{"id":146524,"date":"2026-08-11T09:53:13","date_gmt":"2026-08-11T09:53:13","guid":{"rendered":"https:\/\/my.legal500.com\/guides\/?post_type=comparative_guide&#038;p=146524"},"modified":"2026-08-11T09:53:13","modified_gmt":"2026-08-11T09:53:13","slug":"romania-tmt","status":"publish","type":"comparative_guide","link":"https:\/\/my.legal500.com\/guides\/chapter\/romania-tmt\/","title":{"rendered":"Romania: TMT"},"content":{"rendered":"","protected":false},"template":"","class_list":["post-146524","comparative_guide","type-comparative_guide","status-publish","hentry","guides-tmt","jurisdictions-romania"],"acf":[],"appp":{"post_list":{"below_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Rubin Meyer Doru &amp; Trandafir, SPCA<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2026\/07\/RMDT_logo-nou_format-jpg.jpg\"\/><\/span><\/div>"},"post_detail":{"above_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Rubin Meyer Doru &amp; Trandafir, SPCA<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2026\/07\/RMDT_logo-nou_format-jpg.jpg\"\/><\/span><\/div>","below_title":"<span class=\"guide-intro\">This country specific Q&amp;A provides an overview of TMT laws and regulations applicable in Romania<\/span><div class=\"guide-content\"><div class=\"filter\">\r\n\r\n\t\t\t\t<input type=\"text\" placeholder=\"Search questions and answers...\" class=\"filter-container__search-field\">\r\n\t\t\t<\/div>\r\n\r\n\t\t\t\r\n\r\n\r\n\t\t\t<ol class=\"custom-counter\">\r\n\r\n\t\t\t\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 How are proprietary rights in software and associated materials protected?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Software is protected mainly under the Copyright Law no. 8\/1996, which transposes the Software Directive no.2009\/24\/EC, the InfoSoc Directive no.2001\/29\/EC, and the DSM Directive (EU)2019\/790 on Copyright in the Digital Single Market. Protection arises automatically upon creation, without registration, although voluntary registration at the Romanian Copyright Office \u2013 ORDA provides evidentiary benefits and opposability. It covers all material expressions of a program, including source code, object code, preparatory design material and accompanying manuals, but not also the underlying ideas, principles, logic, algorithms, programming language as such, data file formats, or interfaces. This solution is reinforced by the CJEU case law, eg, C-406\/10, <em>SAS Institute Inc. v World Programming Ltd<\/em>.<\/p>\n<p>Associated materials are, upon the case, protected through several cumulative regimes: (i) documentation and original graphical user interfaces may attract copyright as literary\/artistic works (C-393\/09, <em>BSA<\/em>, or C-406\/10, <em>SAS Institute Inc. v World Programming Ltd<\/em>); (ii) databases benefit from the sui generis database right (Law 8\/1996, transposing Directive 96\/9\/EC on the legal protection of databases); (iii) confidential technical know-how is protected as a trade secret under Law no. 11\/1991 on combating unfair competition and, more substantially, under the Government Emergency Ordinance (GEO) no.25\/2019 transposing the Trade Secrets Directive (EU) 2016\/943. This latter law protects confidential software algorithms, source code, and development methodologies provided they meet the requirements of secrecy, commercial value, and reasonable protective measures. Remedies, in this case, include injunctions, damages, and seizure of infringing products. Computer-implemented inventions may be patentable only where they produce a further technical effect, since programs \u201cas such\u201d are excluded under Law no. 64\/1991 on patents \u2013 which mirrors Article 52 of the European Patent Convention (EPC) ratified by the Romanian Parliament via Law no.615\/2002. Branding and product names are protected as trademarks under the Trademarks Law No. 84\/1998.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 In the event that software is developed by a software developer, consultant or other party for a customer, who will own the resulting proprietary rights in the newly created software in the absence of any agreed contractual position?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Romanian copyright system is author-centric. Developers \u2014 always natural persons \u2014 retain copyright ownership by default. They are the recognized authors and initial owners of both moral and economic (patrimonial) rights. According to the Copyright Law no.8\/1996, moral rights are inalienable and economic rights may pass to a third party only by written assignment, which is a validity condition.<\/p>\n<p>For commissioned works generally, article 47 of the Copyright Law provides that the rights remain with the author \/ developer, absent contrary stipulation. Exceptionally, for programs created by an employee in the exercise of their duties, or on the employer\u2019s direct instructions, article 75 of the Copyright Law provides that the patrimonial rights belong to the employer unless otherwise agreed in writing.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 Are there any specific laws that govern the harm \/ liability caused by Software \/ computer systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Romania has not implemented a standalone \u201csoftware liability\u201d framework. Liability is therefore governed by general regimes: contractual liability, under the Romanian Civil Code, including warranty for hidden defects and liability for non-performance, same as tort\/delict (under articles 1349 and 1357 et seq), with distinct liability for damage caused by things (article 1376). Product liability is specifically addressed by Law no. 240\/2004 transposing the Product Liability Directive (PLD) no.85\/374\/EEC, which imposes strict producer liability for damage caused by defective products, and which has generated vivid debates on whether intangible standalone software qualifies as a \u2018product\u2019.<\/p>\n<p>The revised Product Liability Directive (EU) 2024\/2853, which is meant to repeal the PLD, expressly brings standalone software, AI systems and digital manufacturing files within the notion of \u2018product\u2019, and addresses cybersecurity vulnerabilities, software updates and the burden of proof. The revised PLD must be transposed by 9 December 2026 and will apply to all products placed on the market after that deadline. Under the current regime, however, software embedded in physical products, such as IoT devices, or medical devices, etc, is generally treated as part of the product for liability purposes.