DPIA and FRIA assessment paths for an AI project in Romania

DPIA vs FRIA in Romania: Which Assessment Does Your AI Project Need?

AI governance • Romania • Assessment decisions

DPIA vs FRIA in Romania is a question of two different legal tests. A data protection impact assessment (DPIA) addresses risks arising from personal-data processing under the GDPR. A fundamental rights impact assessment (FRIA) under the AI Act applies to specified deployers of certain high-risk AI systems. Your project may require one, both, or neither mandatory assessment.

When do these obligations apply?

The GDPR assessment requirements already apply. Under the AI Act’s consolidated timetable, Chapter III Sections 1–3, including Article 27, apply to Annex III high-risk systems from 2 December 2027. The corresponding date for Article 6(1)/Annex I product systems is 2 August 2028; that does not extend Article 27 to every product system.

Article 111 contains separate transition provisions for existing systems. A project review should record when the system was placed on the market or put into service and whether subsequent design changes affect its treatment. The future FRIA timetable does not postpone GDPR duties. Source: consolidated AI Act, Articles 111 and 113.

DPIA vs FRIA: the differences that change your project

Both assessments examine potential harm to people. A DPIA is not limited to confidentiality or cybersecurity: it also examines other rights and freedoms affected by personal-data processing. FRIA addresses the impact of the specified AI deployment on fundamental rights.

Click or tap a row to reveal its practical takeaway. Keyboard users: Tab to a green label and press Enter or Space. Swipe the table sideways on a small screen.

Two assessments, separate applicability tests
Decision pointDPIA: GDPR Article 35FRIA: AI Act Article 27
Personal-data processing likely to create high risks to individuals, assessed in its context.A covered deployer using an in-scope Article 6(2)/Annex III high-risk system.
The controller, with DPO advice where a DPO is designated and relevant processor assistance.The deployer covered by Article 27.
Processing, necessity, proportionality, risks to people and safeguards.Deployment context, affected groups, risks of harm, human oversight and responses.
Before the relevant processing begins; review when risk changes.Before first use where the obligation applies; update changed or outdated elements.
Prior consultation when the Article 36 threshold is met; no universal filing requirement for every DPIA.Notify results to the market surveillance authority under Article 27(3), subject to its exception.
Shared evidence can support the assessment of the actual processing.Relevant DPIA sections may be cross-referenced or incorporated; remaining requirements still need coverage.

GDPR Articles 28, 35–36 and 39; AI Act Article 27.

When does an AI project need a DPIA?

AI use alone does not automatically trigger a DPIA. The controller must assess whether the nature, scope, context and purposes of the processing make a high risk to people likely. Article 35 expressly recognises the relevance of new technologies.

The GDPR identifies particular situations, including systematic and extensive automated evaluation underpinning decisions with legal or similarly significant effects, large-scale processing of special-category or criminal-offence data, and large-scale systematic monitoring of publicly accessible areas. Applicable supervisory-authority lists must also be checked.

For a Romanian deployment, the file should therefore address the applicable requirements and guidance of the Romanian data protection authority, ANSPDCP, alongside Article 35. Record the reasons for a negative screening conclusion too. A supplier’s description of a product as “low risk” is not an assessment of your processing.

Where required, the DPIA must describe the processing and purposes, assess necessity and proportionality, evaluate risks to individuals and specify safeguards. This is a substantive project assessment, not simply a signed template. Source: GDPR Article 35.

For the broader data-protection framework, see our guide to GDPR compliance when using AI in Romania.

Who needs a FRIA under the AI Act?

The Article 27 obligation does not cover every business using high-risk AI. It concerns Article 6(2) high-risk systems and specified categories of deployer, with an exclusion for the critical-infrastructure area in Annex III point 2.

  • Bodies governed by public law deploying qualifying systems.
  • Private entities providing public services deploying qualifying systems. This status requires analysis; it is not synonymous with every company selling services to the public.
  • Deployers of qualifying creditworthiness or credit-scoring systems for natural persons under Annex III point 5(b), which excludes systems used to detect financial fraud.
  • Deployers of qualifying life and health insurance risk-assessment or pricing systems for natural persons under Annex III point 5(c).

Classification under Article 6 must be checked first, including the conditions of any applicable exception. The exact intended purpose matters. A financial-sector tool is not automatically a creditworthiness system, and a medical product is not automatically within the Article 27 FRIA route. Source: AI Act Articles 6 and 27 and Annex III.

Explore four deployment scenarios

These hypothetical examples explain the screening logic. They assume the stated facts and do not replace an assessment of the actual system, applicable dates or transition rules.

Candidate ranking: DPIA and FRIA can diverge

A private manufacturer uses extensive automated applicant evaluation to support hiring decisions. These facts point to a DPIA requirement under Article 35(3)(a), even if a person makes the final decision. Recruitment may also fall within Annex III. However, on the assumption that the manufacturer is neither a public-law body nor a private public-service provider, its employer status alone does not trigger Article 27 FRIA.

Consumer credit: prepare for both assessments

A lender uses an in-scope high-risk system to score individuals for loan eligibility. Systematic and extensive profiling with significant consequences can trigger a DPIA. Article 27 separately covers qualifying deployers under Annex III point 5(b). Address the applicable FRIA timetable and any transition provisions, rather than assuming both duties started on the same date.

Public benefits: assess deployment and processing together

A public body uses a qualifying high-risk system to assess eligibility for essential assistance benefits. Its status and use case bring Article 27 into the analysis. The personal-data processing needs separate DPIA screening, including relevant public-task legislation and any Article 35(10) position. One completed assessment does not automatically discharge the other.

Drafting assistant: examine the actual workflow

A team drafts generic product descriptions without personal data or decisions about people. On those narrow facts, the workflow does not itself establish a DPIA or Article 27 FRIA requirement. Check account data, logs and supplier processing separately. Introducing customer records, employee evaluation or regulated decisions changes the analysis. Other duties may still apply.

Can one assessment document cover DPIA and FRIA?

A coordinated file can reduce duplicated work, provided each legal requirement remains identifiable. The consolidated Article 27(4) expressly allows relevant DPIA sections to be cross-referenced or incorporated into FRIA where they already meet the corresponding obligations.

Start with a shared description of the system, purposes, data flows, affected people and safeguards. Then keep a requirement map showing which sections satisfy GDPR Article 35 and which satisfy AI Act Article 27. Identify gaps rather than renaming a DPIA “FRIA”. Source: AI Act Article 27(4)–(5).

As a practical drafting approach, include a separate deployment chapter addressing who may be affected beyond the immediate users, how mistakes influence access to opportunities or services, who can intervene, and how complaints lead to corrective action. Avoid treating GDPR as only a privacy checklist: the DPIA itself must consider risks to rights and freedoms.

What the FRIA needs to address

Article 27 requires the deployment process and intended use, duration and frequency, affected people and groups, specific risks of harm, implementation of human oversight, and measures if risks materialise, including governance and complaint mechanisms. Reusing a supplier assessment in similar cases is permitted, but the deployer must check its fit and update changed or outdated elements. Source: AI Act Article 27(1)–(2).

Who prepares, reviews and owns the decision?

The controller remains responsible for the DPIA; the covered deployer remains responsible for FRIA. A consultant, DPO or supplier can contribute without taking over the organisation’s statutory role.

For the DPIA, seek the designated DPO’s advice and preserve their independent advisory and monitoring function. Obtain relevant processor assistance. For the deployment review, involve the business owner, technical team and people responsible for oversight and complaints. A useful internal decision records outstanding conditions, the person accountable for each safeguard and the circumstances requiring a fresh review. Source: GDPR Articles 28(3)(f), 35(2) and 39; AI Act Article 27.

Contractual cooperation should cover the evidence you need to assess the deployment. Our AI vendor contracts guide addresses information rights, changes and supplier responsibilities.

Must the assessment be sent to an authority?

A DPIA and a FRIA follow different authority procedures. Under GDPR Article 36, prior consultation is required where high residual risk remains that cannot be sufficiently mitigated. There is no general GDPR obligation to submit every DPIA for approval.

Article 27(3) provides for notification of FRIA results to the market surveillance authority using the relevant template, subject to the Article 46(1) exception. That notification is not the GDPR prior-consultation procedure and should not be described as automatic permission to deploy. Confirm the competent authority and operational submission arrangements for the specific deployment. GDPR Article 36; AI Act Article 27(3).

A practical assessment file before deployment

  1. Define the use case. Identify the system, version, intended purpose, users, affected people and decisions it informs.
  2. Map roles separately. Record GDPR controller/processor roles and the relevant AI Act roles.
  3. Screen the legal route. Check prohibited practices, AI classification, DPIA triggers and Article 27 deployer coverage.
  4. Record timing. Distinguish existing GDPR duties from future AI Act requirements and applicable transition provisions.
  5. Collect evidence. Obtain data-flow information, supplier instructions, meaningful performance limitations, oversight arrangements and relevant testing.
  6. Assess harms and safeguards. Describe how the actual deployment may affect people and how controls reduce those risks.
  7. Map shared sections. Make each DPIA and FRIA requirement traceable, retaining any necessary separate analysis.
  8. Resolve escalation. Identify prior consultation, notification, unresolved risks and conditions preventing launch.
  9. Assign review triggers. Consider changes in purpose, model, data, affected groups or decision authority, and evidence from incidents or complaints.

How Atrium Romanian Lawyers Assisted an International Manufacturing Group

Anonymised client matter. The description below omits identifying information and focuses on the legal work performed.

Questions examined

  • Whether the candidate-data processing required a DPIA;
  • Whether the use of the system could trigger a FRIA under the AI Act;
  • What human-oversight and documentation measures were needed before implementation.

Legal analysis

Our review of the recruitment process identified extensive automated evaluations of candidates with a significant impact on access to employment opportunities. The company therefore decided to complete a DPIA before implementation.

We also carried out a separate analysis of the system’s classification under the AI Act, including the organisation’s status and the obligations applicable to the deployer. The review confirmed that the DPIA and any FRIA analysis had to be treated separately because their legal triggers differ.

Measures adopted

  • Documentation of the decision logic and system limitations;
  • Mandatory stages of human verification;
  • Internal procedures for challenging results and handling complaints;
  • Updated contractual documentation and AI-governance workflows.

Practical result

Following the project, the company was able to continue the implementation on the basis of stronger documentation concerning compliance and risk management.

A focused consultation can clarify which assessment route applies and what your team needs before making deployment commitments.

Frequently asked questions

Does every AI project need both a DPIA and a FRIA?

No. Screen personal-data processing under GDPR Article 35 and, separately, the system and deployer under AI Act Article 27. One assessment may be mandatory while the other is not. A negative screening result does not remove other applicable legal obligations.

Does human review remove the need for a DPIA?

Not automatically. Article 35 has its own risk test, and its automated-evaluation category is not confined to solely automated decisions. Genuine human oversight can affect risks and safeguards, but a human signature does not by itself settle DPIA applicability.

Does a private employer need a statutory FRIA for recruitment AI?

Not solely because it is an employer using high-risk recruitment AI. Article 27 covers specified deployers and uses. Check whether the organisation is a public-law body or private public-service provider, while independently assessing its GDPR and other AI Act obligations.

Can we rely on the supplier’s impact assessment?

Supplier evidence can support the work, and Article 27 permits reliance on existing assessments in similar cases. The organisation still needs to check whether the document addresses its actual deployment, affected groups, safeguards and applicable obligations. A generic assurance is insufficient evidence of that fit.

Can we wait until the FRIA application date to conduct a DPIA?

No, if GDPR already requires a DPIA for the proposed processing. The DPIA must precede that processing. The AI Act timetable and transition provisions must be analysed separately and do not suspend GDPR requirements.

Does completing an assessment authorise the project?

No. An assessment documents analysis and safeguards; it does not supply a missing legal basis, legalise prohibited AI or override unresolved legal restrictions. Complete any required consultation or notification procedure and resolve conditions that prevent lawful deployment.

