Newsletter No. 26
I. Information and training activities carried out by the NCPDP
During the second quarter of 2026 (April-June), the National Center for Personal Data Protection (NCPDP) continued to register significant progress in its efforts to inform and raise awareness among the general public regarding personal data protection. Through various initiatives, the institution sought to strengthen the public’s understanding of the importance of respecting the right to privacy and the rules governing the processing of personal data. These actions have contributed to increasing the sense of responsibility among both individuals and controllers, with a view to ensuring compliance in the processing and protection of information containing personal data.
During the reporting period, training courses continued to be organized for the subdivisions of the General Police Inspectorate (GPI), in accordance with the training plan approved and signed by the heads of the NCPDP and the GPI on January 28, 2026.
Accordingly, training courses were organized for the following subdivisions:
- April 3 – Telenești Police Inspectorate;
- May 7 – Ungheni Police Inspectorate;
- June 10 – Hîncești Police Inspectorate.
In this context, 202 representatives of the GPI subdivisions were trained.
At the same time, training courses continued to be organized for the subdivisions of the General Inspectorate of Border Police (GIBP), in accordance with the training plan approved and signed by the heads of the NCPDP and the GIBP on January 28, 2026.
Accordingly, training courses were organized for the following subdivisions:
- April 29 – Chișinău International Airport Border Police Sector;
- May 14 – Southern Regional Directorate;
- June 18 – Western Regional Directorate.
In this context, 278 representatives of the GIBP subdivisions were trained.
During the reporting period, the NCPDP continued to demonstrate openness and a spirit of cooperation by organizing a series of training courses, upon request, for representatives of public and private institutions.
Accordingly, training courses were organized for the following institutions:
- April 1 – Institute for Standardization of Moldova;
- April 10 – National Center for Sustainable Energy;
- April 23 – The Alliance of NGOs Active in the Field of Social Protection of Children and Families;
- May 13 – Agency for Military Science and Memory;
- May 16 and May 23 – The Building Administrators’ School;
- May 18 – Ministry of Justice;
- May 22 – National Anticorruption Centre;
- June 4 – National Lottery;
- June 9 – Rîșcani Territorial Medical Association;
- June 16 – Parliament of the Republic of Moldova;
- June 17 – Electoral Council of Telenești District Electoral Constituency No. 34;
- June 26 – Association of Auditors and Auditing Firms of Moldova (AFAM);
- June 29 – National Youth Council of Moldova.
In this context, 772 representatives of the above-mentioned institutions were trained.
The purpose of the training courses was to familiarize participants with issues related to the field of personal data protection, the regulation of personal data processing procedures, as well as the confidentiality and security regime applicable to personal data in accordance with the legislation in force. During the events, the following topics were addressed: the definition of general concepts related to the field of personal data protection; the principles and legal grounds for personal data processing; the rights of data subjects; the processing of special categories of personal data; data protection requirements in the performance of official duties; ensuring the security and confidentiality of processed personal data; aspects related to the designation of the Data Protection Officer (DPO), as well as the DPO’s duties and responsibilities; aspects related to the Data Protection Impact Assessment (DPIA), including the stages of carrying out a DPIA, etc.
At the same time, the information and awareness-raising campaign for the school community entitled “Personal Data Protection and Children’s Safety in the Online Environment” was continued. The purpose of the campaign was to increase children’s awareness and education regarding the importance of personal data protection, the identification of risks in the online environment, and the adoption of responsible, safe and informed behaviour in the digital space, with the aim of supporting children in browsing the Internet safely, ethically and in an informed manner, while reducing their vulnerability to online threats.
The topics addressed during the campaign included: what personal data is; how to protect personal data online; risks and threats in the online environment; safety on communication platforms and online games, etc. Accordingly, several training sessions were organized.
The events took place during the Personal Development class, with fourth-grade students as the target audience. In this context, 102 students were trained.
During the reporting period, the NCPDP launched the national information and awareness-raising campaign “Protect Your Personal Data: Be Vigilant Against Telephone Fraud”, aimed at strengthening public awareness regarding the identification and prevention of telephone fraud attempts, as well as promoting responsible practices in the processing and disclosure of personal data.
