🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
RO · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 17 sources retrieved model claude-sonnet-5 ·

Romania

RO schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 29 claims · 17 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
29Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

Lead Signal

The EDPB's 2025 Annual Report, published 9 April 2026, reports that EU national data protection authorities collectively issued approximately €1.15 billion in fines during 2025, with 414 cross-border cases created and 572 final One-Stop-Shop decisions under Article 60 of the GDPR. Romania's ANSPDCP participates in this cooperative architecture, having served as lead supervisory authority in the Microstockr SRL case, consulting Germany's North Rhine-Westphalia data protection authority alongside France, Denmark and Spain. This EU-wide cooperative scale forms the backdrop against which Romania's own enforcement activity this cycle should be read.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Fully operational GDPR-aligned regime with an active, resourced DPA and a national implementing statute in force since 2018.

Primary frameworkRegulation (EU) 2016/679 (GDPR) as implemented by Law No. 190/2018
Traffic-light rationale — GreenFully operational GDPR-aligned regime with an active, resourced DPA and a national implementing statute in force since 2018.

Sub-modules (5)

Regulator And AuthorityGreen

ANSPDCP is the single national competent authority for GDPR matters in Romania, operating under Law No. 102/2005 (organisational statute) and Law No. 190/2018 (GDPR implementation).

Claims: CLM-RO-a1b2c3d4

Act And InstrumentsGreen

The operative instruments are the GDPR itself and the national implementing Law No. 190/2018.

Claims: CLM-RO-b2c3d4e5

Material ScopeGreen

Material scope follows GDPR Art 2/4 directly; Law 190/2018 adds detailed rules for journalistic, academic, artistic and literary expression processing.

Claims: CLM-RO-c3d4e5f6

Territorial ScopeGreen

Territorial scope follows GDPR Art 3 directly (establishment + targeting tests); no Romania-specific narrowing or broadening identified.

Claims: CLM-RO-d4e5f6a7

Registration And FilingGreen

Romania abolished the pre-GDPR general notification/registration obligation; ANSPDCP issued a public statement confirming elimination of the notification duty, consistent with GDPR's accountability-based model (Recital 89).

Claims: CLM-RO-e5f6a7b8

Category narrative60 words

Romania implements the GDPR through Law No. 190/2018 Implementing the General Data Protection Regulation, with the National Supervisory Authority for Personal Data Processing (ANSPDCP) as the competent supervisory authority. The regime is a fully-operational EU Member State omnibus regime; Romania did not enact a broad derogation architecture beyond the sector-specific carve-outs (journalism/academic/artistic expression, certification bodies) permitted by GDPR opening clauses.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedDataGuidanceThe National Supervisory Authority for Personal Data Processing (ANSPDCP) is the competent supervisory authority for data protection matters in Romania under Law No. 190/2018.
  2. ConfirmedDataGuidanceRomania implemented the GDPR through Law No. 190/2018 Implementing the General Data Protection Regulation (Regulation (EU) 2016/679).
  3. ConfirmedDataGuidanceLaw No. 190/2018 is relatively comprehensive and includes detailed provisions on the processing of data for journalistic purposes or academic or artistic expression, on certification bodies, and on corrective measures and sanctions for both private and public bodies.
  4. ProbableEUR-LexTerritorial scope of the Romanian regime tracks GDPR Article 3 directly, applying to controllers/processors established in Romania and, via the targeting test, to non-established controllers processing data of subjects in Romania.
  5. ConfirmedDataGuidanceANSPDCP issued a statement on the elimination of the obligation to notify data processing operations, consistent with the GDPR's shift away from ex-ante registration toward accountability-based compliance (Recital 89, Articles 36-37 GDPR).

#

Direct GDPR application with CJEU-clarified consent standard originating from a Romanian reference.

Primary frameworkGDPR Articles 6, 7, 9; Law No. 190/2018
Supervisory authorityANSPDCP
Traffic-light rationale — GreenDirect GDPR application with CJEU-clarified consent standard originating from a Romanian reference.

Sub-modules (4)

Lawful BasesGreen

The six GDPR Article 6 lawful bases apply directly in Romania without a national supplementary list.

