For most of 2025, Albania's new data protection law felt theoretical. It was in force, everyone knew it existed, but few companies felt any pressure to act. Boards treated it as a project for "later", and legal teams filed it behind more urgent matters.

That window is closing. In the first two months of 2026 alone, the Commissioner issued more fines than in all of 2025 - a shift from awareness to enforcement that changes the calculation for every Albanian company that handles personal data.

This guide is about that shift: how the law is actually being enforced, what the penalties have been for, and which obligations are drawing attention. For the full catalogue of what the law requires, scope, principles and rights included, see our overview of Law No. 124/2024.

How the law is enforced

The Commissioner for the Right to Information and the Protection of Personal Data is an independent authority, elected by Parliament for a seven-year term. Its powers are substantial: it can investigate, audit, respond to complaints, and impose administrative sanctions.

Cases reach it in two main ways: a complaint from an individual, typically a customer, an employee or a former partner, or the Commissioner's own initiative. In either case the inquiry usually opens with a request for documents, and the record of processing activities, the privacy notice and the processor contracts are near the top of the list.

On paper the sanctions are severe. Art. 94 sets two tiers, denominated in lek: up to ALL 1 billion or 2% of total annual global turnover, and for the graver infringements up to ALL 2 billion or 4%, whichever is higher. The EUR 10M and EUR 20M figures in circulation are conversions of those amounts, not the statutory ceiling. In practice the fines imposed so far have been far more modest, from around EUR 1,000 to EUR 40,000, reflecting an authority that spent 2025 emphasising guidance over punishment.

The headline ceiling is not the whole cost, though. An investigation consumes management time, a published decision carries reputational weight in a small market, and an order to fix a problem can force a costly remediation on a compressed timetable.

The direction of travel is unmistakable. The Commissioner issued 2 fines in all of 2025, then 6 in just the first two months of 2026. The absolute numbers are still small. The trajectory is the point.

What the fines have actually been for

Many companies assume enforcement will start with the biggest players and the most complex processing, that the Commissioner will chase a sophisticated data-analytics case before it looks at an ordinary employer. The early record suggests the opposite.

Enforcement so far has concentrated on foundational failures: missing information security management systems, inadequate processor contracts, invalid consent, failure to inform data subjects, unpublished privacy policies, and missing DPO appointments. These are not exotic failures. They are the basics.

In other words, the risk is not that your data science is too advanced. It is that your paperwork is missing. A mid-sized firm with clean fundamentals is in a stronger position than a large one with none. The bar right now is not perfection; it is whether the basics exist at all.

The obligations you are judged against

Compliance is not a single document. It is a set of continuous obligations, and these are the ones that surface first in an inspection.

  • A lawful basis for every processing activity. "We have always collected it" is not a basis. A bank relies on legal obligation for anti-money-laundering checks, on contract for servicing a loan, and often on consent for marketing. Three different bases inside the same institution, and consent given for one cannot be stretched to cover the others.
  • Transparency. People must be told, in clear language, what you hold, why, for how long and who you share it with. The test is whether an ordinary customer or employee could actually understand it. A dense legal wall of text that no one reads does not meet the standard.
  • A record of processing activities. A written inventory of everything you do with personal data. This is the single document from which almost every inspection begins. If you cannot produce it, the inspector's first impression is that you do not know what you hold, and everything after that is harder.
  • Data subject rights. Any person can ask to access, correct, delete or port their data, or object to its processing, and you must respond within the legal deadline with identity verification and an audit trail. The request that most often exposes a company is the simplest one: "send me everything you hold about me."
  • Impact assessments. Before any high-risk activity, a new HR system, expanded CCTV, a vendor that will see customer data, an international transfer, you assess the risk and document the mitigation. The value is not the paperwork; it is being forced to ask what could go wrong before you switch something on.
  • Security and breach notification. Security appropriate to the risk, and notification to the Commissioner within 72 hours of becoming aware of a breach. Seventy-two hours is short, and the clock runs from awareness, not from the end of your investigation. Most companies that miss it do so because nobody realised the clock had started.
  • A data protection officer. Where required, a real function with genuine independence rather than a title added to someone's job. We cover when it is mandatory and what it involves in our guide to DPO obligations.
  • Safeguards for international transfers. Email hosted abroad, a cloud CRM, an international payment processor, a parent company's shared HR system. Each of those is a transfer, and each needs a lawful footing.

Because Law 124/2024 is modelled closely on the GDPR, a group that already runs a GDPR programme will find that most of that work transfers. If it does not, the large body of European guidance effectively tells you what "good" looks like.

Where does your organisation stand?

The gap between a company that has done the groundwork and one that has not is wide, and easy for an inspector to see. It is the difference between a short, manageable inquiry and one that escalates.

If you can answer yes to these, you are ahead of most:

  • Do we have a current record of processing activities?
  • A published, accurate privacy notice?
  • A process to answer a data subject request inside the deadline?
  • Signed processing agreements with our vendors?
  • Someone clearly responsible for data protection?
  • A breach procedure that can hit 72 hours?

If any answer is "no" or "not sure", that is where the work, and the risk, begins.

Want to know where your company stands? Download the Law 124/2024 compliance checklist or book a 30-minute conversation.