Romania
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Romania — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Romania follows the European rulebook. For almost every business, data may leave the country and leave Europe. You just have to use one of the approved European transfer routes. Two areas break that pattern. Online gambling companies must keep the main copy of player and betting records on servers physically in Romania. And public bodies are being moved onto a state-run cloud. The privacy regulator works and publishes decisions, but its fines are small.
Data governance in Romania
The eight things that decide how you handle data about people in Romania. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes, it reaches you even with no office in Romania. Romania has no separate test of its own. The European Union's General Data Protection Regulation decides who is covered. It covers any company anywhere that offers goods or services to people in Romania. It also covers any company that monitors what people do here. There is no revenue floor and no staff-count floor. If your business has no office anywhere in the European Union, you must appoint a representative inside the Union. That person does not have to be in Romania.
- What you have to do here:
- Appoint a representative
Romania's national add-on is Law 190/2018, in force since 31 July 2018. It does not change who is covered. It adds duties on top for particular kinds of data use. Two Romanian points matter. First, Law 190/2018 defines 'public authorities and bodies' very widely. It expressly treats religious units and public-benefit associations and foundations as public bodies. That pulls them into the softer penalty track. Second, gambling has a real requirement for someone on the ground. An operator licensed elsewhere in the European Economic Area or Switzerland that serves Romanian players must appoint an authorised representative. That representative's tax home or registered seat must be on Romanian territory. They must be able to act before Romanian authorities.
Sources
- Official sourceEUR-LexRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 44-49, 83
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceAutoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)Law 190/2018 on measures implementing the General Data Protection Regulation - full text hosted by the supervisory authority
dataprotection.ro
Link checked 18 August 2026
- Official sourceAgentia Nationala de Administrare Fiscala (ANAF)Government Decision 111/2016 approving the methodological norms for gambling, articles 136-137 and the licensing annex
static.anaf.ro
“Sistemul informatic al organizatorului va asigura stocarea pe serverul de siguranta a datelor colectate, in forma in care au fost create, pentru o perioada minima de 6 ani de la data colectarii”
Link checked 18 August 2026
Where the data is allowed to live
For nearly every business, yes. Romania has passed no law telling ordinary companies to keep data inside the country. European Union law actually stops member states from doing that for data that is not about people. The only exception there is national security. The biggest Romanian exception is online gambling. The main copy of player and betting records must sit on servers in Romania. Public-sector systems are the other exception, because the state is moving them into its own cloud.
Industry by industry, checked on 18 August 2026. BANKING, PAYMENTS, INSURANCE AND SECURITIES: we found no rule forcing data to stay in the country. Romania brought in the European digital resilience rules by emergency ordinance in March 2026. It named the central bank and the financial supervisory authority as enforcers. Those rules make you know and disclose where your provider handles data, and be able to exit. They do not require the data to be in Romania. HEALTH: we found no rule forcing data to stay in the country on official sources, checked 18 August 2026. The national health insurance house runs the electronic health record centrally. That is a state system, not a duty on private firms. TELECOM: no rule forcing data to stay in the country. Unusually, there is no duty to keep call records either. GOVERNMENT: the Government Cloud Platform is built and run by state bodies on Romanian territory. Public institutions are being moved onto it. Treat public-sector work as staying in the country by default. GAMBLING: a strict rule, see below. EDUCATION, ONLINE RETAIL, SOCIAL MEDIA: we found no industry rule. DEFENCE AND CLASSIFIED MATERIAL: Romania runs a separate approval process for classified information systems. We did not check it this time. MAPPING AND GEOSPATIAL: we found no rule, low confidence. The gambling rule is the real one. The technical rules require the 'safety server' and the 'mirror server' to be on Romanian soil. Every transaction must reach the safety server within 24 hours. The data must stay there in its original form for at least six years. The game server itself may sit anywhere in the European Union, the European Economic Area or Switzerland. So it is a copy-in-country rule, not a total ban on handling data abroad.
Sources
- Official sourceAgentia Nationala de Administrare Fiscala (ANAF)Government Decision 111/2016 approving the methodological norms for gambling, articles 136-137 and the licensing annex
static.anaf.ro
“Sistemul informatic al organizatorului va asigura stocarea pe serverul de siguranta a datelor colectate, in forma in care au fost create, pentru o perioada minima de 6 ani de la data colectarii”
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2018/1807 on the free flow of non-personal data - bans member state localisation except on public security grounds
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 44-49, 83
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceMinisterul FinantelorDraft emergency ordinance implementing Regulation (EU) 2022/2554 (DORA) - competent authorities and penalty scale, published for consultation 29 October 2025
mfinante.gov.ro
“amenda aplicabila entitatilor responsabile, de pana la 10% din cifra de afaceri anuala totala ... pana la 23.000.000 lei”
Link checked 18 August 2026
- Official sourceANCOMANCOM press release on prepaid telecom cards, 29 August 2024 - no identification requirement described
ancom.ro
“legislatia din domeniul comunicatiilor electronice nu stabileste conditii concrete privind furnizarea serviciilor de comunicatii electronice prin intermediul cartelelor preplatite”
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
Use one of the European routes and Romania asks for nothing extra. There is no Romanian registration, no notification and no permit for sending personal data abroad. You have four routes. The destination country is on the European Commission's approved list. Or you sign the European Union's standard contract clauses. Or you have approved group-wide rules. Or you fall inside one of the narrow one-off exceptions. Anything you write yourself still needs the regulator's sign-off.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · Needed for a contract · Legal claims
Romania uses the European system: an approved list of countries, plus approved paperwork for everywhere else. The list is well populated. It covers Andorra, Argentina, Brazil, Canada for commercial bodies, the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom and Uruguay. The United States counts only for companies that have self-certified under the European Union - United States Data Privacy Framework. The 2021 standard contract clauses are still the set in use and have not been amended. New clauses were promised for recipients already directly covered by the Regulation. They are still not adopted. You are still expected to write a transfer risk assessment. Clauses you write yourself need the Romanian supervisory authority's approval first. One point is worth knowing. European guidance finalised in June 2025 says an order from a non-European government is not by itself a lawful reason to hand data over. The item most likely to change is the European Union - United States arrangement. It is valid today. But it is under appeal at the European Court of Justice. In July 2026 the European Data Protection Board formally asked the Commission to look at it again. Do not make it your only route.
Sources
- Official sourceEUR-LexRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 44-49, 83
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionEuropean Commission adequacy decisions, as listed on 18 August 2026
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexCommission Implementing Decision (EU) 2021/914 - Standard Contractual Clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEDPB letter to Commissioner McGrath, 31 July 2026, on the EU-US Data Privacy Framework
edpb.europa.eu
Link checked 18 August 2026
- Official sourceAutoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)Law 190/2018 on measures implementing the General Data Protection Regulation - full text hosted by the supervisory authority
dataprotection.ro
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The National Supervisory Authority for Personal Data Processing enforces the rules, and it really works. It publishes penalty decisions most months, and was still doing so in August 2026. It also leads cross-border cases handed to it by other European regulators. The catch is size. Typical fines run from about 1,000 to 11,000 euros, roughly 1,200 to 13,000 dollars. So the deterrent is reputational more than financial. Cyber security, telecoms, banking, insurance and gambling each have their own separate regulator.
- What it costs if you get it wrong:
- Fixed maximum fine · Percentage of global turnover
Here is the evidence that it works, from the authority's own site. On 1 July 2026 it issued a fine of 57,839 lei, about 11,000 euros. France's regulator had handed Romania the lead in that case. On 20 March 2026 it issued fines of 10,190 lei and 5,095 lei. Those were for filming employees with body cameras without telling them. It published further penalties dated 2, 17 and 31 July and 6 August 2026. The authority is headed by a president, Ancuta Gianina Opre. Two enforcement gaps are worth naming. First, public bodies get a warning and a written repair plan before any fine. Their fines are capped at 200,000 lei, roughly 45,000 dollars. Second, and more striking, Romania's Court of Accounts reported on the National Gambling Office in February 2025. It had never actually connected to or monitored the safety and mirror servers it makes operators install. So the country's strictest data-location rule has been largely unpoliced. The rule is in force. The policing of it is not.