Claims: CLM-RO-f6a7b8c9

Special CategoriesGreen

Special categories follow GDPR Article 9 directly; ANSPDCP enforcement practice (e.g., health-data breach fines) confirms active application of the Art 9 regime to employee medical data.

Claims: CLM-RO-b8c9d0e1

Pseudonymisation And AnonymisationAmber

No Romania-specific statutory safe harbour beyond GDPR Articles 4(5) and 25/32 was identified; EDPB-level guidance on pseudonymisation (under public consultation in 2025) is the applicable reference framework absent national supplementation.

Category narrative51 words

Romania applies the GDPR's Article 6 lawful bases and Article 9 special-category regime directly, with Law 190/2018 not materially derogating from the EU baseline on consent standards. National case law referred to the CJEU (Orange România) clarified the standard for valid, freely-given, specific and informed consent in a Romanian telecoms context.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedEDPBData controllers in Romania must rely on lawfulness under GDPR Article 6(1)(a)-(f) as the exhaustive set of lawful bases for processing personal data.
  2. ConfirmedEUR-LexIn a reference from the Tribunalul București concerning collection and storage of identity-document copies by a mobile telecoms provider, the CJEU examined whether a tick-box declaration and contract signature satisfy the GDPR/Directive 95/46 consent standard, and addressed the burden of proof for valid consent.
  3. ConfirmedDataGuidanceANSPDCP fined Continental Automotive Products SRL after an Excel file containing employees' medical data (special-category data under GDPR Article 9) was repeatedly distributed internally without adequate technical and organisational measures.

#

Rights framework mirrors GDPR baseline; enforcement record shows the regulator actively polices non-compliance with erasure and access obligations.

Primary frameworkGDPR Articles 12-22; Law No. 190/2018
Supervisory authorityANSPDCP
Traffic-light rationale — GreenRights framework mirrors GDPR baseline; enforcement record shows the regulator actively polices non-compliance with erasure and access obligations.

Sub-modules (5)

Access RightGreen

Access right follows GDPR Article 15 directly; no national supplementary access regime identified.

Rectification And ErasureAmber

ANSPDCP sanctioned an individual for, among other violations, failing to respond to a data-subject erasure request under GDPR Article 17(1) after identity cards were published online.

Claims: CLM-RO-c9d0e1f2

Restriction And ObjectionAmber

Restriction/objection rights follow GDPR Articles 18/21 directly; no Romania-specific case identified in this research pass.

Data PortabilityAmber

Portability follows GDPR Article 20 directly; no Romania-specific derogation or guidance identified in this research pass.

Deadlines And Response WindowsGreen

Response deadlines follow the GDPR Article 12(3) one-month default (extendable by two further months for complex requests); no Romania-specific shortening/lengthening identified.

Claims: CLM-RO-d0e1f2a3

Category narrative47 words

Data subject rights (access, rectification, erasure, restriction, objection, portability) apply per GDPR Articles 15-22 with no Romania-specific derogations identified in Law 190/2018 beyond the general journalistic/academic/artistic exemptions. ANSPDCP enforcement actions confirm active supervision of erasure-request compliance (e.g., the evita-teparii.ro case for failure to honour a deletion request).

No periodic updates recorded against this sub-brief.

Sources and claims (2)
  1. ConfirmedDataGuidanceANSPDCP fined an individual RON 50,890 for, inter alia, violating GDPR Article 17(1) by failing to respond to a request to delete personal data, in addition to publishing identity cards online without a legal basis.
  2. ConfirmedDataGuidanceThe individual sanctioned by ANSPDCP was found to have breached GDPR Article 12(3)-12(4) transparency and response-timeliness obligations toward data subjects.

#

Framework is GDPR-aligned (green in principle) but repeated enforcement findings of Article 32/33 non-compliance among controllers warrant an amber operational rating.

Primary frameworkGDPR Articles 5, 24-25, 28, 30, 32-35, 37-39; Law No. 190/2018
Supervisory authorityANSPDCP
Traffic-light rationale — AmberFramework is GDPR-aligned (green in principle) but repeated enforcement findings of Article 32/33 non-compliance among controllers warrant an amber operational rating.

Sub-modules (7)

Accountability And DpiaGreen

ANSPDCP recommends DPIAs and ROPA maintenance in sector guidance (e.g., 2024 election-processing recommendations invoking GDPR Articles 5, 6 and 9 plus a DPIA duty for political-entity controllers).

