Bucharest business district illustrating a share purchase agreement in Romania

Share Purchase Agreement in Romania: Due Diligence, Warranties and Closing Risks

A share purchase agreement in Romania should do more than record the number of shares and the price. It must connect the buyer’s due diligence findings with the conditions for closing, the seller’s warranties, specific indemnities, price mechanics and the corporate and regulatory steps needed to transfer control safely.

In brief: In a Romanian share deal, the buyer acquires the company with its assets, contracts, employees, licences, debts and historical exposure. The SPA therefore allocates risk between buyer and seller. Due diligence identifies the issues; the contract decides whether they must be corrected before closing, reflected in the price, disclosed against warranties, covered by an indemnity or accepted by the buyer. Romanian corporate approvals, ANAF formalities, merger control and investment screening must be tested early because they can change the signing and closing timetable.

This guide is written for foreign investors, international groups, founders and business owners negotiating the acquisition or sale of a Romanian company. It focuses on private acquisitions of shares or social parts, particularly Romanian limited liability companies (SRLs). Listed-company rules, regulated-sector acquisitions, privatisations and public takeovers require additional analysis.

The article complements our procedural guide to changing shareholders in a Romanian company. That guide covers the Trade Register implementation. This one explains how the commercial acquisition should be investigated, negotiated and protected contractually.

What does a share purchase agreement do in Romania?

A share purchase agreement, commonly called an SPA, is the principal contract under which the seller agrees to transfer and the buyer agrees to acquire shares or social parts in a Romanian company. It identifies the securities, price, conditions, closing process and allocation of risk between the parties.

The agreement operates within Romanian contract law and the mandatory rules applicable to the target’s corporate form. For an SRL, the transfer mechanics must be aligned with Articles 202 and 203 of Company Law no. 31/1990 and the applicable registration formalities before the National Trade Register Office (ONRC).

Deal structure
What does the buyer actually acquire?

Select a route to see how the risk profile changes.

Share deal

The buyer acquires the target entity itself. Contracts and assets generally remain with that entity, but so do its historical liabilities and compliance exposure.

Decision pointShare dealAsset deal
What transfersOwnership of the target company.Identified assets, contracts, liabilities or business components.
Historic liabilitiesRemain inside the acquired company and therefore affect the buyer economically.Generally remain with the seller unless assumed by contract or transferred by law.
Contracts and permitsUsually remain with the same legal entity, subject to change-of-control clauses and regulatory rules.May require individual assignment, consent, novation or reissuance.
EmployeesRemain employed by the target.A business transfer may trigger employee-transfer rules and information or consultation duties.
Core documentShare purchase agreement.Business or asset transfer agreement plus asset-specific instruments.

Why must legal due diligence come before the SPA is finalised?

Due diligence should identify the matters that can change the decision to buy, the valuation, the deal timetable or the contractual protection. A report that merely lists documents does not complete the task. Each material finding should be converted into a transaction response.

Share purchase agreement Romania due diligence represented by a green maze with a clear route
Legal due diligence helps the buyer identify risks and determine the appropriate route to a protected transaction. AI-generated illustration.

The scope normally covers corporate title and governance, financing and security, material contracts, real estate, employment, tax, disputes, permits, regulatory compliance, intellectual property, IT, data protection, environmental matters and beneficial ownership. Sector, size and business model determine the emphasis.

Due diligence map
Convert each finding into a deal response

Select a finding to see the appropriate contractual response.

Remediation

Require the seller or target to correct a curable defect before closing and deliver objective evidence that the correction is complete.

WorkstreamKey questionsPossible SPA response
Corporate and titleDoes the seller own the shares? Do the articles of association create pre-emption rights, and are there pledges, options, capital defects or approval restrictions?Title warranty, release condition, shareholder waiver, completion deliverable.
Material contractsDo customers, lenders or suppliers have termination, consent or change-of-control rights?Consent condition, covenant, retention or price adjustment.
EmploymentAre remuneration, dismissals, contractors, collective arrangements and key-person dependencies compliant?Remediation, employment warranty, specific indemnity, retention plan.
TaxAre filings complete? Are there audits, arrears, related-party risks or unsupported tax treatments?Tax covenant, tax warranty, escrow, special indemnity.
IP, technology and dataDoes the target own or validly license critical IP? Are cybersecurity and GDPR controls adequate?Assignment, licence cure, warranty, remediation plan, indemnity.
Disputes and regulationAre there claims, investigations, licences, sanctions, environmental or sector-specific risks?Regulatory condition, conduct covenant, indemnity or exclusion from the deal.

Which clauses matter most in a Romanian share purchase agreement?

The SPA should describe the transaction as one coherent mechanism. Definitions, price, conditions, warranties, disclosure, indemnities, limitations, covenants and closing deliverables must work together. Imported English-law wording should not be used without checking how it operates under the chosen governing law and Romanian mandatory rules.

Clause navigator
How does each protection work?

Select a clause family to see its transaction function.

Warranties

Contractual statements about the target, shares and business. Their value depends on scope, disclosure, knowledge qualifiers, repetition, claim rules and available recovery.

ProtectionPrincipal functionDrafting question
WarrantyAllocates risk if a contractual statement about the target or business is inaccurate.What is warranted, when is it true, and how do disclosure and seller knowledge qualify it?
Specific indemnityAllocates a defined known or identified exposure.What event triggers payment, which losses are covered and do general limitations apply?
Condition precedentPrevents closing until a necessary event, consent or approval occurs.Who controls satisfaction, what evidence is required, and when may either party terminate?
Pre-closing covenantControls how the target operates between signing and closing.Which actions need buyer consent without giving the buyer unlawful premature control?
Limitation regimeSets time limits, thresholds, caps, exclusions and claim procedure.Which claims are carved out, and does the recovery structure match the seller’s credit risk?

