{
 "jurisdiction_id": "RO",
 "jurisdiction": "Romania",
 "url": "https://dataprotection.gi/jurisdictions/romania/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 29,
  "sub_modules": 57,
  "source_register": 17
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "registration_and_filing",
    "regulator_and_authority",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/romania/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Fully operational GDPR-aligned regime with an active, resourced DPA and a national implementing statute in force since 2018.",
   "claims": [
    {
     "statement": "The National Supervisory Authority for Personal Data Processing (ANSPDCP) is the competent supervisory authority for data protection matters in Romania under Law No. 190/2018.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/romania?topic=residency",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Romania implemented the GDPR through Law No. 190/2018 Implementing the General Data Protection Regulation (Regulation (EU) 2016/679).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/legal-research/law-no-1902018-implementing-general-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Law No. 190/2018 is relatively comprehensive and includes detailed provisions on the processing of data for journalistic purposes or academic or artistic expression, on certification bodies, and on corrective measures and sanctions for both private and public bodies.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/romania?topic=residency",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Territorial scope of the Romanian regime tracks GDPR Article 3 directly, applying to controllers/processors established in Romania and, via the targeting test, to non-established controllers processing data of subjects in Romania.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "ANSPDCP issued a statement on the elimination of the obligation to notify data processing operations, consistent with the GDPR's shift away from ex-ante registration toward accountability-based compliance (Recital 89, Articles 36-37 GDPR).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/romania-data-processing-notification",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/romania/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Direct GDPR application with CJEU-clarified consent standard originating from a Romanian reference.",
   "claims": [
    {
     "statement": "Data controllers in Romania must rely on lawfulness under GDPR Article 6(1)(a)-(f) as the exhaustive set of lawful bases for processing personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/sme/be-compliant/process-personal-data-lawfully_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In a reference from the Tribunalul București concerning collection and storage of identity-document copies by a mobile telecoms provider, the CJEU examined whether a tick-box declaration and contract signature satisfy the GDPR/Directive 95/46 consent standard, and addressed the burden of proof for valid consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A62019CJ0061",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "ANSPDCP fined Continental Automotive Products SRL after an Excel file containing employees' medical data (special-category data under GDPR Article 9) was repeatedly distributed internally without adequate technical and organisational measures.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/romania-anspdcp-fines-continental-automotive-products",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/romania/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights framework mirrors GDPR baseline; enforcement record shows the regulator actively polices non-compliance with erasure and access obligations.",
   "claims": [
    {
     "statement": "ANSPDCP fined an individual RON 50,890 for, inter alia, violating GDPR Article 17(1) by failing to respond to a request to delete personal data, in addition to publishing identity cards online without a legal basis.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/romania-anspdcp-fines-individual-ron-50890-sharing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The individual sanctioned by ANSPDCP was found to have breached GDPR Article 12(3)-12(4) transparency and response-timeliness obligations toward data subjects.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/romania-anspdcp-fines-individual-ron-50890-sharing",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/romania/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Framework is GDPR-aligned (green in principle) but repeated enforcement findings of Article 32/33 non-compliance among controllers warrant an amber operational rating.",
   "claims": [
    {
     "statement": "ANSPDCP's October 2024 election-processing recommendations require political entities acting as controllers under GDPR Article 4(7) to conduct a Data Protection Impact Assessment and maintain records of processing activities.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/romania-anspdcp-issues-recommendations-processing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "ANSPDCP guidance reminds political-entity controllers processing personal data during elections to appoint a Data Protection Officer where the GDPR Article 37 threshold is met.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/romania-anspdcp-issues-recommendations-processing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "ANSPDCP guidance requires organisations processing personal data during elections to maintain records of data processing activities consistent with GDPR Article 30.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/romania-anspdcp-issues-recommendations-processing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "ANSPDCP found that Hora Credit IFN S.A. did not take sufficient security measures for personal data, according to Articles 25 and 32 of the GDPR, so as to avoid unauthorised disclosure of personal data to third parties.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2019/romanian-supervisory-authority-fine-against-hora-credit-ifn-sa_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "ANSPDCP fined Hora Credit IFN S.A. for failing to notify the supervisory authority of a security incident within 72 hours from the date it became aware of it, per GDPR Article 33.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2019/romanian-supervisory-authority-fine-against-hora-credit-ifn-sa_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/romania/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Transfer mechanisms are the harmonised EU-wide GDPR Chapter V toolkit; no Romania-specific localisation mandate identified.",
   "claims": [
    {
