Back to Frameworks

Albania Law No. 124/2024 on Personal Data Protection

Albania
vLaw No. 124/2024 (approved 19 December 2024; Fletorja Zyrtare no. 9 of 17 January 2025; in force 1 February 2025; Articles 29(3), 31, 32, 35, 36, 64, 65, 67(2)(3)(5) in force 17 January 2027)
7 domains
52 controls

Albania's GDPR-aligned Law No. 124/2024 On Personal Data Protection, in force since 1 February 2025 and replacing Law 9887/2008: principles, lawful bases, consent (age 16 for online services), sensitive data and criminal records, 30-day responses to rights requests, access, erasure, the right to be forgotten including search engine delisting, restriction, portability, objection and automated decisions, accountability, privacy by design, a representative for foreign businesses, processor contracts, records of processing, security, 72-hour breach notification, confidentiality, impact assessments and prior consultation (in force 17 January 2027), DPOs, transfers under Commissioner adequacy decisions, clauses and binding company rules, journalism, research and direct marketing rules, the law enforcement regime of Part III, and fines up to ALL 2 billion or 4 percent of worldwide turnover. Built from the Commissioner's English version of the Law.

Verified

Albania Law No. 124/2024 on Personal Data Protection is a compliance framework from Albania with 7 domains and 52 controls that map to 250 other frameworks. The largest domains are Part III: processing by competent authorities for security and criminal law purposes (Articles 47 to 74) – Albania Law No. 124/2024 on Personal Data Protection (16 controls), Part II Chapter III: controller and processor obligations, security, breach, impact assessment, DPO, codes and certification (Articles 22 to 38) – Albania Law No. 124/2024 on Personal Data Protection (13 controls), Part II Chapter II: rights of the data subject and their restriction (Articles 12 to 21) – Albania Law No. 124/2024 on Personal Data Protection (9 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

Part II Chapter I: principles and lawful processing (Articles 6 to 11) – Albania Law No. 124/2024 on Personal Data Protection

6 controls
Controls in the Part II Chapter I: principles and lawful processing (Articles 6 to 11) – Albania Law No. 124/2024 on Personal Data Protection domain of Albania Law No. 124/2024 on Personal Data Protection — 6 controls
CodeTitle
albania-law-no-124-2024-on-personal-data-protection::10Article 10: criminal records only under official control or legal authorisation
albania-law-no-124-2024-on-personal-data-protection::11Article 11: processing that does not require identification
albania-law-no-124-2024-on-personal-data-protection::6Article 6: the seven processing principles and accountability
albania-law-no-124-2024-on-personal-data-protection::7Article 7: a lawful basis for every processing and the compatibility test
albania-law-no-124-2024-on-personal-data-protection::8Article 8: valid consent and the age of 16 for online services
albania-law-no-124-2024-on-personal-data-protection::9Article 9: sensitive data prohibited except on nine grounds with safeguards

Part II Chapter II: rights of the data subject and their restriction (Articles 12 to 21) – Albania Law No. 124/2024 on Personal Data Protection

9 controls
Controls in the Part II Chapter II: rights of the data subject and their restriction (Articles 12 to 21) – Albania Law No. 124/2024 on Personal Data Protection domain of Albania Law No. 124/2024 on Personal Data Protection — 9 controls
CodeTitle
albania-law-no-124-2024-on-personal-data-protection::12Article 12: transparent communication and a 30-day response to rights requests
albania-law-no-124-2024-on-personal-data-protection::13Article 13: information to give when collecting data, directly or indirectly
albania-law-no-124-2024-on-personal-data-protection::14Article 14: right of access within 30 days
albania-law-no-124-2024-on-personal-data-protection::15Article 15: rectification and erasure within 30 days
albania-law-no-124-2024-on-personal-data-protection::16Article 16: the right to be forgotten for published data and search results
albania-law-no-124-2024-on-personal-data-protection::17Article 17: restriction of processing and the Commissioner's preliminary order
albania-law-no-124-2024-on-personal-data-protection::18Article 18: data portability
albania-law-no-124-2024-on-personal-data-protection::19Article 19: right to object, absolute for direct marketing
albania-law-no-124-2024-on-personal-data-protection::20Article 20: decisions based solely on automated processing

Part II Chapter III: controller and processor obligations, security, breach, impact assessment, DPO, codes and certification (Articles 22 to 38) – Albania Law No. 124/2024 on Personal Data Protection