How should the purchase price be structured?

The price clause should explain both the headline value and the route from that value to the amount paid. A fixed price is not necessarily simple if debt, cash, working capital, leakage, earn-outs, holdbacks or currency conversion remain unresolved.

MechanismHow it worksMain negotiation risk
Locked-boxPrice is based on historic accounts at an agreed date, protected by a no-leakage covenant.Reliability of the accounts, leakage definition and permitted payments.
Completion accountsPrice adjusts after closing by reference to closing debt, cash, working capital or other metrics.Accounting policies, hierarchy of rules, timetable and expert determination.
Earn-outPart of the consideration depends on future performance or milestones.Control of the business, metric manipulation, extraordinary items and information rights.
Escrow or holdbackPart of the price is retained or deposited to support identified obligations or claims.Release triggers, duration, permitted deductions and insolvency protection.

A buyer should not treat escrow as a substitute for a coherent claims regime. The SPA should state whether recovery is limited to the escrow, whether the buyer may set off, how competing claims are handled and what happens when the escrow expires.

What is the difference between signing and closing?

Signing creates the contractual commitment. Closing completes the agreed transfer and payment once the applicable conditions are satisfied or waived. They may occur on the same day in a simple transaction, but regulatory approvals, third-party consents, financing or restructuring often require a split process.

Transaction roadmap
From exclusivity to effective control

Select a stage to review the principal legal control.

Term sheet

Align structure, valuation, exclusivity, confidentiality, process and principal conditions before the parties spend heavily on diligence and drafting.

Which Romanian approvals and filings can affect closing?

The regulatory analysis should begin before the SPA timetable is agreed. A condition drafted after signing cannot restore leverage or time already lost.

Corporate approval and ONRC registration

For an SRL transfer to an outside buyer, Article 202 of Company Law no. 31/1990 applies together with the target’s articles of association. The parties should verify statutory approval thresholds and any pre-emption or consent rights created by the articles of association, as well as pledges and other restrictions. The applicable ONRC registration formalities and the update of the company’s shareholder register should be built into the completion process.

ANAF notification and tax-debt safeguards

The practical scope of Article V of Law no. 239/2025, as amended by Government Emergency Ordinance no. 13/2026, should be verified in light of the transaction structure and current ONRC and ANAF practice. Although the regime was introduced in the context of transfers affecting company control, registration practice during 2026 has raised questions regarding its application to a broader range of SRL share transfers, as discussed in this analysis of emerging ONRC practice. The parties should confirm the current notification, tax-certificate, guarantee and registration requirements before signing and again before filing.

Merger control

An acquisition of sole or joint control may constitute an economic concentration. Under Competition Law no. 21/1996, the Romanian thresholds are generally met where the combined worldwide turnover of the undertakings concerned exceeds EUR 10 million and at least two undertakings concerned each achieved Romanian turnover exceeding EUR 4 million in the previous financial year. The EU Merger Regulation may apply instead where its thresholds are met. Closing before the required clearance can expose the parties to gun-jumping risk.

Investment screening

Romania’s investment-screening regime under Government Emergency Ordinance no. 46/2022 was substantially amended by Government Emergency Ordinance no. 17/2026. The general value threshold is now EUR 5 million, but a transaction below the threshold may still be examined if it may affect security, public order or EU projects or programmes. The rules can apply to EU and non-EU investors, and the filing contribution is EUR 5,000 where an authorisation application is required. Sector, investor, control, value and transaction structure must be screened early.

Sector approvals, lender consents, foreign-subsidy review or contractual change-of-control notices may also be relevant. The SPA should allocate responsibility, information, cooperation, remedies and the long-stop date for each approval.

What should happen at closing?

Closing should be a coordinated exchange, not a loose collection of signatures. The SPA should identify every deliverable, who provides it, its agreed form and whether all actions are deemed simultaneous.

  1. Confirm conditions. Record satisfaction or valid waiver of every closing condition.
  2. Approve the transfer. Deliver the required shareholder and corporate resolutions.
  3. Transfer the shares. Execute the required instruments and update the shareholder register.
  4. Pay the consideration. Follow the funds flow, escrow and debt repayment arrangements.
  5. Release security. Deliver releases of share pledges, guarantees or target security where agreed.
  6. Change governance. Coordinate resignations, appointments, powers of attorney and bank mandates.
  7. Deliver control items. Transfer corporate books, credentials, keys, seals and agreed records.
  8. Complete filings. Submit ONRC and ANAF documents, together with beneficial-owner filings where required under the applicable transparency rules, within the relevant timetable.

What limitations should apply to seller liability?

Seller limitations often include a de minimis threshold, basket, aggregate cap, time limits, mitigation, exclusion of double recovery and a formal claim procedure. Tax, title, authority, fraud and specific indemnities may have different limits. The commercial result depends on how these provisions interact, not on any one headline cap.

The buyer should also test recoverability. A contractual claim against a seller with no accessible assets may provide little protection. Escrow, holdback, bank security, parent guarantee or warranty and indemnity insurance may be considered depending on transaction size and risk.

A buyer’s pre-signing checklist

  1. Define the acquisition perimeter. Confirm percentage, target entities, securities and excluded items.
  2. Verify title and authority. Check ownership, encumbrances, approvals and signatory powers.
  3. Complete risk-focused due diligence. Prioritise issues that affect value, continuity or closing.
  4. Translate findings into protections. Allocate each material issue to remediation, price, condition, warranty, indemnity or withdrawal.
  5. Select the price mechanism. Define accounting rules, leakage, debt, cash, working capital and dispute resolution.
  6. Screen regulatory approvals. Review merger control, investment screening, sector approvals and third-party consents.
  7. Align signing and closing. Specify conditions, conduct rules, long-stop date, termination and closing deliverables.
  8. Test recovery. Check caps, time limits, exclusions, seller credit and available security.
  9. Plan filings and integration. Prepare ONRC and ANAF filings, beneficial-owner filings where required under the applicable transparency rules, governance steps and day-one actions.

The bottom line

A Romanian SPA should be the final expression of the buyer’s investigation and the parties’ negotiated risk allocation. The strongest agreement is not the longest. It is the one that identifies what is being bought, states how price is calculated, prevents closing before essential approvals, allocates known and unknown risks clearly and gives the parties an executable closing process.

Planning the acquisition or sale of a Romanian company?

A focused transaction review can cover deal structure, legal due diligence, SPA negotiation, regulatory screening, signing, closing and Romanian corporate implementation.

Book a Consultation

Frequently asked questions

Is a share purchase agreement mandatory in Romania?

A written transfer instrument is normally required to document and implement the transaction. In a negotiated acquisition, the SPA is the central agreement because it also records price mechanics, conditions, warranties, indemnities and closing. The required form and supporting corporate documents depend on the target’s legal form and transaction structure.

What is the difference between an SPA and a shareholders’ agreement?

The SPA governs the acquisition of shares and the allocation of transaction risk between buyer and seller. A shareholders’ agreement governs the continuing relationship among shareholders after the investment, including governance, reserved matters, funding, transfers, deadlock and exit. A minority investment may require both documents.

Can signing and closing occur on the same day?

Yes, where no unsatisfied conditions or approvals require a split process. If merger control, investment screening, financing, third-party consent or pre-closing remediation is required, signing normally precedes closing and the SPA must regulate the interim period and long-stop date.

Does due diligence remove the need for warranties?

No. Due diligence and warranties serve different functions. Diligence helps the buyer identify and evaluate risk. Warranties allocate contractual risk for inaccurate statements, subject to disclosure and limitations. Known issues may require remediation, a price adjustment or a specific indemnity rather than reliance on a general warranty.

When is Romanian investment-screening approval required?

The analysis depends on the investor, target activity, transaction structure, control or durable participation, sensitive sector and investment value. The general threshold is EUR 5 million after OUG no. 17/2026, but lower-value transactions may still be examined where security, public-order or relevant EU interests may be affected.

What happens after the SPA closes?

The parties must complete the agreed corporate, Trade Register and ANAF steps, as well as beneficial-owner filings where required under the applicable transparency rules. They must also release or retain escrow as applicable, implement governance changes and perform post-closing covenants. Price-adjustment, earn-out, indemnity and integration obligations may continue long after legal ownership changes.

Disclaimer: This article provides general information and does not constitute legal or tax advice. The correct structure, approvals, tax treatment and contractual protections depend on the parties, target, sector and facts of each transaction.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Business lawyer assisting foreign company with branch office registration in Romania

How to Register a Branch Office of a Foreign Company in Romania

 

 

 

How to Register a Branch Office of a Foreign Company in Romania

Setting up a branch office in Romania offers foreign companies a strategic foothold in the European market. This comprehensive guide provides an overview of the process to register a branch in Romania, ensuring compliance with Romanian regulations and maximizing your business potential. From understanding the nuances of Romanian law to navigating the National Trade Register Office, we’ll walk you through each step.

Play

Need Professional Help?

At our law firm, Atrium Romanian Lawyers, we assist clients with corporate & commercial law, branch registration, and investor-friendly advisory services.


Understanding Branch Offices in Romania

A receptionist welcoming visitors at the front desk of the office.

What is a Branch Office?

A branch office in Romania serves as an extension of the parent company, allowing it to conduct activities in Romania without creating a separate legal personality. Essentially, registering a branch is establishing a physical office in Romania that operates under the umbrella of the existing foreign company. Unlike a Romanian subsidiary, the branch office shares the same legal entity as its parent company, simplifying administrative processes while expanding its reach.

Branch vs. Subsidiary: Key Differences

TypeDescription
Branch OfficeExtension of parent company without separate legal personality; parent is directly liable
SubsidiaryDistinct legal entity with own capital; provides liability protection to parent

Benefits of Establishing a Branch in Romania

  • Test the Romanian market and gain insights before committing to a full-fledged subsidiary
  • Simpler and faster registration process compared to forming a new Romanian legal entity
  • Lower initial setup costs and reduced administrative burden
  • Leverage the established brand and resources of the parent company
  • Direct representation in the European Union market

Legal Framework for Foreign Companies

A close-up of legal documents and a pen on a desk.

Romanian Companies Law 31/1990

The Romanian Companies Law 31/1990 is the cornerstone of corporate governance in Romania, influencing how foreign companies can establish a branch. This law defines the legal entities permitted to operate in Romania and outlines the requirements for company formation, including registering a branch. Understanding this legislation is vital for foreign investors aiming to register a branch in Romania, ensuring compliance with local regulations.

Foreign Branch Legal Requirements

To register a branch in Romania, foreign companies must meet specific legal requirements:

  • Submit parent company’s registration documents, translated and notarized, to the National Trade Register Office (ONRC)
  • Ensure the branch representative has power of attorney to register and legally bind the company
  • Provide a registered office address in Romania with proof of occupancy
  • Define the scope of activities through CAEN codes

Registration with ONRC Romania

The National Trade Register Office (ONRC) is the central authority for registering a branch in Romania. The process involves filing necessary documents, including the parent company’s details, the decision to open a branch, and the appointment of the branch representative. Once approved, the branch office receives a unique registration number and tax identification code, allowing it to operate legally.

