Romania
Part of the European Union, so bloc-wide rules apply here too. Checked yesterday.
The answer
Romania follows the European rulebook. For almost every business, data may leave the country and leave Europe, as long as you use one of the approved European transfer routes. Two areas break that pattern: online gambling companies must keep the master copy of player and betting records on servers physically in Romania, and public bodies are being moved onto a state-run cloud. The privacy regulator works and publishes decisions, but its fines are small.
Data governance in Romania
The eight things that decide how you handle data about people in Romania. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Romania has no separate test of its own. The European Union's General Data Protection Regulation decides who is caught, and it catches any company anywhere in the world that offers goods or services to people in Romania, or that monitors what they do here. There is no revenue floor and no headcount floor. If your business has no establishment anywhere in the European Union you must appoint a representative inside the Union, though that person does not have to be in Romania.
Romania's national add-on is Law 190/2018, in force since 31 July 2018. It does not change who is covered; it adds duties on top for particular kinds of processing. Two Romanian-specific scope points matter. First, Law 190/2018 defines 'public authorities and bodies' very widely and expressly treats religious units and public-benefit associations and foundations as public bodies, which pulls them into the softer penalty track. Second, a genuine in-country personnel requirement exists in gambling: an operator licensed elsewhere in the European Economic Area or Switzerland that serves Romanian players must appoint an authorised representative whose fiscal domicile or seat is on Romanian territory, empowered to act before Romanian authorities.
Sources
- Official sourceEUR-LexRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 44-49, 83
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceAutoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)Law 190/2018 on measures implementing the General Data Protection Regulation - full text hosted by the supervisory authority
dataprotection.ro
Link checked 18 August 2026
- Official sourceAgentia Nationala de Administrare Fiscala (ANAF)Government Decision 111/2016 approving the methodological norms for gambling, articles 136-137 and the licensing annex
static.anaf.ro
“Sistemul informatic al organizatorului va asigura stocarea pe serverul de siguranta a datelor colectate, in forma in care au fost create, pentru o perioada minima de 6 ani de la data colectarii”
Link checked 18 August 2026
Where the data is allowed to live
For nearly every business, yes. Romania has passed no law telling ordinary companies to keep data inside the country, and European Union law actually forbids member states from doing that for non-personal data except on national security grounds. The exception that bites hardest is online gambling: the authoritative copy of player and betting records must sit on servers in Romania. Public-sector systems are the other exception, because the state is moving them into its own cloud.
Sector by sector, checked on 18 August 2026. BANKING, PAYMENTS, INSURANCE AND SECURITIES: no localisation found. Romania implemented the European digital resilience rules by emergency ordinance in March 2026, naming the central bank and the financial supervisory authority as enforcers; those rules demand that you know and disclose where your provider processes data, and that you can exit, but they do not require the data to be in Romania. HEALTH: no localisation rule found on official sources, checked 18 August 2026; the national health insurance house runs the electronic health record centrally, but that is a state system, not a duty on private firms. TELECOM: no localisation, and, unusually, no retention duty either. GOVERNMENT: the Government Cloud Platform is built and run by state bodies on Romanian territory and public institutions are being migrated onto it; treat public-sector work as in-country by default. GAMBLING: hard rule, see below. EDUCATION, ONLINE RETAIL, SOCIAL MEDIA: no sector rule found. DEFENCE AND CLASSIFIED MATERIAL: Romania runs a separate accreditation regime for classified information systems which we did not verify in this pass. MAPPING AND GEOSPATIAL: no rule found, low confidence. The gambling rule is the real wall. The methodological norms require that the 'safety server' and the 'mirror server' be located on national territory, that every transaction reach the safety server within 24 hours, and that the data stay there in original form for at least six years. The game server itself may sit anywhere in the European Union, the European Economic Area or Switzerland, so this is a mirror requirement rather than a total ban on processing abroad.