13 controls
Controls in the Part II Chapter III: controller and processor obligations, security, breach, impact assessment, DPO, codes and certification (Articles 22 to 38) – Albania Law No. 124/2024 on Personal Data Protection domain of Albania Law No. 124/2024 on Personal Data Protection — 13 controls
CodeTitle
albania-law-no-124-2024-on-personal-data-protection::22Article 22: controller responsibility, measures kept under review, and cooperation
albania-law-no-124-2024-on-personal-data-protection::23Article 23: data protection by design and by default
albania-law-no-124-2024-on-personal-data-protection::24Article 24: joint controllers and their written arrangement
albania-law-no-124-2024-on-personal-data-protection::25Article 25: representative in Albania for non-established controllers and processors
albania-law-no-124-2024-on-personal-data-protection::26Article 26: processors, their contracts and sub-processors
albania-law-no-124-2024-on-personal-data-protection::27Article 27: records of processing activities
albania-law-no-124-2024-on-personal-data-protection::28Article 28: security of processing appropriate to the risk
albania-law-no-124-2024-on-personal-data-protection::29Article 29: personal data breach notification to the Commissioner within 72 hours
albania-law-no-124-2024-on-personal-data-protection::30Article 30: confidentiality of personal data, in contracts and after they end
albania-law-no-124-2024-on-personal-data-protection::31Article 31: data protection impact assessment for high-risk processing
albania-law-no-124-2024-on-personal-data-protection::32Article 32: prior consultation, and prior authorisation for public interest processing
albania-law-no-124-2024-on-personal-data-protection::33Article 33: when a data protection officer must be designated
albania-law-no-124-2024-on-personal-data-protection::34Article 34: tasks, qualifications and independence of the data protection officer

Part II Chapter IV: international data transfer (Articles 39 to 42) – Albania Law No. 124/2024 on Personal Data Protection

4 controls
Controls in the Part II Chapter IV: international data transfer (Articles 39 to 42) – Albania Law No. 124/2024 on Personal Data Protection domain of Albania Law No. 124/2024 on Personal Data Protection — 4 controls
CodeTitle
albania-law-no-124-2024-on-personal-data-protection::39Article 39: transfers abroad only with adequate or specific protection; foreign orders
albania-law-no-124-2024-on-personal-data-protection::40Article 40: transfers to destinations with a Commissioner adequacy decision
albania-law-no-124-2024-on-personal-data-protection::41Article 41: transfers without adequacy: safeguards, authorised clauses, derogations
albania-law-no-124-2024-on-personal-data-protection::42Article 42: binding company rules approved by the Commissioner

Part II Chapter V: processing for specific purposes (Articles 43 to 46) – Albania Law No. 124/2024 on Personal Data Protection

3 controls
Controls in the Part II Chapter V: processing for specific purposes (Articles 43 to 46) – Albania Law No. 124/2024 on Personal Data Protection domain of Albania Law No. 124/2024 on Personal Data Protection — 3 controls
CodeTitle
albania-law-no-124-2024-on-personal-data-protection::43Article 43: journalistic, academic, artistic and literary processing
albania-law-no-124-2024-on-personal-data-protection::45Article 45: archiving, research and statistics safeguards
albania-law-no-124-2024-on-personal-data-protection::46Article 46: direct marketing

Part III: processing by competent authorities for security and criminal law purposes (Articles 47 to 74) – Albania Law No. 124/2024 on Personal Data Protection

