A multinational expanding its customer operations into Romania discovers that its standard EU privacy notices, consent forms, and data-sharing agreements do not fully align with local enforcement expectations. The Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP. the Romanian Data Protection Authority) has intensified its investigation activity. Additionally. A single compliance gap can trigger administrative proceedings within weeks of a complaint being filed.
Data protection in Romania is governed by the General Data Protection Regulation (GDPR) as directly applicable EU law, supplemented by Romanian national data protection legislation that addresses specific derogations, enforcement powers, and sectoral rules. Every organisation established in Romania, or offering goods and services to Romanian data subjects, must appoint appropriate roles, implement technical and organisational measures, and maintain records of processing activities. The ANSPDCP may open an investigation and impose sanctions within a relatively short timeframe following a breach notification or third-party complaint.
This page sets out the core legal instruments, procedural requirements, common pitfalls, cross-border considerations, and a practical self-assessment checklist for international businesses managing data protection obligations in Romania.
The regulatory setting for data protection in Romania
Romania implemented the GDPR through a combination of directly applicable EU regulation and domestic legislation that fills the spaces the regulation deliberately left to member states. Romanian national data protection legislation addresses topics such as the minimum age for valid consent in digital services. Exemptions for journalistic and research purposes. Additionally, the powers of the ANSPDCP to conduct dawn raids and impose interim measures.
The ANSPDCP operates as the competent supervisory authority for organisations whose main establishment is in Romania, and as a concerned authority when a cross-border processing activity affects Romanian data subjects. The authority has formal cooperation obligations with other EU supervisory authorities under the one-stop-shop mechanism, but it retains full investigative autonomy for matters that are locally contained.
Under Romanian data protection legislation, organisations that meet certain thresholds – particularly those processing data at scale, processing special categories of data, or carrying out systematic monitoring – must designate a Data Protection Officer (DPO). The DPO must have expert knowledge of data protection law and be positioned within the organisation so as to report directly to senior management without conflicts of interest.
A key distinction that international clients frequently overlook is the difference between a data controller. the entity that determines the purposes and means of processing. and a data processor. the entity that processes data on behalf of the controller. Romanian enforcement practice treats this distinction as foundational. Mislabelling the relationship in a data processing agreement, or operating without a written agreement at all, is one of the most common triggers for ANSPDCP investigation.
For businesses with operations that also intersect with technology, artificial intelligence. Alternatively, automated decision-making. It is worth noting that the obligations arising under data protection law connect closely with obligations under the EU AI Act and related technology regulation. Our analysis of AI law in Romania addresses those overlapping compliance requirements in detail.
Core compliance instruments and procedural requirements
GDPR compliance in Romania rests on several interlocking instruments. Each requires careful drafting and ongoing maintenance – not a one-time implementation exercise.
Records of processing activities (ROPA) must be maintained by any controller or processor that does not fall within the narrow small-enterprise exemption. The ROPA must identify each processing activity, its legal basis, the categories of data and data subjects, the retention period, and the technical and organisational security measures applied. The ANSPDCP has requested ROPAs in the early stages of investigations as the primary diagnostic document. An incomplete or outdated ROPA signals systemic non-compliance to the authority.
Lawful basis mapping is the second foundational instrument. Under the GDPR, each processing activity requires a lawful basis: consent, contractual necessity, legal obligation, vital interests, public task, or legitimate interests. Romanian enforcement practice – consistent with guidance issued by the European Data Protection Board – treats consent as the most precarious basis for ongoing commercial processing. A consent mechanism that is not freely given, specific, informed, and unambiguous will not withstand scrutiny. Legitimate interests assessments, by contrast, offer more durable grounds for many commercial activities, provided the balancing test is genuinely documented.
Data processing agreements (DPAs) must be concluded with every processor engaged by a controller. Romanian businesses frequently engage cloud providers, payroll processors, marketing platforms, and IT service providers without formalising the processing relationship. The ANSPDCP treats the absence of a compliant DPA as an automatic breach. The agreement must specify the subject matter, duration, nature, and purpose of processing, and impose binding obligations on the processor regarding security, sub-processing, and assistance with data subject rights.
Data subject rights procedures must be operational before processing begins, not retrofitted after a complaint is received. Romanian data subjects have the right to access their data, rectify inaccurate data, erase data in defined circumstances, restrict processing, and port data in machine-readable format. Responses to access requests must be provided within one calendar month, with a two-month extension available for complex or numerous requests – provided the data subject is notified of the extension within the first month.
Data breach notification timelines are strict. A personal data breach must be notified to the ANSPDCP within 72 hours of the controller becoming aware of it, unless the breach is unlikely to result in a risk to individuals. Where the breach is likely to result in a high risk, affected data subjects must also be notified without undue delay. Many organisations underestimate what constitutes "becoming aware" – internal IT discovery logs have been used by the ANSPDCP to establish the moment of awareness and to evaluate whether the notification timeline was met.
Data Protection Impact Assessments (DPIAs) are mandatory before commencing any processing that is likely to result in a high risk to individuals. This includes large-scale processing of sensitive data, systematic profiling, and use of new technologies. The ANSPDCP has published a list of processing operations that always require a DPIA under Romanian national data protection legislation. Proceeding without a DPIA where one is required is an aggravating factor in sanction assessments.
To discuss how these compliance instruments apply to your organisation's processing activities in Romania, contact us at info@ferrazwhitmore.com.
Common pitfalls for international businesses operating in Romania
International clients entering Romania often bring compliance programmes built for their home jurisdiction. Several assumptions regularly cause problems.
Assuming one-stop-shop coverage without a main establishment is a frequent error. The one-stop-shop mechanism – under which an organisation is supervised primarily by the authority in its main EU establishment – only applies where the organisation genuinely has a main establishment in the EU. A Romanian subsidiary that takes its own processing decisions, or a non-EU parent directing processing that affects Romanian data subjects, may find the ANSPDCP acting as the lead authority rather than a concerned one. Organisations without a main EU establishment must appoint an EU representative under the GDPR.
Data transfer mechanisms are not self-executing. A transfer of personal data from Romania to a country outside the European Economic Area requires a valid transfer mechanism. Standard Contractual Clauses (SCCs) are the most commonly used instrument, but they must be supplemented by a transfer impact assessment where the destination country does not offer equivalent protection. Many organisations import SCC templates without completing the mandatory documentation or conducting the assessment. The ANSPDCP has signalled awareness of this gap, particularly for transfers to cloud providers headquartered outside the EU.
Consent mechanisms implemented for one market are rarely portable. A pre-ticked consent box, a bundled consent, or a consent obtained as a condition of service will not meet Romanian – or GDPR – standards. Organisations that rely on consent for marketing, analytics, or profiling activities must audit their consent collection infrastructure for each market and ensure that withdrawal is as easy as giving consent.
Romanian employment data processing carries specific obligations. Processing employee data – for payroll, performance monitoring, or access control – has a distinct legal basis architecture under Romanian employment legislation and data protection law. Monitoring employees' electronic communications requires specific conditions to be met, including advance information and proportionality assessment. Failure to respect these conditions has generated complaints to the ANSPDCP from employees, which the authority treats as priority investigations.
The DPO role is frequently under-resourced. Organisations that must designate a DPO sometimes treat the appointment as a formality, assigning the role to an IT manager or legal assistant without adequate authority or resources. The ANSPDCP expects the DPO to have genuine independence, direct access to senior management, and sufficient time to perform the role. Where the authority finds that a designated DPO has been excluded from key processing decisions, this is treated as an aggravating factor.
Cross-border dimension and data transfer strategy
Romania is an EU member state. This means GDPR applies directly, without the need for implementing legislation on core substantive rules. For groups with entities in multiple EU jurisdictions, the Romanian entity's obligations are substantively aligned with those of its counterparts in Portugal, France, or Germany. However, procedural and enforcement nuances vary significantly between authorities.
The ANSPDCP tends to be a proactive authority. It participates actively in European Data Protection Board proceedings and has demonstrated willingness to act on complaints that other authorities might resolve through guidance before escalating. International groups accustomed to a more advisory relationship with their home data protection authority should calibrate their expectations accordingly.
For groups that operate between Romania and Portugal. a common structure for Iberian-Atlantic holding arrangements. the interaction between the ANSPDCP and the Comissão Nacional de Proteção de Dados (CNPD. the Portuguese Data Protection Authority) is governed by the GDPR's cooperation and consistency mechanisms. Where the main establishment is in Portugal, the CNPD leads. Where processing is locally determined in Romania, the ANSPDCP may assert jurisdiction. Our team's experience across both jurisdictions informs this analysis directly. Clients managing data flows between these two markets may also benefit from our work on data protection in Portugal. This addresses the CNPD's enforcement approach and the specific derogations available under Portuguese national data protection legislation.
