A practical review of eight years of enforcement: ANSPDCP activity, top sanctions and what the Digital Omnibus changes.
27 April 2026 marks 10 years since Regulation (EU) 2016/679 (GDPR) was officially adopted, and 25 May 2026 marks 8 years since the date GDPR became directly applicable in Romania. This article offers a practical review of the eight years of GDPR enforcement in the country: how the activity of the National Supervisory Authority (ANSPDCP) has evolved, which are the largest fines imposed on Romanian controllers, how Romania compares with the rest of the European Union, and what major legislative changes lie ahead through the European Commission's "Digital Omnibus" initiative, published on 19 November 2025.
The figures for Romania: over 41,000 complaints received cumulatively by ANSPDCP between 2018 and 2025, approximately 370 fines imposed, with a total estimated value of more than RON 11.1 million (the equivalent of ~EUR 2.2 million). The largest fine initially imposed is EUR 150,000 (Raiffeisen Bank, October 2019), later reduced by the court to EUR 15,000. The largest fine that became final is EUR 100,000 — Banca Transilvania, confirmed by the Cluj Court of Appeal on 14 April 2022.
The two milestones — 10 years since adoption and 8 years since application — are not mere calendar dates. They represent a complete maturity cycle for a piece of European law: the first two years were dedicated to preparation (May 2016 – May 2018), and the following eight years were years of real enforcement, with national case law, complementary legislative changes and a visible learning curve for both controllers and ANSPDCP.
For an organisation, the benchmark year 2026 means two practical things.
First, it is the right moment for a position audit: eight years after the initial implementation, many GDPR policies and procedures have become outdated or no longer reflect operational reality.
Second, it is the threshold from which major legislative changes begin to take effect — "Digital Omnibus", DORA, NIS2, the AI Act, the Data Act — which require a rethinking of the compliance programme, not merely a continuation of the existing one.
The National Supervisory Authority for Personal Data Processing is the autonomous administrative authority with legal personality, under parliamentary control. As of 25 May 2018, ANSPDCP operates as a supervisory authority within the meaning of Article 51 GDPR, with direct powers in resolving complaints, conducting investigations, applying sanctions and representing Romania in the European Data Protection Board (EDPB).
Over the 8 years of GDPR enforcement, ANSPDCP has gone through three distinct stages:
The frequency of press releases has risen steadily: in just the first 4 months of 2026, ANSPDCP published over 18 communications regarding sanctions or decisions.
A statistical summary of the 8 years of real GDPR enforcement in Romania:
| Year | Complaints | Investigations | No. of fines | Amount (RON) |
|---|---|---|---|---|
| 2018 | 4,822 | — | ≈10 | 631,500 |
| 2019 | 6,193 | 912 | 28 | 2,339,291 |
| 2020 | 5,480 | 694 | 29 | 892,115 |
| 2021 | 5,006 | 691 | 36 | 371,131 |
| 2022 | 4,260 | — | 52 | 1,058,863 |
| 2023 | 4,772 | — | 49 | 2,348,265 |
| 2024 | 5,354 | — | 83 | 1,667,859 |
| 2025* | ≈5,100 | — | 85 | ≈1,785,000 |
*The data for 2025 are partial, pending publication of the official ANSPDCP annual report.
The number of complaints and notifications received annually by ANSPDCP has stabilised around 5,000, with a clear peak in 2019 (6,193) and a renewed increase in 2024 (5,354). The 2019 peak has two causes: the "post-application panic" effect (the public became aware of GDPR's existence and filed large volumes of complaints) and the heavily publicised banking cases of that period.
For clients, the signal is clear: data subjects are active and use the mechanisms offered by GDPR. The internal processes for handling Data Subject Requests (DSR) are no longer a nice-to-have, but an operational obligation with sanctioning consequences if the 30-day deadline set out in Article 12(3) GDPR is exceeded.
The evolution in the number of fines is the most telling indicator of the maturing of GDPR enforcement in Romania. From approximately 10 fines in 2018 (the year of entry into application, with an emphasis on warnings) to 85 in 2025, we are talking about an increase of more than eightfold.
The growth is explained by the conclusion of investigation phases started in previous years, the standardisation of the authority's internal procedures, and the consolidation of practice across different categories of violation (cookies, direct marketing, DSR rights, security).
Unlike the number of fines (constantly rising), the total value fluctuates significantly — with peaks in 2019 (RON 2.33 million) and 2023 (RON 2.35 million) and a low in 2021 (RON 0.37 million). This variation reflects two realities: the large, high-profile sanctions from the early days of enforcement (Raiffeisen, Unicredit, ING) significantly increase the totals for those years, while ANSPDCP's practice remains predominantly oriented towards medium and small fines (under EUR 10,000 per case), in line with the principle of proportionality.