16 controls
Controls in the Part III: processing by competent authorities for security and criminal law purposes (Articles 47 to 74) – Albania Law No. 124/2024 on Personal Data Protection domain of Albania Law No. 124/2024 on Personal Data Protection — 16 controls
CodeTitle
albania-law-no-124-2024-on-personal-data-protection::49Article 49: distinguishing categories of persons and verifying data quality
albania-law-no-124-2024-on-personal-data-protection::50 to 52Articles 50 to 52: lawfulness, further purposes and sensitive data in law enforcement
albania-law-no-124-2024-on-personal-data-protection::53Article 53: automated decisions and discriminatory profiling in law enforcement
albania-law-no-124-2024-on-personal-data-protection::54 to 55Articles 54 and 55: modalities for rights and information to data subjects in law enforcement
albania-law-no-124-2024-on-personal-data-protection::56Article 56: access in law enforcement and documented refusals
albania-law-no-124-2024-on-personal-data-protection::57Article 57: rectification, erasure and restriction in law enforcement
albania-law-no-124-2024-on-personal-data-protection::58 to 61Articles 58 to 61: accountability, joint controllers, processors and records in law enforcement
albania-law-no-124-2024-on-personal-data-protection::62Article 62: logging of processing operations
albania-law-no-124-2024-on-personal-data-protection::63Article 63: cooperation with the Commissioner in law enforcement
albania-law-no-124-2024-on-personal-data-protection::64 to 65Articles 64 and 65: impact assessment and prior consultation in law enforcement
albania-law-no-124-2024-on-personal-data-protection::66Article 66: security of law enforcement processing, with ten control objectives
albania-law-no-124-2024-on-personal-data-protection::67Article 67: breach notification in law enforcement
albania-law-no-124-2024-on-personal-data-protection::68 to 69Articles 68 and 69: DPO and confidential reporting of infringements in law enforcement
albania-law-no-124-2024-on-personal-data-protection::70 to 71Articles 70 and 71: law enforcement transfers abroad and adequacy
albania-law-no-124-2024-on-personal-data-protection::72 to 73Articles 72 and 73: law enforcement transfers without adequacy and specific derogations
albania-law-no-124-2024-on-personal-data-protection::74Article 74: direct transfers to recipients that are not competent authorities

Parts IV and V: the Commissioner, cooperation, remedies, liability and penalties (Articles 75 to 95) – Albania Law No. 124/2024 on Personal Data Protection

1 controls
Controls in the Parts IV and V: the Commissioner, cooperation, remedies, liability and penalties (Articles 75 to 95) – Albania Law No. 124/2024 on Personal Data Protection domain of Albania Law No. 124/2024 on Personal Data Protection — 1 controls
CodeTitle
albania-law-no-124-2024-on-personal-data-protection::84Article 84 with Articles 22(4) and 86(2): cooperating with the Commissioner and freezing processing under complaint

Your Compliance Coverage

If you comply with Albania Law No. 124/2024 on Personal Data Protection, you already cover:

