Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)
Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Accountability
Per GDPR + Law 190/2018: accountability instruments per GDPR Articles 25 + 30 + 35.
- Romania Law 190/2018 evidence for ROMANIA-4
- ANSPDCP notification + employee monitoring partial
Accountability and Governance
Controllers and processors required to designate a Data Protection Officer under the GDPR must notify the ANSPDCP of the DPO appointment and provide contact details. The DPO must be properly resourced and have direct access to the highest management level.
- DPO appointment letter
- Notification to ANSPDCP
- Published DPO contact details
- DPO reporting line documentation
- DPO appointed but not notified to the regulator
- DPO with conflicts of interest with other duties
- DPO not resourced sufficiently
Controllers and processors must maintain records of processing activities as required by Article 30 of the GDPR, in Romanian or in a language readily accessible to the supervisory authority, and make them available to ANSPDCP on request.
- Article 30 records register
- Periodic review schedule
- Romanian language version maintained or accessible
- Approval and ownership records
- Records only in English
- Records not reviewed annually
- Owners not assigned
A data protection impact assessment is required where processing is likely to result in a high risk to the rights and freedoms of natural persons. The ANSPDCP has published an indicative list of operations requiring a DPIA, including large scale processing of special category data and systematic monitoring.
- DPIA methodology
- Completed DPIAs aligned to the ANSPDCP list
- DPO consultation records
- Prior consultation requests to ANSPDCP where residual risk remains
- DPIAs treated as one off rather than living documents
- No DPO involvement in DPIAs
- Residual risk not escalated for prior consultation
Adherence to approved codes of conduct or certification mechanisms is an element to demonstrate compliance with the GDPR and Law No. 190/2018, including for international transfers and the imposition of corrective measures.
- Adherence statements to approved codes
- Certification body reports
- Internal audit evidence aligned to the code
- Monitoring body engagement records
- Code adherence claimed but not formally accepted
- Certification expired
- No internal audit referencing the code
Breach and Enforcement
Per GDPR Articles 33-34 + Law 190/2018: breach notification to ANSPDCP + enforcement.
- Romania Law 190/2018 evidence for ROMANIA-8
- ANSPDCP notification + employee monitoring partial
Cross-Border
Per GDPR Chapter V: international transfer restrictions.
- Romania Law 190/2018 evidence for ROMANIA-6
- ANSPDCP notification + employee monitoring partial
Data Subject Rights and Consent
Controllers must respond to data subject rights requests under the GDPR within one month, extendable by two further months for complex requests, with the data subject notified of the extension and reasons. Refusals must be communicated and include the right to lodge a complaint with ANSPDCP.
- Rights request register
- Standard response templates
- Identity verification procedure
- Internal escalation procedure for complex requests
- No central register of requests
- Identity verification inconsistent
- Refusal letters omit right to complain to ANSPDCP
Romania maintains the age of 16 as the threshold for valid consent to information society services offered directly to a child. Below that age, processing requires authorisation of the holder of parental responsibility.
- Age verification mechanism
- Parental consent records
- Privacy notice in child friendly language
- Records of withdrawal of consent
- No age gate on relevant services
- Parental consent mechanism easy to bypass
- Privacy notice not appropriate for younger audiences
Governance
Per GDPR + Law 190/2018: DPO + ANSPDCP cooperation + training.
- Romania Law 190/2018 evidence for ROMANIA-7
- ANSPDCP notification + employee monitoring partial
High-Risk Processing
Per Law 190/2018 + GDPR: special categories + children + employees. Romanian-specific provisions on employee monitoring + national ID processing.
- Romania Law 190/2018 evidence for ROMANIA-3
- ANSPDCP notification + employee monitoring partial
Individual Rights
Per GDPR + Law 190/2018: data subject rights. Standard GDPR rights handling with ANSPDCP-specific guidance.
- Romania Law 190/2018 evidence for ROMANIA-2
- ANSPDCP notification + employee monitoring partial
National Derogations and Special Categories
Processing of genetic, biometric or health data for the purpose of automated decision making or profiling, including for the conclusion or performance of an insurance or healthcare contract, is permitted only with the explicit consent of the data subject or where expressly authorised by law with appropriate safeguards.
- Records of processing identifying genetic, biometric and health data
- Documented lawful basis assessment
- Explicit consent records
- Safeguards documented in data protection impact assessment
- Reliance on legitimate interests rather than explicit consent or specific legal authorisation
- No DPIA covering automated decisions on health data
- Consent text bundled with other purposes
Processing of the personal numeric code (CNP), the series and number of identity documents or of other identifiers of general applicability is permitted only where a clear interest of the controller is established, with specific safeguards including a documented retention period and a designated person responsible for processing.
- Justification memo for processing CNP and similar identifiers
- Retention schedule for records containing the CNP
- Designation of the responsible person
- Access control records for systems holding the CNP
- CNP collected by default without documented need
- No retention period defined for CNP records
- No designated responsible person
Processing of personal data revealing political opinions or membership of unions, political parties or non profit organisations by such entities is permitted under conditions set by the controller for legitimate operational purposes, with appropriate safeguards and respect for data subject rights.
- Membership records system with documented purposes
- DPIA for political opinion processing
- Data subject rights handling procedures
- Statute or by laws referencing personal data handling
- No DPIA for political opinion processing
- Members not informed of their rights
- Excessive data collected beyond membership administration
Processing of personal data for journalistic, academic, artistic or literary expression is subject to exceptions from certain GDPR obligations where necessary to reconcile the right to data protection with the right to freedom of expression and information, with appropriate safeguards.
