Callstrike
Compliance

Voice phishing simulations in Romania

Phone numbers in RomaniaProvisioned by Callstrike after approval

Romania is the only country in this portal whose legislature wrote a rule for exactly this situation, and it is the most demanding one here: five conditions that must all be true at once before the legitimate interests ground is available for monitoring by electronic means. The regulator has enforced them against software that had only ever been run in a test period, so build a voice phishing simulation around the fourth condition and the thirty-day retention cap from the first planning meeting.

Phone numbers

Supplied by Callstrike

Local numbers in Romania, after a one-time approval.

Running a simulation

Permitted on five conditions at once

Fail any one and the legitimate interests ground is not available at all.

Consent

Neither the basis nor the gate

Consultation before the system is introduced is the gate, and it needs no agreement.

Getting a phone number in Romania

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

Romania asks more about people than any other filing in this region. Alongside the company name, the trade registry or fiscal number and the business address, your authorised representative is identified twice over: their name from a passport, identity card or residence permit, and then the number and expiry date of that same document, with their date of birth typed into the form. A power of attorney or other evidence that they are a director or country manager shows they may act for the company. A trade registry certificate, a fiscal registration certificate or a registry excerpt covers most of the company side on its own, and the address line will also take a utility bill, a tax notice, a rent receipt or a title deed.

The Romanian anti-spoofing regime is operative and unusually hard to cite, which is worth knowing before somebody hands you a fabricated reference. It is not a numbered decision at all. It is a bundle of individual decisions addressed to each provider, dated June 2025 and communicated through the regulator's own portal, published only as a redacted template whose number field is blank, so anyone quoting a decision number for Romanian caller identity spoofing has invented it. What it requires is plain enough: since July 2025 providers block calls originated outside Romania that present national numbers other than the mobile ranges, unless the provider can establish with certainty that the number correctly identifies the caller. Read the mobile carve-out as what it is, a deliberate gap in one enforcement mechanism to protect roaming, not a permission.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Romania is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Name of authorized representativePassport, Identity card, Residence or labor permit
Number and expiry of identity document of authorized representativeIdentity card, Passport, Residence or labor permit
Trade registry number or fiscal numberfor example, VATTrade registry certificate, Fiscal registration/vat certificate, Excerpt from the commercial or trade registry
Authorization of representativePower of attorney, Other documentation showing the individual is a director or country manager for the business
Business nameTrade registry certificate, Fiscal registration/vat certificate, Excerpt from the commercial or trade registry
Business addressMust be within locality or region covered by the phone number's prefix; a PO Box is not acceptable where a local address is required.Excerpt from the commercial or trade registry showing the local address, Utility bill, Tax notice, Rent receipt, Title deed

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in Romania?

The position in short, before your counsel reads the detail below.

Yes, and then the conditions. Where monitoring systems by means of electronic communications are used at the workplace, processing employees' data on the employer's legitimate interests is permitted only if five things are true together. The interests must be soundly justified and must prevail over the rights and freedoms of the people concerned. The mandatory, complete and explicit prior information of employees must have been carried out. The trade union or, failing one, the employee representatives must have been consulted before the monitoring systems were introduced. Other, less intrusive methods of reaching your purpose must not previously have proved effective. And retention must be proportionate and in any case no longer than thirty days. Joined by and, and treated by the regulator as conditions on the validity of the ground itself rather than as formalities running alongside it.

The enforcement record is what makes those conditions real, and it is unusually close to what this page is about. The regulator's 2024 report describes an employer monitoring remote workers through an application on their laptops. It found the employer had not proved that less intrusive methods were ineffective, nor that it had consulted before implementing the application, and concluded the legitimate interest invoked could not be considered justified. Two features of that decision are worth pausing on. It applies the article to software rather than to cameras, which disposes of the argument that the provision is really about video. And the application was not even in use at the time, having previously been run only in a test period. A test period still engaged the article, which is the closest thing in Europe to a ruling about a pilot.

The rule people expect to bite does not. The prohibition on automated calling systems is gated on making commercial communications, and that term is defined in a separate statute as any communication intended to promote, directly or indirectly, the products, services, image, name, firm or emblem of a trader. An authorised internal test promotes none of those. It matters that the reason is the purpose rather than the technology, because an AI voice agent is unambiguously an automated calling system that does not require human intervention, so a live operator changes nothing about this analysis. Two details worth carrying: the prohibition covers corporate subscribers as well as individuals, unlike several of its neighbours, and enforcement sits with the data protection authority, which fined fifty thousand lei under the article in August 2026.