As part of the campaign, information materials were developed and distributed throughout the Republic of Moldova through the General Police Inspectorate, the General Inspectorate of Border Police and the Parliament of the Republic of Moldova, thus ensuring the wide dissemination of prevention and awareness messages among citizens.
Among the activities carried out within the campaign was an awareness-raising event organized by the NCPDP in cooperation with the General Inspectorate of Border Police at the Leușeni Border Crossing Point, aimed at increasing citizens’ awareness of the risks associated with telephone fraud attempts and the importance of protecting personal data.
Accordingly, citizens were provided with information materials and practical recommendations on identifying and preventing fraud attempts. They were warned about frequent situations in which unknown individuals contact citizens by telephone while falsely presenting themselves as representatives of banking institutions, law enforcement bodies, public authorities or other entities, with the purpose of obtaining personal data such as name, surname, personal identification number (IDNP), banking details or other sensitive information.
Representatives of the NCPDP emphasized that any request to disclose such information should be treated with the utmost caution and that it is essential to verify both the identity of the caller and the authenticity of the request before disclosing any personal data.
II. Control Activity
During the period April-June 2026, the NCPDP initiated compliance verifications of personal data processing operations in 71 cases. During the reporting period, 59 decisions were issued, of which 25 cases resulted in findings of non-compliance with the legal provisions. During the same period, 33 statements of offence were drawn up and subsequently referred to the competent court for examination.
III. Findings of the National Center for Personal Data Protection
1.The NCPDP found a breach of the provisions of Law No. 133/2011 on Personal Data Protection following the publication, on a social media platform, of images of an identifiable minor without the consent of the legal representative.
During the investigation, the NCPDP established that a user of a social media platform had published photographs depicting a minor child, with the images being accessible to an unlimited number of persons through a public profile. Although the controller claimed that the publication had an exclusively personal purpose, namely conveying birthday wishes to the minor, the Supervisory Authority held that such purpose does not exempt the controller from the obligation to comply with the rules governing the protection of personal data.
The NCPDP reiterated that the image of an identifiable person constitutes personal data and that publishing such an image on a social media platform represents a processing operation, namely the disclosure and dissemination of personal data.
In the case of minors, consent for the processing of personal data must be provided in writing by the legal representative, in accordance with Article 5(3) of Law No. 133/2011. In the present case, the investigation demonstrated that no such consent had been obtained and that none of the exceptions provided for by law were applicable.
The NCPDP also emphasized that publishing images of a minor on a platform accessible to the general public entails the loss of control over their subsequent use, including redistribution, downloading or further dissemination by third parties, which may significantly affect the child’s right to privacy. For this reason, images of minors benefit from an enhanced level of protection, and any processing thereof must strictly comply with the conditions laid down by the applicable legislation.
Furthermore, the NCPDP noted that the mere fact that the photos had been taken in a family context or that the controller had obtained them in the course of previous personal relationships does not confer the right to publish them online. Each act of publishing a child’s images must have its own legal basis and must respect the rights of the data subject.
Following the examination of the circumstances of the case, the NCPDP found a breach of Article 4(1)(a), Article 5(3) and Article 29(1) of Law No. 133/2011 on Personal Data Protection and established the constituent elements of the contravention provided for in Article 74¹(1) of the Contravention Code of the Republic of Moldova concerning failure to comply with the basic conditions for the processing of personal data.
Accordingly, the NCPDP reminds that the protection of children’s personal data is a priority and that the publication of images of minors in the online environment must be carried out only in strict compliance with the legal requirements and with the consent of the legal representative where required by law.
2.The NCPDP registered a notification submitted by the Călărași Police Inspectorate concerning the alleged unlawful processing of students’ personal data at the “Vasile Alecsandri” Theoretical High School through the use of a video surveillance system.
The notification was based on an anonymous call received through the Child Helpline 116 111, alleging that video surveillance cameras had been installed in sanitary facilities intended for students, a situation liable to affect children’s right to privacy, dignity and psychological well-being.
