AI vendor contracts in Romania under the EU AI Act and GDPR

AI Vendor Contracts in Romania: EU AI Act and GDPR Clauses

An AI vendor contract should do more than grant access to a platform. It should identify the system and intended use, allocate regulatory roles, control the use of business and personal data, preserve evidence, set performance and security obligations, and provide a workable exit if the supplier, model or law changes.

Key points for companies buying AI services in Romania:

  • Classify the AI use and the parties’ roles before negotiating warranties and liability.
  • Do not assume that a standard SaaS agreement or a GDPR DPA covers AI-specific risk.
  • State whether prompts, files, outputs and usage data may be retained or used for training.
  • Require enough information, logs and cooperation to meet the customer’s own legal duties.
  • Connect service changes, security incidents and regulatory events to notice, remediation and exit rights.

This guide is intended for Romanian companies, foreign groups operating in Romania, technology suppliers, procurement teams and businesses implementing generative or other AI tools. It focuses on contract structure. For the wider regulatory framework, read our EU AI Act guide for foreign companies.

Why does an AI vendor contract need a separate review?

AI services can change after signature. A supplier may replace a model, add a subprocessor, change data-retention settings, modify safety controls or alter the geographic delivery chain. Outputs may also be probabilistic rather than repeatable. These features create risks that are not fully addressed by ordinary clauses on software access, uptime and confidentiality.

The EU AI Act allocates obligations according to the system, risk category and operator role. The GDPR applies in parallel where personal data is processed. The contract cannot transfer away statutory responsibility, but it can secure the information, instructions, evidence and cooperation needed for each party to perform its own obligations.

Practical distinction: the AI Act analysis, the GDPR role analysis and the commercial allocation of risk are related but separate. A supplier described as a “provider” under the AI Act is not automatically a “processor” under the GDPR.

Start with the AI use, not the vendor’s template

Before redlining the agreement, the customer should record what the system will do, whose decisions it will influence, what data enters the system, who receives the output and whether the tool will be integrated into employment, credit, insurance, education, essential services, biometric or other sensitive workflows. The same product can create different legal exposure when deployed for a different purpose.

Contract navigator
Build the AI contract in five connected layers

Select a layer to see the question that should be answered before signature.

System and intended use

Identify the product, model, version, functions, integrations, users, prohibited uses and decision context. Classification begins with the actual deployment.

AI vendor due diligence before contract negotiation

A customer cannot negotiate intelligently without basic information about the service. The due-diligence request should be proportionate to the use and risk, but it commonly covers:

  • the legal entity supplying the service and the entities supporting it;
  • the model or models used, hosting locations and material third-party dependencies;
  • the intended purpose, known limitations and prohibited uses;
  • data sources, retention rules and whether customer data is used for training or improvement;
  • security controls, incident history, business continuity and disaster recovery;
  • testing, accuracy or performance information relevant to the deployment;
  • subcontractors, subprocessors and international data transfers; and
  • the supplier’s process for regulatory requests, complaints, audit evidence and system changes.

For high-risk deployments, the customer may require contractual access to sufficient documentation, instructions, logs and compliance information to enable it to perform its own obligations under the AI Act. The scope of access should reflect the parties’ respective roles and may need to protect the supplier’s trade secrets and intellectual-property rights. The European Commission’s AI Act information page and its AI Act Service Desk are useful starting points, but the contract must still reflect the particular system and transaction.

What if the service relies on a general-purpose AI model?

Where the service relies on a general-purpose AI model, the customer should also consider whether contractual information rights are needed regarding the model provider, model updates, transparency documentation and downstream restrictions affecting the deployment. These provisions should be tailored to the customer’s position in the AI value chain and should not imply that the customer is entitled to the provider’s complete technical documentation.

What clauses should an AI vendor agreement contain?

Contract layerWhat the clause should resolveRisk if unclear
System and permitted useProduct, model, version, functionality, users, integrations, territories, intended purpose and prohibited uses.The service is used outside its tested or agreed purpose.
Regulatory rolesAI Act operator roles, GDPR roles, responsibility matrix and cooperation duties.Each party assumes the other will supply evidence or perform a mandatory task.
Data and trainingPermitted inputs, retention, model training, improvement, isolation, deletion and export.Confidential or personal data is retained or reused beyond the customer’s expectation.
Performance and oversightRelevant metrics, limitations, testing, human review, logs, notices and remediation.Outputs cannot be evaluated, challenged or reconstructed when a problem occurs.
Security and incidentsTechnical measures, vulnerability management, notification triggers, timing and cooperation.The customer learns too late or receives too little information to respond lawfully.
IP and output rightsRights in inputs, outputs, configurations, documentation, feedback and third-party materials.The customer lacks the rights needed for its intended commercial use.
Change controlNotice of model, policy, subprocessor, location and functionality changes, plus testing and objection rights.A compliant deployment becomes materially different during the contract.
Liability and exitWarranties, indemnities, caps, insurance, suspension, termination, transition, export and deletion.The remedy is commercially unusable when the service fails or must be withdrawn.

Click a row, or focus it and press Enter, to highlight one negotiation layer.

1. Define the system, version and intended purpose

The agreement should identify what is actually being supplied. “AI services” is rarely sufficient. The specification should address the model or service version, functions, interfaces, customer environment, authorised users, territories, dependencies and intended use. If classification or performance depends on a specific configuration, that configuration should be documented.

2. Allocate AI Act and GDPR roles separately

The parties should record their assumed roles under the AI Act and set out who provides instructions, documentation, logs, notices and regulatory cooperation. A separate analysis is required under the GDPR. Depending on the facts, the parties may be controller and processor, independent controllers or, in a narrower class of cases, joint controllers.

Where the supplier processes personal data on the customer’s behalf, Article 28 GDPR terms may be required. See our dedicated guide to the Data Processing Agreement in Romania. The DPA should not be treated as the complete AI contract, and the main agreement should not conflict with it.

3. Control prompts, files, outputs and training use

The contract should distinguish customer content, personal data, telemetry, feedback and output. It should state whether each category may be stored, reviewed by humans, used to improve the service or used to train a shared model. Where “no training” is promised, the clause should explain its scope, including whether safety review, abuse monitoring or service analytics remain permitted.

The European Data Protection Board has emphasised that whether an AI model is anonymous must be assessed case by case. A supplier’s assertion that its model is anonymous should therefore be supported by facts rather than accepted as a label. See the EDPB’s summary of Opinion 28/2024.

4. Make performance, limitations and human oversight usable

Conventional uptime metrics do not measure output quality. Depending on the use, the contract may need agreed tests, documented limitations, error reporting, performance monitoring, bias or drift controls, escalation and human-review requirements. The AI Act’s accuracy requirements should not be treated as a guarantee of error-free outputs. Any contractual accuracy or performance commitment should define the relevant task, dataset, test method, threshold and remedy.

5. Require evidence and audit cooperation

The customer may need records to complete an impact assessment, answer a regulator, investigate a complaint or demonstrate human oversight. The agreement should define which information is available, in what format, how quickly and subject to what confidentiality protections. In practice, enterprise suppliers may satisfy some audit requirements through independent certifications, reports and controlled information-sharing mechanisms rather than unrestricted customer audits. Those materials can support due diligence, but they do not automatically answer system-specific questions.

6. Coordinate security and incident notification

Security clauses should address access controls, encryption where appropriate, vulnerability management, segregation, personnel access, business continuity and incident cooperation. Notification should be triggered by defined events and delivered early enough for the customer to meet its own legal and operational duties. Different events may activate different regimes, so a personal-data breach, an incident affecting the AI system and an ordinary service outage should not be collapsed into one undefined term.

7. Address intellectual property and third-party claims

The contract should distinguish rights in customer inputs, supplier technology, configurations, fine-tuning, documentation, feedback and outputs. It should also allocate responsibility for claims involving training material, output, trademarks, confidential information and third-party components. Broad statements that the customer “owns the output” may be insufficient if the supplier cannot grant exclusivity or if protectability depends on applicable law and human contribution. Ownership language should be assessed together with applicable copyright rules, which may require sufficient human authorship for copyright protection.

8. Control subcontractors, subprocessors and model dependencies

An AI service may depend on model providers, cloud infrastructure, safety services and specialist subprocessors. The contract should identify the relevant chain, require notice of material changes and preserve appropriate objection or termination rights. For personal data, the subprocessor mechanism must align with Article 28 GDPR and any applicable international-transfer safeguards.

9. Regulate model and policy changes

Suppliers often reserve broad rights to modify models, acceptable-use policies and technical features. The customer should seek prior notice of material changes, enough information to reassess the deployment and a remedy when a change materially reduces functionality, alters data use, affects compliance or creates an unacceptable risk.

10. Connect liability to the risks that matter

Liability provisions should be read together with warranties, indemnities, insurance and remedies. A general cap may be commercially unsuitable for confidentiality breaches, unlawful data use, IP claims or deliberate misconduct, while unlimited liability for every model error may be unacceptable to a supplier, particularly where outputs remain subject to human review. The negotiated position should reflect control, foreseeability, fees, insurance and the consequences of the intended use.

11. Preserve suspension, termination and transition rights

The contract should explain what happens if the service becomes prohibited, materially non-compliant, insecure or unsuitable for the agreed purpose. Exit terms should cover data and prompt export, configuration records, transition assistance, continuing access where necessary, deletion, certification and surviving confidentiality or audit duties.

12. Align the whole contract suite

The main agreement, order form, specification, DPA, security schedule, service levels and online policies should be checked together. An order of precedence is important where one document allows training while another prohibits it, or where a linked policy can be changed unilaterally. Our broader contract review checklist explains the commercial clauses that remain relevant alongside the AI-specific controls.

Customer and supplier priorities are not identical

A customer usually seeks transparency, stable functionality, control of its data, evidence for compliance and practical exit rights. A supplier needs a defined intended use, customer cooperation, restrictions against misuse, protection for reusable technology and a liability position proportionate to fees and control. A balanced contract should not hide this tension. It should identify which party can prevent, detect and remedy each risk.

Practical experience: how Atrium approaches an AI contract review

A typical client mandate begins with the operating facts, not a generic AI checklist. Atrium Romanian Lawyers first maps the proposed use, data flows, parties, model dependencies and decisions affected by the tool. We then review the full contract suite, identify provisions that do not match the deployment and separate mandatory compliance points from negotiable commercial risk.

The work may include a priority risk report, tracked changes, replacement clauses and a negotiation list for the business and technical teams. Particular attention is given to training rights, confidentiality, GDPR roles, security incidents, documentation, model changes, intellectual property, liability and exit. This section describes our review method and does not disclose any client’s confidential facts.

AI vendor contract checklist before signature

  1. Document the system, intended use, users and decision context.
  2. Complete the AI Act role assessment and determine whether the deployment may involve prohibited, high-risk, transparency or other regulated AI use cases.
  3. Map personal data, confidential information and international transfers.
  4. Collect the main agreement, order, DPA, security schedule and linked policies.
  5. Confirm whether customer data, prompts or outputs may be used for training.
  6. Test whether supplier documentation supports the customer’s compliance duties.
  7. Define relevant performance measures, limitations and human oversight.
  8. Align incident notification with legal and operational deadlines.
  9. Review IP ownership, licences, third-party material and claims.
  10. Control material changes to models, policies, locations and subcontractors.
  11. Model liability for realistic failure scenarios.
  12. Plan suspension, export, transition and deletion before deployment begins.

Frequently asked questions

Does every AI vendor contract need a GDPR DPA?

No. A DPA is required where the factual relationship meets the controller-processor conditions under Article 28 GDPR. Other arrangements may involve independent or joint controllers. The roles should be assessed from the actual processing, not only from the labels in the contract.

Can an AI supplier use customer prompts to train its model?

That depends on the contract, product settings, supplier role, transparency and applicable data-protection and confidentiality rules. The agreement should state clearly which data may be used, for what purpose, for how long and whether an effective opt-out or enterprise isolation applies.

Does an AI Act clause transfer compliance responsibility to the supplier?

No. A contract can allocate tasks, information duties, warranties and remedies, but it cannot remove statutory obligations imposed on a party by law. Each operator should understand and perform the duties attached to its own role.

Should the contract name the underlying AI model?

Usually, the system and relevant dependencies should be described with enough precision to understand what is being supplied. If the supplier may change the underlying model, the contract should address notice, testing, material degradation, data implications and the customer’s available remedies.

Who owns AI-generated output?

The answer depends on the contract, the output, applicable intellectual-property law, human contribution and third-party material. The agreement should distinguish ownership from a licence to use and should address infringement claims and supplier restrictions.

Can a Romanian lawyer review a foreign vendor’s English-language AI contract?

Yes, where the agreement concerns a Romanian company, Romanian operations or applicable EU and Romanian requirements. The scope should identify whether separate advice is needed for clauses governed exclusively by another country’s law.

Negotiating an AI vendor contract connected with Romania?

Atrium Romanian Lawyers assists customers and technology suppliers with AI, SaaS and IT contract review, drafting and negotiation, including GDPR, security, intellectual-property, liability and exit provisions.

Discuss the contract with a Romanian lawyer

Disclaimer: This article provides general information and does not constitute legal advice. The appropriate contract and compliance analysis depends on the system, intended use, data, parties, operator roles, applicable law and complete contract suite.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Data Processing Agreement in Romania for GDPR controller and processor compliance

Data Processing Agreement Romania: GDPR Guide

A data processing agreement is required when a company engages another party to process personal data on its documented instructions. The label used in the commercial contract is not decisive: the parties must first classify their actual GDPR roles, then align the agreement with the service, security model, subprocessor chain and any international transfers.

In brief

For a Romanian or foreign business subject to the General Data Protection Regulation (GDPR), an Article 28 data processing agreement (DPA) is not a generic confidentiality annex. It must describe the processing and impose specific duties on the processor. A processor DPA is not required where the supplier acts as an independent controller, although controller-to-controller data-sharing provisions may still be appropriate; joint controllers need an Article 26 arrangement. If personal data is transferred outside the European Economic Area, the DPA alone does not provide a Chapter V transfer mechanism, even where transfer clauses are integrated into the same contractual document.

When is a data processing agreement required?

The general rule is that a written DPA is required when one party processes personal data on behalf of another party. Article 28 GDPR requires the controller to appoint only processors that provide sufficient guarantees and to govern the processing through a binding contract or other legal act, in writing, including electronically.

The practical starting point is the service, not the supplier’s preferred contract label. Payroll providers, cloud hosting companies, customer-support platforms, outsourced IT administrators, email delivery services and some marketing vendors commonly act as processors because they handle data for purposes defined by their customer. The same vendor may nevertheless be a controller for separate activities, such as its own billing, fraud prevention or legally required records.

Before signing, map each processing activity and ask who decides why the data is processed and who makes the key decisions regarding the means of processing. Certain non-essential practical means may be left to the processor. The European Data Protection Board’s Guidelines 07/2020 on controller and processor concepts are the relevant official interpretative reference.

Role map

Choose the relationship that best describes the processing

Select a card to see the usual document and the main classification test.

Controller and processor: use an Article 28 DPA.

The controller determines the purposes and makes the key decisions regarding the means of processing; the processor handles data on documented instructions and may decide certain non-essential practical means. Describe the service-specific processing and all mandatory Article 28 controls.

RelationshipMain testUsual documentFrequent mistake
Controller–processorThe supplier processes personal data for the customer’s purposes and on its documented instructions.Article 28 DPA, usually attached to the services agreement.Using a one-page confidentiality clause with no processing details or security annex.
Independent controllersEach party determines its own purposes and makes the key decisions regarding the means of its processing.Controller-to-controller data-sharing terms, transparency allocation and lawful-disclosure provisions.Forcing a processor DPA onto a professional adviser or platform acting for its own lawful purposes.
Joint controllersThe parties jointly determine the purposes and key decisions regarding the means of processing.Transparent Article 26 arrangement allocating responsibilities.Calling one party a processor even though both designed the relevant processing.
Mixed rolesThe role changes by processing activity.Activity-specific clauses covering each role.Applying one label to the entire commercial relationship.

What must an Article 28 DPA contain?

A compliant DPA must identify the processing and include every mandatory control listed in Article 28(3) GDPR. It should specify the subject matter and duration, nature and purpose, types of personal data, categories of data subjects, and the controller’s rights and obligations. It must then translate the statutory requirements into workable contractual duties.

Clause control room

Test the operational core of the DPA

Each control needs both contractual wording and evidence that it can work in practice.

Instructions must be documented and specific enough to control use.

Define permitted purposes, operations, users and transfer instructions. The processor must alert the controller if it considers an instruction unlawful.

Mandatory controlWhat the DPA should settleUseful evidence or annex
Documented instructionsPurposes, permitted operations, access, disclosure, locations and transfers; process for changing instructions.Processing schedule, service description, authorised-user model and change log.
ConfidentialityAuthorised personnel must be bound by contractual or statutory confidentiality.Role-based access, confidentiality undertakings and training records.
Article 32 securityMeasures proportionate to the processing risk, not merely “industry standard security”.Technical and organisational measures annex, certifications, test summaries and remediation process.
SubprocessorsPrior specific or general written authorisation, change notice, objection process and equivalent downstream duties.Current subprocessor list, service and country details, due-diligence records and flow-down terms.
AssistanceSupport for data-subject requests and controller obligations under Articles 32–36.Request workflow, responsibility matrix, response contacts and DPIA support process.
End of serviceController’s choice between return and deletion, copy deletion and lawful-retention exceptions.Export format, deletion timetable, backup treatment and deletion certificate.
Information and auditsEvidence needed to demonstrate compliance and a workable audit or inspection mechanism.Audit reports, questionnaires, certification scope, remediation plan and escalation rights.