Recording is the clearest case in this portal of the well-known provision being the wrong one. The private-life article everyone cites has a participant exception, but the Constitutional Court and then a binding High Court ruling confined its locational element to a domicile in the criminal-law sense, so an employee taking a call at their desk is outside it entirely. The provision that does bite is unlawful interception, which names telephone calls expressly, carries six months to three years, has exactly two exceptions, neither of them participation, legitimate interest or consent, and is prosecuted of the authorities' own motion rather than on anyone's complaint. What keeps you outside it is not an exception but an element: the interception has to be without right, and documented advance authority goes to whether that element is satisfied at all. Onward disclosure is a separate offence, and the High Court has held it is not conditional on the material having been obtained without right, so a lawful recording licenses nothing downstream.

What your company needs to do

7 items, in the order you will need them.

  • Evidence that less intrusive methods did not work, before you buyRomania-specificThis is the condition the regulator actually enforced, and it is the one that has to be satisfied before the exercise rather than justified after it. Record what you tried, what it achieved, and why the gap it left needs a live test. A file assembled afterwards is the exact shape of the case the regulator decided against.
  • Consult the union before the system is introduced, not before you decideRomania-specificThe specific duty attaches to introduction, and the general machinery adds a second layer that must be completed before implementing the decision, with a reasoned reply to any point the representatives put and a formal record of positions. That record is the concrete deliverable a regulator will ask to see. The general threshold is twenty employees, under the 2006 act rather than the 2022 one.
  • Cap retention at thirty days, and let the metrics outlive the recordsRomania-specificThirty days unless a statute provides otherwise or the case is duly justified, and the regulator has penalised employers for exceeding it. Design the programme so what survives is aggregate outcome data rather than a long-lived archive of individual call records, because deleting on schedule should not cost you the trend the programme exists to produce.
  • Give the complete and explicit prior information, and be able to prove itRomania-specificPut the programme in the internal regulation, which is the document that actually carries it here. You must bring it to each employee's knowledge on their first working day and be able to prove you did, and it takes effect against an employee only from the moment of that knowledge. The same applies to every modification, so amending it silently achieves nothing.
  • Record the authority that makes the interception not without rightRomania-specificThe interception offence has no participation exception and no consent exception, and it does not wait for anyone to complain. The element that protects you is that the act must be without right, so written, dated authority from the officer entitled to give it is what the whole recording position stands on. Get it before the campaign, not with the incident report.
  • Control who can replay a recordingOnward disclosure is punished separately, at three months to two years, and the High Court has held that the disclosure offence does not depend on the recording having been made unlawfully. Keep audio inside the team that needs it and anonymise anything that reaches awareness material. Companies are exposed directly, with fines from three thousand to three million lei.
  • Run the impact assessmentThe regulator's own list of processing requiring one names employees expressly, alongside minors, where automated monitoring or systematic recording of behaviour is carried out at large scale. A company-wide campaign is the kind of thing that meets the qualifier, so treat the assessment as owed rather than as a judgement call.

The controls that do the work

How Callstrike is configured, and which provision in Romania each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

Two of the five conditions are answered by what the exercise never holds. The first asks whether your interests prevail over the rights of the people concerned, and the honest weight of an exercise that captures a credential is not the weight of one that captures whether a person would have given it. The fifth caps retention at thirty days. The call ends the instant an employee begins to disclose, so there is no credential store to age out, and what the thirty-day rule applies to is a record of the event rather than a copy of the secret. It also keeps the balance you have to write down a short argument rather than a long one.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

The internal regulation that carries the programme in Romania has mandatory content including the disciplinary offences and applicable sanctions, so what happens to a person who fails is a live question in the document itself rather than an internal convention. A second voice that breaks character as the call ends, vishing training in writing the same day, and an undertaking that results never reach a disciplinary record are terms you can put in that regulation and show to the representatives you are consulting.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

Romanian law makes consultation the gate and legitimate interests the ground, so employee agreement is doing neither job. What this produces is the second of the five conditions in evidenced form: the mandatory, complete and explicit prior information, dated before the campaign, per employee. That matters more here than in most countries because the labour code separately requires you to be able to prove each person was brought to knowledge of the internal regulation, and a signed and timestamped record is what proving it looks like.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

The Romanian delivery problem is origination rather than law, and this route does not have one. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module, so there is no Romanian calling identity for the blocking decisions to examine and no automated calling system for the commercial-communications article to describe. Be precise about what it does not change: the five conditions still govern, because the exercise is still monitoring, and the European transparency duty still applies to the generated voice.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

Five conditions, and all five have been enforced

Romania used the employment derogation the GDPR offers and used it to write a rule about monitoring specifically. Where monitoring systems by means of electronic communications or video surveillance are used at the workplace, processing employees' personal data for the employer's legitimate interests is permitted only if five things are true at once.

The legitimate interests pursued by the employer must be soundly justified and must prevail over the interests, rights and freedoms of the people concerned. The employer must have carried out the mandatory, complete and explicit prior information of employees. The employer must have consulted the trade union or, as the case may be, the employee representatives before introducing the monitoring systems. Other, less intrusive forms and methods of reaching the employer's purpose must not previously have proved effective. And the retention period must be proportionate to the purpose and in any case no longer than thirty days, save where a statute expressly provides otherwise or in duly justified cases.

That is a five-part test in a single sentence, joined by and, and the regulator treats the last four as conditions on the validity of the basis itself rather than as formalities running alongside it. Fail one and the legitimate interests ground is not available at all.

The enforcement record matters more here than usual, because it is unusually close to what this page is about. The regulator's 2024 activity report describes an employer monitoring remote workers through an application installed on their laptops. It found that the employer had not proved that less intrusive methods were ineffective, nor that it had carried out the prior consultation of employees before implementing such an application, and concluded that the legitimate interest invoked could not be considered justified. Two features of that decision are worth pausing on. It applies the article to software monitoring rather than to cameras, which disposes of the argument that the provision is really about video. And the application in question was not in use at the time: it had previously been run only in a test period. A test period still engaged the article.

The other limbs are enforced too, and separately. The regulator has found a breach where an employer could not prove it had carried out the prior consultation of the employees or the union before installing and commissioning a system, and it has penalised retention beyond the thirty-day period more than once, including by formal warning.

One further duty sits on top and is easy to miss. The regulator's own decision listing the processing operations that require a data protection impact assessment includes large-scale processing of the personal data of vulnerable people, expressly naming minors and employees, through automated means of monitoring or systematic recording of behaviour. The large-scale qualifier has to be met, but a company-wide campaign is the kind of thing that meets it.

The famous article does not apply, and the other one has no way out

Romanian call recording is the clearest case in this portal of the well-known provision being the wrong one and the obscure provision being the dangerous one.

The article everyone cites, on infringement of private life, criminalises photographing, capturing or recording images, listening by technical means or audio-recording a person who is in a dwelling or room or its appurtenance, or a private conversation. It carries one month to six months or a fine, it is prosecuted on the prior complaint of the injured party, and it does contain a participant exception: the offence is not committed by a person who took part in the meeting at which the sounds, conversations or images were captured, if they justify a legitimate interest.

Two things nearly remove it from the picture anyway. The Constitutional Court held in 2017 that for the offence to exist the acts must be committed, without right, in a domicile in the criminal-law sense, and the High Court of Cassation and Justice made that binding in 2024 by ruling that the notions of dwelling, room and appurtenance in that article carry the same meaning as in the offence of violation of domicile. An employee taking a call at their desk is outside the locational element. And the participant exception is doubly qualified: it is drafted around a meeting, and the statute is silent on whether a telephone call is one, while the legitimate interest it requires is nowhere defined.

The provision that does bite is the one on unlawful interception, and it is the inverse of what people expect. It is an offence, punishable by six months to three years or a fine, to intercept without right a conversation or a communication made by telephone or by any electronic means of communication. Telephone calls are named expressly, so the argument about whether a call counts as correspondence never arises.

Now read its exceptions, because there are only two: where the person catches the commission of an offence or contributes to proving one, and where they capture facts of public interest. Participation is not among them. Legitimate interest is not among them. Consent is not among them. And the prior-complaint gate that softens the other article is confined by its own terms to the first paragraph, which means the telephone limb is prosecuted of the authorities' own motion. An employee deciding not to complain does not close this exposure.

What protects an employer is not an exception but an element. The offence requires the interception to be without right, and documented advance authority in the programme materials goes to whether that element is satisfied at all, before any justification clause is reached. The procedural code separately provides that recordings made by parties are admissible where they concern their own conversations, but that is a rule about evidence and not a licence to record.

