From 23 August 2026 Moldova applies a new personal data protection law — no. 195/2024. It transposes the European GDPR into national law and concerns any online store that takes orders, sends newsletters or measures analytics. In ECOM the data protection mode is already built into the platform and enabled by default.
What the law is and when it applies
Law 195/2024 was adopted on 25 July 2024 and published in Monitorul Oficial on 23 August 2024. It enters into force 24 months after publication — on 23 August 2026. From that day the old Law 133/2011 is repealed, together with articles 74¹–74³ of the Contravention Code, under which penalties for personal data violations have been issued until now.
The new law is built on the European GDPR: the same legal bases for processing, the same rights for individuals, the same accountability principle — it is not enough to follow the rules, you must be able to prove it. The supervisory authority stays the same — the National Centre for Personal Data Protection (CNPDCP) — but with wider powers: audits, access to systems and premises, orders, temporary or permanent bans on processing, and fines the Centre imposes itself.
Fines and the gradual start
- up to 1,000,000 lei or 1% of the previous year's turnover — for breaching the controller's duties: records of processing, security measures, breach notification, rules on children's data;
- up to 2,000,000 lei or 2% of turnover — for breaching the processing principles and conditions of consent, customers' rights, cross-border transfer rules, and for failing to comply with the Centre's orders.
Whichever figure is higher applies. The law does, however, phase the penalties in: in the first year after entry into force only 10% of the calculated amount is collected, in the second — 40%, and only from the third year — 100%. A fine requires proven intent or negligence, and for minor breaches the Centre may issue a warning instead.
There is no duty to register the store as a controller or notify the Centre about processing — that procedure was abolished earlier. Accountability applies instead: you must keep internal records of processing, the policies, and proof of consents.
Who the law applies to
Anyone processing the data of people located in Moldova — even if the company has no presence in the country. It is enough to offer goods or services to Moldovan customers or to monitor their behaviour on the site. For an online store, personal data means the name, phone, email, delivery address, IDNP on an invoice, order history, and identifiers in analytics and advertising pixels.
What the law requires from an online store
A legal basis for every processing operation. Placing and delivering an order is performance of a contract — no extra consent is needed. Newsletters, retargeting, behavioural analytics and passing data to a partner (a lender, for instance) do require separate consent.
Consent must be active, unbundled and provable. Pre-ticked boxes do not count: consent has to be an unambiguous action. The consent request is separated from the rest of the text, and withdrawing it must be as easy as giving it. The store carries the burden of proof — which means a log: who consented, when, to what, and under which version of the policy.
Transparency. The privacy policy must state: who the controller is and how to reach them, the purposes and legal bases of processing, the recipients of the data, transfers abroad, retention periods, the customer's rights, the right to withdraw consent and to complain to the CNPDCP, whether providing data is mandatory and what happens if it is refused, and whether profiling or automated decisions are used. All in plain language, not a wall of legalese.
Customers' rights and the response deadline. Access, rectification, erasure, restriction of processing, objection, portability. You must respond within one month of the request at the latest; in complex cases the deadline can be extended by two more months, but the extension must be communicated within the first month. The response is free of charge.
A separate right — objecting to marketing. The customer may object to direct marketing at any time and without giving reasons, after which processing for that purpose stops. This right must be communicated explicitly and separately, no later than the first communication.
Records of processing. An internal document: which categories of data, for which purposes, to whom they are disclosed, where they are stored, for how long and with what safeguards. The exemption for companies with fewer than 250 employees barely applies to stores — processing customer data is regular by nature.
Security and incidents. Measures proportionate to the risk: limited access, encryption where relevant, backups, updates, regular testing. A breach must be notified to the CNPDCP within 72 hours of becoming aware of it, and where the risk is high — to the customers as well.
Processors and transfers abroad. With everyone processing data on your behalf (hosting, mailing service, courier, outsourced accounting) you need contractual data processing terms. Transfers to EEA countries need no authorisation; for the rest, standard contractual clauses or other safeguards provided by law are required.