The European Commission has adopted optional standard contractual clauses for controllers and processors under Article 28. The parties may adopt the 2021/915 standard clauses or negotiate their own Article 28 terms. Where the standard clauses are used, additional clauses should not directly or indirectly contradict them or prejudice the fundamental rights and freedoms of data subjects.

Why a generic security clause is not enough

The security schedule should describe controls that match the actual data, systems and risks. Article 32 GDPR requires appropriate technical and organisational measures, taking account of the state of the art, implementation cost, processing context and risks to individuals. Depending on the service, relevant controls may include encryption, access management, logging, vulnerability management, backups, resilience, testing, staff controls and incident response.

A clause stating only that the supplier will apply “appropriate” or “industry standard” security gives the controller little evidence and may leave important assumptions unresolved. The annex should also distinguish controls included in the standard service from optional configurations that the customer must activate.

How should subprocessors be managed?

A processor cannot appoint a subprocessor without the controller’s prior specific or general written authorisation. Under a general authorisation, the processor must notify intended additions or replacements in time for the controller to object. The processor must impose equivalent data-protection obligations downstream and remains fully liable to the controller for the subprocessor’s performance of those obligations.

The contract should state what information accompanies a change notice, how long the objection window lasts, what constitutes a reasonable objection and what happens if the parties cannot resolve it. A nominal right to object is of limited value if the controller receives only a company name, with no service description, processing location or transfer information.

The European Data Protection Board’s Opinion 22/2024 on processors and subprocessors is an important due-diligence reference. Controllers should be able to identify the entire processing chain, including relevant subprocessors and, where appropriate, further sub-processing layers, and obtain enough information to assess whether sufficient guarantees exist.

Does a DPA cover international data transfers?

No. A DPA regulates processing on behalf of a controller, but the DPA alone does not provide a Chapter V transfer mechanism. If data moves to, or is remotely accessed from, a country outside the European Economic Area, the parties must separately establish whether an adequacy decision or another valid safeguard applies. The relevant Article 28 clauses and transfer safeguards may nevertheless be integrated into a single contractual document.

This distinction is easy to miss because two different EU instruments are commonly called “SCCs”. Commission Decision (EU) 2021/915 concerns standard clauses for the Article 28 controller–processor relationship. Commission Decision (EU) 2021/914 contains standard contractual clauses for transfers to third countries. Where the transfer clauses apply, the parties must select the correct module, complete the annexes and assess the destination-country context and any necessary supplementary measures.

How quickly must a processor report a data breach?

The GDPR requires the processor to notify the controller without undue delay after becoming aware of a personal data breach. The familiar 72-hour period applies to the controller’s notification to the competent supervisory authority where the legal conditions are met; it is not the processor’s default reporting deadline.

The DPA should therefore set a fast contractual notification route that gives the controller time to investigate and decide whether regulatory or data-subject communications are required. It should define the incident contact, initial information, phased updates, evidence preservation, cooperation, remediation and post-incident report. A fixed period can be useful, but it should not dilute the statutory “without undue delay” standard.

For the controller’s incident process, see our practical GDPR data breach guide for Romania.

What should the controller check before signing?

The controller should test both the contract and the processor’s ability to perform it. Article 28 requires sufficient guarantees, so signature alone is not the end of the due-diligence exercise.

  1. Confirm the role for each activity. Separate processor functions from any independent or joint-controller processing.
  2. Map the data and people involved. Record data categories, data subjects, purposes, systems, locations, retention and sensitive-data elements.
  3. Review the mandatory clauses. Check every Article 28 requirement and remove conflicts with the main services agreement.
  4. Test the security annex. Align the written controls with the service configuration and the risk level.
  5. Identify all relevant subprocessors. Verify functions, locations, change procedure, downstream obligations and transfer safeguards.
  6. Plan incidents and rights requests. Agree contacts, response steps, information fields and internal escalation.
  7. Set the exit route. Define return, export, deletion, backups, certification and any lawful retention.
  8. Retain accountability evidence. Keep the assessment, negotiated terms, approvals, notices and review dates.

Illustrative vendor scenarios

These examples are simplified and do not replace a factual role analysis.

SaaS provider hosting a customer database

The Romanian customer decides why client records are stored and how staff use them. The SaaS provider hosts and supports the database on the customer’s instructions. An Article 28 DPA is normally required, together with a security schedule and a review of hosting and support subprocessors.

Professional adviser receiving matter information

A lawyer, auditor or other regulated adviser may independently determine certain purposes and make key decisions regarding the means of processing because of professional duties and legal obligations. It may be incorrect to classify every such activity as processor work. The engagement terms should describe the actual roles and disclosures.

Cloud subprocessor with access outside the EEA

The immediate processor uses a support provider in a third country. The controller–processor DPA remains necessary, but it is not sufficient. The parties must also examine the relevant transfer mechanism, complete the required documentation and assess whether supplementary safeguards are needed.

How should the DPA interact with the main services agreement?

The documents should work as one contract set. The services agreement, DPA, security schedule, service levels and subprocessor information should use consistent definitions, liability rules, notice mechanisms, termination rights and order-of-precedence clauses.

Commercial limits on liability require particular attention. A DPA cannot remove statutory obligations or the rights of data subjects, while the allocation of contractual risk between the parties depends on the negotiated agreement and applicable law. Audit rights also need balance: the controller requires meaningful evidence, but the process should protect the processor’s security, confidentiality and other customers.

For a wider commercial review, use our contract review checklist for Romania. Technology businesses may also find our IT and SaaS contract services relevant.

Frequently asked questions

Is a DPA required with every service provider?

No. It is required where the provider processes personal data on behalf of the controller. An independent controller relationship may require data-sharing terms instead, while joint controllers need an Article 26 arrangement. The correct classification depends on the actual purposes, decision-making and degree of instruction for each processing activity.

Can the DPA be an annex to the services agreement?

Yes. The GDPR requires a binding written contract or other legal act but does not require a separate standalone document. An annex is common and can be efficient, provided the main agreement and DPA are consistent and the processing description, security measures and subprocessor terms are complete.

Does an Article 28 DPA replace international transfer SCCs?

No. The Article 28 relationship and the Chapter V transfer basis are separate legal questions. Commission Decision 2021/915 contains controller–processor clauses, while Decision 2021/914 contains transfer clauses for third-country transfers. Depending on the data flow, both sets of requirements may be relevant.

Must the controller approve every subprocessor?

The processor needs prior specific or general written authorisation. Under general authorisation, the controller must be informed of intended additions or replacements and given an opportunity to object. The DPA should make that process meaningful by defining the notice content, timing, objection grounds and consequences.

Must a processor report a breach within 72 hours?

The processor’s statutory duty is to notify the controller without undue delay after becoming aware of a personal data breach. The 72-hour rule concerns the controller’s notification to the supervisory authority where notification is legally required. The DPA should set an incident process that allows the controller to meet its own deadline.

Can a processor use personal data for its own product improvement?

Only if the relevant role, purpose and legal basis support that use. A processor cannot simply expand its instructions into an independent purpose. If the provider determines its own purpose and makes the key decisions regarding the means of a separate activity, it may act as a controller for that activity and must satisfy the corresponding GDPR duties.

Review the DPA against the real data flow

A targeted legal review can classify the parties’ roles, check the mandatory Article 28 terms, identify transfer issues and align the DPA with the services agreement, security evidence and subprocessor chain.

Discuss a data processing agreement

Disclaimer: This article provides general information and does not constitute legal advice. It reflects the law and official guidance available as of the date of publication. The correct analysis depends on the actual processing activities, contractual roles, data flows, security measures and jurisdictions involved.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Geometric maze illustrating contractual risk assessment during a contract review in Romania

Contract Review in Romania: 12 Clauses to Check

Which contract clauses should a business check before signing?

A Romanian business contract should clearly allocate performance, payment, liability, intellectual-property, data and exit risks. These 12 clauses are the practical starting point for a legal and commercial review.

Contract review in Romania should test more than whether an agreement is formally valid. Before signing, a business should understand what it must deliver, when it will be paid, which losses it may bear, how intellectual property and data may be used, and how the relationship can end.

Commercial contracts are often negotiated under pressure. A supplier is ready to begin, a customer wants the final draft immediately, or a foreign group needs its Romanian operation running without delay. That is precisely when unclear wording, inconsistent annexes and borrowed template clauses are most likely to pass unnoticed. Companies entering the market should connect the contract with the wider steps required to start and operate a business in Romania.

Interconnected architectural structure illustrating how contract clauses work together in a Romanian contract review
A well-structured contract depends on interconnected clauses that allocate obligations, remedies and commercial risks consistently.

Under the Romanian Civil Code, a validly concluded contract is binding on the parties, and contractual negotiations and performance are governed by good faith. A useful review therefore connects the legal wording with the operational deal. It identifies which party controls each risk, whether the agreed remedy can work in practice, and what evidence will be needed if performance is disputed.

The following 12 clauses form a practical checklist for Romanian companies and foreign businesses entering agreements governed by Romanian law or involving a Romanian counterparty.

Parties, capacity and signing authority

The contract should identify the correct legal entities, not merely the brand names used in negotiations. For a Romanian company, check its registered name, registered office, Trade Registry number, fiscal identification code and representative. If a group is involved, establish which entity receives the services, issues invoices, owns the relevant assets and assumes liability.

Signing authority should be verified against the company’s constitutional documents, Trade Registry information, corporate approvals or a power of attorney. A signature block describing someone as a “manager” does not itself resolve whether that person may bind the company for the relevant transaction. The representation rules should be checked against the company’s current Romanian articles of incorporation and the registered powers of its administrators.

The internal authority analysis also matters for potential Romanian company director liability, particularly where a director signs outside approved limits or fails to document a material commercial decision.

Check before signingConfirm the contracting entity, the signatory’s authority, any required corporate approval, the position of affiliates and whether subcontracting or assignment to another group company is permitted.

Scope, deliverables and acceptance

The scope clause should describe the goods or services, specifications, quantities, locations, deadlines, dependencies and exclusions. For project work, it should also establish milestones, acceptance tests, correction periods and a change-control procedure.

Review the main agreement together with proposals, statements of work, order forms and technical annexes. If they conflict, an order-of-precedence clause should determine which document controls. Acceptance by silence should also be tested carefully: specify when the review period begins, what constitutes a valid rejection and what happens when defects are minor. Providers using standard customer documentation should also verify the applicable service contract requirements in Romania.

Common riskThe commercial proposal promises one result, the technical annex describes another and the general conditions allow the supplier to treat delivery as accepted before meaningful testing has taken place.

Price, VAT, invoicing and payment

A complete payment clause states the price or calculation method, currency, VAT treatment, invoicing trigger, payment deadline, supporting documents, bank charges and the procedure for disputing an invoice. It should also explain whether the customer may withhold, deduct or set off amounts and whether the supplier may suspend performance for non-payment.

For B2B transactions, Law no. 72/2013 on late payment contains mandatory protections. Article 5(1) establishes a general 60-calendar-day limit for contractual payment terms between professionals. By exception, the parties may agree a longer payment term, provided that the clause is not abusive under Article 12. A term exceeding 60 days is therefore not automatically invalid, but it should be assessed carefully for gross unfairness to the creditor in light of the statutory criteria and the circumstances of the transaction. Where the applicable conditions are met, late payment can trigger statutory penalty interest and the fixed EUR 40 recovery compensation.

For the calculation rules and available remedies, see our guide to late-payment interest and penalties in Romania.

Term, renewal and minimum commitments

The agreement should state its effective date, initial duration and whether it renews automatically. An automatic renewal clause is not necessarily problematic, but the notice window, notice method and effect of a missed deadline must be clear.

Check minimum purchase commitments, exclusivity, take-or-pay obligations and price changes that continue into a renewal term. Add internal calendar reminders for any deadline that determines whether the company remains bound for another year or loses a renegotiation opportunity.

Check before signingIdentify the earliest exit date, the last date for a non-renewal notice and every financial or operational commitment that survives renewal.

Termination, cure periods and exit assistance

The termination clause should distinguish between serious breach, remediable breach, insolvency-related events, prolonged force majeure and termination for convenience. It should specify whether prior notice is required, how long the defaulting party has to cure, and whether termination operates through a contractual mechanism or requires another legal step.

The Romanian Civil Code regulates remedies for non-performance, including termination under Article 1549 and the related provisions. The contract should not merely say that a party “may terminate immediately”. It should align the grounds, notice mechanics and agreed effects with the type of contract and the intended remedy.

Exit provisions matter just as much as the termination trigger. Address final invoices, transition assistance, return of equipment and documents, data export, deletion, continued licences and the clauses that survive termination.

Penalty clauses and late-payment interest

A penalty clause fixes in advance the consequence of non-performance, defective performance or delay. Under Article 1538 of the Romanian Civil Code, its drafting should identify the protected obligation, the triggering event and the calculation method. The agreement should also state whether a penalty is daily or fixed, whether it is capped and how it interacts with damages and other remedies.

Article 1541 permits a court to reduce a penalty in the statutory circumstances, including where it is manifestly excessive in relation to the loss that the parties could have foreseen when concluding the contract. A high percentage is therefore not a substitute for careful drafting.

Common riskA daily penalty has no cap, applies to several overlapping obligations and continues after termination, creating exposure far beyond the economic value of the contract.

Liability caps, exclusions and indemnities

Liability provisions should allocate risk in proportion to the contract’s value, the parties’ control and the available insurance. Review the general cap, any separate or higher caps, excluded categories of loss, claims procedures and responsibility for employees, affiliates and subcontractors.

Do not assume that an indemnity is a familiar standard clause. It should identify the covered events, third-party claims, control of the defence, settlement authority, notification duties and mitigation. Check whether the limitation of liability applies to the indemnity or whether it creates uncapped exposure.

Any exclusion or limitation must also be tested against mandatory law and the nature of the conduct involved. A clause should not be described as protecting a party against every possible form of unlawful conduct. Where the agreement supports a wider investment or group operation, the liability wording should be reviewed together with the company’s corporate and commercial governance arrangements.

Warranties, regulatory compliance and audit rights

Warranties should be specific to the transaction. Depending on the contract, they may cover conformity with specifications, professional licences, legal compliance, authority, sanctions, anti-bribery, tax status, employment practices, product safety or the absence of third-party rights.

The review should also establish the remedy for an inaccurate warranty. Possible outcomes include correction, replacement, a price adjustment, indemnification or termination. An audit right should define scope, frequency, confidentiality, cost allocation and the treatment of identified non-compliance.

Drafting pointA broad promise to comply with “all applicable laws” may be necessary, but it does not replace transaction-specific duties, evidence requirements and an agreed remediation process.

Force majeure, hardship and change in law

Force majeure and hardship solve different problems. Force majeure concerns an external, unforeseeable, absolutely invincible and unavoidable event under the Civil Code framework. Hardship under Article 1271 addresses an exceptional change that makes performance excessively onerous, subject to the statutory conditions and the allocation of contractual risk.

The clause should define notice, evidence, mitigation, suspension, continued payment obligations and the point at which prolonged disruption permits termination. For regulated or long-term projects, add a change-in-law mechanism explaining who bears new compliance costs and whether price or timing may be adjusted.

Check before signingDo not treat every supplier delay, price increase, staff shortage or market change as force majeure. The clause should distinguish ordinary commercial risk from qualifying events.

Confidentiality and intellectual property

A confidentiality clause should define protected information, permitted use, internal access, legally required disclosures, security standards, duration and return or destruction. Trade-secret protection also depends on practical steps, so access controls and marking procedures should match the contractual wording. A standalone non-disclosure agreement in Romania may be appropriate before sensitive negotiations begin.

For intellectual property, distinguish pre-existing materials from deliverables created under the contract. State whether rights are assigned or licensed and address territory, duration, field of use, sublicensing, modifications, source materials and third-party components.

Romanian Law no. 8/1996 on copyright requires an assignment of economic copyright to specify the transferred rights and, for each, the modes of use, duration, extent and remuneration. A generic sentence stating that the customer “owns everything” may therefore be insufficient for the intended result. Businesses acquiring or licensing valuable assets can obtain a separate review from intellectual property lawyers in Romania.

For ownership arrangements between founders and shareholders, see our guide to shareholder agreements in Romania.

Personal data, security and digital services

If the agreement involves personal data, identify whether each party acts as controller, processor, joint controller or independent controller. When a supplier processes personal data on behalf of a controller, Article 28 of the General Data Protection Regulation requires a contract containing specified safeguards. Our GDPR compliance checklist for Romanian companies explains the wider governance controls that should support those clauses.

Review processing instructions, confidentiality, security measures, subprocessors, assistance with data-subject requests, breach notification, international transfers, audit rights and return or deletion. The commercial agreement and data processing agreement should not contain inconsistent liability, notice or termination rules. More complex vendor arrangements may require assistance from GDPR and data protection lawyers in Romania.

For SaaS and other digital services, also check availability commitments, backups, recovery objectives, vulnerability management, incident cooperation, data portability and access after termination. Technology businesses should align these provisions with their wider technology and digital law obligations and, where relevant, obtain a focused IT and software contract review.