Sources
- Official sourceANSPDCPDecizii publicate / published sanction decisions and press releases, list current to 6 August 2026
dataprotection.ro
Link checked 18 August 2026
- Official sourceANSPDCPPress release, 1 July 2026 - cross-border case, Ascendex Technology SRL fined 57,839 lei (11,000 euro)
dataprotection.ro
“Ascendex Technology SRL ... amenda in cuantum de 57.839 lei (echivalentul a 11.000 EUR)”
Link checked 18 August 2026
- Official sourceANSPDCPPress release, 20 March 2026 - body-camera monitoring of employees, fines of 10,190 lei and 5,095 lei
dataprotection.ro
Link checked 18 August 2026
- Official sourceAutoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)Law 190/2018 on measures implementing the General Data Protection Regulation - full text hosted by the supervisory authority
dataprotection.ro
Link checked 18 August 2026
- Official sourceCurtea de Conturi a RomanieiCourt of Accounts audit report on the National Gambling Office, published 21 February 2025
curteadeconturi.ro
Link checked 18 August 2026
- Secondary sourceavocatnet.roReport on the Court of Accounts findings: the gambling office never connected to the safe and mirror servers it licences
avocatnet.ro
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a minimum and a maximum, and they can pull against each other. The minimum: accounting books and their supporting paperwork must be kept ten years. Annual accounts are also ten years. Payroll registers are fifty years. Online gambling records must sit on the Romanian safety server for at least six years. The maximum: recordings and logs from monitoring staff at work must not be kept longer than thirty days.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs
The thirty-day limit on workplace monitoring data is the one that surprises people. Law 190/2018 makes it absolute. The only exceptions are where a specific law says otherwise, or the case is strongly justified. On the minimum side, Accounting Law 82/1991 sets the ten-year rule and the fifty-year payroll rule. A 2023 change allows payroll registers to be kept only five years. That applies where the employer has filed the matching declarations with the pension authority. We flag that as needing confirmation against the consolidated text. Telecoms traffic data must be erased or made anonymous once it is no longer needed to carry the communication. The exception is billing. There you may keep it until the claim is time-barred. Where a minimum and a maximum collide, the minimum usually wins. The law that creates it is the legal duty that justifies keeping the data. But that only rescues the specific records the law names. It does not rescue everything else sitting in the same database. Law 190/2018 also makes writing down your keeping periods a formal condition, not just good practice. That applies whenever you rely on your own business interests to handle someone's national identification number. It also applies when you handle data in the public interest.
Sources
- Official sourceMinisterul FinantelorAccounting Law 82/1991, republished, article 25 and article 35 - record retention periods
mfinante.gov.ro
“Registrele de contabilitate obligatorii si documentele justificative care stau la baza inregistrarilor in contabilitatea financiara se pastreaza in arhiva persoanelor prevazute la art.1 timp de 10 ani ... cu exceptia statelor de salarii, care se pastreaza timp de 50 de ani.”
Link checked 18 August 2026
- Official sourceAutoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)Law 190/2018 on measures implementing the General Data Protection Regulation - full text hosted by the supervisory authority
dataprotection.ro
Link checked 18 August 2026
- Official sourceAgentia Nationala de Administrare Fiscala (ANAF)Government Decision 111/2016 approving the methodological norms for gambling, articles 136-137 and the licensing annex
static.anaf.ro
“Sistemul informatic al organizatorului va asigura stocarea pe serverul de siguranta a datelor colectate, in forma in care au fost create, pentru o perioada minima de 6 ani de la data colectarii”
Link checked 18 August 2026
- Official sourcePortal Legislativ, Ministerul JustitieiLaw 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector
legislatie.just.ro
Link checked 18 August 2026
- Secondary sourceAsociatia pentru Tehnologie si Internet (APTI)Consolidated text of Law 506/2004 - traffic data erasure, breach notification and penalty scale
privacy.apti.ro
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
There are up to four clocks and they do not line up. Every organisation has 72 hours to tell the privacy regulator about a personal data breach. Telecoms and internet providers have a second, faster duty under a separate law and a separate form. Companies classed as essential or important for cyber security have three deadlines. A first alert within 24 hours, a fuller report within 72 hours, and a final report within a month. Banks, insurers and investment firms have their own financial reporting on top.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
The privacy regulator publishes two separate breach forms on its own site. One is for the General Data Protection Regulation. The other is for Law 506/2004. That is the practical proof that the two sets of rules run side by side. One does not absorb the other. Companies providing public electronic communications services must notify without delay under Law 506/2004. The detailed European rules on that notification set a 24-hour first deadline. The cyber security clocks come from Emergency Ordinance 155/2024. It brought in the European network and information security directive on 30 December 2024. Law 124/2025 approved it with changes in July 2025. Two orders of the National Cyber Security Directorate made it work from 20 August 2025. Those orders also opened a 30-day window for organisations to register themselves. We report the 24 hour, 72 hour and one month deadlines as the deadlines of the European directive. We could not open the Romanian text directly, because the directorate's site blocks automated access. So treat the exact Romanian wording as unconfirmed. The most common failure here is a single incident-response plan written to one deadline. If you are a bank that is also an essential organisation and you lose customer records, all four clocks start at once.