<\/p>\n<p>As for the proposed AI Liability Directive, it was dropped by the Commission in 2025 and has not been replaced so far by any other fault-based AI-liability instrument. General tort law and the revised PLD will hence remain to govern this matter.<\/p>\n<p>For consumer-facing digital content and services, GEO no.141\/2021 (transposing Directive (EU) 2019\/770 on certain aspects concerning contracts for the supply of digital content and digital services) sets detailed conformity and remedy rules. Non-conforming software entitles consumers to repairment, replacement, price reduction, or contract termination.<\/p>\n<p>In certain cases, there is sector-specific liability. For example, for medical devices, Software as a Medical Device \u2013 SaMD, is regulated by the Medical Devices Regulation (EU) no.2017\/745 which has been further transposed into national law by various technical norms \u2013 such as Order of the Ministry of Health no.650\/2025 on medical devices for in-vitro diagnosis. Software used in banking and fintech is subject to oversight by the National Bank of Romania \u2013 BNR and the Financial Supervisory Authority \u2013 ASF, with potential administrative and criminal liability for system failures. Also, critical infrastructure software operating in essential services sector is subject to the cyber security obligations laid down in GEO no.155\/2024 transposing the NIS2 Directive (EU) no.2022\/2555. Operators of essential and important services face administrative fines and potential criminal liability for cybersecurity incidents caused by inadequate security measures.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 To the extent not covered by (3) above, are there any specific laws that govern the use (or misuse) of software \/ computer systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes. The Romanian Criminal Code incriminates offences against information systems and data, transposing the Council of Europe\u2019s Convention on Cybercrime and Directive no.2013\/40\/EU on attacks against information systems (which replaces Council Framework Decision 2005\/222\/JHA). They include illegal access to an information system (article 360), illegal interception of data transmissions (article 361), illegal alteration of computer data (article 362), disruption of the operation of an information system (article 363), unauthorised transfer of data (article 364) and the illegal production\/possession of devices or programs for committing such offences (article 365), together with computer-related forgery and fraud (articles 325 and 249).<\/p>\n<p>At the civil level, misuse of software is governed by licence terms and the unfair-competition regime regulated by Law no.11\/1991 on the fight against unfair competition and the Competition Law no.21\/1996. Misuse of software to facilitate anti-competitive practices such as algorithmic collusion or price-fixing bots, etc, is subject to severe penalties. For online intermediaries, liability is governed by the Digital Services Act (DSA) &#8211; Regulation (EU) 2022\/2065. Specific clauses sanctioning the misuse of software or computer systems are contained also in the e-Commerce Law no.365\/2002 and the e-Privacy Law no.506\/2004.<\/p>\n<p>Misuse of software for money laundering, terrorist financing or market manipulation is additionally regulated under the Anti Money Laundering Law (AML) no.129\/2019 and the EU Market Abuse Regulation no.596\/2014.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (Licence and SaaS) \u2013 Other than as identified elsewhere in this overview, are there any technology-specific laws that govern the provision of software between a software vendor and customer, including any laws that govern the use of cloud technology?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Such relationships are largely governed by freedom of contract under the Civil Code.<\/p>\n<p>Several special regimes may however apply. Where the customer is a consumer, the digital content\/services regime under GEO no.141\/2021 and consumer-protection law govern conformity and remedies. GEO no.141\/2021 introduces specific conformity requirements (functionality, compatibility, interoperability), remedies for non-conformity (repair, replacement, price reduction, termination), right of withdrawal for digital content contracts, and information requirements regarding software updates and durability. The General Data Protection Regulation (GDPR) no.2016\/679, GDPR application Law no.190\/2018 and the e-Privacy Law no.506\/2004 also impose specific obligations on the processor (under article 28 GDPR). The EU Data Act (Regulation (EU) 2023\/2854) introduces cloud-switching and egress facilitation, interoperability requirements, mandatory switching assistance and controls over unfair unilaterally imposed data terms, including B2B. E-commerce\/information-society information duties flow largely from Law no.365\/2002. They include transparency obligations for service providers, validity conditionalities for contracts, safe harbour provisions for intermediaries, and cooperation with authorities. Sector rules \u2014 notably DORA Regulation (EU) 2022\/2554 \u2014 govern ICT\/cloud arrangements for financial entities.<\/p>\n<p>Romanian does not have dedicated cloud computing legislation. Cloud services fall, in general, into the scope of Law no.356\/2002 and also of the GDPR and the NIS2 Directive. The EU Cloud Certification Scheme (EUCS) remains in development. Law no.208\/2021 on the National Cloud Strategy, on the other hand, establishes the framework for cloud adoption by public authorities, emphasizing data sovereignty, interoperability, and security standards aligned with the EUCS. Inasmuch as the financial service cloud is concerned, BNR and ASF have issued guidelines on cloud outsourcing by regulated financial institutions, requiring risk assessment, contractual safeguards, and exit strategies.<\/p>\n<p>For SaaS incorporating AI, the EU AI Act (Regulation (EU) 2024\/1689) applies directly, with phased implementation, imposing conformity obligations, strict transparency requirements, and risk management obligations depending on AI system classification.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Is it typical for a software vendor to cap its maximum financial liability to a customer in a software transaction? If \u2018yes\u2019, what would be considered a market standard level of cap?