DPIA and FRIA assessment paths for an AI project in Romania

DPIA vs FRIA in Romania: Which Assessment Does Your AI Project Need?

AI governance • Romania • Assessment decisions

DPIA vs FRIA in Romania is a question of two different legal tests. A data protection impact assessment (DPIA) addresses risks arising from personal-data processing under the GDPR. A fundamental rights impact assessment (FRIA) under the AI Act applies to specified deployers of certain high-risk AI systems. Your project may require one, both, or neither mandatory assessment.

When do these obligations apply?

The GDPR assessment requirements already apply. Under the AI Act’s consolidated timetable, Chapter III Sections 1–3, including Article 27, apply to Annex III high-risk systems from 2 December 2027. The corresponding date for Article 6(1)/Annex I product systems is 2 August 2028; that does not extend Article 27 to every product system.

Article 111 contains separate transition provisions for existing systems. A project review should record when the system was placed on the market or put into service and whether subsequent design changes affect its treatment. The future FRIA timetable does not postpone GDPR duties. Source: consolidated AI Act, Articles 111 and 113.

DPIA vs FRIA: the differences that change your project

Both assessments examine potential harm to people. A DPIA is not limited to confidentiality or cybersecurity: it also examines other rights and freedoms affected by personal-data processing. FRIA addresses the impact of the specified AI deployment on fundamental rights.

Click or tap a row to reveal its practical takeaway. Keyboard users: Tab to a green label and press Enter or Space. Swipe the table sideways on a small screen.

Two assessments, separate applicability tests
Decision pointDPIA: GDPR Article 35FRIA: AI Act Article 27
Personal-data processing likely to create high risks to individuals, assessed in its context.A covered deployer using an in-scope Article 6(2)/Annex III high-risk system.
The controller, with DPO advice where a DPO is designated and relevant processor assistance.The deployer covered by Article 27.
Processing, necessity, proportionality, risks to people and safeguards.Deployment context, affected groups, risks of harm, human oversight and responses.
Before the relevant processing begins; review when risk changes.Before first use where the obligation applies; update changed or outdated elements.
Prior consultation when the Article 36 threshold is met; no universal filing requirement for every DPIA.Notify results to the market surveillance authority under Article 27(3), subject to its exception.
Shared evidence can support the assessment of the actual processing.Relevant DPIA sections may be cross-referenced or incorporated; remaining requirements still need coverage.

GDPR Articles 28, 35–36 and 39; AI Act Article 27.

When does an AI project need a DPIA?

AI use alone does not automatically trigger a DPIA. The controller must assess whether the nature, scope, context and purposes of the processing make a high risk to people likely. Article 35 expressly recognises the relevance of new technologies.

The GDPR identifies particular situations, including systematic and extensive automated evaluation underpinning decisions with legal or similarly significant effects, large-scale processing of special-category or criminal-offence data, and large-scale systematic monitoring of publicly accessible areas. Applicable supervisory-authority lists must also be checked.

For a Romanian deployment, the file should therefore address the applicable requirements and guidance of the Romanian data protection authority, ANSPDCP, alongside Article 35. Record the reasons for a negative screening conclusion too. A supplier’s description of a product as “low risk” is not an assessment of your processing.

Where required, the DPIA must describe the processing and purposes, assess necessity and proportionality, evaluate risks to individuals and specify safeguards. This is a substantive project assessment, not simply a signed template. Source: GDPR Article 35.

For the broader data-protection framework, see our guide to GDPR compliance when using AI in Romania.

Who needs a FRIA under the AI Act?

The Article 27 obligation does not cover every business using high-risk AI. It concerns Article 6(2) high-risk systems and specified categories of deployer, with an exclusion for the critical-infrastructure area in Annex III point 2.

  • Bodies governed by public law deploying qualifying systems.
  • Private entities providing public services deploying qualifying systems. This status requires analysis; it is not synonymous with every company selling services to the public.
  • Deployers of qualifying creditworthiness or credit-scoring systems for natural persons under Annex III point 5(b), which excludes systems used to detect financial fraud.
  • Deployers of qualifying life and health insurance risk-assessment or pricing systems for natural persons under Annex III point 5(c).

Classification under Article 6 must be checked first, including the conditions of any applicable exception. The exact intended purpose matters. A financial-sector tool is not automatically a creditworthiness system, and a medical product is not automatically within the Article 27 FRIA route. Source: AI Act Articles 6 and 27 and Annex III.

Explore four deployment scenarios

These hypothetical examples explain the screening logic. They assume the stated facts and do not replace an assessment of the actual system, applicable dates or transition rules.

Candidate ranking: DPIA and FRIA can diverge

A private manufacturer uses extensive automated applicant evaluation to support hiring decisions. These facts point to a DPIA requirement under Article 35(3)(a), even if a person makes the final decision. Recruitment may also fall within Annex III. However, on the assumption that the manufacturer is neither a public-law body nor a private public-service provider, its employer status alone does not trigger Article 27 FRIA.

Consumer credit: prepare for both assessments

A lender uses an in-scope high-risk system to score individuals for loan eligibility. Systematic and extensive profiling with significant consequences can trigger a DPIA. Article 27 separately covers qualifying deployers under Annex III point 5(b). Address the applicable FRIA timetable and any transition provisions, rather than assuming both duties started on the same date.

Public benefits: assess deployment and processing together

A public body uses a qualifying high-risk system to assess eligibility for essential assistance benefits. Its status and use case bring Article 27 into the analysis. The personal-data processing needs separate DPIA screening, including relevant public-task legislation and any Article 35(10) position. One completed assessment does not automatically discharge the other.

Drafting assistant: examine the actual workflow

A team drafts generic product descriptions without personal data or decisions about people. On those narrow facts, the workflow does not itself establish a DPIA or Article 27 FRIA requirement. Check account data, logs and supplier processing separately. Introducing customer records, employee evaluation or regulated decisions changes the analysis. Other duties may still apply.

Can one assessment document cover DPIA and FRIA?

A coordinated file can reduce duplicated work, provided each legal requirement remains identifiable. The consolidated Article 27(4) expressly allows relevant DPIA sections to be cross-referenced or incorporated into FRIA where they already meet the corresponding obligations.

Start with a shared description of the system, purposes, data flows, affected people and safeguards. Then keep a requirement map showing which sections satisfy GDPR Article 35 and which satisfy AI Act Article 27. Identify gaps rather than renaming a DPIA “FRIA”. Source: AI Act Article 27(4)–(5).

