Markets

B2B website visitor identification in Romania

Romania has become one of the largest IT outsourcing and software development hubs in the EU, with Bucharest and Cluj hosting delivery centres and product teams that sell services to buyers across Western Europe. A large share of the traffic to those sites is quiet due diligence: a prospective client in Germany, France or the Nordics reads case studies, team pages and technical write-ups for weeks before anyone submits a form. Company-level identification names that visitor while the evaluation is still open.

  • FrameworkGDPR + Law No. 190/2018
  • SupervisionANSPDCP (Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal)
  • Usual legal basisLegitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
  • Processing locationISO-certified EU data centres

Because so much of Romania's B2B activity runs through nearshoring relationships, the buyer on the other end of the review is often used to being audited itself and asks correspondingly specific questions. This page sets out the legal framework that applies to a Romanian site, what Romanian and Western-European procurement teams typically check, and how lead.box's documentation is built to answer it.

At a glance

Framework
GDPR + Law No. 190/2018
Supervision
ANSPDCP (Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal)
Usual legal basis
Legitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
Processing location
ISO-certified EU data centres

The legal framework in Romania

Regulation at a glance

  • FrameworkGDPR + Law No. 190/2018
  • SupervisionANSPDCP (Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal)
  • Usual legal basisLegitimate interest, Art. 6(1)(f) GDPR, with a documented balancing test
  • Processing locationISO-certified EU data centres

The GDPR applies directly across Romania, and Law No. 190/2018 supplements it with implementing provisions: it fills in areas the GDPR leaves to national legislation, including rules on processing employee data, national identification numbers and certain categories of special data, and it confirms the powers and procedure of ANSPDCP (Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal) as the country's supervisory authority. For a B2B site operating here, that means a documented lawful basis, an accurate record of processing activities, and a signed processor agreement before any visitor-identification script is deployed.

ANSPDCP's enforcement activity has historically concentrated on complaint-driven investigations and sector sweeps — telecoms, financial services and public administration in particular — rather than proactive audits of every SME website, but it has issued fines for missing or superficial records of processing and for legitimate interest claims that were not actually documented. That practice means a controller cannot rely on ANSPDCP's lighter day-to-day visibility as a reason to skip the paperwork: the balancing test and the record of processing still need to exist and be accurate.

Cookie and similar-technology consent rules follow from the ePrivacy Directive as implemented in Romanian law through Law No. 506/2004 on the processing of personal data in electronic communications, which requires consent for storing or accessing information on a visitor's device beyond what is strictly necessary. Company-level identification that does not set advertising identifiers or cross-site tracking cookies falls outside that consent trigger, while the rest of a Romanian site's tracking setup remains the controller's own assessment.

What the Romanian market expects

Romania's outsourcing and software sector routinely sells into regulated Western-European industries — finance, healthcare, automotive — which means the vendors it hires are frequently held to the standards of that end client rather than a purely domestic baseline. Expect requests for a data processing agreement under Art. 28 GDPR, a named and versioned sub-processor list, a specific answer on where data is processed, and confirmation that the tool's entry fits cleanly into the customer's own record of processing activities.

Because many Romanian companies act as the reviewed party in their own client relationships, their internal reviewers tend to ask precise, technically literate questions rather than working from a generic template. Romanian-language documentation is expected less often for the vendor itself, given the sector's fluency in English, but a Romanian summary still speeds up sign-off with legal or works-council stakeholders who prefer to review in their own language.

As elsewhere, a claim that a tool removes the need for legal review does not survive a Romanian technical audience used to line-by-line data flow diagrams. What holds up is a precise description of what is resolved to a company, what is discarded immediately, and where the customer's responsibility as controller starts.

Start free

Install the snippet and see the first named companies on your own traffic.

What you actually see

Named companies in your dashboard, with industry, size and the pages they read.

Where identification pays off here

The clearest fit is outbound sales for Romanian IT outsourcing and software firms selling to Western Europe: a prospect from a German manufacturer or a French insurer browses a delivery centre's site, portfolio and technical blog over several visits before any call is booked, and naming that account early lets a sales team follow up while the shortlist is still being built rather than after it closes.

It also serves the inverse flow — Western-European buyers researching Romanian development partners in Bucharest and Cluj, and Romanian B2B SaaS or product companies whose own prospects are similarly quiet browsers. A handful of identified visits per week from the right accounts is enough to produce a usable outreach list; the volume of traffic matters less than being able to name who is behind it.

How lead.box works here

GDPR-compliant visitor identification: the 5 rules

1. Company level only

Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.

2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR

Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.

3. No personal identifiers

No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.

4. EU data processing

Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.

5. Transparency and opt-out

Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.

lead.box applies all five rules by design.

