Skip to content
これは参考訳です。英語版が正式かつ法的拘束力を持つ公式バージョンです。 英語版を表示
ROMEDIUM coverage1 enforcement action

Romania — ANSPDCP + EU AI Act + Romanian AI Strategy: AI Compliance Requirements

Romania's National Supervisory Authority for Personal Data Processing (ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal) enforces GDPR. Romania published its national AI strategy through the Ministry of Research, Innovation and Digitalization. Romania has a growing IT sector and is a destination for AI R&D centres. Romania is fully subject to the EU AI Act and participates in the European AI Board.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 2021

Enforcement Begins

August 2, 2026

Maximum Penalty

GDPR (ANSPDCP): up to €20M or 4% global turnover. EU AI Act: €35M or 7% global turnover.

What Your Business Must Do

2 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

EU AI Act Compliance (Mandatory)

Critical

Romania is subject to the EU AI Act. AI systems deployed in Romania or processing Romanian residents' data must comply. High-risk AI systems in financial services (BNR oversight), healthcare (MS oversight), and public administration require conformity assessment and registration in the EU database. NOTE: the EU AI Act high-risk (Annex III) conformity-assessment deadline was deferred EU-wide from 2026-08-02 to 2027-12-02 by the "Digital Omnibus" amendment, Regulation (EU) 2026/1744 (in force 2026-07-27) -- Article 50 transparency obligations still apply from 2026-08-02, but conformity assessment/technical documentation/registration for stand-alone high-risk systems is not due until 2027-12-02 (2028-08-02 for Annex I product-embedded high-risk systems).

Deadline: December 2, 2027

EU AI Act Art. 6, Annex III (high-risk classification); Art. 16 (provider obligations); Art. 43 (conformity assessment); Art. 26 (deployer obligations)

ANSPDCP GDPR Compliance for AI

High Priority

ANSPDCP requires DPIA for AI profiling and automated decision-making affecting Romanian residents. Document legal basis for all AI training data. Implement individual rights mechanisms (access, erasure, objection) within GDPR timelines. ANSPDCP has issued guidance on data minimization for AI training.

GDPR Art. 22 (automated decisions); Art. 35 (DPIA); Art. 21 (right to object to profiling)

Who Does This Apply To?

Applies to: any organisation established in Romania, and any organisation outside Romania processing the personal data of Romanian residents through AI systems — GDPR applies with extraterritorial reach (Art. 3), obligations attaching to the processing activity rather than company size, with no general small-business exemption. As an EU member state, Romania is fully subject to the EU AI Act: AI deployed in Romania or processing Romanian residents' data must be risk-classified, and high-risk AI in financial services (BNR oversight), healthcare (MS oversight) and public administration requires conformity assessment and EU-database registration. The National Supervisory Authority for Personal Data Processing (ANSPDCP) requires a DPIA for AI profiling and automated decision-making, a documented lawful basis for AI training data (legitimate interest requires a balancing test weighing training benefits against individual rights), and fulfilment of individual rights including the Article 21 right to object to AI-inferred profiling. Penalties reach €20M / 4% of global turnover under GDPR and €35M / 7% under the EU AI Act.

Recent Enforcement Actions

2023-08-21Source verified· as of 2026-08-22

Against:

Recent Regulatory Guidance

guidance2024

ANSPDCP — DPIA-Mandatory Processing List (includes AI profiling)

ANSPDCP's published list of processing operations requiring a mandatory DPIA includes systematic and comprehensive evaluation of personal aspects relating to natural persons, based on automated processing and/or profiling, that produces legal or similarly significant effects — directly covering AI-driven scoring, eligibility, and recommendation systems. The EU Omnibus Directive (2019/2161), transposed into Romanian consumer-protection law, separately requires traders to disclose personalised pricing based on automated profiling, with the pre-personalization reference price shown clearly.

Frequently Asked Questions

Does Romania — ANSPDCP + EU AI Act + Romanian AI Strategy apply to my business?

Romania's National Supervisory Authority for Personal Data Processing (ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal) enforces GDPR. Romania published its national AI strategy through the Ministry of… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Romania — ANSPDCP + EU AI Act + Romanian AI Strategy is: GDPR (ANSPDCP): up to €20M or 4% global turnover. EU AI Act: €35M or 7% global turnover.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Romania — ANSPDCP + EU AI Act + Romanian AI Strategy?

The 2 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.dataprotection.ro

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan