Corporate data breach response centre managing a GDPR incident in Romania

GDPR Data Breach in Romania: 72-Hour Guide

A GDPR data breach in Romania creates an immediate legal decision window. The company must contain the incident, determine whether personal data were compromised, assess the risk to individuals and decide whether the Romanian supervisory authority, the ANSPDCP, must be notified within 72 hours.

GDPR data breach response and personal data security in Romania

What companies should know immediately:

  • The 72-hour period runs from the controller’s awareness of the breach, not necessarily from the moment the incident first occurred.
  • Every personal data breach must be documented, even when notification is not required.
  • The ANSPDCP must be notified unless the breach is unlikely to create a risk to individuals’ rights and freedoms.
  • Affected individuals must also be informed without undue delay when the breach is likely to create a high risk.
  • An incomplete investigation does not justify silence. GDPR permits information to be submitted in phases.

This guide is designed for Romanian companies, foreign investors, directors, compliance teams and data protection officers responding to an actual or suspected incident. It should be used together with an incident-specific legal and technical assessment. For preventive support and breach response, see our data protection services in Romania.

What qualifies as a personal data breach?

Article 4(12) of the General Data Protection Regulation defines a personal data breach as a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data. The concept is wider than a cyberattack and covers confidentiality, integrity and availability incidents.

Breach typeWhat it meansCommon exampleImmediate check
ConfidentialityPersonal data are accessed or disclosed without authorisation.An email with customer files is sent to the wrong recipient, credentials are stolen or an attacker exfiltrates a database.Who received or accessed the data, and can further access be stopped?
IntegrityPersonal data are altered without authorisation or by accident.Payroll details are changed, records are corrupted or an unauthorised user modifies a customer account.Which records changed, can the original data be restored, and were decisions made using incorrect data?
AvailabilityPersonal data become unavailable or are destroyed.Ransomware encrypts files, a database is deleted or a lost device contains the only copy of records.Are reliable backups available, how long will services be disrupted, and could the loss harm individuals?

A security event that does not involve personal data is not a personal data breach under GDPR. Conversely, a small incident can still be a breach. Under the data protection rules applicable in Romania, the number of affected people matters, but so do the sensitivity of the data, the ease of identification, the possible consequences and the vulnerability of the people concerned.

When does the 72-hour notification period start?

Article 33 requires notification without undue delay and, where feasible, no later than 72 hours after the controller becomes aware of the breach. According to the EDPB breach-notification guidelines, awareness exists when the controller has a reasonable degree of certainty that a security incident occurred and led to personal data being compromised.

A brief initial investigation may be necessary to determine whether personal data were actually affected. That does not permit an organisation to delay investigation or postpone escalation. Once there is reasonable certainty, the clock runs even if the full cause, exact number of records or final consequences are still being investigated.

72-hour incident clock
From awareness to notification

Select a stage to see the priority. The timetable is operational guidance, not a replacement for immediate action.

Confirm awareness

Record when the controller first reached a reasonable degree of certainty that personal data had been compromised. Preserve the facts supporting that timestamp.

Do not wait for a final forensic report before making the legal notification decision. Article 33 expressly permits phased notification when all information cannot be provided at the same time.

Must every breach be notified to the ANSPDCP?

No. Every breach must be recorded internally, but not every breach must be reported to the authority. The controller must assess the likely impact on the rights and freedoms of natural persons. The result falls into one of three practical levels.

Notification decision matrix
Choose the response level

Select a risk level to see the corresponding GDPR response. The conclusion must be supported by documented facts.

Document internally

If the breach is unlikely to result in a risk to individuals, authority notification is not required. The breach, assessment, effects and remedial action must still be recorded.

Assessment resultRequired actionTypical considerations
Unlikely to create riskDocument the breach and the reasons for not notifying.Strong effective safeguards, limited data, verified recovery, no realistic adverse effect and reliable containment.
Likely to create riskNotify the competent supervisory authority without undue delay and, where feasible, within 72 hours.Possible identity theft, fraud, loss of confidentiality, discrimination, financial loss, reputational harm or loss of control over data.
Likely to create high riskNotify the authority and communicate with affected individuals without undue delay, unless an Article 34 exception applies.Special-category data, credentials or financial data, vulnerable people, large-scale exposure, easy identification or serious likely consequences.

Risk is not determined by a single formula. The company should consider the type of breach, nature and volume of data, identifiability, severity and likelihood of consequences, number and characteristics of affected people, and the effectiveness of safeguards such as encryption. The EDPB’s practical breach examples are useful benchmarks, but the actual incident must be assessed on its own facts.

What must an ANSPDCP notification contain?

Article 33(3) establishes the minimum information. The ANSPDCP’s current online notification form requests additional operational details that allow the authority to understand the incident and the controller’s response.

Notification fieldWhat the company should prepare
Nature of the breachA concise incident summary, whether confidentiality, integrity or availability was affected, and the relevant systems and processing operations.
People and recordsCategories and approximate number of affected data subjects, plus categories and approximate number of personal data records.
Contact pointName and contact details of the DPO or another person able to provide further information.
Likely consequencesThe realistic adverse effects for individuals, including how they could occur and which groups face the greatest exposure.
MeasuresContainment and remediation already performed, further measures proposed, and actions intended to mitigate adverse effects.
TimelineIncident date and time where known, detection, awareness, response milestones and reasons for any notification made after 72 hours.
Additional contextProcessors involved, security measures, cross-border aspects, other authorities notified and whether the filing is initial or supplemental.

If exact figures are not yet available, provide reasonable estimates and state that the investigation continues. Under Article 33(4), missing information may be supplied in phases without undue further delay. If the filing occurs after 72 hours, it must include reasons for the delay.

How is a breach notified in Romania?

The ANSPDCP maintains a dedicated personal data breach notification page with access to its online form. Before submission, the company should identify the correct controller, confirm whether the incident also affects other group entities or joint controllers, and determine whether the ANSPDCP is the competent or lead supervisory authority for any cross-border processing.

The notification should be consistent with the internal breach register, technical evidence, communications plan and any supplemental filing. A company should not understate confirmed facts, speculate beyond the evidence or present an incomplete notification as final.

Enforcement point: the ANSPDCP has publicly reported sanctions for failure to notify a personal data breach within the 72-hour period. Breach-notification obligations under Articles 33 and 34 also fall within the GDPR administrative-fine tier of up to EUR 10 million or, for an undertaking, up to 2% of total worldwide annual turnover for the preceding financial year, whichever is higher. The actual measure depends on the Article 83 assessment and the circumstances of the case.

Who should be involved in the response?

A data breach cannot be handled by IT alone. The legal assessment depends on verified technical facts, while technical containment must preserve evidence and avoid creating inconsistent records. A small decision team should be activated immediately, with clear authority and one incident chronology.

Response team
Four connected workstreams

Select a workstream to see its principal responsibility. All teams should work from the same verified timeline.

Security and IT

Contain the incident, preserve logs and forensic evidence, confirm affected systems and data, remove persistence, restore safely and record every material action.

  • Security and IT: containment, forensic preservation, affected-system analysis, eradication, recovery and evidence of technical safeguards.
  • DPO and legal counsel: awareness timestamp, controller or processor status, risk assessment, authority competence, notification drafting and privilege strategy where applicable.
  • Management and communications: decision authority, resources, operational continuity, messaging and escalation to insurers or relevant corporate bodies.
  • Processors and vendors: incident facts, contractual notification, audit cooperation, subprocessor information and coordinated remedial action.

What is the difference between a controller and a processor?

