Law / Romania

Romania

European Union law applies in Romania Romania is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Romania, described on this page below, applies here too.

13 of 15 named instruments researched to a stage, across all six areas of law we track: 12 in force and 1 enacted but not yet in force. As of 15 September 2026.

When they take effect9 of 13 carry a date, 4 do not.
2014: 1 instrument (1 in force) ’14 2015: 0 instruments 2016: 1 instrument (1 in force) 2017: 0 instruments 2018: 5 instruments (5 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 2 instruments (2 in force) 2025: 0 instruments 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (183 words)

Romania has not enacted the national implementing legislation the EU AI Act requires: a Government Memorandum adopted 12 March 2026 proposed the National Authority for Administration and Regulation in Communications (ANCOM) as the national market surveillance authority and single contact point, alongside sector regulators for financial services and other domains, and ANCOM's own public statement confirms that neither ANCOM nor any other designated authority can verify or sanction non-compliance with the AI Act until a national law establishing the sanctioning procedure and the applicable penalties enters into force, still under drafting as of the date below.

The National Artificial Intelligence Strategy 2024-2027, approved by Government Decision in July 2024, sets non-binding strategic priorities for public-sector AI adoption and imposes no obligation on a private or public entity.

Romania's Criminal Code does reach one AI-specific practice directly: its child-pornography offence at art. 374 has defined prohibited material, since a 2016 amendment, to include an image that credibly simulates a minor in sexually explicit conduct without depicting a real person, bringing AI-generated or deepfake child-sexual-abuse material within the same criminal ban that covers real-person depictions.

AI prohibited practices

Cod penal, Art. 374, Pornografia infantilă (Child Pornography, Including Simulated or Computer-Generated Depictions of Minors)

Codul penal (Legea nr. 286/2009) art. 374, alin. (4) astfel cum a fost modificat prin Ordonanța de urgență nr. 18/2016, publicată în Monitorul Oficial nr. 389 din 23 mai 2016Codul penal (Legea nr. 286/2009), art. 374, official consolidated text on legislatie.just.ro, Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived February 23, 2026. Publisher's page: https://legislatie.just.ro/Public/DetaliiDocument/223635

In force since 23 May 2016. Binds public and private bodies.

What this law does

Cod penal art. 374 defines prohibited child-pornography material to include, since a 2016 amendment, an image that does not depict a real person but credibly simulates a minor in sexually explicit conduct, bringing AI-generated, deepfake or otherwise synthetic material within the same ban that reaches real-person depictions. The same definition reaches any representation of a child's genitals for a sexual purpose.

Producing, possessing, storing, exhibiting, promoting, distributing, or making such material available carries 1 to 5 years' imprisonment. That penalty rises to 2 to 7 years where the offence is committed through a computer system or another means of storing computer data. Accessing such material through a computer system or electronic communications carries 3 months to 3 years' imprisonment or a fine.

What it requires

Privacy law6 instruments, 5 in force, 1 enacted but not yet in force

Research summary (121 words)

Romania gives the General Data Protection Regulation (GDPR) domestic effect through Legea nr. 190/2018, applicable from 31 July 2018. The Act's own text is not independently confirmed: legislatie.just.ro, the official consolidated-text portal, fails on every attempt, first with a DNS resolution failure and then with an HTTP/2 stream reset, a genuine access failure rather than evidence the document does not exist, so this rests entirely on commentary (CMS, DLA Piper).

The genuine Romanian addition surveyed ties explicit consent or express legal authorization to using genetic, biometric, or health data for automated decision-making or profiling, and separate rules govern the national identification number under a legitimate-interests basis; neither was independently verified. Every substantive claim here should be treated as unverified until a primary-source read becomes possible.

Breach notification

GDPR Articles 33-34, Breach Notification

Regulation (EU) 2016/679, Arts. 33-34GDPR Arts. 33-34

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify ANSPDCP within 72 hours of becoming aware of a personal-data breach, and notify the affected individual without undue delay where the breach is likely to result in a high risk. Both commentary sources agree there is no Romanian-specific derogation from this timeline; DLA Piper adds a procedural detail that controllers notify using a special notification form, which the primary text is not cited for.

What it requires

Comprehensive regime

Law No. 190/2018 on Measures for the Implementation of Regulation (EU) 2016/679

Legea nr. 190/2018 privind masuri de punere in aplicare a Regulamentului (UE) 2016/679CMS and DLA Piper commentary only

In force since 31 July 2018. Binds public and private bodies.