Sources
- Official sourceAgentia Nationala de Administrare Fiscala (ANAF)Government Decision 111/2016 approving the methodological norms for gambling, articles 136-137 and the licensing annex
static.anaf.ro
“Sistemul informatic al organizatorului va asigura stocarea pe serverul de siguranta a datelor colectate, in forma in care au fost create, pentru o perioada minima de 6 ani de la data colectarii”
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2018/1807 on the free flow of non-personal data - bans member state localisation except on public security grounds
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 44-49, 83
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceMinisterul FinantelorDraft emergency ordinance implementing Regulation (EU) 2022/2554 (DORA) - competent authorities and penalty scale, published for consultation 29 October 2025
mfinante.gov.ro
“amenda aplicabila entitatilor responsabile, de pana la 10% din cifra de afaceri anuala totala ... pana la 23.000.000 lei”
Link checked 18 August 2026
- Official sourceANCOMANCOM press release on prepaid telecom cards, 29 August 2024 - no identification requirement described
ancom.ro
“legislatia din domeniul comunicatiilor electronice nu stabileste conditii concrete privind furnizarea serviciilor de comunicatii electronice prin intermediul cartelelor preplatite”
Link checked 18 August 2026
Sending data out of the country
Use one of the European routes and Romania asks for nothing extra. There is no Romanian registration, no notification, and no permit for sending personal data abroad. The routes are: the destination country is on the European Commission's approved list, or you sign the European Union's standard contract clauses, or you have approved binding corporate rules, or you fall inside one of the narrow one-off exceptions. Anything you write yourself still needs the regulator's sign-off.
The model is an approved-list plus approved-paperwork system, and the approved list is well populated: Andorra, Argentina, Brazil, Canada for commercial bodies, the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay, and the United States only for companies that have self-certified under the European Union - United States Data Privacy Framework. The 2021 standard contract clauses remain the operative set and have not been amended; the promised new clauses for importers already directly covered by the Regulation are still not adopted. A transfer risk assessment is still expected. Bespoke, non-standard clauses need prior authorisation from the Romanian supervisory authority. One point worth knowing: European guidance finalised in June 2025 says an order from a non-European government is not by itself a lawful reason to hand data over. The most time-sensitive item is the European Union - United States framework: it is valid today, but it is under appeal at the European Court of Justice and in July 2026 the European Data Protection Board formally asked the Commission to re-examine it. Do not build a single-route architecture on it.
Sources
- Official sourceEUR-LexRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 44-49, 83
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionEuropean Commission adequacy decisions, as listed on 18 August 2026
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexCommission Implementing Decision (EU) 2021/914 - Standard Contractual Clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEDPB letter to Commissioner McGrath, 31 July 2026, on the EU-US Data Privacy Framework
edpb.europa.eu
Link checked 18 August 2026
- Official sourceAutoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)Law 190/2018 on measures implementing the General Data Protection Regulation - full text hosted by the supervisory authority
dataprotection.ro
Link checked 18 August 2026
The regulator, and whether it actually acts
The National Supervisory Authority for Personal Data Processing, and it genuinely works. It publishes sanction decisions most months, and it was still doing so in August 2026. It also takes the lead in cross-border cases handed to it by other European regulators. The catch is size: typical fines run from about 1,000 to 11,000 euros, roughly 1,200 to 13,000 dollars, so the deterrent is reputational more than financial. Cyber security, telecoms, banking, insurance and gambling each have their own separate regulator.
Evidence of live enforcement, from the authority's own site: a fine of 57,839 lei, about 11,000 euros, on 1 July 2026 in a case where France's regulator handed Romania the lead; fines of 10,190 lei and 5,095 lei on 20 March 2026 for filming employees with body cameras without telling them; and further published sanctions dated 2, 17 and 31 July and 6 August 2026. The authority is headed by a president, Ancuta Gianina Opre. Two enforcement gaps are worth naming. First, public bodies get a warning and a written remediation plan before any fine, and their fines are capped at 200,000 lei, roughly 45,000 dollars. Second, and more striking, Romania's Court of Accounts reported in February 2025 that the National Gambling Office had never actually connected to or monitored the safety and mirror servers it requires operators to install, meaning the country's strictest data-location rule has been largely unpoliced. The rule is in force; the policing of it is not.
