Commercial lease agreement in Romania with office key and floor plan

Commercial Lease Agreement Romania: 12 Key Clauses

Commercial real estate · Romania

A commercial lease is a long-term allocation of occupancy cost, operational responsibility and exit risk. Review the legal and practical controls before the premises, rent and fit-out commitments become difficult to unwind.

12 key clausesLandlord and tenant viewRomanian Civil Code focus
Decision lens Can the premises support the business, and can the contract control the downside? Use the interactive maps below to move from the commercial brief to signing, operation and exit.

A commercial lease agreement in Romania can commit a company to years of rent, service charges and restoration costs. The commercial decision therefore depends not only on the monthly headline rent, but also on whether the premises can lawfully support the tenant’s activity and whether the contract allocates operational risks clearly.

Commercial lease agreement in Romania with office key and floor plan
Commercial premises and lease documentation in Romania.

This guide is intended for landlords and companies leasing offices, retail units, warehouses and other business premises. It explains the principal clauses to check under the Romanian Civil Code and the related property, tax and authorisation framework. Residential leases and leases of public property follow additional rules and are outside this article’s main scope.

Is a written commercial lease mandatory in Romania?

Romanian law does not generally require a privately owned commercial lease to be notarised for validity. A signed written contract is nevertheless essential for evidence, enforceability, tax treatment and protection against third parties.

The lease relationship is governed principally by the Romanian Civil Code, especially the general rules on lease agreements. The parties have broad contractual freedom in a business-to-business transaction, but statutory rules apply where the lease is silent, and certain mandatory provisions of Romanian law may apply irrespective of contractual wording.

Under Article 1798 of the Civil Code, a lease concluded in authentic form, or a privately signed lease registered with the competent tax authority, may constitute an enforceable title for rent payment under the conditions stated by law. Tax registration affects enforceability, not the validity of the lease. It is not a universal requirement for the existence of every corporate lease, although the applicable tax and registration duties must still be checked for the particular landlord and transaction.

For leases requiring stronger protection against a future buyer or other third parties, the parties should assess land-book registration. The correct mechanism depends on the property, the lease term and the landlord’s registered title. A company entering a long-term lease should not assume that signature alone gives the same protection as registration.

Lease signing roadmap
From premises selection to rent commencement

Select a stage to see the legal control that should be completed before moving forward.

Define the commercial scope

Fix the exact premises, intended activity, timetable, fit-out assumptions, headline rent and critical conditions before detailed drafting begins.

What should be checked before the commercial lease is signed?

Verify the landlord, title, cadastral identity, permitted use, technical condition and authorisation route before the lease becomes unconditional.

The tenant should compare the land-book extract and cadastral plan with the space actually offered. The review should cover ownership, mortgages, litigation annotations, existing leases, access rights, parking, common areas and the landlord’s authority to grant the agreed use. These checks overlap with a focused real estate due diligence review in Romania.

The proposed activity must also be compatible with the building’s authorised use and applicable planning, fire-safety, sanitary, environmental and sector-specific requirements. A contractual statement that the tenant will obtain “all permits” does not solve a structural problem with the premises. The lease should distinguish permits relating to the building from those relating to the tenant’s own business.

For buildings or units covered by Law no. 372/2005, the owner must address the applicable energy-performance certificate obligations when leasing. The current framework covers offices, retail and other occupied commercial uses, subject to statutory exemptions. See the official energy performance legislation.

CheckTenant questionContract response
Title and authorityDoes the landlord own and control the exact premises?Attach current land-book and corporate authority evidence.
Permitted useCan the intended activity operate lawfully here?Make effectiveness or rent commencement conditional where appropriate.
Physical conditionWho bears existing defects and compliance works?Use a detailed handover report, photos and defect list.
Third-party rightsCould a lender, buyer or other tenant disrupt use?Consider lender consent, non-disturbance and land-book protection.
Utilities and capacityAre power, HVAC, access and loading capacity sufficient?Define technical specifications and remedies for shortfalls.

The 12 clauses that determine the real commercial risk

Commercial lease risk selector
Where can the lease create the greatest exposure?

Select a clause to see the negotiation priority.

Total occupancy cost

Model base rent, indexation, VAT, service charge, utilities, insurance contributions and one-off fit-out or reinstatement expenses.

1. Parties, authority and guarantees

Identify each party by its full legal name, registered office, registration number and tax code. Confirm the signatory’s authority. If a parent company, bank or shareholder gives security, specify whether it is a guarantee, autonomous demand guarantee, deposit or another instrument, together with its cap, duration and claim procedure.

2. Exact premises and permitted use

The lease should attach a plan and state the exclusive area, common-area allocation, parking and access rights. “Office use” or “commercial use” may be too vague. Describe the actual activity and deal with signage, customer access, deliveries, opening hours, hazardous materials and exclusivity if commercially relevant.

3. Term, commencement and long-stop date

Separate the signature date, handover date, fit-out access date, lease commencement and rent commencement. If delivery or permits are delayed, a long-stop date should allow the affected party to terminate. The Civil Code limits leases to a maximum statutory duration, so unusually long structures require specific review.

4. Rent, currency and indexation

State the currency, payment currency, exchange-rate source, due date and invoicing mechanics. An indexation clause should identify the index, reference period, first adjustment date, whether decreases apply and whether there is a cap or floor. Avoid combining indexation with discretionary “market rent” language unless the valuation procedure is clear.

5. VAT, withholding and invoicing

The lease of immovable property is generally VAT-exempt under the Romanian Fiscal Code, subject to important statutory exceptions and the landlord’s option to apply VAT under the prescribed procedure. Ancillary services, bundled supplies, invoicing structures and certain categories of premises may require distinct treatment. The contract should state whether figures include or exclude VAT and what happens if the VAT treatment changes. The parties should also align invoicing with the applicable Romanian electronic invoicing rules. For wider compliance context, see the site’s Romanian tax guidance.

6. Service charge and operating costs

Define recoverable costs, allocation formula, budget, reconciliation, audit rights and exclusions. Capital expenditure, financing costs, structural defects, landlord negligence, vacancy costs and costs relating to other tenants should not be hidden in a generic “all building expenses” clause. Retail leases may also involve marketing contributions and turnover reporting.

Cost itemPoint to negotiateTypical control
Base rentArea, currency, payment date and rent-free periodRent schedule attached to the lease
IndexationIndex, floor, cap and first adjustmentWorked example and no double escalation
Service chargeRecoverable categories and allocationAnnual budget, reconciliation and audit right
UtilitiesMetered consumption versus allocationSeparate meters or transparent formula
VATExempt or taxable treatmentExpress net/gross wording and change mechanism
ReinstatementRemoval and restoration at exitAgreed baseline and pre-expiry inspection

7. Deposit and financial security

Specify the amount, currency, replenishment duty, permitted deductions, return deadline and whether interest accrues. A bank guarantee should state the required issuing bank, wording, expiry buffer and renewal consequences. The landlord should not have an unlimited right to draw security for disputed amounts.

8. Handover, condition and defects

A signed handover protocol should record keys, meters, systems, inventory, photographs and defects. Define the condition standard at delivery and the remedy if the premises fail the agreed technical specifications. The tenant should not inadvertently accept latent or structural defects merely by taking possession.

9. Fit-out, alterations and ownership of improvements

Address design approval, permits, contractors, access, insurance, health and safety, delays and damage. The lease must also say whether improvements become the landlord’s property, whether compensation is available and what must be removed at expiry. These provisions should be coordinated with the construction-law implications of fit-out works.

10. Repairs, maintenance and building services

The Civil Code places core delivery, maintenance and peaceful-use obligations on the landlord, while the tenant normally bears routine repairs resulting from ordinary use, subject to the contract and the nature of the defect. A commercial lease should allocate structure, roof, façade, common systems, HVAC, internal installations and statutory upgrades expressly, together with response times and self-help rights.

Responsibility map
Who controls each category of work?

Select the responsible actor. The final allocation must be stated in the lease and coordinated with insurance and access rights.

Landlord-controlled matters

Ownership, structural integrity, roof and façade, common systems and building-level approvals normally require the landlord’s control and cooperation.

MatterStarting allocationLease control
Structure, roof and façadeLandlordResponse deadline, access and tenant remedy if use is disrupted
Routine internal maintenanceTenantStandard of care and exclusions for latent defects
Common building systemsLandlord or service-charge regimeService levels, cost allocation and outage remedies
Tenant fit-outTenant, subject to approvalDesign approval, permits, ownership and reinstatement
Statutory upgradeDepends on cause and scopeBuilding-level versus activity-specific responsibility

11. Assignment, subletting and corporate change

The Romanian Civil Code contains specific rules on assignment and subletting, which are frequently modified by commercial lease clauses. The contract should therefore state whether landlord consent is required and on what conditions. The tenant may seek objective consent standards for group reorganisations, business transfers and subleases, while the landlord may require financial tests or continued liability.

12. Default, termination, force majeure and hardship

List the defaults that justify termination, notice method, cure periods and consequences. Non-payment, unlawful use, loss of permits and abandonment need different treatment. Insolvency provisions should be reviewed together with the applicable insolvency legislation: Article 123 of Law no. 85/2014 maintains ongoing contracts at the opening of insolvency proceedings and may limit clauses that terminate or accelerate solely because insolvency has commenced. Force majeure should address genuine impossibility, while hardship or major economic disruption requires a separate allocation because increased cost alone is not automatically force majeure.

What happens if the building is sold?

A tenant should not rely on a simple “sale does not affect the lease” sentence. Ongoing protection depends on the Civil Code’s opposability rules and the steps taken to make the lease effective against the buyer.

Articles 1811 and following of the Civil Code regulate when a lease is opposable to a purchaser and the consequences of transferring the leased property. For registered immovable property, notation of the lease in the Land Registry is a central opposability mechanism; other statutory rules may apply depending on the property and transaction. The lease should require the landlord to notify a sale, procure the buyer’s assumption of obligations and transfer the deposit or guarantees correctly. For material long-term premises, the tenant should assess Land Registry notation and lender non-disturbance arrangements. The seller’s continuing liability, if any, should be stated rather than assumed.

Can the landlord enforce unpaid rent without a full lawsuit?

Potentially yes. A qualifying lease may constitute an enforceable title for rent, but enforceability depends on the contract’s form or tax registration and on the claim being due and sufficiently determined.

Article 1798 of the Civil Code gives qualifying leases enforcement value for rent. Separate rules may also support restitution of the premises when a fixed-term lease expires. Parties should coordinate default clauses with Romanian civil procedure and should not assume that a contractual label such as “enforceable” creates enforcement rights by itself. Broader non-payment strategies are covered in the guide to recovering unpaid business claims in Romania.

Exit & default risk map
How can the lease relationship end?

Select a route to review the clause that should control notice, cost and handover.

Expiry of the agreed term

Set the handover date, inspection process, reinstatement standard, deposit reconciliation and treatment of any continued occupation.

Exit eventDocument to controlMain financial exposure
Fixed-term expiryExpiry notice and handover protocolReinstatement, dilapidations and deposit deductions
Tenant breakBreak notice complying exactly with the clausePenalty, incentive repayment or remaining liabilities
Termination for breachDefault notice and evidence of cure periodArrears, damages, security draw and enforcement costs
Property saleBuyer assumption and opposability evidenceDeposit transfer and continuity of tenant rights
Continued occupationWritten extension or renewal termsUncertain rent, duration and exit notice

Landlord and tenant negotiation checklist

  1. Verify title, cadastral identity, authority and encumbrances.
  2. Confirm that the building and the intended activity can obtain the necessary approvals.
  3. Attach the plan, technical specifications, handover standard and fit-out rules.
  4. Model rent, indexation, VAT, service charge, utilities and exit costs.
  5. Allocate structural, routine and statutory repair obligations precisely.
  6. Align guarantees with actual exposure and release dates.
  7. Negotiate cure periods, break rights, long-stop dates and restoration obligations.
  8. Assess tax registration, enforceability and land-book protection.
  9. Record condition, meters, defects and assets in the handover protocol.
  10. Retain signed notices, invoices, approvals and service-charge reconciliations.

The bottom line

A commercial lease agreement in Romania is primarily a long-term allocation of business risk. The strongest contract is not necessarily the longest. It is the one that identifies the premises accurately, prices the full occupancy cost, makes the authorisation path workable and provides realistic remedies when delivery, operation or exit does not go as planned.

Before committing to a significant lease, both landlord and tenant should coordinate the legal document with technical due diligence, tax treatment, insurance and the operational timeline. A focused contract review in Romania can identify inconsistencies before the commercial timetable makes them expensive to correct.

Frequently Asked Questions

Must a Romanian commercial lease be notarised?

No, not as a general validity rule for a private commercial property. However, authentic form, tax registration and land-book notation can have different consequences for enforcement and opposability. The right structure depends on the parties, term, property and intended protection.

Can rent be stated in euros but paid in Romanian lei?

Yes, parties often denominate rent in euros and provide payment in lei. The lease should identify the exchange-rate source and date, address bank charges and avoid ambiguity about whether indexation applies before or after currency conversion.

Is VAT charged on commercial rent in Romania?

The lease of immovable property is generally VAT-exempt, subject to important statutory exceptions and the landlord’s option to apply VAT under the prescribed procedure. Ancillary services, bundled supplies, invoicing structures and certain premises may receive distinct treatment. The lease should state whether amounts are net or gross and allocate change-of-law risk.

Who pays for repairs in a Romanian commercial lease?

The Civil Code provides a default allocation, broadly separating the landlord’s obligation to maintain usable premises from routine tenant repairs. Commercial contracts usually refine this substantially. Structure, building systems, internal installations, negligence and statutory upgrades should each be addressed expressly.

Can a tenant terminate a fixed-term commercial lease early?

Only if the contract or applicable law provides a right to do so, or if a sufficiently serious breach justifies termination. Businesses should negotiate express break rights, notice periods, conditions and any repayment of incentives rather than rely on a general expectation of early exit.

Does the lease continue if the property is sold?

It may continue against the buyer when the Civil Code’s opposability requirements are satisfied. The tenant should assess land-book notation, the landlord’s sale obligations and any lender arrangements, particularly for high-value fit-out or a long remaining term.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.

Corporate data breach response centre managing a GDPR incident in Romania

GDPR Data Breach in Romania: 72-Hour Guide

A GDPR data breach in Romania creates an immediate legal decision window. The company must contain the incident, determine whether personal data were compromised, assess the risk to individuals and decide whether the Romanian supervisory authority, the ANSPDCP, must be notified within 72 hours.

GDPR data breach response and personal data security in Romania

What companies should know immediately:

  • The 72-hour period runs from the controller’s awareness of the breach, not necessarily from the moment the incident first occurred.
  • Every personal data breach must be documented, even when notification is not required.
  • The ANSPDCP must be notified unless the breach is unlikely to create a risk to individuals’ rights and freedoms.
  • Affected individuals must also be informed without undue delay when the breach is likely to create a high risk.
  • An incomplete investigation does not justify silence. GDPR permits information to be submitted in phases.

This guide is designed for Romanian companies, foreign investors, directors, compliance teams and data protection officers responding to an actual or suspected incident. It should be used together with an incident-specific legal and technical assessment. For preventive support and breach response, see our data protection services in Romania.

What qualifies as a personal data breach?

Article 4(12) of the General Data Protection Regulation defines a personal data breach as a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data. The concept is wider than a cyberattack and covers confidentiality, integrity and availability incidents.

Breach typeWhat it meansCommon exampleImmediate check
ConfidentialityPersonal data are accessed or disclosed without authorisation.An email with customer files is sent to the wrong recipient, credentials are stolen or an attacker exfiltrates a database.Who received or accessed the data, and can further access be stopped?
IntegrityPersonal data are altered without authorisation or by accident.Payroll details are changed, records are corrupted or an unauthorised user modifies a customer account.Which records changed, can the original data be restored, and were decisions made using incorrect data?
AvailabilityPersonal data become unavailable or are destroyed.Ransomware encrypts files, a database is deleted or a lost device contains the only copy of records.Are reliable backups available, how long will services be disrupted, and could the loss harm individuals?

A security event that does not involve personal data is not a personal data breach under GDPR. Conversely, a small incident can still be a breach. Under the data protection rules applicable in Romania, the number of affected people matters, but so do the sensitivity of the data, the ease of identification, the possible consequences and the vulnerability of the people concerned.

When does the 72-hour notification period start?

Article 33 requires notification without undue delay and, where feasible, no later than 72 hours after the controller becomes aware of the breach. According to the EDPB breach-notification guidelines, awareness exists when the controller has a reasonable degree of certainty that a security incident occurred and led to personal data being compromised.

A brief initial investigation may be necessary to determine whether personal data were actually affected. That does not permit an organisation to delay investigation or postpone escalation. Once there is reasonable certainty, the clock runs even if the full cause, exact number of records or final consequences are still being investigated.

72-hour incident clock
From awareness to notification

Select a stage to see the priority. The timetable is operational guidance, not a replacement for immediate action.

Confirm awareness

Record when the controller first reached a reasonable degree of certainty that personal data had been compromised. Preserve the facts supporting that timestamp.

Do not wait for a final forensic report before making the legal notification decision. Article 33 expressly permits phased notification when all information cannot be provided at the same time.

Must every breach be notified to the ANSPDCP?

No. Every breach must be recorded internally, but not every breach must be reported to the authority. The controller must assess the likely impact on the rights and freedoms of natural persons. The result falls into one of three practical levels.

Notification decision matrix
Choose the response level

Select a risk level to see the corresponding GDPR response. The conclusion must be supported by documented facts.

Document internally

If the breach is unlikely to result in a risk to individuals, authority notification is not required. The breach, assessment, effects and remedial action must still be recorded.

Assessment resultRequired actionTypical considerations
Unlikely to create riskDocument the breach and the reasons for not notifying.Strong effective safeguards, limited data, verified recovery, no realistic adverse effect and reliable containment.
Likely to create riskNotify the competent supervisory authority without undue delay and, where feasible, within 72 hours.Possible identity theft, fraud, loss of confidentiality, discrimination, financial loss, reputational harm or loss of control over data.
Likely to create high riskNotify the authority and communicate with affected individuals without undue delay, unless an Article 34 exception applies.Special-category data, credentials or financial data, vulnerable people, large-scale exposure, easy identification or serious likely consequences.

Risk is not determined by a single formula. The company should consider the type of breach, nature and volume of data, identifiability, severity and likelihood of consequences, number and characteristics of affected people, and the effectiveness of safeguards such as encryption. The EDPB’s practical breach examples are useful benchmarks, but the actual incident must be assessed on its own facts.

What must an ANSPDCP notification contain?

Article 33(3) establishes the minimum information. The ANSPDCP’s current online notification form requests additional operational details that allow the authority to understand the incident and the controller’s response.