Commercial lease agreement in Romania with office key and floor plan

Commercial Lease Agreement Romania: 12 Key Clauses

Commercial real estate · Romania

A commercial lease is a long-term allocation of occupancy cost, operational responsibility and exit risk. Review the legal and practical controls before the premises, rent and fit-out commitments become difficult to unwind.

12 key clausesLandlord and tenant viewRomanian Civil Code focus
Decision lens Can the premises support the business, and can the contract control the downside? Use the interactive maps below to move from the commercial brief to signing, operation and exit.

A commercial lease agreement in Romania can commit a company to years of rent, service charges and restoration costs. The commercial decision therefore depends not only on the monthly headline rent, but also on whether the premises can lawfully support the tenant’s activity and whether the contract allocates operational risks clearly.

Commercial lease agreement in Romania with office key and floor plan
Commercial premises and lease documentation in Romania.

This guide is intended for landlords and companies leasing offices, retail units, warehouses and other business premises. It explains the principal clauses to check under the Romanian Civil Code and the related property, tax and authorisation framework. Residential leases and leases of public property follow additional rules and are outside this article’s main scope.

Is a written commercial lease mandatory in Romania?

Romanian law does not generally require a privately owned commercial lease to be notarised for validity. A signed written contract is nevertheless essential for evidence, enforceability, tax treatment and protection against third parties.

The lease relationship is governed principally by the Romanian Civil Code, especially the general rules on lease agreements. The parties have broad contractual freedom in a business-to-business transaction, but statutory rules apply where the lease is silent, and certain mandatory provisions of Romanian law may apply irrespective of contractual wording.

Under Article 1798 of the Civil Code, a lease concluded in authentic form, or a privately signed lease registered with the competent tax authority, may constitute an enforceable title for rent payment under the conditions stated by law. Tax registration affects enforceability, not the validity of the lease. It is not a universal requirement for the existence of every corporate lease, although the applicable tax and registration duties must still be checked for the particular landlord and transaction.

For leases requiring stronger protection against a future buyer or other third parties, the parties should assess land-book registration. The correct mechanism depends on the property, the lease term and the landlord’s registered title. A company entering a long-term lease should not assume that signature alone gives the same protection as registration.

Lease signing roadmap
From premises selection to rent commencement

Select a stage to see the legal control that should be completed before moving forward.

Define the commercial scope

Fix the exact premises, intended activity, timetable, fit-out assumptions, headline rent and critical conditions before detailed drafting begins.

What should be checked before the commercial lease is signed?

Verify the landlord, title, cadastral identity, permitted use, technical condition and authorisation route before the lease becomes unconditional.

The tenant should compare the land-book extract and cadastral plan with the space actually offered. The review should cover ownership, mortgages, litigation annotations, existing leases, access rights, parking, common areas and the landlord’s authority to grant the agreed use. These checks overlap with a focused real estate due diligence review in Romania.

The proposed activity must also be compatible with the building’s authorised use and applicable planning, fire-safety, sanitary, environmental and sector-specific requirements. A contractual statement that the tenant will obtain “all permits” does not solve a structural problem with the premises. The lease should distinguish permits relating to the building from those relating to the tenant’s own business.

For buildings or units covered by Law no. 372/2005, the owner must address the applicable energy-performance certificate obligations when leasing. The current framework covers offices, retail and other occupied commercial uses, subject to statutory exemptions. See the official energy performance legislation.

CheckTenant questionContract response
Title and authorityDoes the landlord own and control the exact premises?Attach current land-book and corporate authority evidence.
Permitted useCan the intended activity operate lawfully here?Make effectiveness or rent commencement conditional where appropriate.
Physical conditionWho bears existing defects and compliance works?Use a detailed handover report, photos and defect list.
Third-party rightsCould a lender, buyer or other tenant disrupt use?Consider lender consent, non-disturbance and land-book protection.
Utilities and capacityAre power, HVAC, access and loading capacity sufficient?Define technical specifications and remedies for shortfalls.

The 12 clauses that determine the real commercial risk

Commercial lease risk selector
Where can the lease create the greatest exposure?

Select a clause to see the negotiation priority.

Total occupancy cost

Model base rent, indexation, VAT, service charge, utilities, insurance contributions and one-off fit-out or reinstatement expenses.

1. Parties, authority and guarantees

Identify each party by its full legal name, registered office, registration number and tax code. Confirm the signatory’s authority. If a parent company, bank or shareholder gives security, specify whether it is a guarantee, autonomous demand guarantee, deposit or another instrument, together with its cap, duration and claim procedure.

2. Exact premises and permitted use

The lease should attach a plan and state the exclusive area, common-area allocation, parking and access rights. “Office use” or “commercial use” may be too vague. Describe the actual activity and deal with signage, customer access, deliveries, opening hours, hazardous materials and exclusivity if commercially relevant.

3. Term, commencement and long-stop date

Separate the signature date, handover date, fit-out access date, lease commencement and rent commencement. If delivery or permits are delayed, a long-stop date should allow the affected party to terminate. The Civil Code limits leases to a maximum statutory duration, so unusually long structures require specific review.

4. Rent, currency and indexation

State the currency, payment currency, exchange-rate source, due date and invoicing mechanics. An indexation clause should identify the index, reference period, first adjustment date, whether decreases apply and whether there is a cap or floor. Avoid combining indexation with discretionary “market rent” language unless the valuation procedure is clear.

5. VAT, withholding and invoicing

The lease of immovable property is generally VAT-exempt under the Romanian Fiscal Code, subject to important statutory exceptions and the landlord’s option to apply VAT under the prescribed procedure. Ancillary services, bundled supplies, invoicing structures and certain categories of premises may require distinct treatment. The contract should state whether figures include or exclude VAT and what happens if the VAT treatment changes. The parties should also align invoicing with the applicable Romanian electronic invoicing rules. For wider compliance context, see the site’s Romanian tax guidance.

6. Service charge and operating costs

Define recoverable costs, allocation formula, budget, reconciliation, audit rights and exclusions. Capital expenditure, financing costs, structural defects, landlord negligence, vacancy costs and costs relating to other tenants should not be hidden in a generic “all building expenses” clause. Retail leases may also involve marketing contributions and turnover reporting.

Cost itemPoint to negotiateTypical control
Base rentArea, currency, payment date and rent-free periodRent schedule attached to the lease
IndexationIndex, floor, cap and first adjustmentWorked example and no double escalation
Service chargeRecoverable categories and allocationAnnual budget, reconciliation and audit right
UtilitiesMetered consumption versus allocationSeparate meters or transparent formula
VATExempt or taxable treatmentExpress net/gross wording and change mechanism
ReinstatementRemoval and restoration at exitAgreed baseline and pre-expiry inspection

7. Deposit and financial security

Specify the amount, currency, replenishment duty, permitted deductions, return deadline and whether interest accrues. A bank guarantee should state the required issuing bank, wording, expiry buffer and renewal consequences. The landlord should not have an unlimited right to draw security for disputed amounts.

8. Handover, condition and defects

A signed handover protocol should record keys, meters, systems, inventory, photographs and defects. Define the condition standard at delivery and the remedy if the premises fail the agreed technical specifications. The tenant should not inadvertently accept latent or structural defects merely by taking possession.

9. Fit-out, alterations and ownership of improvements

Address design approval, permits, contractors, access, insurance, health and safety, delays and damage. The lease must also say whether improvements become the landlord’s property, whether compensation is available and what must be removed at expiry. These provisions should be coordinated with the construction-law implications of fit-out works.

10. Repairs, maintenance and building services

The Civil Code places core delivery, maintenance and peaceful-use obligations on the landlord, while the tenant normally bears routine repairs resulting from ordinary use, subject to the contract and the nature of the defect. A commercial lease should allocate structure, roof, façade, common systems, HVAC, internal installations and statutory upgrades expressly, together with response times and self-help rights.

Responsibility map
Who controls each category of work?

Select the responsible actor. The final allocation must be stated in the lease and coordinated with insurance and access rights.

Landlord-controlled matters

Ownership, structural integrity, roof and façade, common systems and building-level approvals normally require the landlord’s control and cooperation.

MatterStarting allocationLease control
Structure, roof and façadeLandlordResponse deadline, access and tenant remedy if use is disrupted
Routine internal maintenanceTenantStandard of care and exclusions for latent defects
Common building systemsLandlord or service-charge regimeService levels, cost allocation and outage remedies
Tenant fit-outTenant, subject to approvalDesign approval, permits, ownership and reinstatement
Statutory upgradeDepends on cause and scopeBuilding-level versus activity-specific responsibility

11. Assignment, subletting and corporate change

The Romanian Civil Code contains specific rules on assignment and subletting, which are frequently modified by commercial lease clauses. The contract should therefore state whether landlord consent is required and on what conditions. The tenant may seek objective consent standards for group reorganisations, business transfers and subleases, while the landlord may require financial tests or continued liability.

12. Default, termination, force majeure and hardship

List the defaults that justify termination, notice method, cure periods and consequences. Non-payment, unlawful use, loss of permits and abandonment need different treatment. Insolvency provisions should be reviewed together with the applicable insolvency legislation: Article 123 of Law no. 85/2014 maintains ongoing contracts at the opening of insolvency proceedings and may limit clauses that terminate or accelerate solely because insolvency has commenced. Force majeure should address genuine impossibility, while hardship or major economic disruption requires a separate allocation because increased cost alone is not automatically force majeure.

What happens if the building is sold?

A tenant should not rely on a simple “sale does not affect the lease” sentence. Ongoing protection depends on the Civil Code’s opposability rules and the steps taken to make the lease effective against the buyer.

Articles 1811 and following of the Civil Code regulate when a lease is opposable to a purchaser and the consequences of transferring the leased property. For registered immovable property, notation of the lease in the Land Registry is a central opposability mechanism; other statutory rules may apply depending on the property and transaction. The lease should require the landlord to notify a sale, procure the buyer’s assumption of obligations and transfer the deposit or guarantees correctly. For material long-term premises, the tenant should assess Land Registry notation and lender non-disturbance arrangements. The seller’s continuing liability, if any, should be stated rather than assumed.

Can the landlord enforce unpaid rent without a full lawsuit?

Potentially yes. A qualifying lease may constitute an enforceable title for rent, but enforceability depends on the contract’s form or tax registration and on the claim being due and sufficiently determined.

Article 1798 of the Civil Code gives qualifying leases enforcement value for rent. Separate rules may also support restitution of the premises when a fixed-term lease expires. Parties should coordinate default clauses with Romanian civil procedure and should not assume that a contractual label such as “enforceable” creates enforcement rights by itself. Broader non-payment strategies are covered in the guide to recovering unpaid business claims in Romania.

Exit & default risk map
How can the lease relationship end?

Select a route to review the clause that should control notice, cost and handover.

Expiry of the agreed term

Set the handover date, inspection process, reinstatement standard, deposit reconciliation and treatment of any continued occupation.

Exit eventDocument to controlMain financial exposure
Fixed-term expiryExpiry notice and handover protocolReinstatement, dilapidations and deposit deductions
Tenant breakBreak notice complying exactly with the clausePenalty, incentive repayment or remaining liabilities
Termination for breachDefault notice and evidence of cure periodArrears, damages, security draw and enforcement costs
Property saleBuyer assumption and opposability evidenceDeposit transfer and continuity of tenant rights
Continued occupationWritten extension or renewal termsUncertain rent, duration and exit notice

Landlord and tenant negotiation checklist

  1. Verify title, cadastral identity, authority and encumbrances.
  2. Confirm that the building and the intended activity can obtain the necessary approvals.
  3. Attach the plan, technical specifications, handover standard and fit-out rules.
  4. Model rent, indexation, VAT, service charge, utilities and exit costs.
  5. Allocate structural, routine and statutory repair obligations precisely.
  6. Align guarantees with actual exposure and release dates.
  7. Negotiate cure periods, break rights, long-stop dates and restoration obligations.
  8. Assess tax registration, enforceability and land-book protection.
  9. Record condition, meters, defects and assets in the handover protocol.
  10. Retain signed notices, invoices, approvals and service-charge reconciliations.