Sources
- Official sourceANSPDCPBreach notification page - two separate forms, 'Notificare Bresa RGPD' and 'Notificare Bresa L.506/2004'
dataprotection.ro
Link checked 18 August 2026
- Official sourcePortal Legislativ, Ministerul JustitieiEmergency Ordinance 155/2024 of 30 December 2024 establishing the cybersecurity framework for the civil national cyberspace (transposes Directive (EU) 2022/2555)
legislatie.just.ro
Link checked 18 August 2026
- Official sourceEUR-LexDirective (EU) 2022/2555 (NIS2) - Article 23 reporting deadlines
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceLink may be brokenDirectoratul National de Securitate Cibernetica (DNSC)NIS2 legislation page of the National Cyber Security Directorate, listing Emergency Ordinance 155/2024 and Orders 1/2025 and 2/2025
dnsc.ro
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 44-49, 83
eur-lex.europa.eu
Link checked 18 August 2026
- Secondary sourcecertSIGNImplementation of NIS2 in Romania - Emergency Ordinance 155/2024, approved by Law 124/2025, DNSC Orders 1/2025 and 2/2025 of 20 August 2025
certsign.ro
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
Not fully verified — see “What we're not sure about” below.What catches people out
Five things. One: recordings from monitoring staff at work must be deleted after thirty days. Two: if you use a person's national identification number for your own business interests, you must appoint a data protection officer. That is true even if nothing else in European law would force one. Three: Romanian public bodies get a warning first and can only be fined about 45,000 dollars. So complaining about a state body rarely produces a big result. Four: Romania has no law making telecoms companies keep call records, so old records may simply not exist. Five: online gambling has a strict in-country server rule and needs a Romanian representative.
- What you have to do here:
- Appoint a data protection officer · Delete data after a period · Appoint a representative
On trap two, the trigger is broader than people expect. Romanian law treats several numbers as 'national identification numbers'. They are the personal numeric code, identity card series and number, passport number, driving licence number and health insurance number. Using any of them on a business-interests basis brings four conditions, all at once. You need technical and organisational measures aimed at collecting as little as possible. You need a named data protection officer. You need written storage and deletion deadlines. And you need regular training for the staff who touch the data. Almost every Romanian contract, invoice and HR file carries the personal numeric code. So this quietly catches a lot of foreign employers. On trap three, the softer treatment also covers religious units and public-benefit associations and foundations. Romanian law treats them as public bodies. On trap four, the Constitutional Court struck down the 2012 record-keeping law in July 2014. In May 2022 it repeated that Parliament had still not replaced it. That is a gap in what evidence exists, not a privacy win. Parliament can close it at any time. Trap five has a criminal edge too. The Court of Accounts referred parts of gambling supervision to prosecutors in 2025. So this is not a purely administrative area.
Sources
- Official sourceAutoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)Law 190/2018 on measures implementing the General Data Protection Regulation - full text hosted by the supervisory authority
dataprotection.ro
Link checked 18 August 2026
- Official sourcePortal Legislativ, Ministerul JustitieiConstitutional Court Decision 440 of 8 July 2014 striking down Law 82/2012 on the retention of communications data
legislatie.just.ro
Link checked 18 August 2026
- Secondary sourceMediafaxConstitutional Court, May 2022: the legislator has still not enacted a new communications data retention law
mediafax.ro
Link checked 18 August 2026
- Official sourceAgentia Nationala de Administrare Fiscala (ANAF)Government Decision 111/2016 approving the methodological norms for gambling, articles 136-137 and the licensing annex
static.anaf.ro
“Sistemul informatic al organizatorului va asigura stocarea pe serverul de siguranta a datelor colectate, in forma in care au fost create, pentru o perioada minima de 6 ani de la data colectarii”
Link checked 18 August 2026
- Official sourceCurtea de Conturi a RomanieiCourt of Accounts audit report on the National Gambling Office, published 21 February 2025
curteadeconturi.ro
Link checked 18 August 2026
What's changing next
Three dated items. Since 11 March 2026, financial firms face Romanian penalties under the European digital resilience rules. Fines reach 10 percent of yearly turnover. Cyber security enforcement is ramping up after registration and the two orders of August 2025. And on 12 January 2027 a European rule cuts cloud switching and data export fees to zero. That will change every cloud contract you have.