Sources
- Official sourceANSPDCPDecizii publicate / published sanction decisions and press releases, list current to 6 August 2026
dataprotection.ro
Link checked 18 August 2026
- Official sourceANSPDCPPress release, 1 July 2026 - cross-border case, Ascendex Technology SRL fined 57,839 lei (11,000 euro)
dataprotection.ro
“Ascendex Technology SRL ... amenda in cuantum de 57.839 lei (echivalentul a 11.000 EUR)”
Link checked 18 August 2026
- Official sourceANSPDCPPress release, 20 March 2026 - body-camera monitoring of employees, fines of 10,190 lei and 5,095 lei
dataprotection.ro
Link checked 18 August 2026
- Official sourceAutoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)Law 190/2018 on measures implementing the General Data Protection Regulation - full text hosted by the supervisory authority
dataprotection.ro
Link checked 18 August 2026
- Official sourceCurtea de Conturi a RomanieiCourt of Accounts audit report on the National Gambling Office, published 21 February 2025
curteadeconturi.ro
Link checked 18 August 2026
- Secondary sourceavocatnet.roReport on the Court of Accounts findings: the gambling office never connected to the safe and mirror servers it licences
avocatnet.ro
Link checked 18 August 2026
How long you must keep it — and when to delete it
Both directions apply, and they can pull against each other. The floor: accounting books and the paperwork behind them must be kept ten years, annual accounts ten years, and payroll registers fifty years. Online gambling records must sit on the Romanian safety server for at least six years. The ceiling: recordings and logs from monitoring staff at work must not be kept longer than thirty days.
The thirty-day cap on workplace monitoring data is the one that surprises people, and it is written into Law 190/2018 as an absolute unless a specific law says otherwise or the case is strongly justified. On the floor side, Accounting Law 82/1991 sets the ten-year rule and the fifty-year payroll rule; a 2023 amendment allows payroll registers to be kept only five years where the employer has filed the corresponding declarations with the pension authority, which we flag as needing confirmation against the consolidated text. Telecoms traffic data must be erased or anonymised once it is no longer needed to carry the communication, except for billing, where it may be kept until the claim is time-barred. Where a floor and a ceiling collide, the floor generally wins, because the law creating it is the 'legal obligation' that justifies keeping the data - but that logic only rescues the specific records the law names, not everything sitting in the same database. Law 190/2018 also makes writing down retention periods a formal condition, not just good practice, whenever you rely on legitimate interests to handle someone's national identification number or you process in the public interest.
Sources
- Official sourceMinisterul FinantelorAccounting Law 82/1991, republished, article 25 and article 35 - record retention periods
mfinante.gov.ro
“Registrele de contabilitate obligatorii si documentele justificative care stau la baza inregistrarilor in contabilitatea financiara se pastreaza in arhiva persoanelor prevazute la art.1 timp de 10 ani ... cu exceptia statelor de salarii, care se pastreaza timp de 50 de ani.”
Link checked 18 August 2026
- Official sourceAutoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)Law 190/2018 on measures implementing the General Data Protection Regulation - full text hosted by the supervisory authority
dataprotection.ro
Link checked 18 August 2026
- Official sourceAgentia Nationala de Administrare Fiscala (ANAF)Government Decision 111/2016 approving the methodological norms for gambling, articles 136-137 and the licensing annex
static.anaf.ro
“Sistemul informatic al organizatorului va asigura stocarea pe serverul de siguranta a datelor colectate, in forma in care au fost create, pentru o perioada minima de 6 ani de la data colectarii”
Link checked 18 August 2026
- Official sourcePortal Legislativ, Ministerul JustitieiLaw 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector
legislatie.just.ro
Link checked 18 August 2026
- Secondary sourceAsociatia pentru Tehnologie si Internet (APTI)Consolidated text of Law 506/2004 - traffic data erasure, breach notification and penalty scale
privacy.apti.ro
Link checked 18 August 2026
If something goes wrong
There are up to four clocks and they do not line up. Every organisation has 72 hours to tell the privacy regulator about a personal data breach. Telecoms and internet providers have a second, faster duty under a separate law and a separate form. Companies classed as essential or important for cyber security must send a first alert within 24 hours, a fuller report within 72 hours, and a final report within a month. Banks, insurers and investment firms have their own financial-sector reporting on top.
The privacy regulator publishes two distinct breach forms on its own site, one for the General Data Protection Regulation and one for Law 506/2004, which is the practical proof that the two regimes run in parallel rather than one absorbing the other. Providers of publicly available electronic communications services must notify without delay under Law 506/2004, with the detailed European rules on that notification setting a 24-hour initial deadline. The cyber security clocks come from Emergency Ordinance 155/2024, which transposed the European network and information security directive on 30 December 2024, was approved with changes by Law 124/2025 in July 2025, and was operationalised by two orders of the National Cyber Security Directorate on 20 August 2025 that also opened a 30-day window for entities to register themselves. We report the 24 hour, 72 hour and one month deadlines as the transposed directive deadlines; we could not open the Romanian text directly because the directorate's site blocks automated access, so treat the exact Romanian wording as unconfirmed. The most common operational failure here is a single incident-response runbook written to one deadline. If you are a bank that is also an essential entity and you lose customer records, all four clocks start at once.
