How does ANSPDCP (Romanian DPA) + GDPR affect my Magento cookie banner?
Romania’s data protection authority is ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal). GDPR applies as-is across the EU, but ANSPDCP has issued specific guidance + enforcement actions:
- Legea nr. 190/2018, the Romanian national law implementing GDPR. Layered on top, adds rules around employee monitoring + biometric data.
- Cookie consent, ANSPDCP follows EDPB guidance: explicit opt-in, no pre-ticked checkboxes, “Reject all” as prominent as “Accept all”. Active enforcement since 2022, fines RON 5,000-100,000 + EUR equivalents for cookie-wall violations.
- Cookie banner copy, must be in Romanian (primary language) + offer alternatives. Cookie purposes broken down (analytics / marketing / functional). Withdrawal as easy as consent.
- Data residency, ANSPDCP prefers EU-region hosting (Frankfurt, Paris, Amsterdam OK). Many RO merchants choose AWS Frankfurt or ZooM Hosting (RO-based).
- DSAR routing, data subject access requests must be answered within 30 days in Romanian.
We ship a Romanian-language cookie banner (Cookiebot or a Magento-native module) with per-purpose granularity, plus a privacy policy template reviewed against ANSPDCP guidance.