What this law does

Romania gives the General Data Protection Regulation (GDPR) domestic effect through Legea nr. 190/2018, applicable from 31 July 2018. The Act's own text is not cited here; the summary rests on practitioner commentary. Every finding below rests on two commentary sources (CMS, DLA Piper) rather than a primary-source read.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer Restrictions

Regulation (EU) 2016/679, Arts. 44-49, 83(5)(c)GDPR Arts. 44-49, 83(5)(c)

In force since 25 May 2018. Binds public and private bodies.

What this law does

A transfer of personal data outside the EEA requires an adequacy decision, appropriate safeguards, or a narrow Article 49 derogation, backed by the Article 83(5)(c) top fine tier. DLA Piper's commentary states Law 190/2018 contains no specific provisions on international data transfers and General Data Protection Regulation (GDPR) rules apply directly; no primary text was read.

What it requires

Data subject rights

GDPR Articles 12-22, Data-Subject Rights and Electronic Employee Monitoring

Regulation (EU) 2016/679, Arts. 12-22; Legea nr. 190/2018, electronic monitoring of employeesGDPR Arts. 12-22

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 12-22 apply directly. Commentary separately confirms the Act addresses electronic monitoring of employees in the workplace as its own heading, distinct from the biometric and automated-decision-making provision above, but neither commentary source details what that provision actually requires; this is a named gap, not a confirmed absence.

What it requires

Enforcement supervision

ANSPDCP Enforcement and GDPR Article 82

Regulation (EU) 2016/679, Arts. 82-83GDPR Arts. 82-83

In force since 25 May 2018. Binds public and private bodies.

What this law does

Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP, National Supervisory Authority for Personal Data Processing) is Romania's supervisory authority, with no Romania-specific enforcement addition beyond the General Data Protection Regulation (GDPR) Article 83 baseline found. GDPR Article 82 arms an individual with a direct private right of action; commentary describes ordinary Romanian tort liability rules as the procedural vehicle for such a claim rather than a distinct additional remedy. No collective-redress mechanism was found in either commentary source.

What it requires

Sensitive categories

GDPR Article 9 and Law 190/2018 Automated Decision-Making and CNP Rules

Regulation (EU) 2016/679, Art. 9; Legea nr. 190/2018, automated decision-making and national identification number provisionsCMS and DLA Piper commentary only

Commencement not set. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1) treats biometric data processed for unique identification as a special category. Commentary describes a genuine Romanian addition tied to automated decision-making rather than employment: processing genetic, biometric, or health data for automated decision-making or profiling requires explicit consent or express legal authorization, with adequate protective measures.

A second commentary-described addition covers the national identification number: where a controller relies on legitimate interests to process it, the Act reportedly requires a Data Protection Officer, adequate technical and organizational measures, specific retention terms with deletion deadlines, and regular staff training. Neither is independently verified against the Act's own text, and no employment-specific biometric provision appears in either commentary source.

No commencement date is recorded for this instrument: no primary-source text was read and this rests entirely on commentary, so the status here is enacted rather than in force, rather than an asserted but unconfirmed effective date.

What it requires

Scraping law2 instruments, 2 in force

Research summary (160 words)

Romania's Criminal Code criminalizes unauthorized access to a computer system and related conduct (illegal interception, data alteration, system disruption, unauthorized data transfer, and dealing in access-defeating devices or credentials) with tiered custodial penalties, binding any person regardless of the target's public or private status.

Legea nr. 69/2022 transposed the EU Digital Single Market Copyright Directive's text-and-data-mining exceptions into Legea nr. 8/1996 privind dreptul de autor, permitting research organizations and cultural-heritage institutions to reproduce and extract text and data from lawfully accessible works without authorization, and permitting a general text-and-data-mining exception for any person subject to a rights holder's express, machine-readable opt-out.

The EU's own text-and-data-mining and copyright framework (the Digital Single Market (DSM) Directive itself, the General Data Protection Regulation (GDPR), and the AI Act) applies to Romania directly as an EU member state and is not restated here; what follows is limited to what Romania's own transposition and Criminal Code add. Romania's data-protection regime for scraped personal data is researched under the privacy topic, not here.