Maps to 250 other frameworks

72 total controls
GDPR
11 source controls mapped|21 target controls covered
15%
Nigeria Data Protection Act 2023 (NDPA)
5 source controls mapped|6 target controls covered
7%
Nebraska Data Privacy Act
5 source controls mapped|6 target controls covered
7%
South Korea PIPA
5 source controls mapped|4 target controls covered
7%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
5 source controls mapped|16 target controls covered
7%
ISO/IEC 23894:2023
5 source controls mapped|6 target controls covered
7%
Vietnam Law on Cybersecurity (No. 116/2025/QH15)
4 source controls mapped|3 target controls covered
6%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
4 source controls mapped|2 target controls covered
6%
UK GDPR (UK General Data Protection Regulation)
4 source controls mapped|3 target controls covered
6%
Regional Comprehensive Economic Partnership (RCEP) - E-Commerce Chapter
4 source controls mapped|2 target controls covered
6%
Trinidad and Tobago Data Protection Act 2011
4 source controls mapped|5 target controls covered
6%
TEFCA - Trusted Exchange Framework and Common Agreement
4 source controls mapped|2 target controls covered
6%
Tanzania Personal Data Protection Act 2022
4 source controls mapped|4 target controls covered
6%
Regulation on the European Health Data Space (EHDS)
4 source controls mapped|4 target controls covered
6%
Pakistan Personal Data Protection Bill 2023
4 source controls mapped|3 target controls covered
6%
Israel Protection of Privacy Law (5741-1981)
4 source controls mapped|4 target controls covered
6%
ICH E6(R3) - Good Clinical Practice
4 source controls mapped|3 target controls covered
6%
FTC GLBA Safeguards Rule (16 CFR Part 314)
4 source controls mapped|2 target controls covered
6%
Florida Digital Bill of Rights (FDBR)
4 source controls mapped|4 target controls covered
6%
ISO/IEC 27400:2022
4 source controls mapped|5 target controls covered
6%
AICPA Privacy Management Framework (PMF)
4 source controls mapped|5 target controls covered
6%
WHO Global Strategy on Digital Health 2020-2025
4 source controls mapped|3 target controls covered
6%
Barbados Data Protection Act 2019
4 source controls mapped|7 target controls covered
6%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
4 source controls mapped|8 target controls covered
6%
Sweden Data Protection Act (Dataskyddslag, 2018:218)
4 source controls mapped|3 target controls covered
6%
Azerbaijan Law on Personal Data (2010)
4 source controls mapped|5 target controls covered
6%
Belgium Data Protection Act (Wet van 30 juli 2018, Loi du 30 juillet 2018)
4 source controls mapped|6 target controls covered
6%
South Korea ISMS-P
4 source controls mapped|4 target controls covered
6%
Notifiable Data Breaches Scheme (Australia)
3 source controls mapped|1 target controls covered
4%
NIST SP 800-146
3 source controls mapped|3 target controls covered
4%
NIST SP 800-145
3 source controls mapped|3 target controls covered
4%
NIST SP 800-144
3 source controls mapped|3 target controls covered
4%
MTCS (Singapore)
3 source controls mapped|5 target controls covered
4%
ISMAP (Japan)
3 source controls mapped|2 target controls covered
4%
FedRAMP Rev 5
3 source controls mapped|5 target controls covered
4%
ISO/IEC 29100:2024
3 source controls mapped|6 target controls covered
4%
ISO/IEC 29134:2023
3 source controls mapped|3 target controls covered
4%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
3 source controls mapped|4 target controls covered
4%
ISO/IEC 27011:2024
3 source controls mapped|5 target controls covered
4%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
3 source controls mapped|5 target controls covered
4%
IAIS Insurance Core Principles (ICPs)
3 source controls mapped|2 target controls covered
4%
Connecticut Data Privacy Act (CTDPA)
3 source controls mapped|1 target controls covered
4%
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
3 source controls mapped|3 target controls covered
4%
NIST SP 800-190
3 source controls mapped|4 target controls covered
4%
ISO/IEC 25012:2008 - Data Quality Model
3 source controls mapped|3 target controls covered
4%
SSAE 18 - Attestation Standards (SOC Reporting)
3 source controls mapped|4 target controls covered
4%
SOC 2
3 source controls mapped|5 target controls covered
4%
UK Open Banking Standard
3 source controls mapped|2 target controls covered
4%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
3 source controls mapped|2 target controls covered
4%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
3 source controls mapped|4 target controls covered
4%
Virginia CDPA
3 source controls mapped|3 target controls covered
4%
Vietnam PDPD
3 source controls mapped|2 target controls covered
4%
Uruguay DPL
3 source controls mapped|3 target controls covered
4%
UK AI Regulation Framework
3 source controls mapped|1 target controls covered
4%
Turkey KVKK
3 source controls mapped|2 target controls covered
4%
Texas Data Privacy and Security Act (TDPSA)
3 source controls mapped|1 target controls covered
4%
Taiwan PDPA
3 source controls mapped|3 target controls covered
4%
Qatar DPL
3 source controls mapped|3 target controls covered
4%
Privacy Act 2020
3 source controls mapped|4 target controls covered
4%
Privacy Act 1988 (Australia)
