Law / Romania

Romania

privacy

Romania gives the General Data Protection Regulation (GDPR) domestic effect through Legea nr. 190/2018, applicable from 31 July 2018. This document rests entirely on commentary (CMS, DLA Piper): legislatie.just.ro, the official consolidated-text portal, failed on every attempt this session, first with a DNS resolution failure and then with an HTTP/2 stream reset, a genuine access failure rather than evidence the document does not exist.

The genuine Romanian addition surveyed in this pass ties explicit consent or express legal authorization to using genetic, biometric, or health data for automated decision-making or profiling, and separate rules govern the national identification number under a legitimate-interests basis; neither was independently verified. Every substantive claim here should be treated as unverified until a primary-source read becomes possible.

14 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

GDPR Articles 33-34, Breach Notification

cite Regulation (EU) 2016/679, Arts. 33-34 stage In effect since 2018-05-25 source GDPR Arts. 33-34

A controller must notify ANSPDCP within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. Both commentary sources agree there is no Romanian-specific derogation from this timeline; DLA Piper adds a procedural detail that controllers notify using a special notification form, not independently verified against primary text.

What it asks of an app

Comprehensive regime

Law No. 190/2018 on Measures for the Implementation of Regulation (EU) 2016/679

cite Legea nr. 190/2018 privind masuri de punere in aplicare a Regulamentului (UE) 2016/679 stage In effect since 2018-07-31 source CMS and DLA Piper commentary only

Romania gives the General Data Protection Regulation (GDPR) domestic effect through Legea nr. 190/2018, applicable from 31 July 2018. This session could not read the Act's primary text: legislatie.just.ro, the official consolidated-text portal, failed on every attempt, first with a DNS resolution failure via a direct fetch, then with an HTTP/2 stream reset via a crawler-based reader, confirmed twice, a genuine access failure rather than evidence the document does not exist. Every finding below rests on two commentary sources (CMS, DLA Piper) rather than a primary-source read.

What it asks of an app

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

cite Regulation (EU) 2016/679, Arts. 44-49, 83(5)(c) stage In effect since 2018-05-25 source GDPR Arts. 44-49, 83(5)(c)

A transfer of personal data outside the EEA requires an adequacy decision, appropriate safeguards, or a narrow Article 49 derogation, backed by the Article 83(5)(c) top fine tier. DLA Piper's commentary states Law 190/2018 contains no specific provisions on international data transfers and General Data Protection Regulation (GDPR) rules apply directly; no primary text was read.

What it asks of an app

Data subject rights

GDPR Articles 12-22, Data-Subject Rights and Electronic Employee Monitoring

cite Regulation (EU) 2016/679, Arts. 12-22; Legea nr. 190/2018, electronic monitoring of employees stage In effect since 2018-05-25 source GDPR Arts. 12-22

General Data Protection Regulation (GDPR) Articles 12-22 apply directly. Commentary separately confirms the Act addresses electronic monitoring of employees in the workplace as its own heading, distinct from the biometric and automated-decision-making provision above, but neither commentary source details what that provision actually requires; this is a named gap, not a confirmed absence.

What it asks of an app

Enforcement supervision

ANSPDCP Enforcement and GDPR Article 82

cite Regulation (EU) 2016/679, Arts. 82-83 stage In effect since 2018-05-25 source GDPR Arts. 82-83

Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP, National Supervisory Authority for Personal Data Processing) is Romania's supervisory authority, with no Romania-specific enforcement addition beyond the General Data Protection Regulation (GDPR) Article 83 baseline found in this pass.

GDPR Article 82 arms an individual with a direct private right of action; commentary describes ordinary Romanian tort liability rules as the procedural vehicle for such a claim rather than a distinct additional remedy. No collective-redress mechanism was found in either commentary source.

What it asks of an app

Sensitive categories

GDPR Article 9 and Law 190/2018 Automated Decision-Making and CNP Rules

cite Regulation (EU) 2016/679, Art. 9; Legea nr. 190/2018, automated decision-making and national identification number provisions stage Enacted source CMS and DLA Piper commentary only

General Data Protection Regulation (GDPR) Article 9(1) treats biometric data processed for unique identification as a special category. Commentary describes a genuine Romanian addition tied to automated decision-making rather than employment: processing genetic, biometric, or health data for automated decision-making or profiling requires explicit consent or express legal authorization, with adequate protective measures.

A second commentary-described addition covers the national identification number: where a controller relies on legitimate interests to process it, the Act reportedly requires a Data Protection Officer, adequate technical and organizational measures, specific retention terms with deletion deadlines, and regular staff training. Neither was independently verified against the Act's own text this session, and no employment-specific biometric provision was found in either commentary source.

No commencement date is recorded for this instrument: this document rests entirely on commentary with no primary-source text read, and status is downgraded from in_effect to enacted rather than asserting an unconfirmed effective date.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.