The controller decides why and how personal data are processed and carries the Article 33 duty to notify the competent supervisory authority. A processor must notify the controller without undue delay after becoming aware of a personal data breach. GDPR does not give processors a separate 72-hour period for notifying the controller.

Data processing agreements should therefore establish an immediate escalation channel, minimum incident information, continuous updates, preservation duties and cooperation with notifications and communications. A processor’s delayed or incomplete report does not remove the controller’s obligation once the controller becomes aware.

RolePrimary breach dutyContractual control
ControllerAssess risk, document every breach, notify the competent authority where required and communicate with individuals where high risk is likely.Maintain response governance and require processors to provide prompt, usable incident information.
ProcessorNotify the controller without undue delay and assist with the controller’s Article 32–36 obligations.Define rapid reporting, evidence preservation, subprocessor escalation, investigation access and update frequency.
Joint controllersAllocate responsibilities transparently, while each remains accountable for the GDPR obligations applicable to it.Agree in advance who leads investigation, authority contact and data-subject communication.

Vendor and technology contracts should be reviewed before an incident occurs. Our IT law services in Romania cover data-processing terms, security obligations, audit rights and incident-response clauses.

When must affected individuals be informed?

Under Article 34, the controller must communicate the breach to affected individuals without undue delay when it is likely to result in a high risk to their rights and freedoms. This obligation is separate from the 72-hour authority-notification rule. The communication must use clear and plain language and explain the nature of the breach, the contact point, likely consequences and measures taken or proposed.

Communication is not required when one of the Article 34(3) conditions applies:

  • appropriate protection measures applied to the affected data and made them unintelligible to unauthorised persons, such as effective encryption;
  • subsequent measures ensure that the high risk is no longer likely to materialise; or
  • individual communication would involve disproportionate effort, in which case a public communication or similarly effective measure is required.

The message should help people protect themselves. Depending on the incident, practical steps may include changing credentials, enabling multi-factor authentication, contacting a bank, monitoring accounts, watching for targeted phishing or using a dedicated support contact. Avoid minimising the event or overwhelming recipients with technical detail.

How should breach risk be assessed?

The legal threshold concerns risk to people, not only damage to the company. Business interruption, contractual liability and reputational harm matter to the response, but they do not replace the individual-rights analysis required by Articles 33 and 34.

Breach risk map
Where can harm materialise?

Select a risk area to review typical consequences. More than one area may apply to the same incident.

Identity fraud and impersonation

Identification data, credentials, signatures or financial information may enable account takeover, fraudulent transactions or convincing social-engineering attacks.

High-risk indicators include sensitive or criminal-offence data, authentication credentials, detailed financial or identity information, data concerning children or other vulnerable people, large-scale exposure, malicious exfiltration, weak safeguards and consequences that are difficult for individuals to reverse. Effective encryption, rapid verified retrieval from a trusted recipient and prompt credential revocation may reduce risk, but each control must be tested against the facts.

What evidence and documentation should be preserved?

Article 33(5) requires the controller to document every personal data breach, including the facts, effects and remedial action. The record must allow the supervisory authority to verify compliance. A defensible incident file should include:

  • the original alert, detection data and a precise incident chronology;
  • the awareness timestamp and the facts supporting it;
  • affected systems, processing activities, data categories, people and record estimates;
  • logs, forensic images, access records, emails, vendor reports and chain-of-custody information where relevant;
  • containment, eradication, recovery and mitigation actions;
  • the risk and high-risk assessments, including reasons and assumptions;
  • the decision to notify or not notify, approvals and any delay explanation;
  • copies of the initial and supplemental ANSPDCP filings;
  • data-subject communications or the documented Article 34 exception; and
  • post-incident findings, corrective actions and responsibility for completion.

Records should distinguish confirmed facts from estimates and hypotheses. The company should also consider cybersecurity, contractual and insurance requirements, DORA and other sector-specific reporting duties, and criminal-law reporting duties. These may use different thresholds and deadlines from GDPR.

A practical 72-hour response checklist

  1. Activate the incident team. Establish one decision lead, secure communications and a contemporaneous chronology.
  2. Contain without destroying evidence. Isolate affected resources, revoke compromised access and preserve logs and forensic material.
  3. Confirm whether personal data are involved. Identify the controller, processor, systems, processing activities and data flows.
  4. Record the awareness timestamp. Explain when reasonable certainty was reached and what facts supported it.
  5. Map the scope. Identify data categories, affected people, approximate record volumes, jurisdictions and vulnerable groups.
  6. Assess risk to individuals. Analyse likelihood, severity, safeguards, realistic misuse and reversibility of harm.
  7. Decide on authority notification. Notify unless the breach is unlikely to create risk. Use phased notification if necessary.
  8. Assess high risk separately. Decide whether individuals must be informed and prepare clear protective guidance.
  9. Coordinate other duties. Review processors, insurers, contractual partners, cybersecurity rules and sector regulators.
  10. Continue and close the response. Supplement filings, verify recovery, complete remediation and retain the breach record.

For a broader preventive review, use our GDPR compliance checklist for Romanian companies. Even though the checklist was published earlier, the core governance controls remain relevant and should be checked against current processing and security practices.

Frequently asked questions

Does the 72-hour period start when IT sees the first suspicious alert?

Not necessarily. The EDPB treats a controller as aware when it has a reasonable degree of certainty that a security incident occurred and compromised personal data. A short initial investigation may establish whether a breach occurred, but it must begin promptly and cannot be used to delay awareness artificially.

Must every ransomware incident be notified to the ANSPDCP?

Not automatically, but ransomware often creates availability, integrity and possibly confidentiality risks. The controller must determine whether personal data were affected, whether exfiltration or unauthorised access occurred, whether reliable backups exist and what consequences are likely for individuals. The conclusion and supporting facts must be documented.

Is an email sent to the wrong recipient a reportable breach?

It is normally a confidentiality breach if personal data were disclosed without authorisation. Whether ANSPDCP notification is required depends on the risk assessment, including the data involved, recipient, ability to retrieve or delete the message, evidence of access and possible consequences. The incident must still be recorded internally.

Can a company notify before the investigation is complete?

Yes. Article 33 permits phased notification when all required information cannot be provided at the same time. The initial notification should contain the available facts and make clear what remains under investigation. Additional information must be supplied without undue further delay.

Does a processor notify the ANSPDCP directly?

The processor’s express Article 33 duty is to notify the controller without undue delay. The controller assesses and makes the supervisory-authority notification. Separate duties may arise from the processor’s own role in other processing, contractual arrangements, cross-border circumstances or sector-specific law.

Must affected people always be informed?

No. Direct communication is required when the breach is likely to result in a high risk, unless an Article 34(3) exception applies. Authority notification uses the lower threshold of likely risk. A breach may therefore require ANSPDCP notification without requiring direct communication to individuals.

What happens if the 72-hour deadline is missed?

The company should notify without further delay and explain why the filing is late. A missed deadline does not remove the notification obligation. The authority may consider the delay, cooperation, mitigation, severity and other Article 83 factors when deciding on corrective measures or a fine.

Need urgent advice on a GDPR data breach in Romania?

We help companies assess notification thresholds, prepare ANSPDCP filings, coordinate processor responses and draft communications to affected individuals.

Book a consultation

Legal disclaimer: This article provides general information and does not constitute legal advice. The applicable response depends on the facts, the company’s role, the data and individuals affected, the competent authority and any sector-specific obligations. Obtain advice for the specific incident.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Geometric maze illustrating contractual risk assessment during a contract review in Romania

Contract Review in Romania: 12 Clauses to Check

Which contract clauses should a business check before signing?

A Romanian business contract should clearly allocate performance, payment, liability, intellectual-property, data and exit risks. These 12 clauses are the practical starting point for a legal and commercial review.