The bottom line

A commercial lease agreement in Romania is primarily a long-term allocation of business risk. The strongest contract is not necessarily the longest. It is the one that identifies the premises accurately, prices the full occupancy cost, makes the authorisation path workable and provides realistic remedies when delivery, operation or exit does not go as planned.

Before committing to a significant lease, both landlord and tenant should coordinate the legal document with technical due diligence, tax treatment, insurance and the operational timeline. A focused contract review in Romania can identify inconsistencies before the commercial timetable makes them expensive to correct.

Frequently Asked Questions

Must a Romanian commercial lease be notarised?

No, not as a general validity rule for a private commercial property. However, authentic form, tax registration and land-book notation can have different consequences for enforcement and opposability. The right structure depends on the parties, term, property and intended protection.

Can rent be stated in euros but paid in Romanian lei?

Yes, parties often denominate rent in euros and provide payment in lei. The lease should identify the exchange-rate source and date, address bank charges and avoid ambiguity about whether indexation applies before or after currency conversion.

Is VAT charged on commercial rent in Romania?

The lease of immovable property is generally VAT-exempt, subject to important statutory exceptions and the landlord’s option to apply VAT under the prescribed procedure. Ancillary services, bundled supplies, invoicing structures and certain premises may receive distinct treatment. The lease should state whether amounts are net or gross and allocate change-of-law risk.

Who pays for repairs in a Romanian commercial lease?

The Civil Code provides a default allocation, broadly separating the landlord’s obligation to maintain usable premises from routine tenant repairs. Commercial contracts usually refine this substantially. Structure, building systems, internal installations, negligence and statutory upgrades should each be addressed expressly.

Can a tenant terminate a fixed-term commercial lease early?

Only if the contract or applicable law provides a right to do so, or if a sufficiently serious breach justifies termination. Businesses should negotiate express break rights, notice periods, conditions and any repayment of incentives rather than rely on a general expectation of early exit.

Does the lease continue if the property is sold?

It may continue against the buyer when the Civil Code’s opposability requirements are satisfied. The tenant should assess land-book notation, the landlord’s sale obligations and any lender arrangements, particularly for high-value fit-out or a long remaining term.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.

Open office door representing employee dismissal and professional transition in Romania

Employee Dismissal in Romania: Employer Guide

Employee dismissal in Romania is lawful only when the employer relies on a ground recognised by the Labour Code and follows the procedure attached to that specific ground. A genuine business reason is not enough if the required notice, investigation, evaluation, consultation or written decision is defective.

What Romanian employers should know:

  • First identify the correct termination route; dismissal is only one way an employment contract may end.
  • Match the evidence and procedure to the legal ground before communicating a decision.
  • A minimum 20-working-day notice applies to certain dismissals, not to every dismissal.
  • Procedural breaches can lead to absolute nullity, salary compensation and, if requested, reinstatement.
  • The employer normally carries the burden of proving the legality and factual basis of the measure in court.

This guide is intended for Romanian companies, foreign investors, HR teams and managers considering an individual or collective dismissal. It reflects the structure of the Romanian Labour Code and highlights the points that most often create litigation risk. For advice on a particular case, see our Romanian employment law services.

Employment dismissal documents reviewed in a Romanian corporate office
A defensible dismissal decision begins with the correct legal ground, evidence and procedure.

Is every employment termination a dismissal?

No. Under Article 58 of the Romanian Labour Code, dismissal is the termination of an individual employment contract at the employer’s initiative. It may be based on reasons related to the employee or on reasons unrelated to the employee.

Dismissal should not be confused with termination by mutual agreement, resignation, expiry of a fixed-term contract, termination by operation of law or written termination during or at the end of a probationary period under Article 31(3). Termination during the probationary period is a distinct mechanism, separate from dismissal. Each route has different conditions. Relabelling a unilateral dismissal as a “mutual termination” does not make it consensual; genuine agreement must exist.

Practical point: decide the legal route before drafting documents. Mixing several grounds in one decision, or changing the ground after litigation begins, can undermine the defence.

Route selector
Choose the correct termination route

Select a route to see its legal character. The route must be identified before documents are drafted.

Dismissal

Employer-initiated termination under Article 58. It requires a statutory ground and the procedure attached to that ground.

Legal grounds for employee dismissal in Romania

The main grounds are divided between reasons related to the employee and reasons unrelated to the employee. The required evidence and procedure differ substantially.

GroundCore legal testKey procedural safeguard
Disciplinary misconductA serious breach or repeated breaches of work discipline, the employment contract, collective agreement, internal regulations or lawful managerial orders.Prior disciplinary investigation, except for a written warning.
Preventive arrest or house arrestThe measure lasts for more than 30 days, under the conditions of the Criminal Procedure Code.Written and reasoned decision within the applicable statutory period.
Medical unfitnessPhysical or mental unfitness is established by a decision of the competent medical bodies.Consideration and offer of compatible vacant positions under Article 64.
Professional inadequacyThe employee is professionally unfit for the position held.Prior evaluation under the procedure in the applicable collective agreement or internal regulation, plus Article 64 vacancy steps.
RedundancyThe position is effectively eliminated for a real and serious cause unrelated to the employee.Documented reorganisation and at least 20 working days’ notice; collective rules may also apply.

When is dismissal prohibited?

Before any employee dismissal in Romania, the employer should check both Articles 59 and 60 of the Labour Code. Article 59 prohibits dismissal on protected grounds, including protected characteristics, trade-union membership or activity, lawful participation in a strike and the exercise of specified employment rights. Article 60 creates temporary prohibitions during specified periods, including certified temporary incapacity for work, quarantine, maternity leave, parental leave, leave to care for a sick child, annual leave, paternity leave, caregiver leave and certain emergency family absences. A pregnant employee is protected if the employer knew of the pregnancy before issuing the decision. Separate anti-discrimination and retaliation rules may also apply under Law no. 202/2002 and the Whistleblower Protection Law no. 361/2022.

The protected-period analysis should be made immediately before the dismissal decision is issued and communicated. Article 60 also contains an exception linked to judicial reorganisation, bankruptcy and dissolution of the employer, but it should be applied only after checking the employer’s precise legal status and the special insolvency rules.

Does every dismissed employee receive 20 working days’ notice?

No. Article 75 grants a minimum notice period of 20 working days for dismissal due to medical unfitness, professional inadequacy and redundancy under Articles 65 and 66. It does not create a universal notice period for every type of dismissal. In particular, disciplinary dismissal does not carry the same statutory notice entitlement.

The notice period and its start date should be documented clearly. Employers should not assume that paying an equivalent amount automatically remedies a failure to observe the statutory notice period. If the parties want a negotiated exit with compensation, that should be structured separately as a genuine mutual termination agreement.

How does disciplinary dismissal work?

Employee dismissal in Romania based on misconduct is the most procedure-sensitive route. Before imposing it, the employer must ordinarily conduct the prior disciplinary investigation regulated by Article 251. The process should include a written summons specifying the subject, date, time and place of the meeting, a real opportunity for the employee to present explanations and evidence, and a documented assessment of the defence.

The sanction must also be proportionate. Article 250 requires the employer to consider factors such as the circumstances of the misconduct, degree of fault, consequences, the employee’s general conduct and any previous disciplinary sanctions. A finding that misconduct occurred does not automatically justify dismissal if a lesser sanction is proportionate.

The disciplinary decision must be issued in writing within 30 calendar days from the date the employer became aware of the misconduct, but no later than six months from the date of the act. It must contain all mandatory elements under Article 252 and be communicated within five calendar days of issue. Read our dedicated guide to the disciplinary procedure in Romania.

Evidence that usually matters

  • the internal regulation, policies and lawful instructions allegedly breached;
  • proof that the employee received or could access those rules;
  • emails, access logs, reports, witness statements or other lawfully obtained evidence;
  • the summons, interview record, employee’s written defence and supporting documents;
  • a reasoned proportionality assessment; and
  • proof of issuing and communicating the final decision within the statutory periods.

How should professional inadequacy be documented?

Professional inadequacy concerns the employee’s ability to meet the professional requirements of the role; it is not a disciplinary accusation. Article 61(d) provides the legal ground for dismissal, while Article 63(2) requires the employee to undergo a prior evaluation under the procedure established by the applicable collective labour agreement or, in its absence, the internal regulation.

The evaluation should rely on objective, role-related standards communicated in advance. The job description, performance objectives, prior reviews, training records and concrete work results should tell a consistent story. A hastily created evaluation standard or a process designed around one predetermined outcome is vulnerable to challenge.

Before dismissal, Article 64 requires the employer to offer available positions compatible with the employee’s professional training or, where relevant, work capacity. If no suitable vacancy exists, the employer must seek the support of the territorial employment agency. The employee has three working days to express written consent to an offered position.

What is required for medical-unfitness dismissal?

Medical unfitness under Article 61(c) cannot rest on a manager’s impression or an ordinary performance assessment. It must be established through a decision of the competent medical bodies. The employer must then follow the compatible-vacancy process under Article 64 and grant the minimum statutory notice.

This ground should also be kept distinct from disability discrimination and reasonable workplace accommodation issues. Medical information must be handled with particular attention to confidentiality and data-protection requirements.

When is redundancy lawful?

Employee dismissal in Romania for redundancy is governed principally by Article 65. It is lawful when the employee’s position is effectively eliminated and the elimination has a real and serious cause unrelated to that employee. The employer does not have to prove that dismissal was the only imaginable business choice, but it should be able to show that the reorganisation is genuine and that the eliminated role no longer exists in substance.

A defensible file commonly includes the competent corporate decision, the business rationale, organisational charts before and after implementation, the updated headcount and job descriptions, financial or operational supporting material where relevant, and evidence that the employee’s duties were genuinely removed or redistributed.

A changed job title alone is not decisive. Courts can examine whether a supposedly eliminated position continues in substance or is promptly refilled under a different label.

Where only some identical or comparable positions are removed, the selection issue requires particular care. In Decision no. 30/2020, the High Court declined to rule on the merits and dismissed the recurs în interesul legii as inadmissible. It held that the question concerned applying the law to specific facts rather than resolving a genuine issue of legal interpretation. The decision therefore did not unify the divergent lower-court approaches described in the referral on whether selection criteria are required when an employer eliminates only some positions from a group of identical or similar positions. As a risk-management measure, any criteria used should be objective, consistently applied and supported by evidence.

Employers planning a broader reorganisation may also consult our guide to employee rights during company restructuring in Romania.

When do collective-dismissal rules apply?

A redundancy programme can become a collective dismissal if, within a period of 30 calendar days, the statutory thresholds in Article 68 are reached.

Employer workforceCollective-dismissal threshold within 30 calendar days
More than 20 and fewer than 100 employeesAt least 10 employees
100–299 employeesAt least 10% of employees
300 or more employeesAt least 30 employees
Live threshold check
Collective dismissal threshold check

Enter the employer’s total workforce and the dismissals planned within 30 calendar days.

Enter both figures, then select “Check threshold”.

This is a preliminary numerical check. Article 68 aggregation and the treatment of other employer-initiated terminations must still be reviewed.

For threshold calculations, certain other employer-initiated terminations for reasons unrelated to the employee may also be counted when the statutory conditions are met. Fragmenting one programme into several documents or dates does not necessarily prevent the collective rules from applying.

The employer must begin consultations with the trade union or employee representatives in good time, provide the written information required by Article 69 and genuinely examine ways to avoid or reduce dismissals and mitigate their consequences. If the programme proceeds, the territorial labour inspectorate and territorial employment agency must receive the statutory notification at least 30 calendar days before dismissal decisions are issued, subject to the detailed Labour Code procedure.

What must the written dismissal decision contain?

The applicable deadline and the mandatory content should be analysed separately. Article 62 establishes the deadline for issuing decisions based on Article 61(b)–(d) and also requires the decision to state its factual and legal reasons, the challenge period and the competent court. Article 76 sets out the other mandatory elements applicable to dismissal decisions, while Article 252 contains the specific requirements for disciplinary decisions. Depending on the case, the written decision should include:

  • the factual and legal reasons for dismissal;
  • the duration of the notice period, where applicable;
  • the collective-dismissal selection criteria, where applicable;
  • the list of available positions and the Article 64 response period, where applicable;
  • for a disciplinary sanction, the mandatory elements in Article 252, including why the employee’s defence was rejected; and
  • the statutory challenge period and competent court, where required.