Claims: CLM-RO-e1f2a3b4

Dpo RequirementsGreen

DPO appointment thresholds follow GDPR Articles 37-39 directly; Romania's election guidance explicitly reminds political-entity controllers to appoint a DPO where required.

Claims: CLM-RO-f2a3b4c5

Ropa RequirementsGreen

ROPA duties follow GDPR Article 30 directly; ANSPDCP guidance for electoral-processing controllers explicitly requires maintenance of records of processing activities.

Claims: CLM-RO-a3b4c5d6

Joint Controller ArrangementsAmber

Joint-controller allocation follows GDPR Article 26 directly; no Romania-specific supplementary rule identified in this research pass.

Security MeasuresAmber

ANSPDCP found Hora Credit IFN and Continental Automotive Products to have failed to implement appropriate technical and organisational security measures under GDPR Articles 25 and 32.

Claims: CLM-RO-b4c5d6e7

Breach NotificationAmber

Breach notification follows GDPR Article 33's 72-hour rule; ANSPDCP has separately fined a controller for failing to notify a security incident within 72 hours, and has opened investigations directly from breach notifications submitted by controllers (Continental, UiPath).

Claims: CLM-RO-c5d6e7f8

Retention And DisposalAmber

Retention/disposal follows GDPR Article 5(1)(e) storage-limitation principle directly; no Romania-specific statutory retention schedule beyond sectoral rules was identified in this research pass.

Category narrative56 words

Accountability, DPIA, security-of-processing, breach notification and retention duties in Romania follow GDPR Articles 5, 24-25, 30, 32-35 directly. ANSPDCP's enforcement docket (Hora Credit IFN, Continental Automotive, UiPath) repeatedly cites Articles 25, 32 and 33, confirming active supervision of security measures and the 72-hour breach-notification duty; failure to notify within 72 hours has itself been separately sanctioned.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedDataGuidanceANSPDCP's October 2024 election-processing recommendations require political entities acting as controllers under GDPR Article 4(7) to conduct a Data Protection Impact Assessment and maintain records of processing activities.
  2. ProbableDataGuidanceANSPDCP guidance reminds political-entity controllers processing personal data during elections to appoint a Data Protection Officer where the GDPR Article 37 threshold is met.
  3. ProbableDataGuidanceANSPDCP guidance requires organisations processing personal data during elections to maintain records of data processing activities consistent with GDPR Article 30.
  4. ConfirmedEDPBANSPDCP found that Hora Credit IFN S.A. did not take sufficient security measures for personal data, according to Articles 25 and 32 of the GDPR, so as to avoid unauthorised disclosure of personal data to third parties.
  5. ConfirmedEDPBANSPDCP fined Hora Credit IFN S.A. for failing to notify the supervisory authority of a security incident within 72 hours from the date it became aware of it, per GDPR Article 33.

#

Transfer mechanisms are the harmonised EU-wide GDPR Chapter V toolkit; no Romania-specific localisation mandate identified.

Primary frameworkGDPR Articles 44-50 (Chapter V); EU adequacy decisions
Supervisory authorityANSPDCP
Traffic-light rationale — GreenTransfer mechanisms are the harmonised EU-wide GDPR Chapter V toolkit; no Romania-specific localisation mandate identified.

Sub-modules (6)

Transfer MechanismsGreen

Transfer mechanisms (adequacy, SCCs, BCRs, Article 49 derogations) are the standard EU-wide GDPR Chapter V toolkit; no Romania-specific instrument identified.

Claims: CLM-RO-d6e7f8a9

Adequacy ReceivedGreen

Adequacy decisions are adopted by the European Commission for the EU as a whole; Romania does not receive or grant adequacy independently as an EU Member State.

Claims: CLM-RO-e7f8a9b0

Adequacy GrantedGreen

Same as adequacy_received — adequacy is an EU-level competence, not exercised individually by Romania.

Sccs And BcrsGreen

ANSPDCP applies the EU Standard Contractual Clauses and BCR framework as adopted at EU level; no Romania-specific SCC variant identified.

Transfer Impact AssessmentAmber

TIA obligations follow the EDPB's EU-wide post-Schrems II guidance; no Romania-specific TIA supplementary requirement identified.