As a practical drafting approach, include a separate deployment chapter addressing who may be affected beyond the immediate users, how mistakes influence access to opportunities or services, who can intervene, and how complaints lead to corrective action. Avoid treating GDPR as only a privacy checklist: the DPIA itself must consider risks to rights and freedoms.

What the FRIA needs to address

Article 27 requires the deployment process and intended use, duration and frequency, affected people and groups, specific risks of harm, implementation of human oversight, and measures if risks materialise, including governance and complaint mechanisms. Reusing a supplier assessment in similar cases is permitted, but the deployer must check its fit and update changed or outdated elements. Source: AI Act Article 27(1)–(2).

Who prepares, reviews and owns the decision?

The controller remains responsible for the DPIA; the covered deployer remains responsible for FRIA. A consultant, DPO or supplier can contribute without taking over the organisation’s statutory role.

For the DPIA, seek the designated DPO’s advice and preserve their independent advisory and monitoring function. Obtain relevant processor assistance. For the deployment review, involve the business owner, technical team and people responsible for oversight and complaints. A useful internal decision records outstanding conditions, the person accountable for each safeguard and the circumstances requiring a fresh review. Source: GDPR Articles 28(3)(f), 35(2) and 39; AI Act Article 27.

Contractual cooperation should cover the evidence you need to assess the deployment. Our AI vendor contracts guide addresses information rights, changes and supplier responsibilities.

Must the assessment be sent to an authority?

A DPIA and a FRIA follow different authority procedures. Under GDPR Article 36, prior consultation is required where high residual risk remains that cannot be sufficiently mitigated. There is no general GDPR obligation to submit every DPIA for approval.

Article 27(3) provides for notification of FRIA results to the market surveillance authority using the relevant template, subject to the Article 46(1) exception. That notification is not the GDPR prior-consultation procedure and should not be described as automatic permission to deploy. Confirm the competent authority and operational submission arrangements for the specific deployment. GDPR Article 36; AI Act Article 27(3).

A practical assessment file before deployment

  1. Define the use case. Identify the system, version, intended purpose, users, affected people and decisions it informs.
  2. Map roles separately. Record GDPR controller/processor roles and the relevant AI Act roles.
  3. Screen the legal route. Check prohibited practices, AI classification, DPIA triggers and Article 27 deployer coverage.
  4. Record timing. Distinguish existing GDPR duties from future AI Act requirements and applicable transition provisions.
  5. Collect evidence. Obtain data-flow information, supplier instructions, meaningful performance limitations, oversight arrangements and relevant testing.
  6. Assess harms and safeguards. Describe how the actual deployment may affect people and how controls reduce those risks.
  7. Map shared sections. Make each DPIA and FRIA requirement traceable, retaining any necessary separate analysis.
  8. Resolve escalation. Identify prior consultation, notification, unresolved risks and conditions preventing launch.
  9. Assign review triggers. Consider changes in purpose, model, data, affected groups or decision authority, and evidence from incidents or complaints.

How Atrium Romanian Lawyers Assisted an International Manufacturing Group

Anonymised client matter. The description below omits identifying information and focuses on the legal work performed.

Questions examined

  • Whether the candidate-data processing required a DPIA;
  • Whether the use of the system could trigger a FRIA under the AI Act;
  • What human-oversight and documentation measures were needed before implementation.

Legal analysis

Our review of the recruitment process identified extensive automated evaluations of candidates with a significant impact on access to employment opportunities. The company therefore decided to complete a DPIA before implementation.

We also carried out a separate analysis of the system’s classification under the AI Act, including the organisation’s status and the obligations applicable to the deployer. The review confirmed that the DPIA and any FRIA analysis had to be treated separately because their legal triggers differ.

Measures adopted

  • Documentation of the decision logic and system limitations;
  • Mandatory stages of human verification;
  • Internal procedures for challenging results and handling complaints;
  • Updated contractual documentation and AI-governance workflows.

Practical result

Following the project, the company was able to continue the implementation on the basis of stronger documentation concerning compliance and risk management.

A focused consultation can clarify which assessment route applies and what your team needs before making deployment commitments.

Frequently asked questions

Does every AI project need both a DPIA and a FRIA?

No. Screen personal-data processing under GDPR Article 35 and, separately, the system and deployer under AI Act Article 27. One assessment may be mandatory while the other is not. A negative screening result does not remove other applicable legal obligations.

Does human review remove the need for a DPIA?

Not automatically. Article 35 has its own risk test, and its automated-evaluation category is not confined to solely automated decisions. Genuine human oversight can affect risks and safeguards, but a human signature does not by itself settle DPIA applicability.

Does a private employer need a statutory FRIA for recruitment AI?

Not solely because it is an employer using high-risk recruitment AI. Article 27 covers specified deployers and uses. Check whether the organisation is a public-law body or private public-service provider, while independently assessing its GDPR and other AI Act obligations.

Can we rely on the supplier’s impact assessment?

Supplier evidence can support the work, and Article 27 permits reliance on existing assessments in similar cases. The organisation still needs to check whether the document addresses its actual deployment, affected groups, safeguards and applicable obligations. A generic assurance is insufficient evidence of that fit.

Can we wait until the FRIA application date to conduct a DPIA?

No, if GDPR already requires a DPIA for the proposed processing. The DPIA must precede that processing. The AI Act timetable and transition provisions must be analysed separately and do not suspend GDPR requirements.

Does completing an assessment authorise the project?

No. An assessment documents analysis and safeguards; it does not supply a missing legal basis, legalise prohibited AI or override unresolved legal restrictions. Complete any required consultation or notification procedure and resolve conditions that prevent lawful deployment.

Data Processing Agreement in Romania for GDPR controller and processor compliance

Data Processing Agreement Romania: GDPR Guide

A data processing agreement is required when a company engages another party to process personal data on its documented instructions. The label used in the commercial contract is not decisive: the parties must first classify their actual GDPR roles, then align the agreement with the service, security model, subprocessor chain and any international transfers.

In brief

For a Romanian or foreign business subject to the General Data Protection Regulation (GDPR), an Article 28 data processing agreement (DPA) is not a generic confidentiality annex. It must describe the processing and impose specific duties on the processor. A processor DPA is not required where the supplier acts as an independent controller, although controller-to-controller data-sharing provisions may still be appropriate; joint controllers need an Article 26 arrangement. If personal data is transferred outside the European Economic Area, the DPA alone does not provide a Chapter V transfer mechanism, even where transfer clauses are integrated into the same contractual document.

