ROschema gdpri-v2trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC
Last updated · 10 categories · 29
claims · 26 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
29Claimsbaseline..claims[]
13Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
No categories are currently flagged red.
Jurisdiction brief
Standing brief, as of 23 August 2026.
Lead Signal
Continental Automotive Products SRL was fined RON 76,336, approximately EUR 15,000, by ANSPDCP for violations of GDPR Articles 32(1)(b) and 32(2), following a data breach involving employees' medical data. The investigation that produced this fine was triggered by the controller's own breach notification under Law 363/2018's 72-hour reporting rule, meaning the enforcement action originated from the controller's compliance with its notification duty rather than from an external complaint or a regulator-initiated inspection. The fine, dated 19 January 2026 and reported this cycle, anchors the controller-processor-duties and enforcement signal for Romania, and sits alongside two further named enforcement actions that together define an active, moderate-intensity enforcement cycle.
Other Developments
Data subject rights enforcement. ANSPDCP's decision concerning the operator of evita-teparii.ro reaffirmed deletion-request and Article 12 information obligations, applying even to a natural-person-operated website rather than only to conventional corporate controllers. The investigation, closed in early 2026 and reported in May 2026, resulted in four separate administrative fines together with three Article 58(2) corrective measures, indicating that ANSPDCP is willing to pursue a full enforcement stack against a small or informal operator rather than limiting enforcement intensity to larger corporate targets.
Algorithmic governance horizon. The EU AI Act's high-risk-system obligations, including AML and fraud-detection tools falling under Annex III, become fully applicable from 2 August 2026. This creates an approaching compliance intersection for Romanian financial-sector data processing, which already operates under GDPR Article 32 security obligations; from the applicability date, financial-sector controllers deploying AML or fraud-detection tooling classified as high-risk will need to satisfy AI Act risk-assessment and governance duties layered on top of their existing data-protection security obligations.
Further enforcement activity. Roumasport was fined EUR 10,000 for a GDPR breach, reported 20 April 2026, adding a third named enforcement action to this cycle's record alongside Continental Automotive Products and the evita-teparii.ro operator, and reinforcing the read of a sustained rather than escalating enforcement tempo.
Cross-Monitor Connections
The EU AI Act's approaching full-applicability date for high-risk AML and fraud-detection systems intersects directly with obligations tracked by the Financial Integrity Monitor: Annex III high-risk systems used for anti-money-laundering purposes will need to satisfy both AI Act risk-assessment duties and existing AML/CFT control requirements from the same 2 August 2026 compliance date, creating a compounding burden for the same class of Romanian financial-sector controllers. No adtech, cross-border-transfer, or World Payments Monitor-relevant development surfaced on the data-protection side this cycle to connect further.
Outlook
Romania's enforcement posture this cycle reads as active but moderate: three named actions, against Continental Automotive Products, the evita-teparii.ro operator, and Roumasport, sit within GDPR's statutory fine range rather than approaching its maxima, suggesting a sustained rather than escalating regulatory environment. The clearer horizon marker for the coming cycle is 2 August 2026, when EU AI Act high-risk obligations for AML and fraud-detection systems become fully applicable; how Romanian financial-sector controllers absorb this compounding compliance burden alongside their existing GDPR Article 32 duties will be the key development to watch.
trust tier: ai_unverified
Standing brief, as of 23 August 2026.
Regulatory Status
Romania's data-protection enforcement environment this cycle is active but moderate: three named ANSPDCP actions (Continental Automotive Products, the evita-teparii.ro operator, and Roumasport) span controller/processor duties (GDPR Article 32 security violations following a self-reported breach) and data subject rights (deletion-request and Article 12 obligations applied even to a natural-person operator, with a full stack of fines plus Article 58(2) corrective measures). Separately, the EU AI Act's high-risk-system obligations for AML and fraud-detection tools under Annex III become fully applicable from 2 August 2026, creating an approaching compliance intersection with Romanian financial-sector data processing already governed by GDPR Article 32.
Outlook
The key markers for the coming cycle are whether ANSPDCP's enforcement tempo remains moderate or escalates, and how Romanian financial-sector controllers absorb the EU AI Act's 2 August 2026 high-risk obligations for AML and fraud-detection systems alongside their existing GDPR security duties.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Traffic-light rationale — GreenFully operational GDPR-aligned regime with an active, resourced DPA and a national implementing statute in force since 2018.
Sub-modules (5)
Regulator And AuthorityGreen
ANSPDCP is the single national competent authority for GDPR matters in Romania, operating under Law No. 102/2005 (organisational statute) and Law No. 190/2018 (GDPR implementation).
Claims (1):
The National Supervisory Authority for Personal Data Processing (ANSPDCP) is the competent supervisory authority for data protection matters in Romania under Law No. 190/2018.
Act And InstrumentsGreen
The operative instruments are the GDPR itself and the national implementing Law No. 190/2018.
