Check your site

Rules

Cookies and the law in Moldova

Correct as of September 2026. General information, not legal advice.

If your site has Google Analytics, a Facebook pixel, a chat widget or a video embed, it is writing cookies into your visitor's browser. This article explains, in plain language, what the rules in Moldova ask of you and where the EU rules start to apply on top of them.

Two sets of rules, not one

A site in Moldova usually lives under two regimes at the same time. The first is Moldovan law: Law 195/2024 on personal data protection. It was adopted in July 2024, came into force on 23 August 2026, replaced Law 133/2011 and aligned the Moldovan regime with the European one. The second is the EU's own GDPR and ePrivacy rules, which follow the visitor rather than the company — they apply to a Moldovan site as soon as it offers goods or services to people in the EU, or watches how they behave.

That second point catches more sites than owners expect. A shop in Chișinău that ships to Romania, a hotel that takes bookings from Germany, an agency with clients in the EU — all of them are addressing people in the EU, and the EU rules travel with those people.

What "consent" actually has to look like

The requirement is not that you show a notice. It is that nothing beyond the strictly necessary runs until the visitor has agreed. In practice that means:

  • Analytics, advertising and any third-party embed stay switched off until an answer is given.
  • Refusing is as easy as agreeing — one click, in the same place, with the same visual weight.
  • Silence is not agreement. A banner that only says "by using this site you accept cookies" collects nothing.
  • You can show, later, that a particular visitor agreed to a particular set of categories at a particular time.
  • Withdrawing consent is possible at any time, and takes about as much effort as giving it.

What is "strictly necessary"

A small set of cookies does not need consent because the site cannot work without them: the session that keeps you logged in, the basket contents, a load balancer's routing cookie, the record of the cookie choice itself. Audience measurement, remarketing, heatmaps and A/B tests are not in that set, however useful they are to you.

Who enforces this in Moldova

The National Centre for Personal Data Protection is the supervisory authority. In practice, most cases start with a complaint from a visitor rather than a spot check, and the first contact is usually a request for explanations rather than a fine. That is worth knowing because it changes what you should have ready: a clear record of what your site loads and what each visitor agreed to answers such a request in one email.

A practical order of work

  • Find out what your site actually loads. Most owners are surprised — old tags outlive the campaigns they were added for.
  • Put a banner in place that blocks those scripts until the visitor answers, rather than one that only informs.
  • Write a short cookie page listing what is set, by whom and for how long, and link it from the banner.
  • Keep the consent records. Without them, "we asked" is a claim rather than a fact.
  • Re-check after any change to marketing tags, and at least a few times a year.

Correct as of September 2026. This is general information about how the rules work, not legal advice about your particular site, and no tool — ours included — can put you in "full compliance" on its own. If your case is complicated, or a supervisory authority has already contacted you, talk to a lawyer.

You can see what your own site loads right now with the check below: enter the address, and we will send you a summary of the cookies and third-party services found on your open pages.

We only read public pages. The result appears here, the details go to your email.