Governing law, jurisdiction and notices

In cross-border contracts, governing law and forum are separate questions. The Rome I Regulation generally allows the parties to choose the law governing their contractual obligations, subject to its safeguards and mandatory rules. The Brussels I bis Regulation governs jurisdiction and the recognition and enforcement of judgments in relevant EU civil and commercial matters.

Consider whether the selected court or arbitral tribunal is proportionate to the likely dispute, where evidence and assets are located, the language and cost of proceedings, and whether an eventual judgment or award can be enforced efficiently.

The notice clause should identify valid addresses, permitted delivery methods, deemed receipt and the process for updating contact details. A termination or claim notice sent to the commercial contact may fail if the contract requires delivery to a different address or by a specific method. Where non-payment is already a concern, the agreement should be tested against the available legal recovery options for unpaid invoices in Romania.

Contract review in Romania: risk map

Contract areaQuestion to answerRisk if unclear
AuthorityIs the correct entity bound by an authorised person?Enforceability, approval and group-liability disputes.
PerformanceWhat exactly must be delivered, tested and accepted?Disputes over completion, defects and payment.
PaymentWhen is money due and what follows from delay?Cash-flow loss, penalties and invoice disputes.
ExitHow can the relationship end and what survives?Lock-in, service interruption and lost data.
LiabilityWhich losses are covered, capped or excluded?Exposure disproportionate to contract value.
IP and dataWho owns or may use assets, information and data?Loss of rights, GDPR exposure and operational dependency.
DisputesWhich law, forum and notice rules apply?Unexpected cost and difficult enforcement.

A practical pre-signing review process

Confirm the commercial dealRecord the intended result, price, timeline and points already agreed before editing legal language.
Read every contract documentReview the agreement, annexes, order forms, proposals, policies and incorporated online terms together.
Rank the risksSeparate legal defects, high-value commercial exposure, operational ambiguity and points that are negotiable preferences.
Propose usable wordingConvert each material issue into a replacement clause, tracked change or clear negotiation question.
Check signing and evidenceConfirm authority, approvals, signature method, final attachments and preservation of the executed version.
Calendar post-signing dutiesTrack notices, renewals, price reviews, certificates, audits and delivery or payment milestones.

Need a Romanian contract reviewed before signing?

Atrium Romanian Lawyers assists Romanian and foreign businesses with contract review, drafting and negotiation. The review can be delivered as tracked changes, replacement clauses, a consolidated draft or a practical risk report adapted to your position in the transaction.

Frequently asked questions

Is a business contract written in English valid in Romania?

Romanian companies can generally conclude commercial contracts in English. The transaction may nevertheless require Romanian-language documents or translations for authorities, courts, employees, consumers, notaries or regulated formalities. The governing-language clause should state which version prevails if the contract is bilingual.

Can a foreign-law contract be used with a Romanian company?

Potentially, yes. In a cross-border contract, the parties may often choose the governing law, but the Rome I framework, mandatory rules, the place of performance and the practical enforcement route must be considered. Choosing foreign law does not automatically remove every Romanian mandatory provision relevant to the transaction.

Are contractual penalties enforceable in Romania?

Romanian law recognises penalty clauses, but the obligation, trigger and calculation must be clear. Article 1541 of the Civil Code permits judicial reduction in the statutory circumstances, including a penalty that is manifestly excessive compared with the foreseeable loss at contract formation.

When should contract review in Romania take place?

Ideally before signing and before the commercial position becomes difficult to change. A new review is also appropriate before renewal, when the scope or price changes, when a party proposes an amendment, or when performance problems and a possible dispute emerge.

What should a foreign company send to the reviewing lawyer?

Send the complete draft and annexes, the commercial proposal, your role in the transaction, the applicable deadline, the principal business concerns and any terms already agreed. Identifying whether you are the customer, supplier, licensor, employer, investor or distributor changes the risk analysis.

Disclaimer: This article provides general legal information and does not constitute legal, tax or commercial advice. Contractual rights and risks depend on the complete document, the transaction, the parties, mandatory rules and the relevant facts.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Romanian company director liability and corporate governance risk assessment

Romanian Company Director Liability: Duties and Risks

When can Romanian company director liability arise?

The company is a separate legal person, but that shield is not absolute. A director may face personal exposure for breach of corporate duties, insolvency misconduct, bad-faith tax conduct, a personal guarantee or other unlawful acts.

COMPANYSEPARATE LEGAL PERSONLiability shield BREACH OF DUTYloss + causationINSOLVENCYArticle 169 conductTAX LIABILITYbad-faith conductPERSONAL GUARANTEEcontractual exposure AI-generated illustration

Romanian company director liability does not arise automatically from the company’s debts. Personal liability requires a separate legal basis, such as a damaging breach of the director’s mandate or statutory duties, conduct that contributed to insolvency, bad-faith conduct connected with unpaid taxes, or a personal contractual commitment. Foreign directors should verify their registered powers, keep an evidence trail for material decisions and escalate financial distress early.

Accepting a director appointment in Romania is more than an administrative formality. Understanding Romanian company director liability requires reviewing both the legal mandate and the director’s actual decision-making role. The director may represent the company, commit it contractually, manage assets and supervise accounting, tax, employment and regulatory processes. Those powers carry duties to the company under the articles of association, shareholder resolutions, the rules on mandate and Romanian company law.

The exact framework depends on the company form and governance structure. The Romanian term administrator may refer to an administrator of a limited liability company (SRL) or a member of the board of directors of a joint-stock company (SA). An SA may also use a two-tier system with a management board and supervisory board. The appointment document and the articles of association should therefore be read before applying any general rule.

Is a Romanian company director personally liable for company debts?

Generally, no. An ordinary supplier, landlord or lender claim is normally against the company. The director becomes personally exposed only where the creditor or another claimant can rely on a distinct statutory, contractual or delictual basis and prove the elements required for that route.

This distinction matters. A company’s inability to pay does not, by itself, transfer every unpaid invoice to its director. Equally, the words “limited liability” do not protect a director from consequences of their own conduct.

SituationUsual starting pointPotential director exposure
Ordinary commercial debtThe company is the contracting party and primary debtor.No automatic personal liability merely because the company does not pay.
Breach of mandate or company-law dutyThe company may have suffered loss through the director’s act or omission.Liability may arise if breach, damage and causation are established under the applicable rules.
Insolvency misconductThe company enters insolvency with unpaid liabilities.The insolvency court may order persons who contributed to insolvency through conduct listed in Article 169 to bear part or all of the liabilities, within the causally connected loss.
Unpaid tax obligationsThe company remains the tax debtor.Joint liability may be established in the bad-faith situations listed in Article 25 of the Fiscal Procedure Code.
Personal guaranteeThe company receives finance, a lease or credit.The director may be liable under the separate guarantee they signed, according to its terms.
Separate unlawful actThe director acts personally as well as for the company.Civil, administrative or criminal consequences may apply depending on the specific act and statute.

Do not confuse shareholder liability with director liability. A shareholder’s exposure as an investor and a director’s exposure as a manager are different questions. One person may hold both roles, but each potential claim needs its own legal basis.

What are the core duties of a Romanian company director?

Articles 72 and 73 of Romanian Companies Law no. 31/1990 connect administrators’ obligations and liability to the rules on mandate and the special provisions of the Companies Law. They also identify responsibility toward the company for matters including the reality of capital contributions, the actual existence of distributed dividends, legally required registers, implementation of shareholder resolutions and strict performance of duties imposed by law and the articles of association.

Duty areaPractical meaningUseful evidence
Act within authorityFollow the law, articles of association, appointment terms and valid shareholder or board resolutions.Current constitutional documents, authority matrix, registered representation powers and written approvals.
Protect company interestsUse management powers for the company rather than for an undisclosed personal or third-party benefit.Conflict disclosures, abstentions, independent valuations and documented commercial rationale.
Make informed decisionsObtain information proportionate to the value, urgency and risk of the decision.Board packs, forecasts, legal and financial advice, alternatives considered and minutes.
Supervise records and complianceEnsure required registers and accounting records exist and that delegated functions are reasonably monitored.Compliance calendar, management reports, tax confirmations, audit trails and escalation logs.
Implement corporate decisionsCarry out valid shareholder decisions accurately and within the company’s legal powers.Signed resolutions, implementation plans, filings and completion records.
Preserve confidentialityProtect confidential information and business secrets during and, where applicable, after the mandate.Access controls, confidentiality undertakings and documented return or deletion of company information.

For SA board members, Article 1441 of Romanian Companies Law no. 31/1990 expressly requires prudence and diligence of a good administrator, loyalty in the company’s interest and confidentiality. It also recognises an informed-business-decision protection where the director was reasonably entitled to believe that the decision served the company and relied on adequate information. That provision should not be copied mechanically into an SRL analysis; the SRL’s own statutory rules, mandate and constitutional documents must be assessed.

Decision record

A defensible director decision has four layers

1AUTHORITYWho may decide?Which approval?2INFORMATIONFacts and forecastsProfessional advice3CONFLICTSDisclose interestsManage participation4MINUTESRationale and voteActions and follow-up AI-generated illustration
The file should show how the decision was authorised, informed, conflict-checked and implemented—not merely its eventual outcome.

How do SRL and SA director duties differ?

An SRL is usually managed by one or more administrators appointed through the articles of association or by the shareholders. Article 197 contains SRL-specific administration rules and refers expressly to Articles 75, 76, 77(1) and 79. Articles 72 and 73 remain central to the mandate-based duties and liability framework, but the articles of association are also essential because they define individual or joint representation, reserved matters, term of office and internal approval limits.

An SA has a more prescriptive governance framework. In the one-tier system, a board of directors may delegate management to directors; in the two-tier system, the management board operates under a supervisory board. Duties, delegation, conflicts, meeting procedure and the mechanics of corporate liability actions can therefore differ materially from an SRL.

Foreign group policy is not enough. A director of a Romanian subsidiary must apply the subsidiary’s Romanian-law documents and duties. Instructions from the parent company, investor or beneficial owner do not automatically excuse an act outside authority or against the Romanian company’s interests.

Before accepting or using the mandate, confirm the director provisions in the Romanian articles of incorporation. Where governance rights are also allocated between investors, coordinate those documents with the shareholder agreement while recognising that a private agreement does not replace mandatory corporate rules or Trade Register formalities.

When can the company claim against a director?

A corporate claim typically focuses on whether the director breached an applicable duty and caused quantifiable loss to the company. The decision and representation mechanics depend on the company form, the alleged conduct and the applicable articles of the Companies Law. Article 155 contains the general-meeting mechanism for an SA action against directors for damage caused to the company through breach of their duties.

Approval by shareholders should not be treated as a universal release. The legal effect depends on what was disclosed, the nature of the decision, the company form, mandatory law, third-party rights and whether the approving body had authority. A director should still require accurate materials and record concerns.

Unauthorised transaction

A director signs beyond registered or internal powers and the company suffers loss. Liability, enforceability and internal recourse require separate analysis of the authority documents and third-party circumstances.

Related-party benefit

Company assets or opportunities are directed to a connected party without transparent approval, adequate information or defensible commercial terms.

Ignored compliance warning

Management receives a specific accounting, tax or regulatory warning but takes no proportionate action, allowing avoidable loss to increase.

When can insolvency create personal exposure?

Financial distress is a critical turning point. Article 66 of Romanian Insolvency Law no. 85/2014 generally requires an insolvent debtor to apply to the tribunal within a maximum of 30 days from the onset of insolvency, subject to the statute’s rules for good-faith restructuring negotiations. The competent tax authority must be notified of the intended insolvency application 15 days before filing, and proof of that notification must be attached to the application. A legal entity’s application is signed by the persons authorised to represent it under its constitutional documents; a shareholder resolution is not required by Article 66(5).

Under Article 169, the insolvency court may order management or supervisory members, any individual or legal entity exercising control over the debtor’s financial or operational decisions regardless of formal title, and other persons who contributed to insolvency through listed conduct to bear part or all of the debtor’s liabilities, without exceeding the loss causally connected to that conduct.

Article 169 risk categoryExamples of evidence reviewed
Using company assets or credit for personal or third-party benefitRelated-party payments, asset transfers, undocumented loans and non-commercial terms.
Conducting personal business under cover of the companyRevenue diversion, overlapping contracts, beneficial ownership and use of company resources.
Continuing activity in personal interest when cessation of payments was clearly approachingCash-flow forecasts, creditor ageing, director benefits and the rationale for continued trading.
Fictitious, unlawful or missing accountingLedgers, source documents, backups, handover records and access to accounting systems.
Diverting or concealing assets, or fictitiously increasing liabilitiesAsset registers, disposals, inventory movements, invoices and connected-party balances.
Transferring assets or a significant part of the business to a closely related personTransfers made while the debtor is in financial difficulty, compliance with Article 73(2¹) of the Companies Law, the relationship between the parties, continuation of the business through the new entity and evidence of an intention to shield assets from creditors.
Ruinous financing used to delay cessation of paymentsPricing, security, repayment prospects, alternatives considered and decision minutes.
Preferential payment to one creditor shortly before cessationPayment sequence, creditor relationship, maturity dates and justification.
Other intentional conduct contributing to insolvencyThe specific act, intent, resulting loss and causal connection to insolvency.

Law no. 239/2025 inserted Article 169(1)(e1), which specifically targets the transfer of assets or a significant part of the business of a debtor in financial difficulty to a person closely related to the debtor, where the obligations imposed by Article 73(21) of the Companies Law are breached and the transfer is intended to continue the activity through the new entity while shielding assets from the debtor’s creditors.

A final Article 169 liability judgment now has consequences beyond the payment order. Under Article 169(10), the person may not be appointed as a company administrator and, if already serving as an administrator elsewhere, loses that right for 10 years from the date the judgment becomes final. The person is also barred for 5 years from founding companies or acquiring a controlling participation in a new company.

Distress response

The evidence trail becomes more important as liquidity deteriorates

1MONITORCash and arrears2VERIFYSolvency status3ADVISELegal and financial4DECIDERestructure or file5PRESERVERecords and handoverAI-generated illustration
Early monitoring and documented advice help directors distinguish temporary pressure from statutory insolvency and respond within the applicable deadline.

Failure to hand over accounting records can create a rebuttable presumption of fault and causation under Article 169. For collegial management or supervisory bodies, a member who opposed the relevant act and recorded the opposition may have a specific defence under Article 169(5). A silent disagreement is therefore much weaker than a properly documented one.

When can a director become jointly liable for Romanian tax debts?

Article 25 of Romanian Fiscal Procedure Code no. 207/2015 creates specific joint-liability routes for overdue tax obligations. They are not triggered merely by holding office. The relevant provisions require the statutory circumstances and, for the principal director-related routes, bad faith.

Potential cases include administrators or other persons who, in bad faith:

  • caused the debtor’s insolvency by transferring or concealing its assets;
  • failed during their mandate to request the opening of insolvency proceedings for tax obligations from that period that remained unpaid when insolvency was declared;
  • caused the non-declaration or non-payment at maturity of tax obligations;
  • caused an unjustified tax refund or reimbursement; or
  • caused tax debts to accumulate and prevented their payment in the circumstances covered by Article 25(21).

A tax assessment against the company and a decision establishing the director’s joint liability are different acts. The facts, legal basis, procedural steps and challenge deadlines should be reviewed immediately when a director receives a Romanian tax notice.

Can delegation, resignation or shareholder instructions remove liability?

Delegation

Delegating finance, tax or operations does not necessarily eliminate a director’s own supervision duties. The appropriate level of oversight depends on the company form, governance structure, importance of the function, warning signs and the director’s legal powers. A clear written delegation and regular reporting are stronger than an informal assumption that “the accountant handles it.”

Resignation

Resignation can end future management authority once effective and properly implemented, but it does not erase possible liability for earlier acts or omissions. The director should document the handover, return company property, preserve relevant records and ensure required Trade Register formalities are handled.

Shareholder or parent-company instructions

A shareholder instruction does not automatically legalise conduct that breaches mandatory law or the director’s duties to the Romanian company. Material instructions should be checked against reserved matters, representation rules, corporate benefit, conflicts and insolvency considerations.

Directors’ and officers’ insurance

D&O insurance may fund defence costs or certain covered claims, but wording, exclusions, notification duties, deductibles and Romanian mandatory law matter. It cannot be assumed to cover fraud, intentional misconduct, all tax exposure, fines or every insolvency claim.

Practical checklist for foreign directors of Romanian companies

  1. Verify the mandate. Obtain the current articles of association, appointment decision and Trade Register extract.
  2. Map authority. Distinguish individual representation, joint signatures, shareholder reserved matters and internal approval thresholds.
  3. Build a reporting pack. Receive timely cash-flow, tax, accounting, litigation, employment and regulatory information.
  4. Document material decisions. Record information reviewed, options, conflicts, rationale, vote and follow-up responsibility.
  5. Control related-party dealings. Disclose interests and obtain the approvals and supporting valuation appropriate to the transaction.
  6. Supervise filings and records. Use a compliance calendar and require evidence of submission and payment—not verbal confirmation alone.
  7. Escalate warnings. Investigate missed tax payments, unpaid salaries, creditor enforcement, deteriorating liquidity and missing records promptly.
  8. Record disagreement. Use the legally appropriate board record and written notification; do not rely on an informal objection.
  9. Assess distress early. Seek Romanian insolvency and tax advice before the statutory filing window is lost, allow for the 15-day advance tax-authority notification and scrutinise transfers to closely related persons.
  10. Plan the exit. Coordinate resignation, handover, registrations, access removal, record preservation and insurance notification.