When is a data processing agreement required?

The general rule is that a written DPA is required when one party processes personal data on behalf of another party. Article 28 GDPR requires the controller to appoint only processors that provide sufficient guarantees and to govern the processing through a binding contract or other legal act, in writing, including electronically.

The practical starting point is the service, not the supplier’s preferred contract label. Payroll providers, cloud hosting companies, customer-support platforms, outsourced IT administrators, email delivery services and some marketing vendors commonly act as processors because they handle data for purposes defined by their customer. The same vendor may nevertheless be a controller for separate activities, such as its own billing, fraud prevention or legally required records.

Before signing, map each processing activity and ask who decides why the data is processed and who makes the key decisions regarding the means of processing. Certain non-essential practical means may be left to the processor. The European Data Protection Board’s Guidelines 07/2020 on controller and processor concepts are the relevant official interpretative reference.

Role map

Choose the relationship that best describes the processing

Select a card to see the usual document and the main classification test.

Controller and processor: use an Article 28 DPA.

The controller determines the purposes and makes the key decisions regarding the means of processing; the processor handles data on documented instructions and may decide certain non-essential practical means. Describe the service-specific processing and all mandatory Article 28 controls.

RelationshipMain testUsual documentFrequent mistake
Controller–processorThe supplier processes personal data for the customer’s purposes and on its documented instructions.Article 28 DPA, usually attached to the services agreement.Using a one-page confidentiality clause with no processing details or security annex.
Independent controllersEach party determines its own purposes and makes the key decisions regarding the means of its processing.Controller-to-controller data-sharing terms, transparency allocation and lawful-disclosure provisions.Forcing a processor DPA onto a professional adviser or platform acting for its own lawful purposes.
Joint controllersThe parties jointly determine the purposes and key decisions regarding the means of processing.Transparent Article 26 arrangement allocating responsibilities.Calling one party a processor even though both designed the relevant processing.
Mixed rolesThe role changes by processing activity.Activity-specific clauses covering each role.Applying one label to the entire commercial relationship.

What must an Article 28 DPA contain?

A compliant DPA must identify the processing and include every mandatory control listed in Article 28(3) GDPR. It should specify the subject matter and duration, nature and purpose, types of personal data, categories of data subjects, and the controller’s rights and obligations. It must then translate the statutory requirements into workable contractual duties.

Clause control room

Test the operational core of the DPA

Each control needs both contractual wording and evidence that it can work in practice.

Instructions must be documented and specific enough to control use.

Define permitted purposes, operations, users and transfer instructions. The processor must alert the controller if it considers an instruction unlawful.

Mandatory controlWhat the DPA should settleUseful evidence or annex
Documented instructionsPurposes, permitted operations, access, disclosure, locations and transfers; process for changing instructions.Processing schedule, service description, authorised-user model and change log.
ConfidentialityAuthorised personnel must be bound by contractual or statutory confidentiality.Role-based access, confidentiality undertakings and training records.
Article 32 securityMeasures proportionate to the processing risk, not merely “industry standard security”.Technical and organisational measures annex, certifications, test summaries and remediation process.
SubprocessorsPrior specific or general written authorisation, change notice, objection process and equivalent downstream duties.Current subprocessor list, service and country details, due-diligence records and flow-down terms.
AssistanceSupport for data-subject requests and controller obligations under Articles 32–36.Request workflow, responsibility matrix, response contacts and DPIA support process.
End of serviceController’s choice between return and deletion, copy deletion and lawful-retention exceptions.Export format, deletion timetable, backup treatment and deletion certificate.
Information and auditsEvidence needed to demonstrate compliance and a workable audit or inspection mechanism.Audit reports, questionnaires, certification scope, remediation plan and escalation rights.

The European Commission has adopted optional standard contractual clauses for controllers and processors under Article 28. The parties may adopt the 2021/915 standard clauses or negotiate their own Article 28 terms. Where the standard clauses are used, additional clauses should not directly or indirectly contradict them or prejudice the fundamental rights and freedoms of data subjects.

Why a generic security clause is not enough

The security schedule should describe controls that match the actual data, systems and risks. Article 32 GDPR requires appropriate technical and organisational measures, taking account of the state of the art, implementation cost, processing context and risks to individuals. Depending on the service, relevant controls may include encryption, access management, logging, vulnerability management, backups, resilience, testing, staff controls and incident response.

A clause stating only that the supplier will apply “appropriate” or “industry standard” security gives the controller little evidence and may leave important assumptions unresolved. The annex should also distinguish controls included in the standard service from optional configurations that the customer must activate.

How should subprocessors be managed?

A processor cannot appoint a subprocessor without the controller’s prior specific or general written authorisation. Under a general authorisation, the processor must notify intended additions or replacements in time for the controller to object. The processor must impose equivalent data-protection obligations downstream and remains fully liable to the controller for the subprocessor’s performance of those obligations.

The contract should state what information accompanies a change notice, how long the objection window lasts, what constitutes a reasonable objection and what happens if the parties cannot resolve it. A nominal right to object is of limited value if the controller receives only a company name, with no service description, processing location or transfer information.

The European Data Protection Board’s Opinion 22/2024 on processors and subprocessors is an important due-diligence reference. Controllers should be able to identify the entire processing chain, including relevant subprocessors and, where appropriate, further sub-processing layers, and obtain enough information to assess whether sufficient guarantees exist.

Does a DPA cover international data transfers?

No. A DPA regulates processing on behalf of a controller, but the DPA alone does not provide a Chapter V transfer mechanism. If data moves to, or is remotely accessed from, a country outside the European Economic Area, the parties must separately establish whether an adequacy decision or another valid safeguard applies. The relevant Article 28 clauses and transfer safeguards may nevertheless be integrated into a single contractual document.

This distinction is easy to miss because two different EU instruments are commonly called “SCCs”. Commission Decision (EU) 2021/915 concerns standard clauses for the Article 28 controller–processor relationship. Commission Decision (EU) 2021/914 contains standard contractual clauses for transfers to third countries. Where the transfer clauses apply, the parties must select the correct module, complete the annexes and assess the destination-country context and any necessary supplementary measures.

How quickly must a processor report a data breach?

