binds Competent authorities only, and the Law defines the purpose rather than the institution. Art. 1(1) covers processing by competent authorities for the prevention of criminal offences, including prevention of and protection against threats to public order and public security; the detection or investigation of offences or the conduct of criminal prosecution; the trial of criminal cases; and the execution of criminal penalties or safety measures. Art. 2(2) applies it to processing wholly or partly by automated means and to non-automated processing of data forming part of a filing system. Art. 2(3) excludes processing of state-secret data under Law no. 245/2008 so far as necessary and proportionate for national security and defence. The division of labour with the general statute is clean: art. 2(2)(c) of Law 195/2024 carves the same law-enforcement purposes out of the general regime, so a Moldovan police, prosecution, judicial or prison body processing for those purposes answers to art. 11 of this Law and not to art. 22 of Law 195/2024, while the same body processing for any other purpose — its own staff records, for instance — answers to art. 22. Art. 3(1) imports the art. 4 definitions of Law 195/2024, including «creare de profiluri», so the profiling concept is identical across the two. Private controllers are outside this Law entirely.. Law no. 160 of 30 July 2026 on the protection of personal data processed for the purpose of preventing and combating crime transposes Directive (EU) 2016/680, and its art. 11 is drafted as a prohibition rather than as a right the data subject must assert. Art. 11(1): «O decizie întemeiată exclusiv pe prelucrarea automată, inclusiv pe crearea de profiluri, care produce un efect juridic negativ pentru persoana vizată sau care o afectează în mod semnificativ se interzice, cu excepția cazului în care este autorizată de actele normative ce prevăd garanții adecvate pentru drepturile și libertățile persoanei vizate, cel puțin dreptul de a obține intervenția umană din partea operatorului» — a decision based solely on automated processing, including profiling, which produces an adverse legal effect for the data subject or significantly affects them is prohibited, unless authorised by normative acts that provide adequate safeguards, at minimum the right to obtain human intervention from the controller. Two differences from the general regime at art. 22 of Law 195/2024 are load-bearing. First, the only way out is a normative act: there is no contract limb and no consent limb, so a competent authority cannot cure a solely automated decision by obtaining agreement. Second, the effect that triggers the bar is an adverse one — «un efect juridic negativ» — rather than any legal effect. Art. 11(2) bars such decisions from resting on the special categories of data at art. 7 unless appropriate safeguards for the rights, freedoms and legitimate interests of the data subject are in place, and art. 11(3) separately prohibits profiling that results in discrimination against natural persons on the basis of those special categories — an outright ban with no authorisation route at all.

In force since 23 August 2026, stated as a calendar date rather than derived: art. 45(1) reads «Prezenta lege intră în vigoare la data de 23 august 2026». That is 3 days after publication — the Law was adopted on 30 July 2026, promulgated by Presidential Decree no. 729-X of 14 August 2026 and published in Monitorul Oficial nr. 382-385 of 20 August 2026 at art. 404 — and it is the same day the general statute Law 195/2024 took effect, which is plainly deliberate: art. 45(2) uses the occasion to amend arts. 63(3), 86(1) and 87(3) of Law 195/2024 so that the Centre's fining powers reach processors and not only controllers. The two acts were designed as a pair and neither can be read alone: this Law borrows the general statute's definitions (art. 3(1)), its complaint procedure (art. 44(2), citing Chapter VIII section 2 of Law 195/2024) and its fine-setting criteria (art. 43(2), citing art. 87). Moldova had no separate law-enforcement data-protection regime before this — the repealed Law no. 133/2011 covered both spheres — so art. 11 is a new rule rather than a re-enactment.

Stated maximum penalty — Up to 2 000 000 Moldovan lei, imposed by the National Centre for Personal Data Protection on the controller or the processor. Art. 43(1) sets a single band, without the turnover alternative that art. 88 of Law 195/2024 carries, and it attaches to two triggers: (a) a finding of an infringement of this Law, which includes art. 11, and (b) failure to comply with a corrective measure, a temporary or definitive limitation on processing, or a suspension of data flows ordered by the Centre, or refusal of access. Art. 43(2) applies the art. 87 criteria of Law 195/2024 to the setting of the amount, and art. 43(3) sends the money to the state budget. The same taper applies: art. 46(1) sets the fine actually applied at 10 per cent of the amount determined in the first year, 40 per cent in the second and 100 per cent from the third, so the effective ceiling in the year to 23 August 2027 is 200 000 lei. Art. 44 adds an internal-reporting channel — any employee of a competent authority may complain to the Centre about a suspected infringement, the Centre must keep the reporter's identity confidential, and retaliation in the professional context is prohibited. Impact tier: public sector.

In force · 23 Aug 2026 checked 25 Aug 2026 Law 160/2026 art. 11 ↗ high confidence

Questions & answers

From the data

When does Law 195/2024 art. 22 and Law 160/2026 art. 11 take effect in Moldova?

Law 195/2024 art. 22 and Law 160/2026 art. 11 is already in force, with obligations live since August 23, 2026. Two GDPR-family automated-decision rules, both in force since 23 August 2026; no AI-specific statute.

