Tag Corporate compliance Romania

Corporate data breach response centre managing a GDPR incident in Romania

GDPR Data Breach in Romania: 72-Hour Guide

A GDPR data breach in Romania creates an immediate legal decision window. The company must contain the incident, determine whether personal data were compromised, assess the risk to individuals and decide whether the Romanian supervisory authority, the ANSPDCP, must be notified within 72 hours.

GDPR data breach response and personal data security in Romania

What companies should know immediately:

  • The 72-hour period runs from the controller’s awareness of the breach, not necessarily from the moment the incident first occurred.
  • Every personal data breach must be documented, even when notification is not required.
  • The ANSPDCP must be notified unless the breach is unlikely to create a risk to individuals’ rights and freedoms.
  • Affected individuals must also be informed without undue delay when the breach is likely to create a high risk.
  • An incomplete investigation does not justify silence. GDPR permits information to be submitted in phases.

This guide is designed for Romanian companies, foreign investors, directors, compliance teams and data protection officers responding to an actual or suspected incident. It should be used together with an incident-specific legal and technical assessment. For preventive support and breach response, see our data protection services in Romania.

What qualifies as a personal data breach?

Article 4(12) of the General Data Protection Regulation defines a personal data breach as a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data. The concept is wider than a cyberattack and covers confidentiality, integrity and availability incidents.

Breach typeWhat it meansCommon exampleImmediate check
ConfidentialityPersonal data are accessed or disclosed without authorisation.An email with customer files is sent to the wrong recipient, credentials are stolen or an attacker exfiltrates a database.Who received or accessed the data, and can further access be stopped?
IntegrityPersonal data are altered without authorisation or by accident.Payroll details are changed, records are corrupted or an unauthorised user modifies a customer account.Which records changed, can the original data be restored, and were decisions made using incorrect data?
AvailabilityPersonal data become unavailable or are destroyed.Ransomware encrypts files, a database is deleted or a lost device contains the only copy of records.Are reliable backups available, how long will services be disrupted, and could the loss harm individuals?

A security event that does not involve personal data is not a personal data breach under GDPR. Conversely, a small incident can still be a breach. Under the data protection rules applicable in Romania, the number of affected people matters, but so do the sensitivity of the data, the ease of identification, the possible consequences and the vulnerability of the people concerned.

When does the 72-hour notification period start?

Article 33 requires notification without undue delay and, where feasible, no later than 72 hours after the controller becomes aware of the breach. According to the EDPB breach-notification guidelines, awareness exists when the controller has a reasonable degree of certainty that a security incident occurred and led to personal data being compromised.

A brief initial investigation may be necessary to determine whether personal data were actually affected. That does not permit an organisation to delay investigation or postpone escalation. Once there is reasonable certainty, the clock runs even if the full cause, exact number of records or final consequences are still being investigated.

72-hour incident clock
From awareness to notification

Select a stage to see the priority. The timetable is operational guidance, not a replacement for immediate action.

Confirm awareness

Record when the controller first reached a reasonable degree of certainty that personal data had been compromised. Preserve the facts supporting that timestamp.

Do not wait for a final forensic report before making the legal notification decision. Article 33 expressly permits phased notification when all information cannot be provided at the same time.

Must every breach be notified to the ANSPDCP?

No. Every breach must be recorded internally, but not every breach must be reported to the authority. The controller must assess the likely impact on the rights and freedoms of natural persons. The result falls into one of three practical levels.

Notification decision matrix
Choose the response level

Select a risk level to see the corresponding GDPR response. The conclusion must be supported by documented facts.

Document internally

If the breach is unlikely to result in a risk to individuals, authority notification is not required. The breach, assessment, effects and remedial action must still be recorded.

Assessment resultRequired actionTypical considerations
Unlikely to create riskDocument the breach and the reasons for not notifying.Strong effective safeguards, limited data, verified recovery, no realistic adverse effect and reliable containment.
Likely to create riskNotify the competent supervisory authority without undue delay and, where feasible, within 72 hours.Possible identity theft, fraud, loss of confidentiality, discrimination, financial loss, reputational harm or loss of control over data.
Likely to create high riskNotify the authority and communicate with affected individuals without undue delay, unless an Article 34 exception applies.Special-category data, credentials or financial data, vulnerable people, large-scale exposure, easy identification or serious likely consequences.

Risk is not determined by a single formula. The company should consider the type of breach, nature and volume of data, identifiability, severity and likelihood of consequences, number and characteristics of affected people, and the effectiveness of safeguards such as encryption. The EDPB’s practical breach examples are useful benchmarks, but the actual incident must be assessed on its own facts.

What must an ANSPDCP notification contain?

Article 33(3) establishes the minimum information. The ANSPDCP’s current online notification form requests additional operational details that allow the authority to understand the incident and the controller’s response.

Notification fieldWhat the company should prepare
Nature of the breachA concise incident summary, whether confidentiality, integrity or availability was affected, and the relevant systems and processing operations.
People and recordsCategories and approximate number of affected data subjects, plus categories and approximate number of personal data records.
Contact pointName and contact details of the DPO or another person able to provide further information.
Likely consequencesThe realistic adverse effects for individuals, including how they could occur and which groups face the greatest exposure.
MeasuresContainment and remediation already performed, further measures proposed, and actions intended to mitigate adverse effects.
TimelineIncident date and time where known, detection, awareness, response milestones and reasons for any notification made after 72 hours.
Additional contextProcessors involved, security measures, cross-border aspects, other authorities notified and whether the filing is initial or supplemental.

If exact figures are not yet available, provide reasonable estimates and state that the investigation continues. Under Article 33(4), missing information may be supplied in phases without undue further delay. If the filing occurs after 72 hours, it must include reasons for the delay.

How is a breach notified in Romania?

The ANSPDCP maintains a dedicated personal data breach notification page with access to its online form. Before submission, the company should identify the correct controller, confirm whether the incident also affects other group entities or joint controllers, and determine whether the ANSPDCP is the competent or lead supervisory authority for any cross-border processing.

The notification should be consistent with the internal breach register, technical evidence, communications plan and any supplemental filing. A company should not understate confirmed facts, speculate beyond the evidence or present an incomplete notification as final.

Enforcement point: the ANSPDCP has publicly reported sanctions for failure to notify a personal data breach within the 72-hour period. Breach-notification obligations under Articles 33 and 34 also fall within the GDPR administrative-fine tier of up to EUR 10 million or, for an undertaking, up to 2% of total worldwide annual turnover for the preceding financial year, whichever is higher. The actual measure depends on the Article 83 assessment and the circumstances of the case.

Who should be involved in the response?

A data breach cannot be handled by IT alone. The legal assessment depends on verified technical facts, while technical containment must preserve evidence and avoid creating inconsistent records. A small decision team should be activated immediately, with clear authority and one incident chronology.

Response team
Four connected workstreams

Select a workstream to see its principal responsibility. All teams should work from the same verified timeline.

Security and IT

Contain the incident, preserve logs and forensic evidence, confirm affected systems and data, remove persistence, restore safely and record every material action.

  • Security and IT: containment, forensic preservation, affected-system analysis, eradication, recovery and evidence of technical safeguards.
  • DPO and legal counsel: awareness timestamp, controller or processor status, risk assessment, authority competence, notification drafting and privilege strategy where applicable.
  • Management and communications: decision authority, resources, operational continuity, messaging and escalation to insurers or relevant corporate bodies.
  • Processors and vendors: incident facts, contractual notification, audit cooperation, subprocessor information and coordinated remedial action.

What is the difference between a controller and a processor?

The controller decides why and how personal data are processed and carries the Article 33 duty to notify the competent supervisory authority. A processor must notify the controller without undue delay after becoming aware of a personal data breach. GDPR does not give processors a separate 72-hour period for notifying the controller.

Data processing agreements should therefore establish an immediate escalation channel, minimum incident information, continuous updates, preservation duties and cooperation with notifications and communications. A processor’s delayed or incomplete report does not remove the controller’s obligation once the controller becomes aware.