Notification fieldWhat the company should prepare
Nature of the breachA concise incident summary, whether confidentiality, integrity or availability was affected, and the relevant systems and processing operations.
People and recordsCategories and approximate number of affected data subjects, plus categories and approximate number of personal data records.
Contact pointName and contact details of the DPO or another person able to provide further information.
Likely consequencesThe realistic adverse effects for individuals, including how they could occur and which groups face the greatest exposure.
MeasuresContainment and remediation already performed, further measures proposed, and actions intended to mitigate adverse effects.
TimelineIncident date and time where known, detection, awareness, response milestones and reasons for any notification made after 72 hours.
Additional contextProcessors involved, security measures, cross-border aspects, other authorities notified and whether the filing is initial or supplemental.

If exact figures are not yet available, provide reasonable estimates and state that the investigation continues. Under Article 33(4), missing information may be supplied in phases without undue further delay. If the filing occurs after 72 hours, it must include reasons for the delay.

How is a breach notified in Romania?

The ANSPDCP maintains a dedicated personal data breach notification page with access to its online form. Before submission, the company should identify the correct controller, confirm whether the incident also affects other group entities or joint controllers, and determine whether the ANSPDCP is the competent or lead supervisory authority for any cross-border processing.

The notification should be consistent with the internal breach register, technical evidence, communications plan and any supplemental filing. A company should not understate confirmed facts, speculate beyond the evidence or present an incomplete notification as final.

Enforcement point: the ANSPDCP has publicly reported sanctions for failure to notify a personal data breach within the 72-hour period. Breach-notification obligations under Articles 33 and 34 also fall within the GDPR administrative-fine tier of up to EUR 10 million or, for an undertaking, up to 2% of total worldwide annual turnover for the preceding financial year, whichever is higher. The actual measure depends on the Article 83 assessment and the circumstances of the case.

Who should be involved in the response?

A data breach cannot be handled by IT alone. The legal assessment depends on verified technical facts, while technical containment must preserve evidence and avoid creating inconsistent records. A small decision team should be activated immediately, with clear authority and one incident chronology.

Response team
Four connected workstreams

Select a workstream to see its principal responsibility. All teams should work from the same verified timeline.

Security and IT

Contain the incident, preserve logs and forensic evidence, confirm affected systems and data, remove persistence, restore safely and record every material action.

  • Security and IT: containment, forensic preservation, affected-system analysis, eradication, recovery and evidence of technical safeguards.
  • DPO and legal counsel: awareness timestamp, controller or processor status, risk assessment, authority competence, notification drafting and privilege strategy where applicable.
  • Management and communications: decision authority, resources, operational continuity, messaging and escalation to insurers or relevant corporate bodies.
  • Processors and vendors: incident facts, contractual notification, audit cooperation, subprocessor information and coordinated remedial action.

What is the difference between a controller and a processor?

The controller decides why and how personal data are processed and carries the Article 33 duty to notify the competent supervisory authority. A processor must notify the controller without undue delay after becoming aware of a personal data breach. GDPR does not give processors a separate 72-hour period for notifying the controller.

Data processing agreements should therefore establish an immediate escalation channel, minimum incident information, continuous updates, preservation duties and cooperation with notifications and communications. A processor’s delayed or incomplete report does not remove the controller’s obligation once the controller becomes aware.

RolePrimary breach dutyContractual control
ControllerAssess risk, document every breach, notify the competent authority where required and communicate with individuals where high risk is likely.Maintain response governance and require processors to provide prompt, usable incident information.
ProcessorNotify the controller without undue delay and assist with the controller’s Article 32–36 obligations.Define rapid reporting, evidence preservation, subprocessor escalation, investigation access and update frequency.
Joint controllersAllocate responsibilities transparently, while each remains accountable for the GDPR obligations applicable to it.Agree in advance who leads investigation, authority contact and data-subject communication.

Vendor and technology contracts should be reviewed before an incident occurs. Our IT law services in Romania cover data-processing terms, security obligations, audit rights and incident-response clauses.

When must affected individuals be informed?

Under Article 34, the controller must communicate the breach to affected individuals without undue delay when it is likely to result in a high risk to their rights and freedoms. This obligation is separate from the 72-hour authority-notification rule. The communication must use clear and plain language and explain the nature of the breach, the contact point, likely consequences and measures taken or proposed.

Communication is not required when one of the Article 34(3) conditions applies:

  • appropriate protection measures applied to the affected data and made them unintelligible to unauthorised persons, such as effective encryption;
  • subsequent measures ensure that the high risk is no longer likely to materialise; or
  • individual communication would involve disproportionate effort, in which case a public communication or similarly effective measure is required.

The message should help people protect themselves. Depending on the incident, practical steps may include changing credentials, enabling multi-factor authentication, contacting a bank, monitoring accounts, watching for targeted phishing or using a dedicated support contact. Avoid minimising the event or overwhelming recipients with technical detail.

How should breach risk be assessed?

The legal threshold concerns risk to people, not only damage to the company. Business interruption, contractual liability and reputational harm matter to the response, but they do not replace the individual-rights analysis required by Articles 33 and 34.

Breach risk map
Where can harm materialise?

Select a risk area to review typical consequences. More than one area may apply to the same incident.

Identity fraud and impersonation

Identification data, credentials, signatures or financial information may enable account takeover, fraudulent transactions or convincing social-engineering attacks.

High-risk indicators include sensitive or criminal-offence data, authentication credentials, detailed financial or identity information, data concerning children or other vulnerable people, large-scale exposure, malicious exfiltration, weak safeguards and consequences that are difficult for individuals to reverse. Effective encryption, rapid verified retrieval from a trusted recipient and prompt credential revocation may reduce risk, but each control must be tested against the facts.

What evidence and documentation should be preserved?

Article 33(5) requires the controller to document every personal data breach, including the facts, effects and remedial action. The record must allow the supervisory authority to verify compliance. A defensible incident file should include:

  • the original alert, detection data and a precise incident chronology;
  • the awareness timestamp and the facts supporting it;
  • affected systems, processing activities, data categories, people and record estimates;
  • logs, forensic images, access records, emails, vendor reports and chain-of-custody information where relevant;
  • containment, eradication, recovery and mitigation actions;
  • the risk and high-risk assessments, including reasons and assumptions;
  • the decision to notify or not notify, approvals and any delay explanation;
  • copies of the initial and supplemental ANSPDCP filings;
  • data-subject communications or the documented Article 34 exception; and
  • post-incident findings, corrective actions and responsibility for completion.

Records should distinguish confirmed facts from estimates and hypotheses. The company should also consider cybersecurity, contractual and insurance requirements, DORA and other sector-specific reporting duties, and criminal-law reporting duties. These may use different thresholds and deadlines from GDPR.

A practical 72-hour response checklist

  1. Activate the incident team. Establish one decision lead, secure communications and a contemporaneous chronology.
  2. Contain without destroying evidence. Isolate affected resources, revoke compromised access and preserve logs and forensic material.
  3. Confirm whether personal data are involved. Identify the controller, processor, systems, processing activities and data flows.
  4. Record the awareness timestamp. Explain when reasonable certainty was reached and what facts supported it.
  5. Map the scope. Identify data categories, affected people, approximate record volumes, jurisdictions and vulnerable groups.
  6. Assess risk to individuals. Analyse likelihood, severity, safeguards, realistic misuse and reversibility of harm.
  7. Decide on authority notification. Notify unless the breach is unlikely to create risk. Use phased notification if necessary.
  8. Assess high risk separately. Decide whether individuals must be informed and prepare clear protective guidance.
  9. Coordinate other duties. Review processors, insurers, contractual partners, cybersecurity rules and sector regulators.
  10. Continue and close the response. Supplement filings, verify recovery, complete remediation and retain the breach record.

For a broader preventive review, use our GDPR compliance checklist for Romanian companies. Even though the checklist was published earlier, the core governance controls remain relevant and should be checked against current processing and security practices.

Frequently asked questions

Does the 72-hour period start when IT sees the first suspicious alert?

Not necessarily. The EDPB treats a controller as aware when it has a reasonable degree of certainty that a security incident occurred and compromised personal data. A short initial investigation may establish whether a breach occurred, but it must begin promptly and cannot be used to delay awareness artificially.

Must every ransomware incident be notified to the ANSPDCP?

Not automatically, but ransomware often creates availability, integrity and possibly confidentiality risks. The controller must determine whether personal data were affected, whether exfiltration or unauthorised access occurred, whether reliable backups exist and what consequences are likely for individuals. The conclusion and supporting facts must be documented.

Is an email sent to the wrong recipient a reportable breach?

It is normally a confidentiality breach if personal data were disclosed without authorisation. Whether ANSPDCP notification is required depends on the risk assessment, including the data involved, recipient, ability to retrieve or delete the message, evidence of access and possible consequences. The incident must still be recorded internally.

Can a company notify before the investigation is complete?

Yes. Article 33 permits phased notification when all required information cannot be provided at the same time. The initial notification should contain the available facts and make clear what remains under investigation. Additional information must be supplied without undue further delay.

Does a processor notify the ANSPDCP directly?

The processor’s express Article 33 duty is to notify the controller without undue delay. The controller assesses and makes the supervisory-authority notification. Separate duties may arise from the processor’s own role in other processing, contractual arrangements, cross-border circumstances or sector-specific law.

Must affected people always be informed?

No. Direct communication is required when the breach is likely to result in a high risk, unless an Article 34(3) exception applies. Authority notification uses the lower threshold of likely risk. A breach may therefore require ANSPDCP notification without requiring direct communication to individuals.

What happens if the 72-hour deadline is missed?

The company should notify without further delay and explain why the filing is late. A missed deadline does not remove the notification obligation. The authority may consider the delay, cooperation, mitigation, severity and other Article 83 factors when deciding on corrective measures or a fine.

Need urgent advice on a GDPR data breach in Romania?

We help companies assess notification thresholds, prepare ANSPDCP filings, coordinate processor responses and draft communications to affected individuals.

Book a consultation

Legal disclaimer: This article provides general information and does not constitute legal advice. The applicable response depends on the facts, the company’s role, the data and individuals affected, the competent authority and any sector-specific obligations. Obtain advice for the specific incident.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Open office door representing employee dismissal and professional transition in Romania

Employee Dismissal in Romania: Employer Guide

Employee dismissal in Romania is lawful only when the employer relies on a ground recognised by the Labour Code and follows the procedure attached to that specific ground. A genuine business reason is not enough if the required notice, investigation, evaluation, consultation or written decision is defective.

What Romanian employers should know:

  • First identify the correct termination route; dismissal is only one way an employment contract may end.
  • Match the evidence and procedure to the legal ground before communicating a decision.
  • A minimum 20-working-day notice applies to certain dismissals, not to every dismissal.
  • Procedural breaches can lead to absolute nullity, salary compensation and, if requested, reinstatement.
  • The employer normally carries the burden of proving the legality and factual basis of the measure in court.

This guide is intended for Romanian companies, foreign investors, HR teams and managers considering an individual or collective dismissal. It reflects the structure of the Romanian Labour Code and highlights the points that most often create litigation risk. For advice on a particular case, see our Romanian employment law services.

Employment dismissal documents reviewed in a Romanian corporate office
A defensible dismissal decision begins with the correct legal ground, evidence and procedure.

Is every employment termination a dismissal?

No. Under Article 58 of the Romanian Labour Code, dismissal is the termination of an individual employment contract at the employer’s initiative. It may be based on reasons related to the employee or on reasons unrelated to the employee.

Dismissal should not be confused with termination by mutual agreement, resignation, expiry of a fixed-term contract, termination by operation of law or written termination during or at the end of a probationary period under Article 31(3). Termination during the probationary period is a distinct mechanism, separate from dismissal. Each route has different conditions. Relabelling a unilateral dismissal as a “mutual termination” does not make it consensual; genuine agreement must exist.

Practical point: decide the legal route before drafting documents. Mixing several grounds in one decision, or changing the ground after litigation begins, can undermine the defence.

Route selector
Choose the correct termination route

Select a route to see its legal character. The route must be identified before documents are drafted.

Dismissal

Employer-initiated termination under Article 58. It requires a statutory ground and the procedure attached to that ground.

Legal grounds for employee dismissal in Romania

The main grounds are divided between reasons related to the employee and reasons unrelated to the employee. The required evidence and procedure differ substantially.

GroundCore legal testKey procedural safeguard
Disciplinary misconductA serious breach or repeated breaches of work discipline, the employment contract, collective agreement, internal regulations or lawful managerial orders.Prior disciplinary investigation, except for a written warning.
Preventive arrest or house arrestThe measure lasts for more than 30 days, under the conditions of the Criminal Procedure Code.Written and reasoned decision within the applicable statutory period.
Medical unfitnessPhysical or mental unfitness is established by a decision of the competent medical bodies.Consideration and offer of compatible vacant positions under Article 64.
Professional inadequacyThe employee is professionally unfit for the position held.Prior evaluation under the procedure in the applicable collective agreement or internal regulation, plus Article 64 vacancy steps.
RedundancyThe position is effectively eliminated for a real and serious cause unrelated to the employee.Documented reorganisation and at least 20 working days’ notice; collective rules may also apply.

When is dismissal prohibited?

Before any employee dismissal in Romania, the employer should check both Articles 59 and 60 of the Labour Code. Article 59 prohibits dismissal on protected grounds, including protected characteristics, trade-union membership or activity, lawful participation in a strike and the exercise of specified employment rights. Article 60 creates temporary prohibitions during specified periods, including certified temporary incapacity for work, quarantine, maternity leave, parental leave, leave to care for a sick child, annual leave, paternity leave, caregiver leave and certain emergency family absences. A pregnant employee is protected if the employer knew of the pregnancy before issuing the decision. Separate anti-discrimination and retaliation rules may also apply under Law no. 202/2002 and the Whistleblower Protection Law no. 361/2022.

The protected-period analysis should be made immediately before the dismissal decision is issued and communicated. Article 60 also contains an exception linked to judicial reorganisation, bankruptcy and dissolution of the employer, but it should be applied only after checking the employer’s precise legal status and the special insolvency rules.

Does every dismissed employee receive 20 working days’ notice?

No. Article 75 grants a minimum notice period of 20 working days for dismissal due to medical unfitness, professional inadequacy and redundancy under Articles 65 and 66. It does not create a universal notice period for every type of dismissal. In particular, disciplinary dismissal does not carry the same statutory notice entitlement.

The notice period and its start date should be documented clearly. Employers should not assume that paying an equivalent amount automatically remedies a failure to observe the statutory notice period. If the parties want a negotiated exit with compensation, that should be structured separately as a genuine mutual termination agreement.

How does disciplinary dismissal work?

Employee dismissal in Romania based on misconduct is the most procedure-sensitive route. Before imposing it, the employer must ordinarily conduct the prior disciplinary investigation regulated by Article 251. The process should include a written summons specifying the subject, date, time and place of the meeting, a real opportunity for the employee to present explanations and evidence, and a documented assessment of the defence.

The sanction must also be proportionate. Article 250 requires the employer to consider factors such as the circumstances of the misconduct, degree of fault, consequences, the employee’s general conduct and any previous disciplinary sanctions. A finding that misconduct occurred does not automatically justify dismissal if a lesser sanction is proportionate.

The disciplinary decision must be issued in writing within 30 calendar days from the date the employer became aware of the misconduct, but no later than six months from the date of the act. It must contain all mandatory elements under Article 252 and be communicated within five calendar days of issue. Read our dedicated guide to the disciplinary procedure in Romania.

Evidence that usually matters

  • the internal regulation, policies and lawful instructions allegedly breached;
  • proof that the employee received or could access those rules;
  • emails, access logs, reports, witness statements or other lawfully obtained evidence;
  • the summons, interview record, employee’s written defence and supporting documents;
  • a reasoned proportionality assessment; and
  • proof of issuing and communicating the final decision within the statutory periods.

How should professional inadequacy be documented?

Professional inadequacy concerns the employee’s ability to meet the professional requirements of the role; it is not a disciplinary accusation. Article 61(d) provides the legal ground for dismissal, while Article 63(2) requires the employee to undergo a prior evaluation under the procedure established by the applicable collective labour agreement or, in its absence, the internal regulation.

The evaluation should rely on objective, role-related standards communicated in advance. The job description, performance objectives, prior reviews, training records and concrete work results should tell a consistent story. A hastily created evaluation standard or a process designed around one predetermined outcome is vulnerable to challenge.

Before dismissal, Article 64 requires the employer to offer available positions compatible with the employee’s professional training or, where relevant, work capacity. If no suitable vacancy exists, the employer must seek the support of the territorial employment agency. The employee has three working days to express written consent to an offered position.

What is required for medical-unfitness dismissal?

Medical unfitness under Article 61(c) cannot rest on a manager’s impression or an ordinary performance assessment. It must be established through a decision of the competent medical bodies. The employer must then follow the compatible-vacancy process under Article 64 and grant the minimum statutory notice.

This ground should also be kept distinct from disability discrimination and reasonable workplace accommodation issues. Medical information must be handled with particular attention to confidentiality and data-protection requirements.

When is redundancy lawful?

Employee dismissal in Romania for redundancy is governed principally by Article 65. It is lawful when the employee’s position is effectively eliminated and the elimination has a real and serious cause unrelated to that employee. The employer does not have to prove that dismissal was the only imaginable business choice, but it should be able to show that the reorganisation is genuine and that the eliminated role no longer exists in substance.

A defensible file commonly includes the competent corporate decision, the business rationale, organisational charts before and after implementation, the updated headcount and job descriptions, financial or operational supporting material where relevant, and evidence that the employee’s duties were genuinely removed or redistributed.

A changed job title alone is not decisive. Courts can examine whether a supposedly eliminated position continues in substance or is promptly refilled under a different label.

Where only some identical or comparable positions are removed, the selection issue requires particular care. In Decision no. 30/2020, the High Court declined to rule on the merits and dismissed the recurs în interesul legii as inadmissible. It held that the question concerned applying the law to specific facts rather than resolving a genuine issue of legal interpretation. The decision therefore did not unify the divergent lower-court approaches described in the referral on whether selection criteria are required when an employer eliminates only some positions from a group of identical or similar positions. As a risk-management measure, any criteria used should be objective, consistently applied and supported by evidence.

Employers planning a broader reorganisation may also consult our guide to employee rights during company restructuring in Romania.

When do collective-dismissal rules apply?

A redundancy programme can become a collective dismissal if, within a period of 30 calendar days, the statutory thresholds in Article 68 are reached.

Employer workforceCollective-dismissal threshold within 30 calendar days
More than 20 and fewer than 100 employeesAt least 10 employees
100–299 employeesAt least 10% of employees
300 or more employeesAt least 30 employees
Live threshold check
Collective dismissal threshold check

Enter the employer’s total workforce and the dismissals planned within 30 calendar days.