The GDPR requires the processor to notify the controller without undue delay after becoming aware of a personal data breach. The familiar 72-hour period applies to the controller’s notification to the competent supervisory authority where the legal conditions are met; it is not the processor’s default reporting deadline.

The DPA should therefore set a fast contractual notification route that gives the controller time to investigate and decide whether regulatory or data-subject communications are required. It should define the incident contact, initial information, phased updates, evidence preservation, cooperation, remediation and post-incident report. A fixed period can be useful, but it should not dilute the statutory “without undue delay” standard.

For the controller’s incident process, see our practical GDPR data breach guide for Romania.

What should the controller check before signing?

The controller should test both the contract and the processor’s ability to perform it. Article 28 requires sufficient guarantees, so signature alone is not the end of the due-diligence exercise.

  1. Confirm the role for each activity. Separate processor functions from any independent or joint-controller processing.
  2. Map the data and people involved. Record data categories, data subjects, purposes, systems, locations, retention and sensitive-data elements.
  3. Review the mandatory clauses. Check every Article 28 requirement and remove conflicts with the main services agreement.
  4. Test the security annex. Align the written controls with the service configuration and the risk level.
  5. Identify all relevant subprocessors. Verify functions, locations, change procedure, downstream obligations and transfer safeguards.
  6. Plan incidents and rights requests. Agree contacts, response steps, information fields and internal escalation.
  7. Set the exit route. Define return, export, deletion, backups, certification and any lawful retention.
  8. Retain accountability evidence. Keep the assessment, negotiated terms, approvals, notices and review dates.

Illustrative vendor scenarios

These examples are simplified and do not replace a factual role analysis.

SaaS provider hosting a customer database

The Romanian customer decides why client records are stored and how staff use them. The SaaS provider hosts and supports the database on the customer’s instructions. An Article 28 DPA is normally required, together with a security schedule and a review of hosting and support subprocessors.

Professional adviser receiving matter information

A lawyer, auditor or other regulated adviser may independently determine certain purposes and make key decisions regarding the means of processing because of professional duties and legal obligations. It may be incorrect to classify every such activity as processor work. The engagement terms should describe the actual roles and disclosures.

Cloud subprocessor with access outside the EEA

The immediate processor uses a support provider in a third country. The controller–processor DPA remains necessary, but it is not sufficient. The parties must also examine the relevant transfer mechanism, complete the required documentation and assess whether supplementary safeguards are needed.

How should the DPA interact with the main services agreement?

The documents should work as one contract set. The services agreement, DPA, security schedule, service levels and subprocessor information should use consistent definitions, liability rules, notice mechanisms, termination rights and order-of-precedence clauses.

Commercial limits on liability require particular attention. A DPA cannot remove statutory obligations or the rights of data subjects, while the allocation of contractual risk between the parties depends on the negotiated agreement and applicable law. Audit rights also need balance: the controller requires meaningful evidence, but the process should protect the processor’s security, confidentiality and other customers.

For a wider commercial review, use our contract review checklist for Romania. Technology businesses may also find our IT and SaaS contract services relevant.

Frequently asked questions

Is a DPA required with every service provider?

No. It is required where the provider processes personal data on behalf of the controller. An independent controller relationship may require data-sharing terms instead, while joint controllers need an Article 26 arrangement. The correct classification depends on the actual purposes, decision-making and degree of instruction for each processing activity.

Can the DPA be an annex to the services agreement?

Yes. The GDPR requires a binding written contract or other legal act but does not require a separate standalone document. An annex is common and can be efficient, provided the main agreement and DPA are consistent and the processing description, security measures and subprocessor terms are complete.

Does an Article 28 DPA replace international transfer SCCs?

No. The Article 28 relationship and the Chapter V transfer basis are separate legal questions. Commission Decision 2021/915 contains controller–processor clauses, while Decision 2021/914 contains transfer clauses for third-country transfers. Depending on the data flow, both sets of requirements may be relevant.

Must the controller approve every subprocessor?

The processor needs prior specific or general written authorisation. Under general authorisation, the controller must be informed of intended additions or replacements and given an opportunity to object. The DPA should make that process meaningful by defining the notice content, timing, objection grounds and consequences.

Must a processor report a breach within 72 hours?

The processor’s statutory duty is to notify the controller without undue delay after becoming aware of a personal data breach. The 72-hour rule concerns the controller’s notification to the supervisory authority where notification is legally required. The DPA should set an incident process that allows the controller to meet its own deadline.

Can a processor use personal data for its own product improvement?

Only if the relevant role, purpose and legal basis support that use. A processor cannot simply expand its instructions into an independent purpose. If the provider determines its own purpose and makes the key decisions regarding the means of a separate activity, it may act as a controller for that activity and must satisfy the corresponding GDPR duties.

Review the DPA against the real data flow

A targeted legal review can classify the parties’ roles, check the mandatory Article 28 terms, identify transfer issues and align the DPA with the services agreement, security evidence and subprocessor chain.

Discuss a data processing agreement

Disclaimer: This article provides general information and does not constitute legal advice. It reflects the law and official guidance available as of the date of publication. The correct analysis depends on the actual processing activities, contractual roles, data flows, security measures and jurisdictions involved.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Online company registration in Romania represented by incorporation documents, an international globe and a modern Bucharest office building

Online Company Registration in Romania: Electronic Signature and ONRC Filing

Online company registration in Romania is available for many founders, including non-residents. The filing can be submitted electronically or through an authorised representative, but a valid electronic signature is only one part of the route. The documents, signing authority, identity checks and ONRC platform requirements must also align.

Documents required for online company registration in Romania including identification, electronic signature, power of attorney and ONRC filing
Remote incorporation depends on coordinating the founder’s identification, electronic signature, power of attorney, company documents and ONRC filing.

This guide explains the online filing route for foreign individuals, overseas companies and Romanian founders. It focuses on the relationship between electronic signatures, filing authority, documents and the National Trade Register Office platform. For the broader choice of entity, capital and corporate structure, see our company formation in Romania guide.

Can you register a Romanian company online?

Often yes, but online registration is not the same as an automatic paper-free process. The ONRC application can be filed electronically, while foreign-document formalities, identity verification, representation and bank onboarding may follow separate rules.

Romania’s National Trade Register Office online portal offers services including company-name reservation and incorporation. Law No. 265/2022 also regulates online company formation and electronic communication with the Trade Register.

