The footer of your site probably has a line saying “All rights reserved” and a link to a privacy policy nobody has read since it was put there. Maybe it was copied from another site, maybe it still has another company’s name in it. The cookie banner says “This site uses cookies” and has a single button. That is how a good share of the sites in Romania look, including some built on serious budgets.
The problem is not only the fine. A customer who looks for the company’s tax number before paying and cannot find it leaves. A buyer who cannot find the returns policy calls you or files a complaint with ANPC, the Romanian consumer protection authority. And Google Analytics started before consent brings you, at best, data you are not allowed to use.
Below you have the requirements grouped by topic, from company details to accessibility, each with a reference to the legal text, so you can check for yourself. The scope is a company running a site aimed at Romania, whether the company is Romanian or not.
This article presents the requirements as they appear in the legislation. It is not legal advice. For particular situations (medical data, minors, sales outside the EU, licensed activities) talk to a lawyer.
Company details: what must appear on every page
Law 365/2002 on electronic commerce requires, in article 5, that the identification details of the service provider be made available “directly, permanently and easily accessible”. It applies to any site through which a company presents or sells its services, not only to online stores. A “Contact” page is not enough on its own: the place that meets all three conditions is the footer of every page.
What must appear:
- the full company name, with the legal form (SRL, SA, PFA, or the equivalent for a foreign company);
- the registered office, with the full address;
- the registration number at the Trade Register (Registrul Comerțului);
- the tax identification number (CUI), with the RO prefix if the company is registered for VAT;
- contact details through which you can actually be reached: an email address and a phone number;
- the share capital, for SRL and SA companies;
- the details of the supervisory authority, if your activity requires a licence (for example financial services, healthcare, tourism).
A recent detail: since 2024, the Trade Register number in Romania is issued in a new format, without slashes, such as J2024123456789. Companies set up before that keep the old number, such as J40/1234/2015. If you set up the company recently, check that you have not picked up the old format from a template.
The full texts of the acts cited, with current amendments, are on the official portal legislatie.just.ro (in Romanian). Search by number and year.
Privacy policy: what it must say, not just exist
EU Regulation 2016/679 (GDPR) requires, in articles 13 and 14, that the person whose data you collect receives a set of information at the time of collection. The privacy policy is the document that brings that information together. A generic text does not meet the requirement, because the information is specific to your company.
The minimum content:
- who the controller is: the company name and contact details;
- what data you collect: name, email, phone, delivery address, payment details, IP address, data from cookies;
- for what purpose and on what legal basis you process it: performance of a contract (the order), consent (the newsletter), legal obligation (invoicing), legitimate interest (site security);
- how long you keep it, by category, with specific periods or the criteria used to set them;
- who you share it with: the hosting provider, the email service, the courier, the payment processor, Google Analytics or another statistics service, plus whether any of them is outside the EU;
- the person’s rights (access, rectification, erasure, objection, portability, withdrawal of consent) and how to exercise them, usually through an email address;
- the details of the data protection officer, if you have one;
- the right to lodge a complaint with ANSPDCP, the data protection authority in Romania.
The list of recipients is the one most often wrong, because it changes: a different hosting provider, a different courier, a new chat widget on the site. Every change has to reach the policy too. If the site has a plan for regular upkeep, put the policy review on the same list as the updates.
Cookies: a banner that only informs is not enough
Law 506/2004, which transposes the ePrivacy directive in Romania, requires the user’s consent before storing or reading any information on their device, except what is strictly necessary for the site to work. GDPR sits on top of it and says what consent must look like: freely given, specific, informed and expressed through a clear action.
Translated into what the site has to do:
- Strictly necessary cookies (session, cart, language, the choice made in the banner) can be set without consent.
- Statistics cookies (Analytics), marketing cookies (Ads, the Meta pixel) and those from embedded content (YouTube, maps) are set only after the visitor has accepted.
- Refusing must be as easy as accepting: a “Reject” button next to “Accept”, on the same level, not hidden behind “Settings”.
- The visitor must be able to change the choice later, usually through a link in the footer that reopens the banner.
- The cookie policy lists each cookie or category: who sets it, for what purpose and for how long.
The simple test: open the site in a private window, do not click anything in the banner and look at the network requests in the browser console. If you see requests to google-analytics.com or facebook.com, the banner is decorative. Scripts must be blocked until consent, not just declared.
For Google Analytics and Google Ads there is Consent Mode: the banner tells Google the consent state and the scripts behave accordingly. Basic mode loads nothing until consent; advanced mode sends cookieless signals before consent and is harder to defend. Choose deliberately, do not leave the plugin’s default setting.
Forms and newsletter: what you ask for and how
Any form on the site collects personal data, so it falls under GDPR. The requirements are few and specific:
- a short notice next to the submit button, with the purpose of the processing and a link to the privacy policy;
- no box ticked by default, especially the one for the newsletter or marketing;
- only the fields you need: for a quote request you do not need a personal identification number, for a newsletter you do not need a phone number.