Claims (1):
Romania implemented the GDPR through Law No. 190/2018 Implementing the General Data Protection Regulation (Regulation (EU) 2016/679).
Material ScopeGreen
Material scope follows GDPR Art 2/4 directly; Law 190/2018 adds detailed rules for journalistic, academic, artistic and literary expression processing.
Claims (1):
Law No. 190/2018 is relatively comprehensive and includes detailed provisions on the processing of data for journalistic purposes or academic or artistic expression, on certification bodies, and on corrective measures and sanctions for both private and public bodies.
Territorial ScopeGreen
Territorial scope follows GDPR Art 3 directly (establishment + targeting tests); no Romania-specific narrowing or broadening identified.
Claims (1):
Territorial scope of the Romanian regime tracks GDPR Article 3 directly, applying to controllers/processors established in Romania and, via the targeting test, to non-established controllers processing data of subjects in Romania.
Registration And FilingGreen
Romania abolished the pre-GDPR general notification/registration obligation; ANSPDCP issued a public statement confirming elimination of the notification duty, consistent with GDPR's accountability-based model (Recital 89).
Claims (1):
ANSPDCP issued a statement on the elimination of the obligation to notify data processing operations, consistent with the GDPR's shift away from ex-ante registration toward accountability-based compliance (Recital 89, Articles 36-37 GDPR).
Category narrative60 words
Romania implements the GDPR through Law No. 190/2018 Implementing the General Data Protection Regulation, with the National Supervisory Authority for Personal Data Processing (ANSPDCP) as the competent supervisory authority. The regime is a fully-operational EU Member State omnibus regime; Romania did not enact a broad derogation architecture beyond the sector-specific carve-outs (journalism/academic/artistic expression, certification bodies) permitted by GDPR opening clauses.
no periodic updates on record for this sub-brief
Sources and claims (5)
ConfirmedDataGuidance — The National Supervisory Authority for Personal Data Processing (ANSPDCP) is the competent supervisory authority for data protection matters in Romania under Law No. 190/2018.observed
ConfirmedDataGuidance — Romania implemented the GDPR through Law No. 190/2018 Implementing the General Data Protection Regulation (Regulation (EU) 2016/679).observed
ConfirmedDataGuidance — Law No. 190/2018 is relatively comprehensive and includes detailed provisions on the processing of data for journalistic purposes or academic or artistic expression, on certification bodies, and on corrective measures and sanctions for both private and public bodies.observed
ProbableEUR-Lex — Territorial scope of the Romanian regime tracks GDPR Article 3 directly, applying to controllers/processors established in Romania and, via the targeting test, to non-established controllers processing data of subjects in Romania.observed
ConfirmedDataGuidance — ANSPDCP issued a statement on the elimination of the obligation to notify data processing operations, consistent with the GDPR's shift away from ex-ante registration toward accountability-based compliance (Recital 89, Articles 36-37 GDPR).observed
Traffic-light rationale — GreenDirect GDPR application with CJEU-clarified consent standard originating from a Romanian reference.
Sub-modules (4)
Lawful BasesGreen
The six GDPR Article 6 lawful bases apply directly in Romania without a national supplementary list.
Claims (1):
Data controllers in Romania must rely on lawfulness under GDPR Article 6(1)(a)-(f) as the exhaustive set of lawful bases for processing personal data.
Consent ThresholdsAmber
The CJEU, on a reference from the Tribunalul București, held in Orange România (C-61/19) that a pre-ticked box or contract signature alone does not establish valid consent absent an active, unambiguous indication of wishes and that the burden of proving valid consent lies with the controller.
Claims (1):
In a reference from the Tribunalul București concerning collection and storage of identity-document copies by a mobile telecoms provider, the CJEU examined whether a tick-box declaration and contract signature satisfy the GDPR/Directive 95/46 consent standard, and addressed the burden of proof for valid consent.
Special CategoriesGreen
Special categories follow GDPR Article 9 directly; ANSPDCP enforcement practice (e.g., health-data breach fines) confirms active application of the Art 9 regime to employee medical data.
Claims (1):
ANSPDCP fined Continental Automotive Products SRL after an Excel file containing employees' medical data (special-category data under GDPR Article 9) was repeatedly distributed internally without adequate technical and organisational measures.
Pseudonymisation And AnonymisationAmber
No Romania-specific statutory safe harbour beyond GDPR Articles 4(5) and 25/32 was identified; EDPB-level guidance on pseudonymisation (under public consultation in 2025) is the applicable reference framework absent national supplementation.
