Back to Frameworks

Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)

Romania
v2018 (GDPR implementation)
13 domains
28 controls

Romania's Law No. 190/2018 on measures for implementing EU Regulation 2016/679 (GDPR) supplements the GDPR with national provisions. The National Supervisory Authority for Personal Data Processing (ANSPDCP - Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal) oversees enforcement. The law includes provisions for the age of digital consent (16 years), processing of national identification numbers (CNP), genetic and biometric data, research derogations, and sector-specific rules for health and employment data.

Verified

Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation) is a compliance framework from Romania with 13 domains and 28 controls. The largest domains are National Derogations and Special Categories (6 controls), Accountability and Governance (4 controls), Supervision, Enforcement and Cooperation (4 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (13)

Accountability

1 controls
Controls in the Accountability domain of Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)1 controls
CodeTitle
ROMANIA-4DPIA, Privacy by Design, Accountability

Accountability and Governance

4 controls
Controls in the Accountability and Governance domain of Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)4 controls
CodeTitle
RO-LAW190-006Designation and Notification of the Data Protection Officer
RO-LAW190-011Records of Processing Activities
RO-LAW190-013Data Protection Impact Assessments
RO-LAW190-020Codes of Conduct and Certification

Breach and Enforcement

1 controls
Controls in the Breach and Enforcement domain of Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)1 controls
CodeTitle
ROMANIA-8Breach Notification, Enforcement

Cross-Border

1 controls
Controls in the Cross-Border domain of Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)1 controls
CodeTitle
ROMANIA-6International Transfer

Data Subject Rights and Consent

2 controls
Controls in the Data Subject Rights and Consent domain of Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)2 controls
CodeTitle
RO-LAW190-010Data Subject Rights Handling
RO-LAW190-015Children's Consent for Information Society Services

Governance

1 controls
Controls in the Governance domain of Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)1 controls
CodeTitle
ROMANIA-7DPO, ANSPDCP Cooperation, Training

High-Risk Processing

1 controls
Controls in the High-Risk Processing domain of Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)1 controls
CodeTitle
ROMANIA-3Special Categories, Children, Employee Monitoring

Individual Rights

1 controls
Controls in the Individual Rights domain of Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)1 controls
CodeTitle
ROMANIA-2Data Subject Rights

National Derogations and Special Categories

6 controls
Controls in the National Derogations and Special Categories domain of Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)6 controls
CodeTitle
RO-LAW190-001Lawful Basis for Processing Genetic, Biometric and Health Data
RO-LAW190-002Processing of National Identification Numbers (CNP)
RO-LAW190-003Processing of Personal Data by Political Parties and Non Profits
RO-LAW190-004Processing of Personal Data for Journalistic, Academic, Artistic or Literary Expression
RO-LAW190-005Workplace Monitoring of Employees
RO-LAW190-019Records Relating to Criminal Convictions and Offences

Scope and Lawful Basis

1 controls
Controls in the Scope and Lawful Basis domain of Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)1 controls
CodeTitle
ROMANIA-1GDPR Implementation, Scope, Lawful Basis (Romania)

Security and Processor

1 controls
Controls in the Security and Processor domain of Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)1 controls
CodeTitle
ROMANIA-5Security of Processing and Processor Agreements

Supervision, Enforcement and Cooperation

4 controls
Controls in the Supervision, Enforcement and Cooperation domain of Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)4 controls
CodeTitle
RO-LAW190-007Compliance with the National Supervisory Authority (ANSPDCP)
RO-LAW190-008Public Authorities and Corrective Measures
RO-LAW190-009Administrative Fines and Sanctions
RO-LAW190-018Cross Border Cooperation and One Stop Shop

Transfers, Breach and Electronic Communications

4 controls
Controls in the Transfers, Breach and Electronic Communications domain of Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)4 controls
CodeTitle
RO-LAW190-012International Data Transfers
RO-LAW190-014Personal Data Breach Notification
RO-LAW190-016Direct Marketing and Electronic Communications
RO-LAW190-017Cookies and Online Tracking

What is Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation) and who does it apply to?

Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation) is a compliance framework from Romania with 13 domains and 28 controls. Romania's Law No. 190/2018 on measures for implementing EU Regulation 2016/679 (GDPR) supplements the GDPR with national provisions. The National Supervisory Authority for Personal Data Processing (ANSPDCP - Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal) oversees enforcement. The law includes provisions for the age of digital consent (16 years), processing of national identification numbers (CNP), genetic and biometric data, research derogations, and sector-specific rules for health and employment data. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation) actually require?

Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation) has 28 controls organised across 13 domains. The largest domains are National Derogations and Special Categories (6 controls), Accountability and Governance (4 controls), Supervision, Enforcement and Cooperation (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation) do I already cover?

Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation) does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)?

Start your Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 28 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required