The newsletter has its own rules. Consent must be explicit (opt-in), separate from accepting the terms or placing the order. Every message sent must contain an unsubscribe link that works in a single click. And you must be able to prove consent: the date, the time, the IP address and the form through which it was given. Email marketing services keep these automatically; for a list imported from Excel, the proof is missing.
Online stores: the extra obligations
An online store has, on top of everything above, a set of obligations from consumer protection legislation. Most of them come from Government Emergency Ordinance (OUG) 34/2014 on consumer rights in distance contracts and from OUG 140/2021 on the guarantee of conformity, the Romanian transpositions of the EU consumer rights and sale of goods directives.
| Requirement | Where it appears on the site | Legal text |
|---|---|---|
| Terms and conditions: the order process, prices including VAT, delivery, payment | own page, link in the footer and at checkout | Law 365/2002, OUG 34/2014 |
| The 14-day right of withdrawal, without giving a reason, for consumers | terms and conditions, returns policy, order confirmation | OUG 34/2014 |
| The withdrawal form | downloadable or fillable on the site | OUG 34/2014 |
| Returns and refund policy: deadlines, who pays the shipping, when the money is refunded | own page, link in the footer | OUG 34/2014 |
| The legal guarantee of conformity | terms and conditions, product page | OUG 140/2021 |
| The ANPC icon and link, the link to the ODR platform | footer of every page | consumer protection legislation |
A few requirements concern the order flow, not a static page. The total price, including VAT and delivery, is shown before the customer presses the order button, and the button says clearly that it involves an obligation to pay. After the order, the customer receives an email confirmation with the applicable terms, then the invoice.
The right of withdrawal applies to consumers, meaning individuals buying outside their professional activity. It has exceptions (personalised products, perishable goods, sealed goods that have been unsealed), but they must be written explicitly in the terms. If the terms do not inform about withdrawal at all, the ordinance extends the withdrawal period by 12 months.
The ANPC link and the link to the ODR platform go in the footer, on all pages, with the official icons from anpc.ro and the address ec.europa.eu/consumers/odr. The European Commission announced the closure of the ODR platform in 2025; check the current form of the requirement on anpc.ro before removing the link. When you start an online store from scratch, these pages are planned together with the site structure, not after launch.
Accessibility: the new obligation from 2025
EU Directive 2019/882, the European Accessibility Act, applies from 28 June 2025 to certain products and services, among them e-commerce, consumer banking services, passenger transport and electronic communications. Romania transposed it through national law. In short: an online store or a service sold to consumers through a site must be usable with a screen reader or from the keyboard alone.
The reference standard is EN 301 549, which for websites points to WCAG 2.1 level AA. In practice this means alternative text for images, sufficient contrast between text and background, forms with correct labels, keyboard navigation, a logical heading structure, captions for video. Microenterprises providing services are exempt from the directive’s requirements, but the exemption depends on the number of employees and the turnover, so check it for your specific case in the national transposition law.
What is missing most often in practice
The list comes from sites taken over or reviewed in recent years, in order of frequency.
- The tax number and the Trade Register number are missing from the footer. They appear on the invoice, they appear in the contract, but on the site there is only the trading name.
- The privacy policy is copied from another site. Sometimes with the other company’s name still in the text, sometimes with providers you have never used.
- The cookie banner only informs. A single “Got it” button, no way to refuse, and the scripts load anyway.
- Analytics starts before consent. Usually because it was placed directly in the theme or through Tag Manager, bypassing the banner.
- The ANPC link is missing or points to a page that no longer exists.
- The terms and conditions do not mention the right of withdrawal or limit it to “defective products”, which is something else.
- The contact form has the newsletter box ticked by default or has no notice about processing at all.
None of these needs a large budget; most are fixed in a day’s work. Data security is also a GDPR obligation, in article 32 (updates, backups, protection against unauthorised access), a separate topic covered in the secured websites programme.
Checklist
- The footer has the company name, registered office, Trade Register number, tax number, email, phone and share capital.
- The privacy policy is written for your company and lists the real providers.
- The cookie policy lists the cookies that actually exist on the site.
- The banner has “Accept” and “Reject” on the same level and blocks scripts until consent.
- A “Cookie settings” link in the footer reopens the banner.
- Forms have the processing notice and no box ticked by default.
- The newsletter requires opt-in and every message has an unsubscribe link.
- Store: terms and conditions with the 14-day right of withdrawal and the withdrawal form.
- Store: returns policy, guarantee of conformity, total price before ordering.
- Store: ANPC icon and ODR link in the footer, order confirmation by email, invoice.
- The site can be navigated from the keyboard alone and images have alternative text.
- You have noted the date of the last policy review and who does the next one.
Open your site, scroll to the bottom and read the footer like a customer who wants to know who they are dealing with. Look for the company name, the registered office, the Trade Register number, the tax number, an email and a phone number. Note what is missing and send it to the person who manages the site. It takes five minutes.