Category narrative51 words
Romania applies the GDPR's Article 6 lawful bases and Article 9 special-category regime directly, with Law 190/2018 not materially derogating from the EU baseline on consent standards. National case law referred to the CJEU (Orange România) clarified the standard for valid, freely-given, specific and informed consent in a Romanian telecoms context.
no periodic updates on record for this sub-brief
Sources and claims (3)
ConfirmedEDPB — Data controllers in Romania must rely on lawfulness under GDPR Article 6(1)(a)-(f) as the exhaustive set of lawful bases for processing personal data.observed
ConfirmedEUR-Lex — In a reference from the Tribunalul București concerning collection and storage of identity-document copies by a mobile telecoms provider, the CJEU examined whether a tick-box declaration and contract signature satisfy the GDPR/Directive 95/46 consent standard, and addressed the burden of proof for valid consent.observed
ConfirmedDataGuidance — ANSPDCP fined Continental Automotive Products SRL after an Excel file containing employees' medical data (special-category data under GDPR Article 9) was repeatedly distributed internally without adequate technical and organisational measures.observed
Traffic-light rationale — GreenRights framework mirrors GDPR baseline; enforcement record shows the regulator actively polices non-compliance with erasure and access obligations.
Sub-modules (5)
Access RightGreen
Access right follows GDPR Article 15 directly; no national supplementary access regime identified.
Rectification And ErasureAmber
ANSPDCP sanctioned an individual for, among other violations, failing to respond to a data-subject erasure request under GDPR Article 17(1) after identity cards were published online.
Claims (1):
ANSPDCP fined an individual RON 50,890 for, inter alia, violating GDPR Article 17(1) by failing to respond to a request to delete personal data, in addition to publishing identity cards online without a legal basis.
Restriction And ObjectionAmber
Restriction/objection rights follow GDPR Articles 18/21 directly; no Romania-specific case identified in this research pass.
Data PortabilityAmber
Portability follows GDPR Article 20 directly; no Romania-specific derogation or guidance identified in this research pass.
Deadlines And Response WindowsGreen
Response deadlines follow the GDPR Article 12(3) one-month default (extendable by two further months for complex requests); no Romania-specific shortening/lengthening identified.
Claims (1):
The individual sanctioned by ANSPDCP was found to have breached GDPR Article 12(3)-12(4) transparency and response-timeliness obligations toward data subjects.
Category narrative47 words
Data subject rights (access, rectification, erasure, restriction, objection, portability) apply per GDPR Articles 15-22 with no Romania-specific derogations identified in Law 190/2018 beyond the general journalistic/academic/artistic exemptions. ANSPDCP enforcement actions confirm active supervision of erasure-request compliance (e.g., the evita-teparii.ro case for failure to honour a deletion request).
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (2)
ConfirmedDataGuidance — ANSPDCP fined an individual RON 50,890 for, inter alia, violating GDPR Article 17(1) by failing to respond to a request to delete personal data, in addition to publishing identity cards online without a legal basis.observed
ConfirmedDataGuidance — The individual sanctioned by ANSPDCP was found to have breached GDPR Article 12(3)-12(4) transparency and response-timeliness obligations toward data subjects.observed
Framework is GDPR-aligned (green in principle) but repeated enforcement findings of Article 32/33 non-compliance among controllers warrant an amber operational rating.
Traffic-light rationale — AmberFramework is GDPR-aligned (green in principle) but repeated enforcement findings of Article 32/33 non-compliance among controllers warrant an amber operational rating.
Sub-modules (7)
Accountability And DpiaGreen
ANSPDCP recommends DPIAs and ROPA maintenance in sector guidance (e.g., 2024 election-processing recommendations invoking GDPR Articles 5, 6 and 9 plus a DPIA duty for political-entity controllers).
Claims (1):
ANSPDCP's October 2024 election-processing recommendations require political entities acting as controllers under GDPR Article 4(7) to conduct a Data Protection Impact Assessment and maintain records of processing activities.
Dpo RequirementsGreen
DPO appointment thresholds follow GDPR Articles 37-39 directly; Romania's election guidance explicitly reminds political-entity controllers to appoint a DPO where required.
Claims (1):
ANSPDCP guidance reminds political-entity controllers processing personal data during elections to appoint a Data Protection Officer where the GDPR Article 37 threshold is met.
Ropa RequirementsGreen
ROPA duties follow GDPR Article 30 directly; ANSPDCP guidance for electoral-processing controllers explicitly requires maintenance of records of processing activities.
Claims (1):
ANSPDCP guidance requires organisations processing personal data during elections to maintain records of data processing activities consistent with GDPR Article 30.
Joint Controller ArrangementsAmber
Joint-controller allocation follows GDPR Article 26 directly; no Romania-specific supplementary rule identified in this research pass.
Security MeasuresAmber
ANSPDCP found Hora Credit IFN and Continental Automotive Products to have failed to implement appropriate technical and organisational security measures under GDPR Articles 25 and 32.
Claims (1):
ANSPDCP found that Hora Credit IFN S.A. did not take sufficient security measures for personal data, according to Articles 25 and 32 of the GDPR, so as to avoid unauthorised disclosure of personal data to third parties.
Breach NotificationAmber
Breach notification follows GDPR Article 33's 72-hour rule; ANSPDCP has separately fined a controller for failing to notify a security incident within 72 hours, and has opened investigations directly from breach notifications submitted by controllers (Continental, UiPath).