Data LocalisationGreen

No general data-localisation mandate identified for Romania beyond sector-specific retention/record-keeping rules under national law.

Category narrative72 words

As an EU Member State, Romania does not operate an independent adequacy regime; cross-border transfer mechanisms (adequacy decisions, SCCs, BCRs, derogations) are governed exclusively at EU level under GDPR Chapter V and apply uniformly in Romania. ANSPDCP participates in EU one-stop-shop cross-border cooperation (Article 60 GDPR), as demonstrated in the UiPath and Microstockr cases where ANSPDCP acted as lead or cooperating authority with other EU DPAs (Germany's NRW authority, France, Denmark, Spain).

No periodic updates recorded against this sub-brief.

Sources and claims (2)
  1. ConfirmedEDPBANSPDCP cooperated as lead supervisory authority under Article 60 GDPR one-stop-shop with the German Land of North Rhine-Westphalia's data protection authority (and consulted France, Denmark and Spain) in a cross-border case against Microstockr SRL, a Romania-based controller.
  2. ConfirmedEUR-LexAs an EU Member State, Romania is bound by European Commission adequacy decisions adopted under GDPR Article 45 for the EU as a whole rather than adopting independent national adequacy findings.

#

Financial and employment overlays are evidenced by case law/enforcement; health, education, telecoms-specific and insurance overlays were not separately confirmed in this pass and are marked absent.

Primary frameworkGDPR (general); ECHR Article 8 (employment monitoring, via Bărbulescu); Law No. 190/2018
Supervisory authorityANSPDCP
Traffic-light rationale — AmberFinancial and employment overlays are evidenced by case law/enforcement; health, education, telecoms-specific and insurance overlays were not separately confirmed in this pass and are marked absent.

Sub-modules (7)

Financial Sector OverlayAmber

ANSPDCP sanctioned non-bank lender Hora Credit IFN S.A. for GDPR violations in loan-agreement data processing, including insufficient security measures and late breach notification.

Claims: CLM-RO-f8a9b0c1

Health Sector OverlayAmber

No dedicated Romanian health-sector DP statute was identified in this pass; health-data breaches (e.g., Continental Automotive medical-data case) are handled under general GDPR Article 9 rules rather than a distinct sectoral instrument.

Telecoms And EprivacyGreen

ePrivacy/cookie rules in Romania are implemented via Law No. 506/2004 (transposing Directive 2002/58/EC), enforced by ANSPDCP alongside GDPR consent standards, as seen in the Microstockr cookie-consent decision.

Claims: CLM-RO-a9b0c1d2

Employment DataAmber

The ECHR Grand Chamber's Bărbulescu v. Romania judgment establishes that Romanian and EU law require employers to give employees prior notice of the nature and extent of monitoring before accessing their communications.

Claims: CLM-RO-b0c1d2e3

Credit And ScoringAmber

No dedicated Romanian credit-scoring statute distinct from GDPR Article 22 was identified; the Hora Credit IFN case concerned general processing compliance rather than automated credit-scoring specifically.

EducationAmber

No dedicated Romanian education-sector DP overlay was identified in this research pass.

InsuranceAmber

No dedicated Romanian insurance-sector DP overlay was identified in this research pass.

Category narrative63 words

Sectoral overlays identified in Romania include financial-sector consumer-credit processing (Hora Credit IFN, an IFN/non-bank lender, sanctioned under GDPR for loan-processing data handling) and employment/workplace-monitoring rules shaped by the Grand Chamber ECHR Bărbulescu v. Romania judgment, which imposes transparency conditions on employer monitoring of employee communications. No dedicated Romanian health-sector, education-sector, or insurance-sector DP statute distinct from GDPR was identified in this research pass.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedEDPBANSPDCP sanctioned non-bank lender Hora Credit IFN S.A. for GDPR violations in the collection and processing of personal data for concluding and executing consumer loan agreements, including insufficient security measures and a 72-hour breach-notification failure.
  2. ConfirmedEDPBRomania's ePrivacy cookie-consent obligation under Article 5(3) of Directive 2002/58/EC is transposed by Law No. 506/2004 and enforced by ANSPDCP with a consent standard aligned to GDPR Articles 4(11) and 6(1)(a).
  3. ConfirmedIAPPThe ECHR Grand Chamber, in Bărbulescu v. Romania, held that an employer's monitoring of an employee's electronic communications was unlawful because the employer did not give the employee prior notice of the nature and extent of the monitoring, aligning Romanian workplace-monitoring practice with Council of Europe, Romanian and EU law transparency requirements.

