Skip to the content
Global Data RulesData governance rules, country by country

Romania

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Romania — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: MediumEnforcement: Active

Romania follows the European rulebook. For almost every business, data may leave the country and leave Europe. You just have to use one of the approved European transfer routes. Two areas break that pattern. Online gambling companies must keep the main copy of player and betting records on servers physically in Romania. And public bodies are being moved onto a state-run cloud. The privacy regulator works and publishes decisions, but its fines are small.

Data governance in Romania

The eight things that decide how you handle data about people in Romania. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, it reaches you even with no office in Romania. Romania has no separate test of its own. The European Union's General Data Protection Regulation decides who is covered. It covers any company anywhere that offers goods or services to people in Romania. It also covers any company that monitors what people do here. There is no revenue floor and no staff-count floor. If your business has no office anywhere in the European Union, you must appoint a representative inside the Union. That person does not have to be in Romania.

What you have to do here:
Appoint a representative

Where the data is allowed to live

For nearly every business, yes. Romania has passed no law telling ordinary companies to keep data inside the country. European Union law actually stops member states from doing that for data that is not about people. The only exception there is national security. The biggest Romanian exception is online gambling. The main copy of player and betting records must sit on servers in Romania. Public-sector systems are the other exception, because the state is moving them into its own cloud.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

Use one of the European routes and Romania asks for nothing extra. There is no Romanian registration, no notification and no permit for sending personal data abroad. You have four routes. The destination country is on the European Commission's approved list. Or you sign the European Union's standard contract clauses. Or you have approved group-wide rules. Or you fall inside one of the narrow one-off exceptions. Anything you write yourself still needs the regulator's sign-off.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · Needed for a contract · Legal claims

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The National Supervisory Authority for Personal Data Processing enforces the rules, and it really works. It publishes penalty decisions most months, and was still doing so in August 2026. It also leads cross-border cases handed to it by other European regulators. The catch is size. Typical fines run from about 1,000 to 11,000 euros, roughly 1,200 to 13,000 dollars. So the deterrent is reputational more than financial. Cyber security, telecoms, banking, insurance and gambling each have their own separate regulator.

What it costs if you get it wrong:
Fixed maximum fine · Percentage of global turnover

How long you must keep it — and when to delete it

There is a minimum and a maximum, and they can pull against each other. The minimum: accounting books and their supporting paperwork must be kept ten years. Annual accounts are also ten years. Payroll registers are fifty years. Online gambling records must sit on the Romanian safety server for at least six years. The maximum: recordings and logs from monitoring staff at work must not be kept longer than thirty days.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

There are up to four clocks and they do not line up. Every organisation has 72 hours to tell the privacy regulator about a personal data breach. Telecoms and internet providers have a second, faster duty under a separate law and a separate form. Companies classed as essential or important for cyber security have three deadlines. A first alert within 24 hours, a fuller report within 72 hours, and a final report within a month. Banks, insurers and investment firms have their own financial reporting on top.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

Not fully verified — see “What we're not sure about” below.

What catches people out

Five things. One: recordings from monitoring staff at work must be deleted after thirty days. Two: if you use a person's national identification number for your own business interests, you must appoint a data protection officer. That is true even if nothing else in European law would force one. Three: Romanian public bodies get a warning first and can only be fined about 45,000 dollars. So complaining about a state body rarely produces a big result. Four: Romania has no law making telecoms companies keep call records, so old records may simply not exist. Five: online gambling has a strict in-country server rule and needs a Romanian representative.

What you have to do here:
Appoint a data protection officer · Delete data after a period · Appoint a representative

What's changing next

Three dated items. Since 11 March 2026, financial firms face Romanian penalties under the European digital resilience rules. Fines reach 10 percent of yearly turnover. Cyber security enforcement is ramping up after registration and the two orders of August 2025. And on 12 January 2027 a European rule cuts cloud switching and data export fees to zero. That will change every cloud contract you have.

