RO — Country Profile

Romania

5TOTAL
5OFFICIAL SOURCES
1TOPIC AREAS
Law / Act3
National Strategy1
Other1
19 JAN 2026 · Other

National Supervisory Authority for Personal Data Processing investigation into Continental Automotive Products SRL over alleged failure to protect employee data

On 19 January 2026, the National Supervisory Authority for Personal Data Processing (ANSPDCP) imposed fines totalling EUR 15'000 (RON 25'455 and RON 50'911) against Continental Automotive Products SRL for breaches of the General Data Protection Regulation. The ANSPDCP imposed a EUR 5'000 fine for infringements of Article 5(1)(c) and Article 5(2) on data minimisation and accountability, and a EUR 10'000 fine for infringements of Article 32(1)(b) and Article 32(2) on the security of processing....

Official materialNational StrategyOfficial source · dataprotection.ro ↗
30 APR 2025 · Law / Act

Data Protection Authority investigation into Bitdefender over alleged GDPR violations following email security breach

On 30 April 2025, the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) concluded an investigation into Bitdefender SRL and found violations of Article 32(1)(b) and (d), as well as Article 32(2) of the General Data Protection Regulation (GDPR). As a result, the company was fined RON 49’772. The investigation was initiated following a personal data breach notification submitted by Bitdefender SRL under Article 33 of the GDPR. The breach was caused by a programming ...

Primary legal sourceNational StrategyOfficial source · dataprotection.ro ↗
20 JAN 2025 · Law / Act

ANSPDCP investigation into Vodafone Romania regarding GDPR compliance in telecom services

On 20 January 2025, the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) issued a ruling against Vodafone Romania for breaching Articles 32(4) and 32(1)(b) of the General Data Protection Regulation (GDPR). Vodafone was fined RON 74’526 (EUR 15’000) for failing to ensure the confidentiality of customer data, including names, personal identification numbers, and addresses. The Investigation revealed unauthorised data disclosures via invoice photos shared with third...

Primary legal sourceNational StrategyOfficial source · dataprotection.ro ↗
28 OCT 2024 · Law / Act

ANSPDCP investigation into Vodafone's GDPR compliance

On 28 October 2024, the National Supervisory Authority for the Processing of Personal Data in Romania (ANSPDCP) concluded an investigation into Vodafone Romania SA, identifying a breach of Article 32 of the General Data Protection Regulation (GDPR). The investigation, initiated from a complaint about the improper disclosure of email addresses in communications regarding account manager changes, revealed that Vodafone Romania SA failed to implement adequate technical and organisational measure...

Primary legal sourceNational StrategyOfficial source · dataprotection.ro ↗
National Strategy

Romanian AI Legislative Proposal L255/2024 (Rejected)

AI law in Romania: No published, consolidated Romanian "AI Act Implementation Law" was located. The closest primary national instrument is a parliamentary proposal titled "Propunere legislativă....

Official materialNational StrategyOfficial source · eur-lex.europa.eu ↗