Questions from this market

Yes, it is workable under the GDPR and Law No. 190/2018 as long as identification stops at the company and never singles out an individual visitor. The usual legal basis is legitimate interest under Art. 6(1)(f) GDPR, supported by a documented balancing test and disclosed in the privacy policy. Because much of Romania's B2B sector sells into regulated Western-European industries and is itself frequently audited by its own clients, in-house counsel here tend to expect a written balancing test rather than a verbal reassurance from a vendor. lead.box provides a template balancing test and a data processing agreement so your own legal team can confirm the assessment matches your specific site and audience rather than relying on a general statement.

ANSPDCP, the Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal, is Romania's supervisory authority under the GDPR and Law No. 190/2018. Its enforcement has historically concentrated on complaint-driven cases and sector sweeps in telecoms, financial services and public administration rather than proactive audits of every SME website, but it has issued fines for missing or superficial records of processing and for legitimate interest claims that were never actually documented. That means a Romanian controller cannot treat ANSPDCP's lower day-to-day visibility as a reason to skip the paperwork; the record of processing and the balancing test still need to exist and be accurate, especially for companies whose end clients run their own compliance audits.

No, lead.box's own resolution step does not trigger an additional cookie banner because it does not set advertising identifiers, device fingerprints or cross-site tracking cookies on the visitor's device. Romania's cookie consent obligation comes from Law No. 506/2004 on the processing of personal data in electronic communications, which implements the ePrivacy Directive and requires consent for storing or accessing information on a visitor's terminal equipment beyond what is strictly necessary; company-level matching via IP address falls outside that specific trigger the way an ad pixel would not. Everything else running on your Romanian site — analytics, retargeting, chat tools — keeps its own separate assessment, which remains your responsibility as controller and is worth confirming with counsel.

Data concerning visits from the EU, including Romania, is processed in ISO-certified EU data centres and is not moved outside the EU for this purpose. This tends to matter more in Romania than the domestic regulator alone would suggest, because Romanian outsourcing and software companies are frequently reselling assurances up the chain to Western-European end clients who run their own vendor security questionnaires and expect a specific, written answer rather than an assumption of EU hosting. lead.box provides that confirmation in writing along with the Art. 28 GDPR data processing agreement and a named, versioned sub-processor list, so it can be attached directly to a client's own due diligence file without further back-and-forth.

Expect a technically literate review rather than a checklist exercise, since many Romanian IT and outsourcing companies are themselves regularly audited by regulated Western-European clients and apply the same rigour when they buy tools. Typical requirements include a signed Art. 28 GDPR data processing agreement, a named and versioned sub-processor list, a specific answer on processing location, and confirmation that the vendor's entry fits cleanly into the customer's own record of processing activities. Reviewers here often ask precise, data-flow-level questions rather than working from a generic template, so having each document ready in advance, instead of promising to follow up later, is what actually shortens the sign-off in this market.

It is not a strict GDPR requirement for the vendor, and Romania's IT and outsourcing sector generally works comfortably in English, so this is usually a smaller obstacle here than in some neighbouring markets. Even so, a Romanian-language summary of the data processing description and balancing test can still speed up sign-off with legal or works-council stakeholders who prefer to review compliance material in their own language before approving a new script on a production website. lead.box can produce that Romanian summary on request; it supplements rather than replaces the underlying English contract, and it is most useful when the reviewing team includes non-technical or legal staff outside the English-fluent engineering group.

lead.box issues invoices against your company's fiscal identification code (CUI) so the invoice can be booked correctly under Romanian accounting rules and, where applicable, treated as a cross-border EU service; your finance team should confirm reverse-charge and any e-Factura submission obligations with its own accountant, since lead.box does not provide tax advice. Romanian finance teams are typically precise about matching invoice details — company name, registered address and CUI — to the exact ONRC company register entry, and about ensuring the invoice can be reflected correctly wherever e-Factura reporting applies to the purchase. Supplying accurate billing details at signup avoids a corrected invoice later and keeps contracting separate from the technical rollout timeline.

Standard analytics dashboards report anonymous session counts, not which company is behind a visit, which is of limited use to a Romanian sales team trying to prioritise outbound follow-up. lead.box resolves qualifying visits to a named company using IP-to-company matching and first-party tracking, turning a page-view number into an account a rep can actually contact. This is particularly relevant for Romanian outsourcing and software firms selling to Western Europe, where a prospective client from a German manufacturer or a French insurer will typically browse case studies and technical pages across several visits before booking a call — identification names that account while the shortlist is still being built, rather than only after a generic inbound enquiry arrives.

See which companies are already researching you in Romania

Install a first-party snippet, watch the first named companies appear, and hand your legal or procurement reviewer the documents in the same week.

Start free

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links