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes, liability caps are common, especially in negotiated B2B contracts, and enforceable under the Civil Code, subject to mandatory limits. Article 1355 of the Civil Code prohibits the exclusion or limitation of liability for intentional fault or gross negligence, and for harm to life or physical\/mental integrity. Unfair-terms rules apply in B2C, and the Data Act now polices unfair unilaterally imposed data terms in B2B. There however are no statutory figures. The market standard is typically a multiple of the fees paid in the preceding twelve months, commonly 100 to 150% of annual charges, and up to 200% (or total contract value) for higher-risk or fixed-term deals, with large enterprise transactions negotiating higher multiples or a fixed monetary cap. All caps must be drafted to accommodate the Article 1355 carve-outs, which cannot be contracted around. Certain other liabilities are typically excluded from the general cap, or subject to higher caps. For details, check Q7 below.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Please comment on whether any of the following areas of liability would typically be excluded from any financial cap on the software vendor\u2019s liability to the customer or subject to a separate enhanced cap in a negotiated software transaction (i.e. unlimited liability): (a) confidentiality breaches; (b) data protection breaches; (c) data security breaches (including loss of data); (d) IPR infringement claims; (e) breaches of applicable law; (f) regulatory fines; (g) wilful or deliberate breaches; (h) claims arising out of or in relation to artificial intelligence.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Romanian-market practice broadly follows the wider EU practice, subject to the limitations brought by article 1355 of the Civil Code:<\/p>\n<ul>\n<li>(a) confidentiality breaches \u2014 frequently excluded from the general cap, or subject to a separate, higher cap, eg, 24 to 36 months. In transactions involving sensitive data, such as healthcare, or financial services, etc, confidentiality breaches may trigger unlimited liability;<\/li>\n<li>(b) data-protection breaches \u2014 usually unlimited, or separately negotiated, esp. driven by the GDPR fines exposure (4% of global turnover and up to \u20ac20 million);<\/li>\n<li>(c) data-security breaches \/ loss of data \u2014 similar to data protection breaches, caps are typically enhanced or even excluded. For SaaS, unlimited liability is sometimes required. Also, vendors\u2019 cybersecurity insurance coverage often influences the level of negotiated caps;<\/li>\n<li>(d) IPR infringement claims and indemnity \u2014 typically unlimited or increased (12-24 months of fees) with carve-outs for deliberate infringement which may remain uncapped. Vendors usually provide indemnification for third-party IP claims, with defence obligations;<\/li>\n<li>(e) breaches of applicable law \u2014 usually unlimited where they engage imperative rules;<\/li>\n<li>(f) regulatory fines \u2014 heavily negotiated; frequently excluded as indirect\/consequential loss. Often excluded from caps where fine is directly caused by the vendor. However, vendors typically limit liability to fines that are \u2018reasonably foreseeable\u2019 and exclude fines resulting from customers\u2019 own conduct;<\/li>\n<li>(g) wilful or deliberate breach and gross negligence \u2014 liability is effectively unlimited by operation of article 1355 of the Civil Code, as is that for death and personal injury;<\/li>\n<li>(h) AI-related claims \u2014increasingly addressed through a separate enhanced cap or dedicated AI warranties\/indemnities, though not yet market-settled. Specific limitations, including exclusion of liability, are negotiated for concrete AI risks such as hallucinations, autonomous decision-errors, outputs based on customer-provided training data, third-party IP claims arising from AI-generated content, or compliance obligations, usually referencing the EU AI Act risk classification. However, the strict AI Act liability provisions, particularly for high-ris AI systems, are expected to trigger more stringent vendor accountability, potentially making unlimited liability for AI-related harms more common in regulated sectors.<\/li>\n<\/ul>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Is it normal practice for software source codes to be held in escrow for the benefit of the software licensee? If so, who are the typical escrow providers used? Is an equivalent service offered for cloud-based software?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Source-code escrow is established market practice for licensed software, and less prevalent for pure SaaS. It is particularly used for business-critical applications (ERP, banking systems, healthcare software), custom-developed software, or software from vendors with perceived financial instability.<\/p>\n<p>Providers active on the Romanian market are predominantly international escrow agents such as NCC Group\/Escode, Iron Mountain, Escrow Associates LLC or similar entities, many with established offices also in Romania. Standard triggers include vendor insolvency, abandonment\/cessation of maintenance, uncured material breach, change of control to a competitor. These are usually subject to negotiation. Escrow agreements are generally governed by the Romanian Civil Code, and the Romanian Copyright Law recognizes the legitimacy of escrow arrangements for software protection.<\/p>\n<p>For cloud\/SaaS, traditional code escrow is of limited utility because of the specific structure of these transactions. The market therefore developed alternative solutions and mechanisms such as: data escrow \/ backup escrow (ensuring customer data is recoverable), API \/ business-continuity arrangements (guaranteeing API availability and documentation), transition assistance obligations (including vendor\u2019s obligation to assist migration upon termination), failover \/ DR provisions (contractual disaster recovery commitments) or third-party SaS escrow services offering continuity verification and transition assistance. The Data Act\u2019s switching and egress obligations however reinforce continuity expectations for cloud services independently of any escrow.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">IT Outsourcing \u2013 Other than as identified elsewhere in this questionnaire, are there any specific technology laws that govern IT outsourcing transactions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no dedicated outsourcing framework, and general contract law applies. There are, however, sector-specific overlays. For financial entities, DORA and the related BNR \/ ASF regulations and guidelines govern ICT third-party and outsourcing arrangements. NIS2 imposes supply-chain security obligations on in-scope entities that flow through to outsourced ICT. GDPR, via article 28, governs any outsourcing involving personal-data processing, and the Data Act governs switching between data-processing services. Public-sector IT outsourcing is additionally subject to the Public Procurement Law no.98\/2016 and the Utilities Procurement Law no.99\/2016.