Skip to the content
Global Data RulesData governance rules, country by country

Romania

Part of the European Union, so bloc-wide rules apply here too. Checked yesterday.

The answer

Depends on your industryWork: MediumEnforcement: Active

Romania follows the European rulebook. For almost every business, data may leave the country and leave Europe, as long as you use one of the approved European transfer routes. Two areas break that pattern: online gambling companies must keep the master copy of player and betting records on servers physically in Romania, and public bodies are being moved onto a state-run cloud. The privacy regulator works and publishes decisions, but its fines are small.

Data governance in Romania

The eight things that decide how you handle data about people in Romania. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Romania has no separate test of its own. The European Union's General Data Protection Regulation decides who is caught, and it catches any company anywhere in the world that offers goods or services to people in Romania, or that monitors what they do here. There is no revenue floor and no headcount floor. If your business has no establishment anywhere in the European Union you must appoint a representative inside the Union, though that person does not have to be in Romania.

High confidenceNational rulesAppoint a local representative

Where the data is allowed to live

For nearly every business, yes. Romania has passed no law telling ordinary companies to keep data inside the country, and European Union law actually forbids member states from doing that for non-personal data except on national security grounds. The exception that bites hardest is online gambling: the authoritative copy of player and betting records must sit on servers in Romania. Public-sector systems are the other exception, because the state is moving them into its own cloud.

High confidenceDepends on your industryAllowlistOnline gamingGovernment

Sending data out of the country

Use one of the European routes and Romania asks for nothing extra. There is no Romanian registration, no notification, and no permit for sending personal data abroad. The routes are: the destination country is on the European Commission's approved list, or you sign the European Union's standard contract clauses, or you have approved binding corporate rules, or you fall inside one of the narrow one-off exceptions. Anything you write yourself still needs the regulator's sign-off.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesExplicit consentNeeded for a contractLegal claims

The regulator, and whether it actually acts

The National Supervisory Authority for Personal Data Processing, and it genuinely works. It publishes sanction decisions most months, and it was still doing so in August 2026. It also takes the lead in cross-border cases handed to it by other European regulators. The catch is size: typical fines run from about 1,000 to 11,000 euros, roughly 1,200 to 13,000 dollars, so the deterrent is reputational more than financial. Cyber security, telecoms, banking, insurance and gambling each have their own separate regulator.

High confidenceActiveFixed maximum finePercentage of global turnover

How long you must keep it — and when to delete it

Both directions apply, and they can pull against each other. The floor: accounting books and the paperwork behind them must be kept ten years, annual accounts ten years, and payroll registers fifty years. Online gambling records must sit on the Romanian safety server for at least six years. The ceiling: recordings and logs from monitoring staff at work must not be kept longer than thirty days.

Medium confidenceKeep data for a minimum periodDelete data after a periodKeep logs

If something goes wrong

There are up to four clocks and they do not line up. Every organisation has 72 hours to tell the privacy regulator about a personal data breach. Telecoms and internet providers have a second, faster duty under a separate law and a separate form. Companies classed as essential or important for cyber security must send a first alert within 24 hours, a fuller report within 72 hours, and a final report within a month. Banks, insurers and investment firms have their own financial-sector reporting on top.

Medium confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things that are not in the summary. One: recordings from monitoring staff at work must be deleted after thirty days. Two: if you use a person's national identification number and your reason is your own business interest, you are legally required to appoint a data protection officer, even if nothing else in European law would force one. Three: Romanian public bodies get a warning first and can only be fined about 45,000 dollars, so suing or complaining about a state body rarely produces a big result. Four: Romania has no telecoms data retention law, so old call records may simply not exist. Five: online gambling has a hard in-country server rule and a Romanian representative requirement.

High confidenceAppoint a data protection officerDelete data after a periodKeep the data in the countryAppoint a local representativeUnenforceable

What's changing next

Three dated items. Financial firms have been exposed to Romanian penalties for the European digital resilience rules since 11 March 2026, with fines reaching 10 percent of yearly turnover. Cyber security enforcement is ramping up after registration and the two implementing orders of August 2025. And on 12 January 2027 a European rule makes cloud switching and data export fees zero, which will change every cloud contract you have.