Who must comply with AI rules in Moldova?

Current obligations bind, among others, Controllers and processors, with the GDPR's own reach. Art. 2(1) applies the Law to processing wholly or partly by automated means and to non-automated processing of personal data forming part of a filing system. Art. 3(1) catches processing in the context of the activities of an establishment of a controller or processor in Moldova regardless of where the processing happens; art. 3(2) reaches a controller or processor with no establishment in Moldova where the processing relates to offering goods or services to data subjects in Moldova, whether or not payment is required, or to monitoring their behaviour in Moldova; art. 3(3) adds Moldovan diplomatic missions and consular offices. There is no small-entity threshold, no turnover floor and no public/private split — art. 88(4) states that the fines apply to public authorities and institutions as well. Four carve-outs sit at art. 2(2): state secrets under Law no. 245/2008, purely personal or household activity, processing by competent authorities for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, which Law no. 160/2026 governs instead, and data on deceased persons except in the art. 52 case. Hiring is squarely covered: the art. 4 definition of profiling names «performanța la locul de muncă» first, and an automated sift producing a hiring outcome at least similarly significantly affects the candidate. Credit scoring and insurance pricing fall the same way. A decision with a human materially in the loop is outside art. 22(1), which reaches only decisions based «exclusiv» on automated processing; the Law supplies no gloss on what degree of human involvement defeats that.; Competent authorities only, and the Law defines the purpose rather than the institution. Art. 1(1) covers processing by competent authorities for the prevention of criminal offences, including prevention of and protection against threats to public order and public security; the detection or investigation of offences or the conduct of criminal prosecution; the trial of criminal cases; and the execution of criminal penalties or safety measures. Art. 2(2) applies it to processing wholly or partly by automated means and to non-automated processing of data forming part of a filing system. Art. 2(3) excludes processing of state-secret data under Law no. 245/2008 so far as necessary and proportionate for national security and defence. The division of labour with the general statute is clean: art. 2(2)(c) of Law 195/2024 carves the same law-enforcement purposes out of the general regime, so a Moldovan police, prosecution, judicial or prison body processing for those purposes answers to art. 11 of this Law and not to art. 22 of Law 195/2024, while the same body processing for any other purpose — its own staff records, for instance — answers to art. 22. Art. 3(1) imports the art. 4 definitions of Law 195/2024, including «creare de profiluri», so the profiling concept is identical across the two. Private controllers are outside this Law entirely.. Scope and thresholds vary per instrument — see each row's source for the legal text.

What are the penalties for AI non-compliance in Moldova?

Stated statutory maxima include: Law 195/2024 art. 22 — Up to 2 000 000 Moldovan lei or, in the case of an undertaking, up to 2 per cent of total annual turnover for the year preceding the sanction, whichever is the higher. Art. 88(2)(b) places «drepturile persoanelor vizate, în conformitate cu art. 12-22» in the higher of the Law's two fine bands, and art. 22 sits inside that range; the lower band at art. 88(1), 1 000 000 lei or 1 per cent, covers controller and processor obligations under arts. 8, 11, 25-39, 42 and 43 and does not reach art. 22. Art. 87(4) caps the total at the amount set for the gravest breach where several provisions are infringed in one or connected processing operations, and art. 87(3) requires intent or negligence. The money is phased in: art. 90(4) applies 10 per cent of the fine set by the Centre in the first year, 40 per cent in the second and 100 per cent from the third, so the ceiling in the year to 23 August 2027 is effectively 200 000 lei or 0.2 per cent of turnover. Enforcement runs through the National Centre for Personal Data Protection, which under art. 87(2) may issue a warning instead of a fine for a minor infringement or where a fine would be a disproportionate burden on a natural person, and which publishes summaries of its decisions under art. 84(3). Art. 85(2) gives at least two months for voluntary payment, and decisions are enforced under the Execution Code. Impact tier: all entities.; Law 160/2026 art. 11 — Up to 2 000 000 Moldovan lei, imposed by the National Centre for Personal Data Protection on the controller or the processor. Art. 43(1) sets a single band, without the turnover alternative that art. 88 of Law 195/2024 carries, and it attaches to two triggers: (a) a finding of an infringement of this Law, which includes art. 11, and (b) failure to comply with a corrective measure, a temporary or definitive limitation on processing, or a suspension of data flows ordered by the Centre, or refusal of access. Art. 43(2) applies the art. 87 criteria of Law 195/2024 to the setting of the amount, and art. 43(3) sends the money to the state budget. The same taper applies: art. 46(1) sets the fine actually applied at 10 per cent of the amount determined in the first year, 40 per cent in the second and 100 per cent from the third, so the effective ceiling in the year to 23 August 2027 is 200 000 lei. Art. 44 adds an internal-reporting channel — any employee of a competent authority may complain to the Centre about a suspected infringement, the Centre must keep the reporter's identity confidential, and retaliation in the professional context is prohibited. Impact tier: public sector.. These are the maximum amounts in the instruments; actual enforcement is at the regulator's discretion.