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">IT Outsourcing \u2013 Please summarise the principal laws (present or impending), if any, that protect individual staff in the event that the service they perform is transferred to a third party IT outsource provider, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The principal instrument is Law no.67\/2006 on the protection of employees\u2019 rights in the event of a transfer of an undertaking, business or parts thereof, which transposes the Acquired Rights Directive no.2001\/23\/EC. Where the outsourcing constitutes a transfer of business, the affected employees\u2019 individual rights and obligations transfer automatically to the transferee on their existing terms; dismissal by reason of the transfer is prohibited; and the transferor and transferee must inform and, where measures are envisaged, consult employees or their representatives in advance, with collective-agreement terms preserved for a period. Whether a particular IT outsourcing amounts to a \u201ctransfer\u201d is fact-specific, relevant CJEU case law making a clear distinction between labour-intensive and asset-reliant activities. Meanwhile, the Romanian Labour Code supplies the general employment framework.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending), if any, that govern telecommunications networks and\/or services, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The core framework is GEO no.111\/2011 on electronic communications, as substantially amended to transpose the European Electronic Communications Code \u2013 EECC (Directive (EU) 2018\/1972). It governs electronic communications networks and services \u2014 now including number-independent interpersonal communications services \u2014 together with end-user rights, access and interconnection, and the management of spectrum and numbering. It is accompanied by Law no.159\/2016 on physical-infrastructure deployment transposing the Broadband Cost Reduction Directive no.2014\/61\/EU, and by Law no. 506\/2004 on privacy in the electronic communications sector. Directly applicable EU instruments include the Open Internet Regulation (EU) 2015\/2120 and the Roaming Regulation (EU) 2022\/612. The sector regulatory authority is the National Authority for Management and Regulation in Communications \u2013 ANCOM, with key policy functions sitting with the Ministry for Research Innovation and Digitalization &#8211; MCID.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise any licensing or authorisation requirements applicable to the provision or receipt of telecommunications services in your country. Please include a brief overview of the relevant licensing or authorisation regime in your response.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Romania operates a merely general authorisation regime, rather than individual licensing. Under GEO no.111\/2011, a provider is only required to submit a notification to ANCOM before, or on, commencing activity, based on which it is, then, entered in the public register of providers. No individual licence is required for the service itself. Individual rights of use are granted only for scarce resources such as radio spectrum (granted by licence, usually via auction or competitive selection) and numbering resources (licences for number blocks). Providers pay an annual turnover-based monitoring tariff to ANCOM. The distinct DSA supervision fee that ANCOM may levy on intermediary-service providers, potentially from 2027, sits separately from the telecoms regime per se.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending) that govern access to communications data by law enforcement agencies, government bodies, and related organisations. In your response, please outline the scope of these laws, including the types of data that can typically be requested, how these laws are applied in practice (e.g., whether requests are confidential, subject to challenge, etc.), and any legal or procedural safeguards that apply.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There currently is no general data-retention mandate in Romania. Law no. 82\/2012 (which had transposed the Data Retention Directive 2006\/24\/EC) was declared unconstitutional by Decision no.440\/2014 of the Constitutional Court, following the trace left by CJEU in C-293\/12 &#8211; <em>Digital Rights Ireland<\/em>, and has not been replaced to date. Access to traffic, location and subscriber data and the interception of communications are nonetheless available to courts, prosecutors and intelligence\/security agencies under the Criminal Procedure Code (technical-surveillance warrants, subject to judicial authorisation), Law no. 506\/2004 (Articles 4 and 12^1, permitting disclosure based on a legal mandate) and the national-security framework \u2014 in particular, Law no.51\/1991 on national security and Law no.14\/1992 on the Romanian Intelligence Service &#8211; SRI.<\/p>\n<p>Disclosure requests may concern traffic, location, equipment-identification and subscriber data, and the content of communications under interception warrants. In practice, such requests are confidential, subject to prior judicial authorisation or the specific national-security procedures, and constrained by necessity and proportionality, with constitutional and judicial oversight. Disclosed data may, as per Law 506\/2004, be subject to non-erasure obligations for a defined period. Content blocking obligations exist also under Law no.535\/2004 on preventing and combating terrorism. The data-retention regime remains nonetheless marked by tensions, with evolving CJEU case law on targeted retention (see C-511\/18 <em>La Quadrature du Net<\/em> et seq).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending) that impose cyber security and\/or operational resiliency obligations applicable to the operation of telecommunications infrastructure and\/or provision of telecommunications services.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Security and integrity obligations under the EECC are embedded in GEO no.111\/2011, mandating notification of significant incidents to ANCOM. They are overlaid by NIS2 \u2013 under which electronic-communications providers are subject to risk-management measures and incident reporting to the DNSC, by DORA \u2013 where telecom providers supply ICT services to financial entities, and by critical-infrastructure and resilience rules transposing the Directive on the resilience of critical entities &#8211; CER (EU) 2022\/2557. 5G supply-chain security is addressed through alignment with the EU 5G Toolbox and national measures on high-risk vendors.