RolePrimary breach dutyContractual control
ControllerAssess risk, document every breach, notify the competent authority where required and communicate with individuals where high risk is likely.Maintain response governance and require processors to provide prompt, usable incident information.
ProcessorNotify the controller without undue delay and assist with the controller’s Article 32–36 obligations.Define rapid reporting, evidence preservation, subprocessor escalation, investigation access and update frequency.
Joint controllersAllocate responsibilities transparently, while each remains accountable for the GDPR obligations applicable to it.Agree in advance who leads investigation, authority contact and data-subject communication.

Vendor and technology contracts should be reviewed before an incident occurs. Our IT law services in Romania cover data-processing terms, security obligations, audit rights and incident-response clauses.

When must affected individuals be informed?

Under Article 34, the controller must communicate the breach to affected individuals without undue delay when it is likely to result in a high risk to their rights and freedoms. This obligation is separate from the 72-hour authority-notification rule. The communication must use clear and plain language and explain the nature of the breach, the contact point, likely consequences and measures taken or proposed.

Communication is not required when one of the Article 34(3) conditions applies:

  • appropriate protection measures applied to the affected data and made them unintelligible to unauthorised persons, such as effective encryption;
  • subsequent measures ensure that the high risk is no longer likely to materialise; or
  • individual communication would involve disproportionate effort, in which case a public communication or similarly effective measure is required.

The message should help people protect themselves. Depending on the incident, practical steps may include changing credentials, enabling multi-factor authentication, contacting a bank, monitoring accounts, watching for targeted phishing or using a dedicated support contact. Avoid minimising the event or overwhelming recipients with technical detail.

How should breach risk be assessed?

The legal threshold concerns risk to people, not only damage to the company. Business interruption, contractual liability and reputational harm matter to the response, but they do not replace the individual-rights analysis required by Articles 33 and 34.

Breach risk map
Where can harm materialise?

Select a risk area to review typical consequences. More than one area may apply to the same incident.

Identity fraud and impersonation

Identification data, credentials, signatures or financial information may enable account takeover, fraudulent transactions or convincing social-engineering attacks.

High-risk indicators include sensitive or criminal-offence data, authentication credentials, detailed financial or identity information, data concerning children or other vulnerable people, large-scale exposure, malicious exfiltration, weak safeguards and consequences that are difficult for individuals to reverse. Effective encryption, rapid verified retrieval from a trusted recipient and prompt credential revocation may reduce risk, but each control must be tested against the facts.

What evidence and documentation should be preserved?

Article 33(5) requires the controller to document every personal data breach, including the facts, effects and remedial action. The record must allow the supervisory authority to verify compliance. A defensible incident file should include:

  • the original alert, detection data and a precise incident chronology;
  • the awareness timestamp and the facts supporting it;
  • affected systems, processing activities, data categories, people and record estimates;
  • logs, forensic images, access records, emails, vendor reports and chain-of-custody information where relevant;
  • containment, eradication, recovery and mitigation actions;
  • the risk and high-risk assessments, including reasons and assumptions;
  • the decision to notify or not notify, approvals and any delay explanation;
  • copies of the initial and supplemental ANSPDCP filings;
  • data-subject communications or the documented Article 34 exception; and
  • post-incident findings, corrective actions and responsibility for completion.

Records should distinguish confirmed facts from estimates and hypotheses. The company should also consider cybersecurity, contractual and insurance requirements, DORA and other sector-specific reporting duties, and criminal-law reporting duties. These may use different thresholds and deadlines from GDPR.

A practical 72-hour response checklist

  1. Activate the incident team. Establish one decision lead, secure communications and a contemporaneous chronology.
  2. Contain without destroying evidence. Isolate affected resources, revoke compromised access and preserve logs and forensic material.
  3. Confirm whether personal data are involved. Identify the controller, processor, systems, processing activities and data flows.
  4. Record the awareness timestamp. Explain when reasonable certainty was reached and what facts supported it.
  5. Map the scope. Identify data categories, affected people, approximate record volumes, jurisdictions and vulnerable groups.
  6. Assess risk to individuals. Analyse likelihood, severity, safeguards, realistic misuse and reversibility of harm.
  7. Decide on authority notification. Notify unless the breach is unlikely to create risk. Use phased notification if necessary.
  8. Assess high risk separately. Decide whether individuals must be informed and prepare clear protective guidance.
  9. Coordinate other duties. Review processors, insurers, contractual partners, cybersecurity rules and sector regulators.
  10. Continue and close the response. Supplement filings, verify recovery, complete remediation and retain the breach record.

For a broader preventive review, use our GDPR compliance checklist for Romanian companies. Even though the checklist was published earlier, the core governance controls remain relevant and should be checked against current processing and security practices.

Frequently asked questions

Does the 72-hour period start when IT sees the first suspicious alert?

Not necessarily. The EDPB treats a controller as aware when it has a reasonable degree of certainty that a security incident occurred and compromised personal data. A short initial investigation may establish whether a breach occurred, but it must begin promptly and cannot be used to delay awareness artificially.

Must every ransomware incident be notified to the ANSPDCP?

Not automatically, but ransomware often creates availability, integrity and possibly confidentiality risks. The controller must determine whether personal data were affected, whether exfiltration or unauthorised access occurred, whether reliable backups exist and what consequences are likely for individuals. The conclusion and supporting facts must be documented.

Is an email sent to the wrong recipient a reportable breach?

It is normally a confidentiality breach if personal data were disclosed without authorisation. Whether ANSPDCP notification is required depends on the risk assessment, including the data involved, recipient, ability to retrieve or delete the message, evidence of access and possible consequences. The incident must still be recorded internally.

Can a company notify before the investigation is complete?

Yes. Article 33 permits phased notification when all required information cannot be provided at the same time. The initial notification should contain the available facts and make clear what remains under investigation. Additional information must be supplied without undue further delay.

Does a processor notify the ANSPDCP directly?

The processor’s express Article 33 duty is to notify the controller without undue delay. The controller assesses and makes the supervisory-authority notification. Separate duties may arise from the processor’s own role in other processing, contractual arrangements, cross-border circumstances or sector-specific law.

Must affected people always be informed?

No. Direct communication is required when the breach is likely to result in a high risk, unless an Article 34(3) exception applies. Authority notification uses the lower threshold of likely risk. A breach may therefore require ANSPDCP notification without requiring direct communication to individuals.

What happens if the 72-hour deadline is missed?

The company should notify without further delay and explain why the filing is late. A missed deadline does not remove the notification obligation. The authority may consider the delay, cooperation, mitigation, severity and other Article 83 factors when deciding on corrective measures or a fine.

Need urgent advice on a GDPR data breach in Romania?

We help companies assess notification thresholds, prepare ANSPDCP filings, coordinate processor responses and draft communications to affected individuals.

Book a consultation

Legal disclaimer: This article provides general information and does not constitute legal advice. The applicable response depends on the facts, the company’s role, the data and individuals affected, the competent authority and any sector-specific obligations. Obtain advice for the specific incident.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Romanian company director liability and corporate governance risk assessment

Romanian Company Director Liability: Duties and Risks

When can Romanian company director liability arise?

The company is a separate legal person, but that shield is not absolute. A director may face personal exposure for breach of corporate duties, insolvency misconduct, bad-faith tax conduct, a personal guarantee or other unlawful acts.

COMPANYSEPARATE LEGAL PERSONLiability shield BREACH OF DUTYloss + causationINSOLVENCYArticle 169 conductTAX LIABILITYbad-faith conductPERSONAL GUARANTEEcontractual exposure AI-generated illustration

Romanian company director liability does not arise automatically from the company’s debts. Personal liability requires a separate legal basis, such as a damaging breach of the director’s mandate or statutory duties, conduct that contributed to insolvency, bad-faith conduct connected with unpaid taxes, or a personal contractual commitment. Foreign directors should verify their registered powers, keep an evidence trail for material decisions and escalate financial distress early.

Accepting a director appointment in Romania is more than an administrative formality. Understanding Romanian company director liability requires reviewing both the legal mandate and the director’s actual decision-making role. The director may represent the company, commit it contractually, manage assets and supervise accounting, tax, employment and regulatory processes. Those powers carry duties to the company under the articles of association, shareholder resolutions, the rules on mandate and Romanian company law.

The exact framework depends on the company form and governance structure. The Romanian term administrator may refer to an administrator of a limited liability company (SRL) or a member of the board of directors of a joint-stock company (SA). An SA may also use a two-tier system with a management board and supervisory board. The appointment document and the articles of association should therefore be read before applying any general rule.

Is a Romanian company director personally liable for company debts?

Generally, no. An ordinary supplier, landlord or lender claim is normally against the company. The director becomes personally exposed only where the creditor or another claimant can rely on a distinct statutory, contractual or delictual basis and prove the elements required for that route.

This distinction matters. A company’s inability to pay does not, by itself, transfer every unpaid invoice to its director. Equally, the words “limited liability” do not protect a director from consequences of their own conduct.

SituationUsual starting pointPotential director exposure
Ordinary commercial debtThe company is the contracting party and primary debtor.No automatic personal liability merely because the company does not pay.
Breach of mandate or company-law dutyThe company may have suffered loss through the director’s act or omission.Liability may arise if breach, damage and causation are established under the applicable rules.
Insolvency misconductThe company enters insolvency with unpaid liabilities.The insolvency court may order persons who contributed to insolvency through conduct listed in Article 169 to bear part or all of the liabilities, within the causally connected loss.
Unpaid tax obligationsThe company remains the tax debtor.Joint liability may be established in the bad-faith situations listed in Article 25 of the Fiscal Procedure Code.
Personal guaranteeThe company receives finance, a lease or credit.The director may be liable under the separate guarantee they signed, according to its terms.
Separate unlawful actThe director acts personally as well as for the company.Civil, administrative or criminal consequences may apply depending on the specific act and statute.

Do not confuse shareholder liability with director liability. A shareholder’s exposure as an investor and a director’s exposure as a manager are different questions. One person may hold both roles, but each potential claim needs its own legal basis.

What are the core duties of a Romanian company director?

Articles 72 and 73 of Romanian Companies Law no. 31/1990 connect administrators’ obligations and liability to the rules on mandate and the special provisions of the Companies Law. They also identify responsibility toward the company for matters including the reality of capital contributions, the actual existence of distributed dividends, legally required registers, implementation of shareholder resolutions and strict performance of duties imposed by law and the articles of association.

Duty areaPractical meaningUseful evidence
Act within authorityFollow the law, articles of association, appointment terms and valid shareholder or board resolutions.Current constitutional documents, authority matrix, registered representation powers and written approvals.
Protect company interestsUse management powers for the company rather than for an undisclosed personal or third-party benefit.Conflict disclosures, abstentions, independent valuations and documented commercial rationale.
Make informed decisionsObtain information proportionate to the value, urgency and risk of the decision.Board packs, forecasts, legal and financial advice, alternatives considered and minutes.
Supervise records and complianceEnsure required registers and accounting records exist and that delegated functions are reasonably monitored.Compliance calendar, management reports, tax confirmations, audit trails and escalation logs.
Implement corporate decisionsCarry out valid shareholder decisions accurately and within the company’s legal powers.Signed resolutions, implementation plans, filings and completion records.
Preserve confidentialityProtect confidential information and business secrets during and, where applicable, after the mandate.Access controls, confidentiality undertakings and documented return or deletion of company information.

For SA board members, Article 1441 of Romanian Companies Law no. 31/1990 expressly requires prudence and diligence of a good administrator, loyalty in the company’s interest and confidentiality. It also recognises an informed-business-decision protection where the director was reasonably entitled to believe that the decision served the company and relied on adequate information. That provision should not be copied mechanically into an SRL analysis; the SRL’s own statutory rules, mandate and constitutional documents must be assessed.

Decision record

A defensible director decision has four layers

1AUTHORITYWho may decide?Which approval?2INFORMATIONFacts and forecastsProfessional advice3CONFLICTSDisclose interestsManage participation4MINUTESRationale and voteActions and follow-up AI-generated illustration
The file should show how the decision was authorised, informed, conflict-checked and implemented—not merely its eventual outcome.

How do SRL and SA director duties differ?

An SRL is usually managed by one or more administrators appointed through the articles of association or by the shareholders. Article 197 contains SRL-specific administration rules and refers expressly to Articles 75, 76, 77(1) and 79. Articles 72 and 73 remain central to the mandate-based duties and liability framework, but the articles of association are also essential because they define individual or joint representation, reserved matters, term of office and internal approval limits.

An SA has a more prescriptive governance framework. In the one-tier system, a board of directors may delegate management to directors; in the two-tier system, the management board operates under a supervisory board. Duties, delegation, conflicts, meeting procedure and the mechanics of corporate liability actions can therefore differ materially from an SRL.

Foreign group policy is not enough. A director of a Romanian subsidiary must apply the subsidiary’s Romanian-law documents and duties. Instructions from the parent company, investor or beneficial owner do not automatically excuse an act outside authority or against the Romanian company’s interests.

Before accepting or using the mandate, confirm the director provisions in the Romanian articles of incorporation. Where governance rights are also allocated between investors, coordinate those documents with the shareholder agreement while recognising that a private agreement does not replace mandatory corporate rules or Trade Register formalities.

When can the company claim against a director?

A corporate claim typically focuses on whether the director breached an applicable duty and caused quantifiable loss to the company. The decision and representation mechanics depend on the company form, the alleged conduct and the applicable articles of the Companies Law. Article 155 contains the general-meeting mechanism for an SA action against directors for damage caused to the company through breach of their duties.

Approval by shareholders should not be treated as a universal release. The legal effect depends on what was disclosed, the nature of the decision, the company form, mandatory law, third-party rights and whether the approving body had authority. A director should still require accurate materials and record concerns.

Unauthorised transaction

A director signs beyond registered or internal powers and the company suffers loss. Liability, enforceability and internal recourse require separate analysis of the authority documents and third-party circumstances.

Related-party benefit

Company assets or opportunities are directed to a connected party without transparent approval, adequate information or defensible commercial terms.

Ignored compliance warning

Management receives a specific accounting, tax or regulatory warning but takes no proportionate action, allowing avoidable loss to increase.

When can insolvency create personal exposure?

Financial distress is a critical turning point. Article 66 of Romanian Insolvency Law no. 85/2014 generally requires an insolvent debtor to apply to the tribunal within a maximum of 30 days from the onset of insolvency, subject to the statute’s rules for good-faith restructuring negotiations. The competent tax authority must be notified of the intended insolvency application 15 days before filing, and proof of that notification must be attached to the application. A legal entity’s application is signed by the persons authorised to represent it under its constitutional documents; a shareholder resolution is not required by Article 66(5).

Under Article 169, the insolvency court may order management or supervisory members, any individual or legal entity exercising control over the debtor’s financial or operational decisions regardless of formal title, and other persons who contributed to insolvency through listed conduct to bear part or all of the debtor’s liabilities, without exceeding the loss causally connected to that conduct.

Article 169 risk categoryExamples of evidence reviewed
Using company assets or credit for personal or third-party benefitRelated-party payments, asset transfers, undocumented loans and non-commercial terms.
Conducting personal business under cover of the companyRevenue diversion, overlapping contracts, beneficial ownership and use of company resources.
Continuing activity in personal interest when cessation of payments was clearly approachingCash-flow forecasts, creditor ageing, director benefits and the rationale for continued trading.
Fictitious, unlawful or missing accountingLedgers, source documents, backups, handover records and access to accounting systems.
Diverting or concealing assets, or fictitiously increasing liabilitiesAsset registers, disposals, inventory movements, invoices and connected-party balances.
Transferring assets or a significant part of the business to a closely related personTransfers made while the debtor is in financial difficulty, compliance with Article 73(2¹) of the Companies Law, the relationship between the parties, continuation of the business through the new entity and evidence of an intention to shield assets from creditors.
Ruinous financing used to delay cessation of paymentsPricing, security, repayment prospects, alternatives considered and decision minutes.
Preferential payment to one creditor shortly before cessationPayment sequence, creditor relationship, maturity dates and justification.
Other intentional conduct contributing to insolvencyThe specific act, intent, resulting loss and causal connection to insolvency.