- Editorial policy on personal data handling
- Documented application of the journalism exemption
- Records of public interest balancing tests
- Complaints handling procedure
- No documented balancing test
- Editorial policy absent or out of date
- Failure to record application of the exemption
Where an employer uses electronic monitoring systems or other monitoring measures at the workplace, the legitimate interests of the employer must be balanced against employee fundamental rights, the monitoring must be necessary and proportionate, employees must be informed in advance, and a consultation with employee representatives must take place where applicable.
- Workplace monitoring policy
- Prior consultation records with employee representatives or unions
- DPIA covering monitoring measures
- Employee privacy notice referencing monitoring
- Records confirming employees were informed before deployment
- No DPIA for monitoring tools
- Employees informed only at induction without periodic refresh
- No prior consultation conducted
Processing of personal data relating to criminal convictions and offences may be carried out only under the control of official authority or when authorised by Romanian law providing for appropriate safeguards.
- Legal basis assessment for criminal data processing
- Documented safeguards
- Access restriction matrix
- Specific retention schedule
- Criminal data processed in HR systems without specific legal basis
- No documented safeguards
- Access not restricted on a need to know basis
Scope and Lawful Basis
Per Romania Law 190/2018 implementing GDPR: scope + lawful basis. Requirements include (a) implement GDPR + Romanian Law 190/2018 supplements + (b) establish lawful basis + (c) maintain Romanian-language documentation + (d) align with ANSPDCP (Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal).
- Romania Law 190/2018 evidence for ROMANIA-1
- ANSPDCP notification + employee monitoring partial
Security and Processor
Per GDPR + Law 190/2018: security + processor management.
- Romania Law 190/2018 evidence for ROMANIA-5
- ANSPDCP notification + employee monitoring partial
Supervision, Enforcement and Cooperation
Controllers and processors must cooperate with the ANSPDCP, provide requested information within set deadlines and implement corrective measures imposed by the authority. Obstruction of supervisory tasks is a contravention.
- Register of ANSPDCP correspondence
- Responses to ANSPDCP information requests
- Implementation plans for corrective measures
- Records of follow up communications
- Late responses to information requests
- No central register of regulator correspondence
- Corrective measures not implemented within deadlines
For public authorities and bodies, the supervisory authority may apply corrective measures including warnings, reprimands and orders, but administrative fines may only be applied for specific contraventions and subject to a remediation plan agreed with the authority.
- Public authority remediation plan
- Records of supervisory authority engagement
- Internal audit reports
- Training records for public sector personnel
- No remediation plan when corrective measures are imposed
- No documented internal audit cycle
- Training overlooked for non IT staff
Administrative fines may be imposed by ANSPDCP for breaches of GDPR or of Law No. 190/2018, taking into account the nature, gravity and duration of the infringement, the categories of personal data affected, the level of cooperation with the authority and any previous infringements.
- Compliance risk register entry
- Records of cooperation with ANSPDCP
- Mitigation evidence for incidents
- Board reports on enforcement risk
- No formal risk register entry
- Incident records lack mitigation steps
- Board not informed of enforcement risk
Where ANSPDCP acts as lead supervisory authority or concerned authority under the GDPR one stop shop mechanism, controllers must cooperate with the consistency procedure and any joint operations, and may be subject to binding decisions of the European Data Protection Board.
- Lead supervisory authority determination
- Group entity structure mapping main establishment
- Records of one stop shop submissions
- Compliance with EDPB decisions
- Main establishment not formally identified
- Inconsistent positions taken before different supervisory authorities
- EDPB guidelines not embedded in policies
Transfers, Breach and Electronic Communications
Transfers of personal data outside the European Economic Area are subject to the conditions set by Chapter V of the GDPR. Controllers must implement appropriate safeguards such as Standard Contractual Clauses and conduct transfer impact assessments where required.
- Transfer register
- Executed Standard Contractual Clauses
- Transfer impact assessments
- Supplementary measures documentation
- No transfer register
- Missing transfer impact assessments for high risk jurisdictions
- Outdated SCC versions in use
Controllers must notify ANSPDCP of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to natural persons. Affected individuals must be notified where the breach is likely to result in a high risk.
- Breach response procedure
- Internal breach register
- Notifications submitted to ANSPDCP
- Affected person notification templates
- No documented procedure for breach severity assessment
- Breach register incomplete
- Notification timelines missed
Direct marketing communications by electronic means are subject to consent or, in the case of an existing customer relationship, to a soft opt in with the right to object made available in each communication. Marketing databases must be kept up to date and respect opt outs.
- Marketing consent records
- Opt out and suppression list
- Sample direct marketing message with unsubscribe link
- Audit log of suppression list updates
- Suppression list not honoured across systems
- Soft opt in applied beyond similar products and services
- Unsubscribe links broken
Storing or accessing information on a user's terminal device, including through cookies and similar technologies, requires prior informed consent except where strictly necessary to provide the service requested by the user.
- Cookie banner configuration evidence
- Cookie policy
- Consent management platform logs
- Audit of strictly necessary classification
- Pre ticked cookie boxes
- Tracking before consent obtained
- No granular controls for advertising cookies
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.