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Mobile communications and connected technologies \u2013 What are the principle standard setting organisations (SSOs) governing the development of technical standards in relation to mobile communications and newer connected technologies such as digital health or connected and autonomous vehicles?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The principal bodies are the European Telecommunications Standards Institute (ETSI), 3GPP (for 3G\u20135G and the emerging 6G), the ITU, IEEE, and ISO\/IEC \u2014 covering also ISO\/IEC 42001 on AI management systems, together with oneM2M for IoT and CEN\/CENELEC for harmonised European standards, including those mandated under the AI Act. For connected and autonomous vehicles, ISO\/SAE 21434 and the UNECE WP.29 regulations (on cybersecurity and on software updates) are central. For digital health, IEEE, ISO TC 215, HL7\/IHE and IEC standards are predominant. At national level, ASRO (the Romanian Standards Association) adopts and transposes European (EN) standards. Standardisation in this field is closely linked with standard-essential-patent (SEP) and FRAND licensing (<a href=\"https:\/\/www.wipo.int\/en\/web\/patents\/topics\/sep\">https:\/\/www.wipo.int\/en\/web\/patents\/topics\/sep<\/a>).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Mobile communications and connected technologies \u2013 How do technical standards facilitating interoperability between connected devices impact the development of connected technologies?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Interoperability standards lower entry barriers, ensure cross-vendor compatibility, unlock network effects and economies of scale, and provide safety and security baselines. Under the EU\u2019s New Legislative Framework (<a href=\"https:\/\/single-market-economy.ec.europa.eu\/single-market\/goods\/new-legislative-framework_en\">https:\/\/single-market-economy.ec.europa.eu\/single-market\/goods\/new-legislative-framework_en<\/a>), conformity with harmonised standards yields a presumption of compliance increasingly relevant under the Radio Equipment Directive 2014\/53\/EU, the Cyber Resilience Act, and the forthcoming AI Act harmonised standards. Standards also shape competition through SEP\/FRAND access, although the EU\u2019s proposed SEP framework is still in a stalemate (<a href=\"https:\/\/single-market-economy.ec.europa.eu\/industry\/strategy\/intellectual-property\/patent-protection-eu\/standard-essential-patents_en\">https:\/\/single-market-economy.ec.europa.eu\/industry\/strategy\/intellectual-property\/patent-protection-eu\/standard-essential-patents_en<\/a>). They also are increasingly mandated by the Data Act\u2019s interoperability rules, the common European data spaces, and the eIDAS2 EU Digital Identity Wallet. For connected\/autonomous vehicles and digital health, standards facilitate approval and market access.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 Please summarise the principal laws (present or impending), if any, that govern data protection, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>GDPR is directly applicable. It is supplemented, domestically, by Law no.190\/2018 containing national implementing measures and addressing genetic\/biometric\/health data, the national identification number, employee monitoring, and the sanctioning of abuses from public authorities, Law no.102\/2005 concerning the organisation and functioning of the supervisory authority, Law no.506\/2004 on privacy in the electronic communications sector \u2013 covering cookies, traffic and location data, and electronic marketing, and Law no.363\/2018 transposing the Law Enforcement Directive (LED) no.2016\/680\/EU.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable data protection laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>For private controllers and processors, the GDPR ceilings apply directly: up to \u20ac20 million or 4% of total worldwide annual turnover, whichever is higher. For local public authorities and institutions, Law no.190\/2018 establishes a graduated regime: a warning and remediation plan in the first instance, with fining only for subsequent non-compliance. Fines are capped at RON 200,000, with delay penalties up to RON 3,000\u20135,000 per day. Breaches of Law no.506\/2004 trigger fines of RON 5,000\u2013100,000, or up to 2% of turnover for larger undertakings. Sanctions are appealable to the administrative courts.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 What data protection rules are relevant to technology contracts in your country?  Do they typically refer to external data protection regimes, e.g. EU GDPR or CCPA, even where the contract has no clear international element?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Data-protection provisions are ubiquitous in technology contracts. Where a processor is engaged, the contract must allocate precise controller\/processor roles and include the mandatory processing terms required by article 28 GDPR (subject-matter and duration, documented instructions, confidentiality, security, sub-processing authorisation, assistance with data-subject rights and breach, deletion\/return, and audit). International transfers require a valid mechanism to deal with adequacy, the 2021 standard contractual clauses under Implementing Decision (EU)2021\/914, or BCRs, plus a transfer-impact assessment. Romanian-law technology contracts routinely reference the GDPR by name even in purely domestic deals, because the GDPR is the governing regime and Law no.190\/2018 merely supplements it. References to the CCPA or other foreign instruments appear only where there is a genuine cross-border (typically US-facing) element, not as a default. Security, breach-cooperation and AI\/data-use clauses are now standard.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Please summarise the principal laws (present or impending), if any, that govern cybersecurity (to the extent they differ from those governing data protection), including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>GEO no.155\/2024 has transposed NIS2 into the national framework, establishing the framework for the cybersecurity of networks and information systems in the national civil cyberspace. It has been approved and materially expanded by Law no.124\/2025, and operationalised by the DNSC implementing Orders no. 1\/2025 and no. 2\/2025. Law no.58\/2023 on Romania\u2019s cybersecurity and cyber defence sets the broader institutional and national-security framework, while GEO no.104\/2021 established the National Cyber Security Directorate &#8211; DNSC. Directly applicable EU rules include DORA for the financial sector and the Cyber Resilience Act (Regulation (EU) 2024\/2847) for products with digital elements. The DNSC is the lead authority, with sector regulators (eg, ASF\/BNR) competent in their own domains.