Law no. 239/2025 inserted Article 169(1)(e1), which specifically targets the transfer of assets or a significant part of the business of a debtor in financial difficulty to a person closely related to the debtor, where the obligations imposed by Article 73(21) of the Companies Law are breached and the transfer is intended to continue the activity through the new entity while shielding assets from the debtor’s creditors.

A final Article 169 liability judgment now has consequences beyond the payment order. Under Article 169(10), the person may not be appointed as a company administrator and, if already serving as an administrator elsewhere, loses that right for 10 years from the date the judgment becomes final. The person is also barred for 5 years from founding companies or acquiring a controlling participation in a new company.

Distress response

The evidence trail becomes more important as liquidity deteriorates

1MONITORCash and arrears2VERIFYSolvency status3ADVISELegal and financial4DECIDERestructure or file5PRESERVERecords and handoverAI-generated illustration
Early monitoring and documented advice help directors distinguish temporary pressure from statutory insolvency and respond within the applicable deadline.

Failure to hand over accounting records can create a rebuttable presumption of fault and causation under Article 169. For collegial management or supervisory bodies, a member who opposed the relevant act and recorded the opposition may have a specific defence under Article 169(5). A silent disagreement is therefore much weaker than a properly documented one.

When can a director become jointly liable for Romanian tax debts?

Article 25 of Romanian Fiscal Procedure Code no. 207/2015 creates specific joint-liability routes for overdue tax obligations. They are not triggered merely by holding office. The relevant provisions require the statutory circumstances and, for the principal director-related routes, bad faith.

Potential cases include administrators or other persons who, in bad faith:

  • caused the debtor’s insolvency by transferring or concealing its assets;
  • failed during their mandate to request the opening of insolvency proceedings for tax obligations from that period that remained unpaid when insolvency was declared;
  • caused the non-declaration or non-payment at maturity of tax obligations;
  • caused an unjustified tax refund or reimbursement; or
  • caused tax debts to accumulate and prevented their payment in the circumstances covered by Article 25(21).

A tax assessment against the company and a decision establishing the director’s joint liability are different acts. The facts, legal basis, procedural steps and challenge deadlines should be reviewed immediately when a director receives a Romanian tax notice.

Can delegation, resignation or shareholder instructions remove liability?

Delegation

Delegating finance, tax or operations does not necessarily eliminate a director’s own supervision duties. The appropriate level of oversight depends on the company form, governance structure, importance of the function, warning signs and the director’s legal powers. A clear written delegation and regular reporting are stronger than an informal assumption that “the accountant handles it.”

Resignation

Resignation can end future management authority once effective and properly implemented, but it does not erase possible liability for earlier acts or omissions. The director should document the handover, return company property, preserve relevant records and ensure required Trade Register formalities are handled.

Shareholder or parent-company instructions

A shareholder instruction does not automatically legalise conduct that breaches mandatory law or the director’s duties to the Romanian company. Material instructions should be checked against reserved matters, representation rules, corporate benefit, conflicts and insolvency considerations.

Directors’ and officers’ insurance

D&O insurance may fund defence costs or certain covered claims, but wording, exclusions, notification duties, deductibles and Romanian mandatory law matter. It cannot be assumed to cover fraud, intentional misconduct, all tax exposure, fines or every insolvency claim.

Practical checklist for foreign directors of Romanian companies

  1. Verify the mandate. Obtain the current articles of association, appointment decision and Trade Register extract.
  2. Map authority. Distinguish individual representation, joint signatures, shareholder reserved matters and internal approval thresholds.
  3. Build a reporting pack. Receive timely cash-flow, tax, accounting, litigation, employment and regulatory information.
  4. Document material decisions. Record information reviewed, options, conflicts, rationale, vote and follow-up responsibility.
  5. Control related-party dealings. Disclose interests and obtain the approvals and supporting valuation appropriate to the transaction.
  6. Supervise filings and records. Use a compliance calendar and require evidence of submission and payment—not verbal confirmation alone.
  7. Escalate warnings. Investigate missed tax payments, unpaid salaries, creditor enforcement, deteriorating liquidity and missing records promptly.
  8. Record disagreement. Use the legally appropriate board record and written notification; do not rely on an informal objection.
  9. Assess distress early. Seek Romanian insolvency and tax advice before the statutory filing window is lost, allow for the 15-day advance tax-authority notification and scrutinise transfers to closely related persons.
  10. Plan the exit. Coordinate resignation, handover, registrations, access removal, record preservation and insurance notification.

The bottom line

Romanian company director liability is conduct-based, not an automatic consequence of a company debt. The strongest protection is disciplined governance: understand the mandate, obtain adequate information, act within authority and in the company’s interest, manage conflicts, preserve reliable records and respond quickly to tax or insolvency warning signs.

Foreign directors should not wait for a dispute to reconstruct the decision process. A focused Romanian-law governance review can identify gaps in signing authority, reserved matters, minutes, compliance reporting and distress procedures before they create personal exposure.

Frequently asked questions

Is an SRL administrator automatically liable for the company’s unpaid debts?

No. The SRL is normally the debtor. Personal liability requires a separate legal or contractual basis, such as breach of the administrator’s duties causing loss, Article 169 insolvency conduct, Article 25 bad-faith tax conduct or a personal guarantee.

Does being a shareholder change a director’s liability?

Shareholder and director exposure are separate. A person who holds both roles may face different claims in each capacity, but liability must be analysed under the legal basis applicable to that role and conduct.

Can shareholder approval protect a Romanian director?

Approval can be relevant, but it is not a universal defence. Its effect depends on the company form, authority of the approving body, quality of disclosure, mandatory law, third-party rights and the conduct involved.

Does resignation end a director’s potential liability?

Resignation can end future authority once effective, but it does not erase potential liability for earlier conduct. Proper handover, registration, preservation of records and insurance notification remain important.

What should a director do if they disagree with a board decision?

Obtain advice on the correct procedure, state the reasons clearly and ensure the opposition is recorded and notified in the form required by the applicable governance rules. This is particularly important for collegial bodies and insolvency-related decisions.

Can D&O insurance eliminate personal liability?

No. It may cover certain defence costs and claims, but policy terms, exclusions, notice requirements and mandatory law apply. Fraud, intentional conduct, fines, tax exposure and insolvency claims may be excluded or limited.

Disclaimer: This article provides general legal information and does not constitute legal, tax or insolvency advice. Director duties and liability depend on the company form, constitutional documents, appointment terms, decision-making process, actual conduct and the law applicable to the specific facts.

AI Notice: AI-assisted content, for review by a qualified Romanian lawyer.

Romanian lawyer reviewing employee and independent contractor arrangements with business clients

Employee vs Contractor in Romania: Legal Risks

Employee or independent contractor in Romania?

Foreign companies must match the contract to the way the work will actually be organised. Romanian employment and tax rules look beyond labels, invoices and foreign templates when control, integration and commercial independence point in another direction.

Individual Employment Labour Code Article 10 Subordination & Authority Mandatory Protections Payroll & Social Security B2B Services Agreement Fiscal Code Article 7 4-of-7 Independence Test Commercial Autonomy Own Risk & Deliverables VS Romanian Substance-Over-Form Legal Review

A company cannot turn an employee into an independent contractor simply by changing the contract title. Romanian authorities and courts may examine how the relationship works in practice: who controls the schedule, location and method of work, whether the individual may serve other clients, who bears commercial risk and whose resources are used. Before engaging a Romanian contractor, foreign companies should test both the written terms and the operating model, document genuine independence and correct any inconsistent practices.

Hiring an individual in Romania requires an early classification decision. The company must determine whether it needs an employee working under its authority or an independent provider responsible for delivering agreed services through their own business activity.