Cumulatively for the period 2018–2025, the total value of GDPR fines imposed in Romania exceeds RON 11.1 million (the equivalent of approximately EUR 2.2 million).
| # | Controller | Amount (EUR) | Year / Date | Main reason |
|---|---|---|---|---|
| 1 | Raiffeisen Bank S.A. | 150,000 / 15,000* | Oct 2019 | Article 32 GDPR — inadequate security; transmission of customer data to Vreau Credit via WhatsApp. *Reduced in court to EUR 15,000. |
| 2 | Unicredit Bank S.A. | 130,000 | Jun 2019 | Article 25 GDPR — privacy by design/by default; exposure of personal ID number (CNP) and address on public documents. The first GDPR fine imposed in Romania. |
| 3 | Banca Transilvania S.A. | 100,000 | Nov 2020 | Article 32(1)(2) + Article 5(1)(f) GDPR — photographing and distributing a customer's statements via WhatsApp. The largest fine that became FINAL in RO. |
| 4 | ING Bank N.V. — Bucharest Branch | 80,000 | Sep 2019 | Article 25, Article 32 GDPR — card transaction processing error (doubling of debited amounts), affecting around 800 customers. |
| 5 | Orange România S.A. | 40,000 | 2024 | Multiple violations — security of processing and handling of data subjects' rights. |
| 6 | Sector 1 of the Municipality of Bucharest | 32,000 | Mar 2024 | Penalty payment for failure to comply with corrective measures; refusal to cooperate with ANSPDCP (Article 31 GDPR). |
| 7 | Raiffeisen Bank S.A. (cumulative) | 28,000 | Sep 2022 | Three cumulative fines — data subject rights, insufficient security, unlawful processing. |
| 8 | Altex România S.A. | 20,000 | Nov 2024 | Article 32 GDPR — double breach: online publication of credentials + credential stuffing attack. |
| 9 | Alior Bank S.A. Warsaw — Bucharest Branch | 17,000 | Jan 2024 | Article 6, Article 5(1)(b) GDPR — processing for incompatible purposes (messages after contract termination); cross-border case. |
| 10 | Untold SRL | 15,000 | Oct 2024 | Article 12, Article 15, Article 17 GDPR — failure to meet the legal deadline for access and erasure requests. |
Four of the top ten fines concern the banking sector (Raiffeisen, Unicredit, Banca Transilvania, ING) and a further two are imposed on the same sector (Raiffeisen cumulative 2022, Alior Bank 2024). This concentration is not accidental: banks are controllers with large volumes of sensitive data (personal ID numbers, financial data, transactional behaviour), they have long chains of processors, and they are the natural subject of the first inspections because the availability of regular reporting makes breaches easier to identify.
The Banca Transilvania case (EUR 100,000, confirmed as final by the Cluj Court of Appeal on 14 April 2022) is instructive. The breach did not arise from a lack of technical measures, but from employee behaviour: a customer's statement was photographed off a screen with a personal phone and distributed via WhatsApp. The implications for the ISMS programme: policies on security organisation, human resources, asset management and activity monitoring must be translated into verifiable operational controls, not just documents.
The Raiffeisen case — EUR 150,000 (October 2019) — is the largest GDPR fine initially imposed by ANSPDCP in Romania. The fact illustrates an important aspect of Romanian practice: the amount announced in the ANSPDCP communication is not always the final one — controllers benefit from an effective right of appeal, and the courts have, in a few cases, reduced the initial sanctions.
The cases of Altex (EUR 20,000), Untold (EUR 15,000), Profi Rom Food (EUR 10,000) and Kaufland (EUR 7,000 cumulative) — all imposed in 2024 — show that, in retail and e-commerce, the main risks come from: weak account passwords, lack of multi-factor authentication (MFA), employee access to CCTV footage via personal phones, and the absence of robust processes for handling data subjects' rights.
The credential stuffing attack against Altex (passwords reused from other services, used to access altex.ro accounts) is a frequent case study in 2024–2025. ANSPDCP was very clear: it is not enough for the controller to defend itself by the existence of a password policy — it must demonstrate active measures to detect automated attempts (rate limiting, CAPTCHA, monitoring of authentication logs, notification of log-in on new devices).
The EUR 32,000 penalty payment imposed in March 2024 on the Sector 1 City Hall does not concern a GDPR violation as such, but the repeated refusal to provide ANSPDCP with the requested information and the failure to comply with a previously established remediation plan. The sanction is for Article 31 GDPR — refusal to cooperate with the authority.
