Skip to content

Evidence request lists

Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014)

Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Enforcement

AL-DPA-20
Investigations and Sanctions

The IDP Commissioner may investigate complaints, conduct audits and impose administrative sanctions for violations.

Artefacts an auditor will ask for
  • Cooperation with Commissioner investigations
  • Records of any sanctions/appeals
Where this commonly fails
  • Obstructing Commissioner investigations

Legal Basis

AL-DPA-23
Processing for Historical, Scientific and Statistical Research

Personal data collected for another purpose may be further processed for historical, scientific or statistical research only where the processing is not used to take measures or decisions about an individual, sensitive data is disclosed for research only on an important public interest and handled by persons bound by confidentiality, and identifying data is encrypted so subjects are no longer identifiable.

Artefacts an auditor will ask for
  • research processing register naming purpose and legal basis
  • confidentiality undertakings signed by researchers
  • encryption or de-identification procedure and evidence it was applied
  • public-interest justification where sensitive data is disclosed
Where this commonly fails
  • research data reused to make decisions about individuals
  • identifiable data retained in research sets with no encryption
  • no confidentiality undertaking from researchers
AL-DPA-24
Processing for Journalistic, Literary or Artistic Purposes

Processing for journalistic, literary or artistic purposes may be exempted from stated obligations of the Law only on the terms and conditions the Commissioner sets by instruction, and only so far as the exemption reconciles data protection with freedom of expression; acting outside those terms and the code of ethics is an administrative infraction.

Artefacts an auditor will ask for
  • record of which obligations are being relied on as exempt and why
  • reference to the Commissioner instruction relied upon
  • editorial or ethics code the controller operates under
Where this commonly fails
  • blanket claim of journalistic exemption across all processing
  • no reconciliation test recorded against freedom of expression
  • exemption claimed for obligations it does not cover
AL-DPA-3
Lawful Basis for Processing

Processing requires consent of the data subject or another lawful basis such as contract, legal obligation, vital interest or legitimate interest.

Artefacts an auditor will ask for
  • Lawful-basis register per processing activity
  • Consent records where relied on
Where this commonly fails
  • No documented legal criterion for processing

Marketing

AL-DPA-14
Direct Marketing

Direct marketing communications require prior consent and a simple opt-out mechanism in every communication.

Artefacts an auditor will ask for
  • Direct-marketing opt-out mechanism
  • Prior-information records before first disclosure for marketing
Where this commonly fails
  • No opt-out from direct marketing

Principles

AL-DPA-2
Data Quality Principles

Personal data must be processed fairly, lawfully, for specified purposes, accurate, kept up to date, and not retained longer than necessary.

Artefacts an auditor will ask for
  • Mapping of processing to the Art 5 principles
  • Retention limits
Where this commonly fails
  • Excessive or indefinite data retention

Processors

AL-DPA-11
Processor Obligations

Processors must act only on documented instructions of the controller and apply equivalent security measures.

Artefacts an auditor will ask for
  • Processor contract imposing Art 20 duties
  • Confidentiality undertakings
Where this commonly fails
  • Processor engaged without binding obligations

Registration

AL-DPA-27
Prior Checking and Commissioner Authorisation

Authorisation from the Commissioner is required before processing sensitive data under Article 7 item 2 letter c and before processing personal data under Article 9 item 1, unless that processing is already authorised by a legal provision, and processing needing authorisation may begin only once the authorisation is received.

Artefacts an auditor will ask for
  • Commissioner authorisation decisions held on file
  • assessment of which processing operations trigger Article 24
  • evidence that processing start dates follow the authorisation date
  • citation of the legal provision where the exemption is relied on
Where this commonly fails
  • processing started before authorisation was granted
  • no assessment of whether Article 24 applies
  • exemption claimed with no legal provision identified
AL-DPA-5
Notification to IDP Commissioner

Controllers must notify the Information and Data Protection Commissioner of processing operations prior to commencement.

Artefacts an auditor will ask for
  • Notification to the Commissioner with the Art 22 content
  • Register entries
Where this commonly fails
  • Processing started without notifying the Commissioner

Rights

AL-DPA-25
Right to Complain to the Commissioner

Any person claiming a violation of rights, freedoms or legal interests over their personal data may complain to or notify the Commissioner and request intervention, with a further route to court; once a complaint is filed the controller must make no changes to the personal data until a final decision.

