purposes of invoicing, preventing commercial disputes or transmitting communications by way of an electronic communication network.
Thus, the New Retention Law appears to introduce non-clarity to the types of data
to be retained by the Providers. Aside from Retained Data, the Providers have no
further obligations to use such retained data, except for specific requests made
according with the relevant legislation.
40
The Providers must delete and transform the Retained Data into anonymous when
such data is no longer needed, but no later than three years as of the date of the
communication (i.e., the date of exchange or transmission of information between
users via a publicly available electronic communications service).
41 Retained Data
from prepaid users of Providers may be processed only for a period of three (3) years
from the date of communication.
An increase in the above period may be requested by courts, prosecution units,
national defence and security bodies. Such a request must be accompanied by a
notice regarding the necessity of retaining such data for purpose of identifying and
conserving evidence (i) during on-going criminal investigations (regardless of the
type of criminal offence investigated) or (ii) for national defence and security
reasons. In such case, the data cannot be kept by the Providers for more than five
(5) years from the date of the request or until the court delivers a final ruling.
42
Access to Retained Data may be granted only in accordance with the legal
restrictions with the prior authorization of the court, in which case the Providers
must communicate the requested Retained Data within a maximum of 48 h as of the
competent public authorities’ request. An exception from the above-mentioned
approval conditions and timeframe is provided for state bodies with powers in
national security and defence (e.g. internal specialized bodies within the Romanian
Intelligence Service, the Ministry of National Defence, the Ministry of Justice, the
Ministry of internal Affairs), as per the specific legislation in this respect. This
approval process was implemented by the Law in response to the Constitutional
Court’s decision. The Court had criticized the fact that the Previous Retention Law
permitted access to Retained Data without a court approval.
Responses to requests for access to Retained Data may be given in hard copy or in
electronic format. All requests and responses submitted in electronic format must be
signed with a certified electronic signature.
43 This obligation may give rise to certain
timing and money wise issues if the Provider does not have the possibility to use a
certified electronic signature.
If the Retained Data is given in hard copy, this may result in increased time and
costs relating to preparing the information for transfer, transferring it to the
requesting entity and reviewing and storing such information. The Providers have
a confidentiality obligation when processing requests for access to Retained Data.
40 See Bibicu et al. (2015).
41 See article 5 (1).
42 See Bibicu et al. (2015).
43 See Bibicu et al. (2015).
306
E. Lazar and D. N. Costescu
Thus, the New Retention Law appears to introduce non-clarity to the types of data
to be retained by the Providers. Aside from Retained Data, the Providers have no
further obligations to use such retained data, except for specific requests made
according with the relevant legislation.
40
The Providers must delete and transform the Retained Data into anonymous when
such data is no longer needed, but no later than three years as of the date of the
communication (i.e., the date of exchange or transmission of information between
users via a publicly available electronic communications service).
41 Retained Data
from prepaid users of Providers may be processed only for a period of three (3) years
from the date of communication.
An increase in the above period may be requested by courts, prosecution units,
national defence and security bodies. Such a request must be accompanied by a
notice regarding the necessity of retaining such data for purpose of identifying and
conserving evidence (i) during on-going criminal investigations (regardless of the
type of criminal offence investigated) or (ii) for national defence and security
reasons. In such case, the data cannot be kept by the Providers for more than five
(5) years from the date of the request or until the court delivers a final ruling.
42
Access to Retained Data may be granted only in accordance with the legal
restrictions with the prior authorization of the court, in which case the Providers
must communicate the requested Retained Data within a maximum of 48 h as of the
competent public authorities’ request. An exception from the above-mentioned
approval conditions and timeframe is provided for state bodies with powers in
national security and defence (e.g. internal specialized bodies within the Romanian
Intelligence Service, the Ministry of National Defence, the Ministry of Justice, the
Ministry of internal Affairs), as per the specific legislation in this respect. This
approval process was implemented by the Law in response to the Constitutional
Court’s decision. The Court had criticized the fact that the Previous Retention Law
permitted access to Retained Data without a court approval.
Responses to requests for access to Retained Data may be given in hard copy or in
electronic format. All requests and responses submitted in electronic format must be
signed with a certified electronic signature.
43 This obligation may give rise to certain
timing and money wise issues if the Provider does not have the possibility to use a
certified electronic signature.
If the Retained Data is given in hard copy, this may result in increased time and
costs relating to preparing the information for transfer, transferring it to the
requesting entity and reviewing and storing such information. The Providers have
a confidentiality obligation when processing requests for access to Retained Data.
40 See Bibicu et al. (2015).
41 See article 5 (1).
42 See Bibicu et al. (2015).
43 See Bibicu et al. (2015).
306
E. Lazar and D. N. Costescu