Given the seriousness of the allegations and the fact that they concerned the processing of minors’ personal data, the NCPDP, pursuant to Articles 19, 20 and 27 of Law No. 133/2011 on Personal Data Protection, initiated supervisory proceedings in order to verify the lawfulness of the personal data processing carried out by the “Vasile Alecsandri” Theoretical High School.
Following the verification, the NCPDP noted that the video surveillance implemented in most of the monitored areas (access routes, corridors, sports grounds, parking areas, certain classrooms and other common areas) pursued legitimate purposes related to ensuring the security of students, staff and the institution’s property and was, in principle, appropriate, necessary and proportionate to the objectives pursued. It was also established that the retention period for the recordings was limited to seven days and that monitoring of those areas corresponded to the controller’s legitimate interest.
However, the NCPDP established that, during the period 7-9 March 2026, four video cameras had been installed inside the sanitary facilities intended for students. Although the institution argued that the devices monitored only the access areas and that certain sections had been excluded from the field of view, the mere recording of images within a space intended for the fulfilment of physiological needs constitutes a serious and unjustified interference with the right to privacy, particularly given that the data subjects were minors, a category benefiting from an enhanced level of protection.
The NCPDP found that the controller had failed to demonstrate the existence of a documented assessment of the necessity of such a measure, the absence of less intrusive alternatives, the performance of a data protection impact assessment, or the existence of an explicit legal basis permitting video surveillance in such areas. Under these circumstances, the installation of video cameras in sanitary facilities did not comply with the principles of lawfulness, necessity, proportionality and data minimisation embodied in Law No. 133/2011.
The NCPDP also established that the obligation to inform data subjects had not been fully complied with. Although the institution had displayed notices bearing the wording “Warning! Video Surveillance Area”, these did not contain all the mandatory information required under Article 12 of Law No. 133/2011 and Decision No. 581/2015 of the Center, namely the identity of the controller, the purpose of the processing, the storage period of the recordings, the recipients of the data and the rights of the data subjects.
In its assessment of the case, the NCPDP also took into account relevant European standards, including the case-law of the European Court of Human Rights and the guidelines of the European Data Protection Board, according to which the installation of video surveillance cameras in areas such as toilets, changing rooms or other premises intended for intimate activities is, in principle, incompatible with the right to respect for private life, regardless of the legitimate purpose invoked.
Consequently, the Supervisory Authority concluded that the “Vasile Alecsandri” Theoretical High School had unlawfully processed the personal data of minor students through the four video cameras installed inside the sanitary facilities, in breach of Article 4(1)(a), (b) and (c), as well as Article 5(5)(e) of Law No. 133/2011 on personal data protection.
Accordingly, by decision, the NCPDP found that the “Vasile Alecsandri” Theoretical High School had infringed the legislation governing personal data protection, the acts committed constituting the elements of the contravention provided for in Article 74¹(1) of the Contravention Code of the Republic of Moldova.
3.Following a notification submitted by the Press Council concerning the publication, on a news portal, of a journalistic article disclosing the personal data of a minor who was the victim of sexual abuse, the NCPDP initiated supervisory proceedings to verify the lawfulness of the processing of such data by the editor-in-chief of the portal.
Following the verification, the NCPDP established that the published article disclosed the personal data of a minor, including her name and surname, image, year of birth, personal identification number (IDNP), place of residence, medical information and data relating to her status as the victim of alleged sexual abuse.
The above-mentioned information falls within the category of special categories of personal data (sensitive personal data), the processing of which is strictly regulated and subject to an enhanced level of protection, particularly where the data subject is a minor. The disclosure of such data without complying with the conditions laid down in Law No. 133/2011 on personal data protection constitutes a serious interference with the fundamental rights of the data subject.
The NCPDP acknowledged that the publication of the journalistic material pursued a public interest objective, namely informing society about a serious situation involving a minor and prompting a response from the competent authorities. At the same time, it noted that the existence of a public interest does not exempt the controller from the obligation to comply with the general principles governing personal data protection, including the principles of lawfulness, proportionality and data minimisation.
Although the right to freedom of expression enjoyed by the press is a fundamental element of democracy, recognised by international human rights instruments, including the Universal Declaration of Human Rights and the European Convention on Human Rights, that right is not absolute.
