Skip to content

Evidence request lists

Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)

Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Accountability

ROMANIA-4
DPIA, Privacy by Design, Accountability

Per GDPR + Law 190/2018: accountability instruments per GDPR Articles 25 + 30 + 35.

Artefacts an auditor will ask for
  • Romania Law 190/2018 evidence for ROMANIA-4
Where this commonly fails
  • ANSPDCP notification + employee monitoring partial

Accountability and Governance

RO-LAW190-006
Designation and Notification of the Data Protection Officer

Controllers and processors required to designate a Data Protection Officer under the GDPR must notify the ANSPDCP of the DPO appointment and provide contact details. The DPO must be properly resourced and have direct access to the highest management level.

Artefacts an auditor will ask for
  • DPO appointment letter
  • Notification to ANSPDCP
  • Published DPO contact details
  • DPO reporting line documentation
Where this commonly fails
  • DPO appointed but not notified to the regulator
  • DPO with conflicts of interest with other duties
  • DPO not resourced sufficiently
RO-LAW190-011
Records of Processing Activities

Controllers and processors must maintain records of processing activities as required by Article 30 of the GDPR, in Romanian or in a language readily accessible to the supervisory authority, and make them available to ANSPDCP on request.

Artefacts an auditor will ask for
  • Article 30 records register
  • Periodic review schedule
  • Romanian language version maintained or accessible
  • Approval and ownership records
Where this commonly fails
  • Records only in English
  • Records not reviewed annually
  • Owners not assigned
RO-LAW190-013
Data Protection Impact Assessments

A data protection impact assessment is required where processing is likely to result in a high risk to the rights and freedoms of natural persons. The ANSPDCP has published an indicative list of operations requiring a DPIA, including large scale processing of special category data and systematic monitoring.

Artefacts an auditor will ask for
  • DPIA methodology
  • Completed DPIAs aligned to the ANSPDCP list
  • DPO consultation records
  • Prior consultation requests to ANSPDCP where residual risk remains
Where this commonly fails
  • DPIAs treated as one off rather than living documents
  • No DPO involvement in DPIAs
  • Residual risk not escalated for prior consultation
RO-LAW190-020
Codes of Conduct and Certification

Adherence to approved codes of conduct or certification mechanisms is an element to demonstrate compliance with the GDPR and Law No. 190/2018, including for international transfers and the imposition of corrective measures.

Artefacts an auditor will ask for
  • Adherence statements to approved codes
  • Certification body reports
  • Internal audit evidence aligned to the code
  • Monitoring body engagement records
Where this commonly fails
  • Code adherence claimed but not formally accepted
  • Certification expired
  • No internal audit referencing the code

Breach and Enforcement

ROMANIA-8
Breach Notification, Enforcement

Per GDPR Articles 33-34 + Law 190/2018: breach notification to ANSPDCP + enforcement.

Artefacts an auditor will ask for
  • Romania Law 190/2018 evidence for ROMANIA-8
Where this commonly fails
  • ANSPDCP notification + employee monitoring partial

Cross-Border

ROMANIA-6
International Transfer

Per GDPR Chapter V: international transfer restrictions.

Artefacts an auditor will ask for
  • Romania Law 190/2018 evidence for ROMANIA-6
Where this commonly fails
  • ANSPDCP notification + employee monitoring partial

Data Subject Rights and Consent

RO-LAW190-010
Data Subject Rights Handling

Controllers must respond to data subject rights requests under the GDPR within one month, extendable by two further months for complex requests, with the data subject notified of the extension and reasons. Refusals must be communicated and include the right to lodge a complaint with ANSPDCP.

Artefacts an auditor will ask for
  • Rights request register
  • Standard response templates
  • Identity verification procedure
  • Internal escalation procedure for complex requests
Where this commonly fails
  • No central register of requests
  • Identity verification inconsistent
  • Refusal letters omit right to complain to ANSPDCP
RO-LAW190-015
Children's Consent for Information Society Services

Romania maintains the age of 16 as the threshold for valid consent to information society services offered directly to a child. Below that age, processing requires authorisation of the holder of parental responsibility.

Artefacts an auditor will ask for
  • Age verification mechanism
  • Parental consent records
  • Privacy notice in child friendly language
  • Records of withdrawal of consent
Where this commonly fails
  • No age gate on relevant services
  • Parental consent mechanism easy to bypass
  • Privacy notice not appropriate for younger audiences

Governance

ROMANIA-7
DPO, ANSPDCP Cooperation, Training

Per GDPR + Law 190/2018: DPO + ANSPDCP cooperation + training.

Artefacts an auditor will ask for
  • Romania Law 190/2018 evidence for ROMANIA-7
Where this commonly fails
  • ANSPDCP notification + employee monitoring partial

High-Risk Processing

ROMANIA-3
Special Categories, Children, Employee Monitoring

Per Law 190/2018 + GDPR: special categories + children + employees. Romanian-specific provisions on employee monitoring + national ID processing.

Artefacts an auditor will ask for
  • Romania Law 190/2018 evidence for ROMANIA-3
Where this commonly fails
  • ANSPDCP notification + employee monitoring partial

Individual Rights

ROMANIA-2
Data Subject Rights

Per GDPR + Law 190/2018: data subject rights. Standard GDPR rights handling with ANSPDCP-specific guidance.

Artefacts an auditor will ask for
  • Romania Law 190/2018 evidence for ROMANIA-2
Where this commonly fails
  • ANSPDCP notification + employee monitoring partial

National Derogations and Special Categories

RO-LAW190-001
Lawful Basis for Processing Genetic, Biometric and Health Data

Processing of genetic, biometric or health data for the purpose of automated decision making or profiling, including for the conclusion or performance of an insurance or healthcare contract, is permitted only with the explicit consent of the data subject or where expressly authorised by law with appropriate safeguards.

Artefacts an auditor will ask for
  • Records of processing identifying genetic, biometric and health data
  • Documented lawful basis assessment
  • Explicit consent records
  • Safeguards documented in data protection impact assessment
Where this commonly fails
  • Reliance on legitimate interests rather than explicit consent or specific legal authorisation
  • No DPIA covering automated decisions on health data
  • Consent text bundled with other purposes
RO-LAW190-002
Processing of National Identification Numbers (CNP)

Processing of the personal numeric code (CNP), the series and number of identity documents or of other identifiers of general applicability is permitted only where a clear interest of the controller is established, with specific safeguards including a documented retention period and a designated person responsible for processing.

Artefacts an auditor will ask for
  • Justification memo for processing CNP and similar identifiers
  • Retention schedule for records containing the CNP
  • Designation of the responsible person
  • Access control records for systems holding the CNP
Where this commonly fails
  • CNP collected by default without documented need
  • No retention period defined for CNP records
  • No designated responsible person
RO-LAW190-003
Processing of Personal Data by Political Parties and Non Profits

Processing of personal data revealing political opinions or membership of unions, political parties or non profit organisations by such entities is permitted under conditions set by the controller for legitimate operational purposes, with appropriate safeguards and respect for data subject rights.

Artefacts an auditor will ask for
  • Membership records system with documented purposes
  • DPIA for political opinion processing
  • Data subject rights handling procedures
  • Statute or by laws referencing personal data handling
Where this commonly fails
  • No DPIA for political opinion processing
  • Members not informed of their rights
  • Excessive data collected beyond membership administration
RO-LAW190-004
Processing of Personal Data for Journalistic, Academic, Artistic or Literary Expression

Processing of personal data for journalistic, academic, artistic or literary expression is subject to exceptions from certain GDPR obligations where necessary to reconcile the right to data protection with the right to freedom of expression and information, with appropriate safeguards.

Artefacts an auditor will ask for
  • Editorial policy on personal data handling
  • Documented application of the journalism exemption
  • Records of public interest balancing tests
  • Complaints handling procedure
Where this commonly fails
  • No documented balancing test
  • Editorial policy absent or out of date
  • Failure to record application of the exemption
RO-LAW190-005
Workplace Monitoring of Employees

Where an employer uses electronic monitoring systems or other monitoring measures at the workplace, the legitimate interests of the employer must be balanced against employee fundamental rights, the monitoring must be necessary and proportionate, employees must be informed in advance, and a consultation with employee representatives must take place where applicable.

Artefacts an auditor will ask for
  • Workplace monitoring policy
  • Prior consultation records with employee representatives or unions
  • DPIA covering monitoring measures
  • Employee privacy notice referencing monitoring
  • Records confirming employees were informed before deployment
Where this commonly fails
  • No DPIA for monitoring tools
  • Employees informed only at induction without periodic refresh
  • No prior consultation conducted
RO-LAW190-019
Records Relating to Criminal Convictions and Offences

Processing of personal data relating to criminal convictions and offences may be carried out only under the control of official authority or when authorised by Romanian law providing for appropriate safeguards.

Artefacts an auditor will ask for
  • Legal basis assessment for criminal data processing
  • Documented safeguards
  • Access restriction matrix
  • Specific retention schedule
Where this commonly fails
  • Criminal data processed in HR systems without specific legal basis
  • No documented safeguards
  • Access not restricted on a need to know basis

Scope and Lawful Basis

ROMANIA-1
GDPR Implementation, Scope, Lawful Basis (Romania)

Per Romania Law 190/2018 implementing GDPR: scope + lawful basis. Requirements include (a) implement GDPR + Romanian Law 190/2018 supplements + (b) establish lawful basis + (c) maintain Romanian-language documentation + (d) align with ANSPDCP (Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal).