Computer misuse

Cod penal, Art. 360-366, Infracțiuni contra siguranței și integrității sistemelor și datelor informatice (Offences Against the Security and Integrity of Computer Systems and Data)

Codul penal (Legea nr. 286/2009), art. 360-366Codul penal (Legea nr. 286/2009), official consolidated text on legislatie.just.ro, Internet Archive capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived February 23, 2026. Publisher's page: https://legislatie.just.ro/Public/DetaliiDocument/223635

In force since 1 February 2014. Binds public and private bodies.

What this law does

Unauthorized access to a computer system is punishable by 3 months to 3 years' imprisonment or a fine, rising to 6 months to 5 years where the access aimed at obtaining data and to 2 to 7 years where the system's access was technically restricted to certain categories of users, per art. 360.

Illegal interception of a non-public data transmission, alteration of the integrity of computer data, and unauthorized transfer of data from a computer system each carry 1 to 5 years' imprisonment, per arts. 361, 362 and 364. Disrupting a computer system's functioning carries 2 to 7 years, per art. 363.

Producing, importing, distributing or making available a device, program, password or access code for the purpose of committing one of these offences carries 6 months to 3 years' imprisonment or a fine, and mere possession of one of these items for that purpose carries 3 months to 2 years' imprisonment or a fine, per art. 365; an attempt at any of these offences is itself punishable, per art. 366.

What it requires

Copyright and text and data mining (TDM)

Legea nr. 8/1996 privind dreptul de autor și drepturile conexe, art. 36^1-36^2, Text and Data Mining Exceptions, inserted by Legea nr. 69/2022

Legea nr. 69/2022 art. I pct. 11, inserting art. 36^1-36^2 into Legea nr. 8/1996 privind dreptul de autor și drepturile conexe, republicată (Monitorul Oficial nr. 321 din 1 aprilie 2022)Legea nr. 69/2022 pentru modificarea și completarea Legii nr. 8/1996

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived July 6, 2026. Publisher's page: https://legislatie.just.ro/Public/DetaliiDocumentAfis/253526

In force. Binds public and private bodies.

What this law does

Legea nr. 69/2022, adopted 28 March 2022 and published in Monitorul Oficial nr. 321 din 1 aprilie 2022, transposed Articles 3 and 4 of the EU Digital Single Market Copyright Directive (2019/790) into Legea nr. 8/1996, inserting two text-and-data-mining exceptions.

Article 36^1 permits a research organization or cultural-heritage institution to reproduce and extract text and data from a lawfully accessible work for scientific-research purposes without the rights holder's authorization, retaining the copy only as long as necessary to verify the research results.

Article 36^2 permits any person to reproduce and extract text and data from a lawfully accessible work for text-and-data-mining purposes generally, but that exception does not apply where the rights holder has expressly reserved the use of the work through machine-readable means or another adequate method, most often for content made public online.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (1,071 words)

Romania transposed the NIS2 Directive (Directive (EU) 2022/2555) through Ordonanța de urgență a Guvernului nr. 155/2024 (OUG 155/2024), signed 30 December 2024 and published in Monitorul Oficial nr. 1332 din 31 decembrie 2024. The Government's own preamble cites a first-quarter-2024 ransomware incident that compromised a managed-service provider and disrupted 26 hospitals nationwide as the specific trigger for the updated supply-chain-security and management-accountability duties.

Article 66(1)(a) repeals Romania's earlier NIS1-era statute, Legea nr. 362/2018 privind asigurarea unui nivel comun ridicat de securitate a rețelelor și sistemelor informatice, outright, so no predecessor regime survives alongside OUG 155/2024 the way Ireland's 2018 NIS Regulations survive pending its own Bill.

Multiple independent Romanian legal-commentary sources (Biris Goran, avocatnet.ro, EuroAvocatura, Lege5.ro) report that Parliament approved the OUG through Legea nr. 124/2025 din 7 iulie 2025 (Monitorul Oficial nr. 638 din 7 iulie 2025) by a single approving article; no primary text of Legea nr. 124/2025 itself was located for this review, so the fact and date of its approval rest on secondary reporting rather than a directly read primary source.

The OUG's own legislatie.just.ro portal page independently corroborates this within what this review did read: its "Forma consolidată" history note records the consolidated text as last revised 10.07.2025, three days after the reported publication date, consistent with the reported approval and commencement dates, though this review did not confirm whether Legea nr. 124/2025 changed any substantive provision or approved the OUG unchanged.