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable cybersecurity laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Under GEO no.155\/2024, administrative fines mirror the Directive structure: for essential entities, up to \u20ac10 million or 2% of total worldwide annual turnover, whichever is higher; for important entities, up to \u20ac7 million or 1.4% of turnover. The Romanian framework also provides for operational\/corrective measures and the temporary suspension of activities or management functions, and establishes personal accountability and possible sanctioning of management bodies. Separate administrative fines may apply under Law no. 58\/2023 and sector-specific legislation, while DORA and the Cyber Resilience Act carry their own EU penalty frameworks.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Are there any cybersecurity regulatory frameworks in your jurisdiction which require registration for certain sectors or services?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes. Under GEO no. 155\/2024, essential and important entities across the NIS2 sectors must self-assess and register with the DNSC. The highly critical sectors include energy, transport, banking, financial-market infrastructure, health, drinking and wastewater, digital infrastructure, ICT service management (B2B), public administration and space; the other critical sectors include postal and courier services, waste management, chemicals, food, manufacturing, digital providers (online marketplaces, search engines, social-networking platforms) and research. Trust-service providers, TLD name registries, DNS providers and cloud\/data-centre operators are expressly captured.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Please summarise the regulatory framework for the reporting of cybersecurity incidents.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Significant incidents are reported to the DNSC via the PNRISC platform, as per Law no.58\/2023, on a graduated timeline: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month, with intermediate updates on request and notification of recipients, where appropriate. Sectoral and parallel regimes apply as well: DORA major-ICT-incident reporting for financial entities; GDPR 72-hour personal-data-breach notification to ANSPDCP, and to data subjects where the risk is high; and Law no. 506\/2004 breach notification for electronic-communications providers. National CSIRT tasks sit with the DNSC.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Which body(ies), if any, is\/are responsible for the regulation of artificial intelligence?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Romania has not yet formally designated an AI regulatory authority, which leaves the Romanian Parliament the main legislative authority, including in this field. The National AI Strategy 2024\u20132027 introduces a dedicated market-surveyance authority coordinated by the Authority for the Digitalisation of Romania (ADR) and the Ministry of Research, Innovation and Digitalisation (MCID). Also, existing regulators retain competence over AI within their mandates in specialized sectors, notably, ANSPDCP for AI processing of personal data, together with ANCOM, ASF and the consumer-protection authority. A list of nine central authorities that are supposed to supervise or ensure compliance with obligations under EU law protecting fundamental rights in accordance with Article 77 of the AI Act has already been notified to the European Commission. However, many of them have not yet implemented specific AI-oversight procedures or measures. At EU level, the European Commission\u2019s AI Office supervises general-purpose AI, supported by the AI Board, scientific panel and advisory forum.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Please summarise the principal laws (present or impending), if any, that govern the deployment and use of artificial intelligence, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The EU AI Act (Regulation (EU) 2024\/1689) is directly applicable, in phases: the rules on prohibited practices and AI literacy, from 2 February 2025; the obligations for general-purpose AI models, the governance architecture and penalties, from 2 August 2025; and the bulk of high-risk-system obligations, from 2 August 2026, with certain high-risk systems embedded in regulated products, from 2 August 2027. The \u201cDigital Omnibus\u201d simplification package, formally adopted in July 2026 but not published in the Official Journal to date, is expected to adjust some of these timelines and obligations. At national level, the Romanian Parliament has proposed two draft bills on AI, in 2024 and 2025 respectively. They are both still under parliamentary review \u2014 and recommended for rejection. In 2024, Romania adopted its National Strategy for Artificial Intelligence (SN-IA) 2024\u20132027, aiming to integrate AI technologies into the economy and society whilst upholding human rights, promoting excellence, and fostering public trust. The strategy aligns with European and international frameworks and seeks to establish Romania as a regional hub for AI expertise and innovation. It nonetheless acknowledges several significant challenges. General regimes (data protection, consumer law, non-discrimination, IP and product liability) continue to apply to AI, as well.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Are there any specific legal provisions (present or impending) in respect of the deployment and use of Large Language Models and\/or generative AI (including agentic AI)?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no Romania-specific framework, and the AI Act continues to apply directly. Providers of general-purpose AI models are thus subject to concrete obligations on technical documentation, a policy on the handling of copyright matters, including the text-and-data-mining opt-outs under the DSM, and the publication of a sufficiently detailed training-data summary, with enhanced obligations for models presenting systemic risk. These are supported by the General Purpose AI (GPAI) Code of Practice. Also, the transparency duties in article 50 require disclosure on the interaction with an AI system and the machine-readable marking of synthetic and \u201cdeepfake\u201d content. Agentic AI is not yet specifically regulated and is captured only insofar as it falls within the scope of the GPAI, high-risk, or transparency provisions etc. Romanian draft bills cited above touch on deepfakes and public-sector AI, but they are not yet in force.