The bottom line

Romanian company director liability is conduct-based, not an automatic consequence of a company debt. The strongest protection is disciplined governance: understand the mandate, obtain adequate information, act within authority and in the company’s interest, manage conflicts, preserve reliable records and respond quickly to tax or insolvency warning signs.

Foreign directors should not wait for a dispute to reconstruct the decision process. A focused Romanian-law governance review can identify gaps in signing authority, reserved matters, minutes, compliance reporting and distress procedures before they create personal exposure.

Frequently asked questions

Is an SRL administrator automatically liable for the company’s unpaid debts?

No. The SRL is normally the debtor. Personal liability requires a separate legal or contractual basis, such as breach of the administrator’s duties causing loss, Article 169 insolvency conduct, Article 25 bad-faith tax conduct or a personal guarantee.

Does being a shareholder change a director’s liability?

Shareholder and director exposure are separate. A person who holds both roles may face different claims in each capacity, but liability must be analysed under the legal basis applicable to that role and conduct.

Can shareholder approval protect a Romanian director?

Approval can be relevant, but it is not a universal defence. Its effect depends on the company form, authority of the approving body, quality of disclosure, mandatory law, third-party rights and the conduct involved.

Does resignation end a director’s potential liability?

Resignation can end future authority once effective, but it does not erase potential liability for earlier conduct. Proper handover, registration, preservation of records and insurance notification remain important.

What should a director do if they disagree with a board decision?

Obtain advice on the correct procedure, state the reasons clearly and ensure the opposition is recorded and notified in the form required by the applicable governance rules. This is particularly important for collegial bodies and insolvency-related decisions.

Can D&O insurance eliminate personal liability?

No. It may cover certain defence costs and claims, but policy terms, exclusions, notice requirements and mandatory law apply. Fraud, intentional conduct, fines, tax exposure and insolvency claims may be excluded or limited.

Disclaimer: This article provides general legal information and does not constitute legal, tax or insolvency advice. Director duties and liability depend on the company form, constitutional documents, appointment terms, decision-making process, actual conduct and the law applicable to the specific facts.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.

Romanian lawyer reviewing employee and independent contractor arrangements with business clients

Employee vs Contractor in Romania: Legal Risks

Employee or independent contractor in Romania?

Foreign companies must match the contract to the way the work will actually be organised. Romanian employment and tax rules look beyond labels, invoices and foreign templates when control, integration and commercial independence point in another direction.

Individual Employment Labour Code Article 10 Subordination & Authority Mandatory Protections Payroll & Social Security B2B Services Agreement Fiscal Code Article 7 4-of-7 Independence Test Commercial Autonomy Own Risk & Deliverables VS Romanian Substance-Over-Form Legal Review

A company cannot turn an employee into an independent contractor simply by changing the contract title. Romanian authorities and courts may examine how the relationship works in practice: who controls the schedule, location and method of work, whether the individual may serve other clients, who bears commercial risk and whose resources are used. Before engaging a Romanian contractor, foreign companies should test both the written terms and the operating model, document genuine independence and correct any inconsistent practices.

Hiring an individual in Romania requires an early classification decision. The company must determine whether it needs an employee working under its authority or an independent provider responsible for delivering agreed services through their own business activity.

This distinction affects much more than the contract label. It can determine employment protections, payroll and social-contribution treatment, working-time controls, termination requirements and the allocation of commercial risk. A foreign template describing someone as a “consultant” or “independent contractor” will not resolve those questions if the day-to-day relationship operates like employment.

Can the parties simply choose employee or contractor status?

No. The parties may choose a contractual structure, but that structure must match the legal and economic reality of the work. A services agreement cannot safely replace an employment contract where the individual is, in substance, working under the company’s authority and direction.

Romanian law approaches classification from more than one direction. The Romanian Labour Code defines an individual employment contract through work performed for and under the authority of an employer in return for remuneration. Separately, the Romanian Fiscal Code defines independent activity through a statutory set of criteria and allows the tax authorities to reclassify a transaction or activity so that its tax treatment reflects its economic substance.

The practical assessment therefore has two connected parts:

  1. Contractual structure: what rights, duties, control mechanisms and risks the documents create.
  2. Operational reality: how managers and the individual actually organise and perform the work.

Risk: A carefully drafted contractor agreement can still be undermined by daily instructions, fixed attendance, manager approval of absences, exclusivity, company-controlled tools or treatment identical to employees.

What is the practical difference between an employee and an independent contractor?

Decision factorEmployeeIndependent contractor
Legal relationshipPerforms work under an individual employment contract.Provides defined services under a civil or commercial agreement.
Direction and controlWorks for and under the authority of the employer.Controls the method and organisation of the service, subject to agreed deliverables.
Schedule and locationNormally follows contractual and employer-established working arrangements.Should have meaningful freedom to choose when, where and how the service is performed.
Commercial riskThe employer bears the business risk and owes the agreed salary.The provider assumes genuine risks linked to cost, performance and organisation.
Other clientsMay have other employment, subject to working-time, conflict and incompatibility rules.Should be free in substance to offer services to several clients.
Tools and resourcesWork is commonly performed with employer-provided systems and resources.The provider ordinarily uses or organises their own professional resources.
Statutory protectionsReceives the mandatory protections attached to employment status.Relies primarily on the services agreement and the law governing that agreement.
Ending the relationshipTermination must follow the applicable employment route and mandatory safeguards.Termination follows the contract and applicable civil or commercial rules.
Legal Matrix

The Workforce Classification Spectrum in Romania

Full Subordination • Mandatory daily working hours • Supervised work execution • Integrated into staff hierarchy ➔ Individual Employment (CIM) Gray / Misclassified Zone • Invoiced through PFA / SRL • But 100% exclusive dedication • Fixed salary-like retainers ⚠ High Reclassification Risk Commercial Autonomy • Freedom of place & schedule • Result/deliverable-based • Multi-client portfolio & risk ✓ Lawful B2B Contractor EMPLOYEE (CIM) SUBSTANCE OVER FORM INDEPENDENT (B2B)
Figure 1: The operational spectrum used by Romanian Labour & Tax authorities to assess workforce relationships.

No single row decides the classification. The correct conclusion depends on the relationship as a whole. For example, a contractor may need access to a client’s secure systems without becoming an employee. Conversely, issuing invoices through a registered business does not by itself prove independence if the individual remains subject to employee-like control.

What does Romanian employment law treat as employment?

The central employment indicator is subordination: the individual performs work for and under the authority of the employer in return for remuneration. The company’s control over the person, not merely its right to accept a deliverable, is particularly important.

Article 10 of the Labour Code defines the individual employment contract as the agreement under which an individual undertakes to perform work for and under the authority of an employer in exchange for remuneration. This is different from a genuine customer-provider relationship, where the customer specifies the expected result but does not manage the provider as part of its workforce.

Where the facts point to employment, our employment lawyers in Romania can review the proposed contract, workplace controls and onboarding documents before work begins.

For employment, the contract must be concluded in writing, in Romanian, no later than the day before the employee starts work. The employer must also complete the required employee-register formalities before work begins. The Romanian Labour Inspectorate confirms these requirements in its official employment-contract guidance.

Operational indicators that may point towards employment include:

  • a manager determines the individual’s daily or weekly schedule;
  • attendance at a company location or continuous online availability is mandatory;
  • the individual receives detailed instructions about how work must be performed;
  • absences require permission rather than coordination of deliverables;
  • performance is managed through the same hierarchy and procedures used for employees;
  • the individual is presented internally or externally as a member of staff;
  • the role is personal and the individual cannot use collaborators or substitutes;
  • the individual bears little or no genuine commercial risk.

These are indicators, not an automatic checklist. The nature of the work, regulatory requirements, information security and customer obligations may justify some controls. The question is whether those controls preserve an independent business relationship or place the individual under employer-like authority.

When does the Fiscal Code recognise an independent activity?

Under Article 7 of the Fiscal Code, an activity performed by an individual for income is independent when at least four of seven statutory criteria are met. The evidence should show that those criteria operate in practice, not only that they were copied into the contract.

Fiscal Code criterionPractical evidence to examine
1. Freedom over place, method and scheduleThe provider plans performance independently and is not assigned employee attendance hours.
2. Freedom to work for several clientsThe contract permits other clients and the operational model does not make that freedom artificial.
3. Assumption of inherent business riskThe provider bears relevant costs, rectification duties or other genuine performance risks.
4. Use of the individual’s own assetsThe provider uses or arranges professional equipment, software, workspace or other business resources where appropriate.
5. Use of intellectual or physical capacityThe service depends on the provider’s own professional expertise or performance.
6. Membership of a regulated professional bodyThe activity is carried out within a legally regulated profession, where applicable.
7. Freedom to perform directly, with staff or collaboratorsThe provider may lawfully organise delivery personally or through employees or collaborators, subject to justified qualification and confidentiality requirements.
Statutory Rule

Romanian Fiscal Code Article 7: The 4-of-7 Independence Test

1 Autonomy Place, method & schedule 2 Multiple Clients Substantive freedom to serve 3 Commercial Risk Inherent business risk borne 4 Own Assets / Tools Equipment, premises, licenses 5 Capacity & Skill Own professional expertise 6 Professional Body Regulated trade or guild 7 Criterion 7: Delegation & Substitutes Lawful freedom to perform directly or via staff/collaborators MINIMUM 4 REQUIRED to satisfy Fiscal Code Art. 7
Figure 2: The 7 statutory criteria under Romanian Fiscal Code Art. 7. At least 4 must be satisfied and backed by operational proof.

Practical tip: Build a short evidence file for each material contractor relationship. Keep the agreement, scope of work, invoices, deliverable records and evidence of independent organisation together. A clause is stronger when the working record supports it.

Are four fiscal criteria enough to eliminate employment risk?

Not necessarily. The four-of-seven test defines independent activity for Romanian tax purposes, but it should not be treated as permission to reproduce an employment relationship through a services contract.

The tax and employment analyses overlap, particularly around control, business risk and operational autonomy, but they do not perform exactly the same function. The Labour Code focuses on work performed under employer authority. The Fiscal Code focuses on the conditions for independent activity and the correct tax treatment of economic substance.

Article 11 of the Fiscal Code allows the tax authorities to disregard a transaction without economic purpose or reclassify the form of a transaction or activity to reflect its economic content. The authority must explain the relevant facts and evidence supporting the reclassification. This makes consistent documentation important, but it also means that documentation must reflect reality.

European Union case law follows a similar substance-based approach for EU-law concepts of “worker”. In Yodel Delivery Network, Case C-692/19, the Court of Justice explained that an “independent contractor” label does not prevent worker classification where independence is merely notional. Relevant considerations included control over time, place and content of work, exposure to commercial risk, integration into the undertaking and freedom to use substitutes or serve third parties.

Which arrangements create the highest misclassification risk?

Fixed employee-style availability

The contractor must work the company’s standard hours, remain continuously available and obtain approval for any absence, regardless of deliverables.

Control over method, not only result

A company manager allocates daily tasks, prescribes the precise working method and continuously supervises the individual in the same way as employees.

Artificial freedom to serve other clients

The agreement permits other clients, but workload, exclusivity expectations or availability requirements make that freedom unrealistic.

No meaningful business risk

The individual receives a fixed recurring amount, bears no relevant costs or correction obligations and is paid regardless of the agreed output.

Full integration into the organisation

The contractor has an internal job title, reports through the employee hierarchy, appears in staff structures and is evaluated under employee procedures.

A recurring monthly fee, a long relationship, one important client or use of a customer system is not automatically decisive. Each fact must be assessed in context. Risk rises when several employee-like elements combine and genuine commercial independence becomes difficult to demonstrate.

What can happen after a misclassification finding?

A misclassification finding can open separate tax, employment, social-contribution and contractual questions. The precise exposure depends on who makes the finding, the period reviewed, the parties involved and the evidence.

Tax and social-contribution exposure

The tax authority may reassess the economic substance of the activity and determine the related tax and contribution consequences. Historic treatment, payment records, filings and the allocation of responsibility between the parties must be reviewed before quantifying any exposure.

Employment rights and claims

An individual may argue that the factual relationship was employment and seek rights associated with employee status. Questions may arise concerning remuneration, working time, leave, termination, employee records and other mandatory protections. The outcome depends on the legal route and the evidence, not on the contract title alone.

Inspection and document risk

Where work has in substance been performed as employment without the required employment formalities, the company may face labour-inspection consequences. Specific sanctions should be assessed against the law in force and the facts at the date of the review.

Commercial and transaction risk

Misclassification can affect due diligence, financing, investment or an acquisition. A buyer may ask for the contractor population, templates, tax treatment, intellectual-property arrangements and potential historic liabilities to be reviewed before closing.

Intellectual property and confidentiality

The company should not assume that an employment-style intellectual-property position automatically applies to an independent provider. Ownership, assignment, permitted use, confidentiality and return or deletion of information should be dealt with expressly and consistently with the actual relationship.

Does contracting through a PFA or an SRL remove the risk?

No business form provides an automatic safe harbour. It may change the contractual and tax analysis, but the parties should still examine who performs the service, how the relationship operates and whether the structure has genuine commercial substance.

A Romanian authorised individual enterprise, commonly referred to as a PFA, is closely connected to the individual providing the activity. An SRL is a separate legal entity, which may employ staff, assume business risks and organise delivery through its own resources. Those differences matter, but neither registration document should replace a factual review.

If the supplier structure is still being established, the practical differences should also be considered alongside our guidance on company formation in Romania for foreign founders.

For an SRL supplier, examine whether the supplier is genuinely providing a business service or whether one individual is effectively inserted into the customer’s organisation under continuous personal control. For a PFA, test the statutory independence criteria directly and retain evidence supporting them.

Foreign companies should also avoid importing assumptions from their home jurisdiction. A worker physically performing activity in Romania may trigger Romanian employment, tax, social-security, registration or permanent-establishment questions. Those cross-border issues require a separate review based on the company, worker, location and duration of the arrangement.

Related structures may require a different analysis. Our guide to dual employment in Romania explains the rules applicable when an individual holds more than one employment contract, while the guide to service contract requirements in Romania covers the clauses and compliance points relevant to genuine service relationships.

Three illustrative classification scenarios

Scenario 1: project-based software specialist

A specialist agrees to deliver defined software modules, chooses the working schedule and location, uses their own business equipment, serves several clients and may use qualified collaborators. The customer controls security standards, acceptance criteria and deadlines but not the specialist’s daily organisation.

Assessment: These facts support independence, subject to the complete contract, tax position and actual implementation.

Scenario 2: “consultant” managed as staff

An individual works from 09:00 to 18:00, reports daily to a department manager, needs approval for time off, uses only company equipment, appears on the internal organisation chart and cannot accept other clients.

Assessment: The contractor label is difficult to reconcile with the operational indicators of subordination and workforce integration.

Scenario 3: regulated client environment

An external professional must work through the customer’s secure system and attend specific meetings because of regulatory and information-security requirements. The professional otherwise decides how to perform the mandate, bears professional risk and maintains other clients.

Assessment: Use of customer systems and scheduled coordination do not decide the issue alone. The purpose and extent of control must be examined.

These scenarios are illustrative. Changing one fact, such as exclusivity, substitution rights, commercial risk or management control, may change the conclusion.

How should a foreign company structure a genuine contractor relationship?

  1. Define the result. Describe services, deliverables, acceptance criteria and deadlines instead of creating an employee job description.
  2. Preserve operational autonomy. Allow the provider meaningful control over place, schedule and method, subject to justified security and coordination requirements.
  3. Address other clients. Avoid broad exclusivity unless a narrow restriction is genuinely necessary and legally supportable.
  4. Allocate business risk. Specify responsibility for costs, tools, corrections, professional organisation and non-conforming deliverables.
  5. Review substitution and collaboration. Permit lawful use of qualified personnel or collaborators where compatible with the service, confidentiality and regulatory requirements.
  6. Separate contractors from HR procedures. Do not automatically apply employee leave approval, performance management, benefits or disciplinary systems.
  7. Protect data, confidentiality and IP. Draft clauses that fit an independent services relationship and the actual information or assets involved.
  8. Keep evidence. Retain statements of work, invoices, deliverables and communications showing independent organisation.
  9. Reassess material changes. Review the classification when the scope, reporting line, exclusivity, workload or duration changes.

How can a company audit its existing Romanian contractors?

Audit Roadmap

7-Step Romanian Contractor Classification Audit

1 Inventory All PFA/SRL 2 Fact Map Daily routine 3 Fiscal Test 4-of-7 check 4 Labour Test Authority check 5 Risk Scan IP & Tax PE 6 Classify Risk tiers 7 Remediate Lawful fix Remediation must be prospective; avoid backdating documents or creating artificial records.
Figure 3: Corporate audit roadmap for evaluating contractor populations in Romania.
  1. Inventory every arrangement. Identify individuals engaged directly, through a PFA, through a personal SRL or through an intermediary.
  2. Map the facts. Record schedule, location, reporting, tools, clients, payment model, risk, substitution and integration.
  3. Test the seven fiscal criteria. Identify which criteria are genuinely met and what evidence supports each conclusion.
  4. Test employment subordination. Compare management practices against the Labour Code concept of work under employer authority.
  5. Check connected risks. Review tax, social security, immigration, permanent establishment, IP, confidentiality and data protection where relevant.
  6. Classify by risk. Separate clearly independent providers, fact-sensitive cases and arrangements that operate like employment.
  7. Implement a lawful correction plan. Amend terms and practices where the relationship remains genuinely independent, or move to an appropriate employment structure where the facts require it.