For data transfers outside the EEA, Romanian-established controllers must maintain up-to-date transfer impact assessments for all third-country recipients. The European Data Protection Board's recommendations on supplementary measures remain the reference standard for assessing whether SCCs alone are sufficient, or whether additional contractual, technical, or organisational safeguards are required.
Groups considering Romania as a point of entry into the CEE region should also account for the interplay between data protection obligations and the requirements arising under Romanian sector-specific legislation. particularly in financial services, healthcare, and telecommunications. Each sector carries additional data retention and security obligations that run alongside GDPR requirements.
For a tailored strategy on cross-border data transfer compliance and ANSPDCP engagement in Romania, reach out to info@ferrazwhitmore.com.
Self-assessment checklist before operating in Romania
This checklist applies to controllers and processors with operations, customers, or processing activities in Romania. Verify each item before commencing or expanding data processing.
- Has your organisation mapped all processing activities and completed a current Record of Processing Activities, identifying the lawful basis for each activity?
- Have data processing agreements been concluded with all processors engaged in Romania, including cloud providers, HR platforms, and IT service providers?
- Is a valid data transfer mechanism in place for each transfer of personal data outside the EEA, supported by a transfer impact assessment where required?
- Where a DPO designation is mandatory, has a qualified individual been appointed with sufficient independence, resources, and direct access to senior management?
- Are data subject rights procedures operational and tested, with documented response workflows capable of meeting the one-month response deadline?
This checklist is a starting point, not an exhaustive audit. Processing operations that involve special categories of data, automated decision-making, or large-scale monitoring require additional steps, including a DPIA and potentially prior consultation with the ANSPDCP.
Organisations that have recently undergone a corporate restructuring, acquisition. Alternatively. Expansion into Romania. including those setting up under Romanian company formation procedures (details of which are covered in our guide to company formation in Romania). should treat data protection compliance as a day-one obligation, not a post-launch refinement.
Frequently asked questions
- How long does it take the ANSPDCP to resolve a complaint or investigation in Romania?
- Timelines vary depending on the complexity of the matter and whether the case involves cross-border processing subject to the one-stop-shop mechanism. A straightforward complaint involving a locally established organisation can result in a formal finding within three to six months. Complex investigations involving multiple controllers or significant data volumes may extend considerably longer. Organisations should not assume that the absence of immediate contact from the ANSPDCP means a complaint has been closed.
- Is it a misconception that GDPR compliance in Romania is the same as in any other EU country?
- This is a common misconception. While the substantive GDPR rules are uniform across the EU, national data protection legislation in Romania introduces additional obligations and derogations – particularly in employment, healthcare, and the public sector. The ANSPDCP's enforcement priorities and procedural approach also differ from those of authorities in other member states. A compliance programme built for Germany or France requires localisation before it is fit for purpose in Romania.
- What are the likely cost implications of a data protection audit and remediation programme in Romania?
- Costs depend on the size and complexity of the organisation's processing operations. A targeted gap analysis and documentation remediation for a mid-sized business typically requires engagement over several weeks. Full compliance programmes for groups with significant processing operations. including data mapping, DPA drafting, DPIA preparation. Additionally. DPO support. represent a more substantial investment. However, this is considerably less than the administrative fines the ANSPDCP may impose for systematic non-compliance. Engaging a lawyer in Romania with GDPR and ANSPDCP experience early in the process allows cost to be directed toward prevention rather than remediation.
About Ferraz & Whitmore
Ferraz & Whitmore is an international law firm in Lisbon advising clients across 46 jurisdictions on data protection, technology law, and cross-border compliance. Our data protection practice supports international businesses in managing GDPR compliance obligations in Romania and across the EU, combining civil law expertise with an internationally oriented approach developed across 15 practice areas. The firm's attorneys have advised on data transfer mechanisms, DPO designations, DPIA procedures, and ANSPDCP engagement for clients in financial services, technology, retail, and professional services. As a law firm in Romania and across the EU, we work with in-house legal teams and senior management who need practical, jurisdiction-specific guidance rather than generic compliance templates. To explore how our data protection services apply to your operations in Romania, contact us at info@ferrazwhitmore.com.
Disclaimer: This publication is provided for informational purposes only and does not constitute legal advice. The information herein should not be relied upon as a substitute for professional legal counsel tailored to your specific circumstances. Ferraz & Whitmore assumes no liability for actions taken or not taken based on the contents of this material. For advice regarding your particular situation, please contact info@ferrazwhitmore.com.