This distinction affects much more than the contract label. It can determine employment protections, payroll and social-contribution treatment, working-time controls, termination requirements and the allocation of commercial risk. A foreign template describing someone as a “consultant” or “independent contractor” will not resolve those questions if the day-to-day relationship operates like employment.

Can the parties simply choose employee or contractor status?

No. The parties may choose a contractual structure, but that structure must match the legal and economic reality of the work. A services agreement cannot safely replace an employment contract where the individual is, in substance, working under the company’s authority and direction.

Romanian law approaches classification from more than one direction. The Romanian Labour Code defines an individual employment contract through work performed for and under the authority of an employer in return for remuneration. Separately, the Romanian Fiscal Code defines independent activity through a statutory set of criteria and allows the tax authorities to reclassify a transaction or activity so that its tax treatment reflects its economic substance.

The practical assessment therefore has two connected parts:

  1. Contractual structure: what rights, duties, control mechanisms and risks the documents create.
  2. Operational reality: how managers and the individual actually organise and perform the work.

Risk: A carefully drafted contractor agreement can still be undermined by daily instructions, fixed attendance, manager approval of absences, exclusivity, company-controlled tools or treatment identical to employees.

What is the practical difference between an employee and an independent contractor?

Decision factorEmployeeIndependent contractor
Legal relationshipPerforms work under an individual employment contract.Provides defined services under a civil or commercial agreement.
Direction and controlWorks for and under the authority of the employer.Controls the method and organisation of the service, subject to agreed deliverables.
Schedule and locationNormally follows contractual and employer-established working arrangements.Should have meaningful freedom to choose when, where and how the service is performed.
Commercial riskThe employer bears the business risk and owes the agreed salary.The provider assumes genuine risks linked to cost, performance and organisation.
Other clientsMay have other employment, subject to working-time, conflict and incompatibility rules.Should be free in substance to offer services to several clients.
Tools and resourcesWork is commonly performed with employer-provided systems and resources.The provider ordinarily uses or organises their own professional resources.
Statutory protectionsReceives the mandatory protections attached to employment status.Relies primarily on the services agreement and the law governing that agreement.
Ending the relationshipTermination must follow the applicable employment route and mandatory safeguards.Termination follows the contract and applicable civil or commercial rules.
Legal Matrix

The Workforce Classification Spectrum in Romania

Full Subordination • Mandatory daily working hours • Supervised work execution • Integrated into staff hierarchy ➔ Individual Employment (CIM) Gray / Misclassified Zone • Invoiced through PFA / SRL • But 100% exclusive dedication • Fixed salary-like retainers ⚠ High Reclassification Risk Commercial Autonomy • Freedom of place & schedule • Result/deliverable-based • Multi-client portfolio & risk ✓ Lawful B2B Contractor EMPLOYEE (CIM) SUBSTANCE OVER FORM INDEPENDENT (B2B)
Figure 1: The operational spectrum used by Romanian Labour & Tax authorities to assess workforce relationships.

No single row decides the classification. The correct conclusion depends on the relationship as a whole. For example, a contractor may need access to a client’s secure systems without becoming an employee. Conversely, issuing invoices through a registered business does not by itself prove independence if the individual remains subject to employee-like control.

What does Romanian employment law treat as employment?

The central employment indicator is subordination: the individual performs work for and under the authority of the employer in return for remuneration. The company’s control over the person, not merely its right to accept a deliverable, is particularly important.

Article 10 of the Labour Code defines the individual employment contract as the agreement under which an individual undertakes to perform work for and under the authority of an employer in exchange for remuneration. This is different from a genuine customer-provider relationship, where the customer specifies the expected result but does not manage the provider as part of its workforce.

Where the facts point to employment, our employment lawyers in Romania can review the proposed contract, workplace controls and onboarding documents before work begins.

For employment, the contract must be concluded in writing, in Romanian, no later than the day before the employee starts work. The employer must also complete the required employee-register formalities before work begins. The Romanian Labour Inspectorate confirms these requirements in its official employment-contract guidance.

Operational indicators that may point towards employment include:

  • a manager determines the individual’s daily or weekly schedule;
  • attendance at a company location or continuous online availability is mandatory;
  • the individual receives detailed instructions about how work must be performed;
  • absences require permission rather than coordination of deliverables;
  • performance is managed through the same hierarchy and procedures used for employees;
  • the individual is presented internally or externally as a member of staff;
  • the role is personal and the individual cannot use collaborators or substitutes;
  • the individual bears little or no genuine commercial risk.

These are indicators, not an automatic checklist. The nature of the work, regulatory requirements, information security and customer obligations may justify some controls. The question is whether those controls preserve an independent business relationship or place the individual under employer-like authority.

When does the Fiscal Code recognise an independent activity?

Under Article 7 of the Fiscal Code, an activity performed by an individual for income is independent when at least four of seven statutory criteria are met. The evidence should show that those criteria operate in practice, not only that they were copied into the contract.

Fiscal Code criterionPractical evidence to examine
1. Freedom over place, method and scheduleThe provider plans performance independently and is not assigned employee attendance hours.
2. Freedom to work for several clientsThe contract permits other clients and the operational model does not make that freedom artificial.
3. Assumption of inherent business riskThe provider bears relevant costs, rectification duties or other genuine performance risks.
4. Use of the individual’s own assetsThe provider uses or arranges professional equipment, software, workspace or other business resources where appropriate.
5. Use of intellectual or physical capacityThe service depends on the provider’s own professional expertise or performance.
6. Membership of a regulated professional bodyThe activity is carried out within a legally regulated profession, where applicable.
7. Freedom to perform directly, with staff or collaboratorsThe provider may lawfully organise delivery personally or through employees or collaborators, subject to justified qualification and confidentiality requirements.
Statutory Rule

Romanian Fiscal Code Article 7: The 4-of-7 Independence Test

1 Autonomy Place, method & schedule 2 Multiple Clients Substantive freedom to serve 3 Commercial Risk Inherent business risk borne 4 Own Assets / Tools Equipment, premises, licenses 5 Capacity & Skill Own professional expertise 6 Professional Body Regulated trade or guild 7 Criterion 7: Delegation & Substitutes Lawful freedom to perform directly or via staff/collaborators MINIMUM 4 REQUIRED to satisfy Fiscal Code Art. 7
Figure 2: The 7 statutory criteria under Romanian Fiscal Code Art. 7. At least 4 must be satisfied and backed by operational proof.

Practical tip: Build a short evidence file for each material contractor relationship. Keep the agreement, scope of work, invoices, deliverable records and evidence of independent organisation together. A clause is stronger when the working record supports it.

Are four fiscal criteria enough to eliminate employment risk?

Not necessarily. The four-of-seven test defines independent activity for Romanian tax purposes, but it should not be treated as permission to reproduce an employment relationship through a services contract.

The tax and employment analyses overlap, particularly around control, business risk and operational autonomy, but they do not perform exactly the same function. The Labour Code focuses on work performed under employer authority. The Fiscal Code focuses on the conditions for independent activity and the correct tax treatment of economic substance.

Article 11 of the Fiscal Code allows the tax authorities to disregard a transaction without economic purpose or reclassify the form of a transaction or activity to reflect its economic content. The authority must explain the relevant facts and evidence supporting the reclassification. This makes consistent documentation important, but it also means that documentation must reflect reality.

European Union case law follows a similar substance-based approach for EU-law concepts of “worker”. In Yodel Delivery Network, Case C-692/19, the Court of Justice explained that an “independent contractor” label does not prevent worker classification where independence is merely notional. Relevant considerations included control over time, place and content of work, exposure to commercial risk, integration into the undertaking and freedom to use substitutes or serve third parties.

Which arrangements create the highest misclassification risk?

Fixed employee-style availability

The contractor must work the company’s standard hours, remain continuously available and obtain approval for any absence, regardless of deliverables.

Control over method, not only result

A company manager allocates daily tasks, prescribes the precise working method and continuously supervises the individual in the same way as employees.

Artificial freedom to serve other clients

The agreement permits other clients, but workload, exclusivity expectations or availability requirements make that freedom unrealistic.