- What you have to do here:
- Make switching cloud provider possible
Powers that already exist matter more here than pending bills. Romania has three. First and largest: the government legislates by emergency ordinance as a matter of routine. Both the cyber security rules and the financial resilience rules arrived that way. They were in force on publication, with Parliament approving later. So a rule keeping data in the country, or a new record-keeping duty, could appear overnight with no consultation. Second: Parliament can pass a new telecoms record-keeping law at any time. The Constitutional Court has twice noted that there is none. Any replacement would land on providers immediately. Third: the gambling regulator sets the technical rules for the safety and mirror servers by order of its president, not by statute. So what those servers must capture, and how fast, can change with no legislative process. Watch two European items as well. One is the cloud certification scheme, still not adopted. The other is the June 2026 European cloud and artificial intelligence proposal. Both would push public-sector work further towards hosting inside the country. Neither has legal effect today. We found no Romanian bill in progress that would force ordinary businesses to keep data in the country, checked 18 August 2026.
Sources
- Official sourcePortal Legislativ, Ministerul JustitieiEmergency Ordinance 14/2026 of 5 March 2026 implementing Regulation (EU) 2022/2554 (DORA), Official Gazette 188/2026
legislatie.just.ro
Link checked 18 August 2026
- Official sourceMinisterul FinantelorDraft emergency ordinance implementing Regulation (EU) 2022/2554 (DORA) - competent authorities and penalty scale, published for consultation 29 October 2025
mfinante.gov.ro
“amenda aplicabila entitatilor responsabile, de pana la 10% din cifra de afaceri anuala totala ... pana la 23.000.000 lei”
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2023/2854 (Data Act) - zero switching charges from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceLink may be brokenDirectoratul National de Securitate Cibernetica (DNSC)NIS2 legislation page of the National Cyber Security Directorate, listing Emergency Ordinance 155/2024 and Orders 1/2025 and 2/2025
dnsc.ro
Link checked 18 August 2026
- Secondary sourcecertSIGNImplementation of NIS2 in Romania - Emergency Ordinance 155/2024, approved by Law 124/2025, DNSC Orders 1/2025 and 2/2025 of 20 August 2025
certsign.ro
Link checked 18 August 2026
- Secondary sourcelitigio.netEmergency Ordinance 14/2026 implementing DORA, Official Gazette 188 of 11 March 2026 - competent authorities and penalty scale
litigio.net
Link checked 18 August 2026
What to do: Diarise 12 January 2027 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries2 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Online gaming data rules
Official name: Hotararea Guvernului nr. 111/2016 - Norme metodologice de punere in aplicare a OUG nr. 77/2009 privind organizarea si exploatarea jocurilor de noroc · Government Decision 111/2016, Official Gazette 151 of 26 February 2016, articles 136-139 and licensing annex · Directly binding regulation
Romania's only strict data-location rule for private business. Online gambling operators must keep a safety server and a mirror server physically in Romania. Those servers hold player identity, location, stakes, winnings and money movements, for at least six years. In February 2025 the Court of Accounts found the regulator had never actually connected to those servers.
Enforced by National Gambling Office
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryThe safety server and the mirror server must be on Romanian soil. Proof of location is a licensing document. The game server itself may sit anywhere in the European Union, European Economic Area or Switzerland.
- Keep data for a minimum period — 6 yearsSix years minimum on the safety server, in the form in which the data was created, then archived.
- Keep logs — within 24 hoursEvery transaction must reach the safety server within 24 hours. Daily consolidated reports go to the mirror server.
- Independent auditTechnical audit of the whole system by a class II licensed auditor, covering server locations, IP addresses, encryption and the automatic transfer mechanism.
- Appoint a representativeOperators licensed elsewhere in the European Economic Area or Switzerland must appoint an authorised representative with fiscal domicile or seat in Romania.