Atrium Romanian Law Office is an expert legal services provider based in Romania, specifically in Bucharest. The firm’s team of experienced Romanian lawyers and professionals are equipped to resolve any legal issue in a timely manner. They offer guidance through the branch registration process, ensuring full compliance with Romanian law.


Step-by-Step Registration Process

A checklist with steps for registration is pinned on a bulletin board.

Phase 1: Preparation of Required Documents

  • Parent company’s articles of association and certificate of incorporation
  • Board resolution authorizing the establishment of the branch
  • Proof of legal existence of the parent company
  • Details of the branch representative and their power of attorney
  • Business plan detailing planned activities in Romania

All foreign documents must be officially translated into Romanian and notarized. This preparation is crucial for avoiding delays with ONRC.

Phase 2: Branch Registration with ONRC

  • Submit all prepared registration documents to ONRC (in person or online)
  • Pay the registration fee (typically €50-€100)
  • ONRC reviews documents for compliance with Romanian legal requirements
  • Upon approval, receive registration certificate and unique fiscal code
  • Branch receives official publication in the Commercial Register

Phase 3: Tax Registration with ANAF

Phase 4: Post-Registration Formalities

  • Open business bank account in Romania
  • Register for social security and employment purposes
  • Apply for sector-specific licenses or permits if required
  • Notify relevant authorities of branch operations

Key Responsibilities After Registration

A computer screen displaying a business registration form.

Role of the Branch Representative

The branch representative holds significant responsibilities:

  • Acts on behalf of the parent company in all matters related to the branch
  • Is authorized to make decisions and enter into contracts
  • Must be a resident of Romania or an EU citizen with valid residence permit
  • Ensures compliance with all Romanian legal and regulatory requirements
  • Serves as the main point of contact with Romanian authorities

Parent Company Obligations

The parent company maintains certain obligations:

  • Remains ultimately liable for all activities conducted by the Romanian branch
  • Must ensure the branch adheres to Romanian legal standards
  • Is responsible for financial reporting and tax compliance
  • Must promptly communicate changes to structure or articles of association
  • Must maintain adequate insurance coverage for branch operations

Common Pitfalls & How to Avoid Them

Two people are discussing documents in a meeting room.
  • Incomplete translations — Ensure all documents are properly translated and notarized by qualified professionals
  • Inadequate branch representative — Choose a qualified individual familiar with Romanian business practices
  • Tax compliance issues — Establish robust accounting and tax reporting procedures from the start
  • Incorrect CAEN codes — Define business activities carefully to match registration requirements
  • Delayed bank account opening — Prepare all documentation in advance to expedite the process
  • Missing sector licenses — Identify and obtain all required permits before commencing operations

Useful Resources & Links


FAQ – Branch Registration in Romania

Q: What is a branch office of a foreign company in Romania?

A: A branch office is an extension of the parent company located abroad. It operates under Romanian laws while representing the foreign legal person and can engage in various business activities.

Q: How long does it take to register a branch in Romania?

A: The registration process typically takes 2-4 weeks, depending on the completeness of submitted documents and ONRC processing time.

Q: What are the registration costs?

A: Costs typically range from €500-€1,500, including ONRC fees, translation and notarization services, publication fees, and optional legal advisory services.

Q: Can a foreign company open multiple branches in Romania?

A: Yes, a foreign company can open multiple branches. However, each branch must be registered separately and comply with local laws and regulations.

Q: What is the difference between a branch and a representative office?

A: A branch can engage in commercial activities and generate revenue, while a representative office is limited to promoting the parent company’s interests without engaging in direct business activities.

Q: Is the branch representative required to be Romanian?

A: The branch representative must be a resident of Romania or an EU citizen with a valid residence permit. They don’t need to be Romanian by nationality.

Q: What are the tax implications for a branch?

A: A branch is subject to corporate income tax on income generated within Romania. It must register for VAT if annual turnover exceeds EUR 88,500 and comply with Romanian tax regulations.

Q: What documents are required to register a branch?

A: Required documents include the parent company’s incorporation certificate, articles of association, proof of legal existence, branch representative details, power of attorney, and information about planned activities.

Q: Can changes be made to the branch after registration?

A: Yes, changes such as branch representative, registered office, or scope of activities must be reported to ONRC. The parent company must ensure all modifications are properly documented and filed.


Disclaimer: This article is for general information only and does not constitute legal advice. Please consult with a qualified Romanian corporate lawyer to verify current laws and regulations before proceeding with branch registration. Laws and procedures are subject to change, and individual circumstances may vary.

Romanian business professional reviewing GDPR compliance checklist on laptop in Bucharest office

GDPR Compliance Checklist for Romanian Companies 2025

Play

GDPR Compliance Checklist for Romanian Companies

What crucial step could protect your business from devastating fines while building customer trust?

Many organizations underestimate how Europe’s strict data protection laws apply to their operations.

While GDPR penalties can reach €20 million or 4% of global revenue, Romanian enforcement authorities have imposed fines ranging from €3,000 to €130,000 for violations, demonstrating that penalties scale with the severity of breaches and organizational size.

GDPR compliance checklist for Romanian companies

Romania’s evolving digital economy demands proactive measures to align with rigorous privacy standards.

Legal experts emphasize that proper adherence involves more than basic policy updates—it requires systematic data governance.

Companies must address consent protocols, breach response plans, and cross-border data flows to avoid regulatory scrutiny.

Specialized legal guidance helps businesses transform compliance into strategic advantages.

Firms adopting privacy-first approaches often see improved client relationships and operational resilience.

Those delaying action risk not only financial consequences but also long-term reputational damage in competitive markets.

For tailored strategies meeting international standards, contact our data protection lawyers in Bucharest.

Our team of legal professionals provide actionable frameworks to navigate complex requirements while prioritizing business growth.

