Cyber Law at Romania

Romania has developed a comprehensive legal framework to address cybercrime and data protection, aligning with European Union standards and international conventions. Here's an overview of the key legislation:

⚖️ Cybercrime Legislation

Law No. 58/2023 on Cybersecurity

Enacted on March 14, 2023, this law establishes Romania's national cybersecurity strategy. Key provisions include:

Mandatory Reporting: Entities providing public services must report cybersecurity incidents within 48 hours to a central portal accessible by 11 public bodies, including intelligence services. Failure to comply can result in fines up to 1% of annual turnover.

Obligations for Cybersecurity Service Providers: Providers must report vulnerabilities identified in clients' systems upon request from authorities, without the need for a judicial warrant.

Expanded Definition of National Security Threats: The law includes "cyberattacks on national infrastructure" and "disinformation campaigns" as threats to national security, granting intelligence services broader surveillance powers.

Despite criticism from civil society regarding potential overreach, the Constitutional Court upheld the law's constitutionality. 

🔐 Data Protection Law

Law No. 677/2001 on the Protection of Individuals with Regard to the Processing of Personal Data

Romania's primary data protection law, enacted in 2001, was later amended to align with the EU's General Data Protection Regulation (GDPR), Key aspects include:

Consent Requirement:Personal data must be processed with the explicit consent of the individual

Data Subject Rights:Individuals have the right to access, correct, and delete their personal data

Data Protection Authority:The National Supervisory Authority for Personal Data Processing oversees compliance and enforcement, Romania ratified the modernized Convention 108+ in March 2022, reinforcing its commitment to international data protection standards

🏛️ Enforcement and Institutional Framework

National Cyber Security Incident Response Center (CERT-RO) Coordinates responses to cybersecurity incidents and supports the implementation of cybersecurity measure.

Directorate for Investigating Organized Crime and Terrorism (DIICOT) Investigates and prosecutes cybercrimes, including hacking, data breaches, and online fraud. 

National Supervisory Authority for Personal Data Processing Enforces data protection laws and ensures compliance with GDPR provision.

📌 Summary

Romania's legal framework for cybersecurity and data protection is robust, aligning with EU regulations and international conventios. While the 2023 cybersecurity law enhances national security measures, it has raised concerns about potential overreach and its impact on civil libertis. Ongoing dialogue between authorities and civil society will be crucial in balancing security needs with individual righs.

LEAVE A COMMENT

0 comments