What it costs if you get it wrong
- Loss of your licenceFailure to prove the servers are on national territory blocks or ends the licence
- Criminal liabilityThe Court of Accounts referred aspects of gambling supervision to prosecutors in 2025
Sources
- Official sourceAgentia Nationala de Administrare Fiscala (ANAF)Government Decision 111/2016 approving the methodological norms for gambling, articles 136-137 and the licensing annex
static.anaf.ro
“Sistemul informatic al organizatorului va asigura stocarea pe serverul de siguranta a datelor colectate, in forma in care au fost create, pentru o perioada minima de 6 ani de la data colectarii”
Link checked 18 August 2026
- Official sourceLink may be brokenOficiul National pentru Jocuri de Noroc (ONJN)Government Decision 111/2016 - copy published by the National Gambling Office
onjn.gov.ro
Link checked 18 August 2026
- Official sourceCurtea de Conturi a RomanieiCourt of Accounts audit report on the National Gambling Office, published 21 February 2025
curteadeconturi.ro
Link checked 18 August 2026
- Secondary sourceavocatnet.roReport on the Court of Accounts findings: the gambling office never connected to the safe and mirror servers it licences
avocatnet.ro
Link checked 18 August 2026
Payment data rules
Official name: Ordonanta de urgenta nr. 14/2026 privind stabilirea unor masuri de punere in aplicare a Regulamentului (UE) nr. 2022/2554 · Emergency Ordinance 14/2026 of 5 March 2026, Official Gazette 188 of 11 March 2026 · Directly binding regulation
Romania's penalties for the European digital operational resilience rules for finance. The central bank supervises banks, payment and e-money firms. The financial supervisory authority covers investment firms, insurers and pension administrators. You must disclose where your provider keeps data. That place does not have to be Romania.
Enforced by National Bank of Romania
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Written vendor contractContracts with technology providers must say where data is used and stored. They must give audit and exit rights. You disclose the location. You are not restricted in choosing it.
- Report cyber incidents
- Keep records of how you use dataRegister of information on all technology outsourcing.
- Independent auditThe central bank is the single national authority coordinating threat-led penetration testing.
What it costs if you get it wrong
- Percentage of global turnover: 10% of total annual turnover, capped at RON 23,000,000 — about $5 millionEntities supervised by the central bank
- Percentage of global turnover: 5% of total annual turnover, or RON 10,000,000 — about $2 millionEntities supervised by the financial supervisory authority
- Fixed maximum fine: RON 23,000,000 — about $5 millionIndividually responsible persons, applied separately from the company fine
Sources
- Official sourceMinisterul FinantelorDraft emergency ordinance implementing Regulation (EU) 2022/2554 (DORA) - competent authorities and penalty scale, published for consultation 29 October 2025
mfinante.gov.ro
“amenda aplicabila entitatilor responsabile, de pana la 10% din cifra de afaceri anuala totala ... pana la 23.000.000 lei”
Link checked 18 August 2026
- Official sourcePortal Legislativ, Ministerul JustitieiEmergency Ordinance 14/2026 of 5 March 2026 implementing Regulation (EU) 2022/2554 (DORA), Official Gazette 188/2026
legislatie.just.ro
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2022/2554 (DORA), applicable since 17 January 2025
eur-lex.europa.eu
Link checked 18 August 2026
- Secondary sourcelitigio.netEmergency Ordinance 14/2026 implementing DORA, Official Gazette 188 of 11 March 2026 - competent authorities and penalty scale
litigio.net
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Europe's main privacy law (2018)
Official name: Legea nr. 190/2018 privind masuri de punere in aplicare a Regulamentului (UE) 2016/679 · Law 190 of 18 July 2018, Official Gazette 651 of 26 July 2018 · Act of parliament
Romania's national add-on to the European rules. It does not restrict where data is stored. It sets a strict 30-day limit on workplace monitoring recordings. It forces a data protection officer on anyone using national identification numbers for their own business interests. And it gives public bodies a warning first, with a low cap on fines.
Enforced by National Supervisory Authority for Personal Data Processing
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Appoint a data protection officer — applies at: Anyone processing a national identification number on a legitimate-interests basis, and public-interest processing where requiredThis trigger is Romanian and has no equivalent in the European Regulation.
- Delete data after a period — applies at: Electronic and video monitoring of employees, 1 monthStorage must be proportionate and no longer than 30 days, unless a specific law says otherwise or the case is strongly justified.
- Secure the dataData minimisation measures are a named condition for using national identification numbers.
- Tell people what you doEmployees must be fully and explicitly informed before monitoring starts.
- Get consentAutomated decisions or profiling based on genetic, biometric or health data need explicit consent, or a law that expressly allows it.