Onward disclosure is a separate offence under both articles, at three months to two years, and the High Court has held that the disclosure offence is not conditional on the material having been obtained without right in the first place. A lawfully made recording does not immunise circulating it to managers or dropping it into awareness training.

Companies are exposed directly. Romanian criminal law uses a general model of corporate liability with no offence list, so both articles reach a legal person, the fine range runs from three thousand to three million lei, the complementary penalties include a one to three year ban on public procurement, and individual liability is preserved alongside it.

Promotion is the test, and nobody supervises the AI duty yet

The Romanian rule on unsolicited communications is scoped, but not by the words people expect. It prohibits making commercial communications by using automated calling and communication systems which do not require human intervention, by fax, by electronic mail or by any other method using publicly available electronic communications services, except where the subscriber or user has given prior express consent. The phrase for direct marketing appears nowhere in the article; the gate is commercial communication.

That term is defined in a different statute, on electronic commerce, as any form of communication intended to promote, directly or indirectly, the products, services, image, name, firm or emblem of a trader or member of a regulated profession. The test is therefore promotional purpose, and an authorised internal security test promotes nothing. That is what puts it outside the article, and it matters that the reason is the purpose rather than the technology, because an AI voice agent is unambiguously an automated calling and communication system that does not require human intervention.

Two details are worth carrying. The prohibition applies to corporate subscribers as well as individuals, unlike several of its European neighbours. And enforcement here belongs to the data protection authority rather than to the telecoms regulator, whose competence under that statute is limited to invoicing, with a range of five thousand to one hundred thousand lei rising to two per cent of turnover for larger undertakings. The authority is actively using it: it imposed a fifty thousand lei fine under this article in August 2026.

One curiosity, reported because it is real. The soft opt-in paragraph of the same article still cross-refers to a data protection statute that was repealed in 2018 and has not been repaired since.

The European transparency duty applies here directly, and its source is Article 50 of the EU AI Act. Since 2 August 2026 a provider must design a system intended to interact directly with people so that they are informed they are interacting with an AI system, unless that is obvious to a reasonably well-informed and observant person; a provider of a system generating synthetic audio must ensure the output is marked in a machine-readable format and detectable as artificially generated; and a deployer of a system generating or manipulating audio constituting a deep fake must disclose that the content was artificially generated. Note precisely where the obviousness escape sits: it is in the first of those paragraphs only and does not extend to the marking duty or to the deep fake disclosure.

There is a second European prohibition that deserves more attention than it has had, on this page and on the others. Using AI systems to infer emotions of a natural person in the workplace has been prohibited since 2 February 2025, at up to thirty-five million euros or seven per cent of worldwide turnover, except where the use is intended for medical or safety reasons. Safety reasons is defined nowhere in the binding text; the phrase occurs exactly once in the whole Regulation, inside the exception it creates. The Commission's own guidelines, which are expressly non-binding, say the notion applies only in relation to the protection of life and health and not to protect other interests, for example property against theft or fraud. A security product is definitionally in the business of protecting against fraud, so on the Commission's reading the exception is closed to it. The realistic escape is the definition rather than the exception: the prohibition is gated to inference from biometric data, and the recitals exclude the mere detection of readily apparent expressions or of characteristics of a person's voice such as a raised voice. Counting who complied is safe. Scoring how frightened someone sounded is not.

Romania has not designated a national authority for any of this in binding law. The Commission's own table shows a dash against Romania, and we searched the government and digitalisation agency sites for an implementing instrument without finding one. We report that as not established rather than as certainly absent, because the table covers single points of contact and is itself dated. The duties bind regardless.

A blocking rule with no number, and a gap for mobile

Romania has an operative anti-spoofing regime and it is unusually hard to cite, which is itself worth knowing before someone hands you a fabricated reference.

The measure is not a numbered decision. It is a bundle of individual decisions addressed to each provider, dated June 2025 and communicated through the regulator's own portal, published publicly only as a redacted template whose number field is blank and whose status reads communicated. Anyone quoting a decision number for Romanian caller identity spoofing has invented it.