Sources
- Official sourceANSPDCPBreach notification page - two separate forms, 'Notificare Bresa RGPD' and 'Notificare Bresa L.506/2004'
dataprotection.ro
Link checked 18 August 2026
- Official sourcePortal Legislativ, Ministerul JustitieiEmergency Ordinance 155/2024 of 30 December 2024 establishing the cybersecurity framework for the civil national cyberspace (transposes Directive (EU) 2022/2555)
legislatie.just.ro
Link checked 18 August 2026
- Official sourceEUR-LexDirective (EU) 2022/2555 (NIS2) - Article 23 reporting deadlines
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceLink may be brokenDirectoratul National de Securitate Cibernetica (DNSC)NIS2 legislation page of the National Cyber Security Directorate, listing Emergency Ordinance 155/2024 and Orders 1/2025 and 2/2025
dnsc.ro
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 44-49, 83
eur-lex.europa.eu
Link checked 18 August 2026
- Secondary sourcecertSIGNImplementation of NIS2 in Romania - Emergency Ordinance 155/2024, approved by Law 124/2025, DNSC Orders 1/2025 and 2/2025 of 20 August 2025
certsign.ro
Link checked 18 August 2026
What catches people out
Five things that are not in the summary. One: recordings from monitoring staff at work must be deleted after thirty days. Two: if you use a person's national identification number and your reason is your own business interest, you are legally required to appoint a data protection officer, even if nothing else in European law would force one. Three: Romanian public bodies get a warning first and can only be fined about 45,000 dollars, so suing or complaining about a state body rarely produces a big result. Four: Romania has no telecoms data retention law, so old call records may simply not exist. Five: online gambling has a hard in-country server rule and a Romanian representative requirement.
On trap two, the trigger is broader than people expect. Romanian law treats the personal numeric code, identity card series and number, passport number, driving licence number and health insurance number all as 'national identification numbers'. Using any of them on a legitimate-interests basis brings four cumulative conditions: technical and organisational measures aimed at data minimisation, a named data protection officer, written storage and deletion deadlines, and periodic training for the staff who touch the data. Since almost every Romanian contract, invoice and HR file carries the personal numeric code, this quietly catches a lot of foreign employers. On trap three, the softer regime also covers religious units and public-benefit associations and foundations, which are treated as public bodies. On trap four, the Constitutional Court struck down the 2012 retention law in July 2014 and repeated in May 2022 that the legislator had still not replaced it; that is a gap in evidence availability, not a privacy win, and it can be closed by Parliament at any time. Trap five carries a criminal edge too: the Court of Accounts referred aspects of gambling supervision to prosecutors in 2025, so this is not a purely administrative area.
Sources
- Official sourceAutoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)Law 190/2018 on measures implementing the General Data Protection Regulation - full text hosted by the supervisory authority
dataprotection.ro
Link checked 18 August 2026
- Official sourcePortal Legislativ, Ministerul JustitieiConstitutional Court Decision 440 of 8 July 2014 striking down Law 82/2012 on the retention of communications data
legislatie.just.ro
Link checked 18 August 2026
- Secondary sourceMediafaxConstitutional Court, May 2022: the legislator has still not enacted a new communications data retention law
mediafax.ro
Link checked 18 August 2026
- Official sourceAgentia Nationala de Administrare Fiscala (ANAF)Government Decision 111/2016 approving the methodological norms for gambling, articles 136-137 and the licensing annex
static.anaf.ro
“Sistemul informatic al organizatorului va asigura stocarea pe serverul de siguranta a datelor colectate, in forma in care au fost create, pentru o perioada minima de 6 ani de la data colectarii”
Link checked 18 August 2026
- Official sourceCurtea de Conturi a RomanieiCourt of Accounts audit report on the National Gambling Office, published 21 February 2025
curteadeconturi.ro
Link checked 18 August 2026
What's changing next
Three dated items. Financial firms have been exposed to Romanian penalties for the European digital resilience rules since 11 March 2026, with fines reaching 10 percent of yearly turnover. Cyber security enforcement is ramping up after registration and the two implementing orders of August 2025. And on 12 January 2027 a European rule makes cloud switching and data export fees zero, which will change every cloud contract you have.
