Guide · 9 min
GDPR in Albania: what law 124/2024 changes
Companies setting up in Albania often assume data protection is a minor matter. Since 2025 it is not: the Albanian framework has been rewritten on the European model.
In short
Albania's law 124/2024 on personal data protection, in force since the very start of 2025, replaces law 9887/2008 and is aligned with the GDPR: the same principles and rights, breach notification within 72 hours, records of processing in place of prior notification, duties around the data protection officer, and penalties on the same scale as the European ones.
For sixteen years data protection in Albania was governed by law 9887 of 2008, a text that predates the GDPR and was in practice treated as a light obligation. With law 124/2024, passed by parliament at the end of 2024, published in the official gazette in January 2025 and in force within days, that framework was replaced by one built on the European regulation.
This is not a cosmetic alignment. The governing principles change, so do the rights granted to individuals, the documentation duties, the rules on transfers to other countries and, above all, the size of the penalties, which follow the same scale as the GDPR. For a company operating in Tirana, the question is no longer whether to deal with it but when.
What changes in practice
The points that affect a company with an office and employees most directly.
The same principles as the GDPR
Lawfulness, fairness and transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity and confidentiality, plus accountability: you have to be able to demonstrate that you meet the others.
Scope reaching outside Albania
The law also applies to controllers not established in Albania who offer goods or services to people in the country or monitor their behaviour. In those cases a representative in Albania is required.
Records of processing instead of notification
The general duty to notify processing to the authority disappears. In its place comes the duty to keep an up-to-date record of what you do with data, produced on request.
Breach notification
Breaches must be documented and reported to the authority without undue delay and, where feasible, within 72 hours. Where the risk to individuals is high, they must be told too.
Data protection officer
The law governs the DPO role and when one must be designated, for both public and private sectors, with an electronic register kept by the authority. Check with your adviser whether your organisation falls within those cases.
Penalties on the European scale
The ceiling is expressed, as under the GDPR, as a very high absolute figure or a percentage of worldwide annual turnover, whichever is greater.
Why it matters even with the company here and clients elsewhere
Many owners with an Sh.p.k. in Tirana reason as if the company sat outside the European perimeter. It does not work that way, on two fronts. On one side, if you process data of people located in the European Union while offering them goods or services, the GDPR still applies to that processing regardless of where you are established. On the other, Albanian law applies to the activity carried out in Albania anyway, starting with your own employees' data.
The practical consequence is that maintaining two different standards helps nobody. Setting the systems to the higher one costs slightly more at the start and removes an entire category of problems later.
From the statute to the configuration
How the obligations translate into things done on the systems.
| Obligation | Technical translation |
|---|---|
| Integrity and confidentiality | Personal accounts, multi-factor authentication, encrypted disks, role-based permissions |
| Storage limitation | Deletion rules on archives and backups, instead of keeping everything forever |
| Breach notification within 72 hours | Retained logs, a response procedure and someone who knows where to look that same evening |
| Records of processing | An inventory of where data sits, who can reach it and through which systems |
| Transfer security | A deliberate choice about where the services you use, and your backup copies, are hosted |
| Accountability | Written documentation of the measures in place, updated when they change |
This guide is informational and is not legal advice. Assessments of your specific situation belong with a lawyer or privacy consultant.
Where to start if nothing has been done
In order: personal accounts for everyone, multi-factor authentication on critical access, disk encryption, a deactivation procedure for leavers, protected backup with retention rules. Five measures that cover most of the real risk and can be done in a few weeks.
Frequently asked questions
It was passed at the end of 2024, published in the official gazette in January 2025 and came into force within days, replacing law 9887/2008. Some specific provisions, including those on mandatory impact assessments, have a deferred start date.
Related services
GDPR compliance
The technical setup that holds up to an audit, not a checklist on paper.
View serviceBackup and disaster recovery
Verified copies and a recovery plan that has actually been tested.
View serviceOpening an office in Albania
The piece company-formation consultants don't cover: the physical office.
View serviceContact
Tell us how many workstations, and by when.
You get a concrete proposal back: hardware, network, backup and support, to buy or to rent. No commitment.