It is easy to lose track of where things actually stand with Albania's data protection law. The primary law is in force, but not every provision applies yet; secondary legislation has been arriving in waves; and enforcement has quietly shifted gear.
For a DPO or general counsel trying to decide how urgently to act, the picture feels murkier than it should. The headlines announced a new law in early 2025 and then went quiet, while the real work of building out the regime continued month by month.
The short version: the foundation is fully live, the quiet first year is over, and the parts still on the horizon reward companies that are already prepared. But the detail matters, because "deferred to 2027" has been widely misread as breathing room on obligations that are, in fact, in force today.
What has already happened
December 2024 to January 2025: the law arrives. Law No. 124/2024 was approved on 19 December 2024, published in the Official Gazette on 17 January 2025, and entered into force on 31 January 2025. Some sources date entry into force to 1 February 2025, applying the fifteen-day rule from publication; the difference shifts the end of the transition period by the same fortnight. It repealed the 2008 law and reset Albania's regime on a GDPR-aligned foundation. This is not a cosmetic update: it is a structurally new law, with new obligations around records of processing, impact assessments, breach notification and the role of the data protection officer, and a sanctions ceiling in the GDPR range. Any compliance work anchored to the 2008 law needs to be rebuilt, not refreshed.
Through 2025: the secondary legislation begins. A primary law sets principles; the operational detail comes from instructions issued by the Commissioner. This is where a company learns what a rule actually requires in practice, and in 2025 these instruments arrived steadily.
- Instruction No. 04/2025 on direct marketing. The one most B2C and B2B marketing teams need to read closely. It sets GDPR-aligned consent standards, addresses profiling, and imposes heightened protection for children under 18. In practice it governs email and SMS campaigns, lead databases and behavioural targeting. If your consent capture, unsubscribe flows or purchased contact lists were built under the old regime, this is where they get tested.
- Guidance No. 05/2025 on processing by competent authorities. This addresses law enforcement, prosecution and the courts. Most private companies are not directly bound by it, but it matters to anyone who receives data requests from those authorities, or processes data on their behalf.
- Instruction No. 07/2025 (November 2025) on personal data in media. Replaces the older journalism instructions and governs how personal data appears in reporting and media content. Essential for media organisations, and relevant to any company with a communications, PR or content function that publishes information about identifiable people.
- Instructions No. 08 and No. 09/2025 (20 November 2025): the certification regime. These create the mechanism for data protection seals and marks and set the criteria for accrediting certification bodies. We covered what this means in practice in our piece on the new certification regime.
Meanwhile, sub-legal acts from the old 2008 regime remain in force until they are individually replaced. The rulebook is currently a mix of new and legacy instruments, and part of the compliance task is knowing which is which.
Late 2025 into 2026: enforcement shifts gear. For most of 2025 the Commissioner emphasised guidance over penalties. That posture has changed: two fines were issued in all of 2025, and six in just the first two months of 2026. The absolute numbers are small, but the transition from an advisory authority to an enforcing one is now visible in the record, and it happened faster than a straight-line read of 2025 would have predicted.
The timeline at a glance
The dated sequence runs like this. The law was approved on 19 December 2024, published on 17 January 2025, and came into force on 31 January 2025, repealing the 2008 law. Across 2025, the Commissioner issued Instruction 04/2025 on direct marketing, Guidance 05/2025 on competent authorities, and in November 2025 Instruction 07/2025 on media plus, on 20 November 2025, Instructions 08 and 09/2025 on certification. Enforcement moved from two fines across 2025 to six in the first two months of 2026. Looking forward, the first certification bodies are expected to be accredited during 2026, while a defined set of provisions remains deferred to January 2027.
Read top to bottom, it is the story of a regime that arrived on paper in early 2025 and became operationally real over the following eighteen months.
What is still deferred, and what that does not mean
Not every part of the law took effect on day one. A set of provisions is deferred to January 2027: communicating a breach directly to the affected individuals, the data protection impact assessment duty and prior consultation, codes of conduct and their monitoring bodies, and the equivalent items in the competent-authorities track. Alongside these, the law contemplates a transition and adaptation period of roughly two years from entry into force.
This is the most commonly misunderstood part of the timeline, so it is worth being blunt about it. The deferral is not a reprieve on the core obligations. Records of processing, data subject rights, security measures, breach notification to the Commissioner within 72 hours and DPO designation all apply now.
What is deferred is narrower: the separate obligation to communicate a breach directly to the affected individuals, which is distinct from notifying the Commissioner and that duty is already live; the impact assessment duty and prior consultation; codes of conduct and their monitoring bodies; and the competent-authority rules. The foundation is fully in force. Only certain downstream mechanisms sit on the 2027 clock.
Treating the whole regime as if it starts in 2027 is the single most expensive misreading a company can make right now.
What you should already have, and what is still coming
It helps to split the picture in two.
Live today, and therefore where inspection risk sits: a maintained record of processing activities, a working process for handling data subject requests inside the legal deadlines, a breach procedure capable of notifying the Commissioner inside 72 hours, appropriate security measures, lawful bases documented for each processing activity, marketing consent that meets Instruction 04/2025, and a designated DPO where the law requires one. If any of these is missing in mid-2026, the gap is not a future risk. It is a present one.
Still coming, and therefore where early preparation converts into advantage: direct-to-individual breach communication and codes of conduct arriving with the 2027 provisions, further secondary instructions as the regime matures, and the certification ecosystem becoming operational as bodies are accredited during 2026.
Beyond that, expect the Commissioner to keep issuing secondary legislation and published decisions. Each new instruction narrows the gap between the GDPR-modelled text and Albanian operational practice, and each published decision signals what the authority is prioritising: which sectors, which failures, which obligations. Reading those decisions as they appear is one of the cheapest ways to stay ahead of enforcement.
Where this leaves your company
The honest summary of mid-2026 is this: the grace conferred by a slow first year is gone, the core obligations are fully live, enforcement is accelerating, and the certification layer that will reward early movers is being built right now. There is no part of this timeline that argues for waiting.
The companies in the best position are not the ones that found a shortcut. They are the ones that treated 2025 as the year to build the foundations, the register, the request processes, the assessments, the breach procedure, so that 2026 is about refinement rather than a scramble to catch up. If your organisation is not yet in that position, the work is well understood and entirely achievable. The point of the timeline is simply that the window for doing it calmly, ahead of pressure, is the one that is open now.
Want to know where your company stands against the obligations that are live today? Download the Law 124/2024 compliance checklist or book a 30-minute conversation.