Articles 11 through 14 impose the risk-management duty and Articles 15 through 17 the incident-reporting duty; both took effect on the OUG's own publication date, 31 December 2024 (Article 65(4) delayed only Articles 60 and 61, the sanctions-enforcement machinery, by 30 days).

Article 11(1) requires an essential or important entity to take proportionate technical, operational and organisational measures across ten baseline categories mirroring NIS2 Article 21(2): risk-analysis and information-security policy and its periodic review, evaluating the effectiveness of risk-management measures, cryptography and encryption policy, supply-chain security including the relationship with direct suppliers and service providers, security of system acquisition, development, maintenance and decommissioning including vulnerability management and disclosure, human-resources security and access control and asset management, incident management, business continuity including backup management, disaster recovery and crisis management, basic cyber-hygiene practices and training, and multi-factor or continuous authentication.

Article 12(1) separately requires the DNSC director to issue an implementing order detailing the technical, operational and organisational requirements within 120 days of the OUG's entry into force (due by roughly 30 April 2025); this review did not confirm whether that order has since issued.

Article 14(1) requires the entity's governing body to approve these risk-management measures, supervise their implementation, and bear responsibility for them, and Article 14(3) requires it to designate a network-and-information-system security officer.

Article 15 sets a graduated incident-notification clock to the Platforma națională pentru raportarea incidentelor de securitate cibernetică (PNRISC) run by the national CSIRT: an early warning within 24 hours of becoming aware of a significant incident (stating whether it is suspected unlawful, malicious, or cross-border in effect), a fuller incident report within 72 hours with an initial severity and impact assessment, an interim report on the CSIRT's request, and a final report within one month of the 72-hour report, or a progress report followed by a final report if the incident is still ongoing at that point, transposing NIS2 Article 23 on the same clock the corpus has already confirmed for Germany, Ireland, Lithuania, Portugal, Slovenia, Latvia, Estonia, Liechtenstein, Sweden and Slovakia.

Article 5 and Article 6, read with Article 8's cross-reference to Legea nr. 346/2004's SME criteria, bind a large or medium enterprise within the Anexa nr. 1 or Anexa nr. 2 sector lists as an essential or important entity respectively; central public-administration bodies and entities designated as critical entities under Romania's critical-entity-resilience legislation are essential regardless of size, and a public-electronic-communications-network or -service provider or a managed-security-service provider is essential even at only medium size.

Article 4's definitions (letters q, u and v) expressly recognise a piață online (online marketplace), a motor de căutare online (online search engine), and a platformă de servicii de socializare în rețea (social-networking-services platform) as digital-provider categories drawn from EU law, matching NIS2's own digital-provider sector; only this digital-provider slice is flagged on this jurisdiction's rows, and the wider sector classes OUG 155/2024 also reaches (energy, transport, banking, health, water, digital infrastructure, public administration, and the size-gated telecom and managed-security-service carve-outs) are recorded here as law the lint does not yet reach rather than flagged on an unrelated activity.

Article 48 empowers DNSC to issue a warning or an amendă contravențională (administrative fine); Article 60(1) lists violating the Article 11(1) risk-management duty at letter a), and violating the Article 15(1) reporting clock or the duty to notify service recipients at letters l) and m), among the contravenții (regulatory administrative offences) it sanctions, unless the same conduct also meets a criminal offence's elements under separate law, in which case it is prosecuted as a crime instead of as this administrative offence.

Article 60(2)(a)-(b) applies the top penalty tier, the greater of a fixed euro-equivalent-in-lei cap or a percentage of net turnover, to a violation of letters a) through m) (which includes both the Article 11(1) risk-management duty and the Article 15(1) reporting-clock and notification duties): up to EUR 10,000,000 or 2 percent for an essential entity, and up to EUR 7,000,000 or 1.4 percent for an important entity, mirroring NIS2 Article 34(4) and (5) exactly; a separate Article 15(3) information-reporting violation at letter n) instead falls in the lower fixed-lei tier Article 60(2)(c)-(d) sets.

DNSC, the Directoratul Național de Securitate Cibernetică, enforces; its sanction decisions are reviewable in contencios administrativ before the Curtea de Apel București within 30 days without a mandatory prior administrative appeal, and this review found no private right of action.

No Romanian instrument reviewed here imposes a mandatory product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here.

Romania has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation, which sits in the privacy topic rather than here, and Article 62 of OUG 155/2024 separately requires DNSC to inform ANSPDCP, Romania's data-protection authority, without undue delay when a cybersecurity incident it supervises also implicates personal-data protection, a coordination duty distinct from an entity's own GDPR Article 33 and 34 breach-notification duty.