Enter both figures, then select “Check threshold”.

This is a preliminary numerical check. Article 68 aggregation and the treatment of other employer-initiated terminations must still be reviewed.

For threshold calculations, certain other employer-initiated terminations for reasons unrelated to the employee may also be counted when the statutory conditions are met. Fragmenting one programme into several documents or dates does not necessarily prevent the collective rules from applying.

The employer must begin consultations with the trade union or employee representatives in good time, provide the written information required by Article 69 and genuinely examine ways to avoid or reduce dismissals and mitigate their consequences. If the programme proceeds, the territorial labour inspectorate and territorial employment agency must receive the statutory notification at least 30 calendar days before dismissal decisions are issued, subject to the detailed Labour Code procedure.

What must the written dismissal decision contain?

The applicable deadline and the mandatory content should be analysed separately. Article 62 establishes the deadline for issuing decisions based on Article 61(b)–(d) and also requires the decision to state its factual and legal reasons, the challenge period and the competent court. Article 76 sets out the other mandatory elements applicable to dismissal decisions, while Article 252 contains the specific requirements for disciplinary decisions. Depending on the case, the written decision should include:

  • the factual and legal reasons for dismissal;
  • the duration of the notice period, where applicable;
  • the collective-dismissal selection criteria, where applicable;
  • the list of available positions and the Article 64 response period, where applicable;
  • for a disciplinary sanction, the mandatory elements in Article 252, including why the employee’s defence was rejected; and
  • the statutory challenge period and competent court, where required.

The decision produces effects from communication to the employee. Communication should therefore be provable. The employer cannot ordinarily defend the case by introducing new dismissal reasons that were absent from the decision.

What are the main employer risks if the dismissal is unlawful?

A failure to comply with the legally required procedure results in absolute nullity under Article 78. Under Article 80, if the court cancels the dismissal, it orders compensation equal to the indexed, increased and updated salaries and the other entitlements the employee would have received. At the employee’s request, the court also restores the parties to the position existing before dismissal by ordering reinstatement.

Employment disputes move quickly and the employer bears the burden of proof under Article 272. A disciplinary decision may be challenged within 30 calendar days of communication under Article 252(5). For most other dismissal-related employment disputes, employees generally have 45 calendar days to challenge the measure under Article 268, calculated from the date on which the person concerned became aware of it, subject to the specific provisions applicable to the type of claim.

Risk map
Employer risk map

Select a consequence to see where the principal exposure arises.

Nullity

A dismissal ordered without observing the statutory procedure is affected by absolute nullity under Article 78.

Additional exposure may arise from discrimination, whistleblower retaliation, unpaid rights, data-protection violations, collective consultation failures or inconsistent treatment of comparable employees.

A practical pre-dismissal checklist for employers

Legal roadmap
Pre-dismissal legal roadmap

Select each step to review the purpose of the control before moving forward.

Legal ground

Identify the exact statutory route first. The evidence, notice and procedure depend on this classification.

  1. Identify the legal route. Confirm whether the case is dismissal, mutual agreement, resignation, expiry, probationary termination or another statutory form.
  2. Check protected status. Verify leave, medical incapacity, pregnancy notifications, representative status, whistleblowing and discrimination risks.
  3. Confirm decision-making authority. Make sure the correct corporate or managerial body approves the measure.
  4. Audit governing documents. Review the employment contract, job description, internal regulation, policies and collective agreement.
  5. Build the evidence file. Preserve documents lawfully and avoid post-hoc rationales.
  6. Run the ground-specific procedure. Investigation, professional evaluation, medical decision, vacancy search or reorganisation documentation cannot be interchanged.
  7. Check collective thresholds. Look at the complete 30-day programme, not only one employee or one department.
  8. Calculate notice correctly. Apply it only where legally required, but do not shorten it.
  9. Draft and quality-check the decision. Confirm every mandatory element, factual statement, date and attachment.
  10. Plan communication and litigation readiness. Retain proof of delivery and a complete, chronological file.

If employment status itself is uncertain, first review our analysis of employee versus contractor risks in Romania. For prevention at the hiring stage, see our guidance on employment contracts in Romania.

Frequently asked questions

Can an employee be dismissed while on sick leave?

As a rule, dismissal cannot be ordered during certified temporary incapacity for work. The employer should verify the medical certificate and the timing of both issuance and communication of the decision. The Labour Code contains a limited exception linked to judicial reorganisation, bankruptcy or dissolution.

Is 20 working days’ notice required for every dismissal?

No. The statutory minimum applies to dismissal for medical unfitness, professional inadequacy and redundancy under Articles 65 and 66. It does not generally apply to disciplinary dismissal.

Can the employer pay salary instead of granting notice?

The Labour Code grants a working notice period in the situations covered by Article 75. An employer should not assume that unilateral payment cures failure to grant it. A separately negotiated mutual termination may include compensation, but it must reflect genuine consent and should be documented accordingly.

Is severance pay mandatory in Romania?

There is no universal statutory severance amount for every redundancy. Article 67 states that affected employees may benefit from compensation under the law and the applicable collective labour agreement. The employment contract, internal policies and established practice should also be checked.

Can an employer eliminate a position and later hire someone else?

Hiring for a materially similar role soon after dismissal may suggest that the original elimination was not effective. The legal assessment turns on substance: duties, organisational need, timing and evidence—not the title alone.

How long does an employee have to challenge dismissal?

A disciplinary sanction may be challenged within 30 calendar days from communication. For other unilateral measures concerning termination, the Labour Code generally provides 45 calendar days from the date the employee became aware of the measure. Case-specific verification is advisable.

Planning or defending employee dismissal in Romania?

We assist employers with dismissal strategy, disciplinary investigations, performance procedures, redundancy documentation, collective consultation and employment litigation.

Discuss the case with a Romanian employment lawyer

Disclaimer: This article provides general information and does not constitute legal advice. The correct procedure depends on the dismissal ground, employment documents, employee status and facts of the case.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Corporate buildings connected by a glass bridge, symbolising solutions to shareholder deadlock in Romania

Shareholder Deadlock in Romania: Exit and Remedies

Corporate governance · Romania

Shareholder Deadlock in Romania: Exit and Remedies

A shareholder deadlock can stop budgets, appointments, financing, contracts and an eventual sale. This guide explains how Romanian shareholders and foreign investors can define the deadlock, preserve ordinary operations, escalate the dispute and use a negotiated or statutory exit route.

The correct response depends on the company type, articles of association, shareholder agreement, voting structure, conduct and remedy sought. The current version of Law no. 31/1990 and the company’s documents should be checked before action.

In short: equal ownership does not automatically mean that a Romanian company is deadlocked. The practical problem arises when a required decision cannot be validly adopted and the failure materially affects the company. The safest response is usually a staged mechanism: define the blocked decision, protect essential operations, escalate, attempt an appropriate form of resolution and preserve any court or exit remedy.

What happens when Romanian shareholders can no longer make decisions?

A deadlock is a governance problem before it becomes a lawsuit. The company may be unable to approve a budget, appoint a manager, authorise financing, sign a material contract or decide whether to sell. The first task is to identify the exact decision that is blocked and the rule that prevents it from being adopted.

A disagreement about strategy is not automatically a legal deadlock. The issue becomes more serious when the required majority, unanimity or joint-signature rule cannot be reached, the dispute continues after a properly convened meeting and the company’s operations are materially affected. A minority investor with a veto may create the same practical risk as two 50/50 shareholders.

Decision blocked

Identify the resolution, voting threshold, quorum, notice and evidence of the failed decision.

Business exposed

Protect payroll, taxes, essential suppliers, insurance, records and ordinary-course activity while the dispute is addressed.

Exit required

Use escalation, mediation, expert determination, buy-sell, transfer, withdrawal or dissolution only where the facts support it.

Important: a shareholder should not assume that stopping all company activity creates negotiating leverage. Directors and administrators still have duties to the company, and emergency or compliance decisions may need to continue.

How should a shareholder diagnose the deadlock?

The diagnosis should compare four documents and four realities: the articles of association, any shareholders’ agreement, the mandates and signing authorities, and the company’s actual governance practice. A private agreement may create obligations between shareholders, but it does not automatically replace the constitutional rules that operate through the company.

Select the point that determines the next governance decision.

Define the blockage

Record the decision that failed, the meeting notice, votes cast, applicable threshold and the operational consequence for the company.

Diagnostic questionWhat to reviewWhy it mattersImmediate control
What decision is blocked?Agenda, minutes, written refusals, voting record and company impact.Separates a material deadlock from an ordinary disagreement.Send a written notice identifying the decision and the consequence.
Which rule applies?Articles, shareholder agreement, Law no. 31/1990 and signing mandates.A private veto may not operate like a statutory voting rule.Map the legal effect of the rule before threatening a remedy.
Can ordinary activity continue?Last approved budget, administrator powers, bank instructions and compliance deadlines.Prevents the dispute from unnecessarily damaging the business.Define essential expenditure and information access while escalation runs.
What is the desired outcome?Continuation, buyout, sale, mediation, court remedy or dissolution.Different outcomes require different documents, evidence and timetables.Select a route proportionate to value, urgency and relationship.

Why must the shareholders’ agreement match the articles of association?

A shareholders’ agreement is normally a private contract between its parties. The articles of association are the company’s constitutional document and contain rules that function through the corporate structure. If the agreement promises a veto but the articles allow the resolution to pass by a lower majority, a shareholder may have a contractual claim without being able to stop the corporate resolution.

For a Romanian SRL, Article 192 of Law no. 31/1990 provides default rules on the majority required for decisions, subject to the statutory framework and the articles. Article 193 addresses voting through social parts. Where capital parity prevents an absolute majority from being established, Article 7(d¹) should be considered when drafting the method for adopting general-meeting resolutions with the participation and vote of all shareholders.

The documents should be coordinated on quorum, notice, voting thresholds, administrator powers, joint-signature rules, reserved matters, transfer restrictions and the treatment of a failed vote. The agreement can contain confidential commercial mechanics, but the corporate rules needed to operate the company should be reflected in the articles and, where required, in registered information.

Articles

Set the constitutional voting and governance rules that operate through the Romanian company.

Shareholder agreement

Add private obligations, escalation steps, information rights, valuation and exit mechanics.

Mandates

Make sure administrator powers and signing authorities do not contradict the agreed decision structure.

How should reserved matters and veto rights be drafted?

Reserved matters protect investors from fundamental changes, but an excessive list can turn normal management into permanent negotiation. Each matter should have a clear financial or strategic threshold, an approval level, a decision-maker and a timetable. The drafting should distinguish shareholder matters from administrator or management matters.

The agreement should state whether consent may be withheld freely or only for specified reasons. It should also explain what happens when a meeting fails, when information is missing, when one shareholder does not attend and when the same proposal is rejected more than once. Silence should not accidentally authorise a major transaction, but it should not paralyse routine activity either.

ClausePurposeDrafting controlDeadlock consequence
Deadlock definitionIdentifies when the process begins.Use material matters, repeated failed votes and written notice.Starts the agreed escalation timetable.
EscalationMoves the issue beyond the original negotiators.Name decision-makers, documents and realistic deadlines.Creates a final internal opportunity to resolve the issue.
Interim operationsKeeps the company functioning.Continue the last approved budget and essential compliance activity.Limits value destruction while the dispute continues.
Buy-sell mechanismAllows one shareholder to acquire the other’s interest.Define price, funding evidence, completion and default.Creates a controlled exit instead of indefinite blockage.
Final remedyEnds an unresolved dispute.Coordinate contractual sequence with statutory rights.Use court dissolution only as a genuine last resort.

What escalation process should come first?

A workable process usually begins with a written deadlock notice. The notice should identify the decision, the failed vote, the relevant documents, the operational risk and the proposed date for a second meeting. It should avoid inflammatory language and should preserve the shareholder’s position without treating every negotiation statement as an admission.

The next stage may involve senior representatives of the shareholder groups who were not involved in daily management. Mediation can help where the dispute concerns valuation, business strategy or loss of trust. Expert determination is more suitable for a discrete accounting, technical or valuation question. The agreement should define the scope of each process and the effect of the decision.

A cooling-off period may be useful, but it should not be so long that it allows statutory challenge periods, financing deadlines or insolvency risks to expire. Information rights, confidentiality and interim access to company records should remain clear throughout the process.

Select the preferred outcome to see the main control.

Continue together

Restore decision-making with a documented escalation, revised mandates, clearer reserved matters and an agreed interim operating plan.

How can the company operate during the deadlock?

A deadlock clause should not become a licence to stop salaries, taxes, insurance, essential supplies or compliance filings. The parties should identify what can continue under the last approved budget and what requires a fresh shareholder decision. Emergency expenditure should be narrowly defined and documented.

Shareholders should preserve access to accounts, records and management information. Neither party should divert customers, employees, intellectual property or corporate opportunities while the exit process is pending. A director or administrator must continue to act within the duties owed to the company. A shareholder instruction does not legalise conduct that breaches mandatory law or harms the company.

The practical protocol should cover bank access, payment approvals, payroll, tax filings, customer communication, data security, insurance, licences and the retention of corporate records. If the company has two administrators who must sign jointly, the parties should check whether that arrangement itself is causing the standstill and whether a lawful adjustment is possible.

Which buy-sell mechanisms can resolve a deadlock?

A buy-sell mechanism can produce a clean exit, but labels such as “Russian roulette” or “Texas shoot-out” are not enough. The clause must explain who may start the process, whether the initiating shareholder offers to buy or sell, how a price is determined and what happens if the other party cannot complete.

These mechanisms may disadvantage a shareholder with less access to financing. Safeguards can include evidence of funds, a minimum price, independent valuation, a reasonable completion period and restrictions on using confidential company information to finance the acquisition. The agreement should address shareholder loans, guarantees, accrued dividends, management positions, releases and the transfer of company property or intellectual property.

For an SRL, transfer restrictions must also be reviewed under Law no. 31/1990 and the articles. Transfers between existing shareholders and transfers to an outsider may be subject to different approval rules. The transfer should be coordinated with the shareholders’ register, the Trade Register filing and any update to beneficial-owner information or regulatory analysis required by the transaction.

What legal remedies exist when there is no workable clause?

The available remedy depends on the company type, the conduct and the relief sought. A shareholder may challenge an unlawful corporate resolution under the applicable company-law rules, but strict procedural periods can apply. The shareholder should preserve the minutes, notices, voting record, documents and evidence of the company’s operational impact before negotiations are allowed to drift.

For an SRL, Article 226 of Law no. 31/1990 may permit withdrawal in the cases stated in the articles, with the agreement of the other shareholders or, where agreement is absent, for serious grounds established by the tribunal. The value of the withdrawing shareholder’s rights may require agreement, expert work or court determination.

Exclusion is not a general cure for deadlock. Article 222 contains specific statutory situations and should not be treated as a broad remedy for an unpleasant or uncooperative shareholder. A company cannot simply exclude a shareholder because negotiations have failed.

Judicial dissolution under Article 227(1)(e) may be available for serious reasons, including grave disagreements that prevent the company from functioning. Dissolution destroys the going-concern investment and may reduce value, so it should normally remain the last remedy after contractual and commercial solutions have been assessed. It is not a substitute for drafting a workable exit clause.

Should a deadlock dispute go to court or arbitration?

Arbitration may offer confidentiality, specialist decision-makers and procedural flexibility, especially in a cross-border investment. The clause must identify the institution or ad hoc rules, seat, language, number of arbitrators and governing law. It should also address urgent relief, interim measures and the relationship with the company and other transaction documents.

Not every corporate issue can be solved only between the contracting shareholders. Some resolutions, registrations or remedies affect the company and require statutory procedures or Trade Register steps. A dispute clause should distinguish contractual claims from company-law remedies and ensure that the company is bound where that is legally possible and commercially intended.

Before filing, compare the value of the investment, the urgency, the evidence, the effect on the business, the available interim relief and the likelihood that a judgment or award can be implemented. Litigation or arbitration can resolve a legal question, but it may not restore the commercial relationship. A negotiated buyout can sometimes preserve more value than a technically successful dissolution claim.

Pre-signing shareholder deadlock checklist

  • Identify decisions that require shareholder approval, administrator approval or joint signatures.
  • Define deadlock by reference to material matters, repeated failed votes and written notice.
  • Coordinate the articles of association, shareholders’ agreement, mandates and registered information.
  • Set realistic escalation steps and name the people who must participate.
  • Protect ordinary-course operations, payroll, taxes, insurance, records and essential contracts.
  • Choose mediation, expert determination or a buy-sell process for the type of dispute it can actually resolve.
  • Define valuation date, methodology, adjustments, discounts, expert appointment and cost allocation.
  • Address transfer restrictions, pre-emption, tag-along, drag-along and Trade Register formalities.
  • Require funding evidence and completion documents for any buyout mechanism.
  • Preserve statutory challenge periods and do not let negotiation remove the right to seek urgent relief.

Frequently asked questions

Is a 50/50 Romanian company automatically deadlocked?

No. Equal ownership creates structural risk, but deadlock exists only when a required decision cannot be adopted and the failure materially affects the company. The articles and shareholder agreement should address parity, governance and exit mechanics.

Can one shareholder force the other to sell?

Only if a valid contractual or statutory mechanism permits it and its conditions are satisfied. A buy-sell clause must address price, funding, completion, transfer formalities and default consequences.

Can a shareholder be excluded simply for causing deadlock?

Not automatically. Exclusion is governed by specific statutory situations and cannot be used as a general remedy merely because the shareholders disagree or negotiations have failed.

Can a shareholder withdraw from a Romanian SRL?

Withdrawal may be available under Article 226 of Law no. 31/1990 in the cases stated in the articles, with the required agreement or, in the absence of agreement, for serious grounds established by the tribunal.

Can shareholder deadlock lead to dissolution?

Yes, judicial dissolution may be available for serious reasons, including grave disagreements that prevent the company from functioning. It is a last-resort remedy because it may destroy going-concern value.

Should the deadlock clause appear in both documents?

Critical voting, governance and registered transfer rules should be coordinated with the articles of association and mandates. Private commercial details may remain in the shareholders’ agreement, subject to enforceability and confidentiality analysis.

Need a Romanian deadlock clause or exit strategy?

A focused review can align the articles, shareholder agreement, voting structure, interim protections, valuation process and available remedies.

Book a consultation

Disclaimer: This article provides general information only and does not constitute legal advice or the creation of a lawyer-client relationship. The correct approach depends on the company type, constitutional documents, shareholder agreement, facts, evidence and remedies sought. Obtain a case-specific assessment before taking corporate or litigation steps.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.

