Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014)
Albania's Law on Protection of Personal Data (Law No. 9887/2008, amended by Law No. 48/2014) establishes the data protection framework. The Information and Data Protection Commissioner oversees enforcement. The law was initially based on the EU Data Protection Directive and has been progressively updated toward GDPR alignment as part of Albania's EU accession process. Covers processing principles, consent, data subject rights, cross-border transfers, and DPO requirements. A new GDPR-aligned law has been under development.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (23)
Awareness
| Code | Title |
|---|---|
| AL-DPA-22 | Data Protection Training |
CCTV
| Code | Title |
|---|---|
| AL-DPA-15 | Video Surveillance |
Chapter I: General Provisions
| Code | Title |
|---|---|
| AL-DPA-1 | Scope and Definitions |
| AL-DPA-2 | Data Quality Principles |
| AL-DPA-3 | Lawful Basis for Processing |
| AO-DPA-1 | Article 1 — Object |
| AO-DPA-2 | Article 2 — Scope of Application |
| AO-DPA-3 | Article 3 — Definitions |
| BA-DPA-1 | Article 1 — Purpose and Scope |
| BA-DPA-2 | Article 2 — Definitions |
| BA-DPA-3 | Article 3 — Scope of Application |
Chapter II: Conditions for the Lawful Processing of Personal Data
| Code | Title |
|---|---|
| AL-DPA-4 | Sensitive Data |
| AL-DPA-5 | Notification to IDP Commissioner |
| AL-DPA-6 | Data Subject Rights - Information |
| AL-DPA-7 | Right of Access |
Chapter III: Rights of the Data Subject
| Code | Title |
|---|---|
| AL-DPA-10 | Security of Processing |
| AL-DPA-11 | Processor Obligations |
| AL-DPA-8 | Right of Rectification and Erasure |
| AL-DPA-9 | Right to Object and Automated Decisions |
Chapter IV: Controller and Processor Obligations
| Code | Title |
|---|---|
| AL-DPA-12 | International Data Transfers |
| AL-DPA-13 | Data Protection Officer |
| AL-DPA-14 | Direct Marketing |
| AO-DPA-11 | Article 15 — Security Measures |
| AO-DPA-12 | Article 16 — Notification to APD |
| AO-DPA-13 | Article 17 — Confidentiality Obligations |
Chapter V: Supervisory Authority
| Code | Title |
|---|---|
| AL-DPA-15 | Video Surveillance |
| AL-DPA-16 | Employee Data |
| AL-DPA-17 | Breach Handling |
| BA-DPA-13 | Article 22 — Personal Data Protection Agency |
| BA-DPA-14 | Article 23 — Powers and Functions |
Documentation
| Code | Title |
|---|---|
| AL-DPA-19 | Records of Processing |
Enforcement
| Code | Title |
|---|---|
| AL-DPA-20 | Investigations and Sanctions |
Governance
| Code | Title |
|---|---|
| AL-DPA-13 | Data Protection Officer |
Government Access
| Code | Title |
|---|---|
| AL-DPA-21 | Direct Access by Public Authorities |
Incident Response
| Code | Title |
|---|---|
| AL-DPA-17 | Breach Handling |
Legal Basis
| Code | Title |
|---|---|
| AL-DPA-3 | Lawful Basis for Processing |
Marketing
| Code | Title |
|---|---|
| AL-DPA-14 | Direct Marketing |
Principles
| Code | Title |
|---|---|
| AL-DPA-2 | Data Quality Principles |
Processors
| Code | Title |
|---|---|
| AL-DPA-11 | Processor Obligations |
Registration
| Code | Title |
|---|---|
| AL-DPA-5 | Notification to IDP Commissioner |
Rights
| Code | Title |
|---|---|
| AL-DPA-6 | Data Subject Rights - Information |
| AL-DPA-7 | Right of Access |
| AL-DPA-8 | Right of Rectification and Erasure |
| AL-DPA-9 | Right to Object and Automated Decisions |
Scope
| Code | Title |
|---|---|
| AL-DPA-1 | Scope and Definitions |
Security
| Code | Title |
|---|---|
| AL-DPA-10 | Security of Processing |
Special Categories
| Code | Title |
|---|---|
| AL-DPA-18 | Children's Data |
| AL-DPA-4 | Sensitive Data |
Transfers
| Code | Title |
|---|---|
| AL-DPA-12 | International Data Transfers |
Workplace
| Code | Title |
|---|---|
| AL-DPA-16 | Employee Data |
Your Compliance Coverage
If you comply with Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014), you already cover:
Portugal Law No. 58/2019 — Data Protection Implementation Act
33%
11 controls mapped
Compare →North Macedonia Law on Personal Data Protection (2020)
33%
11 controls mapped
Compare →Australia My Health Records Act 2012
33%
11 controls mapped
Compare →+ 564 more: EU AI Act (33%), Tunisia Organic Law on Personal Data Protection (Law No. 2004-63) (33%)
See all 567 mapped frameworks ↓Maps to 567 other frameworks
Frequently Asked Questions
What is Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014)?
Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) is a compliance framework from Albania with 23 domains and 50 controls. Albania's Law on Protection of Personal Data (Law No. 9887/2008, amended by Law No. 48/2014) establishes the data protection framework. The Information and Data Protection Commissioner oversees enforcement. The law was initially based on the EU Data Protection Directive and has been progressively updated toward GDPR alignment as part of Albania's EU accession process. Covers processing principles, consent, data subject rights, cross-border transfers, and DPO requirements. A new GDPR-aligned law has been under development. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) have?
Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) has 50 controls organised across 23 domains. The largest domains are Chapter I: General Provisions (9 controls), Chapter IV: Controller and Processor Obligations (6 controls), Chapter V: Supervisory Authority (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) map to?
Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) maps to 567 other compliance frameworks. The top mapping partners are Portugal Law No. 58/2019 — Data Protection Implementation Act (33% coverage), North Macedonia Law on Personal Data Protection (2020) (33% coverage), Australia My Health Records Act 2012 (33% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) compliance?
Start your Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 50 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required