Sector security regimes

Ordonanța de urgență nr. 155/2024, Cybersecurity Risk-Management Measures

Ordonanța de urgență a Guvernului nr. 155/2024 privind instituirea unui cadru pentru securitatea cibernetică a rețelelor și sistemelor… informatice din spațiul cibernetic național civil, reportedly approved by Legea nr. 124/2025, art. 11-14Ordonanța de urgență a Guvernului nr. 155/2024

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived September 14, 2025. Publisher's page: https://legislatie.just.ro/Public/DetaliiDocumentAfis/293121

In force since 31 December 2024. Binds public and private bodies.

What this law does

Article 11(1) requires an essential or important entity to take technical, operational and organisational measures proportionate to its risk exposure to identify, assess and manage the risks to the network and information systems it uses, across at least ten baseline categories mirroring NIS2 Article 21(2): risk-analysis and system-security policy and its periodic review; evaluating the effectiveness of risk-management measures; cryptography and, where applicable, encryption policy; supply-chain security, including the security of the entity's relationship with its direct suppliers and service providers; security of system acquisition, development, maintenance and decommissioning, including vulnerability management and disclosure; human-resources security, access-control policy and asset management; incident management; business continuity, including backup management, disaster recovery and crisis management; basic cyber-hygiene practices and cybersecurity training; and multi-factor or continuous authentication.

Article 12(1) requires the DNSC director to issue an implementing order on these technical, operational and organisational requirements within 120 days of the OUG's entry into force. Article 14 requires the entity's governing body to approve these measures, supervise their implementation and bear responsibility for them, attend training, allocate the resources needed to implement them, and designate a network-and-information-system security officer.

Article 66(1)(a) repeals the predecessor statute, Legea nr. 362/2018, outright as of this OUG's own entry into force. Article 4 defines a piață online (online marketplace) and a motor de căutare online (online search engine) as digital-provider categories among the entities Articles 5 and 6 bind as essential or important.

What it requires

Vulnerability and incident reporting

Ordonanța de urgență nr. 155/2024, Incident Notification

Ordonanța de urgență a Guvernului nr. 155/2024 privind instituirea unui cadru pentru securitatea cibernetică a rețelelor și sistemelor… informatice din spațiul cibernetic național civil, reportedly approved by Legea nr. 124/2025, art. 15-17Ordonanța de urgență a Guvernului nr. 155/2024

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived September 14, 2025. Publisher's page: https://legislatie.just.ro/Public/DetaliiDocumentAfis/293121

In force since 31 December 2024. Binds public and private bodies.

What this law does

Article 15(1) requires an essential or important entity to report to the national cybersecurity-incident-response team, without undue delay, any incident with a significant impact on the provision of its services, and, where relevant, to notify the recipients of its services of a significant incident that could affect them. Article 15(2) routes this reporting through the Platforma națională pentru raportarea incidentelor de securitate cibernetică (PNRISC).

Article 15(7) sets a graduated clock: an early warning within 24 hours of becoming aware of the significant incident, indicating whether it is suspected to be caused by unlawful or malicious acts or to have cross-border impact; an incident report within 72 hours, updating the early warning and giving an initial assessment of the incident's severity and impact, including indicators of compromise where available; an interim report on the national CSIRT's request; and a final report within one month of the 72-hour incident report, including a detailed description of the incident, its likely cause, mitigation measures applied and in progress, and any cross-border impact, or, if the incident is still ongoing at that point, a progress report followed by a final report once it has been resolved.

Article 15(8) sets a flat 24-hour clock for a trust service provider's incidents affecting its trust services. Article 16 lets an entity outside the mandatory scope voluntarily report incidents, cyber threats and near misses to the national CSIRT under the same Article 15 channel, without that report itself creating any additional obligation.

Article 17 extends Articles 15 and 16 to certain electronic-communications entities under Legea nr. 58/2023 that are identified as essential or important entities under this OUG. Article 62 separately requires DNSC to inform ANSPDCP, Romania's data-protection authority, without undue delay when a cybersecurity incident it supervises also implicates personal-data protection.

What it requires

Age gating law1 instrument, 1 in force

Research summary (77 words)

Legea audiovizualului nr. 504/2002 requires linear television and radio broadcasters, and providers of on-demand audiovisual media services, to restrict minors' access to programs that could seriously affect their physical, mental, or moral development, through scheduling, coding, or another technical access-restriction system, with a distinct and lighter contravention regime for on-demand services.