The Alior Bank SA Warsaw — Bucharest Branch case (EUR 17,000, January 2024) is the first major cross-border case concluded at ANSPDCP level. The Bucharest branch was responsible towards Romanian customers, but the IT systems were administered centrally from Poland. ANSPDCP cooperated with the Polish authority (UODO) to impose corrective measures at group level. The trend of genuine cooperation with other European authorities accelerated visibly in 2025–2026.
Vodafone România received at least four separate sanctions between 2022 and 2024 for similar deficiencies (BCC not used in collective correspondence, failure to respond to access requests). Orange was fined EUR 40,000 (the largest fine of 2024). The implicit message is that ANSPDCP does not punish severely the first time, but persists with inspections, and the fines grow cumulatively. Even operators with certified DPOs and mature GDPR policies can accumulate sanctions if their day-to-day operational processes are not tested regularly.
The most comprehensive public database on GDPR fines imposed in the EU/EEA is the GDPR Enforcement Tracker, run by the law firm CMS Legal. According to the CMS Enforcement Tracker Report (2024/2025 edition), by 1 March 2025 European authorities had cumulatively imposed over 2,245 fines, with a total value of approximately EUR 5.65 billion. In 2024 alone, cumulative fines at EU level exceeded EUR 1.2 billion.
At the individual level, the European top is dominated by the Irish authority (DPC), which handles the cross-border investigations into Meta, Instagram, LinkedIn and TikTok — companies whose main European establishment is in Ireland.
Viewed by country, Ireland concentrates approximately EUR 3.5 billion in cumulative GDPR fines — more than four times as much as Luxembourg (second place with ~EUR 746 million, largely the Amazon fine of July 2021). France, Italy and the Netherlands complete the podium of active enforcement. Spain is the country with the most fines in absolute number (over 930), but with low average values.
By comparison, Romania with approximately EUR 2.2 million represents about 0.06% of the total Irish fines. This difference does not necessarily reflect a better level of compliance among Romanian controllers, but two realities: most digital giants have their main European establishment in Ireland or Luxembourg, which channels the large decisions there through the One-Stop-Shop mechanism; and ANSPDCP applies, in line with the principle of proportionality, fines calibrated to local turnover and to the seriousness of the violation.
Important for clients: even a fine that is moderate in absolute value (for example EUR 20,000 for Altex) can generate disproportionate reputational impact and opens the door to collective actions under Article 80 GDPR or civil actions under Article 82. The real risk is not just the initial fine, but the spiral of subsequent costs (lost customers, parallel sectoral investigations, mandatory remediation costs).
On 19 November 2025, the European Commission published the official "Digital Omnibus Regulation Proposal" — the most significant set of amendments to GDPR since its adoption in 2016.
The package comprises two proposed regulations: (1) "Digital Omnibus", which amends GDPR, the ePrivacy Directive, the NIS2 Directive and the Data Act; and (2) "Digital Omnibus on AI", which adjusts the AI Act. The stated objective is to simplify the European digital framework and reduce the compliance burden for businesses, especially for SMEs.
According to the text of the proposal, the Digital Omnibus introduces the following changes to GDPR:
The Digital Omnibus proposal follows the standard path of EU regulations:
Important for our clients: until final adoption, GDPR remains applicable in its current form. Controllers cannot anticipate the Digital Omnibus relaxations in order to reduce their current level of compliance. Any current obligation remains valid, and ANSPDCP continues to apply sanctions based on the text of Regulation 2016/679 until any future amendment.
The European Data Protection Board published a general opinion on the Digital Omnibus, expressing selective concerns — in particular regarding the clarification of "qualified legitimate interest" for AI and the raising of the breach notification threshold. Civil society organisations (noyb, EDRi, BEUC) criticised the proposal as a partial "rollback" of GDPR. The Commission maintains that the changes are "technical" and "do not affect the core of the rights".
The Digital Omnibus generates three types of action over the short and medium term:
Our recommendation: continue the standard monthly GDPR + ISMS maintenance cycle, without any preventive changes. The Digital Omnibus is not yet law — compliance planning must be based on the current GDPR text.
Eight years after application, the level of use of the rights guaranteed by Articles 15–22 of Regulation (EU) 2016/679 is rising. ANSPDCP communications show that complaints regarding the exercise of rights represent the most consistent group of sanctioned reasons. The distribution by type, based on the analysis of public communications from 2023–2025:
Operational recommendation for clients: every controller must keep a centralised register of rights-exercise requests (Data Subject Request Log) with technological SLAs for automatic notification on days 21 and 28 after a request is received. The absence of this register is, in ANSPDCP practice, considered an aggravating circumstance.