Mountain cottage representing real estate due diligence in Romania

Real Estate Due Diligence in Romania: Buyer Checklist

What does real estate due diligence in Romania cover?

The review should answer whether the seller can transfer the asset, whether the registered asset matches what the buyer inspected, whether it can lawfully be used as intended and whether the contract protects the buyer if a risk is not resolved.

Buyer control panel
From property listing to safe signing

Select a control point to see what should be established before the buyer moves to the next decision.

Define the exact asset

List every cadastral unit and accessory right: apartment, house, land, parking space, storage area, access route and any share in common parts.

01 · Title

Can the seller transfer?

Check ownership, authority, historical title, mortgages, seizures, disputes, easements and pre-emption rights before accepting the seller’s timetable.

02 · Asset

Is the asset correctly described?

Reconcile the Land Registry, cadastral plan, contract, measurements and physical inspection so the buyer receives the complete commercial package.

03 · Use

Can the buyer use it as intended?

Separate ownership from planning, construction, fire-safety, access, utility and activity-specific authorisation questions.

04 · Remedy

What happens if a risk remains?

Choose a proportionate response: correction before signing, condition precedent, retention, escrow, warranty, indemnity, price adjustment or withdrawal.

Buying property in Romania creates risk before the final sale agreement is signed. A reservation payment or pre-contract can already restrict the buyer’s options, particularly if the refund clause is weak or the property is described only by its marketing name. A focused review should begin while the buyer can still require documents, renegotiate or withdraw without losing a substantial deposit.

Layered architectural view representing real estate due diligence in Romania
A property transaction is reliable only when its title, cadastral identity, construction history and contractual description align.

This guide focuses on the checks that can change a foreign buyer’s decision. It complements our broader guide to buying property in Romania and the separate explanation of the Romanian Land Registry process.

The scope depends on the asset. An apartment review differs from the acquisition of a house and land, an off-plan unit, agricultural land or commercial premises. The practical starting point is an exact asset list: apartment, parking space, storage area, land share, access rights and every separately registered cadastral unit.

Romania’s system is governed principally by Law no. 7/1996 on cadastre and real-estate publicity. Registered information must be checked against title documents, cadastral plans, construction records, the physical situation and the commercial package promised by the seller.

Is a Land Registry extract enough?

No. A current extract identifies the registered property, owner, rights and burdens, but does not by itself confirm that every construction was authorised, boundaries match occupation, access is legally secured or the intended use is permitted.

The buyer should understand every notation. Mortgages, seizures, litigation, pre-emption rights, easements and prohibitions may affect closing or use. An older copy supplied by an agent is not a substitute for a current extract for the correct cadastral number. The National Agency for Cadastre and Land Registration administers the system.

Historical title documents explain how the seller acquired the asset and whether marital, succession, restitution, authority or earlier-transfer issues require closer examination. See also our guide to property ownership and document verification.

Which title and cadastral checks matter most?

Compare the seller’s identity and capacity with the registered owner, then match the address, cadastral number, surface, category of use, floor plan and boundaries across the Land Registry, cadastral documentation and physical inspection. Differences are not always fatal, but they must be explained before payment.

For houses and land, confirm legal access to the public road, not merely practical access over another property. Review easements, shared roads, utility corridors and maintenance arrangements. For apartments, identify the individual unit and the related share in common parts and land.

CheckEvidencePotential consequence
Seller and titleCurrent extract, acquisition deed, identity or corporate authority, marital or succession documents where relevant.The seller may lack authority or be unable to transfer the full right.
Asset identityCadastral number, plan, measured area, address, floor, boundaries and accessory units.The contract may describe a different or incomplete asset.
BurdensMortgages, seizures, disputes, easements, prohibitions and pre-emption rights.Closing may require releases, creditor cooperation or different payment mechanics.
ConstructionBuilding permit, approved plans, reception records and registration of the completed construction.Unauthorised works may affect use, financing, insurance and resale.
Intended usePlanning rules, registered use, condominium restrictions and approvals.The buyer may own the asset but be unable to use it as planned.
Risk selector
Which finding can change the buyer’s decision?

Select a risk category to see the first response to consider. The final response depends on evidence, value and deal structure.

Title or authority risk

Pause the transaction until the seller’s right and capacity to transfer are evidenced. A price reduction alone may not cure an inability to transfer.

How should construction documents be checked?

The registered existence of a building does not replace a review of how it was authorised, built, received and recorded. The file should show a coherent path from the approved project to the completed property.

Construction works are principally regulated by Law no. 50/1991. The review may include the building permit, approved project, amendments, reception protocol and technical book. Law no. 10/1995 on construction quality provides the wider quality framework.

Alterations inside an apartment also matter. Removed walls, enclosed balconies, changed layouts or combined units may not match approved and cadastral plans. Legal due diligence does not replace a technical survey, structural assessment or measurement by an authorised specialist.

What should be checked for a condominium apartment?

Review both the individual unit and the building-level position: unpaid common expenses, litigation involving the owners’ association, major repairs, special contributions, insurance, common utilities and restrictions affecting use.

Law no. 196/2018 makes the seller’s position with the owners’ association relevant to transfer documentation. Request information about approved or foreseeable works where these may create material cost.

An energy performance certificate is part of transaction documentation in the cases governed by Law no. 372/2005, but it does not replace a technical inspection or assessment of actual utility costs.

Do foreign buyers need an ownership eligibility review?

Yes, whenever land or a land share is included. The treatment of a building should not be assumed to answer the separate question of land ownership.

The route depends on nationality, residence, the asset and applicable treaty or EU rules. Law no. 312/2005 governs land acquisition by foreign citizens, stateless persons and foreign legal entities. Eligibility should be confirmed before a binding pre-contract.

Extravilan agricultural land requires separate analysis because Law no. 17/2014 establishes special conditions and a pre-emption procedure. Our service page on how to buy a property in Romania explains the broader ownership-route question.

How should planning, access and intended use be tested?

Ownership does not guarantee the proposed use. For land, commercial premises or redevelopment, review planning status, building indicators, protected-area constraints, access, utility capacity and approvals specific to the intended activity.

For income-producing property, review leases, deposits, side letters, termination rights, arrears, service charges and whether vacant possession can be delivered. A company acquisition that includes property also requires corporate, tax, contractual and litigation review.

When should a buyer stop, renegotiate or impose conditions?

Not every issue requires withdrawal. Some defects can be corrected before closing; others can be addressed through a price adjustment, retention, escrow, creditor payoff, warranty, indemnity or condition precedent. The response should reflect probability, financial impact and the effect on transfer, use, financing and resale.

Be cautious where title cannot be established, cadastral identity is uncertain, material works lack documentation, legal access is missing, litigation threatens the asset or the contract shifts unresolved risks to the buyer without a workable remedy.

Decision map
What should the buyer do with an unresolved risk?

Select the response that best matches the nature of the finding.

Make it a closing condition

Use a condition precedent or staged closing where the issue can be resolved before transfer and the buyer needs a clear release mechanism.

FindingFirst responseProtection to document
Missing title evidencePause signing or paymentDocument delivery condition and refund right
Mortgage or seizureCoordinate release mechanicsCreditor payoff, release documents and closing sequence
Unclear construction statusObtain records and technical inputCondition precedent, warranty or retention
Access or utility gapVerify legal and practical solutionEasement, infrastructure obligation or price response
Weak deposit clauseRenegotiate before paymentClear repayment triggers and consequences of failed closing

Real estate due diligence in Romania: pre-signing checklist

  1. Confirm buyer eligibility and ownership structure, especially where land is included.
  2. Identify every cadastral unit and accessory right in the commercial deal.
  3. Obtain a current Land Registry extract and review every notation.
  4. Trace the seller’s title and verify capacity and signing authority.
  5. Compare the registered description with the physical property.
  6. Review permits, approved plans, reception records and the technical file.
  7. Check access, utilities, easements and shared infrastructure.
  8. Assess planning status and intended use.
  9. Investigate condominium debts, disputes and planned works.
  10. Align the reservation, pre-contract and final agreement with the findings.
  11. Condition payment and closing on outstanding releases or corrections.
  12. Coordinate legal review with technical, tax, financing and valuation advice.

The bottom line

Real estate due diligence in Romania is a decision process, not a document-collection exercise. The buyer needs a coherent answer about ownership, asset identity, legal use, physical status and contractual protection. The safest time to resolve inconsistencies is before a reservation payment or pre-contract makes withdrawal expensive.

Frequently asked questions

Should due diligence be completed before a reservation agreement?

Ideally, review at least the seller, asset identity, current Land Registry position and refund terms before paying. If the full review cannot be completed, the reservation should preserve withdrawal and repayment rights where essential documents or conditions are unsatisfactory.

Is the notary’s verification the same as buyer due diligence?

No. The notary performs the statutory checks and authentication required for the transaction. The buyer’s lawyer investigates the deal from the buyer’s perspective and negotiates conditions, warranties and payment protections. The roles are complementary.

Can a mortgage be removed at closing?

Potentially, but the release and payment mechanics must be agreed with the creditor, seller and notary. The contract should identify the payoff amount, recipient, release documents and responsibility if registration is delayed.

Does legal due diligence include a structural survey?

No. Legal review examines ownership, registrations, permits, restrictions and transaction documents. A technical specialist should assess structural condition, defects, measurements, installations and construction quality.

Can due diligence continue after a pre-contract is signed?

Yes, but leverage depends on the pre-contract. It should make closing conditional on satisfactory findings and state what happens to the deposit if title, permits, financing or another essential condition fails.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.

\n\n
Geometric maze illustrating contractual risk assessment during a contract review in Romania

Contract Review in Romania: 12 Clauses to Check

Which contract clauses should a business check before signing?

A Romanian business contract should clearly allocate performance, payment, liability, intellectual-property, data and exit risks. These 12 clauses are the practical starting point for a legal and commercial review.

Contract review in Romania should test more than whether an agreement is formally valid. Before signing, a business should understand what it must deliver, when it will be paid, which losses it may bear, how intellectual property and data may be used, and how the relationship can end.

Commercial contracts are often negotiated under pressure. A supplier is ready to begin, a customer wants the final draft immediately, or a foreign group needs its Romanian operation running without delay. That is precisely when unclear wording, inconsistent annexes and borrowed template clauses are most likely to pass unnoticed. Companies entering the market should connect the contract with the wider steps required to start and operate a business in Romania.

Interconnected architectural structure illustrating how contract clauses work together in a Romanian contract review
A well-structured contract depends on interconnected clauses that allocate obligations, remedies and commercial risks consistently.

Under the Romanian Civil Code, a validly concluded contract is binding on the parties, and contractual negotiations and performance are governed by good faith. A useful review therefore connects the legal wording with the operational deal. It identifies which party controls each risk, whether the agreed remedy can work in practice, and what evidence will be needed if performance is disputed.

The following 12 clauses form a practical checklist for Romanian companies and foreign businesses entering agreements governed by Romanian law or involving a Romanian counterparty.

Parties, capacity and signing authority

The contract should identify the correct legal entities, not merely the brand names used in negotiations. For a Romanian company, check its registered name, registered office, Trade Registry number, fiscal identification code and representative. If a group is involved, establish which entity receives the services, issues invoices, owns the relevant assets and assumes liability.

Signing authority should be verified against the company’s constitutional documents, Trade Registry information, corporate approvals or a power of attorney. A signature block describing someone as a “manager” does not itself resolve whether that person may bind the company for the relevant transaction. The representation rules should be checked against the company’s current Romanian articles of incorporation and the registered powers of its administrators.

The internal authority analysis also matters for potential Romanian company director liability, particularly where a director signs outside approved limits or fails to document a material commercial decision.

Check before signingConfirm the contracting entity, the signatory’s authority, any required corporate approval, the position of affiliates and whether subcontracting or assignment to another group company is permitted.

Scope, deliverables and acceptance

The scope clause should describe the goods or services, specifications, quantities, locations, deadlines, dependencies and exclusions. For project work, it should also establish milestones, acceptance tests, correction periods and a change-control procedure.

Review the main agreement together with proposals, statements of work, order forms and technical annexes. If they conflict, an order-of-precedence clause should determine which document controls. Acceptance by silence should also be tested carefully: specify when the review period begins, what constitutes a valid rejection and what happens when defects are minor. Providers using standard customer documentation should also verify the applicable service contract requirements in Romania.

Common riskThe commercial proposal promises one result, the technical annex describes another and the general conditions allow the supplier to treat delivery as accepted before meaningful testing has taken place.

Price, VAT, invoicing and payment

A complete payment clause states the price or calculation method, currency, VAT treatment, invoicing trigger, payment deadline, supporting documents, bank charges and the procedure for disputing an invoice. It should also explain whether the customer may withhold, deduct or set off amounts and whether the supplier may suspend performance for non-payment.

For B2B transactions, Law no. 72/2013 on late payment contains mandatory protections. Article 5(1) establishes a general 60-calendar-day limit for contractual payment terms between professionals. By exception, the parties may agree a longer payment term, provided that the clause is not abusive under Article 12. A term exceeding 60 days is therefore not automatically invalid, but it should be assessed carefully for gross unfairness to the creditor in light of the statutory criteria and the circumstances of the transaction. Where the applicable conditions are met, late payment can trigger statutory penalty interest and the fixed EUR 40 recovery compensation.

For the calculation rules and available remedies, see our guide to late-payment interest and penalties in Romania.

Term, renewal and minimum commitments

The agreement should state its effective date, initial duration and whether it renews automatically. An automatic renewal clause is not necessarily problematic, but the notice window, notice method and effect of a missed deadline must be clear.

Check minimum purchase commitments, exclusivity, take-or-pay obligations and price changes that continue into a renewal term. Add internal calendar reminders for any deadline that determines whether the company remains bound for another year or loses a renegotiation opportunity.

Check before signingIdentify the earliest exit date, the last date for a non-renewal notice and every financial or operational commitment that survives renewal.

Termination, cure periods and exit assistance

The termination clause should distinguish between serious breach, remediable breach, insolvency-related events, prolonged force majeure and termination for convenience. It should specify whether prior notice is required, how long the defaulting party has to cure, and whether termination operates through a contractual mechanism or requires another legal step.

The Romanian Civil Code regulates remedies for non-performance, including termination under Article 1549 and the related provisions. The contract should not merely say that a party “may terminate immediately”. It should align the grounds, notice mechanics and agreed effects with the type of contract and the intended remedy.

Exit provisions matter just as much as the termination trigger. Address final invoices, transition assistance, return of equipment and documents, data export, deletion, continued licences and the clauses that survive termination.

Penalty clauses and late-payment interest

A penalty clause fixes in advance the consequence of non-performance, defective performance or delay. Under Article 1538 of the Romanian Civil Code, its drafting should identify the protected obligation, the triggering event and the calculation method. The agreement should also state whether a penalty is daily or fixed, whether it is capped and how it interacts with damages and other remedies.

Article 1541 permits a court to reduce a penalty in the statutory circumstances, including where it is manifestly excessive in relation to the loss that the parties could have foreseen when concluding the contract. A high percentage is therefore not a substitute for careful drafting.

Common riskA daily penalty has no cap, applies to several overlapping obligations and continues after termination, creating exposure far beyond the economic value of the contract.

Liability caps, exclusions and indemnities

Liability provisions should allocate risk in proportion to the contract’s value, the parties’ control and the available insurance. Review the general cap, any separate or higher caps, excluded categories of loss, claims procedures and responsibility for employees, affiliates and subcontractors.

Do not assume that an indemnity is a familiar standard clause. It should identify the covered events, third-party claims, control of the defence, settlement authority, notification duties and mitigation. Check whether the limitation of liability applies to the indemnity or whether it creates uncapped exposure.

Any exclusion or limitation must also be tested against mandatory law and the nature of the conduct involved. A clause should not be described as protecting a party against every possible form of unlawful conduct. Where the agreement supports a wider investment or group operation, the liability wording should be reviewed together with the company’s corporate and commercial governance arrangements.

Warranties, regulatory compliance and audit rights

Warranties should be specific to the transaction. Depending on the contract, they may cover conformity with specifications, professional licences, legal compliance, authority, sanctions, anti-bribery, tax status, employment practices, product safety or the absence of third-party rights.

The review should also establish the remedy for an inaccurate warranty. Possible outcomes include correction, replacement, a price adjustment, indemnification or termination. An audit right should define scope, frequency, confidentiality, cost allocation and the treatment of identified non-compliance.

Drafting pointA broad promise to comply with “all applicable laws” may be necessary, but it does not replace transaction-specific duties, evidence requirements and an agreed remediation process.

Force majeure, hardship and change in law

Force majeure and hardship solve different problems. Force majeure concerns an external, unforeseeable, absolutely invincible and unavoidable event under the Civil Code framework. Hardship under Article 1271 addresses an exceptional change that makes performance excessively onerous, subject to the statutory conditions and the allocation of contractual risk.

The clause should define notice, evidence, mitigation, suspension, continued payment obligations and the point at which prolonged disruption permits termination. For regulated or long-term projects, add a change-in-law mechanism explaining who bears new compliance costs and whether price or timing may be adjusted.

Check before signingDo not treat every supplier delay, price increase, staff shortage or market change as force majeure. The clause should distinguish ordinary commercial risk from qualifying events.

Confidentiality and intellectual property

A confidentiality clause should define protected information, permitted use, internal access, legally required disclosures, security standards, duration and return or destruction. Trade-secret protection also depends on practical steps, so access controls and marking procedures should match the contractual wording. A standalone non-disclosure agreement in Romania may be appropriate before sensitive negotiations begin.

For intellectual property, distinguish pre-existing materials from deliverables created under the contract. State whether rights are assigned or licensed and address territory, duration, field of use, sublicensing, modifications, source materials and third-party components.

Romanian Law no. 8/1996 on copyright requires an assignment of economic copyright to specify the transferred rights and, for each, the modes of use, duration, extent and remuneration. A generic sentence stating that the customer “owns everything” may therefore be insufficient for the intended result. Businesses acquiring or licensing valuable assets can obtain a separate review from intellectual property lawyers in Romania.

For ownership arrangements between founders and shareholders, see our guide to shareholder agreements in Romania.

Personal data, security and digital services

If the agreement involves personal data, identify whether each party acts as controller, processor, joint controller or independent controller. When a supplier processes personal data on behalf of a controller, Article 28 of the General Data Protection Regulation requires a contract containing specified safeguards. Our GDPR compliance checklist for Romanian companies explains the wider governance controls that should support those clauses.

Review processing instructions, confidentiality, security measures, subprocessors, assistance with data-subject requests, breach notification, international transfers, audit rights and return or deletion. The commercial agreement and data processing agreement should not contain inconsistent liability, notice or termination rules. More complex vendor arrangements may require assistance from GDPR and data protection lawyers in Romania.