No meaningful business risk

The individual receives a fixed recurring amount, bears no relevant costs or correction obligations and is paid regardless of the agreed output.

Full integration into the organisation

The contractor has an internal job title, reports through the employee hierarchy, appears in staff structures and is evaluated under employee procedures.

A recurring monthly fee, a long relationship, one important client or use of a customer system is not automatically decisive. Each fact must be assessed in context. Risk rises when several employee-like elements combine and genuine commercial independence becomes difficult to demonstrate.

What can happen after a misclassification finding?

A misclassification finding can open separate tax, employment, social-contribution and contractual questions. The precise exposure depends on who makes the finding, the period reviewed, the parties involved and the evidence.

Tax and social-contribution exposure

The tax authority may reassess the economic substance of the activity and determine the related tax and contribution consequences. Historic treatment, payment records, filings and the allocation of responsibility between the parties must be reviewed before quantifying any exposure.

Employment rights and claims

An individual may argue that the factual relationship was employment and seek rights associated with employee status. Questions may arise concerning remuneration, working time, leave, termination, employee records and other mandatory protections. The outcome depends on the legal route and the evidence, not on the contract title alone.

Inspection and document risk

Where work has in substance been performed as employment without the required employment formalities, the company may face labour-inspection consequences. Specific sanctions should be assessed against the law in force and the facts at the date of the review.

Commercial and transaction risk

Misclassification can affect due diligence, financing, investment or an acquisition. A buyer may ask for the contractor population, templates, tax treatment, intellectual-property arrangements and potential historic liabilities to be reviewed before closing.

Intellectual property and confidentiality

The company should not assume that an employment-style intellectual-property position automatically applies to an independent provider. Ownership, assignment, permitted use, confidentiality and return or deletion of information should be dealt with expressly and consistently with the actual relationship.

Does contracting through a PFA or an SRL remove the risk?

No business form provides an automatic safe harbour. It may change the contractual and tax analysis, but the parties should still examine who performs the service, how the relationship operates and whether the structure has genuine commercial substance.

A Romanian authorised individual enterprise, commonly referred to as a PFA, is closely connected to the individual providing the activity. An SRL is a separate legal entity, which may employ staff, assume business risks and organise delivery through its own resources. Those differences matter, but neither registration document should replace a factual review.

If the supplier structure is still being established, the practical differences should also be considered alongside our guidance on company formation in Romania for foreign founders.

For an SRL supplier, examine whether the supplier is genuinely providing a business service or whether one individual is effectively inserted into the customer’s organisation under continuous personal control. For a PFA, test the statutory independence criteria directly and retain evidence supporting them.

Foreign companies should also avoid importing assumptions from their home jurisdiction. A worker physically performing activity in Romania may trigger Romanian employment, tax, social-security, registration or permanent-establishment questions. Those cross-border issues require a separate review based on the company, worker, location and duration of the arrangement.

Related structures may require a different analysis. Our guide to dual employment in Romania explains the rules applicable when an individual holds more than one employment contract, while the guide to service contract requirements in Romania covers the clauses and compliance points relevant to genuine service relationships.

Three illustrative classification scenarios

Scenario 1: project-based software specialist

A specialist agrees to deliver defined software modules, chooses the working schedule and location, uses their own business equipment, serves several clients and may use qualified collaborators. The customer controls security standards, acceptance criteria and deadlines but not the specialist’s daily organisation.

Assessment: These facts support independence, subject to the complete contract, tax position and actual implementation.

Scenario 2: “consultant” managed as staff

An individual works from 09:00 to 18:00, reports daily to a department manager, needs approval for time off, uses only company equipment, appears on the internal organisation chart and cannot accept other clients.

Assessment: The contractor label is difficult to reconcile with the operational indicators of subordination and workforce integration.

Scenario 3: regulated client environment

An external professional must work through the customer’s secure system and attend specific meetings because of regulatory and information-security requirements. The professional otherwise decides how to perform the mandate, bears professional risk and maintains other clients.

Assessment: Use of customer systems and scheduled coordination do not decide the issue alone. The purpose and extent of control must be examined.

These scenarios are illustrative. Changing one fact, such as exclusivity, substitution rights, commercial risk or management control, may change the conclusion.

How should a foreign company structure a genuine contractor relationship?

  1. Define the result. Describe services, deliverables, acceptance criteria and deadlines instead of creating an employee job description.
  2. Preserve operational autonomy. Allow the provider meaningful control over place, schedule and method, subject to justified security and coordination requirements.
  3. Address other clients. Avoid broad exclusivity unless a narrow restriction is genuinely necessary and legally supportable.
  4. Allocate business risk. Specify responsibility for costs, tools, corrections, professional organisation and non-conforming deliverables.
  5. Review substitution and collaboration. Permit lawful use of qualified personnel or collaborators where compatible with the service, confidentiality and regulatory requirements.
  6. Separate contractors from HR procedures. Do not automatically apply employee leave approval, performance management, benefits or disciplinary systems.
  7. Protect data, confidentiality and IP. Draft clauses that fit an independent services relationship and the actual information or assets involved.
  8. Keep evidence. Retain statements of work, invoices, deliverables and communications showing independent organisation.
  9. Reassess material changes. Review the classification when the scope, reporting line, exclusivity, workload or duration changes.

How can a company audit its existing Romanian contractors?

Audit Roadmap

7-Step Romanian Contractor Classification Audit

1 Inventory All PFA/SRL 2 Fact Map Daily routine 3 Fiscal Test 4-of-7 check 4 Labour Test Authority check 5 Risk Scan IP & Tax PE 6 Classify Risk tiers 7 Remediate Lawful fix Remediation must be prospective; avoid backdating documents or creating artificial records.
Figure 3: Corporate audit roadmap for evaluating contractor populations in Romania.
  1. Inventory every arrangement. Identify individuals engaged directly, through a PFA, through a personal SRL or through an intermediary.
  2. Map the facts. Record schedule, location, reporting, tools, clients, payment model, risk, substitution and integration.
  3. Test the seven fiscal criteria. Identify which criteria are genuinely met and what evidence supports each conclusion.
  4. Test employment subordination. Compare management practices against the Labour Code concept of work under employer authority.
  5. Check connected risks. Review tax, social security, immigration, permanent establishment, IP, confidentiality and data protection where relevant.
  6. Classify by risk. Separate clearly independent providers, fact-sensitive cases and arrangements that operate like employment.
  7. Implement a lawful correction plan. Amend terms and practices where the relationship remains genuinely independent, or move to an appropriate employment structure where the facts require it.

Risk: Do not “repair” the file by backdating documents or creating evidence that did not exist. Remediation should accurately record the current position and lawfully correct the arrangement going forward, while historic exposure is assessed separately.

The Bottom Line

The employee-versus-contractor decision must be made from the work model, not from the preferred invoice or contract label. Genuine contractors organise an independent activity, retain meaningful autonomy and assume real business responsibility. Employees perform work within the employer’s authority and receive the mandatory protections attached to that status.

For foreign companies, the safest starting point is a combined contract and operations review before the individual begins work. The same review should be repeated whenever the role becomes more integrated, exclusive or manager-controlled.

Frequently asked questions

Can a Romanian contractor work for only one client?

One client does not automatically create employment, but it weakens one of the express indicators of independent activity and may increase economic dependence. The full relationship must still be assessed, including control over schedule and method, commercial risk, tools, substitution rights and whether the contractor is integrated into the client’s organisation.

Is a monthly fixed fee evidence of employment?

Not by itself. A genuine provider may charge a monthly retainer or recurring service fee. Risk increases where the payment resembles a salary and is combined with fixed attendance, continuous personal availability, direct supervision, no deliverable risk and treatment identical to employees.

Can a foreign company hire a Romanian individual as a contractor?

Potentially, but the company should confirm that the activity is genuinely independent and that the contractor has an appropriate legal and tax setup. The arrangement may also raise Romanian tax, social-security, employment, registration or permanent-establishment questions depending on the company, work location and duration.