Medium confidenceIn forceProposedMake switching cloud provider possible

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Online gaming

Hotararea Guvernului nr. 111/2016 - Norme metodologice de punere in aplicare a OUG nr. 77/2009 privind organizarea si exploatarea jocurilor de noroc

Directly binding regulation · Government Decision 111/2016, Official Gazette 151 of 26 February 2016, articles 136-139 and licensing annex

In forceA copy must stay

Romania's only hard data-location rule for private business. Online gambling operators must keep a safety server and a mirror server physically in Romania, holding player identity, geolocation, stakes, winnings and money movements, for at least six years. In February 2025 the Court of Accounts found the regulator had never actually connected to those servers.

In force since 26 February 2016

Enforced by National Gambling Office

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Finance

Ordonanta de urgenta nr. 14/2026 privind stabilirea unor masuri de punere in aplicare a Regulamentului (UE) nr. 2022/2554

Directly binding regulation · Emergency Ordinance 14/2026 of 5 March 2026, Official Gazette 188 of 11 March 2026

In forceYes, with paperwork

Romania's penalty framework for the European digital operational resilience rules for finance. The central bank supervises banks, payment and e-money firms; the financial supervisory authority covers investment firms, insurers and pension administrators. It requires you to disclose where your provider keeps data, but it does not require that place to be Romania.

In force since 11 March 2026

Enforced by National Bank of Romania

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence
Telecoms

Decizia Curtii Constitutionale nr. 440/2014 privind Legea nr. 82/2012

Court decision · Constitutional Court Decision 440 of 8 July 2014; Law 82/2012 never replaced

UnenforceableYes, with paperwork

Romania has no telecoms data retention duty. The Constitutional Court struck the 2012 retention law down in July 2014 and Parliament has never replaced it, a point the court repeated in May 2022. What survives is the e-privacy law: delete traffic data when you no longer need it, and file breach reports on a separate form.

In force since 8 July 2014

Enforced by National Supervisory Authority for Personal Data Processing

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Legea nr. 190/2018 privind masuri de punere in aplicare a Regulamentului (UE) 2016/679

Act of parliament · Law 190 of 18 July 2018, Official Gazette 651 of 26 July 2018

In forceYes, with paperwork

Romania's national add-on to the European rules. It does not restrict where data is stored. It adds a hard 30-day ceiling on workplace monitoring data, forces a data protection officer on anyone using national identification numbers for their own business interests, and gives public bodies a warning-first process with a low fine cap.

In force since 31 July 2018

Enforced by National Supervisory Authority for Personal Data Processing

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence

Ordonanta de urgenta nr. 155/2024 privind instituirea unui cadru pentru securitatea cibernetica a retelelor si sistemelor informatice din spatiul cibernetic national civil

Directly binding regulation · Emergency Ordinance 155/2024, approved with changes by Law 124/2025; DNSC Orders 1/2025 and 2/2025 of 20 August 2025

In forceYes — store it anywhere

Romania's transposition of the European network and information security rules. It imposes no storage location requirement. What it does impose is registration, a layered incident reporting timetable starting at 24 hours, and turnover-based fines that are far larger than anything the privacy regulator hands out.

In force since 30 December 2024But only enforceable from 20 August 2025

Enforced by National Cyber Security Directorate

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

Applies across the European Union1 rule

Written once for the whole bloc, and in force in every member country.

Regulamentul general privind protectia datelor (Regulation (EU) 2016/679)

Directly binding regulation · Regulation (EU) 2016/679; Regulation (EU) 2018/1807

In forceYes, with paperwork

The European layer. Data may leave Romania and leave Europe if you use an approved route. A separate European regulation actually forbids Romania from imposing storage-in-country rules on non-personal data except on public security grounds.