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Do technology contracts in your jurisdiction typically contain either mandatory (e.g. mandated by statute) or recommended provisions dealing with AI risk? If so, what issues or risks need to be addressed or considered in such provisions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Such provisions are not statutorily mandated but are increasingly present in practice, driven by the AI Act\u2019s allocation of roles (provider, deployer, distributor \u2014 critical in SaaS\/AI procurement), the GDPR, current cybersecurity challenges and legal obligations, or IP exposure and liability. Issues commonly addressed include: clear allocation of AI Act compliance responsibilities; permitted-use and human-oversight requirements; training-data source and lawfulness; data-use, customer consent, feedback and confidentiality; accuracy, robustness and bias warranties; transparency and deepfake-marking obligations; security and logging; explainability; IP ownership and indemnities for inputs and outputs; third-party-model flow-downs; audit and documentation rights; etc. The 2024 UNCITRAL Model on Automated Contracting and the EU\u2019s model contractual clauses for procurement of AI (the MCC-AI) are a frequent reference point.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Do software or technology contracts in your jurisdiction typically contain provisions regarding the application or treatment of copyright or other intellectual property rights, or the ownership of outputs in the context of the use of AI systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Increasingly, yes. Under the Romanian Copyright Law, protection requires a human author\u2019s own intellectual creation, so purely AI-generated output generally attracts no copyright, whereas output reflecting sufficient human creative contribution may be protected, but with authorship vesting in the human alone. Contracts, accordingly, assign between vendor and customer: ownership or licensing of inputs and prompts; ownership or licence of outputs \u2013 often with acknowledged limits of protectability; warranties that outputs do not infringe third-party rights, with indemnities covering training-data and output infringement; and permissions or restrictions on text-and-data mining. The text and data mining exceptions contained in the DSM (articles 3\u20135), as transposed by Law no. 69\/2022, are key reference points.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Blockchain \u2013 What are the principal laws (present or impending), if any, that govern (i) blockchain specifically (if any) and (ii) digital assets, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>(i) There is no blockchain-specific legislation; technology-neutral rules apply to distributed-ledger arrangements;<\/p>\n<p>(ii) Digital assets are governed mainly by the Markets in Crypto-Assets ( MiCA) Regulation (EU) 2023\/1114 which is directly applicable. National implementing measures were introduced by GEO no.10\/2025 (enabling the MiCA transitional regime and the crypto Funds-Transfer\/\u201ctravel rule\u201d framework), which also designates the competent authorities: the Financial Supervisory Authority (ASF) for non-bank crypto-asset service providers, and the National Bank of Romania (BNR) for credit-institution crypto activity and the issuance of asset-referenced and e-money tokens. Anti-money-laundering obligations arise under Law no.129\/2019 as amended by GEO no.111\/2020, which also contains concrete rules on VASP authorisation\/registration. Local provisions are based on the comprehensive EU\u2019s Anti Money Laundering &#8211; AML package. NFTs generally fall outside MiCA unless they qualify as financial instruments under MiFID II.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Search Engines and Marketplaces \u2013 Please summarise the principal laws (present or impending), if any, that govern search engines and marketplaces, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>DSA is the main piece of legislation. It has been implemented in Romania by Law no.50\/2024 \u2013 which designates ANCOM as Digital Services Coordinator and amends Law no.365\/2002 on electronic commerce. DSA imposes graduated due-diligence, notice-and-action, transparency and trader-traceability obligations on online platforms, in general, with enhanced obligations for very large online platforms and search engines supervised by the Commission. The Platform-to-Business Regulation (Regulation (EU) 2019\/1150), in turn, imposes fairness and ranking-transparency duties on online intermediation services and search engines used by businesses. Designated gatekeepers are additionally subject to the Digital Markets Act &#8211; DMA (Regulation (EU) 2022\/1925). Consumer protection flows from the distance-selling\/Consumer Rights regime (GEO no.34\/2014), the unfair-commercial-practices law (Law no.363\/2007) as amended by the Omnibus reforms, and the General Product Safety Regulation (Regulation (EU) 2023\/988) for marketplaces. Law no.365\/2002 remains the main national e-commerce baseline.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Social Media \u2013 Please summarise the principal laws (present or impending), if any, that govern social media and online platforms, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>DSA is, again, the principal framework \u2014 covering illegal-content notice-and-action, transparency, recommender-system and \u201cdark-pattern\u201d rules, the protection of minors, and systemic-risk management for very large platforms. Audiovisual content on video-sharing platforms is regulated by Law no.504\/2002 (the Audiovisual Law, transposing the Audiovisual Media Services &#8211; AVMSD Directive 2010\/13\/EU as amended by Directive 2018\/1808), with a reform under way strengthening the protection of minors, advertising rules and measures against disinformation. The hosting-liability standard in Law no.365\/2002 must now be read together with the DSA. Data protection and political-advertising transparency rules contained in the EU Political Advertising Regulation (EU) 2024\/900 also apply.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Social Media \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable online safety laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The principal online-safety exposure arises under the DSA, which provides for fines of up to 6% of the provider\u2019s total worldwide annual turnover for breaches (up to 1% for the supply of incorrect or misleading information, and periodic penalties of up to 5% of average daily worldwide turnover). For very large online platforms and search engines these are enforced by the Commission; otherwise, by ANCOM, under Law no.50\/2024. Audiovisual breaches before the CNA carry separate administrative fines under Law no.504\/2002. Moreover, Digital Markets Act gatekeeper breaches can trigger fined of 10%\u201320% of worldwide turnover.