The decision produces effects from communication to the employee. Communication should therefore be provable. The employer cannot ordinarily defend the case by introducing new dismissal reasons that were absent from the decision.

What are the main employer risks if the dismissal is unlawful?

A failure to comply with the legally required procedure results in absolute nullity under Article 78. Under Article 80, if the court cancels the dismissal, it orders compensation equal to the indexed, increased and updated salaries and the other entitlements the employee would have received. At the employee’s request, the court also restores the parties to the position existing before dismissal by ordering reinstatement.

Employment disputes move quickly and the employer bears the burden of proof under Article 272. A disciplinary decision may be challenged within 30 calendar days of communication under Article 252(5). For most other dismissal-related employment disputes, employees generally have 45 calendar days to challenge the measure under Article 268, calculated from the date on which the person concerned became aware of it, subject to the specific provisions applicable to the type of claim.

Risk map
Employer risk map

Select a consequence to see where the principal exposure arises.

Nullity

A dismissal ordered without observing the statutory procedure is affected by absolute nullity under Article 78.

Additional exposure may arise from discrimination, whistleblower retaliation, unpaid rights, data-protection violations, collective consultation failures or inconsistent treatment of comparable employees.

A practical pre-dismissal checklist for employers

Legal roadmap
Pre-dismissal legal roadmap

Select each step to review the purpose of the control before moving forward.

Legal ground

Identify the exact statutory route first. The evidence, notice and procedure depend on this classification.

  1. Identify the legal route. Confirm whether the case is dismissal, mutual agreement, resignation, expiry, probationary termination or another statutory form.
  2. Check protected status. Verify leave, medical incapacity, pregnancy notifications, representative status, whistleblowing and discrimination risks.
  3. Confirm decision-making authority. Make sure the correct corporate or managerial body approves the measure.
  4. Audit governing documents. Review the employment contract, job description, internal regulation, policies and collective agreement.
  5. Build the evidence file. Preserve documents lawfully and avoid post-hoc rationales.
  6. Run the ground-specific procedure. Investigation, professional evaluation, medical decision, vacancy search or reorganisation documentation cannot be interchanged.
  7. Check collective thresholds. Look at the complete 30-day programme, not only one employee or one department.
  8. Calculate notice correctly. Apply it only where legally required, but do not shorten it.
  9. Draft and quality-check the decision. Confirm every mandatory element, factual statement, date and attachment.
  10. Plan communication and litigation readiness. Retain proof of delivery and a complete, chronological file.

If employment status itself is uncertain, first review our analysis of employee versus contractor risks in Romania. For prevention at the hiring stage, see our guidance on employment contracts in Romania.

Frequently asked questions

Can an employee be dismissed while on sick leave?

As a rule, dismissal cannot be ordered during certified temporary incapacity for work. The employer should verify the medical certificate and the timing of both issuance and communication of the decision. The Labour Code contains a limited exception linked to judicial reorganisation, bankruptcy or dissolution.

Is 20 working days’ notice required for every dismissal?

No. The statutory minimum applies to dismissal for medical unfitness, professional inadequacy and redundancy under Articles 65 and 66. It does not generally apply to disciplinary dismissal.

Can the employer pay salary instead of granting notice?

The Labour Code grants a working notice period in the situations covered by Article 75. An employer should not assume that unilateral payment cures failure to grant it. A separately negotiated mutual termination may include compensation, but it must reflect genuine consent and should be documented accordingly.

Is severance pay mandatory in Romania?

There is no universal statutory severance amount for every redundancy. Article 67 states that affected employees may benefit from compensation under the law and the applicable collective labour agreement. The employment contract, internal policies and established practice should also be checked.

Can an employer eliminate a position and later hire someone else?

Hiring for a materially similar role soon after dismissal may suggest that the original elimination was not effective. The legal assessment turns on substance: duties, organisational need, timing and evidence—not the title alone.

How long does an employee have to challenge dismissal?

A disciplinary sanction may be challenged within 30 calendar days from communication. For other unilateral measures concerning termination, the Labour Code generally provides 45 calendar days from the date the employee became aware of the measure. Case-specific verification is advisable.

Planning or defending employee dismissal in Romania?

We assist employers with dismissal strategy, disciplinary investigations, performance procedures, redundancy documentation, collective consultation and employment litigation.

Discuss the case with a Romanian employment lawyer

Disclaimer: This article provides general information and does not constitute legal advice. The correct procedure depends on the dismissal ground, employment documents, employee status and facts of the case.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Corporate buildings connected by a glass bridge, symbolising solutions to shareholder deadlock in Romania

Shareholder Deadlock in Romania: Exit and Remedies

Corporate governance · Romania

Shareholder Deadlock in Romania: Exit and Remedies

A shareholder deadlock can stop budgets, appointments, financing, contracts and an eventual sale. This guide explains how Romanian shareholders and foreign investors can define the deadlock, preserve ordinary operations, escalate the dispute and use a negotiated or statutory exit route.

The correct response depends on the company type, articles of association, shareholder agreement, voting structure, conduct and remedy sought. The current version of Law no. 31/1990 and the company’s documents should be checked before action.

In short: equal ownership does not automatically mean that a Romanian company is deadlocked. The practical problem arises when a required decision cannot be validly adopted and the failure materially affects the company. The safest response is usually a staged mechanism: define the blocked decision, protect essential operations, escalate, attempt an appropriate form of resolution and preserve any court or exit remedy.

What happens when Romanian shareholders can no longer make decisions?

A deadlock is a governance problem before it becomes a lawsuit. The company may be unable to approve a budget, appoint a manager, authorise financing, sign a material contract or decide whether to sell. The first task is to identify the exact decision that is blocked and the rule that prevents it from being adopted.

A disagreement about strategy is not automatically a legal deadlock. The issue becomes more serious when the required majority, unanimity or joint-signature rule cannot be reached, the dispute continues after a properly convened meeting and the company’s operations are materially affected. A minority investor with a veto may create the same practical risk as two 50/50 shareholders.

Decision blocked

Identify the resolution, voting threshold, quorum, notice and evidence of the failed decision.

Business exposed

Protect payroll, taxes, essential suppliers, insurance, records and ordinary-course activity while the dispute is addressed.

Exit required

Use escalation, mediation, expert determination, buy-sell, transfer, withdrawal or dissolution only where the facts support it.

Important: a shareholder should not assume that stopping all company activity creates negotiating leverage. Directors and administrators still have duties to the company, and emergency or compliance decisions may need to continue.

How should a shareholder diagnose the deadlock?

The diagnosis should compare four documents and four realities: the articles of association, any shareholders’ agreement, the mandates and signing authorities, and the company’s actual governance practice. A private agreement may create obligations between shareholders, but it does not automatically replace the constitutional rules that operate through the company.

Select the point that determines the next governance decision.

Define the blockage

Record the decision that failed, the meeting notice, votes cast, applicable threshold and the operational consequence for the company.

Diagnostic questionWhat to reviewWhy it mattersImmediate control
What decision is blocked?Agenda, minutes, written refusals, voting record and company impact.Separates a material deadlock from an ordinary disagreement.Send a written notice identifying the decision and the consequence.
Which rule applies?Articles, shareholder agreement, Law no. 31/1990 and signing mandates.A private veto may not operate like a statutory voting rule.Map the legal effect of the rule before threatening a remedy.
Can ordinary activity continue?Last approved budget, administrator powers, bank instructions and compliance deadlines.Prevents the dispute from unnecessarily damaging the business.Define essential expenditure and information access while escalation runs.
What is the desired outcome?Continuation, buyout, sale, mediation, court remedy or dissolution.Different outcomes require different documents, evidence and timetables.Select a route proportionate to value, urgency and relationship.

Why must the shareholders’ agreement match the articles of association?

A shareholders’ agreement is normally a private contract between its parties. The articles of association are the company’s constitutional document and contain rules that function through the corporate structure. If the agreement promises a veto but the articles allow the resolution to pass by a lower majority, a shareholder may have a contractual claim without being able to stop the corporate resolution.

For a Romanian SRL, Article 192 of Law no. 31/1990 provides default rules on the majority required for decisions, subject to the statutory framework and the articles. Article 193 addresses voting through social parts. Where capital parity prevents an absolute majority from being established, Article 7(d¹) should be considered when drafting the method for adopting general-meeting resolutions with the participation and vote of all shareholders.

The documents should be coordinated on quorum, notice, voting thresholds, administrator powers, joint-signature rules, reserved matters, transfer restrictions and the treatment of a failed vote. The agreement can contain confidential commercial mechanics, but the corporate rules needed to operate the company should be reflected in the articles and, where required, in registered information.

Articles

Set the constitutional voting and governance rules that operate through the Romanian company.

Shareholder agreement

Add private obligations, escalation steps, information rights, valuation and exit mechanics.

Mandates

Make sure administrator powers and signing authorities do not contradict the agreed decision structure.

How should reserved matters and veto rights be drafted?

Reserved matters protect investors from fundamental changes, but an excessive list can turn normal management into permanent negotiation. Each matter should have a clear financial or strategic threshold, an approval level, a decision-maker and a timetable. The drafting should distinguish shareholder matters from administrator or management matters.

The agreement should state whether consent may be withheld freely or only for specified reasons. It should also explain what happens when a meeting fails, when information is missing, when one shareholder does not attend and when the same proposal is rejected more than once. Silence should not accidentally authorise a major transaction, but it should not paralyse routine activity either.

ClausePurposeDrafting controlDeadlock consequence
Deadlock definitionIdentifies when the process begins.Use material matters, repeated failed votes and written notice.Starts the agreed escalation timetable.
EscalationMoves the issue beyond the original negotiators.Name decision-makers, documents and realistic deadlines.Creates a final internal opportunity to resolve the issue.
Interim operationsKeeps the company functioning.Continue the last approved budget and essential compliance activity.Limits value destruction while the dispute continues.
Buy-sell mechanismAllows one shareholder to acquire the other’s interest.Define price, funding evidence, completion and default.Creates a controlled exit instead of indefinite blockage.
Final remedyEnds an unresolved dispute.Coordinate contractual sequence with statutory rights.Use court dissolution only as a genuine last resort.

What escalation process should come first?

A workable process usually begins with a written deadlock notice. The notice should identify the decision, the failed vote, the relevant documents, the operational risk and the proposed date for a second meeting. It should avoid inflammatory language and should preserve the shareholder’s position without treating every negotiation statement as an admission.

The next stage may involve senior representatives of the shareholder groups who were not involved in daily management. Mediation can help where the dispute concerns valuation, business strategy or loss of trust. Expert determination is more suitable for a discrete accounting, technical or valuation question. The agreement should define the scope of each process and the effect of the decision.

A cooling-off period may be useful, but it should not be so long that it allows statutory challenge periods, financing deadlines or insolvency risks to expire. Information rights, confidentiality and interim access to company records should remain clear throughout the process.

Select the preferred outcome to see the main control.

Continue together

Restore decision-making with a documented escalation, revised mandates, clearer reserved matters and an agreed interim operating plan.

How can the company operate during the deadlock?

A deadlock clause should not become a licence to stop salaries, taxes, insurance, essential supplies or compliance filings. The parties should identify what can continue under the last approved budget and what requires a fresh shareholder decision. Emergency expenditure should be narrowly defined and documented.

Shareholders should preserve access to accounts, records and management information. Neither party should divert customers, employees, intellectual property or corporate opportunities while the exit process is pending. A director or administrator must continue to act within the duties owed to the company. A shareholder instruction does not legalise conduct that breaches mandatory law or harms the company.

The practical protocol should cover bank access, payment approvals, payroll, tax filings, customer communication, data security, insurance, licences and the retention of corporate records. If the company has two administrators who must sign jointly, the parties should check whether that arrangement itself is causing the standstill and whether a lawful adjustment is possible.