What it costs if you get it wrong
- Fixed maximum fine: RON 200,000 — about $45 thousandPublic authorities and bodies, including religious units and public-benefit associations, after a warning and a failed remediation plan
- Fixed maximum fine: RON 100,000 — about $22 thousandPublic bodies, lower band for controller and processor duties
- Percentage of global turnover: 4% of worldwide group turnoverPrivate companies, via the European Regulation
Sources
- Official sourceAutoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)Law 190/2018 on measures implementing the General Data Protection Regulation - full text hosted by the supervisory authority
dataprotection.ro
Link checked 18 August 2026
- Official sourceANSPDCPLegea nr. 190/2018 - announcement of entry into force, 31 July 2018
dataprotection.ro
Link checked 18 August 2026
- Official sourceANSPDCPPress release, 20 March 2026 - body-camera monitoring of employees, fines of 10,190 lei and 5,095 lei
dataprotection.ro
Link checked 18 August 2026
Breach reporting rules
Official name: Ordonanta de urgenta nr. 155/2024 privind instituirea unui cadru pentru securitatea cibernetica a retelelor si sistemelor informatice din spatiul cibernetic national civil · Emergency Ordinance 155/2024, approved with changes by Law 124/2025; DNSC Orders 1/2025 and 2/2025 of 20 August 2025 · Directly binding regulation
Romania's version of the European network and information security rules. It sets no requirement about where data is stored. What it does require is registration, and a layered incident reporting timetable starting at 24 hours. Its fines are based on turnover and are far larger than anything the privacy regulator hands out.
Enforced by National Cyber Security Directorate
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Register or notify — from 20 August 2025Essential and important entities had 30 days from 20 August 2025 to notify the directorate and register.
- Report cyber incidents — within 24 hoursEarly warning within 24 hours, fuller notification within 72 hours, final report within one month, as transposed from the European directive.
- Secure the data
- Independent audit
What it costs if you get it wrong
- Fixed maximum fine: €10,000,000 — about $12 millionEssential entities, or 2% of worldwide turnover if higher
- Fixed maximum fine: €7,000,000 — about $8 millionImportant entities, or 1.4% of worldwide turnover if higher
- Fixed maximum fine: RON 500,000 — about $113 thousandFailing to register as an essential entity
Sources
- Official sourcePortal Legislativ, Ministerul JustitieiEmergency Ordinance 155/2024 of 30 December 2024 establishing the cybersecurity framework for the civil national cyberspace (transposes Directive (EU) 2022/2555)
legislatie.just.ro
Link checked 18 August 2026
- Official sourceLink may be brokenDirectoratul National de Securitate Cibernetica (DNSC)NIS2 legislation page of the National Cyber Security Directorate, listing Emergency Ordinance 155/2024 and Orders 1/2025 and 2/2025
dnsc.ro
Link checked 18 August 2026
- Official sourceEUR-LexDirective (EU) 2022/2555 (NIS2) - Article 23 reporting deadlines
eur-lex.europa.eu
Link checked 18 August 2026
- Secondary sourcecertSIGNImplementation of NIS2 in Romania - Emergency Ordinance 155/2024, approved by Law 124/2025, DNSC Orders 1/2025 and 2/2025 of 20 August 2025
certsign.ro
Link checked 18 August 2026
Applies across the European Union1 rule
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Regulamentul general privind protectia datelor (Regulation (EU) 2016/679) · Regulation (EU) 2016/679; Regulation (EU) 2018/1807 · Directly binding regulation
The European layer. Data may leave Romania and leave Europe if you use an approved route. A separate European regulation stops Romania from making storage-in-country rules for data that is not about people. The only exception is public security.
Enforced by National Supervisory Authority for Personal Data Processing
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, To save someone’s life
What you have to do
- Tell people what you do
- Let people see their data
- Let people delete their data
- Let people take their data elsewhere
- Secure the data
- Keep records of how you use data
- Assess high-risk projects
- Written vendor contract
- Put a transfer safeguard in place
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Appoint a representativeOnly where you have no office in the European Union. The representative may sit in any member state.
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnoverBasic principles, individual rights, unlawful transfers, defying a regulator order
- Fixed maximum fine: €20,000,000 — about $23 millionSame tier, whichever is higher
- Order to stopOrder to stop processing or suspend transfers outside Europe
- Claims by individualsCompensation claims by affected individuals
Sources
- Official sourceEUR-LexRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 44-49, 83
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2018/1807 on the free flow of non-personal data - bans member state localisation except on public security grounds
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexCommission Implementing Decision (EU) 2021/914 - Standard Contractual Clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionEuropean Commission adequacy decisions, as listed on 18 August 2026
commission.europa.eu
Link checked 18 August 2026
On the books, but not enforceable1 rule
These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.
