Law 124 and GDPR Compliance
Data mapping, record of processing activities, policies, DPIAs and readiness for an inspection by the Commissioner.
Request an initial assessmentAlbanian Law No. 124/2024 on personal data protection aligns the national framework with the GDPR. Any organization that processes personal data of customers, employees or users needs to know what data it holds, why it holds it and how it is protected.
MH Consulting takes you from where you are today to a documented compliance program. We start with a gap assessment and finish with policies, records and procedures that work in practice and stand up to an inspection.
What it covers
- Gap analysis against Law 124/2024 and the GDPR
- Data mapping and record of processing activities
- Legal basis for each processing activity
- Privacy policy, notices and internal procedures
- Data protection impact assessments (DPIA) for high-risk processing
- Data processing agreements with vendors and partners
- Procedure for data subject requests
- Incident response plan and breach notification
- Staff training
Frequently asked questions
Law 124 and GDPR Compliance
Who does Law 124/2024 apply to?
In principle, to any public or private organization that processes personal data in Albania, whatever its size. The specific obligations depend on the type and volume of data you process; we establish this in the initial assessment.
How long does a compliance project take?
It depends on the size of the organization and on how much data and how many systems you have. After the initial assessment we give you a phased plan with dates, so you know what is finished and when.
Is a privacy policy on the website enough?
No. The privacy policy is only the visible part. Compliance also needs a record of processing activities, a legal basis for each processing activity, agreements with processors, procedures for data subject requests and incidents, and trained staff.
Services
Other services
Data Protection Officer (DPO)
Outsourced DPO: advice, monitoring and a contact point for the Commissioner.
Learn moreISO 27001 Implementation and Audit
ISMS design, risk management, Annex A controls and certification support.
Learn moreSOC 1, SOC 2 and SOC 3 Reports
Attestation, readiness and training ahead of the engagement.
Learn morePenetration Testing and Red Teaming
Testing of infrastructure, web, mobile and cloud, with technical and executive reports.
Learn moreIT Audit
Audits against COBIT, NIST and the requirements of local regulators.
Learn moreCybersecurity and Resilience
Risk assessment, security frameworks, business continuity and incident response.
Learn moreLet's talk about your next engagement.
Tell us about your engagement — we typically respond within one business day.