Freedom of expression also entails the responsibility of journalists not to infringe the fundamental rights and freedoms of data subjects. Pursuant to Article 3(4) of Law No. 64/2010, restrictions on freedom of expression are permissible only where necessary to protect a legitimate interest and only insofar as the measure is proportionate to the aim pursued, while maintaining a fair balance between the protected interest and the freedom to impart information. In cases involving minors, the best interests of the child prevail over freedom of expression.
During the examination of the case, the NCPDP found that, although certain information had been voluntarily provided to the editorial office by the minor’s legal representative, this did not relieve the controller of the obligation to independently assess the necessity and proportionality of disclosing such information, particularly in view of the sensitive nature of the data and the vulnerability of the data subject.
The NCPDP further noted that the publication in full of the medical documents, the personal identification number, the image and other elements enabling the direct identification of the minor was not necessary for achieving the journalistic purpose pursued. The public could have been informed by less intrusive means, such as anonymising the information or removing elements identifying the victim.
Although the minor’s personal data were removed from the online platform after publication, the NCPDP found that this measure did not remedy the unlawful nature of the initial processing, since, during the period in which the information was publicly available, it could have been accessed, copied and further disseminated by an indeterminate number of persons.
Consequently, the NCPDP concluded that the processing of the minor’s personal data, carried out through the publication of the article on the news portal by the editor-in-chief, was performed in breach of Article 4(1)(a) and (c), as well as Article 29 of Law No. 133/2011 on personal data protection, thereby violating the principles of lawfulness, proportionality and the obligation to ensure the confidentiality of personal data.
IV. Prevention Activity
During the reporting period, the NCPDP issued a number of clarifications, recommendations and guidance for data subjects.
Protect Your Data! Be Vigilant Against Suspicious Phone Calls
The NCPDP warns citizens about fraudulent schemes in which individuals are contacted by telephone by persons falsely claiming to be employees of JSC “Moldtelecom”. Under the pretext of concluding fixed-line telephone service contracts, they request the disclosure of personal data, including IDNP and home address.
The NCPDP strongly recommends:
- Do not disclose personal data (such as your name, surname, IDNP, home address, etc.) by telephone to unknown persons;
- Terminate suspicious phone calls immediately;
- Verify any request, as well as the identity of the person or company contacting you, without disclosing any information or responding to the request;
- Immediately report any suspected fraud to the Police by submitting a complaint or by calling the emergency number 112;
- Inform your family and friends about attacks involving spoofed phone calls, thereby contributing to raising awareness of emerging online threats and reducing the number of potential victims.
As the national supervisory authority for personal data processing, the NCPDP emphasizes the responsibility of every citizen to ensure the protection of personal data, as the security and confidentiality of such data must remain a priority.
Protect Your Personal Data: Telephone Fraud on the Rise
The NCPDP warns citizens about the increasing number of attempted telephone frauds and scams through which unknown persons seek to obtain personal data, such as IDNP, home address or other confidential information, under various pretexts.
Fraudsters assume various false identities, presenting themselves as employees of law enforcement authorities, representatives of banking institutions, employees of the Intelligence and Security Service, inspectors of the State Tax Service, representatives of telecommunications companies or postal service couriers. In this context, the most common scenarios involve alleged bank account verification, the prevention of purported fraud, the protection of personal savings or “profitable” investment opportunities.
The NCPDP strongly recommends:
- Do not disclose personal data (such as your name, surname, IDNP, home address, etc.) by telephone to unknown persons;
- Terminate suspicious phone calls immediately;
- Verify any request, as well as the identity of the person or company contacting you, without disclosing any information or responding to the request;
- Verify information only through official sources and, in the event of a suspicious phone call, immediately end the conversation and contact the institution concerned directly;
- Immediately report any suspected fraud to the Police by submitting a complaint or by calling the emergency number 112;
- Inform your family and friends about attacks involving spoofed phone calls, thereby contributing to raising awareness of emerging online threats and reducing the number of potential victims.
As the national supervisory authority for personal data processing, the NCPDP emphasizes the responsibility of every citizen to ensure the protection of personal data, as the security and confidentiality of such data must remain a priority.
