Albania: Law on Cyber Security
The Law on Cyber Security is legislation adopted by the Albanian Parliament in 2020. It aims to establish a legal framework for protecting critical information infrastructure and information systems from cyber threats. The law applies to all public and private entities that use information systems and networks in Albania, including government institutions, telecommunication providers, and financial institutions.
The law defines cyber threats and establishes measures for preventing, detecting, and responding to such threats. It also requires the establishment of a national cyber security centre to coordinate and implement cyber security policies and strategies. The centre is responsible for monitoring and responding to cyber incidents, as well as for conducting research and developing new technologies to enhance cyber security in the country.
The law also introduces provisions for protecting personal data and privacy in the context of cyber security. It requires entities to comply with international data protection standards and to notify individuals of data breaches. The law has been praised for its comprehensive approach to cyber security and emphasis on protecting critical infrastructure. However, some experts have raised concerns about the law’s potential impact on freedom of expression and the potential for abuse of power by the authorities.
CHAPTER I: GENERAL PROVISIONS
Article 1 – The purpose of the law
Article 2 – Scope of Application
Article 3 – Definitions In this law, the following terms have these meanings:
Article 4 – Processing of personal data
CHAPTER II: RESPONSIBLE ENTITIES IN THE FIELD OF CYBERSECURITY
Article 5 – Competences of Responsible Authority in the field of cyber security
Article 6 – Other entities responsible
Article 7 – Computer Security Incidents Responding Team (CSIRT)
CHAPTER III: CYBER SECURITY ADMINISTRATION
Article 8 – Security measures
Article 9 – Types of security measures
Article 10 – Events and incidents of cyber security
Article 11 – Reporting cyber security incidents
Article 12 – Incident Data storage
Article 13 – Data confidentiality
Article 14 – The measures in case of a threat or cyber incident
Article 15 – The warnings
Article 16 – The countermeasures
Article 17 – The protective measures of a general nature
Article 18 – Contact Points
CHAPTER IV: CYBER CRISIS SITUATION
Article 19 – Cyber crisis
CHAPTER V: ADMINISTRATIVE MISDEMEANOR
Article 20 – Corrective measures
Article 21 – Administrative Offences
Article 22 – Administrative sanctions
Article 23 – Procedures
Article 24 – Bylaws
Article 25 – Transitional provisions
Article 26 – Entry into force







