Data Protection in the Romanian Workplace: From Unlawful CNP Processing to AI Act Challenges

Data Protection in the Romanian Workplace: From Unlawful CNP Processing to AI Act Challenges

Introduction

In an increasingly digitalized business environment, compliance with the General Data Protection Regulation (GDPR - Regulation EU 2016/679) remains a constant challenge for companies operating in Romania. Years after its implementation, the National Supervisory Authority for Personal Data Processing (ANSPDCP) continues to issue significant fines for practices that should have been phased out long ago: the public disclosure or unjustified storage of the Personal Numeric Code (CNP) and excessive audio-video monitoring of employees.

Furthermore, the entry into force of new European regulations, such as the Artificial Intelligence Act (AI Act), raises the compliance bar to an unprecedented level.


1. Processing the CNP: A National Identifier with Special Status

The Personal Numeric Code (CNP) is not merely an identification number; under Romanian law (via Law No. 190/2018), it is categorized as a personal data type with a general-application identification function.

According to ANSPDCP enforcement decisions and recent jurisprudence, data controllers frequently make the following mistakes regarding the CNP:

  • Unauthorized Disclosure: Publicly displaying lists containing employees or clients (e.g., pay slips, official reports, ISCIR training schedules) on company notice boards or internal portals accessible to everyone.
  • Unjustified Photocopying of Identity Cards: Requesting and storing copies of ID cards without a clear legal basis or without demonstrating that the objective could not be achieved through less intrusive means.
  • Lack of Consent or Legal Basis: Collecting the CNP for marketing or customer loyalty purposes without a solid legal basis under Article 6 of the GDPR.

Key Principle: The principle of data minimization (Art. 5(1)(c) of the GDPR) dictates that collecting the CNP must be the exception, not the rule. If identity verification can be achieved through other means, requesting the CNP constitutes a breach of the law.


2. Video and Audio Monitoring of Employees: Where Does Legitimate Interest End?

Another high-risk area is the installation of CCTV surveillance systems or audio recording at the workplace. The ANSPDCP has repeatedly fined Romanian employers for cameras directed straight at employees' desks or for audio recording carried out without prior notification.

For employee monitoring to be lawful, an employer must cumulatively satisfy the following conditions (Art. 5 of Law No. 190/2018):

  1. Priority of Alternative Measures: The employer must prove that less intrusive methods were previously attempted to achieve the objective (e.g., card-based access control systems).
  2. Prior Consultation: Mandatory consultation with trade unions or employee representatives before introducing surveillance systems.
  3. Full and Transparent Information: Employees must be informed clearly, explicitly, and prior to the start of monitoring.
  4. Storage Period: Footage retention must not exceed 30 days, unless well-justified by specific legal exceptions.

3. Upcoming European Changes: GDPR Meets the AI Act

The EU data protection framework no longer operates in isolation. Currently, companies active in Romania must navigate the intersection of the GDPR and new European legislation:

  • The AI Act (Artificial Intelligence Act): Prohibits the use of AI-driven emotion recognition systems in the workplace and educational environments. Additionally, AI algorithms used for employee evaluation, recruitment, or promotion are classified as high-risk, requiring strict audits regarding data transparency and the processing of CNPs or biometric data.
  • Pay Transparency Directive: Will require companies to report salary data while strictly maintaining confidentiality (prohibiting the public disclosure of individual CNPs or financial details).

Conclusion

ANSPDCP penalties clearly demonstrate that the Romanian authority no longer tolerates "collecting everything just in case." For local companies and multinationals operating in the market, auditing internal data protection workflows, eliminating unnecessary CNP storage, and securing workplace monitoring are no longer optional—they are essential pillars of compliance and corporate ethics.