Artefacts an auditor will ask for
  • complaints log with dates and outcomes
  • procedure telling staff to freeze the relevant records once a complaint is filed
  • correspondence with the Commissioner
Where this commonly fails
  • records edited or deleted after a complaint is lodged
  • no route offered to the Commissioner in privacy notices
  • complaints handled informally with no record
AL-DPA-26
Compensation for Damage from Unlawful Processing

Anyone who suffers damage as a result of unlawful processing of personal data is entitled to compensation under the rules of the Civil Code.

Artefacts an auditor will ask for
  • register of damage claims and their handling
  • insurance or indemnity arrangements covering processing liability
  • evidence that unlawful-processing incidents are assessed for harm to individuals
Where this commonly fails
  • no assessment of individual harm after an unlawful processing event
  • claims routed nowhere because no owner is named
  • processor contracts silent on liability
AL-DPA-6
Data Subject Rights - Information

Data subjects must be informed of the identity of the controller, purposes, recipients, and their rights at the time of collection.

Artefacts an auditor will ask for
  • Privacy notice covering Art 18 items
Where this commonly fails
  • Data subjects not informed at collection
AL-DPA-7
Right of Access

Data subjects have the right to obtain confirmation of processing and copies of their data within statutory timeframes.

Artefacts an auditor will ask for
  • Access-request handling procedure and logs
Where this commonly fails
  • No mechanism to satisfy access requests
AL-DPA-8
Right of Rectification and Erasure

Data subjects can request correction of inaccurate data and erasure where processing is unlawful or no longer necessary.

Artefacts an auditor will ask for
  • Rectification/blocking/erasure procedure
  • Notification to recipients of corrections
Where this commonly fails
  • Inaccurate data not corrected on request
AL-DPA-9
Right to Object and Automated Decisions

Data subjects can object to processing including direct marketing and to decisions based solely on automated processing.

Artefacts an auditor will ask for
  • Objection-handling process
  • Safeguards/human review for automated decisions
Where this commonly fails
  • Solely-automated decisions without safeguards

Scope

AL-DPA-1
Scope and Definitions

The law applies to processing of personal data by controllers established in Albania or using means located in Albania.

Artefacts an auditor will ask for
  • Determination that processing falls within the law's scope (incl. public authorities, Art 3/1)
Where this commonly fails
  • Processing wrongly treated as out of scope

Security

AL-DPA-10
Security of Processing

Controllers must implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration or loss.

Artefacts an auditor will ask for
  • Technical & organisational security measures
  • Access controls limiting data to authorised persons (Art 27)
Where this commonly fails
  • Inadequate security measures for the risk
AL-DPA-28
Confidentiality Obligation of Controllers, Processors and Staff

Controllers, processors and anyone who learns the content of processed data in the course of their duties remain bound by confidentiality and credibility after their functions end, must not disclose the data except where the law provides, and must not process data they can access without the controller's authorisation unless the law makes it mandatory.

Artefacts an auditor will ask for
  • signed confidentiality undertakings for staff, contractors and processors
  • clauses that survive termination of employment or contract
  • access authorisation records showing who may process what
  • leaver process confirming the obligation continues
Where this commonly fails
  • confidentiality clause lapses on termination
  • contractors and temporary staff never sign one
  • staff process records they can technically reach without any authorisation

Special Categories

AL-DPA-4
Sensitive Data

Sensitive personal data (race, ethnicity, political opinions, religion, health, sexual life, criminal convictions) requires stricter conditions including explicit consent or specific legal authorisation.

Artefacts an auditor will ask for
  • Sensitive-data processing justification (Art 7 conditions)
  • Commissioner authorisation where required
Where this commonly fails
  • Sensitive data processed without an Art 7 condition

Transfers

AL-DPA-12
International Data Transfers

Transfers to countries with an adequate level of protection are permitted; others require IDP authorisation, contractual safeguards or consent.

Artefacts an auditor will ask for
  • Transfer assessment (adequate-country vs Commissioner authorisation)
  • Authorisation records under Art 9
Where this commonly fails
  • Transfer to a non-adequate country without authorisation
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) framework page.