Key points
- Law No. 124/2024 protects personal data and harmonizes Albanian rules with the GDPR, the European data protection regulation.
- It applies to Albanian and foreign companies operating in Albania, as well as to those providing services to Albanian citizens from abroad.
- Processing is based on four principles: legality and transparency, minimization, storage limitation, and security.
- Citizens have the right to information, correction, deletion, objection, and data portability.
- The Commissioner oversees implementation through inspections, corrective measures, and fines.
Published January 17, 2025 · Updated August 16, 2026 with practical implementation and frequently asked questions.
Law No. 124/2024 “On the Protection of Personal Data” imposes new rules on Albanian businesses for every piece of personal data they collect and process. The full text can be found at The copy of the law uploaded to our website.
The purpose of the law is to protect individuals' fundamental rights and freedoms, with privacy at its core. At the same time, it represents harmonization with General Data Protection Regulation, the European General Regulation, thus also a concrete step toward integration.
Update, August 2026. The law is now being implemented in practice. The Commissioner has carried out the first inspections and imposed the first fines during 2025, calculated also in relation to the entity's turnover. The decisions are published at Official page of the Commissioner.
Read also: The register of beneficial owners is changing. What does the new draft law bring?
Who does the law apply to?
The scope of application is broad. The law covers Albanian and foreign companies operating in Albanian territory, as well as those providing services to Albanian citizens from outside the country. It includes all forms of data processing, both automatic and manual. Thus, even a physical employee file kept in a drawer constitutes data processing within the meaning of the law.
The four processing principles
| Principle | What does the business require? |
|---|---|
| Legality and transparency | Individuals are clearly informed of the purpose for which their data is collected. |
| Data minimization | Only the data necessary for the specific purpose are collected. |
| Storage limit | The data are deleted as soon as the purpose of collection is fulfilled. |
| Security | Technical and organizational measures against loss or misuse |
What rights do citizens gain?
The right to information comes first. Every individual has the right to know the purpose of the processing, the retention period, the recipients of the data, and the security measures.
Following that come three rights of action. Rectification and erasure, that is, the request to correct inaccurate data or to delete it. Objection, especially for marketing and profiling. And portability, the right to transfer data from one controller to another.
Your business obligations
Data controllers and processors have three main obligations. First, technical security measures, where the law mentions encryption and pseudonymization. Second, protection by design, meaning the principles are applied when building systems and processes, not as a later add-on. Third, cooperation with the supervisory authority, with full availability to the Commissioner.
International data transfer
The transfer of data abroad is allowed under three conditions. The recipient country guarantees the necessary protection, the Commissioner-approved standard clauses are used, and both Albanian and international law are respected. This restriction particularly affects businesses that work with platforms and foreign clients.
Read also: How are foreign businesses registered in Albania?
Who oversees it, and what are the risks of a violation?
The responsible authority is Commissioner for the Right to Information and the Protection of Personal Data. It monitors enforcement through inspections, handles individual complaints, and educates the public with informational campaigns.
Violations are punished with hefty fines and corrective measures, including an order to halt illegal processing. Therefore, the risk is not only financial; a cease-and-desist order can bring entire workflows to a standstill.
For citizens, the law brings real control over their data. For businesses, more transparency and security, with a lower risk of breaches. And for the country, harmonization with European standards that boosts credibility.
Frequently asked questions
Who does Law 124/2024 apply to?
Albanian and foreign companies operating in Albania, as well as those providing services to Albanian citizens from abroad. All forms of processing, both automated and manual, are covered.
Does it also affect small businesses?
Yes. Payroll records, employee files, and client contacts are personal data. Any business that maintains them is a data controller within the meaning of the law.
What should my business do now?
Clearly inform individuals of the purpose of the collection, retain only the necessary data, delete it when the purpose is fulfilled, and implement technical protection measures.
Where does a citizen file a complaint about data misuse?
To the Commissioner for the Right to Information and Protection of Personal Data, who handles complaints and conducts inspections.
Is Law 124/2024 the same as the GDPR?
It is the Albanian harmonization with the GDPR. The principles, rights, and obligations follow the same logic, adapted to our legislation.