Contract review in Romania should test more than whether an agreement is formally valid. Before signing, a business should understand what it must deliver, when it will be paid, which losses it may bear, how intellectual property and data may be used, and how the relationship can end.

Commercial contracts are often negotiated under pressure. A supplier is ready to begin, a customer wants the final draft immediately, or a foreign group needs its Romanian operation running without delay. That is precisely when unclear wording, inconsistent annexes and borrowed template clauses are most likely to pass unnoticed. Companies entering the market should connect the contract with the wider steps required to start and operate a business in Romania.

Interconnected architectural structure illustrating how contract clauses work together in a Romanian contract review
A well-structured contract depends on interconnected clauses that allocate obligations, remedies and commercial risks consistently.

Under the Romanian Civil Code, a validly concluded contract is binding on the parties, and contractual negotiations and performance are governed by good faith. A useful review therefore connects the legal wording with the operational deal. It identifies which party controls each risk, whether the agreed remedy can work in practice, and what evidence will be needed if performance is disputed.

The following 12 clauses form a practical checklist for Romanian companies and foreign businesses entering agreements governed by Romanian law or involving a Romanian counterparty.

Parties, capacity and signing authority

The contract should identify the correct legal entities, not merely the brand names used in negotiations. For a Romanian company, check its registered name, registered office, Trade Registry number, fiscal identification code and representative. If a group is involved, establish which entity receives the services, issues invoices, owns the relevant assets and assumes liability.

Signing authority should be verified against the company’s constitutional documents, Trade Registry information, corporate approvals or a power of attorney. A signature block describing someone as a “manager” does not itself resolve whether that person may bind the company for the relevant transaction. The representation rules should be checked against the company’s current Romanian articles of incorporation and the registered powers of its administrators.

The internal authority analysis also matters for potential Romanian company director liability, particularly where a director signs outside approved limits or fails to document a material commercial decision.

Check before signingConfirm the contracting entity, the signatory’s authority, any required corporate approval, the position of affiliates and whether subcontracting or assignment to another group company is permitted.

Scope, deliverables and acceptance

The scope clause should describe the goods or services, specifications, quantities, locations, deadlines, dependencies and exclusions. For project work, it should also establish milestones, acceptance tests, correction periods and a change-control procedure.

Review the main agreement together with proposals, statements of work, order forms and technical annexes. If they conflict, an order-of-precedence clause should determine which document controls. Acceptance by silence should also be tested carefully: specify when the review period begins, what constitutes a valid rejection and what happens when defects are minor. Providers using standard customer documentation should also verify the applicable service contract requirements in Romania.

Common riskThe commercial proposal promises one result, the technical annex describes another and the general conditions allow the supplier to treat delivery as accepted before meaningful testing has taken place.

Price, VAT, invoicing and payment

A complete payment clause states the price or calculation method, currency, VAT treatment, invoicing trigger, payment deadline, supporting documents, bank charges and the procedure for disputing an invoice. It should also explain whether the customer may withhold, deduct or set off amounts and whether the supplier may suspend performance for non-payment.

For B2B transactions, Law no. 72/2013 on late payment contains mandatory protections. Article 5(1) establishes a general 60-calendar-day limit for contractual payment terms between professionals. By exception, the parties may agree a longer payment term, provided that the clause is not abusive under Article 12. A term exceeding 60 days is therefore not automatically invalid, but it should be assessed carefully for gross unfairness to the creditor in light of the statutory criteria and the circumstances of the transaction. Where the applicable conditions are met, late payment can trigger statutory penalty interest and the fixed EUR 40 recovery compensation.

For the calculation rules and available remedies, see our guide to late-payment interest and penalties in Romania.

Term, renewal and minimum commitments

The agreement should state its effective date, initial duration and whether it renews automatically. An automatic renewal clause is not necessarily problematic, but the notice window, notice method and effect of a missed deadline must be clear.

Check minimum purchase commitments, exclusivity, take-or-pay obligations and price changes that continue into a renewal term. Add internal calendar reminders for any deadline that determines whether the company remains bound for another year or loses a renegotiation opportunity.

Check before signingIdentify the earliest exit date, the last date for a non-renewal notice and every financial or operational commitment that survives renewal.

Termination, cure periods and exit assistance

The termination clause should distinguish between serious breach, remediable breach, insolvency-related events, prolonged force majeure and termination for convenience. It should specify whether prior notice is required, how long the defaulting party has to cure, and whether termination operates through a contractual mechanism or requires another legal step.

The Romanian Civil Code regulates remedies for non-performance, including termination under Article 1549 and the related provisions. The contract should not merely say that a party “may terminate immediately”. It should align the grounds, notice mechanics and agreed effects with the type of contract and the intended remedy.

Exit provisions matter just as much as the termination trigger. Address final invoices, transition assistance, return of equipment and documents, data export, deletion, continued licences and the clauses that survive termination.

Penalty clauses and late-payment interest

A penalty clause fixes in advance the consequence of non-performance, defective performance or delay. Under Article 1538 of the Romanian Civil Code, its drafting should identify the protected obligation, the triggering event and the calculation method. The agreement should also state whether a penalty is daily or fixed, whether it is capped and how it interacts with damages and other remedies.

Article 1541 permits a court to reduce a penalty in the statutory circumstances, including where it is manifestly excessive in relation to the loss that the parties could have foreseen when concluding the contract. A high percentage is therefore not a substitute for careful drafting.

Common riskA daily penalty has no cap, applies to several overlapping obligations and continues after termination, creating exposure far beyond the economic value of the contract.

Liability caps, exclusions and indemnities

Liability provisions should allocate risk in proportion to the contract’s value, the parties’ control and the available insurance. Review the general cap, any separate or higher caps, excluded categories of loss, claims procedures and responsibility for employees, affiliates and subcontractors.

Do not assume that an indemnity is a familiar standard clause. It should identify the covered events, third-party claims, control of the defence, settlement authority, notification duties and mitigation. Check whether the limitation of liability applies to the indemnity or whether it creates uncapped exposure.

Any exclusion or limitation must also be tested against mandatory law and the nature of the conduct involved. A clause should not be described as protecting a party against every possible form of unlawful conduct. Where the agreement supports a wider investment or group operation, the liability wording should be reviewed together with the company’s corporate and commercial governance arrangements.

Warranties, regulatory compliance and audit rights

Warranties should be specific to the transaction. Depending on the contract, they may cover conformity with specifications, professional licences, legal compliance, authority, sanctions, anti-bribery, tax status, employment practices, product safety or the absence of third-party rights.

The review should also establish the remedy for an inaccurate warranty. Possible outcomes include correction, replacement, a price adjustment, indemnification or termination. An audit right should define scope, frequency, confidentiality, cost allocation and the treatment of identified non-compliance.

Drafting pointA broad promise to comply with “all applicable laws” may be necessary, but it does not replace transaction-specific duties, evidence requirements and an agreed remediation process.

Force majeure, hardship and change in law

Force majeure and hardship solve different problems. Force majeure concerns an external, unforeseeable, absolutely invincible and unavoidable event under the Civil Code framework. Hardship under Article 1271 addresses an exceptional change that makes performance excessively onerous, subject to the statutory conditions and the allocation of contractual risk.

The clause should define notice, evidence, mitigation, suspension, continued payment obligations and the point at which prolonged disruption permits termination. For regulated or long-term projects, add a change-in-law mechanism explaining who bears new compliance costs and whether price or timing may be adjusted.

Check before signingDo not treat every supplier delay, price increase, staff shortage or market change as force majeure. The clause should distinguish ordinary commercial risk from qualifying events.