What you have to do here:
Make switching cloud provider possible

What to do: Diarise 12 January 2027 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries2 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Online gaming

Online gaming data rules

Official name: Hotararea Guvernului nr. 111/2016 - Norme metodologice de punere in aplicare a OUG nr. 77/2009 privind organizarea si exploatarea jocurilor de noroc · Government Decision 111/2016, Official Gazette 151 of 26 February 2016, articles 136-139 and licensing annex · Directly binding regulation

In forceA copy must stay

Romania's only strict data-location rule for private business. Online gambling operators must keep a safety server and a mirror server physically in Romania. Those servers hold player identity, location, stakes, winnings and money movements, for at least six years. In February 2025 the Court of Accounts found the regulator had never actually connected to those servers.

In force since 26 February 2016

Enforced by National Gambling Office

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Finance

Payment data rules

Official name: Ordonanta de urgenta nr. 14/2026 privind stabilirea unor masuri de punere in aplicare a Regulamentului (UE) nr. 2022/2554 · Emergency Ordinance 14/2026 of 5 March 2026, Official Gazette 188 of 11 March 2026 · Directly binding regulation

In forceYes, with paperwork

Romania's penalties for the European digital operational resilience rules for finance. The central bank supervises banks, payment and e-money firms. The financial supervisory authority covers investment firms, insurers and pension administrators. You must disclose where your provider keeps data. That place does not have to be Romania.

In force since 11 March 2026

Enforced by National Bank of Romania

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Europe's main privacy law (2018)

Official name: Legea nr. 190/2018 privind masuri de punere in aplicare a Regulamentului (UE) 2016/679 · Law 190 of 18 July 2018, Official Gazette 651 of 26 July 2018 · Act of parliament

In forceYes, with paperwork

Romania's national add-on to the European rules. It does not restrict where data is stored. It sets a strict 30-day limit on workplace monitoring recordings. It forces a data protection officer on anyone using national identification numbers for their own business interests. And it gives public bodies a warning first, with a low cap on fines.

In force since 31 July 2018

Enforced by National Supervisory Authority for Personal Data Processing

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Breach reporting rules

Official name: Ordonanta de urgenta nr. 155/2024 privind instituirea unui cadru pentru securitatea cibernetica a retelelor si sistemelor informatice din spatiul cibernetic national civil · Emergency Ordinance 155/2024, approved with changes by Law 124/2025; DNSC Orders 1/2025 and 2/2025 of 20 August 2025 · Directly binding regulation

In forceYes — store it anywhere

Romania's version of the European network and information security rules. It sets no requirement about where data is stored. What it does require is registration, and a layered incident reporting timetable starting at 24 hours. Its fines are based on turnover and are far larger than anything the privacy regulator hands out.

In force since 30 December 2024Enforced from 20 August 2025

Enforced by National Cyber Security Directorate

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Applies across the European Union1 rule

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Regulamentul general privind protectia datelor (Regulation (EU) 2016/679) · Regulation (EU) 2016/679; Regulation (EU) 2018/1807 · Directly binding regulation

In forceYes, with paperwork

The European layer. Data may leave Romania and leave Europe if you use an approved route. A separate European regulation stops Romania from making storage-in-country rules for data that is not about people. The only exception is public security.

In force since 25 May 2018

Enforced by National Supervisory Authority for Personal Data Processing

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, To save someone’s life

On the books, but not enforceable1 rule

These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.

Telecoms

Telecoms rules

Official name: Decizia Curtii Constitutionale nr. 440/2014 privind Legea nr. 82/2012 · Constitutional Court Decision 440 of 8 July 2014; Law 82/2012 never replaced · Court decision

UnenforceableYes, with paperwork

Romania has no telecoms data retention duty. The Constitutional Court struck the 2012 retention law down in July 2014 and Parliament has never replaced it, a point the court repeated in May 2022. What survives is the e-privacy law: delete traffic data when you no longer need it, and file breach reports on a separate form.