Claims (1):
ANSPDCP fined Hora Credit IFN S.A. for failing to notify the supervisory authority of a security incident within 72 hours from the date it became aware of it, per GDPR Article 33.
Retention And DisposalAmber
Retention/disposal follows GDPR Article 5(1)(e) storage-limitation principle directly; no Romania-specific statutory retention schedule beyond sectoral rules was identified in this research pass.
Category narrative56 words
Accountability, DPIA, security-of-processing, breach notification and retention duties in Romania follow GDPR Articles 5, 24-25, 30, 32-35 directly. ANSPDCP's enforcement docket (Hora Credit IFN, Continental Automotive, UiPath) repeatedly cites Articles 25, 32 and 33, confirming active supervision of security measures and the 72-hour breach-notification duty; failure to notify within 72 hours has itself been separately sanctioned.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (5)
ConfirmedDataGuidance — ANSPDCP's October 2024 election-processing recommendations require political entities acting as controllers under GDPR Article 4(7) to conduct a Data Protection Impact Assessment and maintain records of processing activities.observed
ProbableDataGuidance — ANSPDCP guidance reminds political-entity controllers processing personal data during elections to appoint a Data Protection Officer where the GDPR Article 37 threshold is met.observed
ProbableDataGuidance — ANSPDCP guidance requires organisations processing personal data during elections to maintain records of data processing activities consistent with GDPR Article 30.observed
ConfirmedEDPB — ANSPDCP found that Hora Credit IFN S.A. did not take sufficient security measures for personal data, according to Articles 25 and 32 of the GDPR, so as to avoid unauthorised disclosure of personal data to third parties.observed
ConfirmedEDPB — ANSPDCP fined Hora Credit IFN S.A. for failing to notify the supervisory authority of a security incident within 72 hours from the date it became aware of it, per GDPR Article 33.observed
Traffic-light rationale — GreenTransfer mechanisms are the harmonised EU-wide GDPR Chapter V toolkit; no Romania-specific localisation mandate identified.
Sub-modules (6)
Transfer MechanismsGreen
Transfer mechanisms (adequacy, SCCs, BCRs, Article 49 derogations) are the standard EU-wide GDPR Chapter V toolkit; no Romania-specific instrument identified.
Claims (1):
ANSPDCP cooperated as lead supervisory authority under Article 60 GDPR one-stop-shop with the German Land of North Rhine-Westphalia's data protection authority (and consulted France, Denmark and Spain) in a cross-border case against Microstockr SRL, a Romania-based controller.
Adequacy ReceivedGreen
Adequacy decisions are adopted by the European Commission for the EU as a whole; Romania does not receive or grant adequacy independently as an EU Member State.
Claims (1):
As an EU Member State, Romania is bound by European Commission adequacy decisions adopted under GDPR Article 45 for the EU as a whole rather than adopting independent national adequacy findings.
Adequacy GrantedGreen
Same as adequacy_received — adequacy is an EU-level competence, not exercised individually by Romania.
Sccs And BcrsGreen
ANSPDCP applies the EU Standard Contractual Clauses and BCR framework as adopted at EU level; no Romania-specific SCC variant identified.
Transfer Impact AssessmentAmber
TIA obligations follow the EDPB's EU-wide post-Schrems II guidance; no Romania-specific TIA supplementary requirement identified.
Data LocalisationGreen
No general data-localisation mandate identified for Romania beyond sector-specific retention/record-keeping rules under national law.
Category narrative72 words
As an EU Member State, Romania does not operate an independent adequacy regime; cross-border transfer mechanisms (adequacy decisions, SCCs, BCRs, derogations) are governed exclusively at EU level under GDPR Chapter V and apply uniformly in Romania. ANSPDCP participates in EU one-stop-shop cross-border cooperation (Article 60 GDPR), as demonstrated in the UiPath and Microstockr cases where ANSPDCP acted as lead or cooperating authority with other EU DPAs (Germany's NRW authority, France, Denmark, Spain).
no periodic updates on record for this sub-brief
Sources and claims (2)
ConfirmedEDPB — ANSPDCP cooperated as lead supervisory authority under Article 60 GDPR one-stop-shop with the German Land of North Rhine-Westphalia's data protection authority (and consulted France, Denmark and Spain) in a cross-border case against Microstockr SRL, a Romania-based controller.observed
ConfirmedEUR-Lex — As an EU Member State, Romania is bound by European Commission adequacy decisions adopted under GDPR Article 45 for the EU as a whole rather than adopting independent national adequacy findings.observed
Financial and employment overlays are evidenced by case law/enforcement; health, education, telecoms-specific and insurance overlays were not separately confirmed in this pass and are marked absent.
