Skip to content

Guide · 9 min

GDPR in Albania: what law 124/2024 changes

Companies setting up in Albania often assume data protection is a minor matter. Since 2025 it is not: the Albanian framework has been rewritten on the European model.

In short

Albania's law 124/2024 on personal data protection, in force since the very start of 2025, replaces law 9887/2008 and is aligned with the GDPR: the same principles and rights, breach notification within 72 hours, records of processing in place of prior notification, duties around the data protection officer, and penalties on the same scale as the European ones.

For sixteen years data protection in Albania was governed by law 9887 of 2008, a text that predates the GDPR and was in practice treated as a light obligation. With law 124/2024, passed by parliament at the end of 2024, published in the official gazette in January 2025 and in force within days, that framework was replaced by one built on the European regulation.

This is not a cosmetic alignment. The governing principles change, so do the rights granted to individuals, the documentation duties, the rules on transfers to other countries and, above all, the size of the penalties, which follow the same scale as the GDPR. For a company operating in Tirana, the question is no longer whether to deal with it but when.

What changes in practice

The points that affect a company with an office and employees most directly.

  • The same principles as the GDPR

    Lawfulness, fairness and transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity and confidentiality, plus accountability: you have to be able to demonstrate that you meet the others.

  • Scope reaching outside Albania

    The law also applies to controllers not established in Albania who offer goods or services to people in the country or monitor their behaviour. In those cases a representative in Albania is required.

  • Records of processing instead of notification

    The general duty to notify processing to the authority disappears. In its place comes the duty to keep an up-to-date record of what you do with data, produced on request.

  • Breach notification

    Breaches must be documented and reported to the authority without undue delay and, where feasible, within 72 hours. Where the risk to individuals is high, they must be told too.

  • Data protection officer

    The law governs the DPO role and when one must be designated, for both public and private sectors, with an electronic register kept by the authority. Check with your adviser whether your organisation falls within those cases.

  • Penalties on the European scale

    The ceiling is expressed, as under the GDPR, as a very high absolute figure or a percentage of worldwide annual turnover, whichever is greater.

Why it matters even with the company here and clients elsewhere

Many owners with an Sh.p.k. in Tirana reason as if the company sat outside the European perimeter. It does not work that way, on two fronts. On one side, if you process data of people located in the European Union while offering them goods or services, the GDPR still applies to that processing regardless of where you are established. On the other, Albanian law applies to the activity carried out in Albania anyway, starting with your own employees' data.

The practical consequence is that maintaining two different standards helps nobody. Setting the systems to the higher one costs slightly more at the start and removes an entire category of problems later.

From the statute to the configuration

How the obligations translate into things done on the systems.

ObligationTechnical translation
Integrity and confidentialityPersonal accounts, multi-factor authentication, encrypted disks, role-based permissions
Storage limitationDeletion rules on archives and backups, instead of keeping everything forever
Breach notification within 72 hoursRetained logs, a response procedure and someone who knows where to look that same evening
Records of processingAn inventory of where data sits, who can reach it and through which systems
Transfer securityA deliberate choice about where the services you use, and your backup copies, are hosted
AccountabilityWritten documentation of the measures in place, updated when they change

This guide is informational and is not legal advice. Assessments of your specific situation belong with a lawyer or privacy consultant.

Where to start if nothing has been done

In order: personal accounts for everyone, multi-factor authentication on critical access, disk encryption, a deactivation procedure for leavers, protected backup with retention rules. Five measures that cover most of the real risk and can be done in a few weeks.

Frequently asked questions

It was passed at the end of 2024, published in the official gazette in January 2025 and came into force within days, replacing law 9887/2008. Some specific provisions, including those on mandatory impact assessments, have a deferred start date.

Contact

Tell us how many workstations, and by when.

You get a concrete proposal back: hardware, network, backup and support, to buy or to rent. No commitment.