NCPDP warns: unlawful use of personal data entails sanctions
Against the background of the increasing number of cases in which personal data fall into the possession of unauthorized persons and are subsequently used by fraudsters in various criminal schemes, the NCPDP reiterates that the processing of such information for unlawful purposes constitutes a violation of the legal provisions.
It has been established that personal data, such as IDNP, home address, telephone number or other information capable of identifying an individual, have been or continue to be obtained through various methods, including by misleading citizens through fraudulent telephone calls, deceptive messages, the collection of data published on social media platforms, or unauthorized access to databases.
The NCPDP emphasizes that the use of personal data without a legal basis, for purposes that may prejudice the interests or the fundamental rights and freedoms of the data subject, constitutes a violation of the legislation governing personal data protection or may give rise to criminal or contraventional liability, and is subject to the sanctions provided by law.
In this context, the NCPDP calls on all persons who hold or have access to personal data to exercise the utmost responsibility when processing such information and to refrain from using personal data for unlawful or abusive purposes.
Furthermore, where personal data have been obtained and retained unlawfully, the NCPDP stresses the need to erase or destroy such information in order to prevent its unlawful use. In this regard, the NCPDP reminds that, starting from 23 August 2026, the new Law No. 195/2024 on personal data protection will enter into force, introducing stricter sanctions, including significantly higher fines for the unlawful processing of personal data.
Respect for the right to privacy and the right to personal data protection constitutes a legal obligation and an essential element in safeguarding the dignity and security of every citizen.
The NCPDP emphasizes the importance of exercising caution and responsibility in order to ensure the protection of personal data.
V. International cooperation
- On 11 May 2026, the Center organized the TAIEX workshop “Mechanisms for ensuring the lawfulness of personal data processing”.
The event brought together European experts and representatives of the NCPDP with the objective of strengthening the institutional capacities of the supervisory authority in exercising its supervisory and enforcement powers in the field of personal data protection, within the context of the Republic of Moldova’s alignment with European Union standards.
The workshop took place against the backdrop of accelerating digital transformation and the growing volume of personal data processing, which require stronger mechanisms to safeguard the fundamental right to privacy. It was also held in anticipation of the entry into force of Law No. 195/2024 on personal data protection, which transposes the relevant EU acquis into national legislation.
The main objective of the event was to deepen participants’ understanding of how data protection authorities in the Member States of the European Union exercise their supervisory powers over the lawfulness of personal data processing, while identifying effective solutions and best practices that could be applied in the activities of the NCPDP.
The international experts participating in the workshop were Mr Bartłomiej Kohnke, representative of the Ministry of Justice of Poland, and Mr Hristo Alaminov, representative of the Commission for Personal Data Protection of Bulgaria. They presented the experience and practices of their respective institutions, providing participants with practical insights and useful tools for supervisory activities.
The discussions highlighted the importance of developing effective supervisory mechanisms based on risk assessment, transparency and the proportionate application of corrective measures, as well as the need to strengthen international cooperation in the field of personal data protection.
The workshop was organized and funded by the TAIEX project of the European Commission.
- During 2-4 June 2026, representatives of the Center carried out a study visit entitled “Mechanisms for Supervisory Activities and the Imposition of Administrative Fines” in the Kingdom of the Netherlands, with the aim of strengthening institutional capacities and learning from European best practices in the field of personal data protection within the context of the harmonization of the national legal framework with European Union standards.
The agenda of the visit included meetings and working sessions with representatives of the Dutch Data Protection Authority (Autoriteit Persoonsgegevens – AP), the Ministry of Justice and Security, as well as representatives of the private sector.
During the discussions held at the Dutch Data Protection Authority, participants were presented with the institution’s organizational structure, responsibilities and powers, complaint-handling mechanisms, the management of personal data breaches and supervisory activities. Discussions also covered preventive and awareness-raising measures promoted by the supervisory authority, procedures for imposing corrective measures and sanctions, as well as the authority’s role in reviewing draft legislation.
