Last updated: 29 May 2026 · v2.09
The Public Institution "e-Governance Agency" ("AGE") processes personal data as controller, in accordance with Law no. 133/2011 on personal data protection, Law no. 195/2024 (full entry into force on 23 August 2026), Convention 108+ of the Council of Europe (ratified by Moldova on 15 May 2026) and subordinate acts. This Policy explains what data we collect through the Government Data Portal date.gov.md (the "Portal"), for what purposes, with whom we share it, how long we keep it, and what your rights are.
1. Data controller
- Name: Public Institution "e-Governance Agency"
- Address: 134 Stefan cel Mare si Sfant Blvd., MD-2012, Chisinau, Republic of Moldova
- General email: office@egov.md
- Data Protection Officer (DPO): requests on data-subject rights to office@egov.md with subject "Attn. DPO".
- Supervisory authority: National Center for Personal Data Protection (NCPDP), datepersonale.md.
- Processor: SE "Information Technology and Cyber Security Service" (STISC), as operator of the MCloud governmental platform under GD no. 414/2018.
2. Applicable legal framework
Personal data protection:
- Law no. 133/2011 on personal data protection;
- Law no. 195/2024 on personal data protection (full entry into force 23 August 2026);
- Convention 108+ of the Council of Europe (CETS no. 223), ratified by Moldova on 15 May 2026;
- NCPDP Order no. 25/2024 on lawfulness control of processing.
Data exchange and interoperability:
- Law no. 142/2018 on data exchange and interoperability;
- GD no. 211/2019 — MConnect Connection Regulation;
- Law no. 467/2003 on state information resources;
- Law no. 71/2007 on registers.
Electronic identification and cybersecurity:
- Law no. 124/2022 on electronic identification and trust services;
- Law no. 48/2023 on cybersecurity;
- GD no. 562/2025 — minimum cybersecurity requirements for essential-service operators.
Access to information, state secrecy, copyright, procedure:
- Law no. 148/2023 on access to information of public interest;
- Law no. 245/2008 on state secrecy;
- Law no. 230/2022 on copyright and related rights;
- Administrative Code (Law no. 116/2018).
3. Categories of data processed
- Technical access data: IP, session ID, browser type/version, OS, pages visited, date/time, HTTP response code, referrer.
- Authentication data (via MPass — GD no. 1090/2013): IDNP (where applicable), first and last name, capacity as legal-entity representative (IDNO/CUIIO), role.
- Form data: request content, register query parameters, service-request data.
- Correspondence data: emails, phone interactions or contact-form messages, including email address, body and attachments.
- Audit data (MConnect logs): logs of data consumption/supply for traceability under art. 11 of Law no. 142/2018.
- Cybersecurity data: security event logs, indicators of compromise, system telemetry under Law no. 48/2023 and GD no. 562/2025.
We do not proactively collect special categories (racial/ethnic origin, political opinions, religious beliefs, health, biometric or genetic data), except where included by the User in voluntary correspondence.
4. Legal bases (art. 5 of Law no. 133/2011 / art. 6 of Law no. 195/2024)
- Legal obligation — AGE's tasks under Law no. 109/2025 and Law no. 142/2018;
- Exercise of official authority — managing MConnect and shared services;
- Performance of a contract or pre-contractual steps — for Connection Requests;
- Legitimate interest — information security, fraud prevention, proper operation;
- Consent — non-essential cookies, notifications, surveys.
5. Purposes of processing
- Portal operation and security;
- authentication and access control;
- handling MConnect Connection Requests and AGE decisions;
- auditing data-exchange operations;
- cybersecurity incident detection, prevention and response, including notification to the Cybersecurity Agency;
- handling requests, petitions and complaints under the Administrative Code;
- aggregate, anonymized usage statistics;
- compliance with legal obligations (reporting, archiving, cooperation with authorities).
6. Recipients
- authorized AGE personnel (administrators, security officer, DPO, lawyers);
- SE "STISC" as processor under a processing contract (art. 30 Law 133/2011 / art. 28 Law 195/2024);
- register and information-system holders for MConnect requests;
- Cybersecurity Agency / CERT-Gov for notifiable incidents (Law 48/2023);
- competent authorities (NCPDP, Prosecutor's Office, courts, Information and Security Service) under lawful requests;
- auditors and external consultants bound by contractual confidentiality.
AGE does not sell or transfer your data for commercial purposes to third parties.
7. Cross-border transfers
As a rule, data is stored in the Republic of Moldova on MCloud. Transfers to third countries take place only with the safeguards in art. 32 of Law 133/2011 / ch. V of Law 195/2024 and Convention 108+, with NCPDP authorization where required. Moldova benefits from the European Commission adequacy decision (Decision 2020/419), facilitating EEA transfers.
8. Retention periods
- technical access logs: generally 12 months; security logs up to 3 years;
- MConnect Requests and decisions: while the connection lasts and 5 years after termination;
- support correspondence: 3 years after closure;
- analytics cookies: up to 13 months (NCPDP recommendation, aligned with EDPB practice);
- cybersecurity incident notification records: at least 5 years under Law 48/2023.
9. Data-subject rights
- access;
- rectification;
- erasure (right to be forgotten);
- restriction of processing;
- objection (legitimate-interest processing);
- portability within technical limits;
- not to be subject to a decision based solely on automated processing, including profiling;
- to withdraw consent at any time;
- to lodge a complaint with NCPDP (datepersonale.md) or seek judicial remedy.
Requests are submitted in writing, signed by hand or electronically under Law no. 124/2022, to office@egov.md. AGE responds within 30 days (art. 73 Administrative Code).
10. Cookies and similar technologies
- Strictly necessary cookies (session, MPass authentication, language preference, anti-CSRF) — set without prior consent, on legitimate-interest grounds;
- Analytics cookies (if enabled) — only with consent, for aggregate measurement;
- Local storage (localStorage / sessionStorage) — for display preferences.
You may configure your browser to refuse cookies; refusing strictly necessary ones may render the Portal unusable.
11. Data security
- TLS 1.2+ encryption in transit and, where appropriate, at rest;
- strong authentication (MPass), role-based and need-to-know access control;
- continuous monitoring, audit logs, incident detection, periodic incident-response exercises;
- vulnerability testing, Data Protection Impact Assessment (DPIA) under art. 25 of Law no. 195/2024;
- processor contracts under art. 30 Law 133/2011 / art. 28 Law 195/2024;
- compliance with minimum cybersecurity requirements (GD no. 562/2025) and incident-reporting obligations under Law no. 48/2023.
In case of a breach posing a high risk to data subjects' rights, AGE notifies NCPDP and, where appropriate, the affected persons within statutory deadlines. Law no. 195/2024 will introduce a standard 72-hour notification deadline upon awareness.
12. Automated decisions and profiling
The Portal does not take decisions based solely on automated processing producing legal effects. Technical safeguards (anti-spam filters, rate limiting, abuse detection) are auxiliary security measures and do not constitute profiling.
13. Minors
The Portal is not exclusively intended for minors and does not intentionally collect children's data. Where such processing is identified, AGE takes steps to cease it and delete the data.
14. Changes
AGE may revise this Policy. The current version is permanently published with effective date. Substantial changes are notified visibly at least 14 days in advance.
15. Contact
For questions on personal-data processing: office@egov.md ("Attn. DPO") or +373 (22) 820 026. See also the Terms and Conditions.