Dormant switches matter more here than pending bills, and Romania has three. First and largest: the government legislates by emergency ordinance as a matter of routine. Both the cyber security framework and the financial resilience rules arrived that way, in force on publication, with Parliament approving later. A localisation or retention duty could therefore appear overnight with no consultation. Second: Parliament can re-enact a telecoms data retention law at any time. The Constitutional Court has twice noted the absence of one, and any replacement would land on providers immediately. Third: the gambling regulator sets the technical procedure for the safety and mirror servers by order of its president rather than by statute, so what those servers must capture, and how fast, can be changed without any legislative process. Watch also the still-unadopted European cloud certification scheme and the June 2026 European cloud and artificial intelligence proposal, both of which would push public-sector work further towards in-country hosting; neither has legal effect today. We found no Romanian bill in progress that would impose data localisation on ordinary businesses, checked 18 August 2026.
Sources
- Official sourcePortal Legislativ, Ministerul JustitieiEmergency Ordinance 14/2026 of 5 March 2026 implementing Regulation (EU) 2022/2554 (DORA), Official Gazette 188/2026
legislatie.just.ro
Link checked 18 August 2026
- Official sourceMinisterul FinantelorDraft emergency ordinance implementing Regulation (EU) 2022/2554 (DORA) - competent authorities and penalty scale, published for consultation 29 October 2025
mfinante.gov.ro
“amenda aplicabila entitatilor responsabile, de pana la 10% din cifra de afaceri anuala totala ... pana la 23.000.000 lei”
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2023/2854 (Data Act) - zero switching charges from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceLink may be brokenDirectoratul National de Securitate Cibernetica (DNSC)NIS2 legislation page of the National Cyber Security Directorate, listing Emergency Ordinance 155/2024 and Orders 1/2025 and 2/2025
dnsc.ro
Link checked 18 August 2026
- Secondary sourcecertSIGNImplementation of NIS2 in Romania - Emergency Ordinance 155/2024, approved by Law 124/2025, DNSC Orders 1/2025 and 2/2025 of 20 August 2025
certsign.ro
Link checked 18 August 2026
- Secondary sourcelitigio.netEmergency Ordinance 14/2026 implementing DORA, Official Gazette 188 of 11 March 2026 - competent authorities and penalty scale
litigio.net
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Hotararea Guvernului nr. 111/2016 - Norme metodologice de punere in aplicare a OUG nr. 77/2009 privind organizarea si exploatarea jocurilor de noroc
Directly binding regulation · Government Decision 111/2016, Official Gazette 151 of 26 February 2016, articles 136-139 and licensing annex
Romania's only hard data-location rule for private business. Online gambling operators must keep a safety server and a mirror server physically in Romania, holding player identity, geolocation, stakes, winnings and money movements, for at least six years. In February 2025 the Court of Accounts found the regulator had never actually connected to those servers.
Enforced by National Gambling Office
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryThe safety server and the mirror server must be located on Romanian national territory; proof of location is a licensing document. The game server itself may sit anywhere in the European Union, European Economic Area or Switzerland.
- Keep data for a minimum period — 6 yearsSix years minimum on the safety server, in the form in which the data was created, then archived.
- Keep logs — within 24 hoursEvery transaction must reach the safety server within 24 hours; daily consolidated reports go to the mirror server.
- Independent auditTechnical audit of the whole system by a class II licensed auditor, covering server locations, IP addresses, encryption and the automatic transfer mechanism.
- Appoint a local representativeOperators licensed elsewhere in the European Economic Area or Switzerland must appoint an authorised representative with fiscal domicile or seat in Romania.
