ANSPDCP Enforcement and GDPR Article 82
Regulation (EU) 2016/679, Arts. 82-83
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018.
An enforcement supervision rule binding public and private bodies.
As of 2 September 2026.
What it requires
- Expect ANSPDCP to have General Data Protection Regulation (GDPR) Article 83 fining power over your processing of personal data of a person in Romania.
- Expect any person in Romania who suffered material or non-material damage from an infringement to have a direct GDPR Article 82 right to compensation from you as controller or processor, pursued through ordinary Romanian tort procedure.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Penalty structure
GDPR Article 83(5)'s top-tier ceiling. Legea nr. 190/2018's own Chapter VI (Articles 12-14) sets no separate Romanian figure: Article 12(3) expressly sanctions violations of the law's own national-specific provisions (Articles 3-9, e.g. national identification number processing) under the conditions of GDPR Article 83(5), channeling them into this same ceiling rather than a reduced national cap. For public authorities and bodies, Articles 13-14 add a mandatory first step of a warning and remediation plan before ANSPDCP may apply a fine at all, but do not set a different monetary ceiling once a fine is applied.
- Rule
- Higher of
- As of
- 2 September 2026
- Currency
- EUR
- Fixed cap
- 20,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP, National Supervisory Authority for Personal Data Processing)
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP, National Supervisory Authority for Personal Data Processing) is Romania's supervisory authority, with no Romania-specific enforcement addition beyond the General Data Protection Regulation (GDPR) Article 83 baseline found. GDPR Article 82 arms an individual with a direct private right of action; commentary describes ordinary Romanian tort liability rules as the procedural vehicle for such a claim rather than a distinct additional remedy. No collective-redress mechanism was found in either commentary source.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsprocesses_voice
Read the law
GDPR Arts. 82-83
CMS and DLA Piper commentary (no primary text read)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.