FewCookies

Blog · Updated: July 7, 2026

Romania’s cookie law (Law 506/2004) explained in plain language

Law 506/2004 is Romania’s transposition of the ePrivacy Directive, and it requires informed consent before installing non-essential cookies on a visitor’s device. It says "you need consent", and GDPR says what that consent must look like: freely given, specific, informed and expressed through a clear action. Cookies strictly necessary for the site to work are exempt; everything else — analytics, marketing, remarketing — needs prior consent.

Law 506/2004 is Romania’s transposition of the ePrivacy Directive, and it requires informed consent before installing non-essential cookies on a visitor’s device. It says "you need consent", and GDPR says what that consent must look like: freely given, specific, informed and expressed through a clear action. Cookies strictly necessary for the site to work are exempt; everything else — analytics, marketing, remarketing — needs prior consent.

What does Law 506/2004 actually require?

Law 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector is Romania's version of the ePrivacy Directive. In short, the cookie rule is:

  • Information — the visitor must know which cookies you use, for what purpose and for how long.
  • Prior consent — for any non-essential cookie, consent must be obtained before that cookie is written or read, not after.
  • Exemption for essential cookies — cookies strictly necessary to deliver the service the user asked for do not need consent.

The key word is "prior". If Analytics or a marketing pixel fires on page load and the banner appears only afterwards, you have already broken the law — no matter what the visitor chooses next.

How does it interact with GDPR?

Law 506/2004 and GDPR do not contradict each other — they complement each other. One says that you need consent, the other says what valid consent looks like.

QuestionLaw 506/2004 (ePrivacy)GDPR
Do I need consent for cookies?Yes, for non-essential ones, before setting them.
What must the consent be like?Freely given, specific, informed, by a clear action.
What if it is missing?Cookie set unlawfully.Data processed with no legal basis.

That is why you cannot "pick" one of them: a marketing cookie fired without a click breaks Law 506/2004 (set without consent) and GDPR (processing with no basis) at the same time. We cover the fines and real risk separately.

What does "essential cookie" really mean?

The exemption for essential cookies is real but narrow. A cookie is "strictly necessary" only if the site cannot deliver the service the user asked for without it — not if it is merely useful to you.

  • Genuinely essential: authentication session cookie, shopping cart, load balancing, remembering the choice made in the consent banner.
  • NOT essential (need consent): Google Analytics, the Meta Pixel, remarketing, heatmaps, A/B tests, marketing chat.

The classic trap is labelling analytics "essential" because you want the data. Your wish does not change the category: statistics measure how the site is used, but the site works perfectly without them, so they need consent. If you are not sure what your site sets, a free scan lists every cookie and its category.

What myths circulate about consent?

A few widespread beliefs that do not survive the GDPR standard:

  1. "Scrolling the page means consent." No. Consent requires a clear affirmative action; browsing or scrolling is not a "yes".
  2. "A «By continuing you accept» message is enough." No — that is implied consent, exactly what the standard forbids.
  3. "Pre-ticked boxes count as consent." No. The CJEU held in Planet49 (2019) that an already-ticked box is not valid consent.
  4. "A banner with just «OK» is compliant." No, if rejecting is not as easy as accepting — EDPB guidance requires refusing to be as simple as accepting.

A proper banner informs, offers accept and reject on equal footing, and blocks trackers until the choice is made. FewCookies does exactly that — real blocking, all four Consent Mode v2 signals and bilingual policies at €6/month tax included, with a 7-day trial and no card. Start by checking where you stand now with a free scan.

Frequently asked questions

Is Law 506/2004 different from GDPR?

Yes, they are distinct regulations that complement each other. Law 506/2004 (Romania’s ePrivacy transposition) requires consent before non-essential cookies, while GDPR defines what valid consent means. A tracker fired without consent breaks both at once.

Which cookies are exempt from consent?

Only those strictly necessary to deliver the service the user asked for: the authentication session, the shopping cart, load balancing and remembering the banner choice. Analytics, marketing pixels and remarketing are not essential and need prior consent.

Is consent obtained by scrolling the page valid?

No. Consent requires a clear affirmative action, and scrolling or merely browsing does not qualify. It is implied consent, which the GDPR standard rejects — just like the pre-ticked boxes the CJEU invalidated in Planet49.

Want to see which cookies and trackers fire on your site before consent? The scan is free and needs no account. Check your site for free →