What it costs if you get it wrong
- Loss of your licenceFailure to prove the servers are on national territory blocks or ends the licence
- Criminal liabilityThe Court of Accounts referred aspects of gambling supervision to prosecutors in 2025
Sources
- Official sourceAgentia Nationala de Administrare Fiscala (ANAF)Government Decision 111/2016 approving the methodological norms for gambling, articles 136-137 and the licensing annex
static.anaf.ro
“Sistemul informatic al organizatorului va asigura stocarea pe serverul de siguranta a datelor colectate, in forma in care au fost create, pentru o perioada minima de 6 ani de la data colectarii”
Link checked 18 August 2026
- Official sourceLink may be brokenOficiul National pentru Jocuri de Noroc (ONJN)Government Decision 111/2016 - copy published by the National Gambling Office
onjn.gov.ro
Link checked 18 August 2026
- Official sourceCurtea de Conturi a RomanieiCourt of Accounts audit report on the National Gambling Office, published 21 February 2025
curteadeconturi.ro
Link checked 18 August 2026
- Secondary sourceavocatnet.roReport on the Court of Accounts findings: the gambling office never connected to the safe and mirror servers it licences
avocatnet.ro
Link checked 18 August 2026
Ordonanta de urgenta nr. 14/2026 privind stabilirea unor masuri de punere in aplicare a Regulamentului (UE) nr. 2022/2554
Directly binding regulation · Emergency Ordinance 14/2026 of 5 March 2026, Official Gazette 188 of 11 March 2026
Romania's penalty framework for the European digital operational resilience rules for finance. The central bank supervises banks, payment and e-money firms; the financial supervisory authority covers investment firms, insurers and pension administrators. It requires you to disclose where your provider keeps data, but it does not require that place to be Romania.
Enforced by National Bank of Romania
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Written vendor contractContracts with technology providers must state where data is processed and stored, and give audit and exit rights. Location must be disclosed, not restricted.
- Report cyber incidents
- Keep records of processingRegister of information on all technology outsourcing.
- Independent auditThe central bank is the single national authority coordinating threat-led penetration testing.
What it costs if you get it wrong
- Percentage of global turnover: 10% of total annual turnover, capped at RON 23,000,000 — about $5 millionEntities supervised by the central bank
- Percentage of global turnover: 5% of total annual turnover, or RON 10,000,000 — about $2 millionEntities supervised by the financial supervisory authority
- Fixed maximum fine: RON 23,000,000 — about $5 millionIndividually responsible persons, applied separately from the company fine
Sources
- Official sourceMinisterul FinantelorDraft emergency ordinance implementing Regulation (EU) 2022/2554 (DORA) - competent authorities and penalty scale, published for consultation 29 October 2025
mfinante.gov.ro
“amenda aplicabila entitatilor responsabile, de pana la 10% din cifra de afaceri anuala totala ... pana la 23.000.000 lei”
Link checked 18 August 2026
- Official sourcePortal Legislativ, Ministerul JustitieiEmergency Ordinance 14/2026 of 5 March 2026 implementing Regulation (EU) 2022/2554 (DORA), Official Gazette 188/2026
legislatie.just.ro
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2022/2554 (DORA), applicable since 17 January 2025
eur-lex.europa.eu
Link checked 18 August 2026
- Secondary sourcelitigio.netEmergency Ordinance 14/2026 implementing DORA, Official Gazette 188 of 11 March 2026 - competent authorities and penalty scale
litigio.net
Link checked 18 August 2026
Decizia Curtii Constitutionale nr. 440/2014 privind Legea nr. 82/2012
Court decision · Constitutional Court Decision 440 of 8 July 2014; Law 82/2012 never replaced
Romania has no telecoms data retention duty. The Constitutional Court struck the 2012 retention law down in July 2014 and Parliament has never replaced it, a point the court repeated in May 2022. What survives is the e-privacy law: delete traffic data when you no longer need it, and file breach reports on a separate form.
Enforced by National Supervisory Authority for Personal Data Processing
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Delete data after a periodTraffic data must be erased or made anonymous once it is no longer needed to carry the communication, subject to a billing exception.
- Report breaches to the regulatorProviders of publicly available electronic communications services notify the supervisory authority on a separate Law 506/2004 form, without delay.