Under Article 105 of Law No. 265/2022, the registrar may exceptionally request physical presence if there is a suspicion of identity falsification. The same provision states that physical presence is not required when the incorporation application and supporting documents, including the articles of association, were prepared by a public notary or lawyer. If presence is exceptionally requested during online formation, the remaining stages may still be completed electronically.

StageCan it be handled remotely?Important qualification
Name reservationNormally yesThe proposed name must satisfy Trade Register availability and naming rules.
Preparation of incorporation documentsYesThe documents must reflect the chosen structure, activities, management and registered office.
Signing and representationOften yesThe route may use a qualified electronic signature or a compliant power of attorney, depending on the document and filing method.
Trade Register filingYesElectronic filing must meet the portal’s technical and signature requirements.
Bank account onboardingBank-dependentBanks apply their own know-your-customer, beneficial-owner and risk procedures.
Sector permitsDepends on the activityRegulated activities may require separate authorisations before or after incorporation.

What are the steps for remote company formation in Romania?

The legal sequence is straightforward, but the filing route should be chosen before documents are signed. Select each step below to see its practical purpose.

Online filing roadmap
From signature to registration

Select a step to review what must be resolved before the next stage.

Confirm the structure

Choose the company type, shareholders, directors, activities, decision rules and capital before preparing the filing documents.

  1. Confirm the company structure. Decide the entity type, ownership, administrators, business activities and signing authority. An SRL is common, but it should not be selected automatically when investment, governance or regulated activities require another structure. See our 2026 guide to Romanian limited liability companies.
  2. Reserve the company name. Submit alternatives that comply with the Trade Register rules. Our separate guide explains how to register a company name in Romania.
  3. Establish the registered office. Every Romanian company needs a valid registered office and supporting title to use the address. For the documents commonly used in an incorporation file, see our foreign-founder document checklist.
  4. Prepare, formalise and translate the documents. Coordinate the articles of association, identity or corporate records, declarations, beneficial-owner information, office evidence and powers of attorney. Foreign public documents may require apostille, legalisation or an applicable exemption, depending on the issuing state, bilateral treaties, EU legislation and the nature of the document, followed by an authorised Romanian translation where required.
  5. Sign and file through the selected route. If the electronic filing route is used, the signature and submission must satisfy the applicable ONRC technical and procedural requirements. A properly authorised representative may provide an alternative route, provided that the authority granted complies with the requirements applicable to the filing.
  6. Complete post-registration onboarding. After incorporation, organise accounting, tax registrations or options, bank onboarding, employment setup and any permits required for the actual activity.

Which documents do foreign founders usually need?

The exact file depends on whether the shareholder is an individual or a foreign company, the founder’s country, the administrators, the registered office and the intended activities. Do not sign foreign documents until their Romanian formality and translation route has been checked.

Founder or issueTypical documents or informationRemote-formation check
Foreign individual shareholderValid identity document, personal details, declarations and specimen/signing information as applicableConfirm legibility, validity, signature method and whether additional identification evidence is required.
Foreign corporate shareholderRecent company extract, constitutional documents, representation evidence and corporate approvalConfirm issue date, competent signatory, apostille or legalisation and Romanian translation.
AdministratorIdentity data, acceptance and statutory declarationsCheck eligibility, tax-identification implications and the signing route.
Company constitutionArticles of association specifying ownership, management, activities, capital and governanceAlign every translated or signed version. See our articles of incorporation guide.
Registered officeDocument proving the right to use the Romanian address and any required supporting recordsConfirm permitted use, term and consistency with the filing.
Beneficial ownerBeneficial-owner information and any declaration required under the legislation applicable at the time of filingTrace the ownership chain and identify the natural persons who ultimately own or control the company.
RepresentativePower of attorney or lawyer’s authority, depending on the routeMatch the scope, form and authentication requirements to the acts the representative will perform.

Do founders need a qualified electronic signature?

A qualified electronic signature may support electronic filing, but its legal validity does not, by itself, make it sufficient for every ONRC submission. A founder may instead use a properly authorised representative, provided that the power of attorney complies with the form requirements applicable to the specific filing and the jurisdiction where it is executed.

The signature route should be tested before execution. Romania’s framework includes Law No. 214/2024 on electronic signatures and trust services, while the Trade Register procedure is governed specifically by Law No. 265/2022 and the portal’s filing requirements. The availability of electronic filing depends not only on the legal validity of the electronic signature but also on the technical and procedural requirements imposed by the National Trade Register Office.

Remote identity checks may also involve regulated identification services. The Romanian Authority for Digitalisation publishes information on remote identification by video means, but the availability and acceptance of a particular method still depend on the institution and transaction.

Is a Romanian notary always required?

No. Notarial involvement is not a universal requirement for every remote Romanian incorporation. It may nevertheless be necessary or useful for a particular power of attorney, foreign public document, contribution, identity issue or transaction-specific formality.

The correct answer depends on the document, the country where it is issued and the chosen filing route. For foreign founders, the practical question is usually not “Do I need a notary for the company?” but “Which document, if any, needs notarisation, apostille or legalisation, and in which country?”

How long does remote incorporation take?

Romanian law provides a short decision period for a complete Trade Register application, but that is not a guaranteed end-to-end formation time. Document collection, foreign formalities, translations, corrections, registered-office arrangements and bank checks sit outside that narrow decision window.

Under Articles 105 and 107 of Law No. 265/2022, the registrar generally resolves complete applications on documents within one working day and, when the legal requirements are met, orders registration according to the statutory procedure. Procedural exceptions, requests for additional evidence or a need to remedy the file may affect this stage. The one-working-day period should not be advertised as the total time needed by a foreign founder.

If the file is incomplete or does not meet the legal requirements, Article 106 allows a remedy or completion period of up to 15 calendar days. The practical schedule should therefore separate:

  • preparation time for the corporate structure and registered office;
  • time for foreign documents, apostille or legalisation and translation;
  • the Trade Register review of a complete filing;
  • time needed to cure any filing defect; and
  • post-incorporation bank, accounting, tax and licensing steps.

Is the bank account part of the online incorporation?

No. Company registration and bank onboarding are separate processes. Incorporation by the Trade Register does not compel a bank to open an account remotely or remove its customer due-diligence requirements.

Each bank decides what identification, beneficial-owner, source-of-funds and business-model evidence it needs. Some institutions offer remote onboarding in eligible cases; others may request a video identification, additional documents or physical attendance. Founders should compare banking routes early, especially where the ownership chain is international or the activity carries heightened compliance risk. See our guide to opening a Romanian business bank account as a non-resident.