3 source controls mapped|6 target controls covered
4%
POPIA
3 source controls mapped|5 target controls covered
4%
Peru DPL
3 source controls mapped|4 target controls covered
4%
Personal Data Act (personopplysningsloven)
3 source controls mapped|5 target controls covered
4%
PDPA Thailand
3 source controls mapped|5 target controls covered
4%
PDPA Singapore
3 source controls mapped|5 target controls covered
4%
Oregon Consumer Privacy Act
3 source controls mapped|4 target controls covered
4%
OECD AI Principles
3 source controls mapped|1 target controls covered
4%
NIST SP 800-122
3 source controls mapped|5 target controls covered
4%
Nigeria Data Protection Regulation (NDPR)
3 source controls mapped|5 target controls covered
4%
New Jersey Data Privacy Act
3 source controls mapped|3 target controls covered
4%
New Hampshire Data Privacy Act
3 source controls mapped|4 target controls covered
4%
Montana Consumer Data Privacy Act
3 source controls mapped|4 target controls covered
4%
Minnesota Consumer Data Privacy Act
3 source controls mapped|3 target controls covered
4%
Mexico LFPDPPP
3 source controls mapped|5 target controls covered
4%
Mauritius DPA
3 source controls mapped|5 target controls covered
4%
Maryland Online Data Privacy Act of 2024
3 source controls mapped|3 target controls covered
4%
Malaysia PDPA 2010
3 source controls mapped|4 target controls covered
4%
Liechtenstein DPA
3 source controls mapped|3 target controls covered
4%
LGPD
3 source controls mapped|3 target controls covered
4%
Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP)
3 source controls mapped|3 target controls covered
4%
Law No. 172-13 on the Protection of Personal Data
3 source controls mapped|3 target controls covered
4%
Kentucky Consumer Data Protection Act
3 source controls mapped|4 target controls covered
4%
Japan AI Guidelines
3 source controls mapped|1 target controls covered
4%
Jamaica Data Protection Act 2020
3 source controls mapped|4 target controls covered
4%
Iowa Consumer Data Protection Act
3 source controls mapped|4 target controls covered
4%
Indonesia PDP Law
3 source controls mapped|2 target controls covered
4%
Indiana Consumer Data Protection Act
3 source controls mapped|3 target controls covered
4%
India DPDP Act
3 source controls mapped|3 target controls covered
4%
IEEE 7000
3 source controls mapped|2 target controls covered
4%
4%
Family Educational Rights and Privacy Act (FERPA)
3 source controls mapped|6 target controls covered
4%
Saudi Arabia PDPL
3 source controls mapped|8 target controls covered
4%
Bahrain PDPL
3 source controls mapped|6 target controls covered
4%
ISO/IEC 30111:2019
2 source controls mapped|2 target controls covered
3%
WCAG 2.2
2 source controls mapped|1 target controls covered
3%
W3C Verifiable Credentials (VC) Data Model 2.0
2 source controls mapped|1 target controls covered
3%
UK Gambling Commission LCCP and Remote Technical Standards
2 source controls mapped|2 target controls covered
3%
UK Bribery Act 2010
2 source controls mapped|3 target controls covered
3%
SLSA
2 source controls mapped|1 target controls covered
3%
SIG (Shared Assessments)
2 source controls mapped|1 target controls covered
3%
Protective Security Policy Framework (PSPF) Release 2026
2 source controls mapped|1 target controls covered
3%
PSD2 SCA
2 source controls mapped|1 target controls covered
3%
PTES
2 source controls mapped|1 target controls covered
3%
PIC/S Guide to Good Manufacturing Practice for Medicinal Products
2 source controls mapped|3 target controls covered
3%
Philippines Cybercrime Prevention Act (RA 10175)
2 source controls mapped|1 target controls covered
3%
PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
2 source controls mapped|2 target controls covered
3%
OWASP Top 10:2025
2 source controls mapped|1 target controls covered
3%
OWASP SAMM
2 source controls mapped|1 target controls covered
3%
OWASP MASVS
2 source controls mapped|1 target controls covered
3%
OWASP DevSecOps Maturity Model (DSOMM)
2 source controls mapped|2 target controls covered
3%
OWASP ASVS
2 source controls mapped|1 target controls covered
3%
OSFI B-13
2 source controls mapped|1 target controls covered
3%
OpenSSF Scorecard
2 source controls mapped|1 target controls covered
3%
Open Banking Security
2 source controls mapped|1 target controls covered
3%
OCC Heightened Standards (12 CFR Part 30, Appendix D)
2 source controls mapped|1 target controls covered
3%
O-RAN WG11 Security Specification
2 source controls mapped|3 target controls covered
3%
NRC 10 CFR 73.54 - Nuclear Facility Cybersecurity
2 source controls mapped|5 target controls covered
3%
NIST SP 800-92
2 source controls mapped|1 target controls covered
3%
NIST SP 800-88
2 source controls mapped|1 target controls covered
3%
3%
NIST SP 800-63-4
2 source controls mapped|1 target controls covered
3%
NIST SP 800-61 Rev. 3
2 source controls mapped|1 target controls covered
3%
NIST SP 800-137
2 source controls mapped|1 target controls covered
3%
NIST SP 800-123
2 source controls mapped|1 target controls covered
3%
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)
2 source controls mapped|1 target controls covered
3%
Monetary Authority of Singapore Technology Risk Management Guidelines
2 source controls mapped|1 target controls covered
