Romanian data watchdog reports surge in privacy complaints and fines
The National Authority for Personal Data Processing recorded thousands of privacy complaints in 2025, issuing numerous fines and corrective actions.
During 2025, Romania's data protection authority, ANSPDCP, handled a substantial influx of complaints and notifications concerning personal data breaches, leading to a significant number of investigations. The regulator responded with a series of monetary sanctions, formal warnings and mandated corrective steps. The most frequent violations related to illegal access to personal information, both online and offline, disclosure to third parties, cyber-security incidents and unwanted marketing communications.
Additional concerns were raised about the use of surveillance cameras by private parties and firms. The agency also fielded a high number of inquiries about GDPR compliance from both public institutions and private entities. A notable share of the imposed fines faced legal challenges, with many cases brought before the courts.
Why it matters
The findings highlight growing data-privacy risks in Romania and the regulator's active enforcement, affecting businesses and citizens alike.
In this story
