1.2 Organization of the Report
This report is divided into four chapters.
After the introduction provided in Sect. 1, Sect. 2 will give an overview of the
general data protection framework and its provisions in the Romanian legal system,
presenting the novelties that came up with it. For this purpose, that chapter will
examine the applicable rules and the provisions of the laws regulating the National
Supervisory Authority for Personal Data Processing activity, the provisions of the
law on electronic commerce, the provisions of the law regarding on the measures for
the application of Regulation (EU) 2016/679 and lastly the provisions of the law on
the regulation of personal data processing by the structures/units of the Ministry of
Administration and Interior in the activities of preventing, investigating and fighting
crimes, as well as maintaining and securing public order.
Section 3 will be analysing the status of specific areas on the field of data
protection—health data and employment data.
Section 4 will provide an overview of the Romanian Data retention law.
2 The General Data Protection Framework
The new legislation proves to be quite complex and compared to the former
Romanian data protection regulation/law,
2 which has been operating for almost
15 years without any major changes brought to it during these years, GDPR
3
(General Data Protection Regulation) came up with many revolutionary changes in
the collecting, processing and storing of personal data. These include, among others:
a) An increase in penalties for breaches of personal data protection rules. Compared to the current situation, where maximum fines amount to 50,000 lei, the
Regulation sets out the DPA (Data protection authority) may impose a fine of up
to 83,610,000 lei (around 20 million EUR), or 4% of the total worldwide
turnover;
b) Expanding the current and introducing new individual’s rights, including the
right to request restrictions to the scope of the processing of personal data, the
right to data portability, the right to be provided with a copy of the personal data
at no charge and the right “to be forgotten” (droit a l’oublie);
2 See Law No. 677/2001 on the Protection of Individuals with Regard to the Processing of Personal
Data and the Free Movement of Such Data, amended and completed, published in the Official
Gazette no. 790 from 12 December 2001.
3 See Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on
the protection of natural persons with regard to the processing of personal data and on the free
movement of such data, OJ L 119, 4.5.2016, repealing Directive 95/46/EC.
286
E. Lazar and D. N. Costescu
This report is divided into four chapters.
After the introduction provided in Sect. 1, Sect. 2 will give an overview of the
general data protection framework and its provisions in the Romanian legal system,
presenting the novelties that came up with it. For this purpose, that chapter will
examine the applicable rules and the provisions of the laws regulating the National
Supervisory Authority for Personal Data Processing activity, the provisions of the
law on electronic commerce, the provisions of the law regarding on the measures for
the application of Regulation (EU) 2016/679 and lastly the provisions of the law on
the regulation of personal data processing by the structures/units of the Ministry of
Administration and Interior in the activities of preventing, investigating and fighting
crimes, as well as maintaining and securing public order.
Section 3 will be analysing the status of specific areas on the field of data
protection—health data and employment data.
Section 4 will provide an overview of the Romanian Data retention law.
2 The General Data Protection Framework
The new legislation proves to be quite complex and compared to the former
Romanian data protection regulation/law,
2 which has been operating for almost
15 years without any major changes brought to it during these years, GDPR
3
(General Data Protection Regulation) came up with many revolutionary changes in
the collecting, processing and storing of personal data. These include, among others:
a) An increase in penalties for breaches of personal data protection rules. Compared to the current situation, where maximum fines amount to 50,000 lei, the
Regulation sets out the DPA (Data protection authority) may impose a fine of up
to 83,610,000 lei (around 20 million EUR), or 4% of the total worldwide
turnover;
b) Expanding the current and introducing new individual’s rights, including the
right to request restrictions to the scope of the processing of personal data, the
right to data portability, the right to be provided with a copy of the personal data
at no charge and the right “to be forgotten” (droit a l’oublie);
2 See Law No. 677/2001 on the Protection of Individuals with Regard to the Processing of Personal
Data and the Free Movement of Such Data, amended and completed, published in the Official
Gazette no. 790 from 12 December 2001.
3 See Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on
the protection of natural persons with regard to the processing of personal data and on the free
movement of such data, OJ L 119, 4.5.2016, repealing Directive 95/46/EC.
286
E. Lazar and D. N. Costescu