Confidentiality and intellectual property

A confidentiality clause should define protected information, permitted use, internal access, legally required disclosures, security standards, duration and return or destruction. Trade-secret protection also depends on practical steps, so access controls and marking procedures should match the contractual wording. A standalone non-disclosure agreement in Romania may be appropriate before sensitive negotiations begin.

For intellectual property, distinguish pre-existing materials from deliverables created under the contract. State whether rights are assigned or licensed and address territory, duration, field of use, sublicensing, modifications, source materials and third-party components.

Romanian Law no. 8/1996 on copyright requires an assignment of economic copyright to specify the transferred rights and, for each, the modes of use, duration, extent and remuneration. A generic sentence stating that the customer “owns everything” may therefore be insufficient for the intended result. Businesses acquiring or licensing valuable assets can obtain a separate review from intellectual property lawyers in Romania.

For ownership arrangements between founders and shareholders, see our guide to shareholder agreements in Romania.

Personal data, security and digital services

If the agreement involves personal data, identify whether each party acts as controller, processor, joint controller or independent controller. When a supplier processes personal data on behalf of a controller, Article 28 of the General Data Protection Regulation requires a contract containing specified safeguards. Our GDPR compliance checklist for Romanian companies explains the wider governance controls that should support those clauses.

Review processing instructions, confidentiality, security measures, subprocessors, assistance with data-subject requests, breach notification, international transfers, audit rights and return or deletion. The commercial agreement and data processing agreement should not contain inconsistent liability, notice or termination rules. More complex vendor arrangements may require assistance from GDPR and data protection lawyers in Romania.

For SaaS and other digital services, also check availability commitments, backups, recovery objectives, vulnerability management, incident cooperation, data portability and access after termination. Technology businesses should align these provisions with their wider technology and digital law obligations and, where relevant, obtain a focused IT and software contract review.

Governing law, jurisdiction and notices

In cross-border contracts, governing law and forum are separate questions. The Rome I Regulation generally allows the parties to choose the law governing their contractual obligations, subject to its safeguards and mandatory rules. The Brussels I bis Regulation governs jurisdiction and the recognition and enforcement of judgments in relevant EU civil and commercial matters.

Consider whether the selected court or arbitral tribunal is proportionate to the likely dispute, where evidence and assets are located, the language and cost of proceedings, and whether an eventual judgment or award can be enforced efficiently.

The notice clause should identify valid addresses, permitted delivery methods, deemed receipt and the process for updating contact details. A termination or claim notice sent to the commercial contact may fail if the contract requires delivery to a different address or by a specific method. Where non-payment is already a concern, the agreement should be tested against the available legal recovery options for unpaid invoices in Romania.

Contract review in Romania: risk map

Contract areaQuestion to answerRisk if unclear
AuthorityIs the correct entity bound by an authorised person?Enforceability, approval and group-liability disputes.
PerformanceWhat exactly must be delivered, tested and accepted?Disputes over completion, defects and payment.
PaymentWhen is money due and what follows from delay?Cash-flow loss, penalties and invoice disputes.
ExitHow can the relationship end and what survives?Lock-in, service interruption and lost data.
LiabilityWhich losses are covered, capped or excluded?Exposure disproportionate to contract value.
IP and dataWho owns or may use assets, information and data?Loss of rights, GDPR exposure and operational dependency.
DisputesWhich law, forum and notice rules apply?Unexpected cost and difficult enforcement.

A practical pre-signing review process

Confirm the commercial dealRecord the intended result, price, timeline and points already agreed before editing legal language.
Read every contract documentReview the agreement, annexes, order forms, proposals, policies and incorporated online terms together.
Rank the risksSeparate legal defects, high-value commercial exposure, operational ambiguity and points that are negotiable preferences.
Propose usable wordingConvert each material issue into a replacement clause, tracked change or clear negotiation question.
Check signing and evidenceConfirm authority, approvals, signature method, final attachments and preservation of the executed version.
Calendar post-signing dutiesTrack notices, renewals, price reviews, certificates, audits and delivery or payment milestones.

Need a Romanian contract reviewed before signing?

Atrium Romanian Lawyers assists Romanian and foreign businesses with contract review, drafting and negotiation. The review can be delivered as tracked changes, replacement clauses, a consolidated draft or a practical risk report adapted to your position in the transaction.

Frequently asked questions

Is a business contract written in English valid in Romania?

Romanian companies can generally conclude commercial contracts in English. The transaction may nevertheless require Romanian-language documents or translations for authorities, courts, employees, consumers, notaries or regulated formalities. The governing-language clause should state which version prevails if the contract is bilingual.

Can a foreign-law contract be used with a Romanian company?

Potentially, yes. In a cross-border contract, the parties may often choose the governing law, but the Rome I framework, mandatory rules, the place of performance and the practical enforcement route must be considered. Choosing foreign law does not automatically remove every Romanian mandatory provision relevant to the transaction.

Are contractual penalties enforceable in Romania?

Romanian law recognises penalty clauses, but the obligation, trigger and calculation must be clear. Article 1541 of the Civil Code permits judicial reduction in the statutory circumstances, including a penalty that is manifestly excessive compared with the foreseeable loss at contract formation.

When should contract review in Romania take place?

Ideally before signing and before the commercial position becomes difficult to change. A new review is also appropriate before renewal, when the scope or price changes, when a party proposes an amendment, or when performance problems and a possible dispute emerge.

What should a foreign company send to the reviewing lawyer?

Send the complete draft and annexes, the commercial proposal, your role in the transaction, the applicable deadline, the principal business concerns and any terms already agreed. Identifying whether you are the customer, supplier, licensor, employer, investor or distributor changes the risk analysis.

Disclaimer: This article provides general legal information and does not constitute legal, tax or commercial advice. Contractual rights and risks depend on the complete document, the transaction, the parties, mandatory rules and the relevant facts.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Commercial invoice overlooking the Bucharest skyline, illustrating late payment in Romania

Late Payment in Romania: Penalties, Interest and Legal Remedies

When is a Romanian invoice late — and what can a creditor recover?

A missed payment deadline in Romania is not only a collections problem. It can trigger statutory penalty interest, a fixed recovery compensation and, with the right contract, a pre-agreed penalty clause — without the creditor having to prove any loss.

Overdue commercial invoice, payment deadline and legal documents in a Romanian law office

Late-payment claims may include interest, recovery compensation and documented collection costs.

Late payment in Romania is heavily regulated for business-to-business transactions. Under Law 72/2013, which transposes EU Directive 2011/7, a B2B invoice is generally payable within about 30 days unless the parties expressly agreed a longer term — capped at 60 days unless a longer term is not abusive. On late payment, provided the creditor has performed its obligations and the delay is imputable to the debtor, a professional creditor can claim the applicable statutory or contractual late-payment interest or penalty, together with the €40 flat recovery compensation and recoverable collection costs. For money obligations assumed in the exercise of an undertaking’s activity, the debtor is in delay by operation of law, so interest runs from maturity without a formal demand, subject to the statutory conditions. Exact figures depend on the contract and on the reference rate published by the National Bank of Romania.

Most foreign suppliers start with a practical question: when can you demand more than the unpaid principal, and how do you recover an unpaid invoice in Romania? This guide explains when a payment becomes late, which charges a creditor can add, which payment terms are valid (and which clauses are void), and the realistic recovery route from a first demand through to enforcement.

The rules below focus on business-to-business transactions governed by Romanian law. They apply on top of the general contract-law regime: the Romanian Civil Code and, for commercial transactions, the specific late-payment law, Law 72/2013, based on EU Directive 2011/7 on combating late payment.