In force since 25 May 2018

Enforced by National Supervisory Authority for Personal Data Processing

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk

High confidence

Who you would hear from

  • Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal

    General privacy law, e-privacy law, breach notification, cross-border lead authority

    Fully operational and publishing sanction decisions through 6 August 2026. Headed by president Ancuta Gianina Opre. Fines are typically small, in the 1,000 to 11,000 euro range, and public bodies get a warning plus a remediation plan before any fine, capped at 200,000 lei.

  • Directoratul National de Securitate Cibernetica

    Cyber security of essential and important entities, incident reporting, registration

    Issued two implementing orders on 20 August 2025 and ran the entity registration process. Its website blocks automated access, so we verified its activity through third-party legal reporting rather than by opening the orders directly.

  • Autoritatea Nationala pentru Administrare si Reglementare in Comunicatii

    Electronic communications and postal services

    Active and publishing. Note that breaches of the e-privacy law are enforced by the privacy regulator, not by this body.

  • Banca Nationala a Romaniei

    Banks, payment institutions, e-money issuers; national coordinator for threat-led penetration testing

  • Autoritatea de Supraveghere Financiara

    Insurance, private pensions, capital markets, crowdfunding

  • Oficiul National pentru Jocuri de Noroc

    Gambling licensing, including the in-country safety and mirror server requirement

    It exists, licenses operators and publishes decisions. But the Court of Accounts reported in February 2025 that it had never connected to or monitored the safety and mirror servers it requires, so the country's strictest data-location rule has been effectively unpoliced. Treat licensing enforcement as real and technical supervision as dormant.

  • Autoritatea pentru Digitalizarea Romaniei

    Government Cloud Platform governance and migration of public institutions

    Operational, but its public site returned errors to us on 18 August 2026, so the cloud rules are recorded at medium confidence.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact Romanian wording of the incident reporting deadlines in Emergency Ordinance 155/2024

    The cyber security directorate's website is behind bot protection and the official legislation portal blocks automated fetching. We report the 24 hour, 72 hour and one month deadlines as the deadlines of the European directive being transposed, corroborated by Romanian legal commentary, not from the ordinance text itself.

  • Whether Government Decision 111/2016 as amended still carries the safety and mirror server location wording

    The copy we opened, hosted by the tax administration, is the original 2016 text as published in the Official Gazette. The rule appears unchanged in current commentary and in the licensing annex, but we could not open a consolidated 2026 version on a government site because the gambling office and the legislation portal both refused automated access.

  • Whether payroll registers may now be kept five years rather than fifty

    A 2023 amendment to the Accounting Law is widely reported to allow five years where the employer has filed the matching declarations with the pension authority. The Ministry of Finance copy we opened is the earlier republished text showing fifty years. Plan to the longer period until this is confirmed.

  • Whether Emergency Ordinance 89/2022 requires Government Cloud data to be physically in Romania

    Neither the legislation portal, the digitalisation authority's site, nor the ministry pages would open for us. The platform is in practice built and run by Romanian state bodies on Romanian territory, but we could not quote an article imposing that as a legal duty.

  • Whether any Romanian rule requires health data to stay in the country

    No rule found, checked 18 August 2026. The national health insurance house runs the electronic health record centrally, but we found no obligation on private healthcare providers to store data in Romania. Confidence medium because Romanian health legislation is spread across many instruments we could not fetch.

  • Whether prepaid mobile subscriber identification has become law

    The communications regulator said in August 2024 that no such requirement existed. Bills have appeared repeatedly. We found no evidence of a law in force on 18 August 2026, but we cannot prove a negative.

  • Rules on classified information systems and on geospatial or mapping data

    Not researched in this pass. Romania runs a separate accreditation regime for classified information which is likely to require in-country, accredited systems for anyone holding a national security clearance.

  • The final published penalty figures in Emergency Ordinance 14/2026

    We read the figures from the Ministry of Finance consultation draft, which we could open, and cross-checked them against legal commentary on the published version. The gazette text itself was not directly readable.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Romania versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.