Running non-essential cookies without valid consent breaks two laws at once: GDPR and Romania’s Law 506/2004. GDPR fines reach up to €20 million or 4% of annual global turnover, and the authority that enforces them in Romania is ANSPDCP. In practice the risk does not start with a raid — it starts with a complaint any visitor can file for free — and the fix takes under an hour.
Which two laws are you breaking?
Cookies on a Romanian site fall under two regulations that work together:
- Law 506/2004 — Romania's transposition of the ePrivacy Directive. It requires informed consent before writing or reading non-essential cookies (analytics, marketing, remarketing).
- GDPR (Regulation 2016/679) — defines what valid consent means: freely given, specific, informed and expressed through a clear affirmative action. That is where the standard comes from; Law 506/2004 says "you need consent", and GDPR says "here is what it must look like".
In practice: a banner that sets Google Analytics or the Meta Pixel before the click breaks Law 506/2004 (it fired without consent) and GDPR (it processed personal data with no legal basis). You do not pick one — you breach both at the same time.
Who checks, and what can they impose?
The competent authority in Romania is ANSPDCP (the National Supervisory Authority for Personal Data Processing). It investigates complaints, can run inspections, and can issue orders to comply or fines.
| Measure | What it means in practice |
|---|---|
| Complaint | Anyone can report you to ANSPDCP for free, online. You do not have to be "big" to be targeted — a single unhappy visitor is enough. |
| Inspection / investigation | The authority asks for explanations, proof of consent and compliance records. This is where it shows whether the banner actually blocks or merely decorates. |
| Order to comply | Often the first step: you are told to fix the situation within a deadline. Ignoring it makes the sanction worse. |
| Administrative fine | GDPR allows up to €20 million or 4% of annual global turnover, whichever is higher. The amount is calibrated to severity, cooperation and size. |
The maximum fine is theoretical for most sites, but the entry point — the free complaint and the order to comply — is very real.
Why is "nobody checks small sites" a bad bet?
The "I'm too small to be noticed" logic ignores how a case actually reaches ANSPDCP. The authority does not browse your site out of the blue — the usual trigger is a complaint, and anyone can file one:
- a competitor inspecting your banner;
- a privacy-conscious visitor;
- an unhappy customer looking for a pressure point.
And the evidence is in plain sight: anyone who opens the browser's Network tab sees the trackers firing before any click. No expertise needed — or a free scan that lists them in seconds. A banner that "looks fine" but lets Analytics and the Pixel fire before consent is vulnerable to exactly the cheapest kind of report.
How do you fix it in 30 minutes?
The good news: for a legal problem, cookie compliance is one of the fastest to solve. The practical path:
- Scan first. Run a free scan, no account, to see exactly which trackers fire before consent and which categories they fall into.
- Add a banner that truly blocks. Not one that only shows a message — one that holds non-essential scripts until acceptance and makes rejecting as easy as accepting.
- Send all four Consent Mode v2 signals.
ad_storage,analytics_storage,ad_user_data,ad_personalization— required for Google Ads and Analytics in the EEA since March 2024. - Publish a cookie policy that reflects what the site actually sets, in Romanian and English if your audience is mixed.
FewCookies covers these steps with real blocking, all four Consent Mode v2 signals and hosted bilingual policies, at €6/month tax included and a 7-day trial without a card. Whatever tool you pick, start from a scan — a decision based on what you see in the Network tab beats any guess about who is "checking" you.
Frequently asked questions
Can a small Romanian site be fined for cookies?
Yes. The law does not exempt small sites, and the usual trigger is a complaint any visitor can file for free with ANSPDCP. The maximum GDPR fine (up to €20M or 4% of turnover) is rarely applied to a small site, but the order to comply and the duty to fix are very real.
Do I need consent if I only use Google Analytics?
Yes. Google Analytics sets cookies and processes personal data, so it falls under Law 506/2004 and GDPR. In the EEA you need consent and the Consent Mode v2 signals before Analytics collects data — otherwise you are collecting with no legal basis.
Is a banner saying "By continuing to browse you accept" valid?
No. GDPR requires a clear, affirmative action, and continuing to browse is not valid consent — just like the pre-ticked boxes the CJEU invalidated in Planet49 (2019). A proper banner offers real accept and reject buttons and blocks trackers until the choice is made.
Want to see which cookies and trackers fire on your site before consent? The scan is free and needs no account. Check your site for free →