Key Takeaways

  • Data protection laws apply regardless of a company’s physical location if EU resident information is processed,
  • Penalties can reach €20 million or 4% of global revenue, emphasizing the need for preventive measures,
  • Building customer trust through transparent data practices creates market differentiation,
  • Legal experts offer customized solutions to align business operations with regulatory demands,
  • Compliance involves continuous monitoring, not just one-time adjustments.

Understanding GDPR and Its Impact on Romanian Businesses

How can organizations in Romania turn regulatory demands into strategic opportunities?

The General Data Protection Regulation (GDPR) reshapes how businesses manage information, particularly for entities handling EU residents’ data.

Its extraterritorial scope means even non-EU-based firms must adhere to strict standards when processing personal details of European citizens.

Core Regulatory Foundations

The regulation establishes six foundational principles for data handling, plus an overarching accountability principle.

These mandate that organizations:

  • Process information lawfully and transparently,
  • Collect only necessary data for specific purposes,
  • Maintain accuracy and limit storage durations.

Such requirements demand technical safeguards like encryption and operational protocols for accountability.

Privacy-by-design methodologies ensure protections are embedded in all systems.

Strategic Advantages for Local Entities

Adhering to these standards transforms obligations into opportunities.

Firms prioritizing data protection report:

  • Enhanced client confidence through transparent practices,
  • Reduced breach-related costs and operational disruptions,
  • Differentiation in markets where privacy concerns influence decisions.

For tailored strategies aligning Romanian operations with these regulations, consult our team of Romanian Lawyers.

Proactive adaptation not only mitigates risks but positions businesses as trustworthy data stewards.

Exploring Key GDPR Roles and Terminology

Who holds ultimate accountability in data governance frameworks?

Clarifying responsibilities under privacy regulations helps organizations establish clear operational boundaries.

Three critical roles form the foundation of proper data management practices.

data protection officer

Data Controllers, Processors, and Data Subjects

Data controllers determine why and how personal information is handled.

They bear legal responsibility for compliance across all processing activities.

Third-party processors execute tasks under controller directives but must independently meet security standards.

Individuals whose data is collected, known as data subjects, retain rights to access or delete their information.

Organizations must implement systems to honor these requests efficiently.

The Essential Role of the Data Protection Officer (DPO)

A data protection officer oversees compliance strategies and acts as the regulatory liaison.

This role is mandatory for entities processing sensitive data or conducting large-scale monitoring.

Under Romanian Law 190/2018, organizations processing national identification numbers (CNP) based on legitimate interest must also appoint a DPO, even if they don’t meet the standard GDPR thresholds.

This additional requirement reflects Romania’s enhanced protection for sensitive national identifiers.

Romanian businesses uncertain about role allocations should consult office@theromanianlawyers.com.

Proper classification prevents overlapping liabilities and ensures alignment with cross-border standards.

Conducting a Comprehensive Data Audit and Mapping

Organizations handling personal information must first establish clarity in their data ecosystems.

A systematic audit reveals how data flows through operations, exposing vulnerabilities while ensuring alignment with legal obligations.

This foundational step transforms raw information into actionable insights for risk management.

data audit and mapping

Identifying What Personal Data You Collect

Begin by cataloging every category of personal data your organization processes.

Common examples include:

  • Contact details (names, email addresses).
  • Digital identifiers (IP addresses, device information).
  • Sensitive records (financial data, health information).

Document each data point’s purpose, collection method, and retention timeline.

Assess whether processing activities rely on valid legal grounds like contractual necessity or explicit consent.

Storage locations demand equal scrutiny—identify physical servers, cloud platforms, and third-party repositories holding sensitive materials.

Access controls form another critical audit component.

Map which employees or systems interact with personal data and verify authorization protocols.

This process highlights potential exposure points while streamlining responses to information requests.

Romanian entities seeking structured frameworks for these assessments may contact our data protection legal specialists.

Expert guidance ensures audits meet regulatory expectations while supporting operational efficiency.

GDPR Compliance Checklist for Romanian Companies

Businesses handling EU data face operational complexity when aligning processes with privacy standards.

Structured frameworks simplify adherence while minimizing risks of non-conformance.

Effective strategies combine procedural clarity with technological safeguards to meet evolving requirements.

data protection checklist steps

Actionable Protocols for Information Security

Organizations should prioritize these critical measures:

Action ItemResponsible PartyDeadline
Complete data flow mappingIT & Legal Teams30 Days
Implement encryption protocolsSecurity Department45 Days
Update third-party contractsCompliance Officer60 Days

Consent Management Best Practices

Valid authorization requires unticked checkboxes and separate permissions for distinct processing purposes.

Confirmation emails enhance verification, while centralized logging systems track user agreements with timestamps and purpose details.

Organizations must honor withdrawal requests without undue delay and provide confirmation within one month, as required by GDPR Article 12(3).

Automated systems should flag outdated records immediately upon withdrawal, ensuring ongoing alignment with transparency obligations and ceasing processing activities promptly.

Regular audits verify adherence to storage limitation principles and access controls.

Local enterprises seeking customized frameworks may contact office@theromanianlawyers.com.

Specialized guidance helps establish resilient processes that satisfy regulatory expectations while supporting operational scalability.

Ensuring Website Security and Transparent Privacy Policies

How do modern businesses balance robust security with user transparency?

Websites storing personal information require layered defenses against cyber threats.

Organizations must adopt technical safeguards while clearly communicating data handling practices to users.

website security and privacy policies

Implementing SSL, Strong Passwords, and Anti-Virus Measures

HTTPS encryption via SSL certificates forms the first line of defense.

Multi-factor authentication and complex passwords prevent unauthorized account access.

Regular vulnerability scans and firewall updates address emerging threats.

