The law does not only require the rules to be followed; it requires the organization to be able to prove it. The general duty to register with the Commissioner has been replaced by internal documentation that is made available on request.
Accountability (Articles 22 and 23)
- The controller implements appropriate technical and organizational measures, and reviews and updates them as needed.
- Data protection is considered when a system or process is designed, not after it is built.
- By default, only the data needed for each purpose is processed.
Processors (Article 26)
- The controller uses only processors that offer sufficient guarantees.
- Processing takes place under a written contract that sets out the subject matter, duration, nature and purpose of the processing, the type of data and the categories of data subjects.
- The processor processes only on the controller's written instructions.
- The processor does not engage another processor without the controller's prior written authorization.
The record of processing activities (Article 27)
The controller keeps documentation of its processing activities, in writing and in electronic form: the contact details of the controller and of the data protection officer, the purposes, the categories of data subjects and of data, the categories of recipients, transfers abroad and, where possible, erasure deadlines and a description of the security measures. The record is made available to the Commissioner on request.
This duty does not apply to companies and organizations with fewer than 250 employees, unless the processing may result in a risk to data subjects' rights and freedoms, is not occasional, or involves sensitive or criminal data (Article 27(4)). In practice, most organizations that regularly process customer or employee data do not benefit from this exemption.
Security of processing (Article 28)
- Pseudonymization and encryption of personal data.
- The ability to ensure the confidentiality, integrity, availability and resilience of systems.
- The ability to restore access to data within a reasonable time after an incident.
- A process for regularly testing and evaluating the measures.
This guide is for information and is not legal advice. It is based on the text of Law No. 124/2024 as published by the Commissioner. Last checked on 8 October 2026. Full text of the law (PDF, in Albanian)