Telecoms rules
Official name: Decizia Curtii Constitutionale nr. 440/2014 privind Legea nr. 82/2012 · Constitutional Court Decision 440 of 8 July 2014; Law 82/2012 never replaced · Court decision
Romania has no telecoms data retention duty. The Constitutional Court struck the 2012 retention law down in July 2014 and Parliament has never replaced it, a point the court repeated in May 2022. What survives is the e-privacy law: delete traffic data when you no longer need it, and file breach reports on a separate form.
Enforced by National Supervisory Authority for Personal Data Processing
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Delete data after a periodTraffic data must be erased or made anonymous once it is no longer needed to carry the communication, subject to a billing exception.
- Report breaches to the regulatorProviders of publicly available electronic communications services notify the supervisory authority on a separate Law 506/2004 form, without delay.
What it costs if you get it wrong
- Percentage of global turnover: up to 2% of annual turnover for companies with revenue above RON 5,000,000Breach of Law 506/2004
- Fixed maximum fine: RON 5,000 to RON 100,000 — about $22 thousandBreach of Law 506/2004
Sources
- Official sourcePortal Legislativ, Ministerul JustitieiConstitutional Court Decision 440 of 8 July 2014 striking down Law 82/2012 on the retention of communications data
legislatie.just.ro
Link checked 18 August 2026
- Official sourcePortal Legislativ, Ministerul JustitieiLaw 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector
legislatie.just.ro
Link checked 18 August 2026
- Official sourceLink may be brokenAutoritatea Nationala pentru Administrare si Reglementare in Comunicatii (ANCOM)Law 506/2004 - copy published by the communications regulator
ancom.ro
Link checked 18 August 2026
- Official sourceANSPDCPBreach notification page - two separate forms, 'Notificare Bresa RGPD' and 'Notificare Bresa L.506/2004'
dataprotection.ro
Link checked 18 August 2026
- Secondary sourceMediafaxConstitutional Court, May 2022: the legislator has still not enacted a new communications data retention law
mediafax.ro
Link checked 18 August 2026
- Secondary sourceAsociatia pentru Tehnologie si Internet (APTI)Consolidated text of Law 506/2004 - traffic data erasure, breach notification and penalty scale
privacy.apti.ro
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact Romanian wording of the incident reporting deadlines in Emergency Ordinance 155/2024
We could not confirm the Romanian deadlines against the ordinance text. We report the 24 hour, 72 hour and one month deadlines as the deadlines of the European directive being copied across. Romanian legal commentary agrees. Check the Romanian text before you rely on the exact wording.
Whether Government Decision 111/2016 as amended still carries the safety and mirror server location wording
We could not confirm this against an up-to-date government text. The copy we read, hosted by the tax administration, is the original 2016 text from the Official Gazette. The rule appears unchanged in current commentary and in the licensing annex. But the gambling office and the legislation portal both refused automated access, so we could not check a 2026 consolidated version.
Whether payroll registers may now be kept five years rather than fifty
We could not confirm the payroll keeping period. A 2023 change to the Accounting Law is widely reported to allow five years, where the employer has filed the matching declarations with the pension authority. The Ministry of Finance copy we read is the earlier republished text showing fifty years. Plan for the longer period until this is confirmed.
Whether Emergency Ordinance 89/2022 requires Government Cloud data to be physically in Romania
We could not confirm that any law requires the government cloud to be inside Romania. The legislation portal, the digitalisation authority's site and the ministry pages would not open for us. The platform does appear to be built and run by Romanian state bodies on Romanian territory. But we could not quote an article making that a legal duty.
Whether any Romanian rule requires health data to stay in the country
We found no health rule requiring data to stay in Romania, checked 18 August 2026. The national health insurance house runs the electronic health record centrally. We found no duty on private healthcare providers to store data in Romania. Confidence is medium, because Romanian health law is spread across many texts we could not open. If you work in health, check before you rely on this.
Whether prepaid mobile subscriber identification has become law
We could not confirm this either way. The communications regulator said in August 2024 that no such requirement existed. Bills have appeared repeatedly. We found no law in force on 18 August 2026. But not finding one is not proof that none exists.
Rules on classified information systems and on geospatial or mapping data
We did not research this. Romania runs a separate approval process for classified information. It is likely to require accredited systems inside the country for anyone holding a national security clearance. Check directly if that applies to you.
The final published penalty figures in Emergency Ordinance 14/2026
We could not read the gazette text itself. We took the figures from the Ministry of Finance consultation draft, which we could open. We then cross-checked them against legal commentary on the published version.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.