Risk: Do not “repair” the file by backdating documents or creating evidence that did not exist. Remediation should accurately record the current position and lawfully correct the arrangement going forward, while historic exposure is assessed separately.

The Bottom Line

The employee-versus-contractor decision must be made from the work model, not from the preferred invoice or contract label. Genuine contractors organise an independent activity, retain meaningful autonomy and assume real business responsibility. Employees perform work within the employer’s authority and receive the mandatory protections attached to that status.

For foreign companies, the safest starting point is a combined contract and operations review before the individual begins work. The same review should be repeated whenever the role becomes more integrated, exclusive or manager-controlled.

Frequently asked questions

Can a Romanian contractor work for only one client?

One client does not automatically create employment, but it weakens one of the express indicators of independent activity and may increase economic dependence. The full relationship must still be assessed, including control over schedule and method, commercial risk, tools, substitution rights and whether the contractor is integrated into the client’s organisation.

Is a monthly fixed fee evidence of employment?

Not by itself. A genuine provider may charge a monthly retainer or recurring service fee. Risk increases where the payment resembles a salary and is combined with fixed attendance, continuous personal availability, direct supervision, no deliverable risk and treatment identical to employees.

Can a foreign company hire a Romanian individual as a contractor?

Potentially, but the company should confirm that the activity is genuinely independent and that the contractor has an appropriate legal and tax setup. The arrangement may also raise Romanian tax, social-security, employment, registration or permanent-establishment questions depending on the company, work location and duration.

Does an SRL invoice eliminate misclassification risk?

No. An SRL is a separate legal entity and that distinction matters, but the customer should still examine whether it receives an independently organised business service or manages one individual as part of its workforce. Contracting structure, economic substance and daily practice must be assessed together.

Should the agreement use Romanian law?

The applicable law depends on the parties and cross-border structure. A foreign governing-law clause cannot necessarily remove mandatory rules relevant to work performed in Romania. The governing law, jurisdiction, tax position and mandatory employment protections should be reviewed together before using a foreign template.

When should an existing contractor arrangement be reviewed?

Review it when the contractor becomes exclusive, moves into a managerial reporting line, adopts employee working hours, receives company benefits, stops using independent resources or shifts from project delivery to an ongoing internal role. A periodic review is also appropriate for material or long-running engagements.

Disclaimer: This article provides general legal information and does not constitute legal or tax advice. Classification depends on the contract, the actual working relationship, the parties’ tax status and the applicable Romanian and EU rules.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.

Two corporate professionals reviewing AI transparency controls, compliance dashboards, and synthetic content verification tools on screens in an office setting.

EU AI Act in Romania: 2026 Guide for Foreign Companies

Artificial intelligence and digital regulation · 2026

EU AI Act in Romania: 2026 Guide for Foreign Companies

Foreign companies operating in Romania may be subject to the EU AI Act even when the parent company, vendor or development team is outside the European Union. This practical guide explains the scope rules, the obligations already applying in 2026, the later high-risk deadlines and the records a Romanian business should build now.

The analysis should be read together with the official AI Act text, the Commission’s AI Act implementation page and the current guidance available through the AI Act Service Desk.

Two corporate professionals reviewing AI transparency controls, compliance dashboards, and synthetic content verification tools on screens in an office setting.
AI compliance is a governance process: classify, document, train and monitor.

What is the practical answer for a foreign company?

A Romanian subsidiary, branch or other local operation should begin with an inventory of the AI systems it provides, deploys, imports, distributes or uses for work. The company should then identify whether the system is prohibited, high-risk, subject to transparency duties, or outside the main AI Act obligations. The label used by the vendor is not decisive: the same tool may create different legal questions depending on its function, users, outputs and place of use.

Scope first

Map the Romanian entity, the foreign group, the provider, the deployer, the users and where the output is used. A foreign parent does not automatically remove EU exposure.

Article 2 analysis

Obligations now

AI literacy, prohibited-practice controls, GPAI-related obligations and the new transparency rules must be considered according to the applicable role and system.

2026 operating baseline

Evidence later

Keep an AI register, vendor file, training record, human-oversight process and incident route so the business can show how it reached its classification.

Governance that scales
Key point: the AI Act does not create a universal “AI officer” requirement for every Romanian business. Responsibility must be allocated in a way that fits the company’s systems, roles, risk profile and existing compliance structure.

AI Act timeline for companies operating in Romania

The original AI Act timetable has been supplemented by the Digital Omnibus on AI. The current implementation page of the European Commission identifies the dates below. A deadline table should be treated as a planning tool, not as a substitute for checking the final text and any sector-specific transition rule.

Completed1 August 2024
Entry into force

The Regulation entered into force. The legal framework began its transition period, while later provisions were scheduled to apply in stages.

Applied2 February 2025
Prohibitions and literacy

The prohibited-practice rules and the Article 4 AI-literacy obligation became applicable. Businesses should already have training and prohibited-use controls in place.

Applied2 August 2026
Transparency and supervision

Transparency obligations for certain AI systems, broader enforcement powers and the Commission’s AI Office and national authorities’ implementation work become operational.

Deferred2 December 2027
Selected high-risk uses

Following the Digital Omnibus, high-risk systems in sensitive Annex III areas, including employment, apply from this date. Product-embedded high-risk rules have a later transition.

Rule or milestoneCurrent application pointWhat the Romanian operation should do
Prohibited AI practicesApplied from 2 February 2025; an additional prohibition concerning certain non-consensual intimate or child sexual abuse material applies from 2 December 2026.Screen use cases before procurement or deployment and escalate any practice that may manipulate, exploit, socially score or infer protected characteristics.
AI literacyApplied from 2 February 2025 and enforced by national market-surveillance authorities from 2 August 2026.Adopt role-based training and retain evidence of the measures taken, rather than relying on a generic awareness email.
Transparency rulesApplied from 2 August 2026 for the relevant Article 50 systems and outputs.Review chatbot notices, synthetic-content marking, deepfake disclosures and the editorial process for public-interest text.
Annex III high-risk systemsSelected high-risk use cases, including employment, apply from 2 December 2027 after the Digital Omnibus transition.Classify and plan early. The later date does not remove GDPR, employment, consumer or fundamental-rights duties that may apply now.
High-risk systems in regulated productsExtended transition until 2 August 2028 under the current Commission summary.Coordinate product-safety, sectoral and AI Act analysis with the provider and any notified-body or conformity route.

The Commission’s current AI Act timeline identifies the staged dates and the changes introduced by the Digital Omnibus.

Does the AI Act apply to a foreign company operating in Romania?

Often, yes. The scope is not limited to companies incorporated in an EU Member State. The Regulation covers providers placing AI systems or general-purpose AI models on the Union market, deployers located in the Union, and providers or deployers in a third country where the output produced by the system is used in the Union. Importers, distributors, certain product manufacturers, authorised representatives and affected persons are also expressly addressed.

This creates several common patterns for international groups. A US or UK parent may provide a generative AI platform used by its Romanian subsidiary. A Romanian company may deploy a recruitment tool supplied by a vendor in another country. A group may centralise procurement and security while the local entity makes decisions affecting Romanian workers or customers. The legal analysis should identify each role instead of treating “the group” as a single operator.

Question 1Is the system used in the EU?

If the Romanian entity deploys the system, or its output is used in Romania or elsewhere in the Union, the scope analysis moves beyond the location of the parent company.

Question 2Who provides it?

Record the provider, importer, distributor, group company, authorised representative and vendor chain. Contract labels are useful evidence but do not replace the legal role analysis.

Question 3Who deploys it?

Identify the business unit that determines the purpose and use. The deployer may be the Romanian company, a foreign shared-service centre or another group entity depending on the facts.

Question 4Who is affected?

Employees, applicants, customers and other persons in the Union may be affected even when the technical processing or model hosting takes place outside Romania.

Do not rely on the hosting location alone: cloud hosting, a foreign parent or a vendor’s “EU AI Act compliant” statement does not by itself determine whether the Romanian entity has obligations.

Which AI uses should a Romanian company classify first?

A useful first inventory is operational rather than theoretical. Start with tools that make recommendations, rank people, generate customer-facing outputs, analyse sensitive information, control access to services or influence employment decisions. Include tools purchased by individual teams if company data or company accounts are used.

Business useWhy it needs early reviewFirst evidence to collect
Recruitment, CV screening or candidate scoringEmployment and access-to-self-employment uses are listed in Annex III and may engage high-risk analysis once the relevant rules apply.Vendor description, decision logic, data sources, human review and impact on applicants.
Employee monitoring, task allocation or performance evaluationAI used to affect working relationships or monitor behaviour may fall within the employment category and also raise labour-law and GDPR questions.Purpose, affected groups, indicators, decision owner, notice, consultation and challenge route.
Customer chatbot or voice assistantInteractive systems may require a clear notice that the person is interacting with AI unless the interaction is obvious in context.Interface screenshots, notice wording, escalation to a person and accessibility check.
AI-generated public-facing images, audio or textArticle 50 can require machine-readable marking or disclosure, subject to the relevant exception and content type.Generation workflow, labelling method, human review, editorial responsibility and publication record.
Credit, insurance, access or eligibility decisionsSome essential private or public service uses are listed as high-risk and can intersect with anti-discrimination and sectoral rules.Decision criteria, datasets, human oversight, explanation path and affected-person rights.

Do not classify a system only by the word “AI” in a sales brochure. Ask what the tool actually does, which people it affects, whether it generates or ranks content, whether it makes or supports a decision, and whether it is integrated into a regulated product. The Commission’s AI Act Service Desk provides tools and guidance that can support this initial assessment.

Which AI practices are prohibited?

The AI Act bans certain practices because their risks are considered unacceptable. Examples include harmful manipulation or deception, harmful exploitation of vulnerabilities, social scoring, certain forms of individual criminal-offence prediction, untargeted scraping to create facial-recognition databases, workplace or education emotion recognition, and biometric categorisation to infer protected characteristics, subject to the precise legal wording and exceptions.

For a foreign company with Romanian staff, the workplace emotion-recognition prohibition deserves particular attention. A vendor may market a “wellbeing”, “engagement” or “productivity” product without describing it as emotion recognition. The business should look at the functionality and the data signals used, not only the product name. The same applies to tools that claim to infer personality, intent, reliability or risk from communications.

Procurement gate

Require the business owner to describe the system’s purpose, data sources, affected people and output before purchase or activation.

Red-flag review

Escalate tools involving vulnerability exploitation, social scoring, biometric inference, emotion recognition or behavioural prediction.

Decision record

Record why the company concluded that a use is permitted, prohibited, outside scope or subject to another compliance route.

What transparency duties apply from 2 August 2026?

Article 50 covers specific interactions and outputs. A provider of an AI system intended to interact directly with natural persons must ensure that people are informed that they are interacting with an AI system unless this is obvious in context. Providers of systems generating synthetic audio, image, video or text must ensure that outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, subject to the stated limits and exceptions.

Deployers have additional duties in defined situations. People exposed to emotion-recognition or biometric-categorisation systems must be informed. A deployer of an image, audio or video deepfake must disclose that the content was artificially generated or manipulated, subject to the artistic and other exceptions. Text generated or manipulated by AI and published to inform the public on matters of public interest must also be disclosed, but the obligation does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility.

This is why the website’s ordinary AI Notice and a public disclosure under Article 50 should not be treated as identical. An editorial footer may be useful transparency, but it does not automatically satisfy every machine-readable marking or user-facing notice requirement. Each workflow should be checked according to the system, output, audience and publication context.

Practical control: create a short content decision tree: AI-assisted editing, substantially generated content, deepfake or synthetic media, public-interest text, customer interaction. Assign the corresponding label, machine-readable marker, human review and approval record.

Does every AI-generated business article or image need a label?

No single answer applies to every output. The AI Act distinguishes between the type of system, the type of output and the way the content is published or presented. Standard editing that does not substantially alter the input may fall within an exception to the machine-readable marking duty. A human review and editorial-control exception may apply to certain public-interest text. Deepfakes have their own disclosure rule, while chatbots require a direct-interaction analysis.

The company should document the workflow instead of making a broad statement such as “all AI content is exempt” or “all AI content must be labelled in the same way”. Keep the prompt or source material where appropriate, the generated version, the human changes, the responsible editor, the final label and the publication channel. This is particularly useful where content is repurposed across websites, advertisements, social media and customer communications.

What does AI literacy require?

Article 4 requires providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy for staff and other persons dealing with the operation and use of AI systems on their behalf. The measures should take account of technical knowledge, experience, education, training, the context in which the systems are used and the people or groups on whom the systems are used.

This is a context-based obligation, not a fixed annual course or a universal certification. A marketing employee using a writing assistant, an HR manager using a candidate-ranking tool and an engineer managing a model deployment do not need identical training. The employer should explain relevant limitations, data handling, hallucination and reliability risks, prohibited uses, escalation routes, human review and the consequences of relying on outputs.

Identify AI users

List employees, contractors and other persons acting on the company’s behalf who operate or use an AI system. Include occasional users where the risk justifies it.

Match training to context

Separate basic safe-use guidance from role-specific instruction for HR, legal, customer service, developers, procurement and management.

Keep training records

Retain the audience, date, topics, materials, completion evidence and any follow-up testing or policy acknowledgement.

Update after change

Reassess training when a new system, material model update, high-risk use, incident or regulatory guidance changes the risk profile.

The Commission’s AI-literacy Q&A explains that enforcement of Article 4 is handled by national market-surveillance authorities and that there is no one-size-fits-all competence framework. A Romanian business should therefore build a proportionate internal record rather than wait for a template course.

What should employers know about recruitment and workplace AI?

Annex III identifies AI systems intended for recruitment or selection, including targeted job advertising, application analysis and candidate evaluation. It also identifies systems used to make decisions affecting terms of work-related relationships, promotion or termination, allocate tasks based on individual behaviour or personal traits, or monitor and evaluate performance and behaviour.

Under the current Commission timeline, the rules for high-risk systems in these sensitive areas apply from 2 December 2027 following the Digital Omnibus transition. This does not create a compliance holiday. A Romanian employer must still consider GDPR, Romanian labour law, anti-discrimination rules, information duties, collective arrangements, employment records, confidentiality and the possibility of human challenge. A vendor’s score should not become an unexplained substitute for a lawful employment decision.

Before deploying such a tool, the employer should identify who makes the final decision, what the AI output means, whether a person can disregard it, what data is used, whether a candidate or employee can obtain an explanation, and what happens if the system produces an incorrect or discriminatory result. The analysis should also consider whether the foreign group’s HR platform is being deployed by the Romanian entity or merely accessed for central administration.

Separate the dates: the later high-risk deadline concerns the AI Act’s high-risk requirements. It does not suspend GDPR or employment-law obligations that may arise from the same processing or decision today.

Vendor contracts and AI due diligence

A foreign company should not accept a short vendor statement as its entire AI Act file. The contract and due-diligence record should allow the Romanian operation to understand the system’s intended purpose, role allocation, technical limitations, data use, security, logging, human oversight, incident cooperation, transparency features and change-management process.

Purpose and role

Ask whether the supplier is a provider, GPAI provider, importer, distributor or another operator, and whether the Romanian entity is a deployer. Retain the product description, role matrix and contract.

Data and outputs

Check what data is processed, where it is stored, whether prompts or outputs train a model, and whether personal data can be isolated. Keep the data-flow map, DPA and security schedule.

Human oversight

Confirm whether the operator can intervene, override, suspend or test the system and whether those limits are communicated. Keep the operating procedure and testing logs.

Incidents and changes

Agree how model changes, outages, security events and regulatory requests are communicated. Keep notice SLAs, version history and audit rights.

Exit and continuity

Plan how the company will retrieve records, delete data and continue operations if the tool is withdrawn or reclassified. Keep the exit and retention plan.

Where the tool is supplied by a group company, the intercompany agreement should be tested in the same way as an external vendor contract. The Romanian entity may need practical access to information even when procurement, model management and security are centralised abroad.

How does the AI Act interact with GDPR and Romanian employment law?

The AI Act does not replace GDPR. Article 2 expressly preserves the application of Union data-protection, privacy and communications rules. A company may therefore need a lawful basis, purpose limitation, data minimisation, transparency, retention controls, processor arrangements, security measures and, where relevant, a data-protection impact assessment in addition to its AI Act analysis.

Workplace deployment adds another layer. If an AI tool ranks applicants, monitors employees, allocates tasks or recommends termination, the employer should consider the Labour Code, anti-discrimination protections, employee information and consultation, internal policies and the safeguards around automated decision-making. A human reviewer is important, but “human in the loop” is not a complete answer if the reviewer simply approves an unexplained score.

For customer-facing systems, consumer-protection and sectoral obligations may also apply. For regulated products, product-safety rules, conformity assessment and technical documentation may interact with the AI Act. The right approach is a combined compliance map that shows which regime addresses which risk.

AI Act

Classifies the system and creates duties tied to the operator role, risk level, transparency, literacy and governance.

GDPR

Controls personal-data processing, individual rights, security, profiling and the relationship between controller and processor.

Employment and sector law

Protects workers, customers and regulated activities through additional information, fairness, safety and challenge requirements.

Who supervises the AI Act in Romania?

Enforcement is shared. The European Commission’s AI Office supervises general-purpose AI providers and certain connected systems, while national competent authorities supervise other AI systems. The European Data Protection Supervisor has a specific role for systems used by EU institutions. The Romanian entity should monitor the national designation and implementation measures relevant to its activity instead of assuming that every question goes to one central EU authority.