What it costs if you get it wrong
- Percentage of global turnover: up to 2% of annual turnover for companies with revenue above RON 5,000,000Breach of Law 506/2004
- Fixed maximum fine: RON 5,000 to RON 100,000 — about $22 thousandBreach of Law 506/2004
Sources
- Official sourcePortal Legislativ, Ministerul JustitieiConstitutional Court Decision 440 of 8 July 2014 striking down Law 82/2012 on the retention of communications data
legislatie.just.ro
Link checked 18 August 2026
- Official sourcePortal Legislativ, Ministerul JustitieiLaw 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector
legislatie.just.ro
Link checked 18 August 2026
- Official sourceLink may be brokenAutoritatea Nationala pentru Administrare si Reglementare in Comunicatii (ANCOM)Law 506/2004 - copy published by the communications regulator
ancom.ro
Link checked 18 August 2026
- Official sourceANSPDCPBreach notification page - two separate forms, 'Notificare Bresa RGPD' and 'Notificare Bresa L.506/2004'
dataprotection.ro
Link checked 18 August 2026
- Secondary sourceMediafaxConstitutional Court, May 2022: the legislator has still not enacted a new communications data retention law
mediafax.ro
Link checked 18 August 2026
- Secondary sourceAsociatia pentru Tehnologie si Internet (APTI)Consolidated text of Law 506/2004 - traffic data erasure, breach notification and penalty scale
privacy.apti.ro
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Legea nr. 190/2018 privind masuri de punere in aplicare a Regulamentului (UE) 2016/679
Act of parliament · Law 190 of 18 July 2018, Official Gazette 651 of 26 July 2018
Romania's national add-on to the European rules. It does not restrict where data is stored. It adds a hard 30-day ceiling on workplace monitoring data, forces a data protection officer on anyone using national identification numbers for their own business interests, and gives public bodies a warning-first process with a low fine cap.
Enforced by National Supervisory Authority for Personal Data Processing
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Appoint a data protection officer — applies at: Anyone processing a national identification number on a legitimate-interests basis, and public-interest processing where requiredThis trigger is Romanian and has no equivalent in the European Regulation.
- Delete data after a period — applies at: Electronic and video monitoring of employees, 1 monthStorage must be proportionate and no longer than 30 days, unless a specific law says otherwise or the case is strongly justified.
- Secure the dataData minimisation measures are a named condition for using national identification numbers.
- Tell people what you doEmployees must be fully and explicitly informed before monitoring starts.
- Get consentExplicit consent or an express legal provision is required for automated decisions or profiling based on genetic, biometric or health data.
What it costs if you get it wrong
- Fixed maximum fine: RON 200,000 — about $45 thousandPublic authorities and bodies, including religious units and public-benefit associations, after a warning and a failed remediation plan
- Fixed maximum fine: RON 100,000 — about $22 thousandPublic bodies, lower band for controller and processor duties
- Percentage of global turnover: 4% of worldwide group turnoverPrivate companies, via the European Regulation
Sources
- Official sourceAutoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)Law 190/2018 on measures implementing the General Data Protection Regulation - full text hosted by the supervisory authority
dataprotection.ro
Link checked 18 August 2026
- Official sourceANSPDCPLegea nr. 190/2018 - announcement of entry into force, 31 July 2018
dataprotection.ro
Link checked 18 August 2026
- Official sourceANSPDCPPress release, 20 March 2026 - body-camera monitoring of employees, fines of 10,190 lei and 5,095 lei
dataprotection.ro
Link checked 18 August 2026
Ordonanta de urgenta nr. 155/2024 privind instituirea unui cadru pentru securitatea cibernetica a retelelor si sistemelor informatice din spatiul cibernetic national civil
Directly binding regulation · Emergency Ordinance 155/2024, approved with changes by Law 124/2025; DNSC Orders 1/2025 and 2/2025 of 20 August 2025
Romania's transposition of the European network and information security rules. It imposes no storage location requirement. What it does impose is registration, a layered incident reporting timetable starting at 24 hours, and turnover-based fines that are far larger than anything the privacy regulator hands out.
Enforced by National Cyber Security Directorate
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notify — from 20 August 2025Essential and important entities had 30 days from 20 August 2025 to notify the directorate and register.
- Report cyber incidents — within 24 hoursEarly warning within 24 hours, fuller notification within 72 hours, final report within one month, as transposed from the European directive.
