Romania is a paradox of GDPR enforcement: it is one of the top three EU countries by the number of fines issued — alongside Spain and Italy — yet its fines are among the smallest by value anywhere in the Union. The regulator behind that high-volume, low-amount style is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) — the National Supervisory Authority for Personal Data Processing. This is a profile of what it is, who runs it, and what it fines for. Every fact is sourced.
Quick facts
- Full name: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) — the National Supervisory Authority for Personal Data Processing
- Role: Romania’s GDPR supervisory authority; a member of the EDPB
- Founding law: Law no. 102/2005 on the establishment, organisation and functioning of the ANSPDCP (ANSPDCP — Raport 2024); it applies the GDPR together with Law no. 190/2018, Romania’s GDPR implementation act
- Leadership: President — Ancuța Gianina Opre; Vice-president — Mirela Nistoroiu (ANSPDCP — leadership)
- Seat: Bucharest
- Website: dataprotection.ro
What the ANSPDCP is — and what it is not
The ANSPDCP is Romania’s data protection authority (DPA — the independent national regulator that supervises and enforces data-protection law) and its GDPR supervisory authority, one of the 27 national authorities on the EDPB. It was established as an autonomous public authority under Law no. 102/2005, and it now enforces the GDPR alongside Law no. 190/2018, the national implementing act (ANSPDCP — Raport 2024).
It is not an AI Act authority and not a court; like every DPA, its AI-relevant work runs through the GDPR.
High volume, low amounts — and a focus on security
What defines the ANSPDCP is its enforcement style, and it is the mirror image of Ireland’s. Where the DPC issues a handful of billion-euro decisions, the ANSPDCP issues a large number of fines that are individually small — placing Romania consistently around third in the EU by fine count, behind Spain and Italy, while its average fine is among the lowest in the Union (enforcementtracker.com).
The recurring theme, as in Poland, is security — Article 32 of the GDPR, the duty to put in place appropriate technical and organisational measures. The cases that defined Romanian enforcement are all breach-and-security cases:
- Raiffeisen Bank — €150,000, 2019. The bank did not ensure its own employees complied with data-protection rules, in a credit-checking process; it was part of a €170,000 set of fines (with €20,000 on the platform Vreau Credit) and among the highest Romanian penalties of its time (EDPB).
- UniCredit Bank — €130,000. For inadequate data-protection-by-design and -by-default, after the personal data of more than 337,000 people was disclosed to third parties (ANSPDCP — leadership/decisions).
- World Trade Center Bucharest — €15,000, July 2019 — Romania’s first GDPR fine. A printed paper list used to check hotel guests at breakfast — containing the data of 46 clients — was photographed by unauthorised people and the data published. Small, almost mundane, but it set the template: Romanian fines follow concrete security lapses (EDPB).
The “breakfast list” case captures the ANSPDCP perfectly: not a landmark legal principle, but a real, fixable failure to protect a list of names — exactly the kind of everyday lapse Romania fines, often and modestly.
Who runs it
The ANSPDCP is led by a President, supported by a Vice-president. As listed on its official leadership page, the President is Ancuța Gianina Opre and the Vice-president is Mirela Nistoroiu (ANSPDCP). Opre also signs the authority’s annual activity report (ANSPDCP — Raport 2024).
What this means for you
- If you process personal data and reach Romanian users: the ANSPDCP is your supervisory authority — and statistically one of the more likely in the EU to actually issue a fine, even if the amount is modest.
- If your weak point is security: this is where the ANSPDCP bites. Raiffeisen, UniCredit and the World Trade Center cases were all about inadequate technical and organisational measures (Article 32) ending in a breach. The defence is operational: access control, staff discipline, and not leaving lists of personal data where they can be photographed.
- If you are a journalist or researcher: “Romania’s privacy regulator” = the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), established under Law no. 102/2005, seated in Bucharest, led by President Ancuța Gianina Opre.
TL;DR
The ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal) is Romania’s GDPR supervisory authority and a member of the EDPB, established under Law no. 102/2005 and enforcing the GDPR alongside Law no. 190/2018. Its defining trait is volume over size: Romania sits around third in the EU by number of fines but issues some of the smallest amounts, concentrated on Article 32 security failures — Raiffeisen Bank (€150,000), UniCredit (€130,000) and the famous World Trade Center Bucharest “breakfast list” fine (€15,000, Romania’s first). It is led by President Ancuța Gianina Opre, with Vice-president Mirela Nistoroiu.
Sources
- ANSPDCP — Raport de activitate 2024 (official annual report) — the legal basis (Law no. 102/2005 and Law no. 190/2018) and the authority’s activity, signed by President Ancuța Gianina Opre
- ANSPDCP — leadership (official) — President Ancuța Gianina Opre and Vice-president Mirela Nistoroiu
- EDPB — Romanian SA fines Raiffeisen Bank and Vreau Credit — the €150,000 Raiffeisen security fine
- GDPR pillar · EDPB profile · dataprotection.ro