Bidda Sovereign Intelligence · 10,090 Verified Nodes · 39 Sovereign Pillars

Albania Law on Protection of Personal Data No. 9887 of 2008 - IDPC

Albania's Law on Protection of Personal Data No. 9887 - adopted by the Assembly of the Republic of Albania on 10 March 2008 and amended significantly…

What Albania Law on Protection of Personal Data No. 9887 of 2008 - IDPC requires

Albania's Law on Protection of Personal Data No. 9887 - adopted by the Assembly of the Republic of Albania on 10 March 2008 and amended significantly through subsequent legislation (including the 2012 amendments on Law No. 48/2012 and the major GDPR-aligning amendments of 2017 and 2018 enacted as part of Albania's EU accession preparations) - is Albania's primary personal data protection legislation establishing a comprehensive rights-based framework for the protection of personal data. Albania received EU candidate status in 2014 and formally opened EU accession negotiations in 2022, driving progressive GDPR alignment. The supervisory authority is the Commissioner for the Right of Access to Information and Personal Data Protection (Komisioneri për të Drejtën e Informimit dhe Mbrojtjen e të Dhënave - IDPC), an independent institution whose mandate covers both freedom of information and personal data protection in Albania. Key features of Albania's Law on Protection of Personal Data No. 9887 as amended: (1) Scope - applies to personal data processing by public authorities, legal entities, and individuals established in Albania or processing data of Albanian data subjects regardless of establishment; (2) Data processing principles - processing must comply with: lawfulness; purpose limitation; data minimisation (proportionality); accuracy; storage limitation; security; and accountability; (3) Sensitive personal data - enhanced protection for: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; health status; sexual orientation; criminal convictions; biometric data; and genetic data; (4) Lawful processing conditions - consent; contractual necessity; legal obligation; vital interests; public interest; or legitimate interests; (5) Data subject rights - right of access; right to rectification; right to erasure; right to restriction; right to object; right not to be subject to solely automated decisions; and rights relating to data portability (introduced by GDPR-alignment amendments); (6) Data Protection Officer - required for public authorities and organisations processing personal data on a large scale or systematically; (7) Breach notification - controllers must notify the IDPC of personal data breaches within 72 hours of awareness, mirroring the GDPR timeline under the GDPR-alignment amendments; (8) Data Protection Impact Assessment - required for high-risk processing aligned with GDPR standards; (9) Cross-border transfers - personal data may only be transferred to countries providing adequate protection or subject to IDPC-approved safeguards; (10) Penalties - administrative fines graduated by violation severity. Albania's Law is among the most GDPR-aligned data protection frameworks in the Western Balkans, supporting Albania's EU accession trajectory and its significant information technology and outsourcing sector.

Pillar: Data Protection & Privacy · Authority: Commissioner for the Right of Access to Information and Personal Data Protection (IDPC, Albania) · Version: 1.0.0 · Last updated:

Primary source: https://www.idp.al/

SHA-256 integrity: ea9ee6dca3f71557934087d052f40cd0636ea6cdc8c11f59d4cbe45ad6639c17

Primary Citations — 7 traced to source

  • Law on Protection of Personal Data No. 9887 (adopted 10 March 2008, amended through GDPR-alignment legislation, Albania) - processing principles: lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, security, accountability; sensitive personal data: racial/ethnic origin, political opinions, religious beliefs, trade union membership, health, sexual orientation, criminal convictions, biometric, genetic; data subject rights: access, rectification, erasure, restriction, portability, objection, automated decision-making protection; DPO mandatory; 72-hour IDPC breach notification; DPIA required; GDPR-equivalent transfer framework
  • Commissioner for the Right of Access to Information and Personal Data Protection (IDPC, Albania) - independent supervisory authority whose mandate covers both freedom of information and personal data protection; registers DPO notifications; receives breach notifications; investigates complaints; conducts inspections; issues binding orders; imposes administrative fines; publishes compliance guidance aligned with EU EDPB standards; participates in Council of Europe data protection consultations; idp.al is the official IDPC portal

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.