In short: A company website in Romania must show its Trade Register number and CUI under Law 365/2002, have a privacy policy describing what the site actually does, and a cookie banner where rejecting is as easy as accepting. Most sites I review are missing the Trade Register number and CUI.
Most websites I take over or review are missing something the law requires. It is rarely on purpose: the developer focused on the looks, and the owner did not know this was their job too. This article goes through the legal requirements for a company website in Romania, and which law demands each one.
One important note: this is not legal advice. As a developer I see what is usually missing, and I refer to the text of the laws. If your activity is regulated (healthcare, finance, law) or you are unsure, ask a lawyer.
An online store needs more than this: I wrote a separate article on the right of withdrawal and the mandatory elements of online stores.
1. Legal requirements: company details, clearly visible
Under Article 5 of Law 365/2002 on electronic commerce, anyone offering services through a website must give easy, direct and permanent access to:
- the company's name;
- its registered office;
- its phone number, email address and any details needed to contact it directly;
- its Trade Register number (Registrul Comerțului);
- its tax identification code (CUI);
- the details of the competent authority, if the activity requires authorisation;
- for regulated professions, the professional title and professional body.
Most sites are missing the Trade Register number and the CUI. The simplest place for them is the footer, where they appear on every page. You will find them there on my own site too.
2. A privacy policy that is about your site
If the site has a contact form, a newsletter signup, or a tracking code (such as Google Analytics), you are processing personal data, and under the GDPR (EU Regulation 2016/679) you must tell visitors: who processes the data, for what purpose, on what legal basis, how long you keep it, who you share it with, and what rights they have.
The most common mistake is a template copied from elsewhere that does not describe what actually happens on your site. It mentions a newsletter you never sent, and leaves out the Facebook pixel that is running. That does more harm than good.
A few questions the policy must answer concretely:
- Where does form data go? Only to email, or is it also stored in the site's database? For how long?
- Which external service receives data? Email provider, analytics, maps, embedded video.
- How can someone ask for their data to be deleted?
My own privacy policy, for example, states that contact form messages are kept for 24 months and then deleted automatically. The site is actually configured that way, so the text matches what happens.
The form also needs a consent checkbox that links to the policy. I wrote more about forms here, because a badly configured checkbox sometimes blocks the whole form.
3. Cookie consent that actually works
Under Law 506/2004, cookies that are not strictly necessary (analytics, ad tracking, embedded social content) may only be used with the visitor's prior consent.
The common mistakes:
- There is a cookie banner, but it does nothing. It says "we use cookies", but Google Analytics starts on the first page load whether you accept or not.
- There is only an "Accept" button. Rejecting must be as easy as accepting.
- There is no cookie policy listing the cookies on the site.
To check: open the site in a private browser window, do not accept cookies, and look in the browser's developer tools (F12 → Application → Cookies) for a cookie starting with _ga. If it is there, tracking runs without consent.
On my site, Google Analytics only starts after consent. My statistics undercount because of this, but the setup is compliant.
4. Accessibility: who does it apply to?
Since June 2025, Law 232/2022 sets accessibility requirements for certain online services, above all online stores. Micro-enterprises are exempt. I described in detail who is covered and who is not.
5. Not mandatory, but strongly recommended
- Image copyright. A photo downloaded from Google is not yours. Use your own images, bought or freely licensed photos, and keep the licence.
- A secure connection (HTTPS). No specific law requires it, but if you collect data through a form, the GDPR expects appropriate security, and browsers mark unencrypted sites as "not secure".
- Email authentication. If the form sends email, set up SPF, DKIM and DMARC properly, otherwise messages land in spam or someone else can send email in your company's name. It happened to me too.
A ten-minute checklist
- Does the footer show the company name, registered office, Trade Register no., CUI, phone, email?
- Is there a privacy policy, and does it actually describe your site?
- Is there a consent checkbox next to the form, linking to the policy?
- Does the cookie banner have a "Reject" button too?
- After rejecting, is there no
_gacookie? - Is there a cookie policy?
- Do you know where your images come from?
If the answer to any of these is no, send me your site's address and I will tell you what is missing. On every site I build these are included from the start, and when taking over an existing site they are part of the first assessment.