What it requires is clear enough. From 7 July 2025, providers must block access to national numbering resources in the case of calls originated outside Romanian territory towards numbers in the national plan which present as calling line identity either numbers from the national plan other than those in the mobile ranges, or numbers carrying the Romanian country code but not respecting the plan's structure. The duty does not apply where the provider can establish with certainty that the number correctly identifies the party initiating the call, and non-compliance carries up to thirty thousand lei for each day of delay.

Read the carve-out carefully, because it is a real gap and it is deliberate: the mobile ranges are excluded, on the reasoning that applying the rule to them could affect the legitimate use of Romanian numbers abroad in roaming. That is a gap in one enforcement mechanism. It is not a permission, and the rest of the framework still applies.

The rest of the framework is assembled rather than stated in one place. Providers must transmit the calling line identity without altering, modifying or deleting it, and may only carry resources the regulator has allocated. Numbers are assigned directly to subscribers, and a subscriber must use its numbers only in the format in which they were assigned, must not sub-assign them, and must use them only for the service for which they were assigned. The regulator's own working definition of spoofing is the display of a telephone number that does not belong to the person actually making the call.

The practical split for a campaign is therefore sharp. Presenting a bank's or a public institution's number is exactly the conduct Romania treats as spoofing, and if the call originates abroad it must be blocked. Presenting an internal helpdesk number the employer genuinely holds is the caller presenting its own number and is not caught by any of this.

What the country matrix holds for Romania

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Consultation before introduction, and a reasoned reply on the record

Nothing in Romanian law requires employee or union agreement to a monitoring measure. The highest duty anywhere in the set is consultation with a reasoned reply and the parties' positions minuted, and that is still more than most countries in this portal ask for.

The specific duty is the one already described: the employer must have consulted the trade union or, failing that, the employee representatives before introducing the monitoring systems. Before introducing, not before deciding and not afterwards, and the enforcement record shows the regulator asking for proof that it happened.

The general machinery adds a second layer with its own timing rule. For decisions capable of leading to important changes in work organisation, in contractual relations or in employment relations, employers must initiate and complete the information and consultation process before implementing the decisions. The consultation must be conducted so that representatives can obtain a reasoned reply to any point of view they put, and it concludes with a formal record of the parties' positions. That record is a concrete deliverable, and it is the thing a regulator will ask to see.

The threshold for that machinery is not where readers of the 2022 statute expect. The 2022 social dialogue act reaches outward under the conditions of a 2006 act on information and consultation, and it is that older act, which was not repealed, that carries the size test: it applies to undertakings established in Romania with at least twenty employees. Its wording requires consultation with a view to negotiating an agreement, which is a procedural aim and must not be upgraded into a consent requirement. Failing to initiate consultations carries two and a half to twenty-five thousand lei.

The document that actually carries a simulation programme in Romania is the internal regulation. It is drawn up by the employer with the consultation of the union or the employee representatives, its mandatory content includes concrete rules on work discipline and the disciplinary offences and applicable sanctions, and breach of it is itself a disciplinary offence. Two procedural rules make it real rather than nominal: the employer must bring it to each employee's knowledge on their first working day and must be able to prove it did so, and it takes effect against an employee only from the moment of that knowledge. The same applies to every modification.

One negative worth stating. The labour code contains no provision at all about employer electronic monitoring. Its word for monitoring appears only in the minimum-wage machinery and its word for surveillance only in temporary agency work and occupational medicine. The employer's authority rests on the generic right of control, and every monitoring-specific condition lives in the data protection statute described above.

The word test appears nowhere, and phishing appears as a ban

Romania transposed the European network and information security directive by an emergency ordinance published on the last day of 2024, with its sanctions provisions deferred to the end of January 2025.

It does not mandate simulation, and the way it does not is worth setting out because a careless search will suggest otherwise. Counted over the gazette text, the Romanian words for simulation and for penetration test return zero, and the word stem for test returns zero as a word: a naive substring search finds four hits and every one of them is the word for attestation, in the context of auditor accreditation. That is precisely the false positive that lets someone claim the ordinance requires testing.

Phishing does appear once, and it appears as a prohibition rather than a duty. The ordinance forbids a person reporting a vulnerability under coordinated disclosure from circumventing barriers by techniques such as brute-force attacks, phishing or other social engineering procedures. Social engineering appears in the same sentence and nowhere else.

The human-layer duty is the ordinary one: basic cyber-hygiene practices and cybersecurity training among the risk-management measures, plus a training duty on the governance side. The word for exercises appears a handful of times and refers to national crisis exercises run by the national authorities and the European agency, not to duties on individual entities.