During the meeting with representatives of the Ministry of Justice and Security of the Kingdom of the Netherlands, participants exchanged views on the experience gained through the implementation of the Dutch GDPR Implementation Act and its possible revision, as well as on the Ministry’s responsibilities in its relations with the independent supervisory authority under the GDPR.
The study visit also included a meeting with representatives of the telecommunications company KPN, during which practical aspects related to data protection governance, voluntary compliance measures, preventive activities and cooperation with the competent supervisory authorities were discussed.
The study visit was organized with the support of the European Union Partnership Mission in the Republic of Moldova (EUPM).
- During 9-11 June 2026, representatives of the Center participated in the 50th Plenary Meeting of the Consultative Comitee of the Convention 108.
One of the key topics discussed concerned the current status of the signature and ratification of the Protocol amending Convention 108 (CETS No. 223), commonly referred to as Convention 108+.
The Secretariat informed participants that, since November 2025, further progress had been achieved, with the Republic of Moldova depositing its instrument of ratification of the Amending Protocol to Convention 108 on 15 May 2026. At the time of the meeting, 46 countries had signed the Protocol, of which 34 had already ratified it.
A significant moment of the meeting was the presentation delivered by H.E. Ambassador Gabriel Revel, Permanent Representative of the Principality of Monaco to the Council of Europe and Chair of the Committee of Ministers’ Rapporteur Group on Legal Cooperation (GR-J). He emphasized that Member States were looking forward to the prompt entry into force of Convention 108+ and that positive pressure on States which had not yet ratified the Protocol continued to increase.
Interinstitutional cooperation within the Council of Europe remains essential. The involvement of the CDBIO, T-CY, CDNET and PC-FIMI committees highlights the cross-cutting nature of personal data protection, which intersects with areas such as biomedicine, cybercrime, emerging digital technologies and information manipulation. The Secretariat will continue exploring opportunities for cooperation and will report on progress in November 2026.
The plenary meeting demonstrated the dynamic and evolving nature of the European legal framework on personal data protection. The Convention 108 Committee continues to play an essential role in shaping public policies, defining the ethical principles of digitalisation and promoting responsible data governance at the global level. Participation in this session provided a valuable opportunity to exchange expertise and strengthen international cooperation, reaffirming the commitment of the Republic of Moldova to safeguarding fundamental rights in the digital era.
- On 15 June 2026, the Center organized the TAIEX workshop “Personal data processing in the context of human resources management: practices and challenges”.
The event brought together representatives of public authorities in the Republic of Moldova responsible for human resources management, as well as specialists from the NCPDP, with the objective of strengthening professional knowledge and capacities regarding the processing of personal data within employment relationships and identifying best practices in this field.
The main objective of the workshop was to deepen participants’ understanding of the legal and practical aspects of personal data processing in employment relationships, employers’ obligations to ensure the security and confidentiality of personal data, and the impact of new technologies on employees’ right to privacy.
The international expert participating in the workshop was Mr Vlad Drăguș, PhD in Law and legal expert within the Romanian National Cybersecurity Unit (DNSC), who presented relevant European experience and best practices concerning personal data protection in employment relationships and information security.
The workshop was organized and funded by the Technical Assistance and Information Exchange Instrument (TAIEX) of the European Commission.
- During 24-25 June 2026, representatives of the Center participated in the 77th meeting of the International Working Group on Data Protection in Technology (IWGDPT), also known as the Berlin Group. The event took place in Warsaw, Republic of Poland, at the invitation of the Polish Personal Data Protection Office (UODO).
The event brought together international experts in the field of personal data protection with the primary objective of strengthening international cooperation and examining the impact of emerging technologies on the right to privacy and the protection of personal data. During the two-day meeting, participants discussed a number of topical issues, including:
- the use of artificial intelligence and the ways in which organizations can adapt their activities to better protect personal data;
- extended reality, new mechanisms enabling users to manage their privacy preferences and the use of cloud-based services;
- developments in new communication technologies and their impact on personal data protection;
- the use of artificially generated data and its role in the development of new digital services.
The meeting agenda also included presentations by international experts, tour de table sessions on recent developments at national level, and thematic discussions dedicated to future trends in emerging technologies and personal data protection.