Which buy-sell mechanisms can resolve a deadlock?

A buy-sell mechanism can produce a clean exit, but labels such as “Russian roulette” or “Texas shoot-out” are not enough. The clause must explain who may start the process, whether the initiating shareholder offers to buy or sell, how a price is determined and what happens if the other party cannot complete.

These mechanisms may disadvantage a shareholder with less access to financing. Safeguards can include evidence of funds, a minimum price, independent valuation, a reasonable completion period and restrictions on using confidential company information to finance the acquisition. The agreement should address shareholder loans, guarantees, accrued dividends, management positions, releases and the transfer of company property or intellectual property.

For an SRL, transfer restrictions must also be reviewed under Law no. 31/1990 and the articles. Transfers between existing shareholders and transfers to an outsider may be subject to different approval rules. The transfer should be coordinated with the shareholders’ register, the Trade Register filing and any update to beneficial-owner information or regulatory analysis required by the transaction.

What legal remedies exist when there is no workable clause?

The available remedy depends on the company type, the conduct and the relief sought. A shareholder may challenge an unlawful corporate resolution under the applicable company-law rules, but strict procedural periods can apply. The shareholder should preserve the minutes, notices, voting record, documents and evidence of the company’s operational impact before negotiations are allowed to drift.

For an SRL, Article 226 of Law no. 31/1990 may permit withdrawal in the cases stated in the articles, with the agreement of the other shareholders or, where agreement is absent, for serious grounds established by the tribunal. The value of the withdrawing shareholder’s rights may require agreement, expert work or court determination.

Exclusion is not a general cure for deadlock. Article 222 contains specific statutory situations and should not be treated as a broad remedy for an unpleasant or uncooperative shareholder. A company cannot simply exclude a shareholder because negotiations have failed.

Judicial dissolution under Article 227(1)(e) may be available for serious reasons, including grave disagreements that prevent the company from functioning. Dissolution destroys the going-concern investment and may reduce value, so it should normally remain the last remedy after contractual and commercial solutions have been assessed. It is not a substitute for drafting a workable exit clause.

Should a deadlock dispute go to court or arbitration?

Arbitration may offer confidentiality, specialist decision-makers and procedural flexibility, especially in a cross-border investment. The clause must identify the institution or ad hoc rules, seat, language, number of arbitrators and governing law. It should also address urgent relief, interim measures and the relationship with the company and other transaction documents.

Not every corporate issue can be solved only between the contracting shareholders. Some resolutions, registrations or remedies affect the company and require statutory procedures or Trade Register steps. A dispute clause should distinguish contractual claims from company-law remedies and ensure that the company is bound where that is legally possible and commercially intended.

Before filing, compare the value of the investment, the urgency, the evidence, the effect on the business, the available interim relief and the likelihood that a judgment or award can be implemented. Litigation or arbitration can resolve a legal question, but it may not restore the commercial relationship. A negotiated buyout can sometimes preserve more value than a technically successful dissolution claim.

Pre-signing shareholder deadlock checklist

  • Identify decisions that require shareholder approval, administrator approval or joint signatures.
  • Define deadlock by reference to material matters, repeated failed votes and written notice.
  • Coordinate the articles of association, shareholders’ agreement, mandates and registered information.
  • Set realistic escalation steps and name the people who must participate.
  • Protect ordinary-course operations, payroll, taxes, insurance, records and essential contracts.
  • Choose mediation, expert determination or a buy-sell process for the type of dispute it can actually resolve.
  • Define valuation date, methodology, adjustments, discounts, expert appointment and cost allocation.
  • Address transfer restrictions, pre-emption, tag-along, drag-along and Trade Register formalities.
  • Require funding evidence and completion documents for any buyout mechanism.
  • Preserve statutory challenge periods and do not let negotiation remove the right to seek urgent relief.

Frequently asked questions

Is a 50/50 Romanian company automatically deadlocked?

No. Equal ownership creates structural risk, but deadlock exists only when a required decision cannot be adopted and the failure materially affects the company. The articles and shareholder agreement should address parity, governance and exit mechanics.

Can one shareholder force the other to sell?

Only if a valid contractual or statutory mechanism permits it and its conditions are satisfied. A buy-sell clause must address price, funding, completion, transfer formalities and default consequences.

Can a shareholder be excluded simply for causing deadlock?

Not automatically. Exclusion is governed by specific statutory situations and cannot be used as a general remedy merely because the shareholders disagree or negotiations have failed.

Can a shareholder withdraw from a Romanian SRL?

Withdrawal may be available under Article 226 of Law no. 31/1990 in the cases stated in the articles, with the required agreement or, in the absence of agreement, for serious grounds established by the tribunal.

Can shareholder deadlock lead to dissolution?

Yes, judicial dissolution may be available for serious reasons, including grave disagreements that prevent the company from functioning. It is a last-resort remedy because it may destroy going-concern value.

Should the deadlock clause appear in both documents?

Critical voting, governance and registered transfer rules should be coordinated with the articles of association and mandates. Private commercial details may remain in the shareholders’ agreement, subject to enforceability and confidentiality analysis.

Need a Romanian deadlock clause or exit strategy?

A focused review can align the articles, shareholder agreement, voting structure, interim protections, valuation process and available remedies.

Book a consultation

Disclaimer: This article provides general information only and does not constitute legal advice or the creation of a lawyer-client relationship. The correct approach depends on the company type, constitutional documents, shareholder agreement, facts, evidence and remedies sought. Obtain a case-specific assessment before taking corporate or litigation steps.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.

Geometric maze illustrating contractual risk assessment during a contract review in Romania

Contract Review in Romania: 12 Clauses to Check

Which contract clauses should a business check before signing?

A Romanian business contract should clearly allocate performance, payment, liability, intellectual-property, data and exit risks. These 12 clauses are the practical starting point for a legal and commercial review.

Contract review in Romania should test more than whether an agreement is formally valid. Before signing, a business should understand what it must deliver, when it will be paid, which losses it may bear, how intellectual property and data may be used, and how the relationship can end.

Commercial contracts are often negotiated under pressure. A supplier is ready to begin, a customer wants the final draft immediately, or a foreign group needs its Romanian operation running without delay. That is precisely when unclear wording, inconsistent annexes and borrowed template clauses are most likely to pass unnoticed. Companies entering the market should connect the contract with the wider steps required to start and operate a business in Romania.

Interconnected architectural structure illustrating how contract clauses work together in a Romanian contract review
A well-structured contract depends on interconnected clauses that allocate obligations, remedies and commercial risks consistently.

Under the Romanian Civil Code, a validly concluded contract is binding on the parties, and contractual negotiations and performance are governed by good faith. A useful review therefore connects the legal wording with the operational deal. It identifies which party controls each risk, whether the agreed remedy can work in practice, and what evidence will be needed if performance is disputed.

The following 12 clauses form a practical checklist for Romanian companies and foreign businesses entering agreements governed by Romanian law or involving a Romanian counterparty.

Parties, capacity and signing authority

The contract should identify the correct legal entities, not merely the brand names used in negotiations. For a Romanian company, check its registered name, registered office, Trade Registry number, fiscal identification code and representative. If a group is involved, establish which entity receives the services, issues invoices, owns the relevant assets and assumes liability.

Signing authority should be verified against the company’s constitutional documents, Trade Registry information, corporate approvals or a power of attorney. A signature block describing someone as a “manager” does not itself resolve whether that person may bind the company for the relevant transaction. The representation rules should be checked against the company’s current Romanian articles of incorporation and the registered powers of its administrators.

The internal authority analysis also matters for potential Romanian company director liability, particularly where a director signs outside approved limits or fails to document a material commercial decision.

Check before signingConfirm the contracting entity, the signatory’s authority, any required corporate approval, the position of affiliates and whether subcontracting or assignment to another group company is permitted.

Scope, deliverables and acceptance

The scope clause should describe the goods or services, specifications, quantities, locations, deadlines, dependencies and exclusions. For project work, it should also establish milestones, acceptance tests, correction periods and a change-control procedure.

Review the main agreement together with proposals, statements of work, order forms and technical annexes. If they conflict, an order-of-precedence clause should determine which document controls. Acceptance by silence should also be tested carefully: specify when the review period begins, what constitutes a valid rejection and what happens when defects are minor. Providers using standard customer documentation should also verify the applicable service contract requirements in Romania.

Common riskThe commercial proposal promises one result, the technical annex describes another and the general conditions allow the supplier to treat delivery as accepted before meaningful testing has taken place.

Price, VAT, invoicing and payment

A complete payment clause states the price or calculation method, currency, VAT treatment, invoicing trigger, payment deadline, supporting documents, bank charges and the procedure for disputing an invoice. It should also explain whether the customer may withhold, deduct or set off amounts and whether the supplier may suspend performance for non-payment.

For B2B transactions, Law no. 72/2013 on late payment contains mandatory protections. Article 5(1) establishes a general 60-calendar-day limit for contractual payment terms between professionals. By exception, the parties may agree a longer payment term, provided that the clause is not abusive under Article 12. A term exceeding 60 days is therefore not automatically invalid, but it should be assessed carefully for gross unfairness to the creditor in light of the statutory criteria and the circumstances of the transaction. Where the applicable conditions are met, late payment can trigger statutory penalty interest and the fixed EUR 40 recovery compensation.

For the calculation rules and available remedies, see our guide to late-payment interest and penalties in Romania.

Term, renewal and minimum commitments

The agreement should state its effective date, initial duration and whether it renews automatically. An automatic renewal clause is not necessarily problematic, but the notice window, notice method and effect of a missed deadline must be clear.

Check minimum purchase commitments, exclusivity, take-or-pay obligations and price changes that continue into a renewal term. Add internal calendar reminders for any deadline that determines whether the company remains bound for another year or loses a renegotiation opportunity.

Check before signingIdentify the earliest exit date, the last date for a non-renewal notice and every financial or operational commitment that survives renewal.

Termination, cure periods and exit assistance

The termination clause should distinguish between serious breach, remediable breach, insolvency-related events, prolonged force majeure and termination for convenience. It should specify whether prior notice is required, how long the defaulting party has to cure, and whether termination operates through a contractual mechanism or requires another legal step.

The Romanian Civil Code regulates remedies for non-performance, including termination under Article 1549 and the related provisions. The contract should not merely say that a party “may terminate immediately”. It should align the grounds, notice mechanics and agreed effects with the type of contract and the intended remedy.

Exit provisions matter just as much as the termination trigger. Address final invoices, transition assistance, return of equipment and documents, data export, deletion, continued licences and the clauses that survive termination.

Penalty clauses and late-payment interest

A penalty clause fixes in advance the consequence of non-performance, defective performance or delay. Under Article 1538 of the Romanian Civil Code, its drafting should identify the protected obligation, the triggering event and the calculation method. The agreement should also state whether a penalty is daily or fixed, whether it is capped and how it interacts with damages and other remedies.

Article 1541 permits a court to reduce a penalty in the statutory circumstances, including where it is manifestly excessive in relation to the loss that the parties could have foreseen when concluding the contract. A high percentage is therefore not a substitute for careful drafting.

Common riskA daily penalty has no cap, applies to several overlapping obligations and continues after termination, creating exposure far beyond the economic value of the contract.

Liability caps, exclusions and indemnities

Liability provisions should allocate risk in proportion to the contract’s value, the parties’ control and the available insurance. Review the general cap, any separate or higher caps, excluded categories of loss, claims procedures and responsibility for employees, affiliates and subcontractors.

Do not assume that an indemnity is a familiar standard clause. It should identify the covered events, third-party claims, control of the defence, settlement authority, notification duties and mitigation. Check whether the limitation of liability applies to the indemnity or whether it creates uncapped exposure.

Any exclusion or limitation must also be tested against mandatory law and the nature of the conduct involved. A clause should not be described as protecting a party against every possible form of unlawful conduct. Where the agreement supports a wider investment or group operation, the liability wording should be reviewed together with the company’s corporate and commercial governance arrangements.