3%
MITRE D3FEND
2 source controls mapped|1 target controls covered
3%
MITRE ATT&CK
2 source controls mapped|1 target controls covered
3%
ITU Radio Regulations and Space Security Standards
2 source controls mapped|1 target controls covered
3%
ITAR - International Traffic in Arms Regulations
2 source controls mapped|1 target controls covered
3%
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.4)
2 source controls mapped|1 target controls covered
3%
ICH Q10 - Pharmaceutical Quality System
2 source controls mapped|2 target controls covered
3%
ICAO Annex 17 - Aviation Security (AVSEC)
2 source controls mapped|1 target controls covered
3%
IATF 16949:2016 - Quality Management System for Automotive Production
2 source controls mapped|2 target controls covered
3%
IATA Operational Safety Audit (IOSA) Standards Manual
2 source controls mapped|1 target controls covered
3%
HKMA SPM
2 source controls mapped|1 target controls covered
3%
HKMA Cyber Resilience Assessment Framework (C-RAF)
2 source controls mapped|1 target controls covered
3%
GLI-33 - Gaming Laboratories International Event Wagering Systems
2 source controls mapped|1 target controls covered
3%
GLBA
2 source controls mapped|1 target controls covered
3%
GAMP 5 - Good Automated Manufacturing Practice
2 source controls mapped|2 target controls covered
3%
French Sapin II Law (Law No. 2016-1691)
2 source controls mapped|1 target controls covered
3%
FDA Quality Management System Regulation (QMSR)
2 source controls mapped|1 target controls covered
3%
FATF Recommendation 16 - Payment Transparency (Travel Rule)
2 source controls mapped|1 target controls covered
3%
US Foreign Corrupt Practices Act (FCPA)
2 source controls mapped|1 target controls covered
3%
ISO/IEC 23837:2023
2 source controls mapped|1 target controls covered
3%
ISO/IEC 27031:2011
2 source controls mapped|1 target controls covered
3%
ISO/IEC 27007:2020
2 source controls mapped|1 target controls covered
3%
ISO/IEC 29147:2018
2 source controls mapped|2 target controls covered
3%
IEC 62351 - Power Systems Communication Security
2 source controls mapped|1 target controls covered
3%
ISO/IEC 27004:2016
2 source controls mapped|3 target controls covered
3%
ISO/IEC 27014:2020
2 source controls mapped|2 target controls covered
3%
ASIS SPC.1-2009 - Organizational Resilience Standard
2 source controls mapped|1 target controls covered
3%
ISO/IEC 29115:2013 - Entity Authentication Assurance Framework
2 source controls mapped|1 target controls covered
3%
IEC 60601-1 - Medical Electrical Equipment Safety
2 source controls mapped|2 target controls covered
3%
ISO/IEC 27050-1:2019
2 source controls mapped|1 target controls covered
3%
PCI DSS 4.0
2 source controls mapped|1 target controls covered
3%
DFARS 252.204-7012 - Safeguarding Covered Defense Information
2 source controls mapped|1 target controls covered
3%
UK Telecommunications (Security) Act 2021
2 source controls mapped|1 target controls covered
3%
Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct
2 source controls mapped|1 target controls covered
3%
ISO 22320:2018
2 source controls mapped|3 target controls covered
3%
ISO 41001:2018 - Facility Management Systems
2 source controls mapped|2 target controls covered
3%
ISO 14064 - Greenhouse Gas Accounting and Verification (Parts 1-3)
2 source controls mapped|1 target controls covered
3%
Annex 11 to EU GMP - Computerised Systems
2 source controls mapped|3 target controls covered
3%
Kuwait National Cybersecurity Framework
2 source controls mapped|1 target controls covered
3%
ISO 26262:2018 - Functional Safety for Road Vehicles
2 source controls mapped|1 target controls covered
3%
SANS Incident Handler's Handbook and PICERL Methodology
2 source controls mapped|2 target controls covered
3%
NIST Cybersecurity Framework 2.0
2 source controls mapped|2 target controls covered
3%
Automotive SPICE (ASPICE) v4.1 - Process Assessment Model
2 source controls mapped|2 target controls covered
3%
3%
ISO/IEC 27043:2015
2 source controls mapped|1 target controls covered
3%
COBIT 2019
2 source controls mapped|1 target controls covered
3%
US SEC Digital Assets and Crypto Regulatory Framework
2 source controls mapped|2 target controls covered
3%
PCI SSF
2 source controls mapped|1 target controls covered
3%
Illinois Biometric Information Privacy Act (BIPA)
2 source controls mapped|1 target controls covered
3%
IEC 62304:2015 Medical Device Software Lifecycle Processes
2 source controls mapped|3 target controls covered
3%
ISO 56002
2 source controls mapped|2 target controls covered
3%
ISO/IEC 17025:2017 - General Requirements for Testing and Calibration
2 source controls mapped|2 target controls covered
3%
PCI P2PE
2 source controls mapped|1 target controls covered
3%
FedRAMP High
2 source controls mapped|1 target controls covered
3%
FedRAMP Moderate
2 source controls mapped|1 target controls covered
3%
Science Based Targets Initiative (SBTi) - Net-Zero Standard
2 source controls mapped|2 target controls covered
3%
Singapore Cybersecurity Act 2018
2 source controls mapped|1 target controls covered
3%
ISO 8000 - Data Quality
2 source controls mapped|2 target controls covered
3%
ISO 20400:2017 - Sustainable Procurement
2 source controls mapped|2 target controls covered
