Chat on WhatsApp

How does ANSPDCP (Romanian DPA) + GDPR affect my Magento cookie banner?

Romania’s data protection authority is ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal). GDPR applies as-is across the EU, but ANSPDCP has issued specific guidance + enforcement actions:

  • Legea nr. 190/2018, the Romanian national law implementing GDPR. Layered on top, adds rules around employee monitoring + biometric data.
  • Cookie consent, ANSPDCP follows EDPB guidance: explicit opt-in, no pre-ticked checkboxes, “Reject all” as prominent as “Accept all”. Active enforcement since 2022, fines RON 5,000-100,000 + EUR equivalents for cookie-wall violations.
  • Cookie banner copy, must be in Romanian (primary language) + offer alternatives. Cookie purposes broken down (analytics / marketing / functional). Withdrawal as easy as consent.
  • Data residency, ANSPDCP prefers EU-region hosting (Frankfurt, Paris, Amsterdam OK). Many RO merchants choose AWS Frankfurt or ZooM Hosting (RO-based).
  • DSAR routing, data subject access requests must be answered within 30 days in Romanian.

We ship a Romanian-language cookie banner (Cookiebot or a Magento-native module) with per-purpose granularity, plus a privacy policy template reviewed against ANSPDCP guidance.

Was this helpful?