How does ANSPDCP (Romanian DPA) + GDPR affect my Magento cookie banner?

Romania’s data protection authority is ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal). GDPR applies as-is across the EU, but ANSPDCP has issued specific guidance + enforcement actions:

  • Legea nr. 190/2018, the Romanian national law implementing GDPR. Layered on top, adds rules around employee monitoring + biometric data.
  • Cookie consent, ANSPDCP follows EDPB guidance: explicit opt-in, no pre-ticked checkboxes, “Reject all” as prominent as “Accept all”. Active enforcement since 2022, fines RON 5,000-100,000 + EUR equivalents for cookie-wall violations.
  • Cookie banner copy, must be in Romanian (primary language) + offer alternatives. Cookie purposes broken down (analytics / marketing / functional). Withdrawal as easy as consent.
  • Data residency, ANSPDCP prefers EU-region hosting (Frankfurt, Paris, Amsterdam OK). Many RO merchants choose AWS Frankfurt or ZooM Hosting (RO-based).
  • DSAR routing, data subject access requests must be answered within 30 days in Romanian.

We ship a Romanian-language cookie banner (Cookiebot or a Magento-native module) with per-purpose granularity, plus a privacy policy template reviewed against ANSPDCP guidance.

Kishan Savaliya
Kishan Savaliya
Adobe Certified Magento Commerce Developer
Ahmedabad [IN]working hours, replies within four hours
When do you need it

Read personally. Never shared. Or email the brief.

More on magento developer romania

Need it fixed, not just explained?

Send the brief with your store URL; the written quote comes back within 24 hours.