Warranties, regulatory compliance and audit rights

Warranties should be specific to the transaction. Depending on the contract, they may cover conformity with specifications, professional licences, legal compliance, authority, sanctions, anti-bribery, tax status, employment practices, product safety or the absence of third-party rights.

The review should also establish the remedy for an inaccurate warranty. Possible outcomes include correction, replacement, a price adjustment, indemnification or termination. An audit right should define scope, frequency, confidentiality, cost allocation and the treatment of identified non-compliance.

Drafting pointA broad promise to comply with “all applicable laws” may be necessary, but it does not replace transaction-specific duties, evidence requirements and an agreed remediation process.

Force majeure, hardship and change in law

Force majeure and hardship solve different problems. Force majeure concerns an external, unforeseeable, absolutely invincible and unavoidable event under the Civil Code framework. Hardship under Article 1271 addresses an exceptional change that makes performance excessively onerous, subject to the statutory conditions and the allocation of contractual risk.

The clause should define notice, evidence, mitigation, suspension, continued payment obligations and the point at which prolonged disruption permits termination. For regulated or long-term projects, add a change-in-law mechanism explaining who bears new compliance costs and whether price or timing may be adjusted.

Check before signingDo not treat every supplier delay, price increase, staff shortage or market change as force majeure. The clause should distinguish ordinary commercial risk from qualifying events.

Confidentiality and intellectual property

A confidentiality clause should define protected information, permitted use, internal access, legally required disclosures, security standards, duration and return or destruction. Trade-secret protection also depends on practical steps, so access controls and marking procedures should match the contractual wording. A standalone non-disclosure agreement in Romania may be appropriate before sensitive negotiations begin.

For intellectual property, distinguish pre-existing materials from deliverables created under the contract. State whether rights are assigned or licensed and address territory, duration, field of use, sublicensing, modifications, source materials and third-party components.

Romanian Law no. 8/1996 on copyright requires an assignment of economic copyright to specify the transferred rights and, for each, the modes of use, duration, extent and remuneration. A generic sentence stating that the customer “owns everything” may therefore be insufficient for the intended result. Businesses acquiring or licensing valuable assets can obtain a separate review from intellectual property lawyers in Romania.

For ownership arrangements between founders and shareholders, see our guide to shareholder agreements in Romania.

Personal data, security and digital services

If the agreement involves personal data, identify whether each party acts as controller, processor, joint controller or independent controller. When a supplier processes personal data on behalf of a controller, Article 28 of the General Data Protection Regulation requires a contract containing specified safeguards. Our GDPR compliance checklist for Romanian companies explains the wider governance controls that should support those clauses.

Review processing instructions, confidentiality, security measures, subprocessors, assistance with data-subject requests, breach notification, international transfers, audit rights and return or deletion. The commercial agreement and data processing agreement should not contain inconsistent liability, notice or termination rules. More complex vendor arrangements may require assistance from GDPR and data protection lawyers in Romania.

For SaaS and other digital services, also check availability commitments, backups, recovery objectives, vulnerability management, incident cooperation, data portability and access after termination. Technology businesses should align these provisions with their wider technology and digital law obligations and, where relevant, obtain a focused IT and software contract review.

Governing law, jurisdiction and notices

In cross-border contracts, governing law and forum are separate questions. The Rome I Regulation generally allows the parties to choose the law governing their contractual obligations, subject to its safeguards and mandatory rules. The Brussels I bis Regulation governs jurisdiction and the recognition and enforcement of judgments in relevant EU civil and commercial matters.

Consider whether the selected court or arbitral tribunal is proportionate to the likely dispute, where evidence and assets are located, the language and cost of proceedings, and whether an eventual judgment or award can be enforced efficiently.

The notice clause should identify valid addresses, permitted delivery methods, deemed receipt and the process for updating contact details. A termination or claim notice sent to the commercial contact may fail if the contract requires delivery to a different address or by a specific method. Where non-payment is already a concern, the agreement should be tested against the available legal recovery options for unpaid invoices in Romania.

Contract review in Romania: risk map

Contract areaQuestion to answerRisk if unclear
AuthorityIs the correct entity bound by an authorised person?Enforceability, approval and group-liability disputes.
PerformanceWhat exactly must be delivered, tested and accepted?Disputes over completion, defects and payment.
PaymentWhen is money due and what follows from delay?Cash-flow loss, penalties and invoice disputes.
ExitHow can the relationship end and what survives?Lock-in, service interruption and lost data.
LiabilityWhich losses are covered, capped or excluded?Exposure disproportionate to contract value.
IP and dataWho owns or may use assets, information and data?Loss of rights, GDPR exposure and operational dependency.
DisputesWhich law, forum and notice rules apply?Unexpected cost and difficult enforcement.

A practical pre-signing review process

Confirm the commercial dealRecord the intended result, price, timeline and points already agreed before editing legal language.
Read every contract documentReview the agreement, annexes, order forms, proposals, policies and incorporated online terms together.
Rank the risksSeparate legal defects, high-value commercial exposure, operational ambiguity and points that are negotiable preferences.
Propose usable wordingConvert each material issue into a replacement clause, tracked change or clear negotiation question.
Check signing and evidenceConfirm authority, approvals, signature method, final attachments and preservation of the executed version.
Calendar post-signing dutiesTrack notices, renewals, price reviews, certificates, audits and delivery or payment milestones.

Need a Romanian contract reviewed before signing?

Atrium Romanian Lawyers assists Romanian and foreign businesses with contract review, drafting and negotiation. The review can be delivered as tracked changes, replacement clauses, a consolidated draft or a practical risk report adapted to your position in the transaction.

Frequently asked questions

Is a business contract written in English valid in Romania?

Romanian companies can generally conclude commercial contracts in English. The transaction may nevertheless require Romanian-language documents or translations for authorities, courts, employees, consumers, notaries or regulated formalities. The governing-language clause should state which version prevails if the contract is bilingual.

Can a foreign-law contract be used with a Romanian company?

Potentially, yes. In a cross-border contract, the parties may often choose the governing law, but the Rome I framework, mandatory rules, the place of performance and the practical enforcement route must be considered. Choosing foreign law does not automatically remove every Romanian mandatory provision relevant to the transaction.

Are contractual penalties enforceable in Romania?

Romanian law recognises penalty clauses, but the obligation, trigger and calculation must be clear. Article 1541 of the Civil Code permits judicial reduction in the statutory circumstances, including a penalty that is manifestly excessive compared with the foreseeable loss at contract formation.

When should contract review in Romania take place?

Ideally before signing and before the commercial position becomes difficult to change. A new review is also appropriate before renewal, when the scope or price changes, when a party proposes an amendment, or when performance problems and a possible dispute emerge.

What should a foreign company send to the reviewing lawyer?

Send the complete draft and annexes, the commercial proposal, your role in the transaction, the applicable deadline, the principal business concerns and any terms already agreed. Identifying whether you are the customer, supplier, licensor, employer, investor or distributor changes the risk analysis.

Disclaimer: This article provides general legal information and does not constitute legal, tax or commercial advice. Contractual rights and risks depend on the complete document, the transaction, the parties, mandatory rules and the relevant facts.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Commercial invoice overlooking the Bucharest skyline, illustrating late payment in Romania

Late Payment in Romania: Penalties, Interest and Legal Remedies

When is a Romanian invoice late — and what can a creditor recover?

A missed payment deadline in Romania is not only a collections problem. It can trigger statutory penalty interest, a fixed recovery compensation and, with the right contract, a pre-agreed penalty clause — without the creditor having to prove any loss.

Overdue commercial invoice, payment deadline and legal documents in a Romanian law office

Late-payment claims may include interest, recovery compensation and documented collection costs.

Late payment in Romania is heavily regulated for business-to-business transactions. Under Law 72/2013, which transposes EU Directive 2011/7, a B2B invoice is generally payable within about 30 days unless the parties expressly agreed a longer term — capped at 60 days unless a longer term is not abusive. On late payment, provided the creditor has performed its obligations and the delay is imputable to the debtor, a professional creditor can claim the applicable statutory or contractual late-payment interest or penalty, together with the €40 flat recovery compensation and recoverable collection costs. For money obligations assumed in the exercise of an undertaking’s activity, the debtor is in delay by operation of law, so interest runs from maturity without a formal demand, subject to the statutory conditions. Exact figures depend on the contract and on the reference rate published by the National Bank of Romania.

Most foreign suppliers start with a practical question: when can you demand more than the unpaid principal, and how do you recover an unpaid invoice in Romania? This guide explains when a payment becomes late, which charges a creditor can add, which payment terms are valid (and which clauses are void), and the realistic recovery route from a first demand through to enforcement.

The rules below focus on business-to-business transactions governed by Romanian law. They apply on top of the general contract-law regime: the Romanian Civil Code and, for commercial transactions, the specific late-payment law, Law 72/2013, based on EU Directive 2011/7 on combating late payment.

What can a Romanian creditor charge on a late invoice?

Penalty interest, plus a fixed €40 recovery compensation, plus enforceable recovery costs — and, if the contract says so, a daily contractual penalty. Penalty interest, the €40 minimum compensation and a contractual penalty do not require proof of actual loss. Additional recovery costs, however, must be substantiated. These rights accrue provided the creditor has performed its obligations and the delay is imputable to the debtor.

Romanian law gives a creditor who is not paid at maturity a right to moratory damages — penalty interest — running from the due date until payment, at the rate agreed in the contract or, absent agreement, at the statutory rate, without having to prove any loss (Civil Code, Article 1535). The debtor cannot defend by showing the creditor suffered a smaller loss.

Depending on the contract, the creditor may claim the applicable statutory or contractual late-payment interest or penalty, together with the €40 minimum compensation and recoverable collection costs. Whether a contractual late-payment penalty may be cumulated with another form of moratory damages depends on the drafting and legal nature of the contractual remedies.

  1. Statutory or contractual penalty interest — at the rate agreed by the parties or, absent agreement, the statutory penalty interest at the reference rate plus 8 percentage points for professional relations, applied for each semester on the rate in force at the start of that semester (Law 72/2013, Article 4, read with OG 13/2011, Article 3).
  2. Fixed minimum compensation of €40 — a flat amount of recovery damages, payable in lei at the exchange rate on the payment date, in addition to the interest (Law 72/2013, Article 10).
  3. Substantiated recovery costs — collection expenses actually incurred and established can be claimed as damages (Law 72/2013, Article 9).
  4. Contractual penalty clause — a pre-agreed per-day penalty, enforceable without proof of loss (Civil Code, Article 1538), subject to the statutory reduction grounds in Civil Code, Article 1541. Whether it may be cumulated with other moratory damages depends on the contract’s drafting.

Risk: A creditor who ignores the interest route and waits silently may still recover the principal, but documentation matters. If the debtor later disputes the amount, the creditor must show when each sum became due. Keep invoices, delivery or acceptance evidence and the calculation of interest from maturity.

When is a payment legally late?

At the contractual due date, or generally 30 calendar days after the debtor receives the invoice when no term was agreed. In B2B contracts, an agreed payment term longer than 60 days is valid only if it is not abusive (grossly unfair) to the creditor.

The starting point is the term agreed in the contract. The parties may choose the payment date, subject to an important limit in business relations: the contractual payment term cannot exceed 60 calendar days, and a longer term is permitted only if the clause is not abusive under Law 72/2013, Article 5.

When the contract is silent, Law 72/2013, Article 3 fixes the moment from which penalty interest runs. For a professional creditor, interest runs after 30 calendar days from receipt by the debtor of the invoice or of any equivalent payment request. Where the date of receipt is uncertain or the invoice is received before the goods or services, the law uses the date of delivery of the goods or performance of the services as the reference point.

For money obligations assumed in the exercise of an undertaking’s activity, the debtor is in delay by operation of law: interest begins to run at maturity without any formal demand or notification (Civil Code, Article 1523). A written reminder still matters — it creates evidence of the claim and of the date from which the debtor was asked to pay, which becomes relevant in litigation.