In force since 8 July 2014

Enforced by National Supervisory Authority for Personal Data Processing

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal

    General privacy law, e-privacy law, breach notification, cross-border lead authority

    Fully working and publishing penalty decisions through 6 August 2026. Headed by president Ancuta Gianina Opre. Fines are typically small, in the 1,000 to 11,000 euro range. Public bodies get a warning plus a repair plan before any fine, capped at 200,000 lei.

  • Directoratul National de Securitate Cibernetica

    Cyber security of essential and important entities, incident reporting, registration

    Issued two implementing orders on 20 August 2025 and ran the entity registration process.

  • Autoritatea Nationala pentru Administrare si Reglementare in Comunicatii

    Electronic communications and postal services

    Active and publishing. Note that breaches of the e-privacy law are enforced by the privacy regulator, not by this body.

  • Banca Nationala a Romaniei

    Banks, payment institutions, e-money issuers; national coordinator for threat-led penetration testing

  • Autoritatea de Supraveghere Financiara

    Insurance, private pensions, capital markets, crowdfunding

  • Oficiul National pentru Jocuri de Noroc

    Gambling licensing, including the in-country safety and mirror server requirement

    It exists, licenses operators and publishes decisions. But the Court of Accounts reported in February 2025 that it had never connected to or monitored the safety and mirror servers it requires. So the country's strictest data-location rule has gone largely unpoliced. Treat licensing enforcement as real and technical supervision as not happening.

  • Autoritatea pentru Digitalizarea Romaniei

    Government Cloud Platform governance and migration of public institutions

    Operational, but its public site returned errors to us on 18 August 2026, so the cloud rules are recorded at medium confidence.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact Romanian wording of the incident reporting deadlines in Emergency Ordinance 155/2024

    We could not confirm the Romanian deadlines against the ordinance text. We report the 24 hour, 72 hour and one month deadlines as the deadlines of the European directive being copied across. Romanian legal commentary agrees. Check the Romanian text before you rely on the exact wording.

  • Whether Government Decision 111/2016 as amended still carries the safety and mirror server location wording

    We could not confirm this against an up-to-date government text. The copy we read, hosted by the tax administration, is the original 2016 text from the Official Gazette. The rule appears unchanged in current commentary and in the licensing annex. But the gambling office and the legislation portal both refused automated access, so we could not check a 2026 consolidated version.

  • Whether payroll registers may now be kept five years rather than fifty

    We could not confirm the payroll keeping period. A 2023 change to the Accounting Law is widely reported to allow five years, where the employer has filed the matching declarations with the pension authority. The Ministry of Finance copy we read is the earlier republished text showing fifty years. Plan for the longer period until this is confirmed.

  • Whether Emergency Ordinance 89/2022 requires Government Cloud data to be physically in Romania

    We could not confirm that any law requires the government cloud to be inside Romania. The legislation portal, the digitalisation authority's site and the ministry pages would not open for us. The platform does appear to be built and run by Romanian state bodies on Romanian territory. But we could not quote an article making that a legal duty.

  • Whether any Romanian rule requires health data to stay in the country

    We found no health rule requiring data to stay in Romania, checked 18 August 2026. The national health insurance house runs the electronic health record centrally. We found no duty on private healthcare providers to store data in Romania. Confidence is medium, because Romanian health law is spread across many texts we could not open. If you work in health, check before you rely on this.

  • Whether prepaid mobile subscriber identification has become law

    We could not confirm this either way. The communications regulator said in August 2024 that no such requirement existed. Bills have appeared repeatedly. We found no law in force on 18 August 2026. But not finding one is not proof that none exists.

  • Rules on classified information systems and on geospatial or mapping data

    We did not research this. Romania runs a separate approval process for classified information. It is likely to require accredited systems inside the country for anyone holding a national security clearance. Check directly if that applies to you.

  • The final published penalty figures in Emergency Ordinance 14/2026

    We could not read the gazette text itself. We took the figures from the Ministry of Finance consultation draft, which we could open. We then cross-checked them against legal commentary on the published version.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.