#

Cookie-consent enforcement is confirmed and active; dark patterns, opt-out signal recognition, clean-room rules and cross-context advertising lack confirmed Romania-specific findings in this pass.

Primary frameworkDirective 2002/58/EC as transposed by Law No. 506/2004; GDPR
Supervisory authorityANSPDCP
Traffic-light rationale — AmberCookie-consent enforcement is confirmed and active; dark patterns, opt-out signal recognition, clean-room rules and cross-context advertising lack confirmed Romania-specific findings in this pass.

Sub-modules (6)

Cookies And TrackersAmber

ANSPDCP enforced the active-consent cookie standard against Microstockr SRL, finding that consent obtained via pre-existing account/contract mechanisms did not meet the 'free, specific, informed and unambiguous' standard required for storing/accessing information on user terminal equipment.

Claims: CLM-RO-c1d2e3f4

Dark PatternsAmber

No dedicated Romanian dark-patterns prohibition distinct from GDPR/DSA fair-processing principles was identified in this research pass.

Opt Out SignalsAmber

No Romania-specific recognition mandate for Global Privacy Control or DAA-style opt-out signals was identified in this research pass.

Clean Rooms And DcrAmber

No Romania-specific clean-room or data-collaboration-room regulatory framework was identified in this research pass.

Cross Context AdvertisingAmber

Cross-context advertising in Romania is governed by the general GDPR consent/legitimate-interest framework; no Romania-specific 'sale'/'share' concept analogous to US state law was identified.

Direct MarketingAmber

Direct marketing consent/suppression follows the ePrivacy opt-in standard under Law No. 506/2004 and GDPR Article 21(3) objection rights; no additional Romania-specific suppression registry was identified in this research pass.

Category narrative51 words

Cookie/tracker consent in Romania follows the ePrivacy Directive as transposed by Law No. 506/2004, enforced by ANSPDCP with the same GDPR-aligned active-consent standard applied in the Microstockr decision (rejecting pre-ticked or passive consent mechanisms). No Romania-specific dark-patterns statute, clean-room regime, or GPC/DAA opt-out-signal mandate distinct from EU-wide DSA/GDPR frameworks was identified.

No periodic updates recorded against this sub-brief.

Sources and claims (1)
  1. ConfirmedEDPBANSPDCP found that Microstockr SRL failed to obtain valid cookie consent under Article 5(3) of Directive 2002/58/EC (as transposed by Law No. 506/2004) because the consent mechanism did not constitute a free, specific, informed and unambiguous active indication of the user's wishes.

#

Governed by directly-applicable EU-level AI Act/GDPR; amber reflects genuine EU-wide uncertainty over high-risk AI Act timelines and guidance that also affects Romanian deployers/providers.

Primary frameworkGDPR Article 22; Regulation (EU) 2024/1689 (EU AI Act)
Supervisory authorityANSPDCP
Traffic-light rationale — AmberGoverned by directly-applicable EU-level AI Act/GDPR; amber reflects genuine EU-wide uncertainty over high-risk AI Act timelines and guidance that also affects Romanian deployers/providers.

Sub-modules (6)

Profiling RestrictionsGreen

Profiling restrictions follow GDPR Article 22 directly; no Romania-specific expansion or narrowing identified.

Automated Decision Making TransparencyGreen

ADM transparency obligations follow GDPR Articles 13(2)(f), 14(2)(g) and 15(1)(h) directly.

Ai Risk AssessmentsAmber

The EU AI Act's high-risk system obligations (Chapter III, Annex III — covering biometrics, employment, education, law enforcement) apply directly in Romania; however, the general application date of 2 August 2026 for high-risk rules is subject to a pending Commission Digital Omnibus proposal to adjust timelines linked to the availability of harmonised standards and Commission guidance.

Claims: CLM-RO-d2e3f4a5

Biometric RegimeAmber

Biometric data processing is governed by GDPR Article 9(1) (biometric data for unique identification as a special category) and, from August 2026, EU AI Act Annex III high-risk rules for biometric identification/categorisation systems; no Romania-specific biometric statute was identified.