Advanced protections include:

  • Content Delivery Networks (CDNs) to mitigate DDoS attacks,
  • Intrusion detection systems monitoring server activity,
  • Automated backups stored in geographically separate locations.

Designing Clear and Accessible Privacy Notices

Privacy policies must explain data collection purposes in plain language.

Every page should feature a visible link to these documents. Essential disclosures include:

  • Types of information gathered (contact details, device data)
  • Legal basis for processing activities
  • Third-party data sharing arrangements

Entities developing their online platforms should consult office@theromanianlawyers.com for policy reviews.

Proper alignment with privacy standards builds credibility while reducing legal exposure.

Managing Third-Party Vendors and International Data Transfers

How can businesses ensure their partners meet strict data protection standards?

Organizations relying on external vendors must verify their adherence to privacy regulations.

This requires thorough evaluations and contractual safeguards to maintain accountability across supply chains.

Evaluating Vendor Requirements and Contracts

Entities handling personal information must catalog all service providers processing data.

This includes cloud platforms, payment systems, and marketing tools.

Assessments should examine vendors’ security certifications, breach response plans, and documentation of regulatory alignment.

Legally binding agreements define responsibilities between controllers and processors.

These contracts specify permitted activities, retention timelines, and security protocols.

Subcontractor arrangements require explicit approval to maintain oversight.

RequirementActionMechanism
Vendor AccountabilityReview security auditsAnnual assessments
Data TransfersImplement SCCsContractual clauses
Risk MitigationConduct impact analysesTransfer evaluations

Cross-border data flows demand additional precautions.

Companies must confirm whether recipient countries have EU adequacy status.

For other regions, standardized contractual clauses or binding corporate rules become mandatory safeguards.

Romanian enterprises navigating these complexities should seek specialized Romanian Lawyer.

Proactive vendor management frameworks prevent regulatory violations while fostering trust with European partners.

Contact office@theromanianlawyers.com for tailored strategies addressing cross-border operational challenges.

Preparing for Data Breaches and Facilitating Data Subject Rights

What separates resilient organizations from vulnerable ones when cyber threats strike?

Proactive preparation for security incidents and efficient handling of individual rights form the backbone of modern data governance.

Organizations must balance rapid response capabilities with systematic processes to address user inquiries.

Developing a Robust Breach Response Plan

Effective incident management requires predefined protocols.

Immediate detection mechanisms trigger containment procedures within one hour of identifying unauthorized data access.

Forensic teams analyze breach scope while legal advisors determine notification obligations to authorities within 72 hours.

Regular simulation exercises test communication channels between IT, legal, and PR departments.

Documentation templates for breach reports ensure regulatory requirements are met without delays.

Continuous monitoring systems flag unusual activity patterns to prevent escalation.

Streamlining Data Subject Access Requests

Individuals increasingly exercise their right to review or delete personal information.

Centralized portals allow users to submit requests through secure authentication methods.

Automated workflows verify identities and route inquiries to appropriate teams within 24 hours.

Response templates maintain consistency while adhering to legal timelines.

Secure delivery channels protect sensitive information during transmission.

Audit trails demonstrate compliance with access rights obligations during regulatory inspections.

Entities requiring customized frameworks for incident management or user rights processes should contact office@theromanianlawyers.com.

Structured approaches transform regulatory demands into operational strengths while maintaining stakeholder trust.

FAQ

When must Romanian businesses appoint a data protection officer?

Organizations must designate a data protection officer if they systematically monitor individuals on a large scale or process sensitive categories like health records.

Public authorities in Romania also require this role regardless of data volume.

How long can companies retain customer information under EU regulations?

Storage periods must align with the original purpose for collection.

For example, transaction records may be kept for tax compliance periods specified by ANAF (Romania’s tax authority), while marketing contact lists require periodic reviews for relevance.

What technical safeguards are mandatory for website security?

Essential measures include SSL encryption, multi-factor authentication, regular penetration testing, and documented patch management processes.

Organizations should implement security measures proportionate to the risk level of data processing, following GDPR Article 32 requirements for appropriate technical and organizational measures.

Are international cloud providers like AWS or Microsoft Azure GDPR-compliant for Romanian data?

Providers operating under EU-approved mechanisms like Standard Contractual Clauses (SCCs) or binding corporate rules generally meet requirements.

However, companies must verify current certifications and update Data Processing Agreements (DPAs) annually.

What penalties apply for violating data subject rights in Romania?

The National Supervisory Authority for Personal Data Processing (ANSPDCP) can impose fines up to €20 million or 4% of global turnover.

Recent enforcement actions targeted improper consent practices and delayed breach notifications.

How should organizations handle data access requests from employees?

Businesses must respond within 30 days, providing free electronic copies of records.

Implement automated DSAR workflows in platforms like Microsoft 365 or specialized tools such as OneTrust to track and fulfill requests efficiently.

Employment contract being signed in a bright Romanian office

Employment Contracts in Romania: Mandatory Clauses and Employer Checklist

Employment contracts in Romania must be concluded in writing and in Romanian, signed using wet-ink or a legally valid electronic signature, contain the mandatory information required by the Labour Code and be recorded in REGES-ONLINE before the employee starts work. A compliant template is only the starting point: the contract must also match the actual role, schedule, workplace, pay structure and working arrangement.

In brief: The employer is responsible for the written contract, pre-contract information, medical fitness check, delivery of a signed copy and timely REGES-ONLINE registration. An indefinite full-time contract is the default. Fixed-term, part-time, mobile and telework arrangements require additional wording. Clauses on probation, confidentiality, mobility, training and non-compete protection must be drafted within statutory limits. Changes to core terms generally require an addendum before they take effect, while REGES reporting follows separate deadlines.