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Spatial Computing \u2013 Please summarise the principal laws (present or impending), if any, that govern spatial computing, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>With no specific regime in place, technology-neutral EU and Romanian law applies cumulatively. GDPR governs the data captured by immersive devices and the resulting profiling. The AI Act applies to embedded AI. Product-safety law, the Radio Equipment Directive 2014\/53\/EU and the Cyber Resilience Act apply to headsets and devices. Consumer and digital-content rules (in particular, GEO no.141\/2021) apply to immersive content and in-app purchases. The DSA governs user-generated-content and platform layers. IP (Law no.8\/1996 and Law no.84\/1998) protects virtual assets, avatars and branding, and MiCA or financial-services rules engage where in-world tokens or payments arise. Child-safety, harassment and content offences are addressed through the DSA, audiovisual and criminal law.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Quantum Computing \u2013 Please summarise the principal laws (present or impending), if any, that govern quantum computing and\/or issues around quantum cryptography, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no specific legislation. Adjacent frameworks might however be relevant: export controls on dual-use items \u2014 including quantum technologies \u2014 under Regulation (EU) 2021\/821 and national implementing rules; cybersecurity policy on migration to post-quantum cryptography (EU and national roadmaps, DNSC guidance, and the EU coordinated Post-Quantum Cryptography implementation &#8211; <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/recommendation-coordinated-implementation-roadmap-transition-post-quantum-cryptography\">https:\/\/digital-strategy.ec.europa.eu\/en\/library\/recommendation-coordinated-implementation-roadmap-transition-post-quantum-cryptography<\/a>), together with the European Quantum Communication Infrastructure (EuroQCI) and quantum-communication initiatives &#8211; <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/european-quantum-communication-infrastructure-euroqci\">https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/european-quantum-communication-infrastructure-euroqci<\/a>; the security screening of strategic research projects and infrastructure; and general IP and contract law.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Datacentres \u2013 Does your jurisdiction have any specific regulations that apply to data centres?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Data centres are governed cumulatively by construction, zoning and environmental permitting; energy law and grid-connection rules; and the Energy Efficiency Directive \u2013 EED (EU) 2023\/1791 (Article 12) with Delegated Regulation (EU) 2024\/1364, which impose energy-performance reporting for data centres above the relevant threshold into the EU database. From a cybersecurity standpoint, data centres and cloud operators fall within \u201cdigital infrastructure\u201d \/ \u201cICT service management\u201d under NIS2 \/ GEO no. 155\/2024), and may be subject to critical-entity resilience obligations under the transposition of the CER Directive (EU) 2022\/2557. Data-protection and Data Act rules govern hosted data and switching, and strategic-infrastructure FDI screening may apply.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">General \u2013 What are your top 3 predictions for significant developments in technology law in the next 3 years?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><ol>\n<li>AI Act local operationalisation: the overdue designation of the national competent authority and the build-out of supervisory capacity, with the high-risk and GPAI obligations as adjusted by the 2026 AI Omnibus, and the spread of ISO\/IEC 42001-based AI governance among regulated deployers (including law firms and the public sector).<\/li>\n<li>Cybersecurity convergence and enforcement: maturation of NIS2 legislation, with initial DNSC enforcement focused on supply-chain security and management liability, alongside DORA and the Cyber Resilience Act reshaping product and ICT-contract obligations.<\/li>\n<li>The data and platform economy: Data Act-driven cloud switching, IoT data access and data sharing; the roll-out of the common European data spaces and the eIDAS2 EU Digital Identity Wallet; and continued DSA\/DMA enforcement \u2014 which should reshape technology contracts and platform design.<\/li>\n<\/ol>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">General \u2013 Do technology contracts in your country commonly include provisions to address sustainability \/ net-zero obligations or similar environmental commitments?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Not as a statutory requirement, but increasingly by negotiation. The drivers are the Corporate Sustainability Reporting Directive (EU) 2022\/2464 and ESG-disclosure flow-downs to suppliers; data-centre energy-reporting (Article 12 EED and Delegated Regulation (EU) 2024\/1364); green public procurement (Law no.98\/2016 and GPP criteria); and corporate net-zero commitments. Clauses now appearing in Romanian-market IT and cloud contracts include supplier sustainability representations, energy-efficiency and renewable-energy commitments, ESG reporting and audit cooperation, restrictions correlated with the Waste Electrical and Electronic Equipment &#8211; WEEE and RoHS Directives, and supply-chain due-diligence undertakings in line with the Corporate Sustainability Due Diligence Directive.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\r\n<div class=\"word-count-hidden\" style=\"display:none;\">Estimated word count: <span class=\"word-count\">6654<\/span><\/div>\r\n\r\n\t\t\t<\/ol>\r\n\r\n<script type=\"text\/javascript\" src=\"\/wp-content\/themes\/twentyseventeen\/src\/jquery\/components\/filter-guides.js\" async><\/script><\/div>"}},"_links":{"self":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide\/146524","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide"}],"about":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/types\/comparative_guide"}],"wp:attachment":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/media?parent=146524"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}