     "statement": "ANSPDCP cooperated as lead supervisory authority under Article 60 GDPR one-stop-shop with the German Land of North Rhine-Westphalia's data protection authority (and consulted France, Denmark and Spain) in a cross-border case against Microstockr SRL, a Romania-based controller.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2021-08/ro_2020-12_final_decision_redacted.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "As an EU Member State, Romania is bound by European Commission adequacy decisions adopted under GDPR Article 45 for the EU as a whole rather than adopting independent national adequacy findings.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/romania/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial and employment overlays are evidenced by case law/enforcement; health, education, telecoms-specific and insurance overlays were not separately confirmed in this pass and are marked absent.",
   "claims": [
    {
     "statement": "ANSPDCP sanctioned non-bank lender Hora Credit IFN S.A. for GDPR violations in the collection and processing of personal data for concluding and executing consumer loan agreements, including insufficient security measures and a 72-hour breach-notification failure.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2019/romanian-supervisory-authority-fine-against-hora-credit-ifn-sa_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Romania's ePrivacy cookie-consent obligation under Article 5(3) of Directive 2002/58/EC is transposed by Law No. 506/2004 and enforced by ANSPDCP with a consent standard aligned to GDPR Articles 4(11) and 6(1)(a).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2021-08/ro_2020-12_final_decision_redacted.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The ECHR Grand Chamber, in Bărbulescu v. Romania, held that an employer's monitoring of an employee's electronic communications was unlawful because the employer did not give the employee prior notice of the nature and extent of the monitoring, aligning Romanian workplace-monitoring practice with Council of Europe, Romanian and EU law transparency requirements.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/takeaways-from-the-echr-employee-monitoring-decision",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/romania/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Cookie-consent enforcement is confirmed and active; dark patterns, opt-out signal recognition, clean-room rules and cross-context advertising lack confirmed Romania-specific findings in this pass.",
   "claims": [
    {
     "statement": "ANSPDCP found that Microstockr SRL failed to obtain valid cookie consent under Article 5(3) of Directive 2002/58/EC (as transposed by Law No. 506/2004) because the consent mechanism did not constitute a free, specific, informed and unambiguous active indication of the user's wishes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/system/files/2021-08/ro_2020-12_final_decision_redacted.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/romania/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Governed by directly-applicable EU-level AI Act/GDPR; amber reflects genuine EU-wide uncertainty over high-risk AI Act timelines and guidance that also affects Romanian deployers/providers.",
   "claims": [
    {
     "statement": "The EU AI Act's obligations for high-risk AI systems (Annex III, including biometrics, education, employment and law enforcement use cases) were due to apply from 2 August 2026, but delayed availability of harmonised standards, common specifications and Commission guidance, along with delayed designation of national competent authorities, has led to a Commission proposal to link entry into application to the availability of supporting compliance measures.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EDPB/EDPS",
     "source_url": "https://www.edpb.europa.eu/system/files/2026-01/edpb_edps_jointopinion_202601_proposal_ai-omnibus_en.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/romania/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Age-of-consent position for Romania could not be confirmed against primary text in this pass; treated as open/Probable rather than silently assumed.",
   "claims": [
    {
     "statement": "GDPR Article 8 sets the default digital age of consent for information-society services at 16, allowing Member States to lower it by national law to not below 13; a Romania-specific statutory derogation could not be confirmed in this research pass.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-10-operational-impacts-of-the-gdpr-part-3-consent",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Absent a confirmed national derogation, controllers offering information-society services directly to children in Romania must obtain parental/guardian consent for children below the GDPR Article 8 default age of 16.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/top-10-operational-impacts-of-the-gdpr-part-3-consent",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/romania/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement is active and evidenced by multiple 2026 decisions, but the regulator's absolute funding/headcount and any Romania-specific collective-redress mechanism could not be confirmed in this pass.",
   "claims": [
    {
     "statement": "ANSPDCP applies corrective measures under GDPR Article 58(2) and administrative fines under GDPR Article 83, procedurally implemented through Law No. 190/2018 Article 12 and Law No. 102/2005 Article 16 (including paragraphs (3), (5), (6) and (7) governing sanctions imposed by decision of the ANSPDCP president in cross-border cases).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2023/romanian-sa-fines-uipath-srl-breaching-articles-25-and-32-gdpr_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 30 January 2026, ANSPDCP fined an individual RON 50,890 (approx. €10,000) for GDPR violations including publishing identity cards online and failing to respond to a data-deletion request.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/romania-anspdcp-fines-individual-ron-50890-sharing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "On 19 January 2026, ANSPDCP fined Continental Automotive Products SRL RON 76,366 (approx. €15,000) for GDPR violations of Articles 32(1)(b) and 32(2) following a data-breach notification involving employees' medical data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/romania-anspdcp-fines-continental-automotive-products",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A Romanian employee successfully pursued an individual complaint to the European Court of Human Rights (Bărbulescu v. Romania) after domestic courts failed to strike an appropriate balance between his privacy rights and his employer's business interests, illustrating the multi-forum redress avenues (domestic courts, ANSPDCP, ECHR) available to Romanian data subjects.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/takeaways-from-the-echr-employee-monitoring-decision",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The EDPB's 2025 Annual Report, published 9 April 2026, reported that EU national DPAs collectively issued approximately €1.15 billion in fines during 2025, with 414 cross-border cases created and 572 final One-Stop-Shop decisions under Article 60 GDPR — the cooperative framework in which ANSPDCP participates.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://edpb.europa.eu/news/news/2026/edpb-annual-report-2025-supporting-stakeholders-through-guidance-and-dialogue_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}