This guide is written for foreign companies, founders, HR teams and managers hiring personnel in Romania. It explains what the contract should contain, which clauses require special care and how contract execution connects with the employer’s registration and personnel-file obligations.

Employment contract and employer checklist prepared in a Romanian office
Employment documentation and onboarding checklist prepared for a new employee in Romania.

Must an employment contract be in writing in Romania?

Yes. Article 16 of the Romanian Labour Code requires the individual employment contract to be concluded in writing and in Romanian. Written form is mandatory under the Labour Code and must be completed before work begins. The employer bears responsibility for concluding the document.

The contract must be signed using wet ink or a legally valid electronic signature, provided to the employee and entered in REGES-ONLINE before work begins. Where electronic signing is used, the parties must use the same type of signature for the document. Registration alone does not replace the signed contract, and a signed contract does not excuse late registration. Foreign-language versions may be used for convenience, but the Romanian version should control or the documents should state clearly how inconsistencies are resolved.

Contract route
Which employment contract fits the role?

Select a route to see the main drafting consequence.

Indefinite full-time

This is the statutory default and usually the simplest route when the business need is ongoing and the normal schedule is eight hours per day and 40 hours per week.

Contract typeWhen it may be usedDrafting control
IndefiniteDefault route for an ongoing role.State start date, role, workplace, schedule, salary and all Article 17 information.
Fixed-termOnly in cases permitted by the Labour Code.State the legal basis and exact duration or objective end event. General maximum: 36 months.
Part-timeWhere the agreed normal hours are below full time.State hours, distribution, change conditions and the statutory overtime restriction.
TeleworkRegular voluntary work outside employer premises using ICT.Include the additional clauses required by Law no. 81/2018.
Mobile workThe duties are not performed at a stable workplace.Define the mobility area and any cash or in-kind mobility benefit.

What mandatory clauses must Romanian employment contracts contain?

The contract must cover the information required by Article 17 of the Labour Code and the applicable framework employment-contract model. The employer should not merely copy headings. Each field must describe the real employment arrangement.

Clause map
Map the mandatory terms to the real job

Select a clause group to review the main control.

Identity and employer

Use the correct legal employer, registered details and authorised signatory. A group brand or foreign parent is not a substitute for identifying the employing entity.

Clause groupWhat should be statedFrequent error
Parties and workplaceIdentity, employer headquarters, workplace or absence of a fixed workplace.Naming a business unit without identifying the legal employer.
Role and dutiesCOR occupation, job description, duties, professional-evaluation criteria and job-specific risks.Using a generic job description unrelated to actual authority or tasks.
Duration and startStart date; indefinite or fixed duration; fixed-term basis and end point where applicable.Using a fixed term without a statutory case supporting it.
Working timeHours per day/week, schedule distribution and conditions for changing the schedule.Using an unequal schedule without expressly providing for it.
PayGross base salary, allowances, bonuses, benefits and payment frequency.Calling a recurring salary component discretionary while administering it as guaranteed.
Leave and noticeAnnual leave, applicable notice conditions and duration, probation period.Contractual notice exceeding the legal maximum for resignation.
Other informationCollective agreement, training rights, employer-provided benefits and applicable procedures.Referring to policies that were not communicated or do not exist.

What must be completed before the employee starts work?

The employer should treat hiring as a controlled sequence. Before the first working day, it must verify identity and work entitlement, obtain the medical fitness certificate, complete the required information process, sign the contract, provide the employee’s copy and transmit the required data to REGES-ONLINE.

Pre-hire control
Employer checklist before work begins

Select each control to see why its order matters.

Identity and status

Verify the person’s identity, qualifications and any immigration or work-authorisation condition before promising a start date that cannot legally be met.

A non-EU national may require a work authorisation and immigration steps before employment can lawfully begin. The employment document should align with the approved position, salary and working conditions. See our guide to recruiting non-EU personnel in Romania.

How does REGES-ONLINE connect with the employment contract?

REGES-ONLINE is the statutory employee register governed by Government Decision no. 295/2025. From 2026, employers should use the online register for new hires and subsequent reportable events. The register reflects the legal documents; it does not create or amend the parties’ agreement by itself.

Reporting calendar
When should the employer report an event?

Select an event to review the general reporting rule.

Before work begins

The new employment contract and required employee data must be transmitted no later than the day before activity starts, including when that day is not a working day.

EventGeneral reporting deadlineInternal control
New employmentNo later than the day before activity starts.Do not permit access to work until signature and transmission are confirmed.
Function, contract type, duration, workplace or working timeGenerally no later than the day before the change takes effect.Align the addendum date, effective date and register entry.
Salary, allowances, bonuses and other additionsWithin 20 working days from the change under Article 5(4) of Government Decision no. 295/2025.Reconcile contract/addendum, payroll and REGES; verify any special rule applying to the source of the change.
TerminationGenerally no later than the termination date or the applicable date of knowledge.Record the correct legal ground and retain the supporting document.

The table states the main operational rules. For salary changes, Article 5(4) of Government Decision no. 295/2025 provides a 20-working-day deadline; a change resulting from a court judgment is subject to the specific 10-working-day rule calculated from the employer’s knowledge of the judgment. Particular suspensions, transfers and corrections also have specific rules. Employers should verify the current REGES-ONLINE guidance for the event concerned.

2026 salary note: Government Decision no. 146/2026 set the national gross minimum base salary at RON 4,325 per month from 1 July 2026. This is a dated statutory amount verified in the official legislation portal. Employers should nevertheless recheck the minimum immediately before implementation, together with sector-specific rules and the 24-month limitation applicable to keeping an employee at the general minimum level.

How should probation, confidentiality and non-compete clauses be drafted?