For financial entities the European digital operational resilience Regulation applies directly from 17 January 2025. Counted through, it contains no occurrence of social engineering and none of phishing; its list of test types omits social engineering entirely; and what it does require is compulsory awareness training modules for all staff and senior management, plus threat-led penetration testing at least every three years on live production systems for the entities identified for it.

The human layer arrives only in the delegated regulation on that testing, where social engineering appears three times: in a recital describing the exploitation phase as compromising the entity's systems and exploiting its staff through social engineering, in the red team competency requirements, and in the annex requiring the test plan to state the ethical boundaries for social engineering. Named as a competency and as a plan-content item, never as a standalone obligation.

One national point, reported at the strength we can support it. Romania appears on the European central bank's list of jurisdictions that have adopted the threat-led testing framework, which cuts against the assumption that it has not. The central bank document the list links to could not be retrieved, so that finding rests on the European source alone and is one layer thinner than the rest of this page.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in ROMANIA. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed in advance and the programme is in our regulament intern.

Verify or correct each proposition below against primary Romanian sources, and tell me how to evidence condition (d):

1. ⚠⚠ Legea 190/2018 art. 5 imposes FIVE CUMULATIVE conditions on the legitimate-interests basis for monitoring «prin mijloace de comunicaţii electronice»: prevailing justified interests; mandatory, complete and explicit prior information; consultation of the union or employee representatives BEFORE INTRODUCING the systems; proof that less intrusive means «nu şi-au dovedit anterior eficienţa»; and retention «nu mai mare de 30 de zile». Confirm all five and that failing one removes the ground.
2. ⚠ ANSPDCP's 2024 report applies art. 5 to a monitoring application «rulată anterior doar într-o perioadă de testare». What does that mean for a PILOT campaign?
3. What evidence has ANSPDCP accepted for limb (d) in any published decision?
4. ⚠⚠ The dangerous criminal article is Cod penal art. 302(2), NOT art. 226. Confirm: CCR Decizia 33/2017 §29 and ÎCCJ HP 18/2024 confine art. 226's locational element to a domicile; art. 302(2) names telephone calls, alin. (5) has only TWO exceptions, and alin. (7) confines the prior-complaint gate to alin. (1) so the telephone limb is prosecuted EX OFFICIO.
5. Does documented advance authority negate «fără drept» in art. 302(2)? This is the whole position and it rests on an element rather than an exception.
6. ÎCCJ HP 51/2021: the disclosure offence is «nu este condiționată» on the material having been obtained without right. Confirm the consequence for circulating debrief audio.
7. ⚠ Legea 506/2004 art. 12 says «comunicări comerciale», NOT «marketing direct»; the test is promotional purpose per Legea 365/2002 art. 1 pct. 8. Confirm, and note art. 12(2) still cross-refers to the repealed Legea 677/2001.
8. Legea 467/2006 (not Legea 367/2022) carries the 20-employee threshold and the reasoned-reply duty. Confirm.
9. ⚠ The ANCOM blocking measure has NO decision number: it is individual decisions of 04.06.2025 in force 07.07.2025, with the mobile ranges (0Z = 06/07) carved out. Confirm the carve-out is a gap in enforcement rather than a permission.

Flag anything that has changed since September 2026, and identify any obligation in our own contract colectiv de muncă that this analysis omits.

Common questions

What does Romanian law require before we run a campaign?
Five things at once: justified interests that prevail, complete and explicit prior information to employees, consultation of the union or employee representatives before the system is introduced, evidence that less intrusive methods did not work, and retention capped at thirty days.
Is thirty days really the retention limit?
Yes, unless a statute expressly provides otherwise or the case is duly justified. The regulator has penalised employers for exceeding it, including by formal warning. Plan for outcome data that survives deletion of the underlying records rather than for a long-lived archive.
Can we record the simulation call?
Carefully. The interception offence names telephone calls expressly, has only two exceptions and neither is participation or consent, and it is prosecuted of the authorities' own motion rather than on the employee's complaint. What keeps you outside it is documented authority making the act not without right.
Will calls from outside Romania get through?
Not if they present a Romanian fixed or special number: providers have had to block those since 7 July 2025 unless they can establish with certainty that the number correctly identifies the caller. Mobile ranges are carved out for roaming, which is a gap in enforcement rather than a permission.

Elsewhere in Central and Eastern Europe

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.