On 24 July 2025, Law no. 25-11 on data protection, including data protection authority governance entered into force. The Law establishes a designated data protection commissioner's office responsible for supervising compliance with data protection requirements and ensuring that state institutions and individuals handling personal data meet their legal obligations. The commissioner must possess professional qualifications and specialized legal knowledge in data protection matters. The authority holds responsibility for monitoring data processing activities, investigating violations, verifying compliance with obligations, and maintaining detailed records of all processing operations. The commissioner serves as the primary point of contact with the national data protection authority and maintains independence in exercising supervisory functions, with judicial authorities exempted from the obligation to comply with this requirement when performing their judicial duties.
Original source