The AI Act also allows complaints, investigations, information requests and other enforcement tools. The applicable authority may consider the nature, gravity and duration of an infringement, affected persons, the operator’s size and turnover, cooperation, responsibility, mitigation and whether the conduct was intentional or negligent.

What penalties can apply?

Article 99 sets maximum levels for several categories, while Member States establish the detailed national penalty and enforcement rules. Non-compliance with prohibited practices can reach up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher. Other listed operator obligations, including certain deployer and transparency duties, can reach up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. Incorrect, incomplete or misleading information supplied to authorities can attract a separate maximum of EUR 7.5 million or 1% of worldwide annual turnover.

For SMEs and start-ups, Article 99 provides a lower-of-the-two limits approach for the amounts or percentages referred to in the provision. The figures are maximums, not automatic fines. Authorities must assess the individual circumstances and procedural safeguards remain relevant. Companies should avoid both extremes: treating the maximum as inevitable or assuming that a small local subsidiary has no exposure because the parent owns the technology.

Practical AI Act compliance checklist for a Romanian operation

01 · InventoryBuild the AI register

List systems, vendors, users, business owners, locations, outputs, affected people and group-company relationships. Include pilots and shadow AI.

02 · ClassifyAssign the legal route

Screen scope, prohibited practices, high-risk categories, transparency duties, GPAI dependencies, sector rules and applicable transition dates.

03 · ControlPut safeguards in place

Set access rules, human review, notices, marking, training, procurement controls, incident escalation and data-protection measures.

04 · EvidenceKeep the decision trail

Retain the classification rationale, vendor file, contract, training evidence, approvals, tests, incidents, changes and review date.

Create an inventory

Owner: Legal, IT, procurement and business owners. Output: an AI register with purpose, provider, deployer, data and affected persons.

Approve use cases

Owner: management with legal and security input. Output: a classification note, prohibited-use sign-off and escalation route.

Train users

Owner: HR, compliance and system owners. Output: role-based AI-literacy materials and completion evidence.

Review public outputs

Owner: marketing, communications and editorial owners. Output: a disclosure, marking and human-review record.

Monitor change

Owner: system owner and vendor manager. Output: version, incident, access, performance and reassessment logs.

Common mistakes made by foreign groups

“The parent handles it”

Central governance can help, but the Romanian operation still needs to know its role, local use, affected people and evidence available to it.

“The vendor is compliant”

Vendor compliance material is an input. It does not answer whether the Romanian entity is a deployer, importer or affected operator in the actual workflow.

“The deadline is 2027”

The later high-risk date does not postpone AI literacy, prohibited-practice controls, transparency duties or GDPR and employment-law analysis.

“A human checked it”

A nominal reviewer may not provide meaningful oversight. Define authority to challenge, override, document and stop the system.

“A footer solves labelling”

Website disclosure, user notice and machine-readable marking answer different questions. Match the control to the content and channel.

“Only official AI tools count”

Shadow AI used with company data can create the same confidentiality, data-protection and output risks as an approved platform.

Frequently asked questions

Does the AI Act apply if our parent company is outside the EU?

It may. Scope can arise because the Romanian entity deploys an AI system in the Union or because output from a third-country system is used in the Union. Analyse the actual provider, deployer, importer and output-use roles.

Are AI recruitment tools high-risk from 2 August 2026?

Not necessarily under the current transition timetable. Annex III includes recruitment and worker-management uses, but the Commission currently identifies 2 December 2027 for the selected sensitive high-risk areas after the Digital Omnibus changes. GDPR, employment and anti-discrimination duties can apply earlier.

Must employees disclose every use of ChatGPT or another writing assistant?

No universal AI Act rule requires disclosure of every private drafting step. The right control depends on the system, output, audience, content type, company policy and whether Article 50 applies. The employer should set a clear internal policy for confidential or regulated material.

Is an AI officer mandatory in Romania?

The AI Act does not impose a universal AI-officer title for every company. A foreign group should nevertheless allocate responsibility for inventory, classification, training, procurement, transparency, incidents and regulatory liaison.

Does using a human reviewer remove AI Act and GDPR risk?

No. Meaningful human oversight can be important, but it does not erase the underlying classification, transparency, data-protection, fairness or employment-law analysis. The reviewer must have information, time and authority to challenge the output.

Can we rely entirely on the AI vendor’s compliance statement?

No. Vendor material should be verified against the Romanian workflow, contract, data, users and role allocation. Keep evidence of the questions asked, the answers received and the decision made by the company.

Need to assess AI use in a Romanian business?

A Romanian business lawyer can help map the group structure, classify AI systems, review vendor terms, align GDPR and employment safeguards, and prepare a proportionate evidence file.

Contact Atrium Romanian Lawyers

This page provides general information only and does not constitute legal advice, a legal opinion or the creation of a lawyer-client relationship. Legal solutions depend on the specific facts, systems, contracts and legislation in force at the relevant time.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.

 

 

Diverse non-EU professionals and a Romanian legal adviser illustrating international recruitment, work visa procedures and employer compliance in Romania in 2026.

Recruiting Non-EU Personnel in Romania in 2026: Legal Update for Employers

Immigration and employment guide · 2026

Recruiting Non-EU Personnel in Romania in 2026: Legal Update for Employers

A practical overview for Romanian employers and foreign professionals: when work authorisation may be required, how the employment visa and single permit fit together, and which compliance points should be checked before the employee starts work.

Rules can depend on nationality, residence status, role, employer and route. Check the current procedure with the General Inspectorate for Immigration (IGI).

Do non-EU employees need a work permit in Romania?

Often, yes. A non-EU national generally needs an applicable right to work before beginning employment in Romania, unless an exemption or a different immigration route applies. The analysis starts with nationality, current residence document, proposed role and the Romanian employer’s situation.

Work authorisation

For the standard route, the Romanian employer addresses the employment authorisation process and supports the employee’s immigration file.

Employment visa

Where required, the employee applies for a Romanian long-stay visa for employment after the relevant authorisation or supporting route is available.

Single permit

After entering Romania, the employee normally applies for a single permit or, where conditions are met, an EU Blue Card.

Important: a work permit, a long-stay visa and a residence document are different steps. Treating them as interchangeable can delay onboarding or create employment-compliance risk.

From recruitment decision to lawful onboarding

This visual map shows the four points that should be resolved before the next stage.

01Classify the routeNationality, status, role and employer.
02Prepare the fileContract, qualifications and supporting documents.
03Arrange entryEmployment visa or applicable alternative.
04Maintain statusSingle permit, renewals and later changes.

Common routes for foreign employees

SituationIssue to resolveCheckpoint
Standard employment with a Romanian companyWhether the employer must obtain employment authorisation and which category applies.Match the role, qualifications and contract to the current IGI procedure.
Highly qualified employmentWhether the EU Blue Card conditions are satisfied.Check the contract, qualification, salary and vacant-position evidence.
Posting or intra-company transferWhether the arrangement is posting, ICT or another regulated route.Review the foreign employment relationship, posting documents and Romanian beneficiary.
Exempt categoryWhether the person can work without a separate work permit.Document the exemption and verify its limits.

IGI lists, among others, certain long-term residents, family members of Romanian citizens, students subject to working-time limits, beneficiaries of protection, some posted workers and nationals of Moldova, Ukraine and Serbia in specific full-time arrangements as categories that may work without a work permit. The exemption must be checked against the exact status.

Documents and employer compliance

The file is not limited to the foreign employee’s passport. Depending on the route, the employer may need to coordinate the contract, qualifications, criminal record, insurance, proof of accommodation, means of subsistence and evidence connected with the vacant position.

Contract and registration

The employment contract must be prepared and registered in the applicable employee register procedure. IGI’s current visa guidance refers to REGES-ONLINE under Government Decision no. 295/2025.

Qualification evidence

Check whether professional training, work experience, study recognition or an occupation-specific authorisation is required before filing.

Ongoing deadlines

Track visa validity, residence expiry, renewals and any change of employer, role or working arrangement before the change takes effect.

What the employer should resolve before filing

The most common delays arise before the application reaches the authorities. The employer should first establish whether the proposed role is compatible with the foreign national’s route, whether the person satisfies the professional requirements and whether the employment documents are consistent across the work-authorisation, visa and residence stages.

For highly qualified employment, the analysis may also involve the contract term, the required level of qualification, the salary conditions and evidence that the employer took the required steps concerning the vacant position. For posting and intra-company transfer, the documents must reflect the foreign employer, the Romanian beneficiary and the actual relationship between the entities.

Before recruitment

Classify the worker, role, nationality and proposed Romanian activity before promising a start date.

Before filing

Reconcile the employment contract, qualifications, translations, legalisations and supporting evidence.

Before onboarding

Confirm the right to work, visa and residence conditions, then record the relevant expiry dates.

How the standard recruitment route works

For a standard non-EU recruitment, the Romanian employer usually begins by identifying a genuine vacancy and confirming that the proposed employment fits one of the categories recognised by Romanian immigration rules. The employer should not assume that a candidate’s previous residence in another European country gives the person an automatic right to work in Romania. Residence rights, labour-market access and the right to perform a particular job are separate questions.

The employer then prepares the employment documentation and the evidence required for the relevant employment or posting notice. This may include information about the company, the position, the candidate’s education and experience, the employment contract, medical capacity and the candidate’s criminal record. The exact list depends on the category and on the documents requested by the competent authority.

After the work authorisation or applicable employment route is confirmed, the foreign national may need to apply for a long-stay visa for employment through the Romanian diplomatic mission or consular office with jurisdiction. The visa stage is not simply an administrative formality. The application must reflect the same employer, job, contract and legal route that supported the earlier filing.

After entering Romania, the employee generally applies for a single permit or EU Blue Card through the territorial structure of IGI responsible for the place of residence. The employer should plan this stage before the visa period approaches its expiry and should keep a record of every document and deadline.

Work authorisation, employment visa and residence document

These documents serve different legal functions. A work authorisation or employment notice concerns the foreign national’s access to employment under the relevant Romanian route. A long-stay visa allows the foreign national to enter and remain in Romania for the purpose stated in the visa. A single permit or EU Blue Card confirms the right to stay and, depending on the route, the right to work under the applicable conditions.

This distinction matters for employers because a candidate may have one document without having completed the entire process. For example, an employer may have obtained an employment notice, but the candidate may still need the long-stay visa before travelling to Romania. Conversely, a foreign national may already be present in Romania with a residence document for another purpose, but that does not necessarily mean that the person can start a new job without checking the labour-market access rules.

The safest onboarding process is therefore document-based. Before the first working day, the employer should identify the document that creates or confirms the right to work, check its validity and scope, and retain the evidence required by the applicable rules. HR records should also distinguish the expiry date of the residence document from the expiry date of the employment contract and from any deadline for renewal.

Who may work without a separate work permit?

Romanian immigration rules provide exemptions for specific categories of foreign nationals. IGI identifies, among others, certain long-term residents, some family members of Romanian citizens, beneficiaries of protection in Romania, asylum seekers who have received access to the labour market, tolerated foreigners and certain students. Students may be subject to a working-time limit, so the exemption should not be read as unrestricted access to any full-time position.

IGI also identifies specific situations involving religious activities, nationals of the Republic of Moldova, Ukraine and Serbia employed under the stated full-time and duration conditions, and some holders of EU Blue Cards or long-term residence documents issued by another EU Member State. The relevant facts must be documented. Nationality alone may not be enough if the exemption also depends on residence status, contract type, hours, duration or the nature of the activity.

An employer should request and review the document on which the exemption is based before treating the person as authorised to work. If the person changes employer, job, working hours or residence status, the original exemption may no longer apply in the same way. A copy of the supporting residence document or other evidence should be kept with the employment records, subject to data-protection requirements.

Highly qualified workers and the EU Blue Card

Highly qualified employment follows a more specific route. The current IGI guidance refers to a full-time employment contract for an indefinite period or for a fixed period of at least six months, together with the required professional skills and any occupation-specific authorisation. The contract must satisfy the applicable salary condition, and the employer may need evidence concerning the availability of the vacant position.

The EU Blue Card route can be attractive for international businesses recruiting senior specialists, but it should not be selected merely because the candidate has a university degree or a senior job title. The role, qualification, contract, salary and employer evidence must be tested against the legal conditions in force at the time of filing. The analysis should also cover whether the worker already holds a Blue Card or residence right in another EU Member State and whether a mobility rule applies.

Where the professional activity is regulated, recognition of studies or a professional authorisation may be required. The employer should identify this issue before signing a start-date commitment. If the qualification evidence is incomplete, the immigration process and the employment onboarding may be delayed even where the commercial recruitment decision is sound.

Posting and intra-company transfer

A foreign group may send an employee to Romania without using the same route as a Romanian company hiring a new employee. Posting and intra-company transfer require the parties to establish who remains the employer, who receives the services in Romania and what legal relationship connects the entities. The posting act, foreign employment contract, residence document and Romanian activity should tell the same story.

For an ICT worker, the Romanian beneficiary generally needs to be a branch, subsidiary, representative office or another entity belonging to the same group as the foreign undertaking. The transfer may involve a manager, specialist or trainee and is subject to specific duration and professional-experience conditions. The documents should address the period of transfer, position, salary, working conditions and the obligation to reinstate the worker after the transfer where required.

EU and EEA posting situations can involve different documentary rules from a posting from a third country. The fact that a foreign employer is established in the EU does not remove the need to check Romanian labour, immigration, social-security and notification requirements. Before the worker arrives, the beneficiary should confirm the applicable route and whether the assignment also engages rules on posted workers and Romanian employment conditions.

Documents commonly required for the immigration file

The precise checklist depends on the route, but employers and candidates should expect to coordinate several categories of documents:

Identity and status

Passport or other travel document, residence documents, visa material and evidence of the person’s current immigration status.

Employment evidence

Employment contract, job description, organisational information, posting act or group-company documents, depending on the selected route.

Personal evidence

Criminal record, medical insurance, proof of means of subsistence, accommodation evidence and translated or legalised documents where required.

IGI’s current long-stay visa guidance refers to travel medical insurance with minimum coverage of EUR 30,000 for the relevant visa period, criminal record documents translated and legalised under the applicable rules, and an employment contract registered in REGES-ONLINE for the categories listed on that guidance. These requirements should be checked again against the exact route and the live application platform before filing.

Employer obligations after the employee arrives

The employer’s role does not end when the employee receives a visa. The company should ensure that the employment contract, employee-register entries, payroll information and actual working arrangements remain aligned with the approved route. The foreign national should not be placed in a different position, assigned to a different employer or moved into a different working arrangement without checking whether a new authorisation or notification is required.

IGI states that employers must keep the work or posting permit for the period of employment or posting and must keep a copy of the residence permit or travel document showing the foreign national’s lawful stay. The company should also maintain a practical compliance calendar covering document expiry, renewal windows, passport renewal, changes of address and any planned change in role or employer.

Employment termination creates a separate immigration issue. The work or posting permit may be cancelled when the individual employment contract or posting ends, and the employee’s residence position may need to be reassessed. HR should therefore involve legal counsel before communicating termination dates or signing a settlement where the employee’s right to stay depends on the employment route.

Processing times, fees and practical planning

IGI’s current Employment and Posting guidance states that work or posting permit applications are generally processed within 30 days from registration, with a possible extension of 15 days when further checks are required. The same guidance identifies a shorter period for certain EU Blue Card situations. These are administrative processing references, not a guarantee that the whole recruitment process will finish within that period.

The complete timeline may also include document collection, qualification recognition, translations, legalisation, employer-side corrections, visa appointment availability, travel and the later single-permit application. Employers should therefore avoid promising a fixed start date until the route and documents have been checked. The cost also depends on the category. IGI currently lists different notice fees for permanent, seasonal and other categories, so a fee should be verified from the current official instructions before payment.

Where an application is refused, delayed or returned for correction, the employer should identify whether the issue concerns eligibility, missing evidence, payment identification, translation, the position or the foreign national’s status. Re-submitting documents without resolving the underlying issue can create further delay.

Common mistakes when hiring non-EU personnel

Starting work too early

A signed contract or a visa appointment does not by itself prove that the person can begin the proposed activity in Romania.

Using the wrong route

Recruitment, posting and ICT have different legal facts. Choosing a route based only on the candidate’s nationality can produce an incomplete file.

Ignoring later changes

A change of employer, job, hours, address or group-company assignment may require a new assessment before implementation.

Other recurring problems include relying on an old checklist, assuming that a residence permit issued for studies gives unrestricted access to full-time work, overlooking qualification recognition, submitting inconsistent translations and failing to track the renewal window. Employers should also avoid treating the work permit as a substitute for the employment contract, the residence document or the employment-register obligations.

Frequently asked questions

Can a non-EU employee start work after receiving the visa?

Not automatically. Confirm that the relevant work authorisation, visa and residence conditions are satisfied for the specific route before work begins.

Does every foreign national need a work permit?

No. Romanian rules identify exemptions and special routes. The exact residence status and conditions matter.

What happens after the employee enters Romania?

The employee generally applies to IGI for a single permit or EU Blue Card and should submit the application at least 30 days before the visa-based right to stay expires, subject to the applicable route.

Can an employer change the role or employer freely?

Immigration and employment documents may be tied to the approved route, employer or position. Obtain a route-specific legal assessment before implementing a material change.

Need to assess a Romanian work-permit route?

