Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Regulation (EU) 2016/679, Arts. 33-34
stage In effect
since 2018-05-25
source GDPR Arts. 33-34
A controller must notify ANSPDCP within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. Both commentary sources agree there is no Romanian-specific derogation from this timeline; DLA Piper adds a procedural detail that controllers notify using a special notification form, not independently verified against primary text.
What it asks of an app →
Comprehensive regime
cite Legea nr. 190/2018 privind masuri de punere in aplicare a Regulamentului (UE) 2016/679
stage In effect
since 2018-07-31
source CMS and DLA Piper commentary only
Romania gives the General Data Protection Regulation (GDPR) domestic effect through Legea nr. 190/2018, applicable from 31 July 2018. This session could not read the Act's primary text: legislatie.just.ro, the official consolidated-text portal, failed on every attempt, first with a DNS resolution failure via a direct fetch, then with an HTTP/2 stream reset via a crawler-based reader, confirmed twice, a genuine access failure rather than evidence the document does not exist. Every finding below rests on two commentary sources (CMS, DLA Piper) rather than a primary-source read.
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-49, 83(5)(c)
stage In effect
since 2018-05-25
source GDPR Arts. 44-49, 83(5)(c)
A transfer of personal data outside the EEA requires an adequacy decision, appropriate safeguards, or a narrow Article 49 derogation, backed by the Article 83(5)(c) top fine tier. DLA Piper's commentary states Law 190/2018 contains no specific provisions on international data transfers and General Data Protection Regulation (GDPR) rules apply directly; no primary text was read.
What it asks of an app →
Data subject rights
cite Regulation (EU) 2016/679, Arts. 12-22; Legea nr. 190/2018, electronic monitoring of employees
stage In effect
since 2018-05-25
source GDPR Arts. 12-22
General Data Protection Regulation (GDPR) Articles 12-22 apply directly. Commentary separately confirms the Act addresses electronic monitoring of employees in the workplace as its own heading, distinct from the biometric and automated-decision-making provision above, but neither commentary source details what that provision actually requires; this is a named gap, not a confirmed absence.
What it asks of an app →
Enforcement supervision
cite Regulation (EU) 2016/679, Arts. 82-83
stage In effect
since 2018-05-25
source GDPR Arts. 82-83
Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP, National Supervisory Authority for Personal Data Processing) is Romania's supervisory authority, with no Romania-specific enforcement addition beyond the General Data Protection Regulation (GDPR) Article 83 baseline found in this pass.
GDPR Article 82 arms an individual with a direct private right of action; commentary describes ordinary Romanian tort liability rules as the procedural vehicle for such a claim rather than a distinct additional remedy. No collective-redress mechanism was found in either commentary source.
What it asks of an app →
Sensitive categories
cite Regulation (EU) 2016/679, Art. 9; Legea nr. 190/2018, automated decision-making and national identification number provisions
stage Enacted
source CMS and DLA Piper commentary only
General Data Protection Regulation (GDPR) Article 9(1) treats biometric data processed for unique identification as a special category. Commentary describes a genuine Romanian addition tied to automated decision-making rather than employment: processing genetic, biometric, or health data for automated decision-making or profiling requires explicit consent or express legal authorization, with adequate protective measures.
A second commentary-described addition covers the national identification number: where a controller relies on legitimate interests to process it, the Act reportedly requires a Data Protection Officer, adequate technical and organizational measures, specific retention terms with deletion deadlines, and regular staff training. Neither was independently verified against the Act's own text this session, and no employment-specific biometric provision was found in either commentary source.
No commencement date is recorded for this instrument: this document rests entirely on commentary with no primary-source text read, and status is downgraded from in_effect to enacted rather than asserting an unconfirmed effective date.
What it asks of an app →