EnglishRO
Romania flag

Romania

Romania Data Privacy Laws: GDPR, Law 190/2018 and ANSPDCP Guide (2026)

By Recording Law Editorial TeamReviewed May 20, 202618 min read
Romania Data Privacy Laws: GDPR, Law 190/2018 and ANSPDCP Guide (2026)

Frequently Asked Questions

When did Romania's GDPR implementing law take effect?

Law No. 190/2018 was published in Romania's Official Gazette on 26 July 2018 and became applicable on 31 July 2018, making Romania one of the first EU member states to enact GDPR implementing legislation. The law supplements the GDPR with national rules on biometric data, employee monitoring, national identification numbers, and the public-authority sanctions procedure.

What is the ANSPDCP and what powers does it have?

The ANSPDCP (Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal) is Romania's independent data protection authority. It can investigate controllers and processors, handle complaints, conduct audits, impose administrative fines, restrict or ban processing, and order data erasure. Between 2019 and 2023 it issued 235 GDPR fines, and courts confirmed its decisions in 23 out of 28 finalised challenges.

Can Romanian employers use security cameras to monitor employees?

No. Under Article 5 of Law 190/2018, CCTV installed for building security or public-space monitoring cannot be repurposed to monitor employee work performance. Electronic workplace surveillance is only permitted with advance notice to employees, a proportionate purpose, and a lawful basis under the GDPR and national law.

How are public authorities fined for GDPR violations in Romania?

Romanian public authorities must first receive a written warning with a remedy plan. Only if they fail to implement the remedy within ten days of the deadline can the ANSPDCP impose a fine. Fines are capped at RON 200,000, approximately EUR 40,000, far below the GDPR standard maximum. However, the ANSPDCP can also order processing restrictions and data deletion, which are not subject to the cap.

When must a DPO be appointed in Romania?

The standard GDPR DPO triggers apply: public authorities, large-scale systematic monitoring, and large-scale special-category processing. Law 190/2018 adds a national trigger: a DPO must also be designated when a private-sector controller processes the national identification number (CNP) under the legitimate-interest basis, including by collecting or disclosing documents that contain the CNP.

Can employers use fingerprint or facial recognition for building access in Romania?

Not without a proper legal basis. The ANSPDCP has confirmed that the building access purpose alone does not justify biometric data processing. Employers need either explicit legal authorization from a Romanian law providing adequate data protection safeguards, or explicit consent from each employee and visitor. Many organizations have shifted to key-card or PIN-based access to avoid this requirement.

What is the age of digital consent in Romania?

Romania set the age of digital consent at 16, adopting the GDPR's default. Children under 16 need verifiable parental or guardian consent to use information society services such as social media, online gaming platforms, and digital subscriptions.

How does the EU AI Act apply in Romania?

The EU AI Act applies directly in Romania as EU regulation. Prohibited AI practices have been enforceable since 2 February 2025. Romania designated the ANSPDCP as one of nine fundamental-rights monitoring authorities for high-risk AI systems, but as of mid-2025 had not yet designated a single national market-surveillance authority, missing the August 2025 EU deadline. AI systems that process personal data must comply with both the AI Act and the GDPR simultaneously.

Updates

Expanded to full coverage: constitutional basis, DPO requirements, legal bases, special categories, breach notification, cross-border transfers, EU AI Act overlay, NIS2/Law 124/2025, and 2024-2025 ANSPDCP enforcement actions including Orange Romania and Untold SRL. Word count expanded from 2,280 to approximately 6,400 words.

Sources and References

  1. ANSPDCP Law 190/2018 Official Text(dataprotection.ro).gov
  2. ANSPDCP Official Website(dataprotection.ro).gov
  3. EDPB UiPath Fine 2023(edpb.europa.eu).gov
  4. EDPB UniCredit Bank Fine 2019(edpb.europa.eu).gov
  5. ANSPDCP Orange Romania Sanction(dataprotection.ro).gov
  6. GDPRhub Orange Romania(gdprhub.eu)
  7. GDPRhub Untold SRL(gdprhub.eu)
  8. Romania Insider Georgescu Fine(romania-insider.com)
  9. CMS Romania Data Protection Guide(cms.law)
  10. DLA Piper Romania(dlapiperdataprotection.com)
  11. EuroCloud Romania AI Act(eurocloud.org)
  12. Kinstellar Romania NIS2(kinstellar.com)
  13. EDPB International Transfers Guide(edpb.europa.eu).gov
Share: