Until a few months ago, an inspection by the Commissioner almost always ended with a recommendation. Today it can end with a fine worth hundreds of thousands of euros.
The decisions of 12.06.2026 — around 1 million euros in sanctions against Agi Kons, Progeen and the pharmacy chain Ditë e Natë — mark what is probably the most important change of course ever seen in Albanian data protection practice.
The pattern that worked for years
For years, the market learned a simple lesson: privacy risk in Albania was limited.
The Commissioner would arrive. Violations would be found. A recommendation would follow. A few documents would be fixed. And there it ended.
On 12 June 2026, that pattern broke for good.
How the turn was prepared
Law no. 124/2024 equipped the Commissioner with a new sanctions regime, while Instruction no. 06/2025 set an objective methodology for calculating fines. Together they created the legal basis for sanctions that are not only higher, but also far more defensible under judicial review.
The first tests came quickly. In January 2026, three IT companies were fined around 95 thousand euros in total — we analysed them in our article on the five lessons from the January decisions.
In April 2026, four construction companies received recommendations. No fines — but with an express warning in the text: in case of non-implementation, Articles 92-94 apply. They were spared because they cooperated during the investigation.
It was the final warning, put in writing.
12 June: the three decisions
Agi Kons (construction): 24 million Lekë for Articles 6, 7 and 8 — employee photos and videos published on Instagram without proof of consent — plus 11.11 million Lekë for security gaps and the unformalised relationship with the company maintaining its website. Total: 35.11 million Lekë, around 360 thousand euros.
Progeen (construction): 3 million Lekë for failing to inform data subjects and 18 million Lekë for Articles 27, 28 and 33 — the record of processing activities, security, the DPO. Total: 21 million Lekë, around 220 thousand euros.
Ditë e Natë (pharmacies): sanctioned under Articles 6, 7, 8 and 13 — indefinite retention of customer data, cameras that also filmed public spaces, Instagram publications without consent, incomplete privacy notices.
The same list, a different instrument
Now compare June's list with April's: social media without consent, CCTV over public spaces, undefined retention, missing DPAs, no DPO.
It is the same list. What received a recommendation in April received a fine in June.
This is not a quantitative change. It is a change of philosophy.
Why the course changed
The Commissioner has said it itself: the June decisions mark the transition from the education and orientation phase to the effective application of the law's punitive mechanisms. An authority that only recommends does not pass the equivalence test with its European counterparts — and Albania is in an integration process.
The campaigns are sectoral and escalating: IT in January, construction in April and June, now pharmaceuticals too. Sectors with mass public contact — private healthcare, education, tourism, retail — have every reason to consider themselves next.
And the quiet message of the practice is clear: those who cooperate during the investigation receive a recommendation; those who do not, pay.
What this means for your business
From this moment on, non-compliance is no longer a formal problem. It is a real financial risk.
The points fined in June now carry a published price: employee photos and videos on social media without a consent form, cameras filming the street, undocumented retention periods, missing DPAs with processors — including whoever maintains your website — and no DPO where one is required.
If you have received a recommendation, treat it as a preliminary fine under a suspensive condition: the deadlines are real, and the notification to the Commissioner must be accompanied by evidence, not promises.
In conclusion
The decisions of 12 June 2026 should not be read merely as three administrative proceedings against three companies. They are the clearest signal yet that the period of tolerance is over.
Every controller that keeps relying on the practices of the past is now taking on a far greater economic and reputational risk than only a few months ago.
If you wish to assess your organisation's level of compliance with Law no. 124/2024 before an inspection, you can contact our firm for a preliminary compliance audit.