What most often delays a remote filing?

Common error 1

Signing before the route is confirmed. The founder signs documents that later require a different form, signature or authentication.

Common error 2

Using inconsistent identity or corporate data. Names, addresses, registration numbers or signatory capacities differ across extracts, translations and the articles of association.

Common error 3

Treating the bank as part of ONRC registration. The company is incorporated, but operations are delayed because bank onboarding was not planned separately.

Common error 4

Choosing activities without checking authorisations. A company may be registered while its actual regulated activity still requires a permit, approval or professional condition.

Remote formation checklist for a foreign founder

  1. Confirm the Romanian entity, ownership, administrators and business activities.
  2. Choose the online filing or legal-representation route before signing documents.
  3. Check each foreign document for issue date, apostille or legalisation and Romanian translation.
  4. Secure a compliant registered office and align the supporting document with the intended filing.
  5. Map the beneficial owners through the complete international ownership chain.
  6. Verify the signature and authority of every shareholder, administrator and representative.
  7. Submit one consistent, complete file through the National Trade Register Office route.
  8. Plan banking, accounting, tax and sector-specific compliance as separate workstreams.

The bottom line

Remote company formation in Romania is a workable route for many foreign founders, but it is not a single universal online form. The successful approach coordinates Romanian incorporation requirements with the founder’s home-country documents, a valid signing or representation route, registered-office evidence and separate post-registration onboarding.

Frequently asked questions

Can a foreigner open a company in Romania without travelling there?

Often yes. The filing can be completed electronically or through a properly authorised representative. The final route depends on the founder’s documents, their country of issue, the signing method, identity checks and the requirements of any bank or regulated authority involved after incorporation.

Does every foreign founder need a Romanian electronic signature?

No. A qualified electronic signature may support electronic filing, but acceptance also depends on the technical and procedural requirements imposed by the National Trade Register Office. Legal representation can provide another remote option, provided that the power of attorney satisfies the requirements applicable to the filing and place of execution.

Does a remote incorporation always require a notarised power of attorney?

No universal rule applies to every file. The required form depends on the representative’s acts, the document, the country of execution and applicable Romanian and international formalities. Some powers or foreign documents may require notarisation, apostille or legalisation; others may follow a different route.

Can the Romanian Trade Register ask a founder to appear in person?

Exceptionally, yes. Article 105 of Law No. 265/2022 permits a request for physical presence where there is a suspicion of identity falsification. The law also provides that presence is not required when the application and supporting documents, including the articles of association, were drawn up by a public notary or lawyer.

Is a Romanian bank account opened automatically after registration?

No. The Trade Register incorporates the company, while the chosen bank conducts its own onboarding and compliance review. Remote availability varies by bank and case, especially for non-resident founders, foreign corporate shareholders and complex beneficial-ownership structures.

How long does remote company formation in Romania take?

The registrar’s statutory decision period for a complete application is not the same as the total project time. Foreign-document formalities, translations, registered-office arrangements, corrections and bank onboarding can extend the schedule. A realistic estimate requires review of the specific founders and documents.

Planning to establish a Romanian company remotely?

Atrium Romanian Lawyers assists foreign individuals and international companies with structuring, document preparation, powers of attorney, Trade Register filings and coordinated post-incorporation steps.

Discuss your remote formation route

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.

D&O insurance in Romania illustrated by falling dominoes stopped by a green protective barrier in a boardroom

Director and Officer Insurance in Romania: Does D&O Insurance Cover Management Liability?

Directors and officers insurance in Romania can protect managers and companies against certain defence costs and civil claims arising from alleged management errors. It does not cancel a director’s legal duties, guarantee payment of every claim or cover intentional misconduct simply because the allegation concerns a management decision.

D&O insurance claim process represented by corporate files connected through a structured green path
D&O coverage depends on how the insured person, claim, defence costs, exclusions and notification requirements are defined in the policy.

In brief: A D&O policy is a contractual risk-transfer tool, not immunity from Romanian director liability. Coverage usually depends on who is insured, the capacity in which the person acted, when the claim was made and notified, the policy territory, the applicable retention and the exclusions. Companies should review Side A, Side B and any entity cover separately, test insolvency and regulatory scenarios, and coordinate the policy with corporate indemnities, governance documents and the director’s actual role.

This guide is written for Romanian subsidiaries, foreign groups, founders, shareholders and board members assessing management-liability protection. It complements our detailed guide to Romanian company director liability, which explains when personal exposure may arise under company, insolvency and tax law.

What is D&O insurance and what does it protect?

D&O insurance is a liability policy designed to respond to covered claims alleging a wrongful act by an insured director or officer in that management capacity. Depending on the wording, it may fund defence costs and pay covered settlements, judgments or other insured loss. The policy may also reimburse the company where it lawfully indemnifies the individual.

The expression “wrongful act” is usually defined broadly in the policy, but the definition is only the entrance to the coverage analysis. The claim must also fall within the insured persons, insured capacity, policy period, territory and jurisdiction. It must not be removed by an exclusion, and all notification, consent and cooperation requirements must be met.

Coverage architecture
Who receives protection under Side A, Side B and Side C?

Select a coverage side to review its practical function.

Individual protection

Side A is intended to respond for an insured person when the company cannot or is not permitted to indemnify that person, subject to the policy terms.

Coverage sectionWho is protected?Practical question
Side AThe insured director or officer.Will the policy respond when the company cannot indemnify the individual, including because of insolvency or a legal restriction?
Side BThe company, after it indemnifies an insured person.Is the indemnity lawful, documented and within the policy definition of reimbursable loss?
Side CThe company itself for specified entity claims.Is entity coverage limited to securities claims or extended to other claims, and could it dilute the limit available to individuals?
ExtensionsDepends on the endorsement.Are investigation costs, extradition costs, crisis costs, employment-practices claims or retired-director protection actually included?

Is D&O insurance mandatory for Romanian directors?

There is no safe basis for saying that one identical D&O policy is compulsory for every Romanian company and every SRL administrator. The answer depends on the company form, appointment framework, applicable special regulation and corporate decisions.

Article 15312(4) of Romanian Companies Law no. 31/1990 applies within the governance regime of joint-stock companies (SA) and should not automatically be assumed to create a general insurance obligation for all SRL administrators. For a limited liability company, the articles of association, shareholders’ decision, mandate terms and any sector-specific legislation should be checked separately.