Artefacts an auditor will ask for
  • Romania Law 190/2018 evidence for ROMANIA-1
Where this commonly fails
  • ANSPDCP notification + employee monitoring partial

Security and Processor

ROMANIA-5
Security of Processing and Processor Agreements

Per GDPR + Law 190/2018: security + processor management.

Artefacts an auditor will ask for
  • Romania Law 190/2018 evidence for ROMANIA-5
Where this commonly fails
  • ANSPDCP notification + employee monitoring partial

Supervision, Enforcement and Cooperation

RO-LAW190-007
Compliance with the National Supervisory Authority (ANSPDCP)

Controllers and processors must cooperate with the ANSPDCP, provide requested information within set deadlines and implement corrective measures imposed by the authority. Obstruction of supervisory tasks is a contravention.

Artefacts an auditor will ask for
  • Register of ANSPDCP correspondence
  • Responses to ANSPDCP information requests
  • Implementation plans for corrective measures
  • Records of follow up communications
Where this commonly fails
  • Late responses to information requests
  • No central register of regulator correspondence
  • Corrective measures not implemented within deadlines
RO-LAW190-008
Public Authorities and Corrective Measures

For public authorities and bodies, the supervisory authority may apply corrective measures including warnings, reprimands and orders, but administrative fines may only be applied for specific contraventions and subject to a remediation plan agreed with the authority.

Artefacts an auditor will ask for
  • Public authority remediation plan
  • Records of supervisory authority engagement
  • Internal audit reports
  • Training records for public sector personnel
Where this commonly fails
  • No remediation plan when corrective measures are imposed
  • No documented internal audit cycle
  • Training overlooked for non IT staff
RO-LAW190-009
Administrative Fines and Sanctions

Administrative fines may be imposed by ANSPDCP for breaches of GDPR or of Law No. 190/2018, taking into account the nature, gravity and duration of the infringement, the categories of personal data affected, the level of cooperation with the authority and any previous infringements.

Artefacts an auditor will ask for
  • Compliance risk register entry
  • Records of cooperation with ANSPDCP
  • Mitigation evidence for incidents
  • Board reports on enforcement risk
Where this commonly fails
  • No formal risk register entry
  • Incident records lack mitigation steps
  • Board not informed of enforcement risk
RO-LAW190-018
Cross Border Cooperation and One Stop Shop

Where ANSPDCP acts as lead supervisory authority or concerned authority under the GDPR one stop shop mechanism, controllers must cooperate with the consistency procedure and any joint operations, and may be subject to binding decisions of the European Data Protection Board.

Artefacts an auditor will ask for
  • Lead supervisory authority determination
  • Group entity structure mapping main establishment
  • Records of one stop shop submissions
  • Compliance with EDPB decisions
Where this commonly fails
  • Main establishment not formally identified
  • Inconsistent positions taken before different supervisory authorities
  • EDPB guidelines not embedded in policies

Transfers, Breach and Electronic Communications

RO-LAW190-012
International Data Transfers

Transfers of personal data outside the European Economic Area are subject to the conditions set by Chapter V of the GDPR. Controllers must implement appropriate safeguards such as Standard Contractual Clauses and conduct transfer impact assessments where required.

Artefacts an auditor will ask for
  • Transfer register
  • Executed Standard Contractual Clauses
  • Transfer impact assessments
  • Supplementary measures documentation
Where this commonly fails
  • No transfer register
  • Missing transfer impact assessments for high risk jurisdictions
  • Outdated SCC versions in use
RO-LAW190-014
Personal Data Breach Notification

Controllers must notify ANSPDCP of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to natural persons. Affected individuals must be notified where the breach is likely to result in a high risk.

Artefacts an auditor will ask for
  • Breach response procedure
  • Internal breach register
  • Notifications submitted to ANSPDCP
  • Affected person notification templates
Where this commonly fails
  • No documented procedure for breach severity assessment
  • Breach register incomplete
  • Notification timelines missed
RO-LAW190-016
Direct Marketing and Electronic Communications

Direct marketing communications by electronic means are subject to consent or, in the case of an existing customer relationship, to a soft opt in with the right to object made available in each communication. Marketing databases must be kept up to date and respect opt outs.

Artefacts an auditor will ask for
  • Marketing consent records
  • Opt out and suppression list
  • Sample direct marketing message with unsubscribe link
  • Audit log of suppression list updates
Where this commonly fails
  • Suppression list not honoured across systems
  • Soft opt in applied beyond similar products and services
  • Unsubscribe links broken
RO-LAW190-017
Cookies and Online Tracking

Storing or accessing information on a user's terminal device, including through cookies and similar technologies, requires prior informed consent except where strictly necessary to provide the service requested by the user.

Artefacts an auditor will ask for
  • Cookie banner configuration evidence
  • Cookie policy
  • Consent management platform logs
  • Audit of strictly necessary classification
Where this commonly fails
  • Pre ticked cookie boxes
  • Tracking before consent obtained
  • No granular controls for advertising cookies
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.