For SaaS and other digital services, also check availability commitments, backups, recovery objectives, vulnerability management, incident cooperation, data portability and access after termination. Technology businesses should align these provisions with their wider technology and digital law obligations and, where relevant, obtain a focused IT and software contract review.

Governing law, jurisdiction and notices

In cross-border contracts, governing law and forum are separate questions. The Rome I Regulation generally allows the parties to choose the law governing their contractual obligations, subject to its safeguards and mandatory rules. The Brussels I bis Regulation governs jurisdiction and the recognition and enforcement of judgments in relevant EU civil and commercial matters.

Consider whether the selected court or arbitral tribunal is proportionate to the likely dispute, where evidence and assets are located, the language and cost of proceedings, and whether an eventual judgment or award can be enforced efficiently.

The notice clause should identify valid addresses, permitted delivery methods, deemed receipt and the process for updating contact details. A termination or claim notice sent to the commercial contact may fail if the contract requires delivery to a different address or by a specific method. Where non-payment is already a concern, the agreement should be tested against the available legal recovery options for unpaid invoices in Romania.

Contract review in Romania: risk map

Contract areaQuestion to answerRisk if unclear
AuthorityIs the correct entity bound by an authorised person?Enforceability, approval and group-liability disputes.
PerformanceWhat exactly must be delivered, tested and accepted?Disputes over completion, defects and payment.
PaymentWhen is money due and what follows from delay?Cash-flow loss, penalties and invoice disputes.
ExitHow can the relationship end and what survives?Lock-in, service interruption and lost data.
LiabilityWhich losses are covered, capped or excluded?Exposure disproportionate to contract value.
IP and dataWho owns or may use assets, information and data?Loss of rights, GDPR exposure and operational dependency.
DisputesWhich law, forum and notice rules apply?Unexpected cost and difficult enforcement.

A practical pre-signing review process

Confirm the commercial dealRecord the intended result, price, timeline and points already agreed before editing legal language.
Read every contract documentReview the agreement, annexes, order forms, proposals, policies and incorporated online terms together.
Rank the risksSeparate legal defects, high-value commercial exposure, operational ambiguity and points that are negotiable preferences.
Propose usable wordingConvert each material issue into a replacement clause, tracked change or clear negotiation question.
Check signing and evidenceConfirm authority, approvals, signature method, final attachments and preservation of the executed version.
Calendar post-signing dutiesTrack notices, renewals, price reviews, certificates, audits and delivery or payment milestones.

Need a Romanian contract reviewed before signing?

Atrium Romanian Lawyers assists Romanian and foreign businesses with contract review, drafting and negotiation. The review can be delivered as tracked changes, replacement clauses, a consolidated draft or a practical risk report adapted to your position in the transaction.

Frequently asked questions

Is a business contract written in English valid in Romania?

Romanian companies can generally conclude commercial contracts in English. The transaction may nevertheless require Romanian-language documents or translations for authorities, courts, employees, consumers, notaries or regulated formalities. The governing-language clause should state which version prevails if the contract is bilingual.

Can a foreign-law contract be used with a Romanian company?

Potentially, yes. In a cross-border contract, the parties may often choose the governing law, but the Rome I framework, mandatory rules, the place of performance and the practical enforcement route must be considered. Choosing foreign law does not automatically remove every Romanian mandatory provision relevant to the transaction.

Are contractual penalties enforceable in Romania?

Romanian law recognises penalty clauses, but the obligation, trigger and calculation must be clear. Article 1541 of the Civil Code permits judicial reduction in the statutory circumstances, including a penalty that is manifestly excessive compared with the foreseeable loss at contract formation.

When should contract review in Romania take place?

Ideally before signing and before the commercial position becomes difficult to change. A new review is also appropriate before renewal, when the scope or price changes, when a party proposes an amendment, or when performance problems and a possible dispute emerge.

What should a foreign company send to the reviewing lawyer?

Send the complete draft and annexes, the commercial proposal, your role in the transaction, the applicable deadline, the principal business concerns and any terms already agreed. Identifying whether you are the customer, supplier, licensor, employer, investor or distributor changes the risk analysis.

Disclaimer: This article provides general legal information and does not constitute legal, tax or commercial advice. Contractual rights and risks depend on the complete document, the transaction, the parties, mandatory rules and the relevant facts.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Commercial invoice overlooking the Bucharest skyline, illustrating late payment in Romania

Late Payment in Romania: Penalties, Interest and Legal Remedies

When is a Romanian invoice late — and what can a creditor recover?

A missed payment deadline in Romania is not only a collections problem. It can trigger statutory penalty interest, a fixed recovery compensation and, with the right contract, a pre-agreed penalty clause — without the creditor having to prove any loss.

Overdue commercial invoice, payment deadline and legal documents in a Romanian law office

Late-payment claims may include interest, recovery compensation and documented collection costs.

Late payment in Romania is heavily regulated for business-to-business transactions. Under Law 72/2013, which transposes EU Directive 2011/7, a B2B invoice is generally payable within about 30 days unless the parties expressly agreed a longer term — capped at 60 days unless a longer term is not abusive. On late payment, provided the creditor has performed its obligations and the delay is imputable to the debtor, a professional creditor can claim the applicable statutory or contractual late-payment interest or penalty, together with the €40 flat recovery compensation and recoverable collection costs. For money obligations assumed in the exercise of an undertaking’s activity, the debtor is in delay by operation of law, so interest runs from maturity without a formal demand, subject to the statutory conditions. Exact figures depend on the contract and on the reference rate published by the National Bank of Romania.

Most foreign suppliers start with a practical question: when can you demand more than the unpaid principal, and how do you recover an unpaid invoice in Romania? This guide explains when a payment becomes late, which charges a creditor can add, which payment terms are valid (and which clauses are void), and the realistic recovery route from a first demand through to enforcement.

The rules below focus on business-to-business transactions governed by Romanian law. They apply on top of the general contract-law regime: the Romanian Civil Code and, for commercial transactions, the specific late-payment law, Law 72/2013, based on EU Directive 2011/7 on combating late payment.

What can a Romanian creditor charge on a late invoice?

Penalty interest, plus a fixed €40 recovery compensation, plus enforceable recovery costs — and, if the contract says so, a daily contractual penalty. Penalty interest, the €40 minimum compensation and a contractual penalty do not require proof of actual loss. Additional recovery costs, however, must be substantiated. These rights accrue provided the creditor has performed its obligations and the delay is imputable to the debtor.

Romanian law gives a creditor who is not paid at maturity a right to moratory damages — penalty interest — running from the due date until payment, at the rate agreed in the contract or, absent agreement, at the statutory rate, without having to prove any loss (Civil Code, Article 1535). The debtor cannot defend by showing the creditor suffered a smaller loss.

Depending on the contract, the creditor may claim the applicable statutory or contractual late-payment interest or penalty, together with the €40 minimum compensation and recoverable collection costs. Whether a contractual late-payment penalty may be cumulated with another form of moratory damages depends on the drafting and legal nature of the contractual remedies.

  1. Statutory or contractual penalty interest — at the rate agreed by the parties or, absent agreement, the statutory penalty interest at the reference rate plus 8 percentage points for professional relations, applied for each semester on the rate in force at the start of that semester (Law 72/2013, Article 4, read with OG 13/2011, Article 3).
  2. Fixed minimum compensation of €40 — a flat amount of recovery damages, payable in lei at the exchange rate on the payment date, in addition to the interest (Law 72/2013, Article 10).
  3. Substantiated recovery costs — collection expenses actually incurred and established can be claimed as damages (Law 72/2013, Article 9).
  4. Contractual penalty clause — a pre-agreed per-day penalty, enforceable without proof of loss (Civil Code, Article 1538), subject to the statutory reduction grounds in Civil Code, Article 1541. Whether it may be cumulated with other moratory damages depends on the contract’s drafting.

Risk: A creditor who ignores the interest route and waits silently may still recover the principal, but documentation matters. If the debtor later disputes the amount, the creditor must show when each sum became due. Keep invoices, delivery or acceptance evidence and the calculation of interest from maturity.

When is a payment legally late?

At the contractual due date, or generally 30 calendar days after the debtor receives the invoice when no term was agreed. In B2B contracts, an agreed payment term longer than 60 days is valid only if it is not abusive (grossly unfair) to the creditor.

The starting point is the term agreed in the contract. The parties may choose the payment date, subject to an important limit in business relations: the contractual payment term cannot exceed 60 calendar days, and a longer term is permitted only if the clause is not abusive under Law 72/2013, Article 5.

When the contract is silent, Law 72/2013, Article 3 fixes the moment from which penalty interest runs. For a professional creditor, interest runs after 30 calendar days from receipt by the debtor of the invoice or of any equivalent payment request. Where the date of receipt is uncertain or the invoice is received before the goods or services, the law uses the date of delivery of the goods or performance of the services as the reference point.

For money obligations assumed in the exercise of an undertaking’s activity, the debtor is in delay by operation of law: interest begins to run at maturity without any formal demand or notification (Civil Code, Article 1523). A written reminder still matters — it creates evidence of the claim and of the date from which the debtor was asked to pay, which becomes relevant in litigation.

These rights accrue only where the statutory conditions are met: in particular, the creditor and its subcontractors must have performed their contractual obligations, and the delay must be imputable to the debtor. The debtor must not have paid the amount due at maturity and must be unable to show that the delay is not attributable to it (Law 72/2013, Article 3(1)).

SituationInterest startsBasis
Payment term agreed in the contractOn the day after the contractual due date, generally without a formal demandCivil Code Art. 1535; Art. 1523 (enterprise money obligations)
No payment term agreed (B2B)30 calendar days after the debtor receives the invoice or equivalent payment requestLaw 72/2013, Art. 3(3)
Invoice received before delivery of goods or services30 calendar days after delivery or performanceLaw 72/2013, Art. 3(3)
Debtor is a public authorityGenerally 30 days; exceptionally up to 60 days where expressly stipulated and objectively justified; public healthcare institutions: maximum 60 daysLaw 72/2013, Art. 6–7

For public authorities, the general legal payment term is 30 calendar days. Exceptionally, the parties may stipulate a term of up to 60 calendar days if it is set out expressly in the contract and in the procurement documentation and is objectively justified by the nature or the specific characteristics of the contract (Law 72/2013, Article 7). For public healthcare institutions and public entities providing medical services, the legal payment term is capped at 60 calendar days (Law 72/2013, Article 6(4)).

The parties cannot contract around the invoice date itself: any clause fixing a term for issuing or receiving the invoice is absolutely void (Law 72/2013, Article 5(3)).

How is the interest rate calculated?

Parties may agree their own rate or penalty, but in transactions governed by Law 72/2013 a clause that excludes late-payment interest or sets it below the statutory penalty interest is treated as abusive. Absent an agreement, the statutory penalty interest in professional relations is set at the reference rate plus 8 percentage points per year.

  • Agreed rate or penalty clause. The contract may set a specific annual interest rate or a per-day penalty, for example 0.1% or 0.5% per day. Such clauses are valid and enforceable without proof of loss, subject to reduction by a court on the statutory grounds under Civil Code Article 1541. In transactions governed by Law 72/2013, a clause that excludes late-payment interest or sets it below the statutory penalty-interest level is treated as abusive under Article 14(a).
  • Statutory rate. If the parties did not agree a rate, Law 72/2013, Article 4 applies the statutory penalty interest calculated under Article 3 of OG 13/2011. For professional relations, the rate is the reference rate plus 8 percentage points, with the rate in force on the first calendar day of each semester applying for the whole semester.

The BNR reference rate in force on 1 July 2026 was 6.50%. Accordingly, the statutory B2B penalty interest applicable throughout the second semester of 2026 is 14.50% per annum. Because the reference rate moves, always confirm the rate currently in force on the National Bank of Romania website before relying on a figure.

Tip: For recurring commercial relationships, agree the interest or penalty rate in the contract. A clearly drafted penalty clause removes any argument about which statutory rate applies and creates a strong, predictable claim on each overdue invoice.

The €40 flat compensation and recovery costs

In B2B relations, a creditor is entitled to a flat minimum compensation of €40 per late payment, in addition to the applicable late-payment interest or penalty and to the costs of any enforcement procedure.

Law 72/2013, Article 10 gives the creditor the right to demand, when the conditions for late payment are met, the equivalent in lei at the exchange rate on the payment date of €40, representing flat-rate minimum damages for the costs of recovering the claim. The obligation to pay this amount matures at the same time as penalty interest starts running.

This flat amount is additional to the applicable late-payment interest or penalty and to the costs of any subsequent enforcement procedure. CJEU case law confirms that the fixed €40 minimum is payable for each commercial transaction not paid on time and evidenced by an invoice or an equivalent payment request, even where several invoices are pursued in a single claim (Case C-585/20, BFF Finance Iberia). Where a single contract provides for successive supplies or services subject to separate payment deadlines, the €40 minimum is payable for each late payment (Case C-419/21).

On top of the €40, Article 9 allows the creditor to claim recovery expenses actually incurred and established. By contrast, the €40 itself does not require proof of loss and remains the simplest element to assert on each unpaid invoice.

Which payment terms are valid — and which clauses are void?

A B2B payment term is capped at 60 days unless a longer term is not abusive. Clauses postponing the start of interest, requiring a formal demand before interest runs, or excluding penalty interest or recovery compensation are unenforceable.

Law 72/2013, Article 12 establishes the general test: a clause or practice is abusive where it creates, in a grossly unfair way (“vădit inechitabil”), rights and obligations significantly unbalanced to the creditor’s detriment. Article 13 sets the criteria a court considers, including serious deviation from established good practice, absence of objective reasons for derogating from the statutory payment terms or interest rate, and the counterparty’s dominant position towards an SME. Article 14 identifies clauses deemed abusive by law, without need for further assessment, and Article 15 sanctions abusive clauses by absolute nullity.

Clauses of the following type are deemed abusive by law and are therefore absolutely null under Law 72/2013, Articles 14 and 15:

  • clauses excluding penalty interest or setting it below the statutory penalty interest;
  • clauses fixing a moment for the interest to start later than the statutory moment;
  • clauses making interest depend on a formal putting-in-delay even though the debtor is in delay by operation of law;
  • in contracts between professionals and public authorities, a payment term exceeding what Article 7(1) allows when the exceptional conditions are not met;
  • clauses excluding the possibility of additional damages.

Mistake: relying on a 90-day payment term “because the client insisted”

In B2B contracts a term beyond 60 days is only valid if it is not abusive. A term imposed by the larger counterparty without objective justification is exposed to challenge and will not stop the statutory interest from running.

Mistake: waiting for a formal demand before recognising interest

For enterprise money obligations, delay arises by operation of law. The claim for interest starts at maturity. The creditor does not first have to send a formal notification.

Mistake: writing “0% interest” into the contract to keep the client happy

A clause that excludes penalty interest altogether is unenforceable against a professional creditor and can be disregarded. The statutory interest will still apply.

How to recover an unpaid invoice in Romania: the practical route

The route runs from a written demand, through the payment-order procedure for certain, liquid and due contractual claims, to court judgment and enforcement. Most commercial claims follow these steps, but timing, documents and evidence requirements should be checked against the specific contract before acting.

Documents illustrating the recovery of an unpaid invoice through demand, court proceedings and enforcement in Romania

Recovering an unpaid invoice normally progresses from a documented demand to court proceedings and, where necessary, enforcement.

  1. Commercial reminder. Send a payment request identifying the invoice, due date and interest accruing. Even where delay is automatic, this creates documentary evidence and often resolves the matter.
  2. Statutory summons. Before filing under the payment-order procedure, the creditor must serve a formal summons under Article 1015 of the Code of Civil Procedure through a judicial executor or by registered letter with declared contents and acknowledgment of receipt, granting 15 days to pay.
  3. Court action. If the debtor contests the claim or amount, recover through ordinary court proceedings for the principal, interest and costs.
  4. Enforcement. Once the creditor holds an enforceable title, a judicial executor can attach bank accounts, receivables or other debtor assets.

Risk: The payment-order procedure is not a substitute for litigation when determining the debtor’s defence requires evidentiary administration incompatible with the summary nature of the procedure. The claim must concern a certain, liquid and due contractual obligation established within the documentary framework. Otherwise, the creditor may have to pursue the claim through ordinary proceedings.

Which route fits which situation?

RouteBest forKey document or conditionMain business consideration
Written demand plus statutory interestOverdue but still cooperative counterpartiesInvoice, contract and evidence of deliveryPreserves the relationship while demonstrating the claim
Payment-order procedureCertain, liquid and due contractual claims for a sum of moneyWritten evidence establishing the contractual claim and proof of the mandatory Article 1015 summonsFaster track for clear claims; genuine disputes may derail it
Ordinary court actionDisputed liability, quantum or set-off argumentsFull evidence of the relationship, delivery and defaultLonger timeline; costs can include interest and fees
Enforcement by judicial executorDebtor with assets who does not pay voluntarilyEnforceable title, such as a payment order or judgmentAttachments and garnishment become available

The payment-order and enforcement rules are contained in the Romanian Code of Civil Procedure. Our dedicated guide to the payment ordinance procedure in Romania explains the conditions and required documents. The broader debt recovery in Romania guide covers the complete collection strategy.

Illustrative scenarios

No penalty clause in the contract

A Romanian buyer does not pay a 30-day invoice of €10,000. Because the money obligation was assumed in a business activity, interest runs from maturity without a formal demand at the statutory B2B rate, and the €40 flat compensation applies. The supplier can demand the principal, interest and the €40 in one written request.

Contract with a 0.5% daily penalty

The parties agreed a daily penalty of 0.5% of the unpaid amount. On a disputed invoice, the creditor can claim the contractual penalty without proving any loss under Civil Code Article 1538. A court may reduce the penalty only on statutory grounds, such as partial beneficial performance or a penalty that is manifestly excessive compared with the foreseeable loss.

Debtor contests the invoice

The debtor claims the services were defective and refuses payment. Because the claim is genuinely disputed, the payment-order route may not resolve the matter. The supplier should prepare evidence of performance and acceptance and assess ordinary litigation against the amount at stake.

How to protect your position before and after maturity

The strongest position starts before the invoice is issued. Interest and penalties are easier to claim when the contract supports them and the documentation confirms what was delivered, when it was delivered and for which price.

