Data protection (GDPR)
Law 124/2024 replaced the 2008 act and aligns Albania with the GDPR. Fines can reach 2 billion lek or 4% of global annual turnover, and the Commissioner has moved from advising to inspecting. We help companies be ready for an inspection.
Who it is for
- →Call centres, BPOs and IT firms processing data for EU clients
- →Banks, insurers, telecoms, clinics and e-commerce
- →Public institutions
What we do
- →Gap assessment against Law 124/2024 and the GDPR
- →Record of processing activities
- →Privacy notices and cookie policies
- →Data processing agreements with suppliers and EU clients
- →Data protection impact assessments
- →International data transfers
- →Data breach response plan
- →Training and representation before the Commissioner
Legal basis & regulators
- →Law no. 124/2024 "On personal data protection"
- →Regulation (EU) 2016/679 (GDPR), where the data of people in the EU is processed
Experience
Risk assessments, data processing agreements, controller and processor determination, breach management, and the lawful basis for processing and sharing data in the payments sector.
Frequently asked questions
No. Law 124/2024 removed the notification duty and replaced it with the record of processing activities, which must be given to the Commissioner on request.
Often yes: directly, where you serve people in the EU, or through your contract with the EU client, which obliges you to apply its standards. Albanian law applies in any case.
Public authorities, and entities whose core activity involves systematic large-scale monitoring of individuals or the processing of special categories of data.