Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014)
Evidence request list. 20 controls, 20 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Enforcement
The IDP Commissioner may investigate complaints, conduct audits and impose administrative sanctions for violations.
- Cooperation with Commissioner investigations
- Records of any sanctions/appeals
- Obstructing Commissioner investigations
Legal Basis
Personal data collected for another purpose may be further processed for historical, scientific or statistical research only where the processing is not used to take measures or decisions about an individual, sensitive data is disclosed for research only on an important public interest and handled by persons bound by confidentiality, and identifying data is encrypted so subjects are no longer identifiable.
- research processing register naming purpose and legal basis
- confidentiality undertakings signed by researchers
- encryption or de-identification procedure and evidence it was applied
- public-interest justification where sensitive data is disclosed
- research data reused to make decisions about individuals
- identifiable data retained in research sets with no encryption
- no confidentiality undertaking from researchers
Processing for journalistic, literary or artistic purposes may be exempted from stated obligations of the Law only on the terms and conditions the Commissioner sets by instruction, and only so far as the exemption reconciles data protection with freedom of expression; acting outside those terms and the code of ethics is an administrative infraction.
- record of which obligations are being relied on as exempt and why
- reference to the Commissioner instruction relied upon
- editorial or ethics code the controller operates under
- blanket claim of journalistic exemption across all processing
- no reconciliation test recorded against freedom of expression
- exemption claimed for obligations it does not cover
Processing requires consent of the data subject or another lawful basis such as contract, legal obligation, vital interest or legitimate interest.
- Lawful-basis register per processing activity
- Consent records where relied on
- No documented legal criterion for processing
Marketing
Direct marketing communications require prior consent and a simple opt-out mechanism in every communication.
- Direct-marketing opt-out mechanism
- Prior-information records before first disclosure for marketing
- No opt-out from direct marketing
Principles
Personal data must be processed fairly, lawfully, for specified purposes, accurate, kept up to date, and not retained longer than necessary.
- Mapping of processing to the Art 5 principles
- Retention limits
- Excessive or indefinite data retention
Processors
Processors must act only on documented instructions of the controller and apply equivalent security measures.
- Processor contract imposing Art 20 duties
- Confidentiality undertakings
- Processor engaged without binding obligations
Registration
Authorisation from the Commissioner is required before processing sensitive data under Article 7 item 2 letter c and before processing personal data under Article 9 item 1, unless that processing is already authorised by a legal provision, and processing needing authorisation may begin only once the authorisation is received.
- Commissioner authorisation decisions held on file
- assessment of which processing operations trigger Article 24
- evidence that processing start dates follow the authorisation date
- citation of the legal provision where the exemption is relied on
- processing started before authorisation was granted
- no assessment of whether Article 24 applies
- exemption claimed with no legal provision identified
Controllers must notify the Information and Data Protection Commissioner of processing operations prior to commencement.
- Notification to the Commissioner with the Art 22 content
- Register entries
- Processing started without notifying the Commissioner
Rights
Any person claiming a violation of rights, freedoms or legal interests over their personal data may complain to or notify the Commissioner and request intervention, with a further route to court; once a complaint is filed the controller must make no changes to the personal data until a final decision.
- complaints log with dates and outcomes
- procedure telling staff to freeze the relevant records once a complaint is filed
- correspondence with the Commissioner
- records edited or deleted after a complaint is lodged
- no route offered to the Commissioner in privacy notices
- complaints handled informally with no record
Anyone who suffers damage as a result of unlawful processing of personal data is entitled to compensation under the rules of the Civil Code.
- register of damage claims and their handling
- insurance or indemnity arrangements covering processing liability
- evidence that unlawful-processing incidents are assessed for harm to individuals
- no assessment of individual harm after an unlawful processing event
- claims routed nowhere because no owner is named
- processor contracts silent on liability
Data subjects must be informed of the identity of the controller, purposes, recipients, and their rights at the time of collection.
- Privacy notice covering Art 18 items
- Data subjects not informed at collection
Data subjects have the right to obtain confirmation of processing and copies of their data within statutory timeframes.
- Access-request handling procedure and logs
- No mechanism to satisfy access requests
Data subjects can request correction of inaccurate data and erasure where processing is unlawful or no longer necessary.
- Rectification/blocking/erasure procedure
- Notification to recipients of corrections
- Inaccurate data not corrected on request
Data subjects can object to processing including direct marketing and to decisions based solely on automated processing.
- Objection-handling process
- Safeguards/human review for automated decisions
- Solely-automated decisions without safeguards
Scope
The law applies to processing of personal data by controllers established in Albania or using means located in Albania.
- Determination that processing falls within the law's scope (incl. public authorities, Art 3/1)
- Processing wrongly treated as out of scope
Security
Controllers must implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration or loss.
- Technical & organisational security measures
- Access controls limiting data to authorised persons (Art 27)
- Inadequate security measures for the risk
Controllers, processors and anyone who learns the content of processed data in the course of their duties remain bound by confidentiality and credibility after their functions end, must not disclose the data except where the law provides, and must not process data they can access without the controller's authorisation unless the law makes it mandatory.
- signed confidentiality undertakings for staff, contractors and processors
- clauses that survive termination of employment or contract
- access authorisation records showing who may process what
- leaver process confirming the obligation continues
- confidentiality clause lapses on termination
- contractors and temporary staff never sign one
- staff process records they can technically reach without any authorisation
Special Categories
Sensitive personal data (race, ethnicity, political opinions, religion, health, sexual life, criminal convictions) requires stricter conditions including explicit consent or specific legal authorisation.
- Sensitive-data processing justification (Art 7 conditions)
- Commissioner authorisation where required
- Sensitive data processed without an Art 7 condition
Transfers
Transfers to countries with an adequate level of protection are permitted; others require IDP authorisation, contractual safeguards or consent.
- Transfer assessment (adequate-country vs Commissioner authorisation)
- Authorisation records under Art 9
- Transfer to a non-adequate country without authorisation
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) framework page.