These rights accrue only where the statutory conditions are met: in particular, the creditor and its subcontractors must have performed their contractual obligations, and the delay must be imputable to the debtor. The debtor must not have paid the amount due at maturity and must be unable to show that the delay is not attributable to it (Law 72/2013, Article 3(1)).

SituationInterest startsBasis
Payment term agreed in the contractOn the day after the contractual due date, generally without a formal demandCivil Code Art. 1535; Art. 1523 (enterprise money obligations)
No payment term agreed (B2B)30 calendar days after the debtor receives the invoice or equivalent payment requestLaw 72/2013, Art. 3(3)
Invoice received before delivery of goods or services30 calendar days after delivery or performanceLaw 72/2013, Art. 3(3)
Debtor is a public authorityGenerally 30 days; exceptionally up to 60 days where expressly stipulated and objectively justified; public healthcare institutions: maximum 60 daysLaw 72/2013, Art. 6–7

For public authorities, the general legal payment term is 30 calendar days. Exceptionally, the parties may stipulate a term of up to 60 calendar days if it is set out expressly in the contract and in the procurement documentation and is objectively justified by the nature or the specific characteristics of the contract (Law 72/2013, Article 7). For public healthcare institutions and public entities providing medical services, the legal payment term is capped at 60 calendar days (Law 72/2013, Article 6(4)).

The parties cannot contract around the invoice date itself: any clause fixing a term for issuing or receiving the invoice is absolutely void (Law 72/2013, Article 5(3)).

How is the interest rate calculated?

Parties may agree their own rate or penalty, but in transactions governed by Law 72/2013 a clause that excludes late-payment interest or sets it below the statutory penalty interest is treated as abusive. Absent an agreement, the statutory penalty interest in professional relations is set at the reference rate plus 8 percentage points per year.

  • Agreed rate or penalty clause. The contract may set a specific annual interest rate or a per-day penalty, for example 0.1% or 0.5% per day. Such clauses are valid and enforceable without proof of loss, subject to reduction by a court on the statutory grounds under Civil Code Article 1541. In transactions governed by Law 72/2013, a clause that excludes late-payment interest or sets it below the statutory penalty-interest level is treated as abusive under Article 14(a).
  • Statutory rate. If the parties did not agree a rate, Law 72/2013, Article 4 applies the statutory penalty interest calculated under Article 3 of OG 13/2011. For professional relations, the rate is the reference rate plus 8 percentage points, with the rate in force on the first calendar day of each semester applying for the whole semester.

The BNR reference rate in force on 1 July 2026 was 6.50%. Accordingly, the statutory B2B penalty interest applicable throughout the second semester of 2026 is 14.50% per annum. Because the reference rate moves, always confirm the rate currently in force on the National Bank of Romania website before relying on a figure.

Tip: For recurring commercial relationships, agree the interest or penalty rate in the contract. A clearly drafted penalty clause removes any argument about which statutory rate applies and creates a strong, predictable claim on each overdue invoice.

The €40 flat compensation and recovery costs

In B2B relations, a creditor is entitled to a flat minimum compensation of €40 per late payment, in addition to the applicable late-payment interest or penalty and to the costs of any enforcement procedure.

Law 72/2013, Article 10 gives the creditor the right to demand, when the conditions for late payment are met, the equivalent in lei at the exchange rate on the payment date of €40, representing flat-rate minimum damages for the costs of recovering the claim. The obligation to pay this amount matures at the same time as penalty interest starts running.

This flat amount is additional to the applicable late-payment interest or penalty and to the costs of any subsequent enforcement procedure. CJEU case law confirms that the fixed €40 minimum is payable for each commercial transaction not paid on time and evidenced by an invoice or an equivalent payment request, even where several invoices are pursued in a single claim (Case C-585/20, BFF Finance Iberia). Where a single contract provides for successive supplies or services subject to separate payment deadlines, the €40 minimum is payable for each late payment (Case C-419/21).

On top of the €40, Article 9 allows the creditor to claim recovery expenses actually incurred and established. By contrast, the €40 itself does not require proof of loss and remains the simplest element to assert on each unpaid invoice.

Which payment terms are valid — and which clauses are void?

A B2B payment term is capped at 60 days unless a longer term is not abusive. Clauses postponing the start of interest, requiring a formal demand before interest runs, or excluding penalty interest or recovery compensation are unenforceable.

Law 72/2013, Article 12 establishes the general test: a clause or practice is abusive where it creates, in a grossly unfair way (“vădit inechitabil”), rights and obligations significantly unbalanced to the creditor’s detriment. Article 13 sets the criteria a court considers, including serious deviation from established good practice, absence of objective reasons for derogating from the statutory payment terms or interest rate, and the counterparty’s dominant position towards an SME. Article 14 identifies clauses deemed abusive by law, without need for further assessment, and Article 15 sanctions abusive clauses by absolute nullity.

Clauses of the following type are deemed abusive by law and are therefore absolutely null under Law 72/2013, Articles 14 and 15:

  • clauses excluding penalty interest or setting it below the statutory penalty interest;
  • clauses fixing a moment for the interest to start later than the statutory moment;
  • clauses making interest depend on a formal putting-in-delay even though the debtor is in delay by operation of law;
  • in contracts between professionals and public authorities, a payment term exceeding what Article 7(1) allows when the exceptional conditions are not met;
  • clauses excluding the possibility of additional damages.

Mistake: relying on a 90-day payment term “because the client insisted”

In B2B contracts a term beyond 60 days is only valid if it is not abusive. A term imposed by the larger counterparty without objective justification is exposed to challenge and will not stop the statutory interest from running.

Mistake: waiting for a formal demand before recognising interest

For enterprise money obligations, delay arises by operation of law. The claim for interest starts at maturity. The creditor does not first have to send a formal notification.

Mistake: writing “0% interest” into the contract to keep the client happy

A clause that excludes penalty interest altogether is unenforceable against a professional creditor and can be disregarded. The statutory interest will still apply.

How to recover an unpaid invoice in Romania: the practical route

The route runs from a written demand, through the payment-order procedure for certain, liquid and due contractual claims, to court judgment and enforcement. Most commercial claims follow these steps, but timing, documents and evidence requirements should be checked against the specific contract before acting.

Documents illustrating the recovery of an unpaid invoice through demand, court proceedings and enforcement in Romania

Recovering an unpaid invoice normally progresses from a documented demand to court proceedings and, where necessary, enforcement.

  1. Commercial reminder. Send a payment request identifying the invoice, due date and interest accruing. Even where delay is automatic, this creates documentary evidence and often resolves the matter.
  2. Statutory summons. Before filing under the payment-order procedure, the creditor must serve a formal summons under Article 1015 of the Code of Civil Procedure through a judicial executor or by registered letter with declared contents and acknowledgment of receipt, granting 15 days to pay.
  3. Court action. If the debtor contests the claim or amount, recover through ordinary court proceedings for the principal, interest and costs.
  4. Enforcement. Once the creditor holds an enforceable title, a judicial executor can attach bank accounts, receivables or other debtor assets.

Risk: The payment-order procedure is not a substitute for litigation when determining the debtor’s defence requires evidentiary administration incompatible with the summary nature of the procedure. The claim must concern a certain, liquid and due contractual obligation established within the documentary framework. Otherwise, the creditor may have to pursue the claim through ordinary proceedings.

Which route fits which situation?

RouteBest forKey document or conditionMain business consideration
Written demand plus statutory interestOverdue but still cooperative counterpartiesInvoice, contract and evidence of deliveryPreserves the relationship while demonstrating the claim
Payment-order procedureCertain, liquid and due contractual claims for a sum of moneyWritten evidence establishing the contractual claim and proof of the mandatory Article 1015 summonsFaster track for clear claims; genuine disputes may derail it
Ordinary court actionDisputed liability, quantum or set-off argumentsFull evidence of the relationship, delivery and defaultLonger timeline; costs can include interest and fees
Enforcement by judicial executorDebtor with assets who does not pay voluntarilyEnforceable title, such as a payment order or judgmentAttachments and garnishment become available

The payment-order and enforcement rules are contained in the Romanian Code of Civil Procedure. Our dedicated guide to the payment ordinance procedure in Romania explains the conditions and required documents. The broader debt recovery in Romania guide covers the complete collection strategy.

Illustrative scenarios

No penalty clause in the contract

A Romanian buyer does not pay a 30-day invoice of €10,000. Because the money obligation was assumed in a business activity, interest runs from maturity without a formal demand at the statutory B2B rate, and the €40 flat compensation applies. The supplier can demand the principal, interest and the €40 in one written request.

Contract with a 0.5% daily penalty

The parties agreed a daily penalty of 0.5% of the unpaid amount. On a disputed invoice, the creditor can claim the contractual penalty without proving any loss under Civil Code Article 1538. A court may reduce the penalty only on statutory grounds, such as partial beneficial performance or a penalty that is manifestly excessive compared with the foreseeable loss.

Debtor contests the invoice

The debtor claims the services were defective and refuses payment. Because the claim is genuinely disputed, the payment-order route may not resolve the matter. The supplier should prepare evidence of performance and acceptance and assess ordinary litigation against the amount at stake.

How to protect your position before and after maturity

The strongest position starts before the invoice is issued. Interest and penalties are easier to claim when the contract supports them and the documentation confirms what was delivered, when it was delivered and for which price.

  1. Set a compliant payment term. Align the due date with Law 72/2013, generally up to 60 days in B2B transactions, and state it clearly in the contract.
  2. Agree a penalty or interest rate. Include a per-day penalty clause or an agreed annual interest rate so there is no argument about the statutory rate.
  3. Invoice promptly and completely. Issue the invoice with an unambiguous due date and complete references to the contract and delivery documents.
  4. Confirm receipt and delivery. Keep signed delivery notes, acceptance records or other evidence that the goods or services were provided.
  5. Send a written reminder at maturity. Restate the amount, due date, interest formula and €40 compensation. This becomes part of the evidence supporting the claim.
  6. Calculate interest from the correct date. Use the contractual due date or the applicable 30-day statutory threshold, with the semester rate in force at the start of each semester.
  7. Assess the payment-order procedure early. For a certain, liquid and due contractual claim established through documentary evidence, consider the faster procedure rather than waiting while interest and costs accumulate.
  8. Preserve the enforcement option. If payment does not follow, instruct counsel or a judicial executor before the debtor transfers assets.

The Bottom Line

Late payment in Romania is not merely a collections nuisance. It is a regulated event that gives the creditor a defined set of remedies. A professional creditor can claim the applicable statutory or contractual late-payment interest or penalty, the €40 minimum compensation and substantiated recovery costs. Late-payment interest or a contractual penalty and the €40 minimum compensation do not require proof of actual loss, while additional recovery costs must be established. Getting the payment terms, penalty clause and paper trail right from the beginning converts an overdue invoice into a clearly quantified claim that can be pursued through the payment-order procedure or the ordinary courts.

Frequently asked questions

Do I have to send a formal notice before interest starts running?

For money obligations assumed in the exercise of an undertaking’s activity, the debtor is in delay by operation of law and interest runs from maturity without a formal demand. A written reminder is still advisable as evidence and may be required for other remedies.

What is the statutory interest rate for late payment in Romania?

In professional relations, it is the reference rate plus 8 percentage points per year. With the reference rate at 6.5%, that is approximately 14.5% per annum. Confirm the current reference rate published by the National Bank of Romania before relying on a figure.

Is the €40 compensation automatic?

In B2B relations, yes. When the conditions for late payment are met, the creditor may demand the lei equivalent of €40 as flat-rate minimum recovery damages, in addition to penalty interest and enforcement costs.

Can we agree a payment term longer than 60 days?

Only if the clause is not abusive or grossly unfair to the creditor. A longer term imposed without objective justification is exposed to challenge. Clauses fixing the invoice issue or receipt date are absolutely void.

Are contractual penalty clauses enforceable without proof of loss?

Yes. A penalty clause entitles the creditor to the agreed amount without proving any loss. A court may reduce the penalty only in limited statutory circumstances, including where the penalty is manifestly excessive compared with the foreseeable loss.

Does late payment allow the creditor to terminate the contract?

