Procurement asks the question in one line — "is Moldova adequate?" — and the honest answer is no, followed by three paragraphs nobody sends. The three paragraphs matter, because the follow-up work is much smaller than "not adequate" sounds, and because the flow that carries the real risk is usually not the one being papered. This is our own compliance position, published so a client’s DPO can check it rather than take our word for it.
The status, in three facts
- There is no adequacy decision for Moldova. Checked against the European Commission’s own adequacy decisions page on 30 August 2026. Moldova is absent from the list and no talks are announced on that page. Anyone telling you adequacy is imminent is speculating.
- Moldovan law is now a near-verbatim GDPR transposition. Law No. 195 of 25 July 2024 on personal data protection entered into force on 23 August 2026, repealing the 2011 law. Territorial scope, principles, lawful bases, data-subject rights and accountability read across almost word for word, which means one policy satisfies both. The supervisory authority is the National Centre for Personal Data Protection (CNPDCP) in Chișinău.
- Moldova ratified Convention 108+ on 15 May 2026, as the 34th state. The modernised convention needs 38 ratifications and is not yet in force. This is evidence for a future adequacy case and a useful input to a transfer risk assessment. It is not a transfer mechanism.
So: Article 46 safeguards, which in practice means the 2021 Standard Contractual Clauses plus a documented transfer impact assessment. That is the whole answer to the procurement question. The rest of this article is about applying it to flows that actually exist rather than to flows on a questionnaire.
Which flows are actually restricted transfers
Under the EDPB’s Guidelines 05/2021 (v2.0, adopted 14 February 2023) a transfer requires three cumulative criteria: an exporter subject to the GDPR, a disclosure by that exporter to another controller or processor, and an importer in a third country — the last one applying irrespective of whether the importer is itself subject to the GDPR. Apply that to a recruitment engagement and the map is less alarming than the questionnaire implies.
| Flow | Restricted transfer? | Who is the exporter | Instrument |
|---|---|---|---|
| A candidate in the EU emails their own CV to us, or books a call | No | None — the data subject discloses directly, so criterion two fails | Nothing needed. Our processing is still subject to the GDPR via Art 3(2) |
| An EU client sends us a job spec naming employees, or interview feedback | Yes | The client | SCCs (Decision 2021/914), signed inside the services agreement |
| We forward a candidate profile to an EU client | No | — (Moldova → EEA is outbound from a third country) | Moldovan Law 195 Art 44(2) exempts transfers to the EEA outright |
| A client gives an engineer access to their systems | Yes, continuously | The client | The client’s own Art 46 safeguard plus access controls — see below |
| Either side puts the data in a US SaaS tool | Yes | Whoever controls that tool | Art 28 processing terms plus a Chapter V mechanism for the US leg |
Two consequences worth internalising. A recruiter whose candidates come to them directly originates far fewer restricted transfers than a compliance questionnaire assumes. And when a transfer does exist in the client-to-supplier direction, the client is the exporter and the client’s obligation is to originate the clauses. A supplier should sign them without argument; a supplier who insists the paperwork is entirely the client’s problem has misread who bears the Chapter V duty, and so has a client who insists the reverse.
The transfer everyone forgets
The CV flow is what gets papered. The flow that carries real volumes of personal data is the one that starts on the engineer’s first day: access to your issue tracker, your CRM, your logs, your support inbox, your staging database restored from a production dump last Tuesday. Every one of those is your personal data, made available continuously to a recipient in a third country, with you as exporter. No recruiter’s clauses cover it, because the recruiter is not party to it.
The fix is ordinary engineering hygiene, which is why it is worth doing regardless of the legal framing:
- Scoped, revocable, named accounts — never a shared login, never a standing production credential.
- No production personal data in development or staging. Synthetic or pseudonymised fixtures, seeded automatically, so the lazy path is also the compliant one.
- Access through your own environment where the work allows it, so the data stays where it started.
- Logging that shows who saw what, and an offboarding checklist that actually runs on the last day.
- The engagement paperwork saying which categories of data the engineer may touch, and that the client remains controller of all of it.
A DPO who asks about this flow first is a DPO who has done this before. It is the question we would ask a supplier, and it is the one that most cleanly separates a considered position from a downloaded template.
Which SCC module, and why the wrong one is worse than none
The 2021 clauses come in four modules. For recruitment the choice is between Module One, controller to controller, and Module Two, controller to processor, and it is decided by a factual question: does the supplier decide anything about the data, or only carry out instructions?
A recruitment firm that sources candidates, decides who to approach, keeps its own talent records and answers data-subject requests in its own name is an independent controller. That makes Module One correct. Module Two is right where the supplier genuinely processes only on documented instructions — an outsourced screening mandate, for instance — and it comes with an Article 28 processing agreement attached.
