GDPR Data Breach in Romania: 72-Hour Guide
A GDPR data breach in Romania creates an immediate legal decision window. The company must contain the incident, determine whether personal data were compromised, assess the risk to individuals and decide whether the Romanian supervisory authority, the ANSPDCP, must be notified within 72 hours.

What companies should know immediately:
- The 72-hour period runs from the controller’s awareness of the breach, not necessarily from the moment the incident first occurred.
- Every personal data breach must be documented, even when notification is not required.
- The ANSPDCP must be notified unless the breach is unlikely to create a risk to individuals’ rights and freedoms.
- Affected individuals must also be informed without undue delay when the breach is likely to create a high risk.
- An incomplete investigation does not justify silence. GDPR permits information to be submitted in phases.
This guide is designed for Romanian companies, foreign investors, directors, compliance teams and data protection officers responding to an actual or suspected incident. It should be used together with an incident-specific legal and technical assessment. For preventive support and breach response, see our data protection services in Romania.
What qualifies as a personal data breach?
Article 4(12) of the General Data Protection Regulation defines a personal data breach as a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data. The concept is wider than a cyberattack and covers confidentiality, integrity and availability incidents.
| Breach type | What it means | Common example | Immediate check |
|---|---|---|---|
| Confidentiality | Personal data are accessed or disclosed without authorisation. | An email with customer files is sent to the wrong recipient, credentials are stolen or an attacker exfiltrates a database. | Who received or accessed the data, and can further access be stopped? |
| Integrity | Personal data are altered without authorisation or by accident. | Payroll details are changed, records are corrupted or an unauthorised user modifies a customer account. | Which records changed, can the original data be restored, and were decisions made using incorrect data? |
| Availability | Personal data become unavailable or are destroyed. | Ransomware encrypts files, a database is deleted or a lost device contains the only copy of records. | Are reliable backups available, how long will services be disrupted, and could the loss harm individuals? |
A security event that does not involve personal data is not a personal data breach under GDPR. Conversely, a small incident can still be a breach. Under the data protection rules applicable in Romania, the number of affected people matters, but so do the sensitivity of the data, the ease of identification, the possible consequences and the vulnerability of the people concerned.
When does the 72-hour notification period start?
Article 33 requires notification without undue delay and, where feasible, no later than 72 hours after the controller becomes aware of the breach. According to the EDPB breach-notification guidelines, awareness exists when the controller has a reasonable degree of certainty that a security incident occurred and led to personal data being compromised.
A brief initial investigation may be necessary to determine whether personal data were actually affected. That does not permit an organisation to delay investigation or postpone escalation. Once there is reasonable certainty, the clock runs even if the full cause, exact number of records or final consequences are still being investigated.
Select a stage to see the priority. The timetable is operational guidance, not a replacement for immediate action.
Record when the controller first reached a reasonable degree of certainty that personal data had been compromised. Preserve the facts supporting that timestamp.
Do not wait for a final forensic report before making the legal notification decision. Article 33 expressly permits phased notification when all information cannot be provided at the same time.
Must every breach be notified to the ANSPDCP?
No. Every breach must be recorded internally, but not every breach must be reported to the authority. The controller must assess the likely impact on the rights and freedoms of natural persons. The result falls into one of three practical levels.
Select a risk level to see the corresponding GDPR response. The conclusion must be supported by documented facts.
If the breach is unlikely to result in a risk to individuals, authority notification is not required. The breach, assessment, effects and remedial action must still be recorded.
| Assessment result | Required action | Typical considerations |
|---|---|---|
| Unlikely to create risk | Document the breach and the reasons for not notifying. | Strong effective safeguards, limited data, verified recovery, no realistic adverse effect and reliable containment. |
| Likely to create risk | Notify the competent supervisory authority without undue delay and, where feasible, within 72 hours. | Possible identity theft, fraud, loss of confidentiality, discrimination, financial loss, reputational harm or loss of control over data. |
| Likely to create high risk | Notify the authority and communicate with affected individuals without undue delay, unless an Article 34 exception applies. | Special-category data, credentials or financial data, vulnerable people, large-scale exposure, easy identification or serious likely consequences. |
Risk is not determined by a single formula. The company should consider the type of breach, nature and volume of data, identifiability, severity and likelihood of consequences, number and characteristics of affected people, and the effectiveness of safeguards such as encryption. The EDPB’s practical breach examples are useful benchmarks, but the actual incident must be assessed on its own facts.
What must an ANSPDCP notification contain?