Analysing the ten top fines and the cumulative sanctions of 2023–2025, five recurring patterns of non-compliance can be observed:
The most common reason invoked by ANSPDCP — it appears in over 60% of the fines imposed. The category includes weak passwords, lack of MFA on critical systems, absence of network segmentation, absence of access logging, lack of on-disk or in-transit encryption. Recommendation: map the Annex A controls of ISO/IEC 27001:2022 directly onto the record of processing activities (ROPA), demonstrating per activity which control protects which data.
The recurring error: the one-month deadline (Article 12(3)) is not respected, either because there is no formal process, or because tickets get lost between departments. Implementing a centralised DSR Log drastically reduces this risk.
Companies such as Tensa Art Design, Corint Logistic and BEST ELAN ONLINE have been sanctioned multiple times for commercial SMS and emails without valid double opt-in. Law 506/2004 requires specific consent for each channel (email, SMS, telephone). A frequent confusion: the controller assumes that the purchase (buying the product) automatically consents to marketing — which is incorrect.
Audio-video CCTV on means of transport (Cluj-Napoca), GPS on company cars used during holidays (UP România, Global Ports), video surveillance for internal discipline — all sanctioned for exceeding the necessary minimum (data minimisation) and for the absence of an impact assessment (DPIA). Recommendation: any extensive video surveillance or employee monitoring must go through a DPIA documented in accordance with Article 35 GDPR and must be preceded by a LIA (Legitimate Interest Assessment) where the basis is Article 6(1)(f).
Banca Transilvania, Raiffeisen, Kaufland, Medicover, Genpact — cases in which employees used personal WhatsApp, personal phones or private email to transmit data. The sanction is for Article 29 (employee instruction) and Article 32 (lack of supervision). The connection with the ISMS programme: acceptable use of assets, awareness training, access control.
In addition to the Digital Omnibus (analysed in chapter 7), the next two years will consolidate the European digital package and change the compliance landscape in Romania:
Based on the analysis of the ten major sanctions and the patterns identified, we propose a standardised monthly action plan, compatible with the PDCA cycle and with the structure of Annex A of ISO/IEC 27001:2022.
Ten years after adoption and eight years after application in Romania, GDPR has clearly moved beyond its early stage. The aggregate figures (over 41,000 complaints, approximately 370 fines, over RON 11 million in sanctions) demonstrate that the authority is active and that controllers are under growing compliance pressure. The risk does not come solely from the initial fine, but from the triad of fine + penalty payment + reputational costs, to which the overlap with NIS2, DORA and AI Act sanctions is added.
Infoshare Consulting recommends that its clients adopt a standardised monthly GDPR + ISMS maintenance cycle, integrated with training, awareness and attack simulation activities. Compliance is a continuous process, not a one-off event: as the ten analysed sanctions demonstrate, the organisations that invested in documents without validated operational procedures were the most exposed.
Finally, it is worth recalling the basic principle: ANSPDCP does not punish controllers who make honestly detected and reported mistakes, but those who ignore, hide or fail to cooperate. Proactive cooperation, reporting breaches within 72 hours, swift corrective measures and continuous investment in technical and organisational controls remain the best defences — and, at the same time, the best signals of maturity for clients, partners and the supervisory authority.
ANSPDCP has moved from an educational stage (2018-2020), focused on guidance and warnings, to diversified enforcement (2024-2026), with a record number of fines (83 in 2024, 85 in 2025), the first penalty payment in the public sector and cross-border cases concluded through the One-Stop-Shop mechanism. Cumulatively for 2018-2025: over 41,000 complaints, approximately 370 fines and more than RON 11.1 million (~EUR 2.2 million).
The largest fine initially imposed is EUR 150,000 (Raiffeisen Bank, October 2019), later reduced by the court to EUR 15,000. The largest fine that became final is EUR 100,000, imposed on Banca Transilvania and confirmed by the Cluj Court of Appeal on 14 April 2022 for photographing and distributing a customer's statement via WhatsApp.
Five recurring patterns: lack of adequate technical and organisational measures (Article 32, in over 60% of fines), failure to respect data subjects' rights (Articles 15-22, especially the one-month deadline), direct marketing without valid consent (Article 6 and Law 506/2004), video surveillance or monitoring without a correct legal basis and without a DPIA, and lack of control over employees and processors (data sent via WhatsApp or personal phones).
The Digital Omnibus proposal, published by the European Commission on 19 November 2025, clarifies the definition of personal data, introduces a qualified legitimate interest legal basis for AI, centralises the DPIA lists at EDPB level, raises the breach notification threshold to high risk and extends the deadline from 72 to 96 hours. Until final adoption (estimated 2026-2027, with phased entry into force in 2027-2028) GDPR remains applicable in its current form, and controllers cannot anticipate the relaxations to reduce their level of compliance.
We carry out a position audit and a monthly GDPR + ISMS maintenance plan, prepared also for the Digital Omnibus changes.