Primary frameworkGDPR (general); ECHR Article 8 (employment monitoring, via Bărbulescu); Law No. 190/2018
Traffic-light rationale — AmberFinancial and employment overlays are evidenced by case law/enforcement; health, education, telecoms-specific and insurance overlays were not separately confirmed in this pass and are marked absent.
Sub-modules (7)
Financial Sector OverlayAmber
ANSPDCP sanctioned non-bank lender Hora Credit IFN S.A. for GDPR violations in loan-agreement data processing, including insufficient security measures and late breach notification.
Claims (1):
ANSPDCP sanctioned non-bank lender Hora Credit IFN S.A. for GDPR violations in the collection and processing of personal data for concluding and executing consumer loan agreements, including insufficient security measures and a 72-hour breach-notification failure.
Health Sector OverlayAmber
No dedicated Romanian health-sector DP statute was identified in this pass; health-data breaches (e.g., Continental Automotive medical-data case) are handled under general GDPR Article 9 rules rather than a distinct sectoral instrument.
Telecoms And EprivacyGreen
ePrivacy/cookie rules in Romania are implemented via Law No. 506/2004 (transposing Directive 2002/58/EC), enforced by ANSPDCP alongside GDPR consent standards, as seen in the Microstockr cookie-consent decision.
Claims (1):
Romania's ePrivacy cookie-consent obligation under Article 5(3) of Directive 2002/58/EC is transposed by Law No. 506/2004 and enforced by ANSPDCP with a consent standard aligned to GDPR Articles 4(11) and 6(1)(a).
Employment DataAmber
The ECHR Grand Chamber's Bărbulescu v. Romania judgment establishes that Romanian and EU law require employers to give employees prior notice of the nature and extent of monitoring before accessing their communications.
Claims (1):
The ECHR Grand Chamber, in Bărbulescu v. Romania, held that an employer's monitoring of an employee's electronic communications was unlawful because the employer did not give the employee prior notice of the nature and extent of the monitoring, aligning Romanian workplace-monitoring practice with Council of Europe, Romanian and EU law transparency requirements.
Credit And ScoringAmber
No dedicated Romanian credit-scoring statute distinct from GDPR Article 22 was identified; the Hora Credit IFN case concerned general processing compliance rather than automated credit-scoring specifically.
EducationAmber
No dedicated Romanian education-sector DP overlay was identified in this research pass.
InsuranceAmber
No dedicated Romanian insurance-sector DP overlay was identified in this research pass.
Category narrative63 words
Sectoral overlays identified in Romania include financial-sector consumer-credit processing (Hora Credit IFN, an IFN/non-bank lender, sanctioned under GDPR for loan-processing data handling) and employment/workplace-monitoring rules shaped by the Grand Chamber ECHR Bărbulescu v. Romania judgment, which imposes transparency conditions on employer monitoring of employee communications. No dedicated Romanian health-sector, education-sector, or insurance-sector DP statute distinct from GDPR was identified in this research pass.
no periodic updates on record for this sub-brief
Sources and claims (3)
ConfirmedEDPB — ANSPDCP sanctioned non-bank lender Hora Credit IFN S.A. for GDPR violations in the collection and processing of personal data for concluding and executing consumer loan agreements, including insufficient security measures and a 72-hour breach-notification failure.observed
ConfirmedEDPB — Romania's ePrivacy cookie-consent obligation under Article 5(3) of Directive 2002/58/EC is transposed by Law No. 506/2004 and enforced by ANSPDCP with a consent standard aligned to GDPR Articles 4(11) and 6(1)(a).observed
ConfirmedIAPP — The ECHR Grand Chamber, in Bărbulescu v. Romania, held that an employer's monitoring of an employee's electronic communications was unlawful because the employer did not give the employee prior notice of the nature and extent of the monitoring, aligning Romanian workplace-monitoring practice with Council of Europe, Romanian and EU law transparency requirements.observed
Cookie-consent enforcement is confirmed and active; dark patterns, opt-out signal recognition, clean-room rules and cross-context advertising lack confirmed Romania-specific findings in this pass.
Primary frameworkDirective 2002/58/EC as transposed by Law No. 506/2004; GDPR
Traffic-light rationale — AmberCookie-consent enforcement is confirmed and active; dark patterns, opt-out signal recognition, clean-room rules and cross-context advertising lack confirmed Romania-specific findings in this pass.
Sub-modules (6)
Cookies And TrackersAmber
ANSPDCP enforced the active-consent cookie standard against Microstockr SRL, finding that consent obtained via pre-existing account/contract mechanisms did not meet the 'free, specific, informed and unambiguous' standard required for storing/accessing information on user terminal equipment.
Claims (1):
ANSPDCP found that Microstockr SRL failed to obtain valid cookie consent under Article 5(3) of Directive 2002/58/EC (as transposed by Law No. 506/2004) because the consent mechanism did not constitute a free, specific, informed and unambiguous active indication of the user's wishes.
Dark PatternsAmber
No dedicated Romanian dark-patterns prohibition distinct from GDPR/DSA fair-processing principles was identified in this research pass.
Opt Out SignalsAmber
No Romania-specific recognition mandate for Global Privacy Control or DAA-style opt-out signals was identified in this research pass.
Clean Rooms And DcrAmber
No Romania-specific clean-room or data-collaboration-room regulatory framework was identified in this research pass.
Cross Context AdvertisingAmber
Cross-context advertising in Romania is governed by the general GDPR consent/legitimate-interest framework; no Romania-specific 'sale'/'share' concept analogous to US state law was identified.
Direct MarketingAmber
Direct marketing consent/suppression follows the ePrivacy opt-in standard under Law No. 506/2004 and GDPR Article 21(3) objection rights; no additional Romania-specific suppression registry was identified in this research pass.
Category narrative51 words
Cookie/tracker consent in Romania follows the ePrivacy Directive as transposed by Law No. 506/2004, enforced by ANSPDCP with the same GDPR-aligned active-consent standard applied in the Microstockr decision (rejecting pre-ticked or passive consent mechanisms). No Romania-specific dark-patterns statute, clean-room regime, or GPC/DAA opt-out-signal mandate distinct from EU-wide DSA/GDPR frameworks was identified.
no periodic updates on record for this sub-brief
Sources and claims (1)
ConfirmedEDPB — ANSPDCP found that Microstockr SRL failed to obtain valid cookie consent under Article 5(3) of Directive 2002/58/EC (as transposed by Law No. 506/2004) because the consent mechanism did not constitute a free, specific, informed and unambiguous active indication of the user's wishes.observed
Governed by directly-applicable EU-level AI Act/GDPR; amber reflects genuine EU-wide uncertainty over high-risk AI Act timelines and guidance that also affects Romanian deployers/providers.
Primary frameworkGDPR Article 22; Regulation (EU) 2024/1689 (EU AI Act)
Traffic-light rationale — AmberGoverned by directly-applicable EU-level AI Act/GDPR; amber reflects genuine EU-wide uncertainty over high-risk AI Act timelines and guidance that also affects Romanian deployers/providers.
Sub-modules (6)
Profiling RestrictionsGreen
Profiling restrictions follow GDPR Article 22 directly; no Romania-specific expansion or narrowing identified.
The EU AI Act's high-risk system obligations (Chapter III, Annex III — covering biometrics, employment, education, law enforcement) apply directly in Romania; however, the general application date of 2 August 2026 for high-risk rules is subject to a pending Commission Digital Omnibus proposal to adjust timelines linked to the availability of harmonised standards and Commission guidance.
Claims (1):
The EU AI Act's obligations for high-risk AI systems (Annex III, including biometrics, education, employment and law enforcement use cases) were due to apply from 2 August 2026, but delayed availability of harmonised standards, common specifications and Commission guidance, along with delayed designation of national competent authorities, has led to a Commission proposal to link entry into application to the availability of supporting compliance measures.
Biometric RegimeAmber
Biometric data processing is governed by GDPR Article 9(1) (biometric data for unique identification as a special category) and, from August 2026, EU AI Act Annex III high-risk rules for biometric identification/categorisation systems; no Romania-specific biometric statute was identified.
Genetic DataAmber
Genetic data is a GDPR Article 9(1) special category; no Romania-specific genetic-data statute was identified in this research pass.
State Surveillance CarveoutsAmber
National-security/state-surveillance carve-outs follow the general GDPR Article 2(2)(d)/23 framework; no Romania-specific surveillance statute was identified in this research pass.
Category narrative88 words
Profiling/ADM restrictions in Romania follow GDPR Article 22 directly. The EU AI Act (Regulation (EU) 2024/1689) applies uniformly in Romania as a directly-applicable EU regulation; its high-risk-system obligations (covering biometrics, employment, education and law enforcement use cases under Annex III) were originally due to enter application on 2 August 2026, but a Commission Digital Omnibus proposal is under negotiation to delay/adjust that timeline pending finalisation of Commission guidance on high-risk classification. No Romania-specific biometric or state-surveillance carve-out statute distinct from GDPR/AI Act was identified in this research pass.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (1)
ProbableEDPB/EDPS — The EU AI Act's obligations for high-risk AI systems (Annex III, including biometrics, education, employment and law enforcement use cases) were due to apply from 2 August 2026, but delayed availability of harmonised standards, common specifications and Commission guidance, along with delayed designation of national competent authorities, has led to a Commission proposal to link entry into application to the availability of supporting compliance measures.observed
Traffic-light rationale — AmberAge-of-consent position for Romania could not be confirmed against primary text in this pass; treated as open/Probable rather than silently assumed.
Sub-modules (5)
Age VerificationAmber
GDPR Article 8 permits Member States to set the digital age of consent between 13 and 16; this research pass could not confirm from primary text whether Romania set a national derogation below the 16-year default.