  1. Set a compliant payment term. Align the due date with Law 72/2013, generally up to 60 days in B2B transactions, and state it clearly in the contract.
  2. Agree a penalty or interest rate. Include a per-day penalty clause or an agreed annual interest rate so there is no argument about the statutory rate.
  3. Invoice promptly and completely. Issue the invoice with an unambiguous due date and complete references to the contract and delivery documents.
  4. Confirm receipt and delivery. Keep signed delivery notes, acceptance records or other evidence that the goods or services were provided.
  5. Send a written reminder at maturity. Restate the amount, due date, interest formula and €40 compensation. This becomes part of the evidence supporting the claim.
  6. Calculate interest from the correct date. Use the contractual due date or the applicable 30-day statutory threshold, with the semester rate in force at the start of each semester.
  7. Assess the payment-order procedure early. For a certain, liquid and due contractual claim established through documentary evidence, consider the faster procedure rather than waiting while interest and costs accumulate.
  8. Preserve the enforcement option. If payment does not follow, instruct counsel or a judicial executor before the debtor transfers assets.

The Bottom Line

Late payment in Romania is not merely a collections nuisance. It is a regulated event that gives the creditor a defined set of remedies. A professional creditor can claim the applicable statutory or contractual late-payment interest or penalty, the €40 minimum compensation and substantiated recovery costs. Late-payment interest or a contractual penalty and the €40 minimum compensation do not require proof of actual loss, while additional recovery costs must be established. Getting the payment terms, penalty clause and paper trail right from the beginning converts an overdue invoice into a clearly quantified claim that can be pursued through the payment-order procedure or the ordinary courts.

Frequently asked questions

Do I have to send a formal notice before interest starts running?

For money obligations assumed in the exercise of an undertaking’s activity, the debtor is in delay by operation of law and interest runs from maturity without a formal demand. A written reminder is still advisable as evidence and may be required for other remedies.

What is the statutory interest rate for late payment in Romania?

In professional relations, it is the reference rate plus 8 percentage points per year. With the reference rate at 6.5%, that is approximately 14.5% per annum. Confirm the current reference rate published by the National Bank of Romania before relying on a figure.

Is the €40 compensation automatic?

In B2B relations, yes. When the conditions for late payment are met, the creditor may demand the lei equivalent of €40 as flat-rate minimum recovery damages, in addition to penalty interest and enforcement costs.

Can we agree a payment term longer than 60 days?

Only if the clause is not abusive or grossly unfair to the creditor. A longer term imposed without objective justification is exposed to challenge. Clauses fixing the invoice issue or receipt date are absolutely void.

Are contractual penalty clauses enforceable without proof of loss?

Yes. A penalty clause entitles the creditor to the agreed amount without proving any loss. A court may reduce the penalty only in limited statutory circumstances, including where the penalty is manifestly excessive compared with the foreseeable loss.

Does late payment allow the creditor to terminate the contract?

Non-performance can give rise to termination rights where the statutory conditions are met. Termination is assessed separately from the interest claim and carries its own consequences, so it should be considered with counsel before being used.

Disclaimer: This article provides general legal information about Romanian and EU late-payment rules and does not constitute legal or tax advice. Interest rates, deadlines and remedies depend on the contract, the parties’ status and the specific facts. Figures such as the reference rate change over time.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Romanian company director liability and corporate governance risk assessment

Romanian Company Director Liability: Duties and Risks

When can Romanian company director liability arise?

The company is a separate legal person, but that shield is not absolute. A director may face personal exposure for breach of corporate duties, insolvency misconduct, bad-faith tax conduct, a personal guarantee or other unlawful acts.

COMPANYSEPARATE LEGAL PERSONLiability shield BREACH OF DUTYloss + causationINSOLVENCYArticle 169 conductTAX LIABILITYbad-faith conductPERSONAL GUARANTEEcontractual exposure AI-generated illustration

Romanian company director liability does not arise automatically from the company’s debts. Personal liability requires a separate legal basis, such as a damaging breach of the director’s mandate or statutory duties, conduct that contributed to insolvency, bad-faith conduct connected with unpaid taxes, or a personal contractual commitment. Foreign directors should verify their registered powers, keep an evidence trail for material decisions and escalate financial distress early.

Accepting a director appointment in Romania is more than an administrative formality. Understanding Romanian company director liability requires reviewing both the legal mandate and the director’s actual decision-making role. The director may represent the company, commit it contractually, manage assets and supervise accounting, tax, employment and regulatory processes. Those powers carry duties to the company under the articles of association, shareholder resolutions, the rules on mandate and Romanian company law.

The exact framework depends on the company form and governance structure. The Romanian term administrator may refer to an administrator of a limited liability company (SRL) or a member of the board of directors of a joint-stock company (SA). An SA may also use a two-tier system with a management board and supervisory board. The appointment document and the articles of association should therefore be read before applying any general rule.

Is a Romanian company director personally liable for company debts?

Generally, no. An ordinary supplier, landlord or lender claim is normally against the company. The director becomes personally exposed only where the creditor or another claimant can rely on a distinct statutory, contractual or delictual basis and prove the elements required for that route.

This distinction matters. A company’s inability to pay does not, by itself, transfer every unpaid invoice to its director. Equally, the words “limited liability” do not protect a director from consequences of their own conduct.

SituationUsual starting pointPotential director exposure
Ordinary commercial debtThe company is the contracting party and primary debtor.No automatic personal liability merely because the company does not pay.
Breach of mandate or company-law dutyThe company may have suffered loss through the director’s act or omission.Liability may arise if breach, damage and causation are established under the applicable rules.
Insolvency misconductThe company enters insolvency with unpaid liabilities.The insolvency court may order persons who contributed to insolvency through conduct listed in Article 169 to bear part or all of the liabilities, within the causally connected loss.
Unpaid tax obligationsThe company remains the tax debtor.Joint liability may be established in the bad-faith situations listed in Article 25 of the Fiscal Procedure Code.
Personal guaranteeThe company receives finance, a lease or credit.The director may be liable under the separate guarantee they signed, according to its terms.
Separate unlawful actThe director acts personally as well as for the company.Civil, administrative or criminal consequences may apply depending on the specific act and statute.

Do not confuse shareholder liability with director liability. A shareholder’s exposure as an investor and a director’s exposure as a manager are different questions. One person may hold both roles, but each potential claim needs its own legal basis.

What are the core duties of a Romanian company director?

Articles 72 and 73 of Romanian Companies Law no. 31/1990 connect administrators’ obligations and liability to the rules on mandate and the special provisions of the Companies Law. They also identify responsibility toward the company for matters including the reality of capital contributions, the actual existence of distributed dividends, legally required registers, implementation of shareholder resolutions and strict performance of duties imposed by law and the articles of association.

Duty areaPractical meaningUseful evidence
Act within authorityFollow the law, articles of association, appointment terms and valid shareholder or board resolutions.Current constitutional documents, authority matrix, registered representation powers and written approvals.
Protect company interestsUse management powers for the company rather than for an undisclosed personal or third-party benefit.Conflict disclosures, abstentions, independent valuations and documented commercial rationale.
Make informed decisionsObtain information proportionate to the value, urgency and risk of the decision.Board packs, forecasts, legal and financial advice, alternatives considered and minutes.
Supervise records and complianceEnsure required registers and accounting records exist and that delegated functions are reasonably monitored.Compliance calendar, management reports, tax confirmations, audit trails and escalation logs.
Implement corporate decisionsCarry out valid shareholder decisions accurately and within the company’s legal powers.Signed resolutions, implementation plans, filings and completion records.
Preserve confidentialityProtect confidential information and business secrets during and, where applicable, after the mandate.Access controls, confidentiality undertakings and documented return or deletion of company information.

For SA board members, Article 1441 of Romanian Companies Law no. 31/1990 expressly requires prudence and diligence of a good administrator, loyalty in the company’s interest and confidentiality. It also recognises an informed-business-decision protection where the director was reasonably entitled to believe that the decision served the company and relied on adequate information. That provision should not be copied mechanically into an SRL analysis; the SRL’s own statutory rules, mandate and constitutional documents must be assessed.

Decision record

A defensible director decision has four layers

1AUTHORITYWho may decide?Which approval?2INFORMATIONFacts and forecastsProfessional advice3CONFLICTSDisclose interestsManage participation4MINUTESRationale and voteActions and follow-up AI-generated illustration
The file should show how the decision was authorised, informed, conflict-checked and implemented—not merely its eventual outcome.

How do SRL and SA director duties differ?

An SRL is usually managed by one or more administrators appointed through the articles of association or by the shareholders. Article 197 contains SRL-specific administration rules and refers expressly to Articles 75, 76, 77(1) and 79. Articles 72 and 73 remain central to the mandate-based duties and liability framework, but the articles of association are also essential because they define individual or joint representation, reserved matters, term of office and internal approval limits.

An SA has a more prescriptive governance framework. In the one-tier system, a board of directors may delegate management to directors; in the two-tier system, the management board operates under a supervisory board. Duties, delegation, conflicts, meeting procedure and the mechanics of corporate liability actions can therefore differ materially from an SRL.

Foreign group policy is not enough. A director of a Romanian subsidiary must apply the subsidiary’s Romanian-law documents and duties. Instructions from the parent company, investor or beneficial owner do not automatically excuse an act outside authority or against the Romanian company’s interests.

Before accepting or using the mandate, confirm the director provisions in the Romanian articles of incorporation. Where governance rights are also allocated between investors, coordinate those documents with the shareholder agreement while recognising that a private agreement does not replace mandatory corporate rules or Trade Register formalities.

When can the company claim against a director?

A corporate claim typically focuses on whether the director breached an applicable duty and caused quantifiable loss to the company. The decision and representation mechanics depend on the company form, the alleged conduct and the applicable articles of the Companies Law. Article 155 contains the general-meeting mechanism for an SA action against directors for damage caused to the company through breach of their duties.

Approval by shareholders should not be treated as a universal release. The legal effect depends on what was disclosed, the nature of the decision, the company form, mandatory law, third-party rights and whether the approving body had authority. A director should still require accurate materials and record concerns.

Unauthorised transaction

A director signs beyond registered or internal powers and the company suffers loss. Liability, enforceability and internal recourse require separate analysis of the authority documents and third-party circumstances.

Related-party benefit

Company assets or opportunities are directed to a connected party without transparent approval, adequate information or defensible commercial terms.

Ignored compliance warning

Management receives a specific accounting, tax or regulatory warning but takes no proportionate action, allowing avoidable loss to increase.

When can insolvency create personal exposure?

Financial distress is a critical turning point. Article 66 of Romanian Insolvency Law no. 85/2014 generally requires an insolvent debtor to apply to the tribunal within a maximum of 30 days from the onset of insolvency, subject to the statute’s rules for good-faith restructuring negotiations. The competent tax authority must be notified of the intended insolvency application 15 days before filing, and proof of that notification must be attached to the application. A legal entity’s application is signed by the persons authorised to represent it under its constitutional documents; a shareholder resolution is not required by Article 66(5).

Under Article 169, the insolvency court may order management or supervisory members, any individual or legal entity exercising control over the debtor’s financial or operational decisions regardless of formal title, and other persons who contributed to insolvency through listed conduct to bear part or all of the debtor’s liabilities, without exceeding the loss causally connected to that conduct.

Article 169 risk categoryExamples of evidence reviewed
Using company assets or credit for personal or third-party benefitRelated-party payments, asset transfers, undocumented loans and non-commercial terms.
Conducting personal business under cover of the companyRevenue diversion, overlapping contracts, beneficial ownership and use of company resources.
Continuing activity in personal interest when cessation of payments was clearly approachingCash-flow forecasts, creditor ageing, director benefits and the rationale for continued trading.
Fictitious, unlawful or missing accountingLedgers, source documents, backups, handover records and access to accounting systems.
Diverting or concealing assets, or fictitiously increasing liabilitiesAsset registers, disposals, inventory movements, invoices and connected-party balances.
Transferring assets or a significant part of the business to a closely related personTransfers made while the debtor is in financial difficulty, compliance with Article 73(2¹) of the Companies Law, the relationship between the parties, continuation of the business through the new entity and evidence of an intention to shield assets from creditors.
Ruinous financing used to delay cessation of paymentsPricing, security, repayment prospects, alternatives considered and decision minutes.
Preferential payment to one creditor shortly before cessationPayment sequence, creditor relationship, maturity dates and justification.
Other intentional conduct contributing to insolvencyThe specific act, intent, resulting loss and causal connection to insolvency.

Law no. 239/2025 inserted Article 169(1)(e1), which specifically targets the transfer of assets or a significant part of the business of a debtor in financial difficulty to a person closely related to the debtor, where the obligations imposed by Article 73(21) of the Companies Law are breached and the transfer is intended to continue the activity through the new entity while shielding assets from the debtor’s creditors.

A final Article 169 liability judgment now has consequences beyond the payment order. Under Article 169(10), the person may not be appointed as a company administrator and, if already serving as an administrator elsewhere, loses that right for 10 years from the date the judgment becomes final. The person is also barred for 5 years from founding companies or acquiring a controlling participation in a new company.

Distress response

The evidence trail becomes more important as liquidity deteriorates

1MONITORCash and arrears2VERIFYSolvency status3ADVISELegal and financial4DECIDERestructure or file5PRESERVERecords and handoverAI-generated illustration
Early monitoring and documented advice help directors distinguish temporary pressure from statutory insolvency and respond within the applicable deadline.

Failure to hand over accounting records can create a rebuttable presumption of fault and causation under Article 169. For collegial management or supervisory bodies, a member who opposed the relevant act and recorded the opposition may have a specific defence under Article 169(5). A silent disagreement is therefore much weaker than a properly documented one.

When can a director become jointly liable for Romanian tax debts?

Article 25 of Romanian Fiscal Procedure Code no. 207/2015 creates specific joint-liability routes for overdue tax obligations. They are not triggered merely by holding office. The relevant provisions require the statutory circumstances and, for the principal director-related routes, bad faith.

Potential cases include administrators or other persons who, in bad faith:

  • caused the debtor’s insolvency by transferring or concealing its assets;
  • failed during their mandate to request the opening of insolvency proceedings for tax obligations from that period that remained unpaid when insolvency was declared;
  • caused the non-declaration or non-payment at maturity of tax obligations;
  • caused an unjustified tax refund or reimbursement; or
  • caused tax debts to accumulate and prevented their payment in the circumstances covered by Article 25(21).

A tax assessment against the company and a decision establishing the director’s joint liability are different acts. The facts, legal basis, procedural steps and challenge deadlines should be reviewed immediately when a director receives a Romanian tax notice.

Can delegation, resignation or shareholder instructions remove liability?

Delegation

Delegating finance, tax or operations does not necessarily eliminate a director’s own supervision duties. The appropriate level of oversight depends on the company form, governance structure, importance of the function, warning signs and the director’s legal powers. A clear written delegation and regular reporting are stronger than an informal assumption that “the accountant handles it.”

Resignation

Resignation can end future management authority once effective and properly implemented, but it does not erase possible liability for earlier acts or omissions. The director should document the handover, return company property, preserve relevant records and ensure required Trade Register formalities are handled.

Shareholder or parent-company instructions

A shareholder instruction does not automatically legalise conduct that breaches mandatory law or the director’s duties to the Romanian company. Material instructions should be checked against reserved matters, representation rules, corporate benefit, conflicts and insolvency considerations.

Directors’ and officers’ insurance

D&O insurance may fund defence costs or certain covered claims, but wording, exclusions, notification duties, deductibles and Romanian mandatory law matter. It cannot be assumed to cover fraud, intentional misconduct, all tax exposure, fines or every insolvency claim.

Practical checklist for foreign directors of Romanian companies

  1. Verify the mandate. Obtain the current articles of association, appointment decision and Trade Register extract.
  2. Map authority. Distinguish individual representation, joint signatures, shareholder reserved matters and internal approval thresholds.
  3. Build a reporting pack. Receive timely cash-flow, tax, accounting, litigation, employment and regulatory information.
  4. Document material decisions. Record information reviewed, options, conflicts, rationale, vote and follow-up responsibility.
  5. Control related-party dealings. Disclose interests and obtain the approvals and supporting valuation appropriate to the transaction.
  6. Supervise filings and records. Use a compliance calendar and require evidence of submission and payment—not verbal confirmation alone.
  7. Escalate warnings. Investigate missed tax payments, unpaid salaries, creditor enforcement, deteriorating liquidity and missing records promptly.
  8. Record disagreement. Use the legally appropriate board record and written notification; do not rely on an informal objection.
  9. Assess distress early. Seek Romanian insolvency and tax advice before the statutory filing window is lost, allow for the 15-day advance tax-authority notification and scrutinise transfers to closely related persons.
  10. Plan the exit. Coordinate resignation, handover, registrations, access removal, record preservation and insurance notification.

The bottom line

Romanian company director liability is conduct-based, not an automatic consequence of a company debt. The strongest protection is disciplined governance: understand the mandate, obtain adequate information, act within authority and in the company’s interest, manage conflicts, preserve reliable records and respond quickly to tax or insolvency warning signs.

Foreign directors should not wait for a dispute to reconstruct the decision process. A focused Romanian-law governance review can identify gaps in signing authority, reserved matters, minutes, compliance reporting and distress procedures before they create personal exposure.

Frequently asked questions

Is an SRL administrator automatically liable for the company’s unpaid debts?

No. The SRL is normally the debtor. Personal liability requires a separate legal or contractual basis, such as breach of the administrator’s duties causing loss, Article 169 insolvency conduct, Article 25 bad-faith tax conduct or a personal guarantee.

Does being a shareholder change a director’s liability?

Shareholder and director exposure are separate. A person who holds both roles may face different claims in each capacity, but liability must be analysed under the legal basis applicable to that role and conduct.

Can shareholder approval protect a Romanian director?

Approval can be relevant, but it is not a universal defence. Its effect depends on the company form, authority of the approving body, quality of disclosure, mandatory law, third-party rights and the conduct involved.

Does resignation end a director’s potential liability?

Resignation can end future authority once effective, but it does not erase potential liability for earlier conduct. Proper handover, registration, preservation of records and insurance notification remain important.

What should a director do if they disagree with a board decision?

Obtain advice on the correct procedure, state the reasons clearly and ensure the opposition is recorded and notified in the form required by the applicable governance rules. This is particularly important for collegial bodies and insolvency-related decisions.

Can D&O insurance eliminate personal liability?

No. It may cover certain defence costs and claims, but policy terms, exclusions, notice requirements and mandatory law apply. Fraud, intentional conduct, fines, tax exposure and insolvency claims may be excluded or limited.

Disclaimer: This article provides general legal information and does not constitute legal, tax or insolvency advice. Director duties and liability depend on the company form, constitutional documents, appointment terms, decision-making process, actual conduct and the law applicable to the specific facts.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.

Romanian lawyer reviewing employee and independent contractor arrangements with business clients

Employee vs Contractor in Romania: Legal Risks

Employee or independent contractor in Romania?

Foreign companies must match the contract to the way the work will actually be organised. Romanian employment and tax rules look beyond labels, invoices and foreign templates when control, integration and commercial independence point in another direction.