Cookies and newsletters — two separate rules. Law 195/2024 does not contain the word “cookie”: the duty to disclose tracking mechanisms and the consent procedure comes from Law 284/2004 on information society services. The same law bans sending commercial messages by email without the recipient's prior consent. In practice this means a cookie banner with settings and opt-in for the newsletter: that is the only way consent can be obtained and later proved.
The age of consent is 14. For online services addressed to a child under 14, consent is given by their legal representative.
What ECOM has already done for you
The platform has a data protection mode — Privacy Mode. It is enabled by default in every ECOM store, and it is not a set of patches but one coherent logic: no optional script runs before consent, and every consent is stored as evidence.
Cookie banner and category settings
The banner appears on the first visit and does not disappear until the customer makes a choice. Three equal buttons — “Accept all”, “Reject all” and “Settings”: refusing must be no harder than agreeing.

The settings window holds four categories:
- necessary — session, cart, checkout, language and currency choice, form protection and anti-fraud, storing the cookie choice itself; these cannot be switched off;
- analytics — Google Analytics 4, GTM, Hotjar, Microsoft Clarity;
- marketing — Meta Pixel, Google Ads, TikTok, retargeting;
- functional — live chats, maps, embedded widgets.

The customer switches each optional category on and off separately. The banner and the settings work in every storefront language.
Scripts do not run before consent
Until the customer chooses, analytics and advertising pixels are not loaded at all. Google Consent Mode v2 receives the correct consent state, and when consent is withdrawn the scripts stop and the cookies of those categories are deleted where technically possible. An unknown script with no category assigned does not run — that guards against the classic “a contractor added a pixel and nobody told you”.
Forms: the right consent for each type of processing
Every form where a customer leaves data follows one standard — checkout, one-click purchase, pre-order, credit application, back-in-stock request, feedback, reviews, service centre, and any form built in the constructor:
- transactional — a link to the privacy policy and a notice that by submitting the form the customer confirms they have read the terms; a missing marketing consent never blocks the order;
- marketing — a separate checkbox for receiving messages, unticked by default;
- transfer to third parties (a credit application, for example) — a separate consent specifically for passing data to the chosen partner.
No box is pre-ticked. If a required consent is missing, the form is not submitted and the field is highlighted. The links point to the store's terms page and open in a new tab.

Consent log and policy versions
Every customer action is written as its own record: date and time, chosen categories, language, source (banner or settings window), and the action — accepted all, rejected all, customised, withdrew. Old records are never overwritten, so the consent history can be shown to an inspector. Consent is tied to the version of the privacy and cookie policies, and the policies themselves are versioned: you can see what changed and when. If the changes are significant, the banner can be shown to customers again.
Policy pages
The store has system pages for the terms and the cookie policy in every storefront language. The platform generates the base cookie policy text automatically — categories, purposes, retention periods and a table of the files used; the page carries a permanent “Cookie settings” button through which the customer can change or withdraw consent at any time. Links to the policy sit in the footer, in the banner and in the settings window. The page content is edited in the admin panel separately for each language, with indexing control.

Customer requests, export and erasure
The admin panel has a personal data requests section: a copy of the data, rectification, erasure, withdrawal of consent, restriction of processing. Each request has a status and an owner, so the one-month deadline is visible instead of being kept in someone's head. A customer's data is exported in one action — profile, addresses, orders, consents, subscriptions, tickets, reviews, loyalty points. For erasure there is an anonymisation procedure: personal details are stripped, while order information that must be kept for accounting and tax purposes stays.
Retention periods, records of processing and processors
Retention periods are configured per data type — enquiries, abandoned carts, consent logs, inactive accounts, technical logs — and the data is purged automatically on a schedule. The records of processing come pre-filled with a store's typical operations: order, registration, delivery, payment, newsletter, analytics, support, reviews, returns, service centre. A separate list covers third parties: what data they receive, for what purpose, in which country, and whether there is an international transfer. There is also a security incident log with a flag for whether the CNPDCP and the customers need to be notified.