- Secure the data
- Independent audit
What it costs if you get it wrong
- Fixed maximum fine: €10,000,000 — about $12 millionEssential entities, or 2% of worldwide turnover if higher
- Fixed maximum fine: €7,000,000 — about $8 millionImportant entities, or 1.4% of worldwide turnover if higher
- Fixed maximum fine: RON 500,000 — about $113 thousandFailing to register as an essential entity
Sources
- Official sourcePortal Legislativ, Ministerul JustitieiEmergency Ordinance 155/2024 of 30 December 2024 establishing the cybersecurity framework for the civil national cyberspace (transposes Directive (EU) 2022/2555)
legislatie.just.ro
Link checked 18 August 2026
- Official sourceLink may be brokenDirectoratul National de Securitate Cibernetica (DNSC)NIS2 legislation page of the National Cyber Security Directorate, listing Emergency Ordinance 155/2024 and Orders 1/2025 and 2/2025
dnsc.ro
Link checked 18 August 2026
- Official sourceEUR-LexDirective (EU) 2022/2555 (NIS2) - Article 23 reporting deadlines
eur-lex.europa.eu
Link checked 18 August 2026
- Secondary sourcecertSIGNImplementation of NIS2 in Romania - Emergency Ordinance 155/2024, approved by Law 124/2025, DNSC Orders 1/2025 and 2/2025 of 20 August 2025
certsign.ro
Link checked 18 August 2026
Applies across the European Union1 rule
Written once for the whole bloc, and in force in every member country.
Regulamentul general privind protectia datelor (Regulation (EU) 2016/679)
Directly binding regulation · Regulation (EU) 2016/679; Regulation (EU) 2018/1807
The European layer. Data may leave Romania and leave Europe if you use an approved route. A separate European regulation actually forbids Romania from imposing storage-in-country rules on non-personal data except on public security grounds.
Enforced by National Supervisory Authority for Personal Data Processing
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk
What it makes you do
- Tell people what you do
- Let people see their data
- Let people delete their data
- Let people take their data elsewhere
- Secure the data
- Keep records of processing
- Assess high-risk projects
- Written vendor contract
- Put a transfer safeguard in place
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Appoint a local representativeOnly where the organisation has no establishment in the European Union. The representative may sit in any member state.
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnoverBasic principles, individual rights, unlawful transfers, defying a regulator order
- Fixed maximum fine: €20,000,000 — about $23 millionSame tier, whichever is higher
- Order to stopOrder to stop processing or suspend transfers outside Europe
- Claims by individualsCompensation claims by affected individuals
Sources
- Official sourceEUR-LexRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 44-49, 83
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexRegulation (EU) 2018/1807 on the free flow of non-personal data - bans member state localisation except on public security grounds
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexCommission Implementing Decision (EU) 2021/914 - Standard Contractual Clauses
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionEuropean Commission adequacy decisions, as listed on 18 August 2026
commission.europa.eu
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact Romanian wording of the incident reporting deadlines in Emergency Ordinance 155/2024
The cyber security directorate's website is behind bot protection and the official legislation portal blocks automated fetching. We report the 24 hour, 72 hour and one month deadlines as the deadlines of the European directive being transposed, corroborated by Romanian legal commentary, not from the ordinance text itself.
Whether Government Decision 111/2016 as amended still carries the safety and mirror server location wording
The copy we opened, hosted by the tax administration, is the original 2016 text as published in the Official Gazette. The rule appears unchanged in current commentary and in the licensing annex, but we could not open a consolidated 2026 version on a government site because the gambling office and the legislation portal both refused automated access.
Whether payroll registers may now be kept five years rather than fifty
A 2023 amendment to the Accounting Law is widely reported to allow five years where the employer has filed the matching declarations with the pension authority. The Ministry of Finance copy we opened is the earlier republished text showing fifty years. Plan to the longer period until this is confirmed.
Whether Emergency Ordinance 89/2022 requires Government Cloud data to be physically in Romania
Neither the legislation portal, the digitalisation authority's site, nor the ministry pages would open for us. The platform is in practice built and run by Romanian state bodies on Romanian territory, but we could not quote an article imposing that as a legal duty.
Whether any Romanian rule requires health data to stay in the country
No rule found, checked 18 August 2026. The national health insurance house runs the electronic health record centrally, but we found no obligation on private healthcare providers to store data in Romania. Confidence medium because Romanian health legislation is spread across many instruments we could not fetch.
Whether prepaid mobile subscriber identification has become law
The communications regulator said in August 2024 that no such requirement existed. Bills have appeared repeatedly. We found no evidence of a law in force on 18 August 2026, but we cannot prove a negative.
Rules on classified information systems and on geospatial or mapping data
Not researched in this pass. Romania runs a separate accreditation regime for classified information which is likely to require in-country, accredited systems for anyone holding a national security clearance.
The final published penalty figures in Emergency Ordinance 14/2026
We read the figures from the Ministry of Finance consultation draft, which we could open, and cross-checked them against legal commentary on the published version. The gazette text itself was not directly readable.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Romania versus
Compare