c) The obligation to formally notify the intent to process personal data is revoked,
and on the contrary, the obligation to keep internal records of personal data that
are being processed is introduced;
d) The obligation for companies to establish a job position of a data protection
officer under certain conditions;
e) The rules for technical and organizational measures aimed at protecting personal
data are refined;
f) The data controller will have a new duty to assess the impact of the data
processing on the personal data protection and if necessary, to consult the
supervisory authority on a mandatory basis;
g) Any breach of personal data security and the individuals concerned will have to
be immediately notified to the DPA.
2.1 The Applicable Rules in Romania
On the 31st of July 2018, Law no. 190/2018
4 on the measures for the application of
Regulation (EU) 2016/679 of the European Parliament and of the Council of
27 April 2016 on the protection of natural persons with regard to the processing of
personal data and on the free movement of such data, and repealing Directive 95/46/
EC (General Data Protection Regulation) entered into force. This law establishes the
measures necessary for the implementation at national level, mainly, of the provisions of Article 6 (2), Article 9 (4), Articles 37-39, 42, 43, Article 83 (7), Article
85 and Articles 87-89 of the GDPR.
Also, the Law no. 129/2018 for amending and supplementing Law no. 102/2005
5
regarding the establishment, organization and functioning of the National Supervisory Authority for Personal Data Processing and for repealing Law no. 677/2001 on
the protection of natural persons with regard to the processing of personal data and
on the free movement of such data has entered into force (the “DPA Authority
Law”).
The National Supervisory Authority for Personal Data Processing (NSAPDP)
issued Decision no. 133 of the 3rd of July 2018 on the approval of the procedure for
receiving and solving complaints. This Decision was published in the Official
Journal of Romania no. 600 of the 13th of July 2018, Part I and entered into force
on the date of the publication. This decision approves the procedure for receiving
and solving complains, set out in Annex no. 1, as well as the complaint form in
4 See Law no. 190 of 18 July 2018 on the implementation of Regulation (EU) 2016/679 of the
European Parliament and of the Council of 27 April 2016 on the protection of individuals with
regard to the processing of personal data and on the free movement of such data; and repealing
Directive 95/46/EC, published in the Official Gazette no. 651 from 26 July 2018.
5 See Law no. 102 of 3 May 2005 on the establishment, organization and functioning of the National
Supervisory Authority for Personal Data Processing, published in the Official Gazette no. 947 from
9 November 2018.
Data Protection Regulations: Overview of the Romanian Legislation and. . .
287
and on the contrary, the obligation to keep internal records of personal data that
are being processed is introduced;
d) The obligation for companies to establish a job position of a data protection
officer under certain conditions;
e) The rules for technical and organizational measures aimed at protecting personal
data are refined;
f) The data controller will have a new duty to assess the impact of the data
processing on the personal data protection and if necessary, to consult the
supervisory authority on a mandatory basis;
g) Any breach of personal data security and the individuals concerned will have to
be immediately notified to the DPA.
2.1 The Applicable Rules in Romania
On the 31st of July 2018, Law no. 190/2018
4 on the measures for the application of
Regulation (EU) 2016/679 of the European Parliament and of the Council of
27 April 2016 on the protection of natural persons with regard to the processing of
personal data and on the free movement of such data, and repealing Directive 95/46/
EC (General Data Protection Regulation) entered into force. This law establishes the
measures necessary for the implementation at national level, mainly, of the provisions of Article 6 (2), Article 9 (4), Articles 37-39, 42, 43, Article 83 (7), Article
85 and Articles 87-89 of the GDPR.
Also, the Law no. 129/2018 for amending and supplementing Law no. 102/2005
5
regarding the establishment, organization and functioning of the National Supervisory Authority for Personal Data Processing and for repealing Law no. 677/2001 on
the protection of natural persons with regard to the processing of personal data and
on the free movement of such data has entered into force (the “DPA Authority
Law”).
The National Supervisory Authority for Personal Data Processing (NSAPDP)
issued Decision no. 133 of the 3rd of July 2018 on the approval of the procedure for
receiving and solving complaints. This Decision was published in the Official
Journal of Romania no. 600 of the 13th of July 2018, Part I and entered into force
on the date of the publication. This decision approves the procedure for receiving
and solving complains, set out in Annex no. 1, as well as the complaint form in
4 See Law no. 190 of 18 July 2018 on the implementation of Regulation (EU) 2016/679 of the
European Parliament and of the Council of 27 April 2016 on the protection of individuals with
regard to the processing of personal data and on the free movement of such data; and repealing
Directive 95/46/EC, published in the Official Gazette no. 651 from 26 July 2018.
5 See Law no. 102 of 3 May 2005 on the establishment, organization and functioning of the National
Supervisory Authority for Personal Data Processing, published in the Official Gazette no. 947 from
9 November 2018.
Data Protection Regulations: Overview of the Romanian Legislation and. . .
287