Non-performance can give rise to termination rights where the statutory conditions are met. Termination is assessed separately from the interest claim and carries its own consequences, so it should be considered with counsel before being used.

Disclaimer: This article provides general legal information about Romanian and EU late-payment rules and does not constitute legal or tax advice. Interest rates, deadlines and remedies depend on the contract, the parties’ status and the specific facts. Figures such as the reference rate change over time.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Romanian business professional reviewing GDPR compliance checklist on laptop in Bucharest office

GDPR Compliance Checklist for Romanian Companies 2025

Play

GDPR Compliance Checklist for Romanian Companies

What crucial step could protect your business from devastating fines while building customer trust?

Many organizations underestimate how Europe’s strict data protection laws apply to their operations.

While GDPR penalties can reach €20 million or 4% of global revenue, Romanian enforcement authorities have imposed fines ranging from €3,000 to €130,000 for violations, demonstrating that penalties scale with the severity of breaches and organizational size.

GDPR compliance checklist for Romanian companies

Romania’s evolving digital economy demands proactive measures to align with rigorous privacy standards.

Legal experts emphasize that proper adherence involves more than basic policy updates—it requires systematic data governance.

Companies must address consent protocols, breach response plans, and cross-border data flows to avoid regulatory scrutiny.

Specialized legal guidance helps businesses transform compliance into strategic advantages.

Firms adopting privacy-first approaches often see improved client relationships and operational resilience.

Those delaying action risk not only financial consequences but also long-term reputational damage in competitive markets.

For tailored strategies meeting international standards, contact our data protection lawyers in Bucharest.

Our team of legal professionals provide actionable frameworks to navigate complex requirements while prioritizing business growth.

Key Takeaways

  • Data protection laws apply regardless of a company’s physical location if EU resident information is processed,
  • Penalties can reach €20 million or 4% of global revenue, emphasizing the need for preventive measures,
  • Building customer trust through transparent data practices creates market differentiation,
  • Legal experts offer customized solutions to align business operations with regulatory demands,
  • Compliance involves continuous monitoring, not just one-time adjustments.

Understanding GDPR and Its Impact on Romanian Businesses

How can organizations in Romania turn regulatory demands into strategic opportunities?

The General Data Protection Regulation (GDPR) reshapes how businesses manage information, particularly for entities handling EU residents’ data.

Its extraterritorial scope means even non-EU-based firms must adhere to strict standards when processing personal details of European citizens.

Core Regulatory Foundations

The regulation establishes six foundational principles for data handling, plus an overarching accountability principle.

These mandate that organizations:

  • Process information lawfully and transparently,
  • Collect only necessary data for specific purposes,
  • Maintain accuracy and limit storage durations.

Such requirements demand technical safeguards like encryption and operational protocols for accountability.

Privacy-by-design methodologies ensure protections are embedded in all systems.

Strategic Advantages for Local Entities

Adhering to these standards transforms obligations into opportunities.

Firms prioritizing data protection report:

  • Enhanced client confidence through transparent practices,
  • Reduced breach-related costs and operational disruptions,
  • Differentiation in markets where privacy concerns influence decisions.

For tailored strategies aligning Romanian operations with these regulations, consult our team of Romanian Lawyers.

Proactive adaptation not only mitigates risks but positions businesses as trustworthy data stewards.

Exploring Key GDPR Roles and Terminology

Who holds ultimate accountability in data governance frameworks?

Clarifying responsibilities under privacy regulations helps organizations establish clear operational boundaries.

Three critical roles form the foundation of proper data management practices.

data protection officer

Data Controllers, Processors, and Data Subjects

Data controllers determine why and how personal information is handled.

They bear legal responsibility for compliance across all processing activities.

Third-party processors execute tasks under controller directives but must independently meet security standards.

Individuals whose data is collected, known as data subjects, retain rights to access or delete their information.

Organizations must implement systems to honor these requests efficiently.

The Essential Role of the Data Protection Officer (DPO)

A data protection officer oversees compliance strategies and acts as the regulatory liaison.

This role is mandatory for entities processing sensitive data or conducting large-scale monitoring.

Under Romanian Law 190/2018, organizations processing national identification numbers (CNP) based on legitimate interest must also appoint a DPO, even if they don’t meet the standard GDPR thresholds.

This additional requirement reflects Romania’s enhanced protection for sensitive national identifiers.

Romanian businesses uncertain about role allocations should consult office@theromanianlawyers.com.

Proper classification prevents overlapping liabilities and ensures alignment with cross-border standards.

Conducting a Comprehensive Data Audit and Mapping

Organizations handling personal information must first establish clarity in their data ecosystems.

A systematic audit reveals how data flows through operations, exposing vulnerabilities while ensuring alignment with legal obligations.

This foundational step transforms raw information into actionable insights for risk management.

data audit and mapping

Identifying What Personal Data You Collect

Begin by cataloging every category of personal data your organization processes.

Common examples include:

  • Contact details (names, email addresses).
  • Digital identifiers (IP addresses, device information).
  • Sensitive records (financial data, health information).

Document each data point’s purpose, collection method, and retention timeline.

Assess whether processing activities rely on valid legal grounds like contractual necessity or explicit consent.

Storage locations demand equal scrutiny—identify physical servers, cloud platforms, and third-party repositories holding sensitive materials.

Access controls form another critical audit component.

Map which employees or systems interact with personal data and verify authorization protocols.

This process highlights potential exposure points while streamlining responses to information requests.

Romanian entities seeking structured frameworks for these assessments may contact our data protection legal specialists.

Expert guidance ensures audits meet regulatory expectations while supporting operational efficiency.

GDPR Compliance Checklist for Romanian Companies

Businesses handling EU data face operational complexity when aligning processes with privacy standards.

Structured frameworks simplify adherence while minimizing risks of non-conformance.

Effective strategies combine procedural clarity with technological safeguards to meet evolving requirements.

data protection checklist steps

Actionable Protocols for Information Security

Organizations should prioritize these critical measures:

Action ItemResponsible PartyDeadline
Complete data flow mappingIT & Legal Teams30 Days
Implement encryption protocolsSecurity Department45 Days
Update third-party contractsCompliance Officer60 Days

Consent Management Best Practices

Valid authorization requires unticked checkboxes and separate permissions for distinct processing purposes.

Confirmation emails enhance verification, while centralized logging systems track user agreements with timestamps and purpose details.

Organizations must honor withdrawal requests without undue delay and provide confirmation within one month, as required by GDPR Article 12(3).

Automated systems should flag outdated records immediately upon withdrawal, ensuring ongoing alignment with transparency obligations and ceasing processing activities promptly.

Regular audits verify adherence to storage limitation principles and access controls.

Local enterprises seeking customized frameworks may contact office@theromanianlawyers.com.

Specialized guidance helps establish resilient processes that satisfy regulatory expectations while supporting operational scalability.

Ensuring Website Security and Transparent Privacy Policies

How do modern businesses balance robust security with user transparency?

Websites storing personal information require layered defenses against cyber threats.

Organizations must adopt technical safeguards while clearly communicating data handling practices to users.

website security and privacy policies

Implementing SSL, Strong Passwords, and Anti-Virus Measures

HTTPS encryption via SSL certificates forms the first line of defense.

Multi-factor authentication and complex passwords prevent unauthorized account access.

Regular vulnerability scans and firewall updates address emerging threats.

Advanced protections include:

  • Content Delivery Networks (CDNs) to mitigate DDoS attacks,
  • Intrusion detection systems monitoring server activity,
  • Automated backups stored in geographically separate locations.

Designing Clear and Accessible Privacy Notices

Privacy policies must explain data collection purposes in plain language.

Every page should feature a visible link to these documents. Essential disclosures include:

  • Types of information gathered (contact details, device data)
  • Legal basis for processing activities
  • Third-party data sharing arrangements

Entities developing their online platforms should consult office@theromanianlawyers.com for policy reviews.

Proper alignment with privacy standards builds credibility while reducing legal exposure.

Managing Third-Party Vendors and International Data Transfers

How can businesses ensure their partners meet strict data protection standards?

Organizations relying on external vendors must verify their adherence to privacy regulations.

This requires thorough evaluations and contractual safeguards to maintain accountability across supply chains.

Evaluating Vendor Requirements and Contracts

Entities handling personal information must catalog all service providers processing data.

This includes cloud platforms, payment systems, and marketing tools.

Assessments should examine vendors’ security certifications, breach response plans, and documentation of regulatory alignment.

Legally binding agreements define responsibilities between controllers and processors.

These contracts specify permitted activities, retention timelines, and security protocols.

Subcontractor arrangements require explicit approval to maintain oversight.

RequirementActionMechanism
Vendor AccountabilityReview security auditsAnnual assessments
Data TransfersImplement SCCsContractual clauses
Risk MitigationConduct impact analysesTransfer evaluations

Cross-border data flows demand additional precautions.

Companies must confirm whether recipient countries have EU adequacy status.

For other regions, standardized contractual clauses or binding corporate rules become mandatory safeguards.

Romanian enterprises navigating these complexities should seek specialized Romanian Lawyer.

Proactive vendor management frameworks prevent regulatory violations while fostering trust with European partners.

Contact office@theromanianlawyers.com for tailored strategies addressing cross-border operational challenges.

Preparing for Data Breaches and Facilitating Data Subject Rights

What separates resilient organizations from vulnerable ones when cyber threats strike?

Proactive preparation for security incidents and efficient handling of individual rights form the backbone of modern data governance.

Organizations must balance rapid response capabilities with systematic processes to address user inquiries.

Developing a Robust Breach Response Plan

Effective incident management requires predefined protocols.

Immediate detection mechanisms trigger containment procedures within one hour of identifying unauthorized data access.

Forensic teams analyze breach scope while legal advisors determine notification obligations to authorities within 72 hours.

Regular simulation exercises test communication channels between IT, legal, and PR departments.

Documentation templates for breach reports ensure regulatory requirements are met without delays.

Continuous monitoring systems flag unusual activity patterns to prevent escalation.

Streamlining Data Subject Access Requests

Individuals increasingly exercise their right to review or delete personal information.

Centralized portals allow users to submit requests through secure authentication methods.

Automated workflows verify identities and route inquiries to appropriate teams within 24 hours.

Response templates maintain consistency while adhering to legal timelines.

Secure delivery channels protect sensitive information during transmission.

Audit trails demonstrate compliance with access rights obligations during regulatory inspections.

Entities requiring customized frameworks for incident management or user rights processes should contact office@theromanianlawyers.com.

Structured approaches transform regulatory demands into operational strengths while maintaining stakeholder trust.

FAQ

When must Romanian businesses appoint a data protection officer?

Organizations must designate a data protection officer if they systematically monitor individuals on a large scale or process sensitive categories like health records.

Public authorities in Romania also require this role regardless of data volume.

How long can companies retain customer information under EU regulations?

Storage periods must align with the original purpose for collection.

For example, transaction records may be kept for tax compliance periods specified by ANAF (Romania’s tax authority), while marketing contact lists require periodic reviews for relevance.

What technical safeguards are mandatory for website security?

Essential measures include SSL encryption, multi-factor authentication, regular penetration testing, and documented patch management processes.

Organizations should implement security measures proportionate to the risk level of data processing, following GDPR Article 32 requirements for appropriate technical and organizational measures.

Are international cloud providers like AWS or Microsoft Azure GDPR-compliant for Romanian data?

Providers operating under EU-approved mechanisms like Standard Contractual Clauses (SCCs) or binding corporate rules generally meet requirements.

However, companies must verify current certifications and update Data Processing Agreements (DPAs) annually.

What penalties apply for violating data subject rights in Romania?

The National Supervisory Authority for Personal Data Processing (ANSPDCP) can impose fines up to €20 million or 4% of global turnover.

Recent enforcement actions targeted improper consent practices and delayed breach notifications.

How should organizations handle data access requests from employees?

Businesses must respond within 30 days, providing free electronic copies of records.

Implement automated DSAR workflows in platforms like Microsoft 365 or specialized tools such as OneTrust to track and fulfill requests efficiently.