Claims (1):
GDPR Article 8 sets the default digital age of consent for information-society services at 16, allowing Member States to lower it by national law to not below 13; a Romania-specific statutory derogation could not be confirmed in this research pass.
Parental ConsentAmber
Absent a confirmed derogation, the GDPR Article 8 default requires parental/guardian consent for information-society-service processing of children under 16 in Romania.
Claims (1):
Absent a confirmed national derogation, controllers offering information-society services directly to children in Romania must obtain parental/guardian consent for children below the GDPR Article 8 default age of 16.
Minor Profiling BansAmber
No dedicated Romanian minor-profiling ban distinct from GDPR Article 22/Recital 71 was identified in this research pass.
Education SettingsAmber
No dedicated Romanian education-sector children's-data statute was identified in this research pass.
Dependent AdultsAmber
No dedicated Romanian dependent-adults (elderly/incapacitated) data-protection statute distinct from GDPR general capacity/consent rules was identified in this research pass.
Category narrative102 words
GDPR Article 8 sets the EU default digital age of consent at 16, with Member States permitted to lower it to no less than 13. This research pass did not locate a definitive, authoritative confirmation that Romania has enacted a statutory derogation lowering the age of consent below the GDPR default; Law No. 190/2018 summaries reviewed did not surface an explicit age-of-consent provision, so Romania's position is treated as Probable-default (16) rather than Confirmed pending direct verification of the Law 190/2018 text or ANSPDCP guidance. No dedicated Romanian minor-profiling ban, education-sector-specific DP rule, or dependent-adults DP statute distinct from GDPR was identified.
no periodic updates on record for this sub-brief
Sources and claims (2)
UncertainIAPP — GDPR Article 8 sets the default digital age of consent for information-society services at 16, allowing Member States to lower it by national law to not below 13; a Romania-specific statutory derogation could not be confirmed in this research pass.observed
UncertainIAPP — Absent a confirmed national derogation, controllers offering information-society services directly to children in Romania must obtain parental/guardian consent for children below the GDPR Article 8 default age of 16.observed
Enforcement is active and evidenced by multiple 2026 decisions, but the regulator's absolute funding/headcount and any Romania-specific collective-redress mechanism could not be confirmed in this pass.
Primary frameworkGDPR Articles 58, 77-84; Law No. 190/2018 Article 12-16; Law No. 102/2005
Traffic-light rationale — AmberEnforcement is active and evidenced by multiple 2026 decisions, but the regulator's absolute funding/headcount and any Romania-specific collective-redress mechanism could not be confirmed in this pass.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
ANSPDCP exercises corrective and sanctioning powers under GDPR Article 58(2) and applies the Article 83 fining tiers via Law No. 190/2018 Article 12 and Law No. 102/2005 Article 16 procedural rules.
Claims (1):
ANSPDCP applies corrective measures under GDPR Article 58(2) and administrative fines under GDPR Article 83, procedurally implemented through Law No. 190/2018 Article 12 and Law No. 102/2005 Article 16 (including paragraphs (3), (5), (6) and (7) governing sanctions imposed by decision of the ANSPDCP president in cross-border cases).
Enforcement Activity IndexAmber
ANSPDCP issued at least two significant fines in January 2026 alone (an individual website operator for RON 50,890 and Continental Automotive Products SRL for RON 76,366), continuing an active multi-year enforcement pattern including a 2023 €70,000 fine against UiPath SRL.
Claims (2):
On 30 January 2026, ANSPDCP fined an individual RON 50,890 (approx. €10,000) for GDPR violations including publishing identity cards online and failing to respond to a data-deletion request.
On 19 January 2026, ANSPDCP fined Continental Automotive Products SRL RON 76,366 (approx. €15,000) for GDPR violations of Articles 32(1)(b) and 32(2) following a data-breach notification involving employees' medical data.
Regulator Funding And CapacityAmber
No specific Romania-level funding/headcount figures for ANSPDCP were located in this research pass.
Collective Redress And Class ActionsAmber
No Romania-specific collective-redress or class-action mechanism for data protection claims distinct from GDPR Article 80 representative-action provisions was identified in this research pass.
Private Right Of ActionGreen
Private right of action follows GDPR Articles 79 and 82 directly (judicial remedy and compensation); the Bărbulescu case illustrates individual recourse to the ECHR for a Romanian workplace-monitoring dispute, evidencing an operative multi-forum redress landscape.
Claims (1):
A Romanian employee successfully pursued an individual complaint to the European Court of Human Rights (Bărbulescu v. Romania) after domestic courts failed to strike an appropriate balance between his privacy rights and his employer's business interests, illustrating the multi-forum redress avenues (domestic courts, ANSPDCP, ECHR) available to Romanian data subjects.
