on the processing of personal data and technical information collected in the provision of electronic services by the Public Institution “Public Services Agency”
1. General provisions
This Policy informs users of electronic public services about how the Public Services Agency (hereinafter referred to as the “Agency”) collects, uses, protects and stores personal data provided or obtained in the process of providing electronic services.
The purpose of this Policy is to inform users about the categories of personal data processed, the purposes and legal grounds for processing, the manner in which data are used, protected and stored, as well as the rights of data subjects and the manner in which these rights may be exercised.
The Agency respects the right of natural persons to the protection of personal data and applies the fundamental principles governing data processing, including lawfulness, fairness and transparency of processing, purpose limitation, data minimisation, data accuracy, storage limitation, data integrity and confidentiality, as well as the principle of accountability of the controller.
Personal data are processed in accordance with the applicable legislation:
- Law No. 195/2024 on the protection of personal data;
- Law No. 467/2003 on informatization and state information resources;
- Law No. 71/2007 on registers;
- Law No. 148/2023 on access to information of public interest;
- other applicable regulatory acts.
This Policy applies to users of electronic services provided by the Institution through the digital resources administered by it, regardless of the technical means used to access them.
2. Personal data controller
The personal data controller is:
Public Institution “Public Services Agency”
Legal address: Republic of Moldova, Chișinău municipality, 42 Pușkin Street;
Telephone: 14-909
E-mail: asp@asp.gov.md
Official website: www.asp.gov.md
The Agency, in its capacity as personal data controller, determines the purposes and means of processing personal data in the provision of electronic services, in accordance with the duties and powers established by law.
Where certain processing activities are carried out through service providers, they may act as processors on behalf of the controller, under the conditions provided for by the applicable legislation.
The Agency ensures that processors process personal data on the basis of the controller’s documented instructions and apply appropriate measures to protect such data.
The Data Protection Officer (DPO) is the person designated by the controller in accordance with Article 37 of Law No. 195/2024 who, on the basis of specialist knowledge of personal data protection law and practices, monitors compliance with the relevant legislation, informs and advises the controller, cooperates with the National Centre for Personal Data Protection and acts as the main point of contact for data subjects and the supervisory authority:
Telephone: 0 22 504 893
E-mail: spdcp@asp.gov.md
Persons whose personal data are processed by the Institution benefit from the rights provided for by the applicable personal data protection legislation.
Depending on the nature and legal basis of the processing, data subjects may request, under the conditions provided by law, the exercise of the right to information, access, rectification, erasure, restriction of processing, objection or other applicable rights, and may also lodge a complaint with the competent authority or apply to a court.
How to exercise your rights
To exercise their rights or obtain information regarding the processing of personal data, data subjects may contact the Institution using the contact methods provided on the official website — Personal Data Protection, including through the petition form provided by the Institution or through edemocratie.gov.md.
3. Personal data and technical information processed through electronic services
Depending on the nature of the electronic service requested, the manner of interaction with the user and the requirements of the applicable legislation, the Agency may process the categories of personal data necessary to provide the requested electronic service.
| Category of data processed | Examples of data | Data source |
|---|---|---|
| Data provided by the user | Identification and contact data, information and documents required to examine the request | The user, through electronic forms, applications or submitted documents |
| Data obtained through interoperability | Information required to verify or validate the request | State registers, automated information systems and other authorised information resources |
| Data collected automatically | Technical information concerning the use of electronic services, the device used and the operation of systems | Information systems used to provide electronic services |
a) Data provided directly by the user
When using electronic services, the user may submit information required to examine and resolve the request, including by completing electronic forms or uploading the requested documents.
The Agency processes only the data necessary to provide the requested service, in compliance with the principle of data minimisation.
b) Data obtained through interoperability
In order to provide electronic services, the Agency may verify or validate certain information through interoperability mechanisms with other information systems, under the conditions provided for by the applicable legislation.
The use of these mechanisms is intended to facilitate the processing of requests, reduce the need to submit documents available in other information systems and ensure the accuracy of the information used in providing the service.
c) Data collected automatically
During the use of electronic services, information systems may automatically collect technical data necessary for the operation and administration of the services, including information regarding the connection, the device used and technical events generated by the system.
These data contribute to ensuring the proper operation, availability and improvement of electronic services.
The Institution’s electronic services use cookies and similar technologies to ensure the proper operation, security and improvement of the services provided to users.
What are cookies?
Cookies are small files stored in the browser of the user’s device when accessing a website. They allow the website to retain certain information and ensure the proper functioning of certain features.