A Romanian business lawyer can coordinate the employment, immigration and corporate documents before onboarding and help the employer track later changes.

Contact Atrium Romanian Lawyers

This page provides general information only and does not constitute legal advice, a legal opinion or the creation of a lawyer-client relationship. Legal solutions depend on the specific facts and documents involved.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.

Modern apartment building with calculator and documents illustrating rental income tax in Romania

Non-Resident Tax in Romania on Property Income: The 2026 Guide

 

 

 

Non-Resident Tax in Romania on Property Income: The 2026 Guide

If you own property in Romania but live abroad, you must declare your rental income to ANAF every year. For long-term rentals, the rules are clear: a 20% flat deduction applies and you pay 10% tax on the remaining 80%, producing an effective rate of 8% on gross rent. Short-term rental taxation was modified by Law 239/2025 but the applicable regime depends on your specific situation. Filing is done via the Declarația Unică (D212) by 25 May. With the right guidance, compliance is manageable and the tax burden stays low.

Many foreign property owners in Romania discover their filing obligation only after ANAF finds them first. That is not a position you want to be in. Romanian tax law is clear: non-resident tax in Romania on property income applies to all owners of Romanian property, regardless of where they live. It doesn’t matter if you’re based in Germany, the UK, the US, or anywhere else. If your property is in Romania and it generates rent, Romania taxes it.

Tax Compliance Romania Hero Image Expert legal and tax guidance is essential for navigating the Romanian property market safely.

The good news is that for standard long-term rentals the system is straightforward. The tax rate is a flat 10%, applied to a reduced taxable base. The filing process is digital. And if your home country has a double taxation treaty with Romania, you likely won’t pay tax twice on the same income.

This guide reflects the current rules so you can understand your position and file correctly. Where the law is still developing or requires professional interpretation, we say so clearly.

Whether you’re already renting out an apartment in Bucharest or considering buying property in Romania, understanding your tax position from the start saves time, money, and stress.


Do Non-Residents Have to Pay Tax on Romanian Property Income?

Yes. Romania taxes income generated within its territory, regardless of where the property owner lives. This means rental income from any Romanian property is taxable in Romania, whether you are a resident of an EU country or anywhere else in the world. The obligation to declare and pay applies every year, as long as you earn rental income from the property.

This is what tax professionals call source-based taxation. According to ANAF’s official guidance on fiscal residence, non-resident individuals are liable to Romanian tax only on their Romanian-source income. Rental income from a property located in Romania is, by definition, Romanian-source income.

Bucharest Aerial Property View Bucharest remains a prime location for international real estate investment.

The obligation covers the following categories:

  • Long-term residential rentals (apartments, houses, rooms)
  • Commercial real estate leases (offices, retail spaces, warehouses)
  • Short-term rentals through platforms like Airbnb or Booking.com
  • Agricultural land leased to farming operators

There is no minimum income threshold that removes the obligation. Even a single month of rental income creates a filing requirement. The only question is which regime applies and how much you owe.

If you’re also exploring Romanian property law services for your broader investment needs, it’s worth addressing your tax position alongside your legal structure from the outset. Specialized land registry verification can also help ensure your tax record matches your ownership status.


What Law 239/2025 Actually Changed for 2026 (and What It Didn’t)

Several guides published in early 2026 overstate what Romania’s most recent tax legislation changed for property owners. It’s worth being precise, because the actual changes are narrower than much of the commentary suggests.

Law 239/2025 was published in Romania’s Official Journal in December 2025 and entered into force on 18 December 2025. Its income tax provisions apply to income earned from the 2026 fiscal year onwards.

What Law 239/2025 did not change: the long-term rental flat deduction. The 20% flat expense deduction for long-term rentals has been in place since 1 January 2024, introduced by Emergency Ordinance 115/2023 (OUG 115/2023). It replaced a transitional zero-deduction period in 2023 that followed the earlier 40% regime. If you filed correctly for 2024 and 2025, you were already using the 20% deduction. Law 239/2025 left this unchanged.

What Law 239/2025 primarily addressed is the short-term rental sector. The legislation introduced modifications to how short-term rental income is classified and taxed, including changes to the threshold above which rental activity is reclassified as independent commercial income. However, as explained in the section below, the practical application of these changes is still developing and requires individual assessment.

For long-term landlords, 2026 does not bring material change. For owners operating short-term rentals, the picture is more complex and professional advice is strongly recommended before filing.


How Is Tax Calculated on Long-Term Rental Income?

For long-term rentals, Romania applies a 20% flat expense deduction to gross income. You then pay 10% income tax on the remaining 80%. This makes the effective tax rate on gross rent exactly 8%. No receipts or documentation are required to claim the deduction. It is applied automatically when you file your return.

Long-Term Rental Calculation (2026)100%Gross Rent80%Taxable Base8%FINAL TAXEffective Rate

This deduction has been in place since 1 January 2024 under OUG 115/2023 and remains unchanged for 2026.

Here is the full calculation:

StepAmount / Rule
Gross annual rental income€10,000
Flat deduction (20%)€2,000
Taxable income (80%)€8,000
Tax due (10% of taxable base)€800

The maths is simple. The challenge for most foreign owners isn’t the calculation. It’s knowing they need to do it at all, and filing on time.

A note on social contributions (CASS). This is an area where the rules are more nuanced than many guides suggest, and the position for non-residents is not identical to that of Romanian residents. Whether CASS applies depends on several factors: the type and total amount of Romanian-source income you earn, how that income aggregates across different categories, and whether you fall within Romania’s social insurance obligations as a non-resident. If your rental income is substantial, it is essential to verify your CASS position specifically with a Romanian tax law adviser before filing.


Short-Term Rentals: What Changed and What Is Still Developing

Short-term rental taxation in Romania is the area of most active legislative change, and also the area where the greatest caution is required when reading guides published online.

Historically, income from renting up to 5 rooms on a short-term basis was taxed based on an income norm system (normă de venit), where ANAF assigned a fixed estimated annual income per room regardless of actual earnings.

Law 239/2025 introduced changes to this framework: it modified the room threshold above which short-term rental activity is reclassified as independent commercial income, and introduced provisions relating to the calculation of net income for short-term rentals. The legislation references a flat expense deduction approach as the new mechanism for determining net income in this category.

But the practical application of these changes is still developing. Full implementation depends on secondary legislation and updated ANAF methodological norms. As of the time of writing, the application of the new regime is not uniformly settled across ANAF interpretations.

What we recommend if you operate short-term rentals:

  • Do not assume that a single flat deduction rate applies automatically to your situation
  • Verify the current applicable regime with a tax specialist before filing
  • Keep detailed records of income and rooms rented, as these affect both classification and calculation
  • Be aware that ANAF has significantly increased monitoring of short-term rental platforms and has access to platform data

The direction of travel under Law 239/2025 is toward a simplified deduction approach for short-term rentals. But given that implementation is still developing, presenting precise numbers as settled would not be accurate. If you operate short-term rentals and want to understand exactly where you stand, contact our team for an assessment of your specific position.


How to File: The Declarația Unică Step by Step

Non-residents earning Romanian rental income must file the Single Tax Return (Declarația Unică), form D212, with ANAF. This form covers both income declaration and the establishment of any contribution obligations. The annual deadline is 25 May, confirmed by ANAF’s official 2026 filing guidance.

Play

The Compliance Roadmap:

  1. Step 1: Obtain a Romanian tax identification number (NIF). This is different from a residency permit. Even as a non-resident, you must be registered with the tax authorities (ANAF). This can be done through a Romanian representative.
  2. Step 2: Register your lease contract with ANAF. Long-term rental contracts must be registered via the lease registration process. Failing to register the contract adds a separate compliance failure.
  3. Step 3: Complete the Declarația Unică electronically. The form is filed through the ANAF digital portal (SPV). Do not assume your data will be pre-populated correctly. Treat the return as something you need to complete and verify yourself.
  4. Step 4: Declare both years. The return covers your actual income from the previous year and your estimated income for the current year.
  5. Step 5: Pay by 25 May. Payment can be made through the SPV portal or via banking channels. Use the correct payment reference.
ANAF D212 Filing Roadmap Filing the D212 is the most critical step in maintaining your legal standing in Romania.

A note on withholding by Romanian companies. If your tenant is a Romanian legal entity, the company may in certain circumstances be required to withhold tax at source. You will still need to file the return, and any withheld amounts are credited against your total liability.


Can a Double Taxation Treaty Reduce Your Overall Tax Bill?

Yes, but not in the way most people expect. A double taxation treaty won’t reduce the Romanian tax you pay locally. What it does is prevent you from being taxed twice on the same income: once in Romania and again in your home country.

Double Taxation Treaties Graphic Treaty protection ensures you aren’t penalized for international investments.

Romania has an extensive network of double taxation agreements, covering approximately 87 bilateral treaties. Most treaties work through one of two mechanisms:

  • The credit method: your home country taxes all your income but grants you a credit for the Romanian tax already paid.
  • The exemption method: your home country simply exempts Romanian-source income from domestic taxation.

The method applies depends on the specific treaty. Reviewing it before filing can meaningfully reduce your combined tax burden. If you’re also considering visa or residency options, be aware that changing your status has consequences for treaty application.


Real Case: How We Handled This for a Germany-Based Client

Our client was based in Germany and owned an apartment in Bucharest generating around €14,000 per year. They had not declared this income and were unsure about their obligations.

Calculation ItemValue
Gross annual rental income€14,000
Flat deduction (20%)€2,800
Taxable income (80%)€11,200
Final tax due in Romania (10%)€1,120

We clarified the position, registered the client, and filed the Declarația Unică. Because Germany and Romania have a double taxation agreement, the client was eligible for a tax credit in Germany. The overall burden was managed correctly for the first time.

Key takeaway: Compliance is not the obstacle people think it is. The obstacle is delay. The longer you wait, the more years of unfiled returns accumulate, and the more penalties accrue.


Conclusion

Non-resident tax in Romania on property income follows a clear, predictable framework for long-term rentals. The current rules apply a flat 10% rate after a 20% standard deduction, in place since 2024. The effective rate is 8% on gross rent. Filing is done annually via the Declarația Unică by 25 May.

For short-term rentals, Law 239/2025 introduced changes that are still developing in their practical application. If you operate in this category, professional advice before filing is not optional.

Three things matter most regardless of your rental type: understanding which regime applies to your specific situation, filing on time every year, and reviewing your double taxation treaty position to avoid paying more than you legally owe.

Secure Your Tax Position in Romania

Our legal team handles the entire process for foreign property owners: from NIF acquisition to expert filing and ANAF correspondence management.

Contact Our Tax Specialists

Frequently Asked Questions

Do non-residents have to pay tax on rental income from Romanian property?

Yes. Romania taxes income generated within its territory, regardless of the owner’s country of residence. Both EU and non-EU nationals must declare Romanian rental income annually to ANAF and pay a flat 10% income tax on their net rental income. There is no minimum income threshold that removes this obligation.

What is the flat deduction for long-term rental income in Romania?

The flat deduction for long-term rentals is 20% of gross rental income. This has been in place since 1 January 2024, introduced by Emergency Ordinance 115/2023. It was not changed by Law 239/2025. No documentation is required to claim it: the deduction is applied automatically when you complete the Declarația Unică.

How is short-term rental income taxed in Romania in 2026?

Short-term rental taxation was modified by Law 239/2025, which introduced changes to both the classification threshold and income calculation method for this category. However, the practical application of the new rules depends on implementation through secondary legislation and updated ANAF guidance. The applicable regime varies based on your specific situation. If you operate short-term rentals, we strongly recommend professional advice before filing rather than relying on a single fixed calculation.

How do I file the Declarația Unică as a non-resident?

You must obtain a Romanian tax identification number, then file form D212 electronically through ANAF’s SPV portal by 25 May each year. The return covers your actual income from the previous year and your estimated income for the current year. Do not rely on the return being pre-filled: verify all data carefully before submitting. If you can’t access the portal directly, a local representative can file on your behalf.

What happens if I don’t declare my Romanian rental income?

Failing to file the Declarația Unică results in administrative penalties plus daily interest on any unpaid tax. ANAF has the authority to issue a tax assessment based on estimated income if no return is filed. Romanian tax authorities also have access to data from short-term rental platforms. The longer the delay, the larger the accumulated liability. Voluntary compliance, even for prior years, is almost always a better outcome than waiting to be found.

Disclaimer: This guide provides general information only and does not constitute legal or tax advice. Romanian legislation and ANAF administrative practices are subject to frequent change. Always consult with a qualified Romanian lawyer or tax advisor for your individual situation. Atrium Romanian Lawyers takes no responsibility for outcomes based on this general guidance.

Related Resources

EU Pay Transparency Directive implementation in Romania showing salary transparency and compliance changes effective in 2026

EU Pay Transparency Directive in Romania: Key Changes in 2026

Employment law and equal pay · Romania

EU Pay Transparency Directive in Romania: Key Changes in 2026

Directive (EU) 2023/970 introduces a wider transparency framework for equal pay for equal work or work of equal value. Romanian employers should prepare for changes in recruitment, pay structures, employee information rights and gender-pay reporting, while distinguishing the EU requirements from the Romanian rules and implementing measures actually in force.

The European transposition deadline was 7 June 2026. This guide explains the Directive’s minimum framework and the practical questions Romanian employers should verify against the current national legislation, draft measures and administrative practice.

Play
Video guide: what the EU Pay Transparency Directive may change for Romanian employers and employees.

Short answer: the Directive requires employers to use transparent, objective and gender-neutral pay practices. It addresses salary information before recruitment, employee access to pay data, pay-setting criteria, gender-pay reporting for larger employers and remedies for discrimination. The Directive is not a substitute for checking the Romanian transposition law and the national rules applicable to the employer.

What does the Pay Transparency Directive change?

The Directive moves equal-pay compliance from a purely reactive model toward documented pay structures, accessible information and measurable employer responsibilities.

For Romanian companies, the most important practical point is timing. The Directive required Member States to adopt the measures necessary for transposition by 7 June 2026. That European deadline does not mean that every employer in Romania can apply one uniform checklist without checking national legislation. Romanian employers should separate the EU minimum requirements from the domestic rules that define procedures, authorities, sanctions and any additional obligations.

Recruitment transparency

Candidates should receive the initial remuneration or salary range based on objective, gender-neutral criteria, and employers should not ask for salary history.

Employee information rights

Employees receive a route to request information about their own pay and average pay levels for comparable work, broken down by gender.

Pay-gap reporting

Employers with at least 100 workers face phased reporting obligations under the Directive, subject to national implementation.

Legal safeguard: do not publish a Romanian employer checklist that treats the Directive alone as the complete domestic law. Verify the current transposition status, implementing acts and the competent Romanian authorities before taking a fixed compliance position.

Employer readiness navigator

Use the controls below to see the main question that should be addressed in each workstream.

Select a workstream to open its first compliance question.

Recruitment

Review whether the employer can state an initial salary or range before the relevant recruitment stage and remove questions about current or previous pay.

Recruitment transparency and salary history

Under Article 5 of Directive (EU) 2023/970, job applicants are entitled to information about the initial remuneration or range for the position, set according to objective and gender-neutral criteria. The information must be supplied early enough to permit informed and transparent negotiation, for example in the job advertisement or before the interview.

The Directive also prohibits employers from asking applicants about their pay history in current or previous employment. This affects more than a single interview question. Recruitment teams should review application forms, recruiter scripts, interview templates, reference checks, automated screening flows and agency instructions.

Job titles and vacancy notices should be gender-neutral and recruitment should be organised in a non-discriminatory manner. A salary range is not meaningful if it is so broad that it conceals the employer’s real pay position. The employer should be able to explain the objective criteria used to set the range and the criteria used to determine the final offer.

Before advertising

Define the role, comparable job category, remuneration components and objective range-setting criteria.

During recruitment

Disclose the relevant range at the required stage and remove questions about current or previous salary.

Before the offer

Record the criteria supporting the final offer and keep the process consistent across comparable candidates.

Employee rights to pay information

The Directive gives workers a right to request, in writing, information about their individual remuneration level and the average remuneration levels, broken down by sex, for categories of workers performing the same work or work of equal value. Remuneration is broader than basic salary and may include relevant variable or supplementary components under the applicable framework.

Employers should create a controlled process for receiving, verifying and answering requests. The response should use a defensible job-category methodology and should not disclose identifiable salary information about another individual. The Directive contemplates a written response within two months, subject to the wording of the national implementing rules.

Employers must also communicate the right to request pay information and the prohibition on retaliation at least once a year. Pay secrecy clauses cannot be used to prevent workers from disclosing their own pay for the purpose of enforcing equal-pay rights. Confidentiality obligations may still protect personal data and legitimate business information, but they should not be drafted as a disguised prohibition on exercising statutory rights.

Select the step that should be documented when a pay request arrives.

Receive

Record the date, scope and written form of the request, then assign responsibility for the response.

Objective pay structures and work of equal value

Pay transparency cannot work without a defensible method for comparing roles. The Directive refers to objective, gender-neutral criteria including skills, effort, responsibility and working conditions. Other factors may be relevant if they are genuinely connected to the work and applied consistently.

Employers should avoid relying only on job titles. Two positions with different titles may involve comparable value, while identical titles may cover materially different responsibilities. The assessment should address qualifications, experience, technical and non-technical skills, decision-making, emotional or physical effort, working environment, hazards and scheduling requirements where relevant.

