EU Data Act moves closer to implementation in Romania: balancing direct applicability and national enforcement
Romanian authorities have concluded the public consultation on the draft law implementing the EU Data Act, which establishes the national institutional framework for enforcing the Regulation on fair access to and use of data generated by connected products and related services. Although the EU Data Act (or the “Regulation”) already applies directly across the European Union, its effective enforcement depends on national institutional frameworks. Romania has now concluded the public consultation on its draft implementing law, which would designate the competent authorities, establish the national enforcement framework and introduce the sanctions regime that will apply once the legislation is adopted.
1. Why has Romania adopted a draft implementing law if the Data Act is directly applicable?
Although Regulation (EU) 2023/2854 (the “Data Act”) is directly applicable throughout the European Union and does not require transposition into national law, Member States must still adopt certain implementing measures. On 2 July 2026, the National Authority for Communications Administration and Regulation (“ANCOM”) launched a public consultation on a draft law establishing measures for the application of the Data Act. The public consultation period ended on 3 August 2026.
According to the explanatory memorandum accompanying the draft, the purpose of the legislation is to establish the national institutional and procedural framework necessary for the effective application of the Regulation. This includes designating the competent authorities, defining their powers, introducing administrative procedures and establishing the national enforcement and sanctioning regime.
The draft law complements the directly applicable provisions of the Data Act by establishing the national institutional framework for its supervision and enforcement in Romania. In particular, it identifies the competent authorities and defines their respective responsibilities.
The draft also introduces the administrative procedures that will govern enforcement and establishes the national sanctioning regime, based on a comprehensive list of possible offences.
2. Which authorities will supervise and enforce the provisions of the Data Act in Romania?
The draft law designates ANCOM as the competent authority responsible for the application, monitoring and enforcement of the Data Act. ANCOM will also act as Romania’s national Data Coordinator, serving as the primary point of contact for matters relating to the Regulation.
The National Supervisory Authority for Personal Data Processing (“ANSPDCP”) will retain responsibility for matters relating to the protection of personal data within the application of the Data Act, reflecting the close interaction between the Regulation and the GDPR.
The draft law establishes cooperation mechanisms between the Romanian competent authorities, the European Commission and the European Data Innovation Board (“EDIB”). These provisions are intended to facilitate coordinated supervision and promote the consistent application of the Data Act across the European Union.
3. What penalties does the draft law introduce?
One of the draft law’s principal objectives is to establish Romania’s national enforcement framework under the Data Act. To that end, it introduces the national sanctioning regime required by Article 40 of the Regulation. The draft law identifies no fewer than 77 potential offences. In broad terms, the proposed offences mirror the main compliance areas covered by the Data Act. They concern, among other matters, access to and sharing of data generated by connected products and related services, safeguards for trade secrets, restrictions on the use of shared data by third parties, obligations applicable to providers of data processing services, interoperability requirements, international access to non-personal data and the use of smart contracts in data-sharing arrangements.
The draft law proposes administrative fines ranging from RON 5,000 to RON 60,000 (approximately EUR 1,000 to EUR 12,000), with a revised maximum of RON 100,000 (approximately EUR 19,000) for repeated offences. For entities with a turnover exceeding RON 3,000,000 (approximately EUR 570,000), the fine can reach up to 5% of the entity’s turnover for the preceding year and, for repeated offences, up to 10% of turnover.
At this stage, however, the sanctions and fines remain prospective. As the draft implementing law has not yet been adopted, the proposed enforcement measures and penalties are not yet in force.
4. What does the draft law mean for businesses operating in Romania?
Although the draft implementing law has not yet been adopted, it provides an early indication of how the Data Act is expected to be enforced in Romania. Businesses falling within the scope of the Regulation should use this period to assess their compliance programmes and identify any areas requiring further preparation before the national enforcement framework becomes operational.
In practical terms, companies should assess whether their products and services fall within the scope of the Data Act and, where necessary, review their internal data governance and compliance frameworks accordingly. They should also examine existing data-sharing processes and contractual arrangements, identify internal responsibilities for responding to user data access requests and continue monitoring both the legislative process and any future guidance issued by ANCOM and the European Commission.
Importantly, businesses should not postpone compliance efforts until the implementing law is adopted. The substantive obligations under the Data Act already apply throughout the European Union, while the Romanian draft law clarifies how those obligations will be supervised and enforced at national level.
Download the Client Alert in English