Genetic DataAmber

Genetic data is a GDPR Article 9(1) special category; no Romania-specific genetic-data statute was identified in this research pass.

State Surveillance CarveoutsAmber

National-security/state-surveillance carve-outs follow the general GDPR Article 2(2)(d)/23 framework; no Romania-specific surveillance statute was identified in this research pass.

Category narrative88 words

Profiling/ADM restrictions in Romania follow GDPR Article 22 directly. The EU AI Act (Regulation (EU) 2024/1689) applies uniformly in Romania as a directly-applicable EU regulation; its high-risk-system obligations (covering biometrics, employment, education and law enforcement use cases under Annex III) were originally due to enter application on 2 August 2026, but a Commission Digital Omnibus proposal is under negotiation to delay/adjust that timeline pending finalisation of Commission guidance on high-risk classification. No Romania-specific biometric or state-surveillance carve-out statute distinct from GDPR/AI Act was identified in this research pass.

No periodic updates recorded against this sub-brief.

Sources and claims (1)
  1. ProbableEDPB/EDPSThe EU AI Act's obligations for high-risk AI systems (Annex III, including biometrics, education, employment and law enforcement use cases) were due to apply from 2 August 2026, but delayed availability of harmonised standards, common specifications and Commission guidance, along with delayed designation of national competent authorities, has led to a Commission proposal to link entry into application to the availability of supporting compliance measures.

#

Age-of-consent position for Romania could not be confirmed against primary text in this pass; treated as open/Probable rather than silently assumed.

Primary frameworkGDPR Article 8
Supervisory authorityANSPDCP
Traffic-light rationale — AmberAge-of-consent position for Romania could not be confirmed against primary text in this pass; treated as open/Probable rather than silently assumed.

Sub-modules (5)

Age VerificationAmber

GDPR Article 8 permits Member States to set the digital age of consent between 13 and 16; this research pass could not confirm from primary text whether Romania set a national derogation below the 16-year default.

Claims: CLM-RO-e3f4a5b6

Minor Profiling BansAmber

No dedicated Romanian minor-profiling ban distinct from GDPR Article 22/Recital 71 was identified in this research pass.

Education SettingsAmber

No dedicated Romanian education-sector children's-data statute was identified in this research pass.

Dependent AdultsAmber

No dedicated Romanian dependent-adults (elderly/incapacitated) data-protection statute distinct from GDPR general capacity/consent rules was identified in this research pass.

Category narrative102 words

GDPR Article 8 sets the EU default digital age of consent at 16, with Member States permitted to lower it to no less than 13. This research pass did not locate a definitive, authoritative confirmation that Romania has enacted a statutory derogation lowering the age of consent below the GDPR default; Law No. 190/2018 summaries reviewed did not surface an explicit age-of-consent provision, so Romania's position is treated as Probable-default (16) rather than Confirmed pending direct verification of the Law 190/2018 text or ANSPDCP guidance. No dedicated Romanian minor-profiling ban, education-sector-specific DP rule, or dependent-adults DP statute distinct from GDPR was identified.

No periodic updates recorded against this sub-brief.

Sources and claims (2)
  1. UncertainIAPPGDPR Article 8 sets the default digital age of consent for information-society services at 16, allowing Member States to lower it by national law to not below 13; a Romania-specific statutory derogation could not be confirmed in this research pass.
  2. UncertainIAPPAbsent a confirmed national derogation, controllers offering information-society services directly to children in Romania must obtain parental/guardian consent for children below the GDPR Article 8 default age of 16.

#

Enforcement is active and evidenced by multiple 2026 decisions, but the regulator's absolute funding/headcount and any Romania-specific collective-redress mechanism could not be confirmed in this pass.

Primary frameworkGDPR Articles 58, 77-84; Law No. 190/2018 Article 12-16; Law No. 102/2005
Supervisory authorityANSPDCP
Traffic-light rationale — AmberEnforcement is active and evidenced by multiple 2026 decisions, but the regulator's absolute funding/headcount and any Romania-specific collective-redress mechanism could not be confirmed in this pass.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

ANSPDCP exercises corrective and sanctioning powers under GDPR Article 58(2) and applies the Article 83 fining tiers via Law No. 190/2018 Article 12 and Law No. 102/2005 Article 16 procedural rules.