Depending on their purpose, cookies may be classified as follows:
Strictly necessary cookies
These cookies are necessary for the operation of electronic services and may be used to:
- ensure the proper operation of pages and electronic forms;
- maintain the technical parameters necessary for processing requests;
- ensure the security of electronic services;
- prevent improper use of electronic resources.
Disabling these cookies may affect the operation of certain components of the electronic services.
Analytics and performance cookies
These cookies may be used, where applicable, to:
- analyse how electronic services are used;
- identify technical problems;
- improve the quality, performance and accessibility of the services provided.
Cookies that are not strictly necessary are used under the conditions provided for by the applicable legislation and, where applicable, on the basis of the user’s consent.
Users may manage their cookie preferences through the mechanisms provided by the Institution or through the settings of the browser they use.
Specific elements and technologies integrated into the Agency’s web pages
- Google Analytics, Tag Manager: collect analytical data about traffic, anonymised IP addresses, browser type, approximate location and browsing behaviour.
- Microsoft Clarity: records user interactions on the website (clicks, mouse movements, scrolling) in order to optimise the user experience (UX).
- Internal search form: stores queries entered by users (the
keysparameter). - Language preferences: uses cookies or sessions (
ru,en,ro) to remember the language selected by the visitor. - Redirect links (Surveys and Petitions): redirect users to external platforms (Google Forms, edemocratie.gov.md) where data are collected directly.
4. Audit data and traceability of operations
To ensure the secure operation of electronic services and maintain records of operations performed in information systems, the Agency may process technical audit data generated by the systems used.
Audit data may include information regarding access to and operations performed in systems, such as the date and time of access, technical or user identifiers, actions performed and technical events recorded.
These data are used to:
- maintain the traceability of operations performed in information systems;
- identify and investigate technical or security incidents;
- verify compliance with security and operational requirements for information systems.
Audit data are not used to evaluate the behaviour of users of electronic services for purposes unrelated to the provision of the requested services.
Audit data are retained for the period necessary to fulfil the purposes for which they are collected and in accordance with the requirements of the applicable legislation.
5. Recipients of personal data
For the purposes set out in this Policy, including the provision of electronic services, verification of information and fulfilment of legal obligations, personal data may be disclosed or made available to authorised recipients under the conditions provided for by the applicable legislation.
Depending on the nature of the requested service and the applicable legal basis, recipients of personal data may include:
- public authorities and institutions that have legal powers in the relevant field;
- information systems and information resources used for data exchange through interoperability mechanisms;
- persons authorised by the Institution to carry out activities necessary for the provision and maintenance of electronic services;
- other entities authorised by law.
Personal data are transmitted or access to them is granted only to the extent necessary to achieve the established purposes, on the basis of a legal ground and in compliance with personal data protection requirements.
The Agency ensures that authorised processors process personal data only in accordance with the established instructions and within the limits of the powers granted to them.
6. Data retention period
Personal data are retained for the period necessary to achieve the purposes for which they are processed and in accordance with the retention periods established by the applicable legislation.
The retention period may vary depending on the nature of the data processed, the type of electronic service requested, the purpose of processing and the Institution’s legal obligations regarding record-keeping, archiving and information management.
Upon expiry of the applicable retention periods, personal data are deleted, archived or subjected to other measures provided for by law, in compliance with personal data protection requirements.
For technical data and audit data generated by information systems, the retention period is determined according to security requirements, the need to ensure the traceability of operations and applicable legal obligations.
7. Protection of personal data
The Agency applies appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, disclosure or other forms of improper processing.
Protection measures are determined according to the nature of the data processed, the purposes of processing, the risks identified and the requirements of the applicable legislation, and are intended to ensure the confidentiality, integrity and availability of personal data.
Access to personal data is granted only to authorised persons, within the limits of their established duties and to the extent necessary for the performance of their responsibilities.
Persons who process personal data as part of activities carried out for the Institution are required to comply with data confidentiality and security requirements, including after the termination of employment or contractual relations, under the conditions provided for by the applicable legislation.
The Agency periodically reviews the protection measures applied and takes appropriate action to prevent and manage incidents that may affect the security of personal data.
8. Updating the Privacy Policy
The Agency may update this Privacy Policy in response to changes in the applicable legislation, changes to the electronic services provided, the introduction of new technologies or changes in the manner in which personal data are processed and protected.
The updated version of the Policy is published on the Institution’s official electronic resources — Privacy Policy.
Users may periodically consult the updated version of the Policy to stay informed about how their personal data are processed and protected.
Last updated: 24 August 2026