Romania has no social-media minor-access restriction, app-store age-verification requirement, or age-appropriate design code distinct from the EU's Digital Services Act and Audiovisual Media Services Directive framework.

Adult content age verification (AV)

Legea nr. 504/2002 (Legea audiovizualului), art. 39 and art. 39^1, Minors Protection in Television, Radio, and On-Demand Audiovisual Media Services

Legea audiovizualului nr. 504 din 11 iulie 2002, art. 39 și art. 39^1, republicată și actualizatăLegea audiovizualului nr. 504/2002

In force. Binds public and private bodies.

What this law does

Legea audiovizualului nr. 504 was adopted 11 July 2002 and remains in force, amended repeatedly since. A television or radio broadcaster may not broadcast programs that could seriously affect minors' physical, mental, or moral development, in particular programs containing pornography or unjustified violence, per art. 39(1).

Where a program that could affect that development is broadcast in an uncoded form or without another technical access-restriction measure, it may be shown only after an acoustic or graphic warning, with a visual warning symbol displayed for the whole program, per art. 39(3). A provider of an on-demand audiovisual media service may make available a program that could affect minors' development only if access-restriction measures ensure that minors cannot normally see or hear it, per art. 39^1.

Breach of the linear-broadcast duty under art. 39 is a contravention carrying a fine of 10,000 to 200,000 lei, imposed directly by the Consiliul Național al Audiovizualului (CNA); breach of the on-demand duty under art. 39^1 is a separate, lighter-touch contravention under which CNA first issues a formal notice to come into compliance, with a fine of 5,000 to 100,000 lei applying only if the provider fails to comply with that notice or repeats the violation.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (129 words)

Romania transposed the EU Digital Single Market Copyright Directive's press-publisher neighbouring right through Legea nr. 69/2022, inserting art. 94^1 into Legea nr. 8/1996 privind dreptul de autor. A press publisher holds an exclusive right to authorize or prohibit an information-society service provider's online reproduction and making-available of its press publications, exempting hyperlinks, reporting of simple facts, and individual words or extracts of up to 120 characters.

The same 2022 act separately inserted a general text-and-data-mining exception, subject to a rights holder's machine-readable opt-out, which is researched under the scraping topic rather than restated here since it is not news-specific. Romania has no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act, and no hot-news or misappropriation doctrine distinct from the press-publisher right.

Press publishers' right

Legea nr. 8/1996 privind dreptul de autor și drepturile conexe, art. 94^1, Press Publisher Neighbouring Right, inserted by Legea nr. 69/2022

Legea nr. 69/2022 art. I pct. 21, inserting art. 94^1 into Legea nr. 8/1996 privind dreptul de autor și drepturile conexe, republicată (Monitorul Oficial nr. 321 din 1 aprilie 2022), transposing Directive (EU) 2019/790 art. 15Legea nr. 69/2022 pentru modificarea și completarea Legii nr. 8/1996

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived July 6, 2026. Publisher's page: https://legislatie.just.ro/Public/DetaliiDocumentAfis/253526

In force. Binds private bodies.

What this law does

Legea nr. 69/2022, adopted 28 March 2022 and published in Monitorul Oficial nr. 321 din 1 aprilie 2022, inserted this right.

A press publisher established under Romanian law holds the exclusive patrimonial right to authorize or prohibit an information-society service provider's online use of its press publications, through reproduction (direct or indirect, temporary or permanent, in whole or in part) and through making them available to the public so that they can be accessed individually at a place and time chosen by the public, per art. 94^1(1).

The right does not apply to private or non-commercial use by individual users, to hyperlinks or reporting of simple facts, or to the use of individual words or extracts of up to 120 characters that does not undermine the right's effectiveness or substitute for the publication, per art. 94^1(2).

It does not override the rights of authors or other rights holders whose works are incorporated into a press publication, per art. 94^1(3), and it expires two years after 1 January of the year following the publication's own publication date, per art. 94^1(5).

An author whose work is incorporated in a press publication is entitled to a proportionate share of the publisher's revenue from this right, per art. 94^1(6), and where an author has transferred a right or granted a licence to a press publisher, that transfer or licence itself entitles the publisher to a share of the compensation for a use of the work made under a copyright exception, per art. 94^2.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.