Lead Signal
The EDPB's 2025 Annual Report, published 9 April 2026, reports that EU national data protection authorities collectively issued approximately €1.15 billion in fines during 2025, with 414 cross-border cases created and 572 final One-Stop-Shop decisions under Article 60 of the GDPR. Romania's ANSPDCP participates in this cooperative architecture, having served as lead supervisory authority in the Microstockr SRL case, consulting Germany's North Rhine-Westphalia data protection authority alongside France, Denmark and Spain. This EU-wide cooperative scale forms the backdrop against which Romania's own enforcement activity this cycle should be read.
Other Developments
ANSPDCP fined Continental Automotive Products SRL RON 76,366 (approximately €15,000) on 19 January 2026 after an Excel file containing employees' medical data was repeatedly distributed internally without adequate technical and organisational measures, in violation of GDPR Articles 32(1)(b) and 32(2). Eleven days later, on 30 January 2026, ANSPDCP fined an individual RON 50,890 for publishing identity cards online without a legal basis and for failing to respond to an erasure request, findings the authority tied to breaches of GDPR Articles 17(1) and 12(3)-12(4). Both sanctions sit within a longer enforcement pattern: ANSPDCP separately found that Hora Credit IFN S.A. had not implemented sufficient security measures under GDPR Articles 25 and 32, allowing unauthorised disclosure of personal data to third parties, and fined the lender for failing to notify the supervisory authority of a security incident within the 72-hour window required by GDPR Article 33.
Romania's data protection architecture otherwise remains a directly-implemented GDPR omnibus: ANSPDCP is the competent supervisory authority for data protection matters in Romania under Law No. 190/2018, which implements the General Data Protection Regulation domestically. That statute also includes detailed provisions on processing for journalistic, academic and artistic expression, certification bodies, and corrective measures and sanctions for private and public bodies. The pre-GDPR general notification and registration obligation for data processing has been eliminated, consistent with the accountability-based model. The CJEU's ruling in C-61/19, Orange România, examined whether a tick-box declaration or contract signature satisfies the GDPR consent standard and addressed the controller's burden of proving valid consent. Separately, the EDPB's public consultation on Guidelines 01/2025 on Pseudonymisation closed in March 2025, with a finalised version anticipated later that year, correcting an earlier characterisation of the guidance as still under consultation.
At EU level, high-risk system obligations under Annex III of the AI Act are due to apply from 2 August 2026, subject to a pending European Commission Digital Omnibus proposal that could delay or adjust that timeline pending harmonised standards, common specifications, further Commission guidance and the designation of national competent authorities. This timeline uncertainty bears directly on Romanian deployers and providers of biometric, employment, education and law-enforcement AI systems.
ANSPDCP's October 2024 recommendations for election-related data processing required political entities acting as controllers to conduct a data protection impact assessment and maintain records of processing activities. The same guidance reminded such controllers to appoint a Data Protection Officer where the GDPR Article 37 threshold is met. The same guidance also required organisations processing personal data during elections to maintain records of processing activities consistent with GDPR Article 30.
A gap remains open this cycle: Whether Romania has adopted a national derogation from the GDPR Article 8 default digital age of consent of 16 could not be confirmed against primary statutory text. Controllers offering information-society services to children in Romania must, absent a confirmed national derogation, obtain parental or guardian consent for children below that default age.
Cross-Monitor Connections
The EU AI Act's high-risk application timeline, and the pending Digital Omnibus delay proposal affecting Romanian deployers, is being tracked in full by the artificial-intelligence monitor; this brief retains only the profiling, automated-decision-making transparency and biometric special-category angle under GDPR Articles 9 and 22. The Hora Credit IFN enforcement action, involving a non-bank consumer lender's handling of loan-agreement data, touches financial-sector data handling; any anti-money-laundering or financial-crime dimension of that case is a matter for the financial-integrity monitor, with this brief retaining only the data-protection compliance findings. No payments-specific data-flow issue was surfaced in Romania this cycle, notwithstanding a routing flag toward the world-payments monitor for triage completeness.
Outlook
Romania's regime continues to track the GDPR baseline closely, with ANSPDCP sustaining an active enforcement tempo into 2026 and participating routinely in EU one-stop-shop cooperation. The near-term watch points are the AI Act's Annex III timeline, where the Digital Omnibus proposal could shift Romanian deployers' compliance horizon, and the unresolved question of whether Romania has set its own digital age-of-consent threshold within the range GDPR Article 8 permits.