There is a comfortable story Albanian companies tell themselves about enforcement under Law 124/2024: that when the Commissioner eventually comes, the cases will be about sophisticated things. Algorithmic profiling. Large-scale analytics. Some subtle technical failure that nobody could reasonably have prevented. On that reading, a company with no data science team and no ambitions in that direction has time.
The reported record says otherwise. Across the decisions that have been publicly reported so far, the grounds are consistently foundational. Not one of them turns on sophisticated processing. They turn on the things a competent programme does in its first six months.
A note on what can and cannot be known
Before the pattern, the caveat, because it matters for how much weight to put on any of this.
The Commissioner does not publish decisions in a form that can be enumerated or reliably retrieved. The site carries regulatory decisions and guidance, but not a searchable register of sanctions with amounts and grounds. What is publicly known about enforcement therefore comes from press reporting, which is necessarily partial: outlets report what they learn about, not everything that is decided.
So treat any count of fines as a floor, not a total. There are almost certainly decisions that have not been reported. Anyone who tells you precisely how many sanctions have been issued under Law 124/2024, including anyone quoting a tidy year-on-year comparison, is reporting the coverage rather than the record. We have corrected our own earlier articles on exactly this point.
What the reported cases were actually about
With that caveat in place, the pattern across reported decisions is strikingly consistent. The grounds recur:
- Processing without a valid lawful basis, or without consent where consent was the basis being relied on.
- Publishing or disclosing images, video and files without consent. This comes up repeatedly, and it is rarely malicious. It is usually a marketing decision, an internal file shared outward, or footage treated as the organisation's own property.
- Missing or inadequate processor contracts. The vendor handling the data had no agreement meeting Art. 26(3), or had a plain service contract that never mentioned data protection.
- Inadequate security measures under Art. 28, the Albanian equivalent of GDPR Art. 32.
- No documentation of processing. No register under Art. 27, so no way to show what was being processed, why, or on what basis.
- No incident response procedure, which is the operational half of the 72-hour breach duty under Art. 29.
- Failure to inform data subjects.
Read that list again and notice what is absent. No profiling. No cross-border analytics architecture. No novel technology whose risks were genuinely hard to foresee. The reported sanctions have been imposed for not having the documents, the contracts, the basic security and the basic transparency that the law has required since it came into force.
The sizes are no longer trivial
Early reported fines sat in the range of a few thousand euro, which was easy to treat as a cost of doing business. That is no longer a safe assumption. Reported amounts now run from a few thousand euro up to figures in the hundreds of thousands, and the largest reported sanction to date was imposed for precisely the basic cluster described above: images published without consent, no processor contracts, inadequate security, no documentation of processing, and no incident response plan.
That is the detail worth sitting with. The biggest publicly reported fine in the record was not for anything clever. It was for an accumulation of ordinary gaps, each of which would have been visible in a one-day internal review.
Sectors reported so far include healthcare and dental practices, a political party, a public body, IT services and construction. There is no sign of a sector that is being left alone, and nothing about that list suggests a focus on large or technically sophisticated organisations.
Why basic failures are the ones that get found
This is not a coincidence, and it is not that inspectors lack the skill for harder cases. Basic failures are what an inspection is structurally good at finding.
An inspector asks for the register of processing activities. Either it exists or it does not. They ask for the processing agreement with a named vendor. Either it exists and contains the required clauses, or it does not. They ask who viewed a particular record and when. Either there is a log or there is not. They look at your website and your signage, which are visible from outside without asking anyone's permission.
None of that requires forensic analysis. The documentary obligations are binary and they are the first thing examined, which means a programme that is strong on intent and weak on paperwork fails in the opening hour. Sophisticated processing, by contrast, tends to surface only after a complaint, a breach, or a targeted sectoral inquiry.
What this implies for where you spend effort
If the reported record is the best available guide, the order of work is clear, and it is not the order most organisations choose.
Start with the register under Art. 27, because every other question an inspector asks is anchored to it. Then the processor contracts, because they are checked one by one and the gaps are obvious. Then the basics of security under Art. 28 and a written incident procedure, so the 72-hour duty under Art. 29 is something you can execute rather than improvise. Then transparency: the privacy notice that matches what you actually do, and the signage that matches the cameras you actually have.
Only after those should attention move to the harder questions, the impact assessments under Art. 31 and the risk analysis that genuinely demands judgement. Those matter, but no reported decision so far has turned on them, and a programme that starts there while the register is missing has optimised for the wrong inspection.
A short readiness check
Could you produce your register of processing activities today? Does every vendor handling personal data have an agreement that meets Art. 26(3), rather than a service contract that never mentions data protection? Can you show, in writing, what your security measures actually are? Is there a written incident procedure someone could follow at two in the morning? Does your privacy notice describe what the organisation actually does? If any answer is uncertain, you are exposed on exactly the grounds that have produced the sanctions reported so far, not on anything exotic.