What can a Romanian creditor charge on a late invoice?

Penalty interest, plus a fixed €40 recovery compensation, plus enforceable recovery costs — and, if the contract says so, a daily contractual penalty. Penalty interest, the €40 minimum compensation and a contractual penalty do not require proof of actual loss. Additional recovery costs, however, must be substantiated. These rights accrue provided the creditor has performed its obligations and the delay is imputable to the debtor.

Romanian law gives a creditor who is not paid at maturity a right to moratory damages — penalty interest — running from the due date until payment, at the rate agreed in the contract or, absent agreement, at the statutory rate, without having to prove any loss (Civil Code, Article 1535). The debtor cannot defend by showing the creditor suffered a smaller loss.

Depending on the contract, the creditor may claim the applicable statutory or contractual late-payment interest or penalty, together with the €40 minimum compensation and recoverable collection costs. Whether a contractual late-payment penalty may be cumulated with another form of moratory damages depends on the drafting and legal nature of the contractual remedies.

  1. Statutory or contractual penalty interest — at the rate agreed by the parties or, absent agreement, the statutory penalty interest at the reference rate plus 8 percentage points for professional relations, applied for each semester on the rate in force at the start of that semester (Law 72/2013, Article 4, read with OG 13/2011, Article 3).
  2. Fixed minimum compensation of €40 — a flat amount of recovery damages, payable in lei at the exchange rate on the payment date, in addition to the interest (Law 72/2013, Article 10).
  3. Substantiated recovery costs — collection expenses actually incurred and established can be claimed as damages (Law 72/2013, Article 9).
  4. Contractual penalty clause — a pre-agreed per-day penalty, enforceable without proof of loss (Civil Code, Article 1538), subject to the statutory reduction grounds in Civil Code, Article 1541. Whether it may be cumulated with other moratory damages depends on the contract’s drafting.

Risk: A creditor who ignores the interest route and waits silently may still recover the principal, but documentation matters. If the debtor later disputes the amount, the creditor must show when each sum became due. Keep invoices, delivery or acceptance evidence and the calculation of interest from maturity.

When is a payment legally late?

At the contractual due date, or generally 30 calendar days after the debtor receives the invoice when no term was agreed. In B2B contracts, an agreed payment term longer than 60 days is valid only if it is not abusive (grossly unfair) to the creditor.

The starting point is the term agreed in the contract. The parties may choose the payment date, subject to an important limit in business relations: the contractual payment term cannot exceed 60 calendar days, and a longer term is permitted only if the clause is not abusive under Law 72/2013, Article 5.

When the contract is silent, Law 72/2013, Article 3 fixes the moment from which penalty interest runs. For a professional creditor, interest runs after 30 calendar days from receipt by the debtor of the invoice or of any equivalent payment request. Where the date of receipt is uncertain or the invoice is received before the goods or services, the law uses the date of delivery of the goods or performance of the services as the reference point.

For money obligations assumed in the exercise of an undertaking’s activity, the debtor is in delay by operation of law: interest begins to run at maturity without any formal demand or notification (Civil Code, Article 1523). A written reminder still matters — it creates evidence of the claim and of the date from which the debtor was asked to pay, which becomes relevant in litigation.

These rights accrue only where the statutory conditions are met: in particular, the creditor and its subcontractors must have performed their contractual obligations, and the delay must be imputable to the debtor. The debtor must not have paid the amount due at maturity and must be unable to show that the delay is not attributable to it (Law 72/2013, Article 3(1)).

SituationInterest startsBasis
Payment term agreed in the contractOn the day after the contractual due date, generally without a formal demandCivil Code Art. 1535; Art. 1523 (enterprise money obligations)
No payment term agreed (B2B)30 calendar days after the debtor receives the invoice or equivalent payment requestLaw 72/2013, Art. 3(3)
Invoice received before delivery of goods or services30 calendar days after delivery or performanceLaw 72/2013, Art. 3(3)
Debtor is a public authorityGenerally 30 days; exceptionally up to 60 days where expressly stipulated and objectively justified; public healthcare institutions: maximum 60 daysLaw 72/2013, Art. 6–7

For public authorities, the general legal payment term is 30 calendar days. Exceptionally, the parties may stipulate a term of up to 60 calendar days if it is set out expressly in the contract and in the procurement documentation and is objectively justified by the nature or the specific characteristics of the contract (Law 72/2013, Article 7). For public healthcare institutions and public entities providing medical services, the legal payment term is capped at 60 calendar days (Law 72/2013, Article 6(4)).

The parties cannot contract around the invoice date itself: any clause fixing a term for issuing or receiving the invoice is absolutely void (Law 72/2013, Article 5(3)).

How is the interest rate calculated?

Parties may agree their own rate or penalty, but in transactions governed by Law 72/2013 a clause that excludes late-payment interest or sets it below the statutory penalty interest is treated as abusive. Absent an agreement, the statutory penalty interest in professional relations is set at the reference rate plus 8 percentage points per year.

  • Agreed rate or penalty clause. The contract may set a specific annual interest rate or a per-day penalty, for example 0.1% or 0.5% per day. Such clauses are valid and enforceable without proof of loss, subject to reduction by a court on the statutory grounds under Civil Code Article 1541. In transactions governed by Law 72/2013, a clause that excludes late-payment interest or sets it below the statutory penalty-interest level is treated as abusive under Article 14(a).
  • Statutory rate. If the parties did not agree a rate, Law 72/2013, Article 4 applies the statutory penalty interest calculated under Article 3 of OG 13/2011. For professional relations, the rate is the reference rate plus 8 percentage points, with the rate in force on the first calendar day of each semester applying for the whole semester.

The BNR reference rate in force on 1 July 2026 was 6.50%. Accordingly, the statutory B2B penalty interest applicable throughout the second semester of 2026 is 14.50% per annum. Because the reference rate moves, always confirm the rate currently in force on the National Bank of Romania website before relying on a figure.

Tip: For recurring commercial relationships, agree the interest or penalty rate in the contract. A clearly drafted penalty clause removes any argument about which statutory rate applies and creates a strong, predictable claim on each overdue invoice.

The €40 flat compensation and recovery costs

In B2B relations, a creditor is entitled to a flat minimum compensation of €40 per late payment, in addition to the applicable late-payment interest or penalty and to the costs of any enforcement procedure.

Law 72/2013, Article 10 gives the creditor the right to demand, when the conditions for late payment are met, the equivalent in lei at the exchange rate on the payment date of €40, representing flat-rate minimum damages for the costs of recovering the claim. The obligation to pay this amount matures at the same time as penalty interest starts running.

This flat amount is additional to the applicable late-payment interest or penalty and to the costs of any subsequent enforcement procedure. CJEU case law confirms that the fixed €40 minimum is payable for each commercial transaction not paid on time and evidenced by an invoice or an equivalent payment request, even where several invoices are pursued in a single claim (Case C-585/20, BFF Finance Iberia). Where a single contract provides for successive supplies or services subject to separate payment deadlines, the €40 minimum is payable for each late payment (Case C-419/21).

On top of the €40, Article 9 allows the creditor to claim recovery expenses actually incurred and established. By contrast, the €40 itself does not require proof of loss and remains the simplest element to assert on each unpaid invoice.

Which payment terms are valid — and which clauses are void?

A B2B payment term is capped at 60 days unless a longer term is not abusive. Clauses postponing the start of interest, requiring a formal demand before interest runs, or excluding penalty interest or recovery compensation are unenforceable.

