July 28, 2026

Personal Data Protection, Version 2.0: The Implications of Law No. 195/2024. Part II

Personal Data Protection, Version 2.0: The Implications of Law No. 195/2024. Part II

The Right to Lodge a Complaint

A data subject who believes that their personal data has been processed unlawfully may lodge a complaint with the National Center for Personal Data Protection. The complaint may be submitted within one year from the moment the individual became aware or should have become aware of the unlawful processing of their data, but no later than three years from the date the violation occurred. In the case of continuous violations, the limitation period begins to run from the last unlawful act or omission.

The complaint may be submitted directly by the data subject or through a legally established non-profit body, organization, or association pursuing the public interest in the field of protecting the rights and freedoms of data subjects with regard to personal data protection.

The mandated organization may:

1. Lodge complaints with the National Center for Personal Data Protection;

2. Challenge the actions or omissions of the Center directly before a court of law;

3. Seek and obtain compensation for damages suffered.

The new Law establishes the right of the data subject to challenge the actions or omissions of the National Center for Personal Data Protection directly before the court, without having to follow a prior administrative procedure. Furthermore, if the authority fails to examine the complaint or does not inform the data subject about the actions taken regarding the submitted complaint, the individual may bring an action before the court without first addressing the Center.

The Role of the Supervisory Authority in Ensuring Compliance with Personal Data Processing Rules

The legislation grants the supervisory authority the possibility to apply a complex set of corrective measures intended to ensure effective compliance with legal requirements. These coercive mechanisms do not necessarily have a punitive role, but are designed to prevent and remedy violations of personal data protection legislation.

The data protection authority may intervene by issuing warnings to the controller or processor, both preventively, where there is a risk of a violation, and subsequently, in order to encourage accountability and correct their conduct. The Authority may also impose binding measures requiring the controller or processor to comply with data subjects’ requests and ensure compliance with legislation governing data processing.

In the event of a personal data breach, the authority may require the controller to inform the data subject, thus ensuring transparency and enabling the individual to protect their rights and interests. In cases involving more serious violations, the Authority may impose a temporary or definitive limitation, including a ban on processing activities.

The supervisory authority also has the competence to intervene directly in relation to personal data by ordering the rectification, erasure, or restriction of processing, as well as notifying recipients to whom the data has been disclosed. In matters of certification, the authority may order the withdrawal of a certification already granted or prohibit a certification body from issuing certification where legal requirements are not met, thereby ensuring the credibility and integrity of compliance mechanisms.

Pecuniary Sanctions

A fine is a pecuniary sanction imposed on the controller by the National Center for Personal Data Protection upon finding a violation of personal data processing legislation.

The amount of the fine is determined based on the seriousness and duration of the violation, the number of affected individuals and the extent of the damage, as well as the form of fault — intent or negligence. Relevant factors also include the controller’s conduct after the violation was identified, the measures adopted to mitigate the damage, the degree of cooperation with the authority, and the existence of previous violations.

A fine may only be imposed where fault in the form of intent or negligence is established. In the case of multiple violations committed within the same personal data processing operation, the total amount of the fine is capped at the level applicable to the most serious violation, thus preventing the excessive accumulation of sanctions. The legislator distinguishes between two main categories of violations. The first category concerns breaches related to the general obligations of controllers or processors. For such violations, fines may reach up to 1,000,000 MDL, and in the case of an undertaking, up to 1% of the total annual turnover achieved in the year preceding the sanction. The second category concerns the application of fines of up to 2,000,000 MDL, and in the case of an undertaking, up to 2% of the total annual turnover achieved in the year preceding the sanction. This sanction applies where violations concern the basic principles governing personal data processing, including the conditions for obtaining the data subject’s consent. The law also provides for the application of this sanction in situations where a controller or processor fails to comply with a corrective measure previously issued by the supervisory authority.

Conclusion

The new law on personal data protection establishes an effective legal framework aligned with EU standards in the field of personal data protection, aimed at guaranteeing the effective protection of data subjects’ rights. By combining preventive, corrective, and punitive mechanisms, the Law creates a balanced system that encourages the voluntary compliance of controllers and processors while strengthening their accountability in respecting personal data processing rules.