If a company misused your data, you have a clear right: you can complain to the authority. Here is how it works, step by step — no mystery, no lawyer.
You start getting ads from a company you never gave your email to. You asked to have your data deleted and got silence in return. Or you saw your name and phone number somewhere they had no business being. In all these situations, the law gives you a concrete lever, not just the right to be annoyed: you can file a complaint with the data protection authority.
Many people never do, because they picture a complicated process full of lawyers and paperwork. In reality, it is simpler than it looks. Let us take it step by step.
Article 77 of the GDPR gives you the right to lodge a complaint with a supervisory authority when you believe your data has been processed unlawfully. In Romania, that authority is ANSPDCP — the National Supervisory Authority for Personal Data Processing.
You do not need an extraordinary reason and you do not have to prove you suffered harm. It is enough that you believe, in good faith, that something was wrong with the way a company or institution used your data.
Here is advice few people give you, but it shortens the road enormously. Before going to the authority, write to the company directly.
Send a request to the data protection officer (DPO) or to the contact address in the privacy notice on the website. Say clearly what you want: to see what data they hold on you, to have it deleted, to stop the marketing messages. The controller usually has one month to reply. We have written in detail about what you can actually ask for in our article on the rights of the data subject.
This is not a mandatory step — the law does not stop you from going straight to ANSPDCP. But, honestly, many complaints are settled with a single email sent at the right time. And if the company ignores or refuses you, you already have good evidence for the file.
The complaint goes to ANSPDCP, and the authority has a complaint form and contact details on its website, dataprotection.ro. You can send it through the electronic form, by email, by post to the authority's headquarters or in person, at the registry. Pick whatever is easiest for you; what matters is the content, not the channel.
However you send it, a good complaint states a few things clearly:
A clear, documented complaint is easier to resolve than a vague one written in anger. The extra fifteen minutes are worth it.
Your complaint is registered and reviewed. The authority may ask you for further clarification, may ask the company for explanations and, where appropriate, may open an investigation. At the end, it issues a decision. Along the way, it keeps you informed about where your case stands.
One thing to know from the start: do not expect an answer overnight. A serious review takes time, especially when the authority also checks what the other side has to say. Patience is part of the process.
Depending on what it finds, ANSPDCP can dismiss the complaint (if the company complied with the law), issue a warning, order corrective measures — for example, to stop a processing activity or delete certain data — or impose a fine. Fines usually come when the problem is serious or repeated, not for a first minor slip.
If you are not satisfied with the decision, you have not reached the end of the road: you can challenge it before the administrative court, within the time limit set by law.
It is worth repeating, because this is where most of the hesitation comes from: filing a complaint with ANSPDCP costs nothing and does not require a lawyer. You can write it yourself. A lawyer helps if the stakes are high or if you also want compensation in court, but for the complaint itself you do not need one.
There is another side to the story. If your company received a request from ANSPDCP, the first reflex should not be panic, but order. Reply on time, cooperate openly with the authority and show what measures you took. A company that demonstrates it takes data protection seriously — that it has procedures, that it answers requests, that it keeps an incident register — starts with a big advantage.
This is where the difference shows between a complaint settled quickly and a painful fine. An outsourced data protection officer who knows your organisation, plus a clear response process, shortens the road considerably. If the complaint stems from a data breach, the rules on notifying an incident to ANSPDCP apply.
Nothing. Filing a complaint with the authority is free and you do not need a lawyer. You can write the complaint yourself, in your own words.
No. The authority must know who you are so it can investigate and tell you the outcome. Your data is treated confidentially, but a fully anonymous complaint cannot be resolved.
There is no fixed short deadline. The authority keeps you informed about the status of your complaint and resolves it within a reasonable time that depends on the complexity of the case. A serious investigation takes time.
You can challenge the authority's decision before the administrative court, within the time limit set by law. From your point of view, the ANSPDCP decision is not the final word.
We help you respond properly to the authority and set up the processes that stop complaints before they happen: data subject requests, privacy notices, an incident register.