Compliance, AML & GDPR

Regulatory compliance, anti-money-laundering obligations and data protection — sized to your actual activity, not a generic checklist.

Three Different Questions, Often Asked Together

“Compliance” means something different depending on what your company does. For a regulated activity — financial services, gambling, real estate brokerage, dealing in high-value goods — it means sector-specific licensing and ongoing regulatory obligations. For almost every company, regardless of activity, it also means two more specific regimes: anti-money-laundering (AML) obligations tied to Albanian company law, and data protection obligations under Albania’s data protection framework — which may sit alongside actual EU GDPR exposure if you handle EU residents’ personal data directly.

These three questions are related but distinct, and the right amount of compliance work depends entirely on your specific activity — a services company with no EU customers and no regulated activity needs a fraction of what a fintech or a real estate brokerage needs. Albania For Business Sh.p.k. starts every engagement by figuring out which of these actually applies to you, rather than selling a generic compliance package.

LEGAL SERVICES

COMPLIANCE, AML & GDPR ASSESSMENT

450 EUR
fixed fee

PACKAGE OF COMPLIANCE, AML & GDPR ASSESSMENT INCLUDES:

  • Regulatory scoping — identifying which licences or permits apply to your specific activity
  • AML risk assessment and policy review, including UBO and customer due diligence obligations
  • Data protection gap analysis — what personal data you process, on what legal basis, and where it goes
  • Written compliance report with prioritised action items
  • Draft AML policy and procedures, where your activity requires one
  • Draft privacy policy and data processing documentation, where required
  • Follow-up consultation to review findings and agree next steps
Fixed fee for the initial assessment across all three areas for a single company with one core business activity. Sector-specific licence applications, ongoing AML/GDPR monitoring, and staff training are scoped and quoted separately.

When AML Obligations Apply

  • Every Albanian company has a baseline obligation to declare and keep current its beneficial owner (UBO) register — this applies regardless of activity, and is separate from the deeper obligations below.
  • Regulated activities carry substantially stricter AML obligations — banks and financial institutions, currency exchange, real estate brokerage, dealers in high-value goods (art, jewellery, precious metals), gambling operators, and virtual asset service providers.
  • For regulated activities, obligations typically include customer due diligence, ongoing monitoring, record-keeping, and reporting suspicious transactions to Albania’s Financial Intelligence Unit.
  • Even outside formally regulated sectors, receiving large cash payments or dealing with high-risk counterparties or jurisdictions can trigger AML scrutiny.

When Data Protection & GDPR Obligations Apply

  • Albania has its own data protection law, aligned with EU GDPR principles and enforced by Albania’s data protection authority — this applies to any company processing personal data in Albania, regardless of whether you have EU customers.
  • If you process the personal data of EU residents directly — selling to EU customers, running EU-facing marketing, or operating a platform EU users sign up to — actual EU GDPR can apply extraterritorially, on top of Albanian requirements.
  • Common triggers: e-commerce or SaaS platforms with EU users, employee data (for any company with staff), marketing databases and email lists, and any processing of sensitive categories of data (health, biometric, financial).
  • The scope of what’s required scales with the volume and sensitivity of data you handle — a five-person services company and a consumer app with thousands of EU users face very different obligations.

Compliance Assessment, Step by Step

  1. Activity & data mapping — understanding what your company does, what licences might apply, and what personal data you collect and process.
  2. Regulatory, AML & GDPR gap analysis — comparing your current position against what actually applies to you.
  3. Written report & prioritised recommendations — a clear list of what needs attention first, and what can wait.
  4. Policy drafting — AML policy and procedures, or a privacy policy and data processing documentation, drafted where needed.
  5. Implementation support & follow-up — helping put the recommendations into practice, not just handing over a report.

What We Need From You

  • A description of your business activity, including anything that might be regulated or licensed.
  • What personal data you collect (customers, employees, marketing contacts) and roughly how many people it covers.
  • Whether you sell to, market to, or otherwise process the data of EU residents.
  • Any existing AML or privacy policies you already have, even informal ones.
  • Whether you’ve had any prior contact with a regulator, the Financial Intelligence Unit, or a data protection complaint.

Fee Schedule — Additional & Ongoing Services

Beyond the fixed package above, the following services are priced individually. Your adviser confirms an exact quotation once your structure, nationality and banking preference are known.

Service Indicative Fee
Compliance, AML & GDPR assessment (as above) €450 fixed fee
Sector-specific licence application support quoted individually
AML policy & procedures drafting (standalone) from €300
Privacy policy / GDPR documentation drafting (standalone) from €250
Data processing agreement (DPA) drafting from €200
UBO register review & update from €80
AML / GDPR staff training session from €200
Ongoing compliance monitoring (monthly) from €300 / month
⚠ Practical note

The cost of non-compliance is rarely just the fine — it’s the licence application that stalls, the bank that freezes an account pending clarification, or the EU customer relationship that ends because a data protection question couldn’t be answered. Equally, over-scoping compliance for a small company that doesn’t need it wastes money and attention on documentation nobody will ever read. The assessment exists to size this correctly in both directions, not to sell you the maximum possible program.

Frequently Asked Questions

Compliance is the broadest term — regulatory and licensing obligations tied to your specific activity. AML (anti-money-laundering) is a specific regime, ranging from a baseline UBO declaration for every company to much stricter obligations for regulated sectors. GDPR/data protection is separate again — about how you collect, use and protect personal data. Most companies have some AML and data protection exposure even without a regulated activity.

No. A baseline UBO declaration applies to every company, but a full AML policy with customer due diligence and transaction monitoring is generally only required for regulated activities — financial services, real estate brokerage, dealers in high-value goods, gambling, and similar sectors. Our assessment tells you which category you fall into.

Possibly not “full” compliance in the sense a large platform needs, but some obligations likely apply as soon as you’re processing EU residents’ personal data at all. The scope scales with volume and sensitivity — a handful of customers with basic order data is a very different picture from a subscription platform with detailed user profiles. The assessment sizes this to your actual situation.

The beneficial owner (UBO) register is a baseline company-law requirement — every Albanian company declares who ultimately owns or controls it, and keeps that declaration current. It’s closely tied to AML policy generally, since UBO transparency is one of the core tools AML frameworks rely on, but it applies to every company regardless of activity, not only regulated ones.

This depends on the scale and nature of your data processing — it’s generally required where processing is large-scale, involves sensitive data categories, or is a core part of your business activity, though the specific thresholds should be assessed against your situation rather than assumed. Many smaller companies don’t need a formal DPO but still need basic policies and practices in place.

Consequences range from administrative fines to, in more serious AML cases, restrictions on banking relationships or regulatory licences. For data protection, complaints from individuals or a data breach can trigger regulatory scrutiny even without a fine being the first outcome. The bigger practical risk is often operational — a bank or partner asking a compliance question you can’t answer.

Yes, we scope and support sector-specific licence applications individually, since requirements vary considerably by regulator and activity. This typically follows on from the initial compliance assessment once we’ve identified which licence(s) apply to you.

At minimum, whenever your activity, customer base, or data practices change materially — a new product line, a new market, or a new category of data collected. A periodic review, even where nothing obvious has changed, also catches drift between policy and practice before it becomes a problem.