Individual Employment Labour Code Article 10 Subordination & Authority Mandatory Protections Payroll & Social Security ⚖ B2B Services Agreement Fiscal Code Article 7 4-of-7 Independence Test Commercial Autonomy Own Risk & Deliverables ✓ VS Romanian Substance-Over-Form Legal Review

A company cannot turn an employee into an independent contractor simply by changing the contract title. Romanian authorities and courts may examine how the relationship works in practice: who controls the schedule, location and method of work, whether the individual may serve other clients, who bears commercial risk and whose resources are used. Before engaging a Romanian contractor, foreign companies should test both the written terms and the operating model, document genuine independence and correct any inconsistent practices.

Hiring an individual in Romania requires an early classification decision. The company must determine whether it needs an employee working under its authority or an independent provider responsible for delivering agreed services through their own business activity.

This distinction affects much more than the contract label. It can determine employment protections, payroll and social-contribution treatment, working-time controls, termination requirements and the allocation of commercial risk. A foreign template describing someone as a “consultant” or “independent contractor” will not resolve those questions if the day-to-day relationship operates like employment.

Can the parties simply choose employee or contractor status?

No. The parties may choose a contractual structure, but that structure must match the legal and economic reality of the work. A services agreement cannot safely replace an employment contract where the individual is, in substance, working under the company’s authority and direction.

Romanian law approaches classification from more than one direction. The Romanian Labour Code defines an individual employment contract through work performed for and under the authority of an employer in return for remuneration. Separately, the Romanian Fiscal Code defines independent activity through a statutory set of criteria and allows the tax authorities to reclassify a transaction or activity so that its tax treatment reflects its economic substance.

The practical assessment therefore has two connected parts:

  1. Contractual structure: what rights, duties, control mechanisms and risks the documents create.
  2. Operational reality: how managers and the individual actually organise and perform the work.

Risk: A carefully drafted contractor agreement can still be undermined by daily instructions, fixed attendance, manager approval of absences, exclusivity, company-controlled tools or treatment identical to employees.

What is the practical difference between an employee and an independent contractor?

Decision factorEmployeeIndependent contractor
Legal relationshipPerforms work under an individual employment contract.Provides defined services under a civil or commercial agreement.
Direction and controlWorks for and under the authority of the employer.Controls the method and organisation of the service, subject to agreed deliverables.
Schedule and locationNormally follows contractual and employer-established working arrangements.Should have meaningful freedom to choose when, where and how the service is performed.
Commercial riskThe employer bears the business risk and owes the agreed salary.The provider assumes genuine risks linked to cost, performance and organisation.
Other clientsMay have other employment, subject to working-time, conflict and incompatibility rules.Should be free in substance to offer services to several clients.
Tools and resourcesWork is commonly performed with employer-provided systems and resources.The provider ordinarily uses or organises their own professional resources.
Statutory protectionsReceives the mandatory protections attached to employment status.Relies primarily on the services agreement and the law governing that agreement.
Ending the relationshipTermination must follow the applicable employment route and mandatory safeguards.Termination follows the contract and applicable civil or commercial rules.
Legal Matrix

The Workforce Classification Spectrum in Romania

Full Subordination • Mandatory daily working hours • Supervised work execution • Integrated into staff hierarchy ➔ Individual Employment (CIM) Gray / Misclassified Zone • Invoiced through PFA / SRL • But 100% exclusive dedication • Fixed salary-like retainers ⚠ High Reclassification Risk Commercial Autonomy • Freedom of place & schedule • Result/deliverable-based • Multi-client portfolio & risk ✓ Lawful B2B Contractor EMPLOYEE (CIM) SUBSTANCE OVER FORM INDEPENDENT (B2B)
Figure 1: The operational spectrum used by Romanian Labour & Tax authorities to assess workforce relationships.

No single row decides the classification. The correct conclusion depends on the relationship as a whole. For example, a contractor may need access to a client’s secure systems without becoming an employee. Conversely, issuing invoices through a registered business does not by itself prove independence if the individual remains subject to employee-like control.

What does Romanian employment law treat as employment?

The central employment indicator is subordination: the individual performs work for and under the authority of the employer in return for remuneration. The company’s control over the person, not merely its right to accept a deliverable, is particularly important.

Article 10 of the Labour Code defines the individual employment contract as the agreement under which an individual undertakes to perform work for and under the authority of an employer in exchange for remuneration. This is different from a genuine customer-provider relationship, where the customer specifies the expected result but does not manage the provider as part of its workforce.

Where the facts point to employment, our employment lawyers in Romania can review the proposed contract, workplace controls and onboarding documents before work begins.

For employment, the contract must be concluded in writing, in Romanian, no later than the day before the employee starts work. The employer must also complete the required employee-register formalities before work begins. The Romanian Labour Inspectorate confirms these requirements in its official employment-contract guidance.

Operational indicators that may point towards employment include:

  • a manager determines the individual’s daily or weekly schedule;
  • attendance at a company location or continuous online availability is mandatory;
  • the individual receives detailed instructions about how work must be performed;
  • absences require permission rather than coordination of deliverables;
  • performance is managed through the same hierarchy and procedures used for employees;
  • the individual is presented internally or externally as a member of staff;
  • the role is personal and the individual cannot use collaborators or substitutes;
  • the individual bears little or no genuine commercial risk.

These are indicators, not an automatic checklist. The nature of the work, regulatory requirements, information security and customer obligations may justify some controls. The question is whether those controls preserve an independent business relationship or place the individual under employer-like authority.

When does the Fiscal Code recognise an independent activity?

Under Article 7 of the Fiscal Code, an activity performed by an individual for income is independent when at least four of seven statutory criteria are met. The evidence should show that those criteria operate in practice, not only that they were copied into the contract.

Fiscal Code criterionPractical evidence to examine
1. Freedom over place, method and scheduleThe provider plans performance independently and is not assigned employee attendance hours.
2. Freedom to work for several clientsThe contract permits other clients and the operational model does not make that freedom artificial.
3. Assumption of inherent business riskThe provider bears relevant costs, rectification duties or other genuine performance risks.
4. Use of the individual’s own assetsThe provider uses or arranges professional equipment, software, workspace or other business resources where appropriate.
5. Use of intellectual or physical capacityThe service depends on the provider’s own professional expertise or performance.
6. Membership of a regulated professional bodyThe activity is carried out within a legally regulated profession, where applicable.
7. Freedom to perform directly, with staff or collaboratorsThe provider may lawfully organise delivery personally or through employees or collaborators, subject to justified qualification and confidentiality requirements.
Statutory Rule

Romanian Fiscal Code Article 7: The 4-of-7 Independence Test

1 Autonomy Place, method & schedule 2 Multiple Clients Substantive freedom to serve 3 Commercial Risk Inherent business risk borne 4 Own Assets / Tools Equipment, premises, licenses 5 Capacity & Skill Own professional expertise 6 Professional Body Regulated trade or guild 7 Criterion 7: Delegation & Substitutes Lawful freedom to perform directly or via staff/collaborators MINIMUM 4 REQUIRED to satisfy Fiscal Code Art. 7
Figure 2: The 7 statutory criteria under Romanian Fiscal Code Art. 7. At least 4 must be satisfied and backed by operational proof.

Practical tip: Build a short evidence file for each material contractor relationship. Keep the agreement, scope of work, invoices, deliverable records and evidence of independent organisation together. A clause is stronger when the working record supports it.

Are four fiscal criteria enough to eliminate employment risk?

Not necessarily. The four-of-seven test defines independent activity for Romanian tax purposes, but it should not be treated as permission to reproduce an employment relationship through a services contract.

The tax and employment analyses overlap, particularly around control, business risk and operational autonomy, but they do not perform exactly the same function. The Labour Code focuses on work performed under employer authority. The Fiscal Code focuses on the conditions for independent activity and the correct tax treatment of economic substance.

Article 11 of the Fiscal Code allows the tax authorities to disregard a transaction without economic purpose or reclassify the form of a transaction or activity to reflect its economic content. The authority must explain the relevant facts and evidence supporting the reclassification. This makes consistent documentation important, but it also means that documentation must reflect reality.

European Union case law follows a similar substance-based approach for EU-law concepts of “worker”. In Yodel Delivery Network, Case C-692/19, the Court of Justice explained that an “independent contractor” label does not prevent worker classification where independence is merely notional. Relevant considerations included control over time, place and content of work, exposure to commercial risk, integration into the undertaking and freedom to use substitutes or serve third parties.

Which arrangements create the highest misclassification risk?

Fixed employee-style availability

The contractor must work the company’s standard hours, remain continuously available and obtain approval for any absence, regardless of deliverables.

Control over method, not only result

A company manager allocates daily tasks, prescribes the precise working method and continuously supervises the individual in the same way as employees.

Artificial freedom to serve other clients

The agreement permits other clients, but workload, exclusivity expectations or availability requirements make that freedom unrealistic.

No meaningful business risk

The individual receives a fixed recurring amount, bears no relevant costs or correction obligations and is paid regardless of the agreed output.

Full integration into the organisation

The contractor has an internal job title, reports through the employee hierarchy, appears in staff structures and is evaluated under employee procedures.

A recurring monthly fee, a long relationship, one important client or use of a customer system is not automatically decisive. Each fact must be assessed in context. Risk rises when several employee-like elements combine and genuine commercial independence becomes difficult to demonstrate.

What can happen after a misclassification finding?

A misclassification finding can open separate tax, employment, social-contribution and contractual questions. The precise exposure depends on who makes the finding, the period reviewed, the parties involved and the evidence.

Tax and social-contribution exposure

The tax authority may reassess the economic substance of the activity and determine the related tax and contribution consequences. Historic treatment, payment records, filings and the allocation of responsibility between the parties must be reviewed before quantifying any exposure.

Employment rights and claims

An individual may argue that the factual relationship was employment and seek rights associated with employee status. Questions may arise concerning remuneration, working time, leave, termination, employee records and other mandatory protections. The outcome depends on the legal route and the evidence, not on the contract title alone.

Inspection and document risk

Where work has in substance been performed as employment without the required employment formalities, the company may face labour-inspection consequences. Specific sanctions should be assessed against the law in force and the facts at the date of the review.

Commercial and transaction risk

Misclassification can affect due diligence, financing, investment or an acquisition. A buyer may ask for the contractor population, templates, tax treatment, intellectual-property arrangements and potential historic liabilities to be reviewed before closing.

Intellectual property and confidentiality

The company should not assume that an employment-style intellectual-property position automatically applies to an independent provider. Ownership, assignment, permitted use, confidentiality and return or deletion of information should be dealt with expressly and consistently with the actual relationship.

Does contracting through a PFA or an SRL remove the risk?

No business form provides an automatic safe harbour. It may change the contractual and tax analysis, but the parties should still examine who performs the service, how the relationship operates and whether the structure has genuine commercial substance.

A Romanian authorised individual enterprise, commonly referred to as a PFA, is closely connected to the individual providing the activity. An SRL is a separate legal entity, which may employ staff, assume business risks and organise delivery through its own resources. Those differences matter, but neither registration document should replace a factual review.

If the supplier structure is still being established, the practical differences should also be considered alongside our guidance on company formation in Romania for foreign founders.

For an SRL supplier, examine whether the supplier is genuinely providing a business service or whether one individual is effectively inserted into the customer’s organisation under continuous personal control. For a PFA, test the statutory independence criteria directly and retain evidence supporting them.

Foreign companies should also avoid importing assumptions from their home jurisdiction. A worker physically performing activity in Romania may trigger Romanian employment, tax, social-security, registration or permanent-establishment questions. Those cross-border issues require a separate review based on the company, worker, location and duration of the arrangement.

Related structures may require a different analysis. Our guide to dual employment in Romania explains the rules applicable when an individual holds more than one employment contract, while the guide to service contract requirements in Romania covers the clauses and compliance points relevant to genuine service relationships.

Three illustrative classification scenarios

Scenario 1: project-based software specialist

A specialist agrees to deliver defined software modules, chooses the working schedule and location, uses their own business equipment, serves several clients and may use qualified collaborators. The customer controls security standards, acceptance criteria and deadlines but not the specialist’s daily organisation.

Assessment: These facts support independence, subject to the complete contract, tax position and actual implementation.

Scenario 2: “consultant” managed as staff

An individual works from 09:00 to 18:00, reports daily to a department manager, needs approval for time off, uses only company equipment, appears on the internal organisation chart and cannot accept other clients.

Assessment: The contractor label is difficult to reconcile with the operational indicators of subordination and workforce integration.

Scenario 3: regulated client environment

An external professional must work through the customer’s secure system and attend specific meetings because of regulatory and information-security requirements. The professional otherwise decides how to perform the mandate, bears professional risk and maintains other clients.

Assessment: Use of customer systems and scheduled coordination do not decide the issue alone. The purpose and extent of control must be examined.

These scenarios are illustrative. Changing one fact, such as exclusivity, substitution rights, commercial risk or management control, may change the conclusion.

How should a foreign company structure a genuine contractor relationship?

  1. Define the result. Describe services, deliverables, acceptance criteria and deadlines instead of creating an employee job description.
  2. Preserve operational autonomy. Allow the provider meaningful control over place, schedule and method, subject to justified security and coordination requirements.
  3. Address other clients. Avoid broad exclusivity unless a narrow restriction is genuinely necessary and legally supportable.
  4. Allocate business risk. Specify responsibility for costs, tools, corrections, professional organisation and non-conforming deliverables.
  5. Review substitution and collaboration. Permit lawful use of qualified personnel or collaborators where compatible with the service, confidentiality and regulatory requirements.
  6. Separate contractors from HR procedures. Do not automatically apply employee leave approval, performance management, benefits or disciplinary systems.
  7. Protect data, confidentiality and IP. Draft clauses that fit an independent services relationship and the actual information or assets involved.
  8. Keep evidence. Retain statements of work, invoices, deliverables and communications showing independent organisation.
  9. Reassess material changes. Review the classification when the scope, reporting line, exclusivity, workload or duration changes.

How can a company audit its existing Romanian contractors?

Audit Roadmap

7-Step Romanian Contractor Classification Audit

1 Inventory All PFA/SRL 2 Fact Map Daily routine 3 Fiscal Test 4-of-7 check 4 Labour Test Authority check 5 Risk Scan IP & Tax PE 6 Classify Risk tiers 7 Remediate Lawful fix Remediation must be prospective; avoid backdating documents or creating artificial records.
Figure 3: Corporate audit roadmap for evaluating contractor populations in Romania.
  1. Inventory every arrangement. Identify individuals engaged directly, through a PFA, through a personal SRL or through an intermediary.
  2. Map the facts. Record schedule, location, reporting, tools, clients, payment model, risk, substitution and integration.
  3. Test the seven fiscal criteria. Identify which criteria are genuinely met and what evidence supports each conclusion.
  4. Test employment subordination. Compare management practices against the Labour Code concept of work under employer authority.
  5. Check connected risks. Review tax, social security, immigration, permanent establishment, IP, confidentiality and data protection where relevant.
  6. Classify by risk. Separate clearly independent providers, fact-sensitive cases and arrangements that operate like employment.
  7. Implement a lawful correction plan. Amend terms and practices where the relationship remains genuinely independent, or move to an appropriate employment structure where the facts require it.

Risk: Do not “repair” the file by backdating documents or creating evidence that did not exist. Remediation should accurately record the current position and lawfully correct the arrangement going forward, while historic exposure is assessed separately.

The Bottom Line

The employee-versus-contractor decision must be made from the work model, not from the preferred invoice or contract label. Genuine contractors organise an independent activity, retain meaningful autonomy and assume real business responsibility. Employees perform work within the employer’s authority and receive the mandatory protections attached to that status.

For foreign companies, the safest starting point is a combined contract and operations review before the individual begins work. The same review should be repeated whenever the role becomes more integrated, exclusive or manager-controlled.

Frequently asked questions

Can a Romanian contractor work for only one client?

One client does not automatically create employment, but it weakens one of the express indicators of independent activity and may increase economic dependence. The full relationship must still be assessed, including control over schedule and method, commercial risk, tools, substitution rights and whether the contractor is integrated into the client’s organisation.

Is a monthly fixed fee evidence of employment?

Not by itself. A genuine provider may charge a monthly retainer or recurring service fee. Risk increases where the payment resembles a salary and is combined with fixed attendance, continuous personal availability, direct supervision, no deliverable risk and treatment identical to employees.

Can a foreign company hire a Romanian individual as a contractor?

Potentially, but the company should confirm that the activity is genuinely independent and that the contractor has an appropriate legal and tax setup. The arrangement may also raise Romanian tax, social-security, employment, registration or permanent-establishment questions depending on the company, work location and duration.

Does an SRL invoice eliminate misclassification risk?

No. An SRL is a separate legal entity and that distinction matters, but the customer should still examine whether it receives an independently organised business service or manages one individual as part of its workforce. Contracting structure, economic substance and daily practice must be assessed together.

Should the agreement use Romanian law?

The applicable law depends on the parties and cross-border structure. A foreign governing-law clause cannot necessarily remove mandatory rules relevant to work performed in Romania. The governing law, jurisdiction, tax position and mandatory employment protections should be reviewed together before using a foreign template.

When should an existing contractor arrangement be reviewed?

Review it when the contractor becomes exclusive, moves into a managerial reporting line, adopts employee working hours, receives company benefits, stops using independent resources or shifts from project delivery to an ongoing internal role. A periodic review is also appropriate for material or long-running engagements.

Disclaimer: This article provides general legal information and does not constitute legal or tax advice. Classification depends on the contract, the actual working relationship, the parties’ tax status and the applicable Romanian and EU rules.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.

Two corporate professionals reviewing AI transparency controls, compliance dashboards, and synthetic content verification tools on screens in an office setting.

EU AI Act in Romania: 2026 Guide for Foreign Companies

Artificial intelligence and digital regulation · 2026

EU AI Act in Romania: 2026 Guide for Foreign Companies

Foreign companies operating in Romania may be subject to the EU AI Act even when the parent company, vendor or development team is outside the European Union. This practical guide explains the scope rules, the obligations already applying in 2026, the later high-risk deadlines and the records a Romanian business should build now.

The analysis should be read together with the official AI Act text, the Commission’s AI Act implementation page and the current guidance available through the AI Act Service Desk.

Two corporate professionals reviewing AI transparency controls, compliance dashboards, and synthetic content verification tools on screens in an office setting.
AI compliance is a governance process: classify, document, train and monitor.

What is the practical answer for a foreign company?

A Romanian subsidiary, branch or other local operation should begin with an inventory of the AI systems it provides, deploys, imports, distributes or uses for work. The company should then identify whether the system is prohibited, high-risk, subject to transparency duties, or outside the main AI Act obligations. The label used by the vendor is not decisive: the same tool may create different legal questions depending on its function, users, outputs and place of use.