Optional clauses are enforceable only within the Labour Code. They should solve a real business need and should not attempt to remove statutory employee rights.

ClauseLegal controlDrafting point
ProbationGenerally up to 90 calendar days for execution roles and 120 for management roles.State the period clearly. Probation operates inside a signed employment contract.
ConfidentialityMay protect confidential information during and after employment.Define protected information and permitted disclosures; do not obstruct statutory rights.
Non-competeRequires prohibited activities, third parties, geographic area, duration and monthly indemnity.A generic ban is insufficient. Post-termination effect cannot generally exceed two years.
MobilityApplies where duties are not performed at a stable workplace.Describe the area and the additional cash or in-kind benefits.
TrainingTraining costs and retention consequences require lawful, proportionate wording.Use a separate addendum for significant employer-funded training where appropriate.

A post-employment non-compete obligation requires payment of a monthly non-compete indemnity. The contract must identify the activities prohibited, relevant third parties, geographic area and period. It cannot impose an absolute ban on the employee’s profession. Confidentiality and intellectual-property provisions should also distinguish employee-created works, employer resources, trade secrets and lawful whistleblowing or regulatory disclosures.

What additional clauses are required for telework and part-time work?

Telework and part-time arrangements require more than changing the workplace or number of hours in a standard form.

Under Law no. 81/2018, telework must be expressly agreed. The contract or addendum should address the periods spent at employer premises, how activity may be checked, the method for recording daily start and end working hours in line with Article 119 of the Labour Code, health and safety responsibilities, equipment, data protection, measures against isolation and the treatment of telework expenses.

A part-time contract must state the duration and distribution of hours, the conditions under which the schedule may be changed and the restriction on overtime, subject to narrow statutory emergencies. Omitting mandatory part-time elements may expose the employer to the risk of reclassification and labour-inspector sanctions.

Can the employer change the contract unilaterally?

As a rule, no. Core terms such as role, workplace, salary, working time and contract duration are modified by agreement, normally through a written addendum concluded before the change takes effect. The Labour Code provides narrow exceptions. In addition to delegation and secondment, Article 48 permits the employer temporarily to modify the workplace and type of work without consent in cases of force majeure, as a disciplinary sanction or as a measure to protect the employee, only in the cases and under the conditions provided by law.

Telework under Law no. 81/2018 remains, as a rule, consensual. An employer should not rely on Article 48 as a general power to impose remote work. Any exceptional unilateral remote-work measure must have a specific legal basis applicable at that time.

A policy cannot silently rewrite a contractual benefit or core term. Before changing a package, the employer should classify each item as statutory, contractual, collectively agreed, policy-based or genuinely discretionary. The correct document and employee-consent requirement follow from that classification.

Employer checklist for Romanian employment contracts

  1. Identify the real employer. Confirm the Romanian employing entity and authorised signatory.
  2. Classify the role. Select the correct COR occupation and align it with the job description.
  3. Choose the lawful contract type. Document any fixed-term or part-time basis and special clauses.
  4. Verify the employee. Check identity, qualifications, medical fitness and work authorisation.
  5. Define the workplace. Distinguish office work, mobility, homeworking and telework.
  6. State working time precisely. Include distribution, unequal schedules, shifts or part-time restrictions where relevant.
  7. Map compensation. Separate base salary, allowances, bonuses, benefits and reimbursement of expenses.
  8. Review optional protections. Tailor confidentiality, IP, non-compete, mobility and training clauses.
  9. Sign and deliver the contract. Complete this before the employee starts work, using wet-ink signatures or the same legally valid electronic-signature type for both parties.
  10. Transmit REGES data. Preserve proof and reconcile the register with payroll and personnel-file documents.

Risk: A contract can appear complete and still fail in practice when the job description, actual schedule, payroll treatment and REGES record contradict it. Employers should audit the whole employment file, not only the signature page.

Frequently asked questions

Can a Romanian employment contract be signed only in English?

No. The Labour Code requires the individual employment contract to be concluded in Romanian. A bilingual version may be used for a foreign employee or group process, but the Romanian text must be included and the parties should address which version prevails if wording differs.

When must a new employment contract be registered in REGES-ONLINE?

The required employee and contract data must generally be transmitted no later than the day before the employee starts activity, even if that preceding day is not a working day. The employer should complete registration only after the contract reflects the terms agreed and has been signed.

Is an indefinite employment contract mandatory?

An indefinite contract is the statutory default. A fixed-term contract is lawful only in the situations listed by the Labour Code and must state its duration or objective end point. The general maximum duration is 36 months, subject to the specific rules governing successive contracts.

Can an employee work during the probation period without a contract?

No. Probation takes place within an employment contract. The document must be signed, using wet ink or a legally valid electronic signature, and registered before work starts. The general maximum is 90 calendar days for execution positions and 120 calendar days for management positions, with special rules for certain categories and fixed-term contracts.

Does every remote employee qualify as a teleworker?

Not necessarily. Legal classification depends on how and where work is organised and whether information and communication technology is used regularly outside the employer’s workplace. Where Law no. 81/2018 applies, telework must be expressly agreed and the contract must contain its additional mandatory elements.

Does a salary increase always require an addendum?

A negotiated salary change normally requires a written addendum before it takes effect. Where the change follows directly from legislation, the Labour Code exception to the addendum rule may apply. The employer must still update payroll and transmit the reportable salary data to REGES-ONLINE within the applicable deadline.

Hiring employees or reviewing employment contracts in Romania?

We assist Romanian and international employers with employment-contract drafting, HR documentation, telework arrangements, REGES compliance and cross-border hiring.

Book a Consultation

Disclaimer: This article provides general information and does not constitute legal advice. Contract requirements depend on the role, working arrangement, applicable collective rules and the employee’s status.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.