Recent Developments 180DAmber
Within the last 180 days, ANSPDCP issued fines against an individual for GDPR violations (30 January 2026, RON 50,890) and against Continental Automotive Products SRL (19 January 2026, RON 76,366) for a medical-data breach; at EU level, the EDPB published its 2025 Annual Report (9 April 2026) reporting €1.15bn in aggregate EU DPA fines for 2025, and the Commission continued negotiating a Digital Omnibus delaying/adjusting EU AI Act high-risk timelines relevant to Romanian AI deployers.
Claims (3):
On 30 January 2026, ANSPDCP fined an individual RON 50,890 (approx. €10,000) for GDPR violations including publishing identity cards online and failing to respond to a data-deletion request.
On 19 January 2026, ANSPDCP fined Continental Automotive Products SRL RON 76,366 (approx. €15,000) for GDPR violations of Articles 32(1)(b) and 32(2) following a data-breach notification involving employees' medical data.
The EDPB's 2025 Annual Report, published 9 April 2026, reported that EU national DPAs collectively issued approximately €1.15 billion in fines during 2025, with 414 cross-border cases created and 572 final One-Stop-Shop decisions under Article 60 GDPR — the cooperative framework in which ANSPDCP participates.
Category narrative113 words
ANSPDCP actively exercises GDPR Article 58 investigative and corrective powers and Article 83 fining powers; recent 2026 decisions include fines against an individual website operator (RON 50,890) and Continental Automotive Products SRL (RON 76,366) for data-breach-related violations, continuing a pattern of enforcement seen in earlier UiPath SRL (€70,000), Hora Credit IFN and Association of Owners cases. EU-level context: EDPB reported that in 2025 EU DPAs collectively issued approximately €1.15 billion in fines, with 414 cross-border cases and 572 final One-Stop-Shop decisions, reflecting the cooperative enforcement architecture Romania participates in via Article 60 GDPR. No Romania-specific collective-redress mechanism or private right of action distinct from GDPR Articles 79-82 was identified in this research pass.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (5)
ConfirmedEDPB — ANSPDCP applies corrective measures under GDPR Article 58(2) and administrative fines under GDPR Article 83, procedurally implemented through Law No. 190/2018 Article 12 and Law No. 102/2005 Article 16 (including paragraphs (3), (5), (6) and (7) governing sanctions imposed by decision of the ANSPDCP president in cross-border cases).observed
ConfirmedDataGuidance — On 30 January 2026, ANSPDCP fined an individual RON 50,890 (approx. €10,000) for GDPR violations including publishing identity cards online and failing to respond to a data-deletion request.observed
ConfirmedDataGuidance — On 19 January 2026, ANSPDCP fined Continental Automotive Products SRL RON 76,366 (approx. €15,000) for GDPR violations of Articles 32(1)(b) and 32(2) following a data-breach notification involving employees' medical data.observed
ConfirmedIAPP — A Romanian employee successfully pursued an individual complaint to the European Court of Human Rights (Bărbulescu v. Romania) after domestic courts failed to strike an appropriate balance between his privacy rights and his employer's business interests, illustrating the multi-forum redress avenues (domestic courts, ANSPDCP, ECHR) available to Romanian data subjects.observed
ConfirmedEDPB — The EDPB's 2025 Annual Report, published 9 April 2026, reported that EU national DPAs collectively issued approximately €1.15 billion in fines during 2025, with 414 cross-border cases created and 572 final One-Stop-Shop decisions under Article 60 GDPR — the cooperative framework in which ANSPDCP participates.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
No failing checks.
schema_valid
pass
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
pass
tier_a_b_national_primary_pct
55.56
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Romania
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 29 claim(s) (29 category placement(s)), 26 source(s) in the cumulative register.
All 10 modules populated with at least one claim except adtech_and_commercial_privacy sub-modules beyond cookies/trackers and children_and_vulnerable_groups beyond age/parental-consent, which carry absent_field_provenance narratives. T1 grounding (EDPB-republished ANSPDCP decisions, CJEU judgment, EU AI Act/omnibus texts, EDPB annual report) was obtained for regulator_and_framework, lawful_processing_and_special_data, controller_processor_duties, cross_border_and_adequacy, and enforcement_and_redress. sectoral_watch and adtech_and_commercial_privacy relied partly on T2/T3 secondary reporting (DataGuidance, IAPP) for enforcement narrative colour. children_and_vulnerable_groups age-of-consent position for Romania could not be verified against Law 190/2018 primary text in this pass and is flagged Uncertain with absent_field_provenance rather than assumed.
Unresolved questions (5):
Does Law No. 190/2018 set a national derogation for the GDPR Article 8 digital age of consent below 16, or does Romania apply the EU default of 16?
Are there Romania-specific health-sector, education-sector, or insurance-sector data protection overlays distinct from GDPR general rules?
What is ANSPDCP's current budget and headcount (regulator_funding_and_capacity)?
Is there a Romania-specific collective-redress/class-action mechanism for data protection claims beyond GDPR Article 80 representative actions?
Has Romania adopted any AI Act national-competent-authority designation or supplementary AI governance measure ahead of the 2 August 2026 high-risk application date?