Claims: CLM-RO-a5b6c7d8

Enforcement Activity IndexAmber

ANSPDCP issued at least two significant fines in January 2026 alone (an individual website operator for RON 50,890 and Continental Automotive Products SRL for RON 76,366), continuing an active multi-year enforcement pattern including a 2023 €70,000 fine against UiPath SRL.

Claims: CLM-RO-b6c7d8e9, CLM-RO-c7d8e9f0

Regulator Funding And CapacityAmber

No specific Romania-level funding/headcount figures for ANSPDCP were located in this research pass.

Collective Redress And Class ActionsAmber

No Romania-specific collective-redress or class-action mechanism for data protection claims distinct from GDPR Article 80 representative-action provisions was identified in this research pass.

Private Right Of ActionGreen

Private right of action follows GDPR Articles 79 and 82 directly (judicial remedy and compensation); the Bărbulescu case illustrates individual recourse to the ECHR for a Romanian workplace-monitoring dispute, evidencing an operative multi-forum redress landscape.

Claims: CLM-RO-d8e9f0a1

Recent Developments 180DAmber

Within the last 180 days, ANSPDCP issued fines against an individual for GDPR violations (30 January 2026, RON 50,890) and against Continental Automotive Products SRL (19 January 2026, RON 76,366) for a medical-data breach; at EU level, the EDPB published its 2025 Annual Report (9 April 2026) reporting €1.15bn in aggregate EU DPA fines for 2025, and the Commission continued negotiating a Digital Omnibus delaying/adjusting EU AI Act high-risk timelines relevant to Romanian AI deployers.

Claims: CLM-RO-b6c7d8e9, CLM-RO-c7d8e9f0, CLM-RO-e9f0a1b2

Category narrative113 words

ANSPDCP actively exercises GDPR Article 58 investigative and corrective powers and Article 83 fining powers; recent 2026 decisions include fines against an individual website operator (RON 50,890) and Continental Automotive Products SRL (RON 76,366) for data-breach-related violations, continuing a pattern of enforcement seen in earlier UiPath SRL (€70,000), Hora Credit IFN and Association of Owners cases. EU-level context: EDPB reported that in 2025 EU DPAs collectively issued approximately €1.15 billion in fines, with 414 cross-border cases and 572 final One-Stop-Shop decisions, reflecting the cooperative enforcement architecture Romania participates in via Article 60 GDPR. No Romania-specific collective-redress mechanism or private right of action distinct from GDPR Articles 79-82 was identified in this research pass.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedEDPBANSPDCP applies corrective measures under GDPR Article 58(2) and administrative fines under GDPR Article 83, procedurally implemented through Law No. 190/2018 Article 12 and Law No. 102/2005 Article 16 (including paragraphs (3), (5), (6) and (7) governing sanctions imposed by decision of the ANSPDCP president in cross-border cases).
  2. ConfirmedDataGuidanceOn 30 January 2026, ANSPDCP fined an individual RON 50,890 (approx. €10,000) for GDPR violations including publishing identity cards online and failing to respond to a data-deletion request.
  3. ConfirmedDataGuidanceOn 19 January 2026, ANSPDCP fined Continental Automotive Products SRL RON 76,366 (approx. €15,000) for GDPR violations of Articles 32(1)(b) and 32(2) following a data-breach notification involving employees' medical data.
  4. ConfirmedIAPPA Romanian employee successfully pursued an individual complaint to the European Court of Human Rights (Bărbulescu v. Romania) after domestic courts failed to strike an appropriate balance between his privacy rights and his employer's business interests, illustrating the multi-forum redress avenues (domestic courts, ANSPDCP, ECHR) available to Romanian data subjects.
  5. ConfirmedEDPBThe EDPB's 2025 Annual Report, published 9 April 2026, reported that EU national DPAs collectively issued approximately €1.15 billion in fines during 2025, with 414 cross-border cases created and 572 final One-Stop-Shop decisions under Article 60 GDPR — the cooperative framework in which ANSPDCP participates.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Romania
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 29 claim(s), 17 source(s) in the cumulative register.