Does an SRL invoice eliminate misclassification risk?

No. An SRL is a separate legal entity and that distinction matters, but the customer should still examine whether it receives an independently organised business service or manages one individual as part of its workforce. Contracting structure, economic substance and daily practice must be assessed together.

Should the agreement use Romanian law?

The applicable law depends on the parties and cross-border structure. A foreign governing-law clause cannot necessarily remove mandatory rules relevant to work performed in Romania. The governing law, jurisdiction, tax position and mandatory employment protections should be reviewed together before using a foreign template.

When should an existing contractor arrangement be reviewed?

Review it when the contractor becomes exclusive, moves into a managerial reporting line, adopts employee working hours, receives company benefits, stops using independent resources or shifts from project delivery to an ongoing internal role. A periodic review is also appropriate for material or long-running engagements.

Disclaimer: This article provides general legal information and does not constitute legal or tax advice. Classification depends on the contract, the actual working relationship, the parties’ tax status and the applicable Romanian and EU rules.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.

Business lawyer assisting foreign company with branch office registration in Romania

How to Register a Branch Office of a Foreign Company in Romania

 

 

 

How to Register a Branch Office of a Foreign Company in Romania

Setting up a branch office in Romania offers foreign companies a strategic foothold in the European market. This comprehensive guide provides an overview of the process to register a branch in Romania, ensuring compliance with Romanian regulations and maximizing your business potential. From understanding the nuances of Romanian law to navigating the National Trade Register Office, we’ll walk you through each step.

Play

Need Professional Help?

At our law firm, Atrium Romanian Lawyers, we assist clients with corporate & commercial law, branch registration, and investor-friendly advisory services.


Understanding Branch Offices in Romania

A receptionist welcoming visitors at the front desk of the office.

What is a Branch Office?

A branch office in Romania serves as an extension of the parent company, allowing it to conduct activities in Romania without creating a separate legal personality. Essentially, registering a branch is establishing a physical office in Romania that operates under the umbrella of the existing foreign company. Unlike a Romanian subsidiary, the branch office shares the same legal entity as its parent company, simplifying administrative processes while expanding its reach.

Branch vs. Subsidiary: Key Differences

TypeDescription
Branch OfficeExtension of parent company without separate legal personality; parent is directly liable
SubsidiaryDistinct legal entity with own capital; provides liability protection to parent

Benefits of Establishing a Branch in Romania

  • Test the Romanian market and gain insights before committing to a full-fledged subsidiary
  • Simpler and faster registration process compared to forming a new Romanian legal entity
  • Lower initial setup costs and reduced administrative burden
  • Leverage the established brand and resources of the parent company
  • Direct representation in the European Union market

Legal Framework for Foreign Companies

A close-up of legal documents and a pen on a desk.

Romanian Companies Law 31/1990

The Romanian Companies Law 31/1990 is the cornerstone of corporate governance in Romania, influencing how foreign companies can establish a branch. This law defines the legal entities permitted to operate in Romania and outlines the requirements for company formation, including registering a branch. Understanding this legislation is vital for foreign investors aiming to register a branch in Romania, ensuring compliance with local regulations.

Foreign Branch Legal Requirements

To register a branch in Romania, foreign companies must meet specific legal requirements:

  • Submit parent company’s registration documents, translated and notarized, to the National Trade Register Office (ONRC)
  • Ensure the branch representative has power of attorney to register and legally bind the company
  • Provide a registered office address in Romania with proof of occupancy
  • Define the scope of activities through CAEN codes

Registration with ONRC Romania

The National Trade Register Office (ONRC) is the central authority for registering a branch in Romania. The process involves filing necessary documents, including the parent company’s details, the decision to open a branch, and the appointment of the branch representative. Once approved, the branch office receives a unique registration number and tax identification code, allowing it to operate legally.

Atrium Romanian Law Office is an expert legal services provider based in Romania, specifically in Bucharest. The firm’s team of experienced Romanian lawyers and professionals are equipped to resolve any legal issue in a timely manner. They offer guidance through the branch registration process, ensuring full compliance with Romanian law.


Step-by-Step Registration Process

A checklist with steps for registration is pinned on a bulletin board.

Phase 1: Preparation of Required Documents

  • Parent company’s articles of association and certificate of incorporation
  • Board resolution authorizing the establishment of the branch
  • Proof of legal existence of the parent company
  • Details of the branch representative and their power of attorney
  • Business plan detailing planned activities in Romania

All foreign documents must be officially translated into Romanian and notarized. This preparation is crucial for avoiding delays with ONRC.

Phase 2: Branch Registration with ONRC

  • Submit all prepared registration documents to ONRC (in person or online)
  • Pay the registration fee (typically €50-€100)
  • ONRC reviews documents for compliance with Romanian legal requirements
  • Upon approval, receive registration certificate and unique fiscal code
  • Branch receives official publication in the Commercial Register

Phase 3: Tax Registration with ANAF

Phase 4: Post-Registration Formalities

  • Open business bank account in Romania
  • Register for social security and employment purposes
  • Apply for sector-specific licenses or permits if required
  • Notify relevant authorities of branch operations

Key Responsibilities After Registration

A computer screen displaying a business registration form.

Role of the Branch Representative

The branch representative holds significant responsibilities:

  • Acts on behalf of the parent company in all matters related to the branch
  • Is authorized to make decisions and enter into contracts
  • Must be a resident of Romania or an EU citizen with valid residence permit
  • Ensures compliance with all Romanian legal and regulatory requirements
  • Serves as the main point of contact with Romanian authorities

Parent Company Obligations

The parent company maintains certain obligations:

  • Remains ultimately liable for all activities conducted by the Romanian branch
  • Must ensure the branch adheres to Romanian legal standards
  • Is responsible for financial reporting and tax compliance
  • Must promptly communicate changes to structure or articles of association
  • Must maintain adequate insurance coverage for branch operations

Common Pitfalls & How to Avoid Them

Two people are discussing documents in a meeting room.
  • Incomplete translations — Ensure all documents are properly translated and notarized by qualified professionals
  • Inadequate branch representative — Choose a qualified individual familiar with Romanian business practices
  • Tax compliance issues — Establish robust accounting and tax reporting procedures from the start
  • Incorrect CAEN codes — Define business activities carefully to match registration requirements
  • Delayed bank account opening — Prepare all documentation in advance to expedite the process
  • Missing sector licenses — Identify and obtain all required permits before commencing operations

Useful Resources & Links


FAQ – Branch Registration in Romania

Q: What is a branch office of a foreign company in Romania?

A: A branch office is an extension of the parent company located abroad. It operates under Romanian laws while representing the foreign legal person and can engage in various business activities.

Q: How long does it take to register a branch in Romania?

A: The registration process typically takes 2-4 weeks, depending on the completeness of submitted documents and ONRC processing time.

Q: What are the registration costs?

A: Costs typically range from €500-€1,500, including ONRC fees, translation and notarization services, publication fees, and optional legal advisory services.

Q: Can a foreign company open multiple branches in Romania?

A: Yes, a foreign company can open multiple branches. However, each branch must be registered separately and comply with local laws and regulations.

Q: What is the difference between a branch and a representative office?

A: A branch can engage in commercial activities and generate revenue, while a representative office is limited to promoting the parent company’s interests without engaging in direct business activities.

Q: Is the branch representative required to be Romanian?

A: The branch representative must be a resident of Romania or an EU citizen with a valid residence permit. They don’t need to be Romanian by nationality.

Q: What are the tax implications for a branch?

A: A branch is subject to corporate income tax on income generated within Romania. It must register for VAT if annual turnover exceeds EUR 88,500 and comply with Romanian tax regulations.

Q: What documents are required to register a branch?

A: Required documents include the parent company’s incorporation certificate, articles of association, proof of legal existence, branch representative details, power of attorney, and information about planned activities.

Q: Can changes be made to the branch after registration?

A: Yes, changes such as branch representative, registered office, or scope of activities must be reported to ONRC. The parent company must ensure all modifications are properly documented and filed.


