International Police Cooperation: What Data Protection Safeguards We Are Calling For

The Civic Movement “Construim Încredere” has analysed the draft Law on International Police Cooperation, approved by Government Protocol Decision No. 34 of 12 August 2026.

The draft seeks to bring the Republic of Moldova closer to European standards and partially transposes Regulation (EU) 2024/982 — “Prüm II”, Council Decision 2008/615/JHA and Directive (EU) 2023/977.

We support the objective of the draft law.

More effective cooperation with European Union Member States, Europol and INTERPOL can contribute to preventing and combating cross-border crime.

However, the new instruments give public authorities access to extremely sensitive categories of data. For this reason, greater efficiency must be accompanied by clear safeguards protecting citizens.

What does the draft law change?

The new Law on International Police Cooperation establishes the legal framework for querying and exchanging information between the Republic of Moldova and authorities in other countries.

In certain circumstances, checks will be carried out automatically and almost instantaneously.

The data concerned include:

  • DNA profiles;
  • fingerprints;
  • facial images;
  • vehicle data;
  • police records;
  • travel documents;
  • driving licences;
  • data on missing persons;
  • information on unidentified bodies.

This therefore represents a significant change.

The Republic of Moldova is moving from a model based primarily on requests and responses between authorities towards a system in which some checks can be carried out automatically.

What positive safeguards does the draft contain?

The draft includes several safeguards that we consider necessary and that should be preserved.

These include restrictions on the categories of data that may be exchanged and the application of principles such as lawfulness, data minimisation and institutional accountability.

Furthermore, any match identified automatically — a so-called “hit” — must be manually confirmed by qualified personnel before it can be used.

The draft also prohibits the use of automated facial-image searches to create profiles that may lead to discrimination.

Before connecting to certain European systems, a Data Protection Impact Assessment — DPIA — must be carried out, together with consultation of the National Centre for Personal Data Protection.

Access to and exchanges of data must also be logged.

Citizens are granted the rights to information, rectification, erasure, complaint and compensation.

These safeguards provide an important foundation. However, we believe that the draft law should be improved before it is adopted.

1. Some provisions are too broadly formulated

A law allowing automated access to DNA profiles, fingerprints or facial images must be highly precise.

The current version contains wording such as “other forms of cooperation” and “including but not limited to”.

Such expressions may expand the scope of the law without sufficiently clear and foreseeable limits.

We believe that the forms of international police cooperation should be defined as precisely as possible.

2. Essential safeguards must be laid down directly in the law

Several important elements are to be regulated later through Government acts.

These include, among other matters, data-quality standards, certain search procedures, the organisation of contact points and security arrangements.

We believe that safeguards affecting fundamental rights should be included directly in the organic law.

This would allow them to be debated in Parliament and subjected to genuine public scrutiny.

3. A minimum security standard is required

The draft refers to “encryption and other technical and organisational measures”.

However, this wording does not establish a clear and verifiable minimum standard.

The law should provide more specific requirements concerning:

  • encryption;
  • network segmentation;
  • backups;
  • data recovery;
  • vulnerability testing;
  • system security before systems are put into operation.

A Data Protection Impact Assessment is important, but it cannot replace a technical security assessment.

4. It must be clear who has access to the data

Another important issue is identity and access management.

When institutions handle DNA profiles, fingerprints, facial images and police records, access cannot be regulated solely through general principles.

We consider that clear rules are needed regarding:

  • multi-factor authentication;
  • role-based access control;
  • the principle of least privilege;
  • segregation of duties;
  • periodic review of access rights;
  • deactivation of access when a person changes position or leaves the institution;
  • emergency access.

It should also be clearly established who is responsible for the overall access-management system.

5. Data retention and deletion periods must be harmonised

The draft contains several different retention periods for information.

Different articles refer to periods of one year, three years or 18 months. In other situations, immediate deletion is required.

These rules should be presented within a clear and coherent framework.

For each category of data, it should be clear:

  • how long it is retained;
  • when it is deleted;
  • what happens to backup copies;
  • how false-positive results are removed;
  • what information remains in access logs.

6. Clear rules are needed for security incidents

A potential leak of biometric data can have serious consequences.

For this reason, the law should provide for a clear incident-response mechanism.

It should include severity levels, responsibilities, response deadlines and recovery procedures.

Furthermore, every significant incident should subsequently be analysed in order to prevent recurrence.

7. Logging alone is not sufficient

Maintaining access logs is necessary. However, logs primarily show what has already happened.

A modern system should also be capable of detecting suspicious behaviour in real time.

For example:

  • an unusually high number of queries;
  • access to databases at unusual hours;
  • abnormal data exports;
  • repeated attempts at unauthorised access.

Continuous monitoring is essential when a system processes biometric data.

8. Institutional responsibilities must be clearly delineated

The draft assigns different responsibilities to several institutions.

The National Centre for Personal Data Protection oversees the lawfulness of data processing.

The Electronic Governance Agency has responsibilities relating to the technical security of system interconnections.

Cybersecurity authorities intervene in the event of incidents.

The Single Point of Contact manages operational cooperation.

These roles must be clearly delineated.

Furthermore, there should be an institution or designated individual responsible for the security of the entire mechanism.

9. Citizens must be able to correct errors quickly

One of the most important issues is the protection of the individual.

What happens if the Republic of Moldova transmits incorrect information about a citizen to a foreign authority?

How does the person find out that the data are incorrect?

Where should they submit a request?

Within what period must the information be corrected?

How do we ensure that the correction also reaches the foreign authorities that received the original data?

The law must provide clear answers to these questions.

What does the Civic Movement “Construim Încredere” propose?

We support the development of international police cooperation and the Republic of Moldova’s closer integration with European systems.

At the same time, we call for the draft law to be supplemented before adoption.

We consider the following necessary:

  • a mandatory minimum security standard;
  • a technical assessment before systems are interconnected;
  • clear access-control rules;
  • a coherent system for data retention and deletion;
  • clear incident-response procedures;
  • continuous monitoring;
  • security requirements for suppliers and third parties;
  • vulnerability-management rules;
  • clear delineation of responsibilities between institutions;
  • a rapid redress mechanism for citizens;
  • inclusion of fundamental safeguards directly in the law.

Greater access to data must also mean greater oversight

European integration does not simply mean adopting European rules.

It also requires institutions to have the capacity to implement those rules securely and in full respect of fundamental rights.

When authorities are given the ability to rapidly transmit and verify DNA profiles, fingerprints, facial images and other sensitive data, the level of accountability must increase accordingly.

International police cooperation must be effective, but it must also be secure, transparent and subject to proper oversight.

Greater access to data must mean greater security, greater accountability and stronger protection for citizens.

The full statement is available below.