Description

Law no. 25-11 on data protection, including data protection authority governance entered into force

On 24 July 2025, Law no. 25-11 on data protection, including data protection authority governance entered into force. The Law establishes a designated data protection commissioner's office responsible for supervising compliance with data protection requirements and ensuring that state institutions and individuals handling personal data meet their legal obligations. The commissioner must possess professional qualifications and specialized legal knowledge in data protection matters. The authority holds responsibility for monitoring data processing activities, investigating violations, verifying compliance with obligations, and maintaining detailed records of all processing operations. The commissioner serves as the primary point of contact with the national data protection authority and maintains independence in exercising supervisory functions, with judicial authorities exempted from the obligation to comply with this requirement when performing their judicial duties.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection authority governance
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2025-07-24
in force

On 24 July 2025, Law no. 25-11 on data protection, including data protection authority governance e…