Romanian law refers to professional liability insurance, while modern D&O insurance is a market product developed by insurers. Although D&O insurance frequently serves this purpose in practice, the legal obligation and the insurance wording should not automatically be treated as identical concepts.

Even where insurance is required by the appointment or corporate framework, a policy bearing the label “D&O” does not automatically satisfy every requirement. The insured roles, limit, territory, duration, run-off protection and exclusions must fit the mandate and risk profile.

Practical distinction: a statutory or corporate requirement to maintain professional-liability insurance and the actual protection delivered by a particular D&O wording are separate questions. The appointment documents and the policy should be reviewed together.

Which Romanian director-liability claims may engage the policy?

A D&O policy may be relevant when a director faces a civil claim, investigation or other covered proceeding arising from alleged conduct in office. Whether it responds depends on the precise policy, not merely on the legal label attached to the dispute.

Potential claimRomanian legal contextCoverage question
Breach of mandate or company dutyArticles 72 and 73 connect administrators’ duties and liability to mandate rules and statutory obligations.Is the alleged act within insured capacity, and are defence costs and damages included?
Shareholder or company claimThe company may seek recovery for loss allegedly caused by breach of duty, or shareholders may initiate liability proceedings where permitted by law.Does an insured-versus-insured or major-shareholder exclusion apply?
Insolvency claimArticle 169 of Insolvency Law no. 85/2014 permits liability orders for specified conduct contributing to insolvency.Are insolvency-practitioner claims covered, and is there an insolvency or conduct exclusion?
Regulatory investigationA director may be required to respond to an authority in an official capacity.When does an “investigation” begin, and are interview or representation costs covered?
Tax-related exposureArticle 25 of the Fiscal Procedure Code contains specific circumstances in which administrators or other persons may incur joint fiscal liability, usually where bad faith is established.Are defence costs covered even if tax, penalties or the underlying liability are not?
Employment or whistleblowing claimManagers may be named in allegations concerning workplace decisions or retaliation.Is employment-practices liability included, excluded or subject to a separate sublimit?

How does a D&O claim move from allegation to payment?

The practical sequence begins before liability is established. Many policies are written on a claims-made or claims-made-and-notified basis. A demand, investigation notice, circumstance or written allegation may trigger immediate notification duties even if no court proceedings have started.

Claim flow
From first allegation to coverage decision

Select a step to see the control that protects coverage.

Detect the trigger

Identify whether a demand, investigation, formal notice or known circumstance falls within the policy’s definitions before treating it as ordinary correspondence.

  1. Preserve the notice. Keep the demand, authority letter, board papers and delivery evidence.
  2. Identify every potentially responsive policy. Check local and global programmes, prior-year policies and any run-off cover.
  3. Notify within the required form and period. Do not wait for a final claim value or court filing if the wording requires earlier notice.
  4. Obtain consent before material defence expenditure or settlement. Emergency-cost provisions should be checked where prior consent is impracticable.
  5. Separate insured and uninsured matters. Allocation may be needed between individuals and the company, covered and uncovered allegations, or several policies.
  6. Protect privilege and cooperation. Coordinate Romanian counsel, broker and insurer communications without disclosing privileged analysis unnecessarily.

What does D&O insurance usually not cover?

Exclusions differ materially between insurers and negotiated programmes. The most important distinction is between an allegation and a final conduct determination. Some policies advance defence costs while allegations are unresolved, then apply a dishonesty or personal-profit exclusion only after a final, non-appealable determination or admission. Other wording may be less protective.

Exclusion map
Where can expected protection disappear?

Select a category to review the main wording risk.

Fraud and personal benefit

Deliberate dishonesty, fraudulent conduct and unlawful personal profit are commonly excluded, but the required determination and severability wording are critical.

Exclusion or limitationWhy it mattersReview point
Dishonesty and deliberate conductThe most serious allegations may be the ones the policy ultimately excludes.Check whether exclusion requires a final adjudication and whether one person’s conduct is imputed to others.
Prior knowledge or circumstancesA matter known before inception may fall outside the new policy.Coordinate proposal disclosures, warranty statements and prior notices.
Insured-versus-insuredClaims by the company or another insured may be restricted.Check carve-backs for derivative claims, insolvency practitioners, whistleblowers and employment claims.
Fines, penalties and taxesSome amounts may be excluded from coverage or may be regarded as non-insurable under applicable mandatory law.Separate defence costs from the underlying payment and verify Romanian mandatory law.
Bodily injury and property damageThese risks normally belong under other liability policies.Review defence-cost or management-claim carve-backs where relevant.
Sanctions and territorial limitsCross-border groups may face claims or restrictions outside the expected jurisdiction.Map subsidiaries, directors’ residences, business territories and local-admitted requirements.

Does D&O insurance cover insolvency, tax liability or criminal proceedings?

Not automatically. These are precisely the scenarios where the difference between defence-cost protection and payment of the underlying liability becomes important.

Under Article 169 of Romanian Insolvency Law no. 85/2014, the court may order persons who contributed to insolvency through listed conduct to bear part or all of the debtor’s liabilities within the causally connected loss. A policy must be checked for insolvency-practitioner claims, conduct exclusions, prior-circumstance provisions and the point at which dishonesty is established.

Tax debts, administrative fines, criminal fines, confiscation and amounts representing unlawful gain may be excluded from coverage or may be regarded as non-insurable under applicable mandatory law. Nevertheless, some policies may cover defence costs for a covered person during an investigation or proceeding until an exclusion is established. The precise wording and Romanian public-policy rules control the answer.

A policy cannot prevent an investigation, prosecution, disqualification, regulatory order or the consequences of a final judgment. Insurance is financial protection within contractual and legal boundaries, not a transfer of public-law responsibility.

What should a Romanian company check before buying or renewing D&O cover?

The best review starts with the company’s actual management structure and claim scenarios, not with the premium alone. A low limit, broad entity cover or weak notification clause may leave directors exposed even where the policy looks extensive on a summary page.

Renewal control
D&O policy review checklist

Select a control area before accepting the wording.

People and entities

Match the definition of insured person to registered administrators, delegated directors, supervisory members, de facto managers and relevant employees.

Review itemQuestions to askEvidence
Insured populationAre current, former and future managers covered? Are de facto or shadow roles addressed?Trade Register extract, group chart, delegations and job functions.
Limit and erosionDo defence costs reduce the aggregate limit? Is there dedicated or excess Side A protection?Policy schedule, tower structure and defence-cost clause.
RetentionWhich retention applies to Side A, Side B, entity claims and investigations?Schedule and each coverage clause.
NoticeWhat is a claim or circumstance, where must notice be sent and by when?Definitions, reporting clause and internal escalation process.
Run-offWhat happens after resignation, sale of the company or cancellation?Discovery-period, change-in-control and retired-director provisions.
Territory and jurisdictionDoes the programme follow Romanian directors into relevant foreign proceedings?Territorial clause, jurisdiction clause and local policy map.
Exclusions and severabilityCan one person’s knowledge or conduct prejudice innocent insureds?Conduct, application, imputation and severability wording.

How should D&O insurance fit with corporate governance?

Insurance works best when the governance system can show who decided, on what information, under which authority and with which conflict controls. The policy does not replace accurate minutes, authority matrices, financial reporting, compliance escalation or timely insolvency analysis.

Companies should align the policy with the articles of association, director appointment or mandate, shareholder resolutions, group indemnity arrangements and any transaction documents. A share purchase agreement may require run-off cover for outgoing directors, while a shareholder agreement may address nomination rights and insurance commitments. Neither document should promise protection that the policy does not deliver.

Change of control is particularly important. Many policies restrict cover for wrongful acts occurring after an acquisition or other control event. Transaction planning should therefore address tail coverage, continuity dates, notice of known circumstances and the allocation of premium and claims responsibility.

Risk: the most damaging coverage failure is often procedural rather than substantive: a demand is treated as routine correspondence, the insurer is notified late, defence counsel is instructed without consent or a transaction changes control before run-off protection is arranged.

The bottom line

D&O insurance in Romania can be an important layer of financial protection, especially where directors manage material contracts, regulated activity, cross-border operations or financial distress. Its value depends on the wording and the company’s ability to recognise and manage a claim.

The practical review should connect four documents: the legal mandate, the corporate indemnity, the D&O policy and the internal claims protocol. If they use different definitions of director, authority, claim or covered loss, the gap may emerge only when protection is needed.

Frequently asked questions

Does D&O insurance eliminate a Romanian director’s personal liability?

No. It may fund defence costs and certain covered loss, but it does not remove the underlying legal duties or prevent a court, tax authority, regulator or insolvency practitioner from pursuing the director. Coverage remains subject to the policy terms, exclusions and applicable mandatory law.

Is D&O insurance mandatory for every Romanian SRL administrator?

No general conclusion should be drawn for every SRL. Article 15312(4) of Companies Law no. 31/1990 applies within the governance regime of joint-stock companies (SA) and should not automatically be assumed to create a general insurance obligation for all SRL administrators. Romanian law refers to professional liability insurance, which should not automatically be treated as identical to a modern D&O policy. For an SRL, the articles of association, shareholder decisions, mandate terms and any sector-specific legislation must be reviewed separately.

Does a D&O policy cover fraud or intentional misconduct?

Policies commonly exclude fraud, deliberate dishonesty and unlawful personal benefit. The important drafting questions are when the exclusion applies, whether a final adjudication is required and whether one insured person’s conduct or knowledge can be attributed to innocent insureds.

Can D&O insurance cover an insolvency claim against a director?

Potentially, but not automatically. The policy should be checked for insolvency-practitioner claims, conduct exclusions, prior circumstances, defence-cost treatment and the insurability of the requested amounts. Liability under Article 169 and insurance coverage are separate legal analyses.

What happens to D&O cover after a director resigns?

Resignation does not erase claims relating to earlier conduct. Coverage depends on the claims-made wording, continuity provisions and any discovery or run-off period. The director and company should coordinate resignation, handover, notice of known circumstances and continued access to policy information.

Are defence costs paid in addition to the policy limit?

Not necessarily. Many policies include defence costs within the aggregate limit, so legal fees reduce the amount remaining for settlement or judgment. The schedule, defence clause, sublimits and any dedicated Side A layer should be checked before relying on the headline limit.

Reviewing D&O cover for a Romanian company?

We can review the Romanian-law liability framework, corporate indemnities, appointment documents and proposed policy wording so that the insurance programme reflects the company’s actual governance and risk profile.

Book a Corporate Consultation

Disclaimer: This article provides general legal and insurance information and does not constitute legal, tax, insolvency, insurance-brokerage or coverage advice. Coverage depends on the policy wording, facts, applicable law and insurer’s assessment.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.

Bucharest business district illustrating a share purchase agreement in Romania

Share Purchase Agreement in Romania: Due Diligence, Warranties and Closing Risks

A share purchase agreement in Romania should do more than record the number of shares and the price. It must connect the buyer’s due diligence findings with the conditions for closing, the seller’s warranties, specific indemnities, price mechanics and the corporate and regulatory steps needed to transfer control safely.

In brief: In a Romanian share deal, the buyer acquires the company with its assets, contracts, employees, licences, debts and historical exposure. The SPA therefore allocates risk between buyer and seller. Due diligence identifies the issues; the contract decides whether they must be corrected before closing, reflected in the price, disclosed against warranties, covered by an indemnity or accepted by the buyer. Romanian corporate approvals, ANAF formalities, merger control and investment screening must be tested early because they can change the signing and closing timetable.

This guide is written for foreign investors, international groups, founders and business owners negotiating the acquisition or sale of a Romanian company. It focuses on private acquisitions of shares or social parts, particularly Romanian limited liability companies (SRLs). Listed-company rules, regulated-sector acquisitions, privatisations and public takeovers require additional analysis.

The article complements our procedural guide to changing shareholders in a Romanian company. That guide covers the Trade Register implementation. This one explains how the commercial acquisition should be investigated, negotiated and protected contractually.

What does a share purchase agreement do in Romania?

A share purchase agreement, commonly called an SPA, is the principal contract under which the seller agrees to transfer and the buyer agrees to acquire shares or social parts in a Romanian company. It identifies the securities, price, conditions, closing process and allocation of risk between the parties.

The agreement operates within Romanian contract law and the mandatory rules applicable to the target’s corporate form. For an SRL, the transfer mechanics must be aligned with Articles 202 and 203 of Company Law no. 31/1990 and the applicable registration formalities before the National Trade Register Office (ONRC).

Deal structure
What does the buyer actually acquire?

Select a route to see how the risk profile changes.