Scope first

Map the Romanian entity, the foreign group, the provider, the deployer, the users and where the output is used. A foreign parent does not automatically remove EU exposure.

Article 2 analysis

Obligations now

AI literacy, prohibited-practice controls, GPAI-related obligations and the new transparency rules must be considered according to the applicable role and system.

2026 operating baseline

Evidence later

Keep an AI register, vendor file, training record, human-oversight process and incident route so the business can show how it reached its classification.

Governance that scales
Key point: the AI Act does not create a universal “AI officer” requirement for every Romanian business. Responsibility must be allocated in a way that fits the company’s systems, roles, risk profile and existing compliance structure.

AI Act timeline for companies operating in Romania

The original AI Act timetable has been supplemented by the Digital Omnibus on AI. The current implementation page of the European Commission identifies the dates below. A deadline table should be treated as a planning tool, not as a substitute for checking the final text and any sector-specific transition rule.

Completed1 August 2024
Entry into force

The Regulation entered into force. The legal framework began its transition period, while later provisions were scheduled to apply in stages.

Applied2 February 2025
Prohibitions and literacy

The prohibited-practice rules and the Article 4 AI-literacy obligation became applicable. Businesses should already have training and prohibited-use controls in place.

Applied2 August 2026
Transparency and supervision

Transparency obligations for certain AI systems, broader enforcement powers and the Commission’s AI Office and national authorities’ implementation work become operational.

Deferred2 December 2027
Selected high-risk uses

Following the Digital Omnibus, high-risk systems in sensitive Annex III areas, including employment, apply from this date. Product-embedded high-risk rules have a later transition.

Rule or milestoneCurrent application pointWhat the Romanian operation should do
Prohibited AI practicesApplied from 2 February 2025; an additional prohibition concerning certain non-consensual intimate or child sexual abuse material applies from 2 December 2026.Screen use cases before procurement or deployment and escalate any practice that may manipulate, exploit, socially score or infer protected characteristics.
AI literacyApplied from 2 February 2025 and enforced by national market-surveillance authorities from 2 August 2026.Adopt role-based training and retain evidence of the measures taken, rather than relying on a generic awareness email.
Transparency rulesApplied from 2 August 2026 for the relevant Article 50 systems and outputs.Review chatbot notices, synthetic-content marking, deepfake disclosures and the editorial process for public-interest text.
Annex III high-risk systemsSelected high-risk use cases, including employment, apply from 2 December 2027 after the Digital Omnibus transition.Classify and plan early. The later date does not remove GDPR, employment, consumer or fundamental-rights duties that may apply now.
High-risk systems in regulated productsExtended transition until 2 August 2028 under the current Commission summary.Coordinate product-safety, sectoral and AI Act analysis with the provider and any notified-body or conformity route.

The Commission’s current AI Act timeline identifies the staged dates and the changes introduced by the Digital Omnibus.

Does the AI Act apply to a foreign company operating in Romania?

Often, yes. The scope is not limited to companies incorporated in an EU Member State. The Regulation covers providers placing AI systems or general-purpose AI models on the Union market, deployers located in the Union, and providers or deployers in a third country where the output produced by the system is used in the Union. Importers, distributors, certain product manufacturers, authorised representatives and affected persons are also expressly addressed.

This creates several common patterns for international groups. A US or UK parent may provide a generative AI platform used by its Romanian subsidiary. A Romanian company may deploy a recruitment tool supplied by a vendor in another country. A group may centralise procurement and security while the local entity makes decisions affecting Romanian workers or customers. The legal analysis should identify each role instead of treating “the group” as a single operator.

Question 1Is the system used in the EU?

If the Romanian entity deploys the system, or its output is used in Romania or elsewhere in the Union, the scope analysis moves beyond the location of the parent company.

Question 2Who provides it?

Record the provider, importer, distributor, group company, authorised representative and vendor chain. Contract labels are useful evidence but do not replace the legal role analysis.

Question 3Who deploys it?

Identify the business unit that determines the purpose and use. The deployer may be the Romanian company, a foreign shared-service centre or another group entity depending on the facts.

Question 4Who is affected?

Employees, applicants, customers and other persons in the Union may be affected even when the technical processing or model hosting takes place outside Romania.

Do not rely on the hosting location alone: cloud hosting, a foreign parent or a vendor’s “EU AI Act compliant” statement does not by itself determine whether the Romanian entity has obligations.

Which AI uses should a Romanian company classify first?

A useful first inventory is operational rather than theoretical. Start with tools that make recommendations, rank people, generate customer-facing outputs, analyse sensitive information, control access to services or influence employment decisions. Include tools purchased by individual teams if company data or company accounts are used.

Business useWhy it needs early reviewFirst evidence to collect
Recruitment, CV screening or candidate scoringEmployment and access-to-self-employment uses are listed in Annex III and may engage high-risk analysis once the relevant rules apply.Vendor description, decision logic, data sources, human review and impact on applicants.
Employee monitoring, task allocation or performance evaluationAI used to affect working relationships or monitor behaviour may fall within the employment category and also raise labour-law and GDPR questions.Purpose, affected groups, indicators, decision owner, notice, consultation and challenge route.
Customer chatbot or voice assistantInteractive systems may require a clear notice that the person is interacting with AI unless the interaction is obvious in context.Interface screenshots, notice wording, escalation to a person and accessibility check.
AI-generated public-facing images, audio or textArticle 50 can require machine-readable marking or disclosure, subject to the relevant exception and content type.Generation workflow, labelling method, human review, editorial responsibility and publication record.
Credit, insurance, access or eligibility decisionsSome essential private or public service uses are listed as high-risk and can intersect with anti-discrimination and sectoral rules.Decision criteria, datasets, human oversight, explanation path and affected-person rights.

Do not classify a system only by the word “AI” in a sales brochure. Ask what the tool actually does, which people it affects, whether it generates or ranks content, whether it makes or supports a decision, and whether it is integrated into a regulated product. The Commission’s AI Act Service Desk provides tools and guidance that can support this initial assessment.

Which AI practices are prohibited?

The AI Act bans certain practices because their risks are considered unacceptable. Examples include harmful manipulation or deception, harmful exploitation of vulnerabilities, social scoring, certain forms of individual criminal-offence prediction, untargeted scraping to create facial-recognition databases, workplace or education emotion recognition, and biometric categorisation to infer protected characteristics, subject to the precise legal wording and exceptions.

For a foreign company with Romanian staff, the workplace emotion-recognition prohibition deserves particular attention. A vendor may market a “wellbeing”, “engagement” or “productivity” product without describing it as emotion recognition. The business should look at the functionality and the data signals used, not only the product name. The same applies to tools that claim to infer personality, intent, reliability or risk from communications.

Procurement gate

Require the business owner to describe the system’s purpose, data sources, affected people and output before purchase or activation.

Red-flag review

Escalate tools involving vulnerability exploitation, social scoring, biometric inference, emotion recognition or behavioural prediction.

Decision record

Record why the company concluded that a use is permitted, prohibited, outside scope or subject to another compliance route.

What transparency duties apply from 2 August 2026?

Article 50 covers specific interactions and outputs. A provider of an AI system intended to interact directly with natural persons must ensure that people are informed that they are interacting with an AI system unless this is obvious in context. Providers of systems generating synthetic audio, image, video or text must ensure that outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, subject to the stated limits and exceptions.

Deployers have additional duties in defined situations. People exposed to emotion-recognition or biometric-categorisation systems must be informed. A deployer of an image, audio or video deepfake must disclose that the content was artificially generated or manipulated, subject to the artistic and other exceptions. Text generated or manipulated by AI and published to inform the public on matters of public interest must also be disclosed, but the obligation does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility.

This is why the website’s ordinary AI Notice and a public disclosure under Article 50 should not be treated as identical. An editorial footer may be useful transparency, but it does not automatically satisfy every machine-readable marking or user-facing notice requirement. Each workflow should be checked according to the system, output, audience and publication context.

Practical control: create a short content decision tree: AI-assisted editing, substantially generated content, deepfake or synthetic media, public-interest text, customer interaction. Assign the corresponding label, machine-readable marker, human review and approval record.

Does every AI-generated business article or image need a label?

No single answer applies to every output. The AI Act distinguishes between the type of system, the type of output and the way the content is published or presented. Standard editing that does not substantially alter the input may fall within an exception to the machine-readable marking duty. A human review and editorial-control exception may apply to certain public-interest text. Deepfakes have their own disclosure rule, while chatbots require a direct-interaction analysis.

The company should document the workflow instead of making a broad statement such as “all AI content is exempt” or “all AI content must be labelled in the same way”. Keep the prompt or source material where appropriate, the generated version, the human changes, the responsible editor, the final label and the publication channel. This is particularly useful where content is repurposed across websites, advertisements, social media and customer communications.

What does AI literacy require?

Article 4 requires providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy for staff and other persons dealing with the operation and use of AI systems on their behalf. The measures should take account of technical knowledge, experience, education, training, the context in which the systems are used and the people or groups on whom the systems are used.

This is a context-based obligation, not a fixed annual course or a universal certification. A marketing employee using a writing assistant, an HR manager using a candidate-ranking tool and an engineer managing a model deployment do not need identical training. The employer should explain relevant limitations, data handling, hallucination and reliability risks, prohibited uses, escalation routes, human review and the consequences of relying on outputs.

Identify AI users

List employees, contractors and other persons acting on the company’s behalf who operate or use an AI system. Include occasional users where the risk justifies it.

Match training to context

Separate basic safe-use guidance from role-specific instruction for HR, legal, customer service, developers, procurement and management.

Keep training records

Retain the audience, date, topics, materials, completion evidence and any follow-up testing or policy acknowledgement.

Update after change

Reassess training when a new system, material model update, high-risk use, incident or regulatory guidance changes the risk profile.

The Commission’s AI-literacy Q&A explains that enforcement of Article 4 is handled by national market-surveillance authorities and that there is no one-size-fits-all competence framework. A Romanian business should therefore build a proportionate internal record rather than wait for a template course.

What should employers know about recruitment and workplace AI?

Annex III identifies AI systems intended for recruitment or selection, including targeted job advertising, application analysis and candidate evaluation. It also identifies systems used to make decisions affecting terms of work-related relationships, promotion or termination, allocate tasks based on individual behaviour or personal traits, or monitor and evaluate performance and behaviour.

Under the current Commission timeline, the rules for high-risk systems in these sensitive areas apply from 2 December 2027 following the Digital Omnibus transition. This does not create a compliance holiday. A Romanian employer must still consider GDPR, Romanian labour law, anti-discrimination rules, information duties, collective arrangements, employment records, confidentiality and the possibility of human challenge. A vendor’s score should not become an unexplained substitute for a lawful employment decision.

Before deploying such a tool, the employer should identify who makes the final decision, what the AI output means, whether a person can disregard it, what data is used, whether a candidate or employee can obtain an explanation, and what happens if the system produces an incorrect or discriminatory result. The analysis should also consider whether the foreign group’s HR platform is being deployed by the Romanian entity or merely accessed for central administration.

Separate the dates: the later high-risk deadline concerns the AI Act’s high-risk requirements. It does not suspend GDPR or employment-law obligations that may arise from the same processing or decision today.

Vendor contracts and AI due diligence

A foreign company should not accept a short vendor statement as its entire AI Act file. The contract and due-diligence record should allow the Romanian operation to understand the system’s intended purpose, role allocation, technical limitations, data use, security, logging, human oversight, incident cooperation, transparency features and change-management process.

Purpose and role

Ask whether the supplier is a provider, GPAI provider, importer, distributor or another operator, and whether the Romanian entity is a deployer. Retain the product description, role matrix and contract.

Data and outputs

Check what data is processed, where it is stored, whether prompts or outputs train a model, and whether personal data can be isolated. Keep the data-flow map, DPA and security schedule.

Human oversight

Confirm whether the operator can intervene, override, suspend or test the system and whether those limits are communicated. Keep the operating procedure and testing logs.

Incidents and changes

Agree how model changes, outages, security events and regulatory requests are communicated. Keep notice SLAs, version history and audit rights.

Exit and continuity

Plan how the company will retrieve records, delete data and continue operations if the tool is withdrawn or reclassified. Keep the exit and retention plan.

Where the tool is supplied by a group company, the intercompany agreement should be tested in the same way as an external vendor contract. The Romanian entity may need practical access to information even when procurement, model management and security are centralised abroad.

How does the AI Act interact with GDPR and Romanian employment law?

The AI Act does not replace GDPR. Article 2 expressly preserves the application of Union data-protection, privacy and communications rules. A company may therefore need a lawful basis, purpose limitation, data minimisation, transparency, retention controls, processor arrangements, security measures and, where relevant, a data-protection impact assessment in addition to its AI Act analysis.

Workplace deployment adds another layer. If an AI tool ranks applicants, monitors employees, allocates tasks or recommends termination, the employer should consider the Labour Code, anti-discrimination protections, employee information and consultation, internal policies and the safeguards around automated decision-making. A human reviewer is important, but “human in the loop” is not a complete answer if the reviewer simply approves an unexplained score.

For customer-facing systems, consumer-protection and sectoral obligations may also apply. For regulated products, product-safety rules, conformity assessment and technical documentation may interact with the AI Act. The right approach is a combined compliance map that shows which regime addresses which risk.

AI Act

Classifies the system and creates duties tied to the operator role, risk level, transparency, literacy and governance.

GDPR

Controls personal-data processing, individual rights, security, profiling and the relationship between controller and processor.

Employment and sector law

Protects workers, customers and regulated activities through additional information, fairness, safety and challenge requirements.

Who supervises the AI Act in Romania?

Enforcement is shared. The European Commission’s AI Office supervises general-purpose AI providers and certain connected systems, while national competent authorities supervise other AI systems. The European Data Protection Supervisor has a specific role for systems used by EU institutions. The Romanian entity should monitor the national designation and implementation measures relevant to its activity instead of assuming that every question goes to one central EU authority.

The AI Act also allows complaints, investigations, information requests and other enforcement tools. The applicable authority may consider the nature, gravity and duration of an infringement, affected persons, the operator’s size and turnover, cooperation, responsibility, mitigation and whether the conduct was intentional or negligent.

What penalties can apply?

Article 99 sets maximum levels for several categories, while Member States establish the detailed national penalty and enforcement rules. Non-compliance with prohibited practices can reach up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher. Other listed operator obligations, including certain deployer and transparency duties, can reach up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. Incorrect, incomplete or misleading information supplied to authorities can attract a separate maximum of EUR 7.5 million or 1% of worldwide annual turnover.

For SMEs and start-ups, Article 99 provides a lower-of-the-two limits approach for the amounts or percentages referred to in the provision. The figures are maximums, not automatic fines. Authorities must assess the individual circumstances and procedural safeguards remain relevant. Companies should avoid both extremes: treating the maximum as inevitable or assuming that a small local subsidiary has no exposure because the parent owns the technology.

Practical AI Act compliance checklist for a Romanian operation

01 · InventoryBuild the AI register

List systems, vendors, users, business owners, locations, outputs, affected people and group-company relationships. Include pilots and shadow AI.

02 · ClassifyAssign the legal route

Screen scope, prohibited practices, high-risk categories, transparency duties, GPAI dependencies, sector rules and applicable transition dates.

03 · ControlPut safeguards in place

Set access rules, human review, notices, marking, training, procurement controls, incident escalation and data-protection measures.

04 · EvidenceKeep the decision trail

Retain the classification rationale, vendor file, contract, training evidence, approvals, tests, incidents, changes and review date.

Create an inventory

Owner: Legal, IT, procurement and business owners. Output: an AI register with purpose, provider, deployer, data and affected persons.

Approve use cases

Owner: management with legal and security input. Output: a classification note, prohibited-use sign-off and escalation route.

Train users

Owner: HR, compliance and system owners. Output: role-based AI-literacy materials and completion evidence.

Review public outputs

Owner: marketing, communications and editorial owners. Output: a disclosure, marking and human-review record.

Monitor change

Owner: system owner and vendor manager. Output: version, incident, access, performance and reassessment logs.

Common mistakes made by foreign groups

“The parent handles it”

Central governance can help, but the Romanian operation still needs to know its role, local use, affected people and evidence available to it.

“The vendor is compliant”

Vendor compliance material is an input. It does not answer whether the Romanian entity is a deployer, importer or affected operator in the actual workflow.

“The deadline is 2027”

The later high-risk date does not postpone AI literacy, prohibited-practice controls, transparency duties or GDPR and employment-law analysis.

“A human checked it”

A nominal reviewer may not provide meaningful oversight. Define authority to challenge, override, document and stop the system.

“A footer solves labelling”

Website disclosure, user notice and machine-readable marking answer different questions. Match the control to the content and channel.

“Only official AI tools count”

Shadow AI used with company data can create the same confidentiality, data-protection and output risks as an approved platform.

Frequently asked questions

Does the AI Act apply if our parent company is outside the EU?

It may. Scope can arise because the Romanian entity deploys an AI system in the Union or because output from a third-country system is used in the Union. Analyse the actual provider, deployer, importer and output-use roles.

Are AI recruitment tools high-risk from 2 August 2026?

Not necessarily under the current transition timetable. Annex III includes recruitment and worker-management uses, but the Commission currently identifies 2 December 2027 for the selected sensitive high-risk areas after the Digital Omnibus changes. GDPR, employment and anti-discrimination duties can apply earlier.

Must employees disclose every use of ChatGPT or another writing assistant?

No universal AI Act rule requires disclosure of every private drafting step. The right control depends on the system, output, audience, content type, company policy and whether Article 50 applies. The employer should set a clear internal policy for confidential or regulated material.

Is an AI officer mandatory in Romania?

The AI Act does not impose a universal AI-officer title for every company. A foreign group should nevertheless allocate responsibility for inventory, classification, training, procurement, transparency, incidents and regulatory liaison.

Does using a human reviewer remove AI Act and GDPR risk?

No. Meaningful human oversight can be important, but it does not erase the underlying classification, transparency, data-protection, fairness or employment-law analysis. The reviewer must have information, time and authority to challenge the output.

Can we rely entirely on the AI vendor’s compliance statement?

No. Vendor material should be verified against the Romanian workflow, contract, data, users and role allocation. Keep evidence of the questions asked, the answers received and the decision made by the company.

Need to assess AI use in a Romanian business?

A Romanian business lawyer can help map the group structure, classify AI systems, review vendor terms, align GDPR and employment safeguards, and prepare a proportionate evidence file.

Contact Atrium Romanian Lawyers

This page provides general information only and does not constitute legal advice, a legal opinion or the creation of a lawyer-client relationship. Legal solutions depend on the specific facts, systems, contracts and legislation in force at the relevant time.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.