Soft skills must not be undervalued because they are associated with traditionally female-dominated roles. A pay architecture should therefore explain how the employer evaluates communication, organisation, care, negotiation, customer-facing work and other relevant skills without allowing subjective stereotypes to determine pay.

WorkstreamQuestion for the employerEvidence to retain
Role definitionWhat duties, responsibility and working conditions define the role?Job description, organisation chart and evaluation criteria.
Pay rangeWhat objective factors explain the lower and upper end of the range?Pay bands, approval record and recruitment documentation.
Comparable workWhich workers perform the same work or work of equal value?Job architecture, category methodology and review notes.
Pay differenceCan a difference be explained by objective, gender-neutral criteria?Experience, performance, responsibility and other relevant evidence.

Gender-pay reporting thresholds

The Directive establishes phased reporting obligations for employers with at least 100 workers. The number of workers, the reporting reference period, the calculation methodology and the route through which information is supplied must be checked against the national implementing framework.

Employer sizeDirective reporting timetablePractical preparation
250 or more workersFirst information due by 7 June 2027, then annually.Build annual data collection, validation and representative-facing reporting.
150–249 workersFirst information due by 7 June 2027, then every three years.Prepare the same data architecture with a three-year reporting cycle.
100–149 workersFirst information due by 7 June 2031, then every three years.Start role mapping and data-quality work before the first reporting year.
Under 100 workersNo mandatory reporting under the Directive’s minimum threshold, unless national law provides otherwise.Maintain fair recruitment and pay structures and monitor Romanian legislation.

Reported information may include the overall gender pay gap, gaps in supplementary or variable components, the distribution of workers across pay quartiles and gaps by worker category. Employers should not wait until the first report is due to discover that payroll data, job categories or variable-pay records cannot be reconciled.

When does a joint pay assessment become relevant?

Where the reported pay difference reaches at least 5% in a category of workers, is not justified by objective and gender-neutral criteria and has not been remedied within the period contemplated by the Directive, the employer may need to carry out a joint pay assessment with worker representatives. The exact procedure and competent bodies depend on national implementation.

A joint pay assessment is not a substitute for ordinary pay governance. Employers should first test whether the job categories are coherent, whether remuneration components have been captured consistently, whether part-time and full-time work have been treated correctly and whether objective explanations are documented rather than reconstructed after a complaint.

The process can involve identifying the scale and causes of the difference, reviewing the criteria used for pay and proposing remedies. Worker representatives may have a role in the assessment. Employers should therefore prepare a secure data room, a methodology note and a process for handling questions without disclosing unnecessary personal data.

Important: a 5% difference is not, by itself, proof of unlawful discrimination. It is a trigger for further analysis when the Directive’s other conditions are also met. Conversely, a smaller difference is not an automatic safe harbour if other evidence suggests unequal pay.

Remedies, enforcement and burden of proof

The Directive requires Member States to establish effective, proportionate and dissuasive penalties and to provide effective remedies for workers who suffer loss because of pay discrimination. The amounts and domestic enforcement mechanisms are matters for Romanian implementing legislation and should not be invented in an employer guide before the current national text is verified.

Remedies may include recovery of underpaid remuneration, compensation for loss, interest and other forms of relief available under the applicable law. The Directive also strengthens access to evidence and can affect the allocation of the burden of proof where transparency obligations have not been respected. Romanian employers should therefore treat documentation as part of substantive compliance, not as an administrative afterthought.

Employers should also protect workers and their representatives from retaliation for exercising pay-transparency rights. A complaint, pay request or discussion about remuneration should not be treated as misconduct merely because it creates an uncomfortable management conversation.

Romanian employers: what to prepare now

Even while national implementation is being confirmed, employers can take low-regret steps that do not depend on a particular Romanian form or sanction. The aim is to understand the organisation’s pay logic, identify data gaps and avoid recruitment practices that are difficult to defend later.

  • Map roles and create a working classification for the same work and work of equal value.
  • Document objective, gender-neutral criteria for pay ranges, progression and variable remuneration.
  • Remove salary-history questions from forms, scripts, recruiter instructions and agency briefs.
  • Decide when and how the initial salary or range will be communicated to candidates.
  • Review confidentiality clauses so they do not restrict lawful equal-pay discussions.
  • Create a written route for employee information requests and assign responsibility for responses.
  • Test whether payroll and HRIS data can produce reliable gender and worker-category comparisons.
  • Check how bonuses, allowances, benefits, overtime and other remuneration components are recorded.
  • Prepare a confidential process for investigating unexplained pay differences.
  • Monitor Romanian transposition legislation, implementing acts and guidance from competent authorities.

How should multinational groups prepare their Romanian entities?

Groups operating in more than one Member State should avoid copying a group policy into Romania without a local legal review. The Directive provides a common minimum framework, but the Romanian transposition law may determine the language, reporting channel, authorities, consultation rights, sanctions and interaction with existing equal-treatment rules.

The Romanian entity should be able to identify its own workers, roles, pay components and reporting threshold even where payroll or HR systems are centralised abroad. Group-level data may support the analysis, but it should not obscure the Romanian employer’s responsibilities or transfer personal data without an appropriate legal and security framework.

Multinationals should also reconcile the Directive with recruitment practices used by external agencies, shared-service centres and automated tools. A policy is useful only if it reaches the people who write job advertisements, conduct interviews, approve offers and answer employee requests.

Frequently asked questions

What is the EU Pay Transparency Directive?

Directive (EU) 2023/970 strengthens equal-pay enforcement through recruitment transparency, employee information rights, objective pay structures and phased gender-pay reporting.

Does the Directive apply to Romanian employers?

It covers public and private employers within its scope, but the practical Romanian procedures, authorities, sanctions and any additional obligations depend on the national implementing framework.

Can Romanian employers ask candidates about salary history?

The Directive prohibits asking applicants about their current or previous pay. Employers should remove those questions from interviews, forms, references and recruitment instructions.

Must employers publish a salary range?

The Directive requires applicants to receive information about the initial remuneration or range early enough for informed negotiation. The precise Romanian format and timing should be checked against national implementation.

What is the 5% pay-gap threshold?

A difference of at least 5% may trigger further assessment when it is not justified by objective, gender-neutral criteria and has not been remedied within the relevant period. It is not automatic proof of discrimination or an automatic safe harbour.

When does pay-gap reporting start?

Under the Directive, employers with at least 150 workers have first reporting obligations by 7 June 2027, while employers with 100–149 workers begin by 7 June 2031. Romanian law may define the domestic reporting process.

Need to prepare for pay-transparency rules?

A Romanian employment lawyer can review recruitment practices, pay structures, employee-information procedures and gender-pay data before the national framework creates avoidable risk.

Book a consultation

Disclaimer: This article provides general information only and does not constitute legal advice or the creation of a lawyer-client relationship. The practical obligations depend on Directive (EU) 2023/970, Romanian transposition measures, implementing rules, employer size, pay structures and the facts of the case. Check the current legal framework before taking action.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.

 

 

 

 

 

 

 

 

 
Romania tax debt rescheduling 2026 under Law 239/2025, illustrated by a judge’s gavel, financial charts, digital tax systems, and Romanian flag symbolizing legal and fiscal reform.

Romania Tax Debt Rescheduling 2026 – Law 239/2025 Explained

 

Romania Debt Rescheduling 2026: Law 239/2025 Explained

Romania is entering a more restrictive fiscal environment in 2026 following the adoption of Law no. 239/2025, published in the Official Gazette no. 1160 of December 15, 2025 and effective as of December 18, 2025.

The reform forms part of a broader effort to strengthen budgetary discipline and improve tax collection, in line with Romania’s European fiscal commitments.

While formally structured as amendments to the Fiscal Procedure Code, the new rules introduce material changes to the practical functioning of tax debt rescheduling.

Mechanisms previously characterized by reduced guarantees and extended tolerance periods have been replaced by stricter eligibility criteria, enhanced enforcement safeguards for the tax authority, and increased personal involvement of individuals controlling indebted companies.


Key Takeaways for Romanian Taxpayers in 2026

  • Personal Guarantees in Classic Rescheduling: Article 193¹ introduces a mandatory fideiusiune (personal guarantee) for classic tax rescheduling, creating a contractual extension of liability for the guarantor for the duration of the arrangement.
  • Restricted Access to Simplified Rescheduling: Simplified rescheduling remains available only for lower debt thresholds (up to 400,000 lei for companies and 100,000 lei for individuals) and is subject to higher interest costs.
  • Shortened Compliance Period: The maximum delay for settling current tax obligations during a rescheduling plan has been reduced from 180 days to 60 days.
  • Expanded Fiscal Inactivity Grounds: Failure to maintain a Romanian payment account or submit financial statements may lead to fiscal inactivity status and subsequent administrative procedures.
  • Increased Digital Oversight: SAF-T, e-Factura, and e-VAT reporting data are increasingly used in compliance assessments and rescheduling analyses.

Play

1. Macroeconomic Background of the Reform

Law no. 239/2025 must be viewed within Romania’s broader macroeconomic context.

Analyses published by the National Bank of Romania and the Fiscal Council point to persistent budget deficits, reduced fiscal space, and rising public debt servicing costs.

In prior years, simplified tax rescheduling was frequently used by companies as a liquidity management tool.

The revised framework signals a policy shift toward ensuring predictability of revenue collection and limiting prolonged reliance on deferred payment of public obligations.

For more information on how this affects business planning, consult our corporate law services or see our company formation guide.

2. Personal Guarantees and Contractual Extension of Liability

The most significant change introduced by Law 239/2025 is Article 193¹ of the Fiscal Procedure Code, which requires the submission of a personal guarantee (fideiusiune) in classic tax rescheduling arrangements.

This mechanism does not abolish the principle of limited liability under company law. Instead, it creates a contractual exception whereby a natural person assumes personal liability toward the tax authority for the fulfillment of the rescheduling obligations.

For detailed guidance on this mechanism, consult the National Agency for Fiscal Administration (ANAF) official guidance.

Who May Be Requested to Guarantee

In practice, tax authorities may require the guarantee to be provided by the individual exercising effective control over the company, typically corresponding to the Ultimate Beneficial Owner (UBO) as defined under Law no. 129/2019 on the prevention and combating of money laundering.

For guidance on shareholder responsibilities, see our shareholder rights guide or shareholder agreement documentation. Guarantees from individuals without substantive decision-making authority may be subject to additional scrutiny.

Legal Form and Enforcement Effects

The fideiusiune must be executed in authentic (notarial) form.

Under Romanian law, such instruments generally qualify as enforceable titles. In the event of default, enforcement measures may be initiated in accordance with the Fiscal Procedure Code and applicable procedural safeguards, depending on the nature of the assets involved.

Applicable Deadlines

The law introduces relatively short timeframes for submitting guarantees, ranging from several days following issuance of the fiscal attestation certificate to longer periods following preliminary approval.

Failure to comply may result in rejection of the rescheduling request and continuation of standard collection procedures.

For timely coordination with notaries, review the Romanian Notaries Chamber resources.

3. Simplified Rescheduling: Thresholds and Conditions

Simplified rescheduling under Article 209¹ remains available, but under narrower eligibility criteria than in prior years.

Applicable Monetary Limits

  • Legal entities: 5,000 – 400,000 lei
  • Individuals and unincorporated entities: 500 – 100,000 lei

Debts exceeding these thresholds generally require classic rescheduling, involving additional documentation, financial analysis, and guarantees.

For legal entities, simplified rescheduling is typically available only if the company has been established for at least 12 months.

Learn more about ANAF rescheduling procedures.

Cost of Rescheduling: The interest applicable to simplified rescheduling is approximately 0.02% per day (around 7.3% annually), reducing its attractiveness as a long-term financing substitute.

Compare this with traditional bank lending rates.

4. Ongoing Compliance and the 60-Day Rule

Once a rescheduling plan is approved, taxpayers must remain current with all new tax obligations.

Law 239/2025 reduces the maximum delay for settling such obligations from 180 days to 60 days.

Non-compliance may lead to termination of the rescheduling arrangement, acceleration of outstanding amounts, and potential activation of guarantees, subject to administrative confirmation and procedural rights.

See our compliance monitoring section below.

5. Fiscal Inactivity and Administrative Consequences

The reform expands the grounds on which a taxpayer may be declared fiscally inactive, including:

  1. Failure to maintain a payment account in Romania or with the State Treasury;
  2. Failure to submit annual financial statements within statutory deadlines.

If inactivity persists, the tax authority is required to initiate procedures that may include insolvency or dissolution proceedings, in accordance with applicable legal frameworks.

For insolvency matters, review the Insolvency Law.

6. Digital Reporting and Compliance Monitoring

Romania’s tax administration increasingly relies on digital reporting systems such as SAF-T, e-Factura, and e-VAT.

These systems provide standardized accounting and transactional data used to assess compliance behavior, financial indicators, and risk profiles.

While the law does not mandate automatic decisions based solely on digital data, such reporting plays an important role in administrative analysis and verification processes.

Ensure your company’s digital compliance documentation is up to date.

7. Sectoral Impact and Transactional Considerations

Certain sectors—such as construction, retail, and pharmaceuticals—may face additional challenges due to longer commercial payment cycles combined with the shortened fiscal compliance timelines.

In transactional contexts, including share transfers and reorganizations, outstanding tax liabilities may attract increased scrutiny.

Notification obligations and guarantees may be required for tax debts to remain opposable following ownership changes.

For M&A considerations, consult our transactional structuring guide.


Frequently Asked Questions

Q: Can my company avoid providing a personal guarantee for classic rescheduling?

In practice, ANAF generally requires a personal guarantee for classic rescheduling arrangements, subject to the specific circumstances of the taxpayer and applicable administrative practice. The guarantee must be provided by the individual exercising effective control (typically the UBO as per Law no. 129/2019). For more information on shareholder obligations and control structures, consult our corporate law services. Refusal to provide a required guarantee may result in rejection of the rescheduling request and continuation of standard collection procedures.

Q: What happens if I exceed the 60-day compliance window during rescheduling?

Exceeding the 60-day grace period for settling current tax obligations can lead to the following consequences, subject to administrative confirmation:

  • Termination of the rescheduling arrangement
  • Acceleration of the entire outstanding debt
  • Potential activation of personal guarantees, in accordance with the Fiscal Procedure Code
  • Resumption of standard collection and enforcement procedures

Action: Maintain strict internal tracking of all current tax payment deadlines during any rescheduling period.

Q: Is my company eligible for simplified rescheduling?

Simplified rescheduling is available if your company meets all of the following:

For individuals, the threshold is 500 – 100,000 lei. If your debt exceeds the limit, classic rescheduling (with guarantee) is required. Check ANAF’s official guidance for detailed eligibility requirements.

Q: What does “fiscal inactivity” mean and what are the consequences?

A company is declared fiscally inactive if:

Consequences include initiation of administrative procedures that may lead to insolvency or dissolution proceedings. Prevention: Ensure your company maintains an active Romanian payment account and submits all financial statements on time.

Q: How much does simplified rescheduling cost?

The interest rate for simplified rescheduling is approximately 0.02% per day, which equates to roughly 7.3% annually. This relatively high rate reduces its attractiveness as a long-term financing tool compared to traditional commercial financing. Review current lending rates from the National Bank of Romania for comparison.

For classic rescheduling, interest rates are typically lower and may vary based on the specific arrangement negotiated with ANAF. For further information on tax law and planning, consult our specialized services.

Q: How is the personal guarantee enforced?

The fideiusiune (personal guarantee) must be executed in authentic notarial form (contact the Romanian Notaries Chamber). Under Romanian law, such instruments qualify as enforceable titles, granting ANAF enhanced enforcement rights in case of default:

  • Enforcement mechanisms follow the procedures set out in the Fiscal Procedure Code, which provide the tax authority with enhanced enforcement rights compared to ordinary civil claims
  • The guarantor’s personal assets may be subject to attachment and enforcement
  • Procedural safeguards apply in accordance with the Civil Procedure Code
  • The guarantee remains enforceable for the entire duration of the rescheduling arrangement
Q: What role do digital reporting systems (SAF-T, e-Factura, e-VAT) play?

ANAF uses data from these systems to:

  • Assess your compliance behavior and financial capacity
  • Evaluate your risk profile for rescheduling eligibility
  • Monitor your activities during an existing rescheduling arrangement
  • Detect inconsistencies or red flags in reporting

While automated decisions are not mandatory, accurate and timely submission of SAF-T, e-Factura, and e-VAT reports is an important factor in the overall assessment of rescheduling eligibility. Review ANAF’s digital compliance requirements.

Q: Can I change the guarantor once rescheduling is approved?

The law does not explicitly address substitution of guarantors after initial approval. In practice, ANAF may require consent or may require a new authentic guarantee instrument. Any change should be coordinated with your tax advisor and ANAF before implementation to avoid complications or loss of rescheduling status.

Q: Are there any deadlines for submitting the guarantee?

Yes. The law introduces tight deadlines ranging from several days following issuance of the fiscal attestation certificate to longer periods after preliminary approval. Missing these deadlines typically results in:

  • Rejection of the rescheduling request
  • Loss of provisional rescheduling status
  • Resumption of standard collection procedures

Action: Coordinate guarantee preparation with a notary in advance. Contact the Romanian Notaries Chamber to ensure timely submission.


Disclaimer: This article is provided for general informational purposes only and does not constitute legal or tax advice. The analysis is based on Law no. 239/2025 and publicly available information as of January 2026. Application of the law may vary depending on individual circumstances, administrative practice, and subsequent guidance or case law. Professional advice should be obtained before taking any action based on this content.