When "you can't, it's GDPR" becomes a pretext: how to tell data protection apart from blocking transparency.
The Deputy Prime Minister of Romania publicly stated that he had been denied access to the documents concerning the selection of the management of the Port of Constanța, with the General Data Protection Regulation (GDPR) being invoked as the reason. And from what I observe, this is one of the most widespread problems in Romania: the abusive use of GDPR as a pretext for blocking access to information of public interest.
It is not a tool for keeping institutional documents, public contracts or administrative decisions secret. When an institution invokes GDPR to refuse providing documents that contain no sensitive personal data, it is not applying the law — it is misappropriating it.
This practice is not new. In my work as a GDPR consultant, I frequently encounter situations in which organisations, both public and private, use GDPR as a shield against transparency. The reasons vary: sometimes it is a lack of knowledge of the legislation, other times a defensive reflex, and in some cases a deliberate strategy to avoid accountability.
The Regulation applies to the processing of personal data — that is, information that allows the direct or indirect identification of a natural person: name, personal numeric code (CNP), address, biometric data, health data. Administrative documents, activity reports, meeting minutes, commercial contracts — these are not, in themselves, personal data. They may contain such data, but in that case the solution is anonymisation or pseudonymisation, not a blanket refusal.
Moreover, GDPR coexists with the legislation on access to information of public interest (Law 544/2001 in Romania). The two do not exclude one another. Public institutions have an obligation to provide information of public interest, and may anonymise only those portions that contain personal data.
The Port of Constanța case should be a wake-up call for all organisations in Romania. Using GDPR as a pretext for opacity is not only illegal — it undermines the credibility of the entire data protection framework. The more people hear "you can't, it's GDPR" in contexts where the law does not apply, the less trust the public will have in the Regulation.
My recommendation: if you are denied information on the grounds of GDPR, ask exactly what personal data is involved, what legal basis for processing is being invoked and why partial anonymisation cannot be done. In most cases, you will discover that GDPR has nothing to do with the refusal.
No. GDPR protects the personal data of natural persons; it is not a tool for keeping institutional documents, public contracts or administrative decisions secret. It coexists with Law 544/2001 on access to information of public interest, and the two do not exclude one another. When an institution invokes GDPR to refuse documents that contain no personal data, it is not applying the law, it is misappropriating it.
Public institutions have an obligation to provide information of public interest and may protect only those portions that contain personal data. In practice this means the document is released, while any personal data within it is anonymised or pseudonymised. The rule is access as the principle and data protection as a targeted exception, not a blanket refusal of the document.
Yes, and this is the correct solution. Administrative documents, activity reports, meeting minutes and commercial contracts are not, in themselves, personal data. Where they do contain names, a personal numeric code, addresses or other data that identify a natural person, the answer is to anonymise or pseudonymise those portions, not to refuse to disclose the entire document.
Neither overrides the other; they apply together. If you are denied information on GDPR grounds, ask exactly what personal data is involved, what legal basis for processing is being invoked and why partial anonymisation cannot be done. In most cases you will find that GDPR has nothing to do with the refusal, and the information of public interest is still owed to you.
We help you tell protected data apart from public information and respond correctly to requests.