The Article 3(2) gap, stated honestly
Here is a genuine unresolved point that most suppliers will not raise with you. The 2021 SCCs are drafted for importers not subject to the GDPR. A Moldovan recruiter serving EU clients and sourcing EU candidates is subject to it, under Article 3(2). The Commission has said since 2024 that it is developing an additional set of clauses for importers caught by Article 3(2); as at 30 August 2026 its own SCC page still lists only the June 2021 set as adopted, with no completion date.
What to do in the gap: sign the 2021 clauses anyway. They are the only adopted instrument, every procurement process will require them, and the EDPB’s position is that a Chapter V tool is needed regardless. Then record the mismatch in your Article 30 record so it reads as a considered position rather than an oversight, and re-paper if and when the new set lands. A supplier who can describe this gap to you unprompted has read the source; a supplier who says "we are fully SCC compliant" has read a template.
What the transfer impact assessment has to cover
The assessment is short for this destination and you can reuse it across suppliers. Six things, following the EDPB’s post-Schrems II recommendations:
- The transfer, described. Categories of data, categories of subjects, purposes, frequency, and the actual systems involved — not "HR data".
- The instrument. Which module, signed by whom, when, and where the executed copy lives.
- The destination’s law. For Moldova: Law No. 195/2024 in force since 23 August 2026, a near-verbatim GDPR transposition; an independent supervisory authority with investigative and corrective powers; Convention 108 party since 2008 and Convention 108+ ratified in 2026; judicial remedies available to data subjects. That is a materially stronger position than the third countries this exercise was designed for.
- Access by public authorities. Assess the destination’s surveillance and disclosure law against the transfer in question, and say what you found. If your supplier has never received a government access request, record that too — it is a fact, with a date.
- Supplementary measures. Encryption in transit and at rest, pseudonymisation, access scoping, retention limits, and a contractual commitment to notify and challenge unlawful access requests where the law permits.
- A review date. Adequacy positions change; Moldova is in EU accession negotiations and has the standard adequacy fact pattern. Diarise it rather than rewriting the assessment in a panic when it does change.
One more item belongs in the vendor file rather than the assessment: whether your Moldovan supplier has appointed an Article 27 EU representative. A recruiter processing EU candidate data regularly cannot use the "occasional processing" exemption, and the Dutch supervisory authority has fined a controller EUR 525,000 for that omission alone. Ask us the same question, and here is the answer before you have to ask it: TalentSync has not appointed one. We are working out whether Article 27 applies to us, and the name and address will be published in our privacy policy the moment there is one to publish. Until then, write to victor@talentsync.eu — and a data subject can always complain to their own supervisory authority instead.
If you are a UK client
The UK operates its own list. EU adequacy for the UK was renewed on 19 December 2025, which keeps your own EU flows clean, but it says nothing about a UK-to-Moldova transfer. We could not verify that Moldova appears on the UK’s data bridge list, so assume it does not: use the IDTA, or the UK Addendum to the EU SCCs, together with a transfer risk assessment on the same six headings above. If your legal team establishes otherwise, we would genuinely like to know.
Six things to put in the vendor file
- Executed SCCs, correct module, dated, with the annexes actually filled in.
- The supplier’s privacy notice — does it describe them as controller or processor, and does that match the module you just signed?
- Their Article 27 EU representative, named and published — or, where none is appointed, their written position on it. Ours is in the section above.
- Their retention schedule for candidate data, with a mechanism behind it and not just a sentence.
- Their sub-processor list, and where each one hosts. A US-hosted applicant tracking system is a second transfer with its own analysis.
- Your own answer on system access: which accounts the engineer gets, what data those accounts reach, and who revokes them.
Sources and check dates
Everything above was verified against primary sources on 30 August 2026. We are not lawyers and this is not legal advice; it is our own position, written down so it can be argued with. Where we could not verify something — the Article 3(2) clauses, the UK data bridge — the article says so instead of rounding it off.
- European Commission — adequacy decisions
- European Commission — standard contractual clauses
- EDPB Guidelines 05/2021 on the interplay of Article 3 and Chapter V
- Law No. 195/2024 on personal data protection, English text — published by the CNPDCP
- National Centre for Personal Data Protection — the Moldovan supervisory authority
The contractual side of an engagement — what the clauses sit inside — is on the direct B2B recruitment page, and the same questions in the context of an ongoing assignment are on the hourly collaboration page. If your interest is the jurisdiction itself rather than the paperwork, recruiting in Moldova covers the market we work in.