World Watch/Albania/Data & Privacy

Data & Privacy · Albania

Data protection & privacy laws in Albania (2026)

Comprehensive lawLaw No. 124/2024 'On Personal Data Protection' (in force 31 January 2025), supervised by the Commissioner for the Right to Information and Protection of Personal Data (IDP – idp.al)Country index 85 · A

Albania shaded by its data & privacy status

Albania enacted Law No. 124/2024 on 19 December 2024, published in Official Gazette No. 9 on 17 January 2025 and in force from 31 January 2025, replacing the 2008 Law No. 9887. The new law is fully harmonised with the EU GDPR (Regulation 2016/679) and the Law Enforcement Directive (2016/680), introducing GDPR-equivalent rights, obligations, and sanctions. The independent supervisory authority is the Commissioner for the Right to Information and Protection of Personal Data (IDP), which has shifted to assertive enforcement with a marked increase in fines in early 2026.

Key points

Comprehensive GDPR-aligned law

Law No. 124/2024 repeals Law No. 9887/2008 and mirrors GDPR structure including definitions of pseudonymisation, profiling, data minimisation, and sub-categories of sensitive data (biometric, genetic, health, criminal). Certain provisions, including Data Protection Impact Assessment requirements and prior consultation with the Commissioner, are deferred to take effect within two years of publication (by January 2027).

Supervisory authority

The Commissioner for the Right to Information and Protection of Personal Data (IDP) is an independent public legal entity elected by the Albanian Assembly for a seven-year term. It issues binding guidance, conducts inspections, and imposes administrative fines.

Controller & processor obligations

Controllers must notify the IDP of data breaches within 72 hours and notify affected data subjects when risks are high. Controllers and processors outside Albania must appoint a local representative. The general registration obligation with the Commissioner has been abolished, but prior authorisation remains mandatory for high-risk processing activities.

DPO registry established (June 2025)

Council of Ministers Decision No. 347 of 19 June 2025 created the Electronic Registry of Data Protection Officers, requiring designated DPOs to be registered with the state database, aligning Albania's governance infrastructure with EU standards.

Sanctions

Financial penalties mirror GDPR tiers: up to 1 billion Albanian Lek (or 2% of global annual turnover) for lower-tier violations, and up to 2 billion Albanian Lek (or 4% of global annual turnover) for the most serious infringements such as unlawful processing of special categories of data.

Active enforcement trajectory

In the first two months of 2026 alone, the IDP issued six fines — three times the total issued in the entire preceding year — signalling a decisive shift to proactive enforcement. The IDP also issued binding guidance on CCTV/video surveillance (Guideline No. 03, April 2025) and law enforcement processing (Guidance No. 05/2025, July 2025).

Timeline - major decisions & events

Feb 1, 2026enforcement
Post-reform enforcement surge: six fines in two months under new GDPR-aligned law

In the first two months of 2026 the Albanian Data Protection Commissioner issued six administrative fines — triple the total imposed in all of 2025 — signalling a decisive shift from advisory to assertive enforcement under Law No. 124/2024. Sectors targeted include IT providers, call centres, travel agencies, and medical centres.

EY Albania
Nov 20, 2025guidance
Instruction No. 07/2025: GDPR-inspired framework for journalism and media data processing

The Commissioner adopted Instruction No. 07/2025 governing personal data protection in written, electronic, and audiovisual media, repealing rules dating to 2010–2012 and introducing a modern framework that balances press freedom with privacy rights in line with GDPR principles.

Karanovic & Partners
Jul 1, 2025guidance
Guidance No. 05/2025: Personal data processing by law enforcement authorities

The Commissioner adopted Guidance No. 05/2025 to operationalise Law No. 124/2024 in law enforcement contexts, aligning national practice with EU Directive 2016/680 (the Law Enforcement Directive) and clarifying conditions under which competent authorities may process data for public order and national security purposes.

Karanovic & Partners
May 1, 2025decision
Decision No. 1: Adequate-countries list for cross-border data transfers published

The Commissioner published Decision No. 1 listing countries deemed to offer adequate data protection — including all EU/EEA states and EC-recognised third countries — allowing free transfers to those jurisdictions without additional safeguards such as standard contractual clauses.

Karanovic & Partners
Jan 31, 2025lawofficial
Law No. 124/2024 enters into force — GDPR-equivalent penalties and new obligations apply

Albania's new data protection law became operative, introducing data protection by design and by default, mandatory DPIAs, Data Protection Officers, GDPR-equivalent sanctions (up to ALL 20 million or 4 % of global turnover), and GDPR-aligned definitions for biometric, genetic, and health data; select articles have a two-year transition period.

Albanian Information and Data Protection Commissioner (IDP)
Jul 22, 2022lawofficial
Albania ratifies Convention 108+ — 19th state to upgrade to modernised treaty

Albania forwarded its instrument of ratification for the Amending Protocol to Convention 108 (CETS 223), becoming the 19th state to ratify the modernised treaty whose principles mirror core GDPR concepts; the ratification helped the protocol reach half the signatures needed for its own global entry into force.

Council of Europe
Jul 1, 2022incidentofficial
Iranian state actors ('HomeLand Justice') launch destructive cyberattack on Albanian government

Iranian cyber actors deployed ransomware and disk-wiping malware against Albanian government systems, shutting down e-government services and exfiltrating sensitive personal data including identities of intelligence officers; Albania severed diplomatic ties with Iran in September 2022 — the first country ever to expel a foreign mission solely over a cyberattack.

CISA (U.S. Cybersecurity and Infrastructure Security Agency)
Jan 1, 2014lawofficial
Law No. 120/2014 amends Law No. 9887 — last update before GDPR era

Albania's Parliament amended the 2008 data protection statute, expanding the definitions section and refining processing rules; this was the final substantive modification before the complete replacement in 2024, and left the framework without the key GDPR concepts of pseudonymisation, profiling, or data protection by design.

Albanian Information and Data Protection Commissioner (IDP)
Jun 1, 2005lawofficial
Council of Europe Convention 108 enters into force for Albania

The Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108) — the first binding international data protection instrument — came into force for Albania, establishing foundational international obligations that shaped the 2008 domestic law.

Council of Europe
Jul 22, 1999law
Law No. 8517/1999: Albania's first personal data protection statute enacted

Albania passed its inaugural data protection law, combining it with the right to information and placing oversight with the Ombudsman (Advocate of the People) rather than a dedicated authority; while rudimentary by later standards it established prior notification, consent requirements, and a personal data registry.

Refworld (UNHCR)

Albania - other topics

Last verified 5/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →