Bucharest business district illustrating a share purchase agreement in Romania

Share Purchase Agreement in Romania: Due Diligence, Warranties and Closing Risks

A share purchase agreement in Romania should do more than record the number of shares and the price. It must connect the buyer’s due diligence findings with the conditions for closing, the seller’s warranties, specific indemnities, price mechanics and the corporate and regulatory steps needed to transfer control safely.

In brief: In a Romanian share deal, the buyer acquires the company with its assets, contracts, employees, licences, debts and historical exposure. The SPA therefore allocates risk between buyer and seller. Due diligence identifies the issues; the contract decides whether they must be corrected before closing, reflected in the price, disclosed against warranties, covered by an indemnity or accepted by the buyer. Romanian corporate approvals, ANAF formalities, merger control and investment screening must be tested early because they can change the signing and closing timetable.

This guide is written for foreign investors, international groups, founders and business owners negotiating the acquisition or sale of a Romanian company. It focuses on private acquisitions of shares or social parts, particularly Romanian limited liability companies (SRLs). Listed-company rules, regulated-sector acquisitions, privatisations and public takeovers require additional analysis.

The article complements our procedural guide to changing shareholders in a Romanian company. That guide covers the Trade Register implementation. This one explains how the commercial acquisition should be investigated, negotiated and protected contractually.

What does a share purchase agreement do in Romania?

A share purchase agreement, commonly called an SPA, is the principal contract under which the seller agrees to transfer and the buyer agrees to acquire shares or social parts in a Romanian company. It identifies the securities, price, conditions, closing process and allocation of risk between the parties.

The agreement operates within Romanian contract law and the mandatory rules applicable to the target’s corporate form. For an SRL, the transfer mechanics must be aligned with Articles 202 and 203 of Company Law no. 31/1990 and the applicable registration formalities before the National Trade Register Office (ONRC).

Deal structure
What does the buyer actually acquire?

Select a route to see how the risk profile changes.

Share deal

The buyer acquires the target entity itself. Contracts and assets generally remain with that entity, but so do its historical liabilities and compliance exposure.

Decision pointShare dealAsset deal
What transfersOwnership of the target company.Identified assets, contracts, liabilities or business components.
Historic liabilitiesRemain inside the acquired company and therefore affect the buyer economically.Generally remain with the seller unless assumed by contract or transferred by law.
Contracts and permitsUsually remain with the same legal entity, subject to change-of-control clauses and regulatory rules.May require individual assignment, consent, novation or reissuance.
EmployeesRemain employed by the target.A business transfer may trigger employee-transfer rules and information or consultation duties.
Core documentShare purchase agreement.Business or asset transfer agreement plus asset-specific instruments.

Why must legal due diligence come before the SPA is finalised?

Due diligence should identify the matters that can change the decision to buy, the valuation, the deal timetable or the contractual protection. A report that merely lists documents does not complete the task. Each material finding should be converted into a transaction response.

Share purchase agreement Romania due diligence represented by a green maze with a clear route
Legal due diligence helps the buyer identify risks and determine the appropriate route to a protected transaction. AI-generated illustration.

The scope normally covers corporate title and governance, financing and security, material contracts, real estate, employment, tax, disputes, permits, regulatory compliance, intellectual property, IT, data protection, environmental matters and beneficial ownership. Sector, size and business model determine the emphasis.

Due diligence map
Convert each finding into a deal response

Select a finding to see the appropriate contractual response.

Remediation

Require the seller or target to correct a curable defect before closing and deliver objective evidence that the correction is complete.

WorkstreamKey questionsPossible SPA response
Corporate and titleDoes the seller own the shares? Do the articles of association create pre-emption rights, and are there pledges, options, capital defects or approval restrictions?Title warranty, release condition, shareholder waiver, completion deliverable.
Material contractsDo customers, lenders or suppliers have termination, consent or change-of-control rights?Consent condition, covenant, retention or price adjustment.
EmploymentAre remuneration, dismissals, contractors, collective arrangements and key-person dependencies compliant?Remediation, employment warranty, specific indemnity, retention plan.
TaxAre filings complete? Are there audits, arrears, related-party risks or unsupported tax treatments?Tax covenant, tax warranty, escrow, special indemnity.
IP, technology and dataDoes the target own or validly license critical IP? Are cybersecurity and GDPR controls adequate?Assignment, licence cure, warranty, remediation plan, indemnity.
Disputes and regulationAre there claims, investigations, licences, sanctions, environmental or sector-specific risks?Regulatory condition, conduct covenant, indemnity or exclusion from the deal.

Which clauses matter most in a Romanian share purchase agreement?

The SPA should describe the transaction as one coherent mechanism. Definitions, price, conditions, warranties, disclosure, indemnities, limitations, covenants and closing deliverables must work together. Imported English-law wording should not be used without checking how it operates under the chosen governing law and Romanian mandatory rules.

Clause navigator
How does each protection work?

Select a clause family to see its transaction function.

Warranties

Contractual statements about the target, shares and business. Their value depends on scope, disclosure, knowledge qualifiers, repetition, claim rules and available recovery.

ProtectionPrincipal functionDrafting question
WarrantyAllocates risk if a contractual statement about the target or business is inaccurate.What is warranted, when is it true, and how do disclosure and seller knowledge qualify it?
Specific indemnityAllocates a defined known or identified exposure.What event triggers payment, which losses are covered and do general limitations apply?
Condition precedentPrevents closing until a necessary event, consent or approval occurs.Who controls satisfaction, what evidence is required, and when may either party terminate?
Pre-closing covenantControls how the target operates between signing and closing.Which actions need buyer consent without giving the buyer unlawful premature control?
Limitation regimeSets time limits, thresholds, caps, exclusions and claim procedure.Which claims are carved out, and does the recovery structure match the seller’s credit risk?

How should the purchase price be structured?

The price clause should explain both the headline value and the route from that value to the amount paid. A fixed price is not necessarily simple if debt, cash, working capital, leakage, earn-outs, holdbacks or currency conversion remain unresolved.

MechanismHow it worksMain negotiation risk
Locked-boxPrice is based on historic accounts at an agreed date, protected by a no-leakage covenant.Reliability of the accounts, leakage definition and permitted payments.
Completion accountsPrice adjusts after closing by reference to closing debt, cash, working capital or other metrics.Accounting policies, hierarchy of rules, timetable and expert determination.
Earn-outPart of the consideration depends on future performance or milestones.Control of the business, metric manipulation, extraordinary items and information rights.
Escrow or holdbackPart of the price is retained or deposited to support identified obligations or claims.Release triggers, duration, permitted deductions and insolvency protection.

A buyer should not treat escrow as a substitute for a coherent claims regime. The SPA should state whether recovery is limited to the escrow, whether the buyer may set off, how competing claims are handled and what happens when the escrow expires.

What is the difference between signing and closing?

Signing creates the contractual commitment. Closing completes the agreed transfer and payment once the applicable conditions are satisfied or waived. They may occur on the same day in a simple transaction, but regulatory approvals, third-party consents, financing or restructuring often require a split process.

Transaction roadmap
From exclusivity to effective control

Select a stage to review the principal legal control.

Term sheet

Align structure, valuation, exclusivity, confidentiality, process and principal conditions before the parties spend heavily on diligence and drafting.

Which Romanian approvals and filings can affect closing?

The regulatory analysis should begin before the SPA timetable is agreed. A condition drafted after signing cannot restore leverage or time already lost.

Corporate approval and ONRC registration

For an SRL transfer to an outside buyer, Article 202 of Company Law no. 31/1990 applies together with the target’s articles of association. The parties should verify statutory approval thresholds and any pre-emption or consent rights created by the articles of association, as well as pledges and other restrictions. The applicable ONRC registration formalities and the update of the company’s shareholder register should be built into the completion process.

ANAF notification and tax-debt safeguards

The practical scope of Article V of Law no. 239/2025, as amended by Government Emergency Ordinance no. 13/2026, should be verified in light of the transaction structure and current ONRC and ANAF practice. Although the regime was introduced in the context of transfers affecting company control, registration practice during 2026 has raised questions regarding its application to a broader range of SRL share transfers, as discussed in this analysis of emerging ONRC practice. The parties should confirm the current notification, tax-certificate, guarantee and registration requirements before signing and again before filing.

Merger control

An acquisition of sole or joint control may constitute an economic concentration. Under Competition Law no. 21/1996, the Romanian thresholds are generally met where the combined worldwide turnover of the undertakings concerned exceeds EUR 10 million and at least two undertakings concerned each achieved Romanian turnover exceeding EUR 4 million in the previous financial year. The EU Merger Regulation may apply instead where its thresholds are met. Closing before the required clearance can expose the parties to gun-jumping risk.

Investment screening

Romania’s investment-screening regime under Government Emergency Ordinance no. 46/2022 was substantially amended by Government Emergency Ordinance no. 17/2026. The general value threshold is now EUR 5 million, but a transaction below the threshold may still be examined if it may affect security, public order or EU projects or programmes. The rules can apply to EU and non-EU investors, and the filing contribution is EUR 5,000 where an authorisation application is required. Sector, investor, control, value and transaction structure must be screened early.

Sector approvals, lender consents, foreign-subsidy review or contractual change-of-control notices may also be relevant. The SPA should allocate responsibility, information, cooperation, remedies and the long-stop date for each approval.

What should happen at closing?

Closing should be a coordinated exchange, not a loose collection of signatures. The SPA should identify every deliverable, who provides it, its agreed form and whether all actions are deemed simultaneous.

  1. Confirm conditions. Record satisfaction or valid waiver of every closing condition.
  2. Approve the transfer. Deliver the required shareholder and corporate resolutions.
  3. Transfer the shares. Execute the required instruments and update the shareholder register.
  4. Pay the consideration. Follow the funds flow, escrow and debt repayment arrangements.
  5. Release security. Deliver releases of share pledges, guarantees or target security where agreed.
  6. Change governance. Coordinate resignations, appointments, powers of attorney and bank mandates.
  7. Deliver control items. Transfer corporate books, credentials, keys, seals and agreed records.
  8. Complete filings. Submit ONRC and ANAF documents, together with beneficial-owner filings where required under the applicable transparency rules, within the relevant timetable.

What limitations should apply to seller liability?

Seller limitations often include a de minimis threshold, basket, aggregate cap, time limits, mitigation, exclusion of double recovery and a formal claim procedure. Tax, title, authority, fraud and specific indemnities may have different limits. The commercial result depends on how these provisions interact, not on any one headline cap.

The buyer should also test recoverability. A contractual claim against a seller with no accessible assets may provide little protection. Escrow, holdback, bank security, parent guarantee or warranty and indemnity insurance may be considered depending on transaction size and risk.

A buyer’s pre-signing checklist

  1. Define the acquisition perimeter. Confirm percentage, target entities, securities and excluded items.
  2. Verify title and authority. Check ownership, encumbrances, approvals and signatory powers.
  3. Complete risk-focused due diligence. Prioritise issues that affect value, continuity or closing.
  4. Translate findings into protections. Allocate each material issue to remediation, price, condition, warranty, indemnity or withdrawal.
  5. Select the price mechanism. Define accounting rules, leakage, debt, cash, working capital and dispute resolution.
  6. Screen regulatory approvals. Review merger control, investment screening, sector approvals and third-party consents.
  7. Align signing and closing. Specify conditions, conduct rules, long-stop date, termination and closing deliverables.
  8. Test recovery. Check caps, time limits, exclusions, seller credit and available security.
  9. Plan filings and integration. Prepare ONRC and ANAF filings, beneficial-owner filings where required under the applicable transparency rules, governance steps and day-one actions.

The bottom line

A Romanian SPA should be the final expression of the buyer’s investigation and the parties’ negotiated risk allocation. The strongest agreement is not the longest. It is the one that identifies what is being bought, states how price is calculated, prevents closing before essential approvals, allocates known and unknown risks clearly and gives the parties an executable closing process.

Planning the acquisition or sale of a Romanian company?

A focused transaction review can cover deal structure, legal due diligence, SPA negotiation, regulatory screening, signing, closing and Romanian corporate implementation.

Book a Consultation

Frequently asked questions

Is a share purchase agreement mandatory in Romania?

A written transfer instrument is normally required to document and implement the transaction. In a negotiated acquisition, the SPA is the central agreement because it also records price mechanics, conditions, warranties, indemnities and closing. The required form and supporting corporate documents depend on the target’s legal form and transaction structure.

What is the difference between an SPA and a shareholders’ agreement?

The SPA governs the acquisition of shares and the allocation of transaction risk between buyer and seller. A shareholders’ agreement governs the continuing relationship among shareholders after the investment, including governance, reserved matters, funding, transfers, deadlock and exit. A minority investment may require both documents.

Can signing and closing occur on the same day?

Yes, where no unsatisfied conditions or approvals require a split process. If merger control, investment screening, financing, third-party consent or pre-closing remediation is required, signing normally precedes closing and the SPA must regulate the interim period and long-stop date.

Does due diligence remove the need for warranties?

No. Due diligence and warranties serve different functions. Diligence helps the buyer identify and evaluate risk. Warranties allocate contractual risk for inaccurate statements, subject to disclosure and limitations. Known issues may require remediation, a price adjustment or a specific indemnity rather than reliance on a general warranty.

When is Romanian investment-screening approval required?

The analysis depends on the investor, target activity, transaction structure, control or durable participation, sensitive sector and investment value. The general threshold is EUR 5 million after OUG no. 17/2026, but lower-value transactions may still be examined where security, public-order or relevant EU interests may be affected.

What happens after the SPA closes?

The parties must complete the agreed corporate, Trade Register and ANAF steps, as well as beneficial-owner filings where required under the applicable transparency rules. They must also release or retain escrow as applicable, implement governance changes and perform post-closing covenants. Price-adjustment, earn-out, indemnity and integration obligations may continue long after legal ownership changes.

Disclaimer: This article provides general information and does not constitute legal or tax advice. The correct structure, approvals, tax treatment and contractual protections depend on the parties, target, sector and facts of each transaction.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Romanian business professional reviewing GDPR compliance checklist on laptop in Bucharest office

GDPR Compliance Checklist for Romanian Companies 2025

Play

GDPR Compliance Checklist for Romanian Companies

What crucial step could protect your business from devastating fines while building customer trust?

Many organizations underestimate how Europe’s strict data protection laws apply to their operations.

While GDPR penalties can reach €20 million or 4% of global revenue, Romanian enforcement authorities have imposed fines ranging from €3,000 to €130,000 for violations, demonstrating that penalties scale with the severity of breaches and organizational size.

GDPR compliance checklist for Romanian companies

Romania’s evolving digital economy demands proactive measures to align with rigorous privacy standards.

Legal experts emphasize that proper adherence involves more than basic policy updates—it requires systematic data governance.

Companies must address consent protocols, breach response plans, and cross-border data flows to avoid regulatory scrutiny.

Specialized legal guidance helps businesses transform compliance into strategic advantages.

Firms adopting privacy-first approaches often see improved client relationships and operational resilience.

Those delaying action risk not only financial consequences but also long-term reputational damage in competitive markets.

For tailored strategies meeting international standards, contact our data protection lawyers in Bucharest.

Our team of legal professionals provide actionable frameworks to navigate complex requirements while prioritizing business growth.

Key Takeaways

  • Data protection laws apply regardless of a company’s physical location if EU resident information is processed,
  • Penalties can reach €20 million or 4% of global revenue, emphasizing the need for preventive measures,
  • Building customer trust through transparent data practices creates market differentiation,
  • Legal experts offer customized solutions to align business operations with regulatory demands,
  • Compliance involves continuous monitoring, not just one-time adjustments.

Understanding GDPR and Its Impact on Romanian Businesses

How can organizations in Romania turn regulatory demands into strategic opportunities?

The General Data Protection Regulation (GDPR) reshapes how businesses manage information, particularly for entities handling EU residents’ data.

Its extraterritorial scope means even non-EU-based firms must adhere to strict standards when processing personal details of European citizens.

Core Regulatory Foundations

The regulation establishes six foundational principles for data handling, plus an overarching accountability principle.

These mandate that organizations:

  • Process information lawfully and transparently,
  • Collect only necessary data for specific purposes,
  • Maintain accuracy and limit storage durations.

Such requirements demand technical safeguards like encryption and operational protocols for accountability.

Privacy-by-design methodologies ensure protections are embedded in all systems.

Strategic Advantages for Local Entities

Adhering to these standards transforms obligations into opportunities.

Firms prioritizing data protection report:

  • Enhanced client confidence through transparent practices,
  • Reduced breach-related costs and operational disruptions,
  • Differentiation in markets where privacy concerns influence decisions.

For tailored strategies aligning Romanian operations with these regulations, consult our team of Romanian Lawyers.

Proactive adaptation not only mitigates risks but positions businesses as trustworthy data stewards.

Exploring Key GDPR Roles and Terminology

Who holds ultimate accountability in data governance frameworks?

Clarifying responsibilities under privacy regulations helps organizations establish clear operational boundaries.

Three critical roles form the foundation of proper data management practices.

data protection officer

Data Controllers, Processors, and Data Subjects

Data controllers determine why and how personal information is handled.

They bear legal responsibility for compliance across all processing activities.

Third-party processors execute tasks under controller directives but must independently meet security standards.

Individuals whose data is collected, known as data subjects, retain rights to access or delete their information.

Organizations must implement systems to honor these requests efficiently.

The Essential Role of the Data Protection Officer (DPO)

A data protection officer oversees compliance strategies and acts as the regulatory liaison.

This role is mandatory for entities processing sensitive data or conducting large-scale monitoring.

Under Romanian Law 190/2018, organizations processing national identification numbers (CNP) based on legitimate interest must also appoint a DPO, even if they don’t meet the standard GDPR thresholds.

This additional requirement reflects Romania’s enhanced protection for sensitive national identifiers.

Romanian businesses uncertain about role allocations should consult office@theromanianlawyers.com.

Proper classification prevents overlapping liabilities and ensures alignment with cross-border standards.

Conducting a Comprehensive Data Audit and Mapping

Organizations handling personal information must first establish clarity in their data ecosystems.

A systematic audit reveals how data flows through operations, exposing vulnerabilities while ensuring alignment with legal obligations.

This foundational step transforms raw information into actionable insights for risk management.

data audit and mapping

Identifying What Personal Data You Collect

Begin by cataloging every category of personal data your organization processes.

Common examples include:

  • Contact details (names, email addresses).
  • Digital identifiers (IP addresses, device information).
  • Sensitive records (financial data, health information).

Document each data point’s purpose, collection method, and retention timeline.

Assess whether processing activities rely on valid legal grounds like contractual necessity or explicit consent.

Storage locations demand equal scrutiny—identify physical servers, cloud platforms, and third-party repositories holding sensitive materials.

Access controls form another critical audit component.

Map which employees or systems interact with personal data and verify authorization protocols.

This process highlights potential exposure points while streamlining responses to information requests.

Romanian entities seeking structured frameworks for these assessments may contact our data protection legal specialists.

Expert guidance ensures audits meet regulatory expectations while supporting operational efficiency.

GDPR Compliance Checklist for Romanian Companies

Businesses handling EU data face operational complexity when aligning processes with privacy standards.

Structured frameworks simplify adherence while minimizing risks of non-conformance.

Effective strategies combine procedural clarity with technological safeguards to meet evolving requirements.

data protection checklist steps

Actionable Protocols for Information Security

Organizations should prioritize these critical measures:

Action ItemResponsible PartyDeadline
Complete data flow mappingIT & Legal Teams30 Days
Implement encryption protocolsSecurity Department45 Days
Update third-party contractsCompliance Officer60 Days

Consent Management Best Practices

Valid authorization requires unticked checkboxes and separate permissions for distinct processing purposes.

Confirmation emails enhance verification, while centralized logging systems track user agreements with timestamps and purpose details.

Organizations must honor withdrawal requests without undue delay and provide confirmation within one month, as required by GDPR Article 12(3).

Automated systems should flag outdated records immediately upon withdrawal, ensuring ongoing alignment with transparency obligations and ceasing processing activities promptly.

Regular audits verify adherence to storage limitation principles and access controls.

Local enterprises seeking customized frameworks may contact office@theromanianlawyers.com.

Specialized guidance helps establish resilient processes that satisfy regulatory expectations while supporting operational scalability.

Ensuring Website Security and Transparent Privacy Policies

How do modern businesses balance robust security with user transparency?

Websites storing personal information require layered defenses against cyber threats.

Organizations must adopt technical safeguards while clearly communicating data handling practices to users.

website security and privacy policies

Implementing SSL, Strong Passwords, and Anti-Virus Measures

HTTPS encryption via SSL certificates forms the first line of defense.

Multi-factor authentication and complex passwords prevent unauthorized account access.

Regular vulnerability scans and firewall updates address emerging threats.

Advanced protections include:

  • Content Delivery Networks (CDNs) to mitigate DDoS attacks,
  • Intrusion detection systems monitoring server activity,
  • Automated backups stored in geographically separate locations.

Designing Clear and Accessible Privacy Notices

Privacy policies must explain data collection purposes in plain language.

Every page should feature a visible link to these documents. Essential disclosures include:

  • Types of information gathered (contact details, device data)
  • Legal basis for processing activities
  • Third-party data sharing arrangements

Entities developing their online platforms should consult office@theromanianlawyers.com for policy reviews.

Proper alignment with privacy standards builds credibility while reducing legal exposure.

Managing Third-Party Vendors and International Data Transfers

How can businesses ensure their partners meet strict data protection standards?

Organizations relying on external vendors must verify their adherence to privacy regulations.

This requires thorough evaluations and contractual safeguards to maintain accountability across supply chains.

Evaluating Vendor Requirements and Contracts

Entities handling personal information must catalog all service providers processing data.

This includes cloud platforms, payment systems, and marketing tools.

Assessments should examine vendors’ security certifications, breach response plans, and documentation of regulatory alignment.

Legally binding agreements define responsibilities between controllers and processors.

These contracts specify permitted activities, retention timelines, and security protocols.

Subcontractor arrangements require explicit approval to maintain oversight.

RequirementActionMechanism
Vendor AccountabilityReview security auditsAnnual assessments
Data TransfersImplement SCCsContractual clauses
Risk MitigationConduct impact analysesTransfer evaluations

Cross-border data flows demand additional precautions.

Companies must confirm whether recipient countries have EU adequacy status.

For other regions, standardized contractual clauses or binding corporate rules become mandatory safeguards.

Romanian enterprises navigating these complexities should seek specialized Romanian Lawyer.

Proactive vendor management frameworks prevent regulatory violations while fostering trust with European partners.

Contact office@theromanianlawyers.com for tailored strategies addressing cross-border operational challenges.

Preparing for Data Breaches and Facilitating Data Subject Rights

What separates resilient organizations from vulnerable ones when cyber threats strike?

Proactive preparation for security incidents and efficient handling of individual rights form the backbone of modern data governance.

Organizations must balance rapid response capabilities with systematic processes to address user inquiries.

Developing a Robust Breach Response Plan

Effective incident management requires predefined protocols.

Immediate detection mechanisms trigger containment procedures within one hour of identifying unauthorized data access.

Forensic teams analyze breach scope while legal advisors determine notification obligations to authorities within 72 hours.

Regular simulation exercises test communication channels between IT, legal, and PR departments.

Documentation templates for breach reports ensure regulatory requirements are met without delays.

Continuous monitoring systems flag unusual activity patterns to prevent escalation.

Streamlining Data Subject Access Requests

Individuals increasingly exercise their right to review or delete personal information.

Centralized portals allow users to submit requests through secure authentication methods.

Automated workflows verify identities and route inquiries to appropriate teams within 24 hours.

Response templates maintain consistency while adhering to legal timelines.

Secure delivery channels protect sensitive information during transmission.

Audit trails demonstrate compliance with access rights obligations during regulatory inspections.

Entities requiring customized frameworks for incident management or user rights processes should contact office@theromanianlawyers.com.

Structured approaches transform regulatory demands into operational strengths while maintaining stakeholder trust.

FAQ

When must Romanian businesses appoint a data protection officer?

Organizations must designate a data protection officer if they systematically monitor individuals on a large scale or process sensitive categories like health records.

Public authorities in Romania also require this role regardless of data volume.

How long can companies retain customer information under EU regulations?

Storage periods must align with the original purpose for collection.

For example, transaction records may be kept for tax compliance periods specified by ANAF (Romania’s tax authority), while marketing contact lists require periodic reviews for relevance.

What technical safeguards are mandatory for website security?

Essential measures include SSL encryption, multi-factor authentication, regular penetration testing, and documented patch management processes.

Organizations should implement security measures proportionate to the risk level of data processing, following GDPR Article 32 requirements for appropriate technical and organizational measures.

Are international cloud providers like AWS or Microsoft Azure GDPR-compliant for Romanian data?

Providers operating under EU-approved mechanisms like Standard Contractual Clauses (SCCs) or binding corporate rules generally meet requirements.

However, companies must verify current certifications and update Data Processing Agreements (DPAs) annually.

What penalties apply for violating data subject rights in Romania?

The National Supervisory Authority for Personal Data Processing (ANSPDCP) can impose fines up to €20 million or 4% of global turnover.

Recent enforcement actions targeted improper consent practices and delayed breach notifications.

How should organizations handle data access requests from employees?

Businesses must respond within 30 days, providing free electronic copies of records.

Implement automated DSAR workflows in platforms like Microsoft 365 or specialized tools such as OneTrust to track and fulfill requests efficiently.

Essential Documents for Foreign Founders Starting a Business in Romania

Essential Documents for Foreign Founders Starting a Business in Romania

Company formation in Romania

Essential Documents for Foreign Founders Starting a Business in Romania

Starting a business in Romania requires more than choosing a company name. The incorporation file must connect the founders, ownership structure, registered office, activities, management and beneficial-owner information in a form accepted by the Trade Register.

This guide explains the documents commonly required for foreign founders and why the correct route depends on the founder’s country, legal form, activity and filing method.

Play
Documents and practical steps for foreign founders entering the Romanian market.

Short answer: the core file usually includes founder and administrator identification, company-name information, proof of the registered office, articles of association, beneficial-owner information and the forms required by the ONRC. Foreign corporate shareholders may need additional registry, authority, translation and legalisation documents.

What Documents Are Needed?

The exact list is not identical for every applicant. An individual founder, a foreign company acting as shareholder, an EU citizen, a non-EU national and a representative acting under a power of attorney may face different document and signing requirements.

Individual founder

Usually needs a valid identity document, personal details, ownership and management information, beneficial-owner information and the declarations required for the application.

Foreign corporate shareholder

Usually needs a current registry extract or equivalent, evidence of legal existence, a corporate approval to invest and appoint representatives, and proof of the signatory’s authority.

Authorised representative

Needs a power of attorney or other authority in the form required for the filing. The document may need authentication, apostille or legalisation and an authorised Romanian translation.

Essential incorporation documents for foreign founders in Romania
Incorporation documents should be checked as one coordinated file.

Core Documents for a Romanian Company Formation File

Identity documents

Passports or identity documents for shareholders, administrators and other relevant persons. The required copy, format and translation depend on the filing route and the document’s origin.

Company name

Prepare several compliant name options and obtain the current ONRC proof or reservation document required for the incorporation route.

Registered office

Provide evidence of the right to use the Romanian premises, such as a lease, ownership document or another legally acceptable document. The arrangement should be checked for the intended activity.

Articles of association

The constitutional document should address the legal form, shareholders, capital, activities, management, representation and decision-making rules required by Romanian company law.

Beneficial-owner information

The ownership and control chain must be identified and reflected in the information or declaration required for the company-formation file.

ONRC forms and declarations

The application, declarations and supporting forms must be completed using the current ONRC requirements. The exact forms depend on the legal form and the requested registrations.

Additional Documents for Foreign Corporate Shareholders

When the shareholder is a company incorporated outside Romania, the Trade Register file normally needs evidence that the shareholder exists and that the persons signing or approving the investment have authority to do so.

Registry evidence

A recent extract or equivalent official document may be needed to show the foreign company’s legal existence, registered office, directors and ownership information.

Corporate resolution

The foreign shareholder may need a resolution approving the Romanian investment, the participation in the Romanian company and the appointment of the relevant representative.

Authority to sign

The file should show who may sign the articles of association, power of attorney and other documents on behalf of the foreign company.

Formalities abroad

Depending on the issuing country and document type, authentication, apostille or legalisation may be required before the document can be used in Romania.

There is no universal rule that every foreign document must be notarised or apostilled. The correct form depends on the issuing state, applicable international instruments, the document and the ONRC filing requirements at the time of submission.

Romanian Translations and Document Formalities

Documents submitted to Romanian authorities generally need to be usable in Romanian. A foreign-language document may require an authorised Romanian translation, and the translation may need to follow the form required for that document and filing route.

Before ordering translations or legalisation, check the complete document chain. A translation cannot cure a missing corporate resolution, an expired registry extract or a signatory who lacks authority.

Choosing the Legal Structure and Current Capital Rules

The documents depend on whether the founder chooses an SRL, an SA, a branch or a representative office. An SRL is often suitable for a privately held operating business, but the right structure depends on ownership, funding, governance, activity and the relationship with any foreign parent.

SRL

For a newly incorporated SRL, the minimum share capital is RON 500 under the current rules introduced by Law No. 239/2025. An existing SRL whose reported net turnover exceeds RON 400,000 may face a separate capital-increase obligation under the applicable timing rules.

SA

An SA has different capital, governance and incorporation requirements. The file should be prepared against the rules applicable to the proposed share structure and offering model.

Branch or representative office

These are not interchangeable with a Romanian subsidiary. The foreign parent’s constitutional documents, registry evidence and authority documents become central to the filing.

The current minimum-capital rules should be checked at the time of filing, especially where the founder is incorporating an SRL or modifying an existing Romanian company. The ONRC identifies Law No. 239/2025 as the source of the current SRL capital changes.

Registered Office and Activity Documents

The registered office requires evidence of the right to use the premises. A domiciliation or virtual-office arrangement may be possible in appropriate circumstances, but the document, provider and intended activity must be checked rather than assumed to be interchangeable with an operating location.

Activity codes should be selected under the current CAEN classification. Regulated activities may require additional approvals, professional qualifications or operating authorisations. Company registration alone does not automatically authorise every activity listed in the articles of association.

How the Documentation Process Works

1

Map the founders and structure

Identify shareholders, administrators, beneficial owners, the legal form and whether a foreign company is involved.

2

Check the activities and office

Confirm the CAEN activities, any special authorisations and the document supporting the Romanian registered office.

3

Collect foreign documents

Obtain current registry evidence, corporate resolutions, signatory authority and any required powers of attorney.

4

Complete formalities

Arrange translations and, where necessary, authentication, apostille or legalisation before the filing is submitted.

5

File and respond

Submit the complete application through an available ONRC route and address any request for correction or additional documents.

Can Foreign Founders Complete the Process Remotely?

Often, yes, but remote handling is document-dependent. A founder may act through an authorised representative where the authority document and filing route meet the applicable requirements. Online submission also depends on the current ONRC platform, signature and document-format rules.

Company formation, bank onboarding, tax registration, immigration status and permission to conduct regulated activities are separate questions. Incorporating a company does not automatically give a founder the right to live or work in Romania.

Tax and VAT: Keep These Questions Separate

The incorporation file and the company’s tax position are related but not identical. Microenterprise eligibility, profit tax, VAT registration, dividend taxation, e-Factura and sector-specific tax rules depend on the company’s facts and the law applicable at the relevant time.

For that reason, this documents guide does not state fixed tax rates or turnover thresholds as permanent formation rules. Those matters should be reviewed separately with the company’s Romanian tax adviser.

How Atrium Romanian Lawyers Can Help

Document mapping

We identify the documents required for the founder, foreign shareholder, administrator, registered office and intended activity.

Cross-border formalities

We help coordinate corporate resolutions, powers of attorney, translations and document-form requirements for foreign founders.

ONRC filing strategy

We prepare the formation route around the ownership structure, governance, activities, capital and post-registration needs.

Frequently Asked Questions

What documents does a foreigner need to start a company in Romania?

The core file commonly includes identity documents, company-name information, registered-office evidence, articles of association, beneficial-owner information, declarations and the current ONRC forms. The exact list depends on the founder and legal structure.

What extra documents are needed if the shareholder is a foreign company?

The file may require a current registry extract or equivalent, a corporate resolution, proof of signatory authority and documents concerning the foreign company’s ownership or control. Translation and legalisation requirements depend on the issuing jurisdiction and document.

Do foreign documents always need an apostille?

No. The requirement depends on the issuing country, applicable treaties or legal rules, the document and the filing route. The document chain should be checked before translation and submission.

Do documents need to be translated into Romanian?

Foreign-language documents used in the Romanian filing generally need to be made available in Romanian in the form accepted for that document and procedure. The required translation and certification should be confirmed case by case.

Can I incorporate a Romanian company without visiting Romania?

Often, yes, through an authorised representative or an eligible online route. Whether this is possible depends on the documents, signatures, powers of attorney, identity checks, banking and any sector-specific requirements.

What is the minimum share capital for a new SRL in 2026?

Under the current rules identified by the ONRC, a newly incorporated SRL has a minimum share capital of RON 500. Existing companies may be subject to separate obligations linked to net turnover and the transition rules in Law No. 239/2025.

Does company registration automatically give me a residence permit?

No. Company ownership or incorporation and the right to enter, reside or work in Romania are separate legal questions. Immigration eligibility should be assessed independently.

Does company registration authorise every activity listed in the articles?

No. Some activities require additional authorisations, professional qualifications, licences or operating conditions. The intended activity should be checked before the articles and filing are finalised.

Related Company Formation Resources

Official reference: Current forms, filing routes and procedural information should be checked on the ONRC website and its online portal. The ONRC lists Law No. 31/1990, Law No. 265/2022 and Law No. 239/2025 among the relevant national legislation. The exact document requirements may vary with the founder, jurisdiction, legal form and proposed activity.

Disclaimer: This page provides general information only and does not constitute legal advice, a legal opinion or the creation of a lawyer-client relationship. Legal solutions depend on the specific facts and documents involved.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.