3%
PCI PIN Security
2 source controls mapped|1 target controls covered
3%
ISO/IEC 27003:2017
2 source controls mapped|1 target controls covered
3%
ISO 28001:2007 Supply Chain Security Management
2 source controls mapped|1 target controls covered
3%
ISO/SAE 21434
2 source controls mapped|1 target controls covered
3%
FFIEC IT Examination Handbook
2 source controls mapped|1 target controls covered
3%
UNESCO Recommendation on the Ethics of AI
2 source controls mapped|2 target controls covered
3%
Global Cross-Border Privacy Rules (Global CBPR) Forum
2 source controls mapped|1 target controls covered
3%
UNICEF Policy Guidance on AI for Children (2021)
2 source controls mapped|1 target controls covered
3%
TISAX - Trusted Information Security Assessment Exchange
2 source controls mapped|1 target controls covered
3%
Student Privacy Pledge 2020
2 source controls mapped|1 target controls covered
3%
Oman National Cybersecurity Framework
2 source controls mapped|1 target controls covered
3%
NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
2 source controls mapped|2 target controls covered
3%
NIST Privacy Framework
2 source controls mapped|5 target controls covered
3%
Nevada Gaming Control Board Cybersecurity Requirements
2 source controls mapped|1 target controls covered
3%
MARS-E
2 source controls mapped|3 target controls covered
3%
Australian Privacy Principles (APPs)
2 source controls mapped|4 target controls covered
3%
UK Age Appropriate Design Code (Children's Code)
2 source controls mapped|6 target controls covered
3%
UK Data Protection Act 2018
2 source controls mapped|3 target controls covered
3%
Armenia Law on Protection of Personal Data (2015)
2 source controls mapped|3 target controls covered
3%
Uganda Data Protection and Privacy Act (2019)
2 source controls mapped|5 target controls covered
3%
SOC for Cybersecurity - Cybersecurity Risk Management Examination
2 source controls mapped|2 target controls covered
3%
Singapore AI Governance Framework
1 source controls mapped|1 target controls covered
1%
GS1 Global Standards - Supply Chain Traceability and Data Security
1 source controls mapped|2 target controls covered
1%
RICS Rules of Conduct and Global Professional Standards
1 source controls mapped|1 target controls covered
1%
South Africa Promotion of Access to Information Act (PAIA)
1 source controls mapped|1 target controls covered
1%
SASB Standards
1 source controls mapped|3 target controls covered
1%
OWASP Top 10 for LLM Applications 2025
1 source controls mapped|1 target controls covered
1%
NIST AI 600-1: Generative AI Profile
1 source controls mapped|1 target controls covered
1%
Nigeria Open Banking Regulatory Framework (CBN, 2023)
1 source controls mapped|3 target controls covered
1%
NAIC Insurance Data Security Model Law (MDL-668)
1 source controls mapped|1 target controls covered
1%
Kids Online Safety Act (KOSA)
1 source controls mapped|2 target controls covered
1%
Kenya Data Protection Act
1 source controls mapped|1 target controls covered
1%
ITU-T X.805 - Security Architecture for End-to-End Communications
1 source controls mapped|1 target controls covered
1%
Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486)
1 source controls mapped|2 target controls covered
1%
APPI
1 source controls mapped|3 target controls covered
1%
Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019)
1 source controls mapped|1 target controls covered
1%
COSO Internal Control - Integrated Framework (2013)
1 source controls mapped|1 target controls covered
1%
Azure Security Benchmark
1 source controls mapped|1 target controls covered
1%
Paraguay Law on Protection of Personal Data (Law No. 6534/2020)
1 source controls mapped|1 target controls covered
1%
NIST SP 800-66
1 source controls mapped|1 target controls covered
1%
New Zealand Information Security Manual (NZISM)
1 source controls mapped|1 target controls covered
1%
MDS2 (Medical Device)
1 source controls mapped|2 target controls covered
1%
Law on Personal Data Protection (Official Gazette No. 42/2020)
1 source controls mapped|1 target controls covered
1%
Jordan Personal Data Protection Law (Law No. 24 of 2023)
1 source controls mapped|2 target controls covered
1%
Georgia Law on Personal Data Protection (2012)
1 source controls mapped|1 target controls covered
1%
FDA 21 CFR Part 11
1 source controls mapped|3 target controls covered
1%
ISO 27799:2025
1 source controls mapped|3 target controls covered
1%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
1 source controls mapped|1 target controls covered
1%
US Consumer Product Safety Act (CPSC) Manufacturer and Importer Duties
1 source controls mapped|1 target controls covered
1%
ASD Strategies to Mitigate Cyber Security Incidents
1 source controls mapped|1 target controls covered
1%
Authorised Economic Operator (AEO) Programmes - Global Standards
1 source controls mapped|1 target controls covered
1%
ISO 26000:2010
1 source controls mapped|1 target controls covered
1%
1%
Telecommunications Sector Security Reforms (TSSR)
1 source controls mapped|1 target controls covered
1%
US ITAR and EAR - Export Control and Data Security
1 source controls mapped|1 target controls covered
1%
NIST SP 800-53 Rev 5
1 source controls mapped|1 target controls covered
1%

