In brief
- Law no. 119/2026 establishes the National Platform for Public Digital Infrastructure (PNIDP), a “single register” run by the Romanian Digitalisation Authority (ADR), covering all public institutions’ websites, apps, e-mail addresses, phone numbers, software licenses and IT equipment.
- Every digital resource of the state receives a persistent unique code, and every institution a unique source code, both verifiable by any citizen on the data.gov.ro portal – useful above all for telling a genuine government website apart from a phishing look-alike.
- It covers central and local public authorities and institutions (not the army, police or intelligence services), which have 6 months from the law’s entry into force to register all their digital resources; those who fail to comply risk a fine and, on repeat offences, having their access to the platform blocked.
Published: Official Gazette of Romania (Monitorul Oficial) no. 550 of 3 July 2026
Enters into force: 3 January 2027
For the first time, Romania will have a single register of all official websites, apps, e-mail addresses and phone numbers belonging to public institutions. Law no. 119/2026 on the record-keeping and administration of public digital infrastructure, promulgated by Decree no. 373/2026 and published in the Official Gazette of Romania on 3 July 2026, sets up the National Platform for Public Digital Infrastructure (PNIDP), run by the Romanian Digitalisation Authority (ADR). The law’s declared purpose is twofold: to bring order to the state’s digital “map,” often scattered across thousands of central and local institutions, and to give citizens a simple way of checking whether a website or app claiming to belong to a public institution is genuinely authentic.
In practice, the law requires every public authority and institution to inventory, in a single IT system, everything that counts as “digital infrastructure”: internet domains, subdomains, e-mail addresses, official phone numbers, apps and platforms, software licenses, hardware equipment and digital projects funded with public money. Each resource registered this way receives a unique code, used as a mark of authenticity across all the state’s digital platforms.
The security requirements that the infrastructure in the register has to meet were spelled out a year later, through the catalogue of 218 cybersecurity controls approved by the DNSC.
What it changes in practice
For citizens, the most visible effect will be the ability to check, on the public portal data.gov.ro, whether a website or app claiming to be “official” really does belong to that institution. The persistent unique code assigned to each public digital resource and the unique source code of each institution are meant to work as a kind of digital “authenticity mark,” useful above all against the growing phenomenon of fraudulent look-alike government websites (phishing).
For public institutions, the law introduces a new, substantial administrative obligation: appointing a “digital officer” to continuously inventory and update the institution’s digital resources, with strict reporting deadlines (15 days for ordinary changes, 5 days for urgent ones). More importantly, institutions that fail to register their digital resources in PNIDP will no longer be able to receive funding to modernise them – a lever meant to force compliance faster, and in practice more effectively, than the fines themselves.
For IT suppliers in the public sector (firms that build websites, apps or platforms for city halls, ministries or agencies), the law brings a reuse mechanism: apps and software licenses left unused by one institution can be redistributed to another public institution, with ADR’s approval, which could cut down on redundant software purchases for functionality that already exists elsewhere in the public system.
What has changed compared with the previous situation
- A single, mandatory register now exists: until now there was no centralised record of the websites, apps, licenses and IT equipment held by Romanian public institutions; each authority managed its own digital infrastructure, with no unified reporting to a central body.
- A public authenticity-check mechanism now exists: citizens previously had no official tool to confirm that a website or app genuinely belonged to a public institution; PNIDP’s persistent unique code is meant to fill exactly that gap.
- Public IT funding is now tied to registration: modernisation solutions for public digital resources can no longer be funded or purchased unless the resource in question is registered in PNIDP – a condition that did not exist before.
- The “digital officer” role is created: every public institution must appoint a person dedicated to this record-keeping, with clear duties and deadlines, or, failing that appointment, the obligations fall automatically to the institution’s head.
- The link with cybersecurity is formalised: resources registered in PNIDP fall directly under Emergency Ordinance no. 155/2024 on cybersecurity, and the National Cybersecurity Directorate (DNSC) can set additional security requirements for the platform’s data.
Advantages and disadvantages
What it improves
- For the first time, citizens get an official tool for verifying the authenticity of government websites and apps, useful in the fight against phishing that impersonates public institutions.
- Less waste: software licenses left unused by one institution can be redistributed to another public institution, instead of being purchased again, in parallel, with public money.
- An up-to-date overview of the state’s digital infrastructure helps a faster response to cyber incidents, through coordination between ADR, STS and DNSC.
- Mandatory minimum technical standards (security, interoperability, accessibility) raise the bar for all public websites and apps, including digital accessibility for people with disabilities.
What remains a problem
- The administrative burden falls largely on small town halls and local institutions without dedicated IT staff, who will still have to appoint a digital officer and meet reporting deadlines of just 15, respectively 5, days.
- The fines (5,000-10,000 lei) are modest for institutions with large budgets, and the real pressure comes more from losing access to IT funding than from the penalty itself.
- The law only enters into force 6 months after publication, and the implementing methodological norms (essential for practical application) have a further 60-day deadline from that moment – so the concrete effects for citizens will only be visible from the second half of 2027.
- PNIDP adds to an already long list of the Romanian state’s digital platforms and registers, with the known risk, seen in other similar projects, that gradual implementation stalls at just a handful of large institutions.
Practical advice
- If you work in a public institution (central or local), check early with management who will be appointed “digital officer” – the law gives you 6 months from its entry into force (so until 3 July 2027) to register all the institution’s digital resources in PNIDP, and delays can block funding for IT modernisation projects.
- If you manage websites or apps for a city hall or public institution as a contractor, inform your client about the new registration obligation from the contracting stage of new projects onward, to avoid later funding blockages.
- As a citizen, remember the data.gov.ro portal as a future reference point for checking the authenticity of government websites, especially when you receive links by e-mail or SMS claiming to come from a state institution – until the platform is fully operational, stay alert to the usual signs of phishing (slightly misspelled domains, requests for personal or banking data).
- Don’t mistake PNIDP for a direct public service for citizens: the platform is, in essence, a record-keeping and administration tool for institutions; direct public interaction with it will, at least initially, be limited to checking authenticity codes on the public portal.
Frequently asked questions
What is the National Platform for Public Digital Infrastructure (PNIDP)?
Who is required to register in PNIDP?
When does the law enter into force, and when must registration be completed?
What happens if a public institution fails to register on time?
How does a citizen check whether a government website is authentic?
Does the law apply to private companies too, or only to the state?
Original text of the legal act
Below we reproduce in full the text of Law no. 119/2026, exactly as published in the Official Gazette of Romania, Part I, no. 550 of 3 July 2026 (excerpt from the official PDF edition, pages 4-7). The text below is reproduced in Romanian, the official language of publication.
The full text, as published in the Official Gazette of Romania
Official Gazette of Romania no. 550 of 3 July 2026 16 pages PDF, 105 KB the act starts on page 4
Open the official PDFDownload the PDF
The viewer is not shown on small screens. Use the buttons above to open or download the file.
Disclaimer: This article is for informational purposes only and does not constitute legal advice. For the interpretation and application of legal provisions in specific situations, consult a lawyer or a specialised consultant.
This article is for informational purposes only and does not constitute legal advice. For specific situations, consult a licensed attorney or tax advisor.