Law 72/2013, Article 12 establishes the general test: a clause or practice is abusive where it creates, in a grossly unfair way (“vădit inechitabil”), rights and obligations significantly unbalanced to the creditor’s detriment. Article 13 sets the criteria a court considers, including serious deviation from established good practice, absence of objective reasons for derogating from the statutory payment terms or interest rate, and the counterparty’s dominant position towards an SME. Article 14 identifies clauses deemed abusive by law, without need for further assessment, and Article 15 sanctions abusive clauses by absolute nullity.

Clauses of the following type are deemed abusive by law and are therefore absolutely null under Law 72/2013, Articles 14 and 15:

  • clauses excluding penalty interest or setting it below the statutory penalty interest;
  • clauses fixing a moment for the interest to start later than the statutory moment;
  • clauses making interest depend on a formal putting-in-delay even though the debtor is in delay by operation of law;
  • in contracts between professionals and public authorities, a payment term exceeding what Article 7(1) allows when the exceptional conditions are not met;
  • clauses excluding the possibility of additional damages.

Mistake: relying on a 90-day payment term “because the client insisted”

In B2B contracts a term beyond 60 days is only valid if it is not abusive. A term imposed by the larger counterparty without objective justification is exposed to challenge and will not stop the statutory interest from running.

Mistake: waiting for a formal demand before recognising interest

For enterprise money obligations, delay arises by operation of law. The claim for interest starts at maturity. The creditor does not first have to send a formal notification.

Mistake: writing “0% interest” into the contract to keep the client happy

A clause that excludes penalty interest altogether is unenforceable against a professional creditor and can be disregarded. The statutory interest will still apply.

How to recover an unpaid invoice in Romania: the practical route

The route runs from a written demand, through the payment-order procedure for certain, liquid and due contractual claims, to court judgment and enforcement. Most commercial claims follow these steps, but timing, documents and evidence requirements should be checked against the specific contract before acting.

Documents illustrating the recovery of an unpaid invoice through demand, court proceedings and enforcement in Romania

Recovering an unpaid invoice normally progresses from a documented demand to court proceedings and, where necessary, enforcement.

  1. Commercial reminder. Send a payment request identifying the invoice, due date and interest accruing. Even where delay is automatic, this creates documentary evidence and often resolves the matter.
  2. Statutory summons. Before filing under the payment-order procedure, the creditor must serve a formal summons under Article 1015 of the Code of Civil Procedure through a judicial executor or by registered letter with declared contents and acknowledgment of receipt, granting 15 days to pay.
  3. Court action. If the debtor contests the claim or amount, recover through ordinary court proceedings for the principal, interest and costs.
  4. Enforcement. Once the creditor holds an enforceable title, a judicial executor can attach bank accounts, receivables or other debtor assets.

Risk: The payment-order procedure is not a substitute for litigation when determining the debtor’s defence requires evidentiary administration incompatible with the summary nature of the procedure. The claim must concern a certain, liquid and due contractual obligation established within the documentary framework. Otherwise, the creditor may have to pursue the claim through ordinary proceedings.

Which route fits which situation?

RouteBest forKey document or conditionMain business consideration
Written demand plus statutory interestOverdue but still cooperative counterpartiesInvoice, contract and evidence of deliveryPreserves the relationship while demonstrating the claim
Payment-order procedureCertain, liquid and due contractual claims for a sum of moneyWritten evidence establishing the contractual claim and proof of the mandatory Article 1015 summonsFaster track for clear claims; genuine disputes may derail it
Ordinary court actionDisputed liability, quantum or set-off argumentsFull evidence of the relationship, delivery and defaultLonger timeline; costs can include interest and fees
Enforcement by judicial executorDebtor with assets who does not pay voluntarilyEnforceable title, such as a payment order or judgmentAttachments and garnishment become available

The payment-order and enforcement rules are contained in the Romanian Code of Civil Procedure. Our dedicated guide to the payment ordinance procedure in Romania explains the conditions and required documents. The broader debt recovery in Romania guide covers the complete collection strategy.

Illustrative scenarios

No penalty clause in the contract

A Romanian buyer does not pay a 30-day invoice of €10,000. Because the money obligation was assumed in a business activity, interest runs from maturity without a formal demand at the statutory B2B rate, and the €40 flat compensation applies. The supplier can demand the principal, interest and the €40 in one written request.

Contract with a 0.5% daily penalty

The parties agreed a daily penalty of 0.5% of the unpaid amount. On a disputed invoice, the creditor can claim the contractual penalty without proving any loss under Civil Code Article 1538. A court may reduce the penalty only on statutory grounds, such as partial beneficial performance or a penalty that is manifestly excessive compared with the foreseeable loss.

Debtor contests the invoice

The debtor claims the services were defective and refuses payment. Because the claim is genuinely disputed, the payment-order route may not resolve the matter. The supplier should prepare evidence of performance and acceptance and assess ordinary litigation against the amount at stake.

How to protect your position before and after maturity

The strongest position starts before the invoice is issued. Interest and penalties are easier to claim when the contract supports them and the documentation confirms what was delivered, when it was delivered and for which price.

  1. Set a compliant payment term. Align the due date with Law 72/2013, generally up to 60 days in B2B transactions, and state it clearly in the contract.
  2. Agree a penalty or interest rate. Include a per-day penalty clause or an agreed annual interest rate so there is no argument about the statutory rate.
  3. Invoice promptly and completely. Issue the invoice with an unambiguous due date and complete references to the contract and delivery documents.
  4. Confirm receipt and delivery. Keep signed delivery notes, acceptance records or other evidence that the goods or services were provided.
  5. Send a written reminder at maturity. Restate the amount, due date, interest formula and €40 compensation. This becomes part of the evidence supporting the claim.
  6. Calculate interest from the correct date. Use the contractual due date or the applicable 30-day statutory threshold, with the semester rate in force at the start of each semester.
  7. Assess the payment-order procedure early. For a certain, liquid and due contractual claim established through documentary evidence, consider the faster procedure rather than waiting while interest and costs accumulate.
  8. Preserve the enforcement option. If payment does not follow, instruct counsel or a judicial executor before the debtor transfers assets.

The Bottom Line

Late payment in Romania is not merely a collections nuisance. It is a regulated event that gives the creditor a defined set of remedies. A professional creditor can claim the applicable statutory or contractual late-payment interest or penalty, the €40 minimum compensation and substantiated recovery costs. Late-payment interest or a contractual penalty and the €40 minimum compensation do not require proof of actual loss, while additional recovery costs must be established. Getting the payment terms, penalty clause and paper trail right from the beginning converts an overdue invoice into a clearly quantified claim that can be pursued through the payment-order procedure or the ordinary courts.

Frequently asked questions

Do I have to send a formal notice before interest starts running?

For money obligations assumed in the exercise of an undertaking’s activity, the debtor is in delay by operation of law and interest runs from maturity without a formal demand. A written reminder is still advisable as evidence and may be required for other remedies.

What is the statutory interest rate for late payment in Romania?

In professional relations, it is the reference rate plus 8 percentage points per year. With the reference rate at 6.5%, that is approximately 14.5% per annum. Confirm the current reference rate published by the National Bank of Romania before relying on a figure.

Is the €40 compensation automatic?

In B2B relations, yes. When the conditions for late payment are met, the creditor may demand the lei equivalent of €40 as flat-rate minimum recovery damages, in addition to penalty interest and enforcement costs.

Can we agree a payment term longer than 60 days?

Only if the clause is not abusive or grossly unfair to the creditor. A longer term imposed without objective justification is exposed to challenge. Clauses fixing the invoice issue or receipt date are absolutely void.

Are contractual penalty clauses enforceable without proof of loss?

Yes. A penalty clause entitles the creditor to the agreed amount without proving any loss. A court may reduce the penalty only in limited statutory circumstances, including where the penalty is manifestly excessive compared with the foreseeable loss.

Does late payment allow the creditor to terminate the contract?

Non-performance can give rise to termination rights where the statutory conditions are met. Termination is assessed separately from the interest claim and carries its own consequences, so it should be considered with counsel before being used.

Disclaimer: This article provides general legal information about Romanian and EU late-payment rules and does not constitute legal or tax advice. Interest rates, deadlines and remedies depend on the contract, the parties’ status and the specific facts. Figures such as the reference rate change over time.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Finance team reviewing a Romanian RO e-Factura electronic invoice workflow

RO e-Factura Romania 2026: Foreign Company Guide

RO e-Factura in Romania is no longer only a local accounting issue. A foreign company may be affected because it has a Romanian subsidiary, a fixed establishment, a Romanian VAT registration, domestic transactions or Romanian customers. The correct result depends on the company’s VAT status and the transaction—not simply on the country in which the parent company is incorporated.

Key points for 2026:

  • From 1 January 2026, the statutory transmission deadline is generally five working days, subject to the separate legal deadline for issuing the invoice.
  • A Romanian VAT number alone does not necessarily mean that a foreign company is established in Romania.
  • Domestic B2B clearance, reporting by a non-established supplier and invoices to a foreign Romanian-VAT-registered customer must be classified separately.
  • When RO e-Factura is mandatory, a PDF is not a substitute for the validated structured electronic invoice.
  • The operational record should preserve the XML, the Ministry of Finance electronic seal or validation response, submission evidence and any corrected invoice.

This guide updates the existing Atrium article for the 2026 rules and is intended for foreign investors, finance teams, Romanian subsidiaries and non-resident businesses with Romanian VAT exposure. It should be read together with advice on Romanian tax law and, where a foreign entity needs a local fiscal identifier, the guide to obtaining a Romanian NIF tax identification number.

RO e-Factura compliance in Romania for foreign companies
RO e-Factura compliance workflow for companies operating in Romania. AI-generated illustration.

What changed for RO e-Factura in 2026?

The most important operational change is the move from five calendar days to five working days. The change was introduced through Government Emergency Ordinance no. 89/2025, which amended OUG no. 120/2021 and replaced the previous five-calendar-day transmission deadline with a five-working-day deadline effective from 1 January 2026. See also the explanatory summaries published by Contabilul and VATupdate. The deadline runs from the invoice issue date, but it cannot extend beyond five working days calculated from the statutory deadline for issuing that invoice under the Romanian Fiscal Code. Public holidays and the precise date from which the period is calculated should therefore be built into the company’s controls.

2026 pointPractical meaningControl to implement
Five working daysThe transmission period is counted in working days from 1 January 2026, subject to the invoice-issuance backstop.Use a Romanian working-day calendar and escalate before the final day.
Foreign VAT customersA Romanian-established supplier may have reporting duties for domestic invoices issued to a non-established customer registered for VAT in Romania.Separate establishment, VAT registration and invoice-delivery status in customer master data.
Special B2C exceptionsFrom 1 June 2026, Law 88/2026 introduced optional treatment for certain natural persons and specifically listed categories.Do not treat every individual customer record as identical.
Older guidanceMaterials referring to the calendar-day deadline, future 2025 B2C implementation or obsolete registration forms may be outdated.Version-control procedures and use current ANAF forms and legislation.
Scope selector
Which foreign-company profile are you assessing?

Select the closest profile. The explanation below is a screening result, not a substitute for transaction-level VAT analysis.

Romanian subsidiary

A Romanian company making domestic B2B supplies is ordinarily within the mandatory domestic system. Map invoice types, credentials, software and recipient status before go-live.

Does RO e-Factura apply to a foreign company?

There is no reliable yes-or-no answer based only on the existence of a Romanian VAT number. The analysis should identify the supplier, customer, place of supply, establishment used for the transaction, VAT-registration status and invoice category.

A Romanian subsidiary is a Romanian-established taxable person. A foreign company may also have a Romanian fixed establishment if the relevant VAT tests concerning sufficient permanence and human and technical resources are met. By contrast, a foreign company can be registered for Romanian VAT without being established in Romania.

Particular care is required where a foreign company is not established in Romania but holds a Romanian VAT registration. Such businesses should not automatically be analysed under the same mandatory domestic B2B clearance rules that apply to taxable persons established in Romania. Their obligations must be verified separately under the specific provisions applicable to non-established VAT-registered persons and any optional RO e-Factura registration route.

Business situationLikely RO e-Factura treatmentQuestion requiring verification
Romanian subsidiary invoices a Romanian businessDomestic B2B clearance is generally mandatory.Are any statutory exclusions or special invoice rules relevant?
Foreign company supplies through a Romanian fixed establishmentThe entity may be treated as established for the relevant transaction.Is the Romanian establishment actually involved in the supply?
Foreign company has only a Romanian VAT registrationVAT registration alone does not create a Romanian establishment. Any reporting obligations should be assessed separately from the mandatory domestic B2B clearance regime applicable to established taxable persons.What is the place of supply and has the company opted into the system?
Romanian supplier invoices a non-established customer registered for Romanian VATReporting obligations should be analysed under the specific rules applicable from 1 January 2026. Additional commercial transmission arrangements may still be required depending on the recipient’s status and access to the system.Is the recipient participating in RO e-Factura or only VAT-registered?
Export, intra-Community supply or service with place of supply abroadGenerally outside the domestic B2B exchange rule, subject to transaction-specific reporting.Is the VAT classification and evidence supporting the cross-border treatment correct?

Important distinction: an obligation to report invoice data is not always identical to full platform exchange between supplier and recipient. A non-established business should confirm whether it is reporting a domestic transaction, voluntarily registered in RO e-Factura or subject to the domestic clearance route because of a Romanian establishment.

How does the electronic invoice flow work?

The invoice is prepared as structured data compliant with the Romanian semantic model, based on the European e-invoicing standard. It is transmitted through the Ministry of Finance infrastructure, commonly through SPV-integrated software or an authorised technical solution. The system validates the file. If validation succeeds, the electronic seal is applied and the validated file becomes the system invoice. If it fails, the issuer receives an error response and must correct and resubmit it.

Invoice flow
From accounting data to defensible archive

Select a control point to see what the finance or IT team should retain.

Create structured XML

Generate the invoice from accurate supplier, customer, VAT and line-item data using the current RO_CIUS technical rules.

The official platform makes files available for download for a limited operational period. This is not a substitute for the company’s own legally compliant archive. The archive should allow the original XML, seal or validation status, readable representation, correction trail and accounting entry to be matched.

Technical specifications, validators and official web applications are published through the Ministry of Finance technical information page and the RO e-Factura web applications page.

Which transactions are in scope?

The Romanian rules cover several legally distinct streams: B2B, B2G and B2C reporting, as well as particular reporting obligations for non-established persons. Companies should not use a single ERP flag called “Romanian customer” as a substitute for the legal analysis.

The B2C reporting regime introduced for suppliers established in Romania should not automatically be assumed to apply to every non-resident supplier. For foreign businesses without a Romanian establishment, the legal position should be verified separately based on the applicable provisions and transaction structure.

Transaction2026 starting positionOperational note
Domestic B2B between persons established in RomaniaMandatory platform exchange, unless a statutory exclusion applies.The validated XML is the legally relevant electronic invoice.
B2G invoice within the statutory regimeMandatory according to the public-procurement and e-invoicing rules.Check public authority identifiers and contract references.
B2C invoice issued by an established supplierReporting is generally mandatory, with specific 2026 exceptions.The consumer does not need SPV access for the commercial invoice.
Domestic transaction by a non-established VAT-registered supplierA reporting obligation may apply; optional system registration changes the mechanics.Confirm current registration form and recipient-delivery channel.
Export or intra-Community supplyGenerally outside the domestic B2B exchange obligation.Retain evidence supporting the VAT treatment and destination.
Simplified invoice or other statutory exceptionTreatment depends on the specific legal exception.Do not infer exclusion merely because the amount is small.

How is the five-working-day deadline calculated?

From 1 January 2026, the invoice must generally be transmitted within five working days from the issue date, but no later than five working days after the last legal date on which the invoice should have been issued. The day of the triggering event, weekends and Romanian public holidays can affect the calculation under the applicable time-computation rules.

A delayed invoice issue date does not automatically postpone the transmission deadline. Where the invoice is issued after the statutory issuance deadline under Article 319 of the Romanian Fiscal Code, the five-working-day transmission period must be assessed by reference to the legal issuance deadline rather than the late issuance date. This backstop is also explained in the 2026 deadline summary.

Deadline control
A working-day clock needs four checks

Select a card to see the control that prevents a false deadline.

Confirm issue date

Use the date actually stated on the invoice and reconcile it with the accounting event. Backdating or delayed batch creation can create an immediate compliance risk.

For example, if an invoice is issued on a Monday and there is no public holiday, Tuesday is ordinarily the first working day and the following Monday is the fifth. This is only an illustration: the statutory invoice-issuance deadline and Romanian public holidays must also be checked.

What happens if an invoice fails validation?

A technically rejected file has not completed the required process. The response should be triaged immediately: identify whether the problem concerns syntax, master data, tax codes, totals or a business-rule conflict; correct the source data; regenerate the XML; resubmit it; and preserve both the failed and successful responses.

A successfully communicated invoice cannot simply be “returned” inside the system. Commercial objections should be handled separately, and corrections should follow Article 330 of the Romanian Fiscal Code. The corrective document must itself be transmitted when the RO e-Factura obligation applies.

What penalties and audit risks should foreign companies consider?

The penalty analysis depends on the legal obligation that has been breached. Late reporting can attract fixed fines by taxpayer category. For mandatory domestic B2B exchange, issuing or accepting an invoice outside the system can trigger a percentage-based sanction. The 15% sanction should not be applied mechanically to every cross-border or non-resident scenario without first confirming that the relevant statutory route covers the transaction and party.

The applicability of the 15% sanction should always be assessed by reference to the specific statutory obligation governing the transaction, including the supplier’s establishment status and the legal route under which the invoice was required to be transmitted.

RiskPossible consequencePreventive evidence
One or more late invoices in a calendar monthGenerally RON 5,000–10,000 for large taxpayers; RON 2,500–5,000 for medium taxpayers; RON 1,000–2,500 for other legal persons and individuals.Deadline dashboard, submission timestamps and exception log.
Mandatory domestic B2B invoice issued outside the systemA sanction equal to 15% of the total invoice value may apply to the issuer under the relevant rule.ERP block preventing off-system finalisation of in-scope invoices.
Recipient records an in-scope domestic B2B invoice received outside the systemA corresponding 15% sanction may apply to the recipient, subject to the statutory conditions.Accounts-payable validation against the system record.
Validation failure left unresolvedThe invoice may remain untransmitted and become late.Error queue, named owner, retry log and successful response.
Wrong establishment or customer classificationIncorrect platform route, missing report or duplicate delivery.Documented VAT and establishment decision tree.
Control map
Where implementation most often fails

Select a risk to see the corresponding control.

Wrong customer status

Maintain separate fields for country, Romanian VAT number, establishment status, customer type and participation in RO e-Factura. One “foreign” flag is not enough.

Implementation checklist for a foreign company

  1. Map the Romanian footprint. Identify subsidiaries, branches, fixed establishments, VAT registrations and fiscal representatives.
  2. Classify transaction flows. Separate domestic B2B, B2G, B2C, exports, intra-Community supplies, local reverse-charge cases and other cross-border services.
  3. Confirm access and authority. Verify SPV access, qualified certificates, mandates and the persons authorised to submit or retrieve files.
  4. Update master data. Record establishment status, Romanian VAT identifiers, customer type and system-participation status separately.
  5. Test XML generation. Validate tax codes, units, discounts, advance invoices, credit notes, currency and rounding rules.
  6. Build deadline monitoring. Use Romanian working days, identify the statutory issue-date backstop and prevent submission only on the final day.
  7. Create an error workflow. Route rejected files to a named owner and require documented resubmission.
  8. Control incoming invoices. Reconcile accounts payable with RO e-Factura where domestic B2B exchange is mandatory.
  9. Archive the evidence. Preserve XML, seal or response, readable copy, corrections and submission logs under the applicable accounting and tax-retention rules.
  10. Review changes. Monitor the official Ministry of Finance RO e-Factura hub, current legislation and ANAF technical announcements.

Official registration and verification resources

At the time of publication, ANAF documentation refers to Form 081 for the optional register, Form 082 for the mandatory register and Form 083 for certain non-resident operators. Companies should verify the current ANAF form catalogue before implementation, as registration procedures and form numbering may change over time.

At the time of publication, Form 083 is generally used by certain non-established operators wishing to opt into RO e-Factura. Companies should verify the current ANAF requirements before filing because registration procedures may change.

Use the official ANAF forms catalogue and the ANAF online registers. For the governing framework, consult the current consolidated text of Government Emergency Ordinance no. 120/2021, together with subsequent amendments including Law no. 88/2026.

Need a transaction-specific RO e-Factura review?

A focused review can determine whether a foreign company is established, merely VAT-registered or subject to a separate domestic reporting route, and translate that conclusion into an implementable invoice workflow.

Book a Consultation

Frequently asked questions

Does a Romanian VAT number make a foreign company established in Romania?

No. VAT registration and establishment are separate concepts. A fixed-establishment analysis considers permanence and appropriate human and technical resources, as well as whether that establishment is involved in the transaction. A Romanian VAT registration obtained through direct registration or fiscal representation does not in itself create a Romanian fixed establishment for VAT purposes.

Are all invoices involving a foreign company reported through RO e-Factura?

No. The result depends on the supplier, customer, place of supply, establishment status, Romanian VAT registration and invoice category. Exports and intra-Community supplies are generally outside the domestic B2B exchange rule, although other reporting obligations may apply.

What is the RO e-Factura deadline in 2026?

From 1 January 2026, the general transmission deadline is five working days from issue, but no later than five working days calculated from the statutory deadline for issuing the invoice. Romanian public holidays and the applicable time-computation rules must be included.

Is a PDF invoice sufficient?

Not where mandatory RO e-Factura exchange applies. The structured XML validated through the system and accompanied by the Ministry of Finance electronic seal is the legally relevant electronic invoice. A PDF may remain useful as a readable copy.

Can a recipient reject an invoice in RO e-Factura?

The system invoice cannot simply be returned. The recipient may communicate objections, while any correction should follow Article 330 of the Fiscal Code and be transmitted through RO e-Factura when the obligation applies.

What should a company do after a validation error or platform problem?

Preserve the response and technical logs, identify and correct the error, resubmit promptly and retain the successful confirmation. A company should not assume that a technical issue automatically extends the statutory deadline; any official unavailability procedure should be checked on the facts.

This article provides general information on Romanian electronic invoicing and tax compliance. The result depends on the transaction, place of supply, establishment, VAT status, invoice type, technical implementation and legislation in force. It does not replace legal or tax advice on a specific invoice flow.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.