Coverage is not the same as your position

This page shows what Albania Law No. 124/2024 on Personal Data Protection overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is Albania Law No. 124/2024 on Personal Data Protection and who does it apply to?

Albania Law No. 124/2024 on Personal Data Protection is a compliance framework from Albania with 7 domains and 52 controls. Albania's GDPR-aligned Law No. 124/2024 On Personal Data Protection, in force since 1 February 2025 and replacing Law 9887/2008: principles, lawful bases, consent (age 16 for online services), sensitive data and criminal records, 30-day responses to rights requests, access, erasure, the right to be forgotten including search engine delisting, restriction, portability, objection and automated decisions, accountability, privacy by design, a representative for foreign businesses, processor contracts, records of processing, security, 72-hour breach notification, confidentiality, impact assessments and prior consultation (in force 17 January 2027), DPOs, transfers under Commissioner adequacy decisions, clauses and binding company rules, journalism, research and direct marketing rules, the law enforcement regime of Part III, and fines up to ALL 2 billion or 4 percent of worldwide turnover. Built from the Commissioner's English version of the Law. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Albania Law No. 124/2024 on Personal Data Protection actually require?

Albania Law No. 124/2024 on Personal Data Protection has 52 controls organised across 7 domains. The largest domains are Part III: processing by competent authorities for security and criminal law purposes (Articles 47 to 74) – Albania Law No. 124/2024 on Personal Data Protection (16 controls), Part II Chapter III: controller and processor obligations, security, breach, impact assessment, DPO, codes and certification (Articles 22 to 38) – Albania Law No. 124/2024 on Personal Data Protection (13 controls), Part II Chapter II: rights of the data subject and their restriction (Articles 12 to 21) – Albania Law No. 124/2024 on Personal Data Protection (9 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Albania Law No. 124/2024 on Personal Data Protection do I already cover?

Albania Law No. 124/2024 on Personal Data Protection maps to 250 other compliance frameworks. The top mapping partners are GDPR (15% coverage), Nigeria Data Protection Act 2023 (NDPA) (7% coverage), Nebraska Data Privacy Act (7% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Albania Law No. 124/2024 on Personal Data Protection?

Start your Albania Law No. 124/2024 on Personal Data Protection compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Albania Law No. 124/2024 on Personal Data Protection requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 52 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 723 frameworks.

Get Started Free →

Free forever — no credit card required