Disclaimer: This article is for general information only and does not constitute legal advice. Please consult with a qualified Romanian corporate lawyer to verify current laws and regulations before proceeding with branch registration. Laws and procedures are subject to change, and individual circumstances may vary.

Romanian Company Capital Increase 2025

Romanian Company Capital Increase: Streamlined Processes 2025

Play

Romanian Company Capital Increase: Streamlined Processes 2025

Recent draft reforms on Romanian company capital increase 2025 have reshaped foundational requirements for Romanian companies, requiring both entrepreneurs and established firms to act quickly to stay compliant and maintain operational continuity.

capital increase procedures Romanian Company

Recent proposed changes in corporate legislation will require soon a minimum financial commitment, times higher than before, significantly impacting how companies, especially limited liability companies, operate.

Proposed changes are still in draft form and have not been enacted.

The current minimum capital requirement is 1 RON, and the proposal would increase it to variable amounts (500-90,000 RON).

The draft of law links financial obligations to company size, establishing specific compliance tiers across industries.

These changes will come with tight deadlines, enhanced reporting for banking activities, and stricter registry submissions.

Non-compliance could lead to severe penalties like operational suspension or dissolution.

Seeking professional advice is important, particularly for Romanian company formation or making structural adjustments.

Key Takeaways

  • Romania’s draft of corporate laws will enforce significantly higher minimum financial commitments,
  • Three-tier compliance system will align obligations with business size and revenue,
  • Mandatory banking protocols will affect entity registration and reporting,
  • Legal expertise ensures adherence to strict deadlines and documentation requirements,
  • Non-compliance may result in operational restrictions or business dissolution.

Navigating Romanian Corporate Regulations

The recent legislative draft introduces structured financial benchmarks for commercial entities.

These changes will create clear financial parameters tied to operational scale, ensuring alignment between resources and business activities.

bank account setup requirements

Updated Financial Benchmarks for Businesses

The revised draft establishes three financial tiers based on annual revenue.

Microenterprises with earnings below 395,000 RON must maintain 500 RON in reserves.

Mid-sized organizations generating up to 7 million RON require 5,000 RON.

Larger enterprises surpassing this threshold need 90,000 RON in available funds.

Business SizeRevenue RangeFinancial Reserve
MicroUnder 395k RON500 RON
Medium395k – 7M RON5,000 RON
LargeOver 7M RON90,000 RON

Banking Compliance Essentials

Under recent reforms in Romanian company law, newly incorporated businesses will be required to open and maintain a bank account within 30 days of registration, with banks permitted to refuse only on grounds related to anti-money laundering compliance under Law 129/2019.

Companies that fail to comply risk being declared fiscally inactive by ANAF, a status that suspends tax rights and may trigger fines of up to RON 10,000 for related non-compliance.

In parallel, the draft law increases the minimum share capital for limited liability companies (SRL) in Romania to RON 8,000, obliging existing SRLs to align either at the first amendment of their articles of association or within two years of the law’s entry into force.

Legal specialists recommend that entrepreneurs and investors prepare early to ensure smooth company formation, compliance, and business continuity in Romania.

Step-by-Step: capital increase procedures Romanian Company

Strategic documentation preparation forms the foundation of successful compliance.

Organizations must balance legal precision with operational agility when modifying foundational documents to meet revised standards.

trade register documentation process

Drafting Constitutive Acts and Submissions

Modifying Articles of association requires shareholder approval through formal resolutions.

Romanian lawyers must draft updated Articles reflecting adjusted financial commitments while maintaining alignment with existing operational parameters.

Completed documentation packages must include shareholder agreements and bank deposit confirmations.

The trade register mandates electronic submission of these materials within 15 days of approval.

Common errors in draft versions often delay processing timelines.

Timelines and Compliance Deadlines

Compliance timelines under the proposed Romanian company law reforms focus on SRL share capital increases and related corporate compliance filings.

All limited liability companies (SRL) will be required to raise their minimum share capital to RON 8,000, either at the first amendment of their articles of association or within two years of the law’s entry into force.

Once approved, the shareholder resolution must be registered with the Romanian Trade Register within 15 days, with late submissions leading to administrative penalties.

Although no official deadlines apply to POS installation or payment infrastructure upgrades, businesses should align their banking arrangements and capital adjustments early to avoid being declared fiscally inactive by ANAF and facing operational delays.

Engaging professional legal and accounting services in Romania is strongly recommended to ensure smooth compliance and safeguard business continuity.

Professional guidance helps navigate overlapping requirements efficiently.

Managing Compliance and Fiscal Transparency for Business Success

Effective governance in Romania’s business environment requires close monitoring of regulatory updates and proactive adjustment to new fiscal rules.

The latest company law and tax reforms introduce obligations that connect corporate governance, banking compliance, and shareholder transactions, making coordinated management essential for business stability.

compliance risk management

Mitigating Risks and Avoiding Administrative Blockages

Under the draft reforms, share transfers involving controlling shareholders must be reported to the tax authorities within 15 days.

Where companies have outstanding debts to the state, the Romanian Trade Register may require financial guarantees from the company or incoming shareholders before registering the transfer.

At the same time, failure to maintain an active bank account or to meet the new minimum capital thresholds for SRLs may result in a declaration of fiscal inactivity by ANAF.

Companies declared inactive face serious tax consequences: they must continue paying taxes but lose the right to deduct expenses and face restrictions on VAT claims.

To prevent these risks, businesses should adopt three practical safeguards:

  • Regular audits of banking documentation and shareholder records

  • Immediate updates to Trade Register filings following ownership changes

  • Preemptive resolution of outstanding state debts before major corporate transactions

Specialized legal and accounting advisors in Romania provide real-time monitoring, representation during ANAF audits, and strategic planning to maintain compliance.

Prompt action is also critical when receiving notices from fiscal authorities: while deadlines vary by procedure, some ANAF processes grant only 30 days to submit corrective documentation, and missed deadlines may trigger enforcement measures such as account freezes or asset seizures.

Conclusion

Navigating Romania’s revised corporate framework demands strategic adaptation.

Limited liability companies in Romania face permanent operational changes rather than temporary fixes.

Successful adaptation requires proactive planning with legal specialists.

Organizations prioritizing these measures secure long-term viability in Romania’s transformed business environment.

Romanian legal expertise remains critical for interpreting evolving requirements while safeguarding growth opportunities.

FAQ – Romanian Company Law and Compliance (2025)

What is the minimum share capital for a limited liability company (SRL) in Romania?


Under the draft reforms to Law 31/1990, the minimum share capital for an SRL will increase from 1 RON to 8,000 RON.

Existing companies must align either at the first amendment of their articles of association or within two years of the law’s entry into force.

Certain regulated industries (e.g. banking, insurance) still require much higher thresholds under sector-specific rules.

How long does it take to open a bank account for a capital increase?


Romanian banks usually process share capital deposit accounts within 3–5 business days, provided that the company submits incorporation documents, shareholder identification, and complies with anti-money laundering (AML) checks under Law 129/2019.

What penalties apply for missing compliance deadlines during share transfers?


Failure to submit share transfer documentation to the Trade Register or ANAF within 15 days may result in fines of up to 5,000 RON.

Persistent non-compliance can also expose companies to fiscal inactivity status, which restricts VAT deductions and expense claims, though dissolution is not an automatic sanction.

Do constitutive acts and amendments require notarization?


Notarization is no longer mandatory for standard SRL incorporation or simple amendments since the 2020 simplification of Romanian company law.

However, notarization may still be required in special cases, such as share transfers involving real estate contributions or when parties choose additional contractual safeguards.

What tax obligations follow a capital increase?


Companies must notify ANAF and the Trade Register of any capital increase within 15 days.

While capital injections themselves are not subject to taxation, incomplete or incorrect documentation may trigger tax audits or reclassification of funds.

Can foreign shareholders participate in increasing share capital?


Yes. Foreign investors may contribute capital under the same conditions as Romanian nationals.

For cross-border transfers, companies must comply with AML documentation requirements, and transactions above €10,000 are subject to reporting obligations under Law 129/2019.