Key Facts
Overview
Romania has historically been one of the more permissive EU countries regarding cookie consent, but enforcement has significantly tightened. ANSPDCP issued multiple fines in 2025-2026 for installing non-essential cookies without explicit consent, signaling a clear shift toward strict enforcement.
What This Means for Your Website
- Prior informed consent is required before placing non-essential cookies on Romanian visitors
- Browser settings are no longer considered sufficient consent despite previous tolerance
- ANSPDCP has been issuing fines of RON 15,000-30,000 for cookie violations since 2025
- Consent must align with GDPR standards
Key Requirements
ANSPDCP enforces cookie requirements through Law 506/2004, with penalties ranging from RON 5,000 to RON 100,000 (EUR 1,100-22,000). GDPR fines also apply. Law 190/2018 (GDPR implementation) does not contain dedicated cookie provisions, relying on Law 506/2004 and GDPR principles. The shift from permissive to strict enforcement caught many Romanian websites off guard.
How ConsentStack Handles This
ConsentStack presents Romanian visitors with an opt-in consent banner that meets current ANSPDCP enforcement expectations. No reliance on browser settings — active consent is required for all non-essential cookies.
Penalties
RON 5,000 to RON 100,000 (approx. EUR 1,100-22,000) under ePrivacy law. GDPR penalties also apply.
Key Requirements
- Prior informed consent before placing non-essential cookies
- Information about cookie usage must be provided to users
- Consent should align with GDPR standards
- Strictly necessary exemption for essential cookies
- ANSPDCP increasingly enforcing active consent requirements
Notable Provisions
- Historically more permissive — browser settings previously tolerated
- ANSPDCP tightened enforcement in 2025-2026 with multiple fines
- No dedicated cookie provisions in GDPR implementing law (Law 190/2018)
Other ePrivacy Directive Related Regulations
Other Europe Regulations
Frequently Asked Questions
Has Romania changed its cookie enforcement approach?
Yes. Romania was historically permissive on cookies, but ANSPDCP significantly tightened enforcement in 2025-2026, issuing multiple fines for non-compliant cookie practices.
What are the cookie penalties in Romania?
RON 5,000 to RON 100,000 (approximately EUR 1,100-22,000) under the ePrivacy law. GDPR penalties of up to EUR 20 million or 4% of global turnover also apply.
Are browser settings valid cookie consent in Romania?
No longer viable. While previously tolerated, ANSPDCP now requires active consent and has fined companies for relying on passive consent mechanisms.
Stay compliant with Romanian ePrivacy Law
ConsentStack helps you implement Opt-in consent for Romania automatically.