Checked on September 27, 2026
GDPR in Romania
How the GDPR works in Romania: the supervisory authority, the national law that supplements the regulation, and where to notify a breach.
- Supervisory authority
- National Supervisory Authority for Personal Data Processing (ANSPDCP) (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal)
- National law supplementing the GDPR
- Law 190/2018 on measures implementing Regulation (EU) 2016/679 · Legea nr. 190/2018 privind măsuri de punere în aplicare a Regulamentului (UE) 2016/679 · Legea nr. 190/2018
- Age of digital consent
- 16
- Breach notification
- www.dataprotection.ro/?page=pagina_formular_679
- National specifics
- Breach notifications use the standard form approved by ANSPDCP Decision 128/2018, submitted online.
Where does your company stand?
The free assessment applies these national rules to your answers and scores every area of the law.
Sources
National laws and portals change. This page is general information, not legal advice; confirm with the authority before relying on it.