Access rights, logs and technical security
Rights to view, export and delete personal data are granted separately from the rest of the admin permissions, and actions on data are written to a log: who did what and when. The site runs over HTTPS only, service cookies carry the Secure and HttpOnly flags, personal data and tokens are never passed in the address bar, and access to an order page is checked.
What the store owner has to do
The platform provides the tools — but the store itself remains the data controller. What is worth closing before 23 August 2026:
- Review and fill in the privacy policy — with the content the law requires (see the next section), in every storefront language.
- Extend the store's terms (/terms) with a section on personal data processing and links to the policies.
- Check the cookie policy against the services you actually use: if you added your own scripts, they must appear in the table and in the right category.
- Appoint someone responsible for customer requests and incidents. A full DPO is not required for an ordinary store — it is mandatory mainly for large-scale systematic monitoring or special categories of data — but you do need a person who answers the emails and meets the one-month deadline.
- Fill in the records of processing and the processor list with your own data: payment service, courier, mailing service, outsourced accounting, CRM. With each of them — contractual data processing terms.
- Configure retention periods: how long you keep enquiries, abandoned carts, inactive accounts.
- Rebuild the mailing list if consent used to be collected via a pre-ticked box or bundled with checkout: that kind of consent does not meet the new law.
- Do not switch Privacy Mode off and do not add advertising scripts outside the category registry — otherwise the pixel fires before consent.
- Write a short internal instruction: what to do when a customer sends a request and when a breach is suspected — 72 hours pass quickly.
What to put in the privacy policy
- who the controller is — legal name, address, contacts for data questions;
- what data is collected and on what basis: order and delivery — contract, newsletter and ads — consent, accounting and warranty — legal obligation;
- the purposes of processing in plain language;
- who receives the data: couriers, payment services, analytics and advertising, hosting;
- whether data leaves Moldova and on what basis;
- retention periods per category of data;
- the customer's rights and how to exercise them — a specific address or form, not “contact us”;
- the right to withdraw consent and the right to complain to the CNPDCP;
- whether profiling and automated decisions are used;
- the date of the last update and a link to the cookie policy.
What to add to the store terms (/terms)
- a separate section on personal data with links to the privacy and cookie policies;
- which data is mandatory to place an order and what happens if it is not provided;
- newsletter terms: the subscription is voluntary, separate from the order, and unsubscribing takes one click;
- if you offer credit or instalments — that the data goes to the chosen financial institution and only with separate consent;
- terms for reviews and user content: what gets published and under which name;
- the contact procedure: where to write about data matters and how fast the store replies.
What happens to your analytics — and what to do about it
It is fairer to say this up front: your analytics numbers will drop. Until the customer clicks “Accept”, analytics may not record even the visit itself — let alone the traffic source or the products viewed. Some visitors will choose “Reject all”, others will leave without touching the banner. In the reports it looks like a traffic collapse, although the same number of people are on the site.
This is not a broken counter or a misconfiguration — it is lawful and expected behaviour: the law allows you to count a visitor only after they consent. So once Privacy Mode is on, comparing “before” and “after” in absolute visits is pointless — look at revenue, order count and session-to-order conversion, and read the reports as a sample rather than a census. Google Consent Mode v2 fills part of the gap by modelling, but it will not bring the full picture back.
If you need a fuller view of traffic, there is a second route — server-side analytics. It counts actions on the site's own side, without Google Analytics and without sending data to third-party ad platforms, so far less data is lost. We offer clients our partner's solution — targeting.md: the script is installed on the store, the data stays within the site's perimeter, and the exact configuration and legal basis for processing are agreed for your project. Write to us if you want this setup — we will advise what to connect and how it fits with Privacy Mode.
This material is informational and does not replace legal advice. Primary sources — the text of Law 195/2024 on legis.md and the CNPDCP guidance on datepersonale.md.
