GDPR for sites in Moldova and Romania that work with the EU
Correct as of September 2026. General information, not legal advice.
GDPR is often described as a European law for European companies. That is only half true, and the half that is missing is the one that matters for a site in Chișinău or Cluj selling to customers abroad.
When GDPR reaches a site outside the EU
The regulation applies to you if you are established in the EU — which settles the question for every Romanian site — and also if you are not, but you offer goods or services to people in the EU, or monitor their behaviour. Romania is a member state, so a Romanian site is inside the regime by default. A Moldovan site is pulled in by what it does.
The signals that count are ordinary commercial ones: prices in euro, delivery to EU countries, a language version aimed at an EU market, EU customer reviews, ads targeted at people there. A site that merely happens to be reachable from Germany is not caught. A site that ships to Germany is.
Monitoring counts too, and this is the part that catches sites with no sales at all. Remarketing pixels, cross-site analytics and behavioural profiling of EU visitors are monitoring, whatever your business does.
What actually changes day to day
For a small site, the practical list is shorter than the reputation of the law suggests:
- Have a lawful basis for each use of personal data. For analytics and advertising cookies that basis is consent, asked for before anything loads.
- Keep a short record of what you collect, why, where it is stored and who else can see it. A page of notes is enough for a small site.
- Write a privacy notice a person can actually read, and link it where the data is collected.
- Be able to answer a request from a visitor — a copy of their data, or deletion — within a month.
- Know where your data physically sits, and be able to say so.
- Report a serious breach to the supervisory authority within 72 hours of finding out.
The Moldova-specific piece: transfers
Moldova is not in the EU, so moving personal data from an EU customer to a Moldovan server is a transfer to a third country and needs a legal mechanism. In practice most small sites use the standard contractual clauses their processors already offer, or simply keep the data in the EU in the first place. Where the servers are is a question worth asking every supplier you use, including your banner.
Romania, in one paragraph
A Romanian site is subject to GDPR directly, with the supervisory authority being ANSPDCP, and to Law 506/2004 on privacy in electronic communications, which is where the cookie consent requirement itself lives. The practical requirements on the page are the same as the ones above; what differs is that the authority is domestic and the complaint route is shorter.
Where a consent banner fits
A banner is one instrument, not the whole obligation. It handles the consent part: it stops third-party scripts until the visitor decides, sends the right signals to Google, and keeps a record of each answer. It does not write your privacy notice, choose your lawful bases or manage your suppliers — and any tool that claims to make you compliant by itself is overselling.
Correct as of September 2026. General information, not legal advice. Nothing here promises full compliance for your particular site; a lawyer who has looked at your business is the right source for that.
To see which third-party services your site currently loads for an EU visitor, run the free check below.