Article 33(3) establishes the minimum information. The ANSPDCP’s current online notification form requests additional operational details that allow the authority to understand the incident and the controller’s response.
| Notification field | What the company should prepare |
|---|---|
| Nature of the breach | A concise incident summary, whether confidentiality, integrity or availability was affected, and the relevant systems and processing operations. |
| People and records | Categories and approximate number of affected data subjects, plus categories and approximate number of personal data records. |
| Contact point | Name and contact details of the DPO or another person able to provide further information. |
| Likely consequences | The realistic adverse effects for individuals, including how they could occur and which groups face the greatest exposure. |
| Measures | Containment and remediation already performed, further measures proposed, and actions intended to mitigate adverse effects. |
| Timeline | Incident date and time where known, detection, awareness, response milestones and reasons for any notification made after 72 hours. |
| Additional context | Processors involved, security measures, cross-border aspects, other authorities notified and whether the filing is initial or supplemental. |
If exact figures are not yet available, provide reasonable estimates and state that the investigation continues. Under Article 33(4), missing information may be supplied in phases without undue further delay. If the filing occurs after 72 hours, it must include reasons for the delay.
How is a breach notified in Romania?
The ANSPDCP maintains a dedicated personal data breach notification page with access to its online form. Before submission, the company should identify the correct controller, confirm whether the incident also affects other group entities or joint controllers, and determine whether the ANSPDCP is the competent or lead supervisory authority for any cross-border processing.
The notification should be consistent with the internal breach register, technical evidence, communications plan and any supplemental filing. A company should not understate confirmed facts, speculate beyond the evidence or present an incomplete notification as final.
Enforcement point: the ANSPDCP has publicly reported sanctions for failure to notify a personal data breach within the 72-hour period. Breach-notification obligations under Articles 33 and 34 also fall within the GDPR administrative-fine tier of up to EUR 10 million or, for an undertaking, up to 2% of total worldwide annual turnover for the preceding financial year, whichever is higher. The actual measure depends on the Article 83 assessment and the circumstances of the case.
Who should be involved in the response?
A data breach cannot be handled by IT alone. The legal assessment depends on verified technical facts, while technical containment must preserve evidence and avoid creating inconsistent records. A small decision team should be activated immediately, with clear authority and one incident chronology.
Select a workstream to see its principal responsibility. All teams should work from the same verified timeline.
Contain the incident, preserve logs and forensic evidence, confirm affected systems and data, remove persistence, restore safely and record every material action.
- Security and IT: containment, forensic preservation, affected-system analysis, eradication, recovery and evidence of technical safeguards.
- DPO and legal counsel: awareness timestamp, controller or processor status, risk assessment, authority competence, notification drafting and privilege strategy where applicable.
- Management and communications: decision authority, resources, operational continuity, messaging and escalation to insurers or relevant corporate bodies.
- Processors and vendors: incident facts, contractual notification, audit cooperation, subprocessor information and coordinated remedial action.
What is the difference between a controller and a processor?
The controller decides why and how personal data are processed and carries the Article 33 duty to notify the competent supervisory authority. A processor must notify the controller without undue delay after becoming aware of a personal data breach. GDPR does not give processors a separate 72-hour period for notifying the controller.
Data processing agreements should therefore establish an immediate escalation channel, minimum incident information, continuous updates, preservation duties and cooperation with notifications and communications. A processor’s delayed or incomplete report does not remove the controller’s obligation once the controller becomes aware.
| Role | Primary breach duty | Contractual control |
|---|---|---|
| Controller | Assess risk, document every breach, notify the competent authority where required and communicate with individuals where high risk is likely. | Maintain response governance and require processors to provide prompt, usable incident information. |
| Processor | Notify the controller without undue delay and assist with the controller’s Article 32–36 obligations. | Define rapid reporting, evidence preservation, subprocessor escalation, investigation access and update frequency. |
| Joint controllers | Allocate responsibilities transparently, while each remains accountable for the GDPR obligations applicable to it. | Agree in advance who leads investigation, authority contact and data-subject communication. |
Vendor and technology contracts should be reviewed before an incident occurs. Our IT law services in Romania cover data-processing terms, security obligations, audit rights and incident-response clauses.
When must affected individuals be informed?
Under Article 34, the controller must communicate the breach to affected individuals without undue delay when it is likely to result in a high risk to their rights and freedoms. This obligation is separate from the 72-hour authority-notification rule. The communication must use clear and plain language and explain the nature of the breach, the contact point, likely consequences and measures taken or proposed.
Communication is not required when one of the Article 34(3) conditions applies:
- appropriate protection measures applied to the affected data and made them unintelligible to unauthorised persons, such as effective encryption;
- subsequent measures ensure that the high risk is no longer likely to materialise; or
- individual communication would involve disproportionate effort, in which case a public communication or similarly effective measure is required.
The message should help people protect themselves. Depending on the incident, practical steps may include changing credentials, enabling multi-factor authentication, contacting a bank, monitoring accounts, watching for targeted phishing or using a dedicated support contact. Avoid minimising the event or overwhelming recipients with technical detail.
How should breach risk be assessed?
The legal threshold concerns risk to people, not only damage to the company. Business interruption, contractual liability and reputational harm matter to the response, but they do not replace the individual-rights analysis required by Articles 33 and 34.
Select a risk area to review typical consequences. More than one area may apply to the same incident.
Identification data, credentials, signatures or financial information may enable account takeover, fraudulent transactions or convincing social-engineering attacks.
High-risk indicators include sensitive or criminal-offence data, authentication credentials, detailed financial or identity information, data concerning children or other vulnerable people, large-scale exposure, malicious exfiltration, weak safeguards and consequences that are difficult for individuals to reverse. Effective encryption, rapid verified retrieval from a trusted recipient and prompt credential revocation may reduce risk, but each control must be tested against the facts.
What evidence and documentation should be preserved?
Article 33(5) requires the controller to document every personal data breach, including the facts, effects and remedial action. The record must allow the supervisory authority to verify compliance. A defensible incident file should include:
- the original alert, detection data and a precise incident chronology;
- the awareness timestamp and the facts supporting it;
- affected systems, processing activities, data categories, people and record estimates;
- logs, forensic images, access records, emails, vendor reports and chain-of-custody information where relevant;
- containment, eradication, recovery and mitigation actions;
- the risk and high-risk assessments, including reasons and assumptions;
- the decision to notify or not notify, approvals and any delay explanation;
- copies of the initial and supplemental ANSPDCP filings;
- data-subject communications or the documented Article 34 exception; and
- post-incident findings, corrective actions and responsibility for completion.
Records should distinguish confirmed facts from estimates and hypotheses. The company should also consider cybersecurity, contractual and insurance requirements, DORA and other sector-specific reporting duties, and criminal-law reporting duties. These may use different thresholds and deadlines from GDPR.
A practical 72-hour response checklist
- Activate the incident team. Establish one decision lead, secure communications and a contemporaneous chronology.
- Contain without destroying evidence. Isolate affected resources, revoke compromised access and preserve logs and forensic material.
- Confirm whether personal data are involved. Identify the controller, processor, systems, processing activities and data flows.
- Record the awareness timestamp. Explain when reasonable certainty was reached and what facts supported it.
- Map the scope. Identify data categories, affected people, approximate record volumes, jurisdictions and vulnerable groups.
- Assess risk to individuals. Analyse likelihood, severity, safeguards, realistic misuse and reversibility of harm.
- Decide on authority notification. Notify unless the breach is unlikely to create risk. Use phased notification if necessary.
- Assess high risk separately. Decide whether individuals must be informed and prepare clear protective guidance.
- Coordinate other duties. Review processors, insurers, contractual partners, cybersecurity rules and sector regulators.
- Continue and close the response. Supplement filings, verify recovery, complete remediation and retain the breach record.
For a broader preventive review, use our GDPR compliance checklist for Romanian companies. Even though the checklist was published earlier, the core governance controls remain relevant and should be checked against current processing and security practices.
Frequently asked questions
Does the 72-hour period start when IT sees the first suspicious alert?
Not necessarily. The EDPB treats a controller as aware when it has a reasonable degree of certainty that a security incident occurred and compromised personal data. A short initial investigation may establish whether a breach occurred, but it must begin promptly and cannot be used to delay awareness artificially.
Must every ransomware incident be notified to the ANSPDCP?
Not automatically, but ransomware often creates availability, integrity and possibly confidentiality risks. The controller must determine whether personal data were affected, whether exfiltration or unauthorised access occurred, whether reliable backups exist and what consequences are likely for individuals. The conclusion and supporting facts must be documented.
Is an email sent to the wrong recipient a reportable breach?
It is normally a confidentiality breach if personal data were disclosed without authorisation. Whether ANSPDCP notification is required depends on the risk assessment, including the data involved, recipient, ability to retrieve or delete the message, evidence of access and possible consequences. The incident must still be recorded internally.
Can a company notify before the investigation is complete?
Yes. Article 33 permits phased notification when all required information cannot be provided at the same time. The initial notification should contain the available facts and make clear what remains under investigation. Additional information must be supplied without undue further delay.
Does a processor notify the ANSPDCP directly?
The processor’s express Article 33 duty is to notify the controller without undue delay. The controller assesses and makes the supervisory-authority notification. Separate duties may arise from the processor’s own role in other processing, contractual arrangements, cross-border circumstances or sector-specific law.
Must affected people always be informed?
No. Direct communication is required when the breach is likely to result in a high risk, unless an Article 34(3) exception applies. Authority notification uses the lower threshold of likely risk. A breach may therefore require ANSPDCP notification without requiring direct communication to individuals.
What happens if the 72-hour deadline is missed?
The company should notify without further delay and explain why the filing is late. A missed deadline does not remove the notification obligation. The authority may consider the delay, cooperation, mitigation, severity and other Article 83 factors when deciding on corrective measures or a fine.
Need urgent advice on a GDPR data breach in Romania?
We help companies assess notification thresholds, prepare ANSPDCP filings, coordinate processor responses and draft communications to affected individuals.
Book a consultationLegal disclaimer: This article provides general information and does not constitute legal advice. The applicable response depends on the facts, the company’s role, the data and individuals affected, the competent authority and any sector-specific obligations. Obtain advice for the specific incident.
AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.



















