
They implement Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), published in the Official Journal of the European Union L 119/1 on May 4, 2016.
The National Center for Personal Data Protection (CNPDCP) asserts that the new legislation should not be viewed solely through the lens of fines, and that, above all, it is about accountability, due diligence, and clear rules governing data processing activities. This new legal framework is centered on the individual and their rights.
“The law does not aim to hinder the activities of organizations and institutions, nor does it turn data protection into an administrative or financial burden. On the contrary, it establishes a set of rules that help data controllers understand what data they process, why they process it, how long they store it, and how they must protect it,” the CNPDCP statement reads.
What’s New in These Laws
One of the most important elements of the new laws is the principle of accountability. This means that the data controller must be aware of its data processing activities, assess risks, and establish appropriate measures, internal rules, and procedures that reflect how data is managed.
The CNPDCP clarifies that compliance does not begin when a complaint is filed, an audit is conducted, or a security incident occurs. Compliance begins with preventive measures. However, in July 2024, Law 195/2024 was enacted, granting operators a two-year transition period—sufficient time to adapt their internal processes and measures to the new legal requirements.
Thus, organizations should collect only the data they need, use it for specific purposes, and protect it appropriately. Simple measures, such as strong passwords, restricted access, system updates, and employee training, can significantly contribute to data protection.
The law does not require every organization to implement costly solutions. What is required is caution, prudence, and consistent application of the rules. Knowing what data you have, why you use it, and how you manage it is an important first step toward compliance.
At the same time, data subjects must be informed in a clear and accessible manner about the data being collected, the purposes of processing, the retention period, and the rights they possess.
The CNPDCP clarifies that Law No. 195/2024 establishes a framework for corrective measures and sanctions for violations of the law, but the identification of a violation does not automatically result in the imposition of a fine. In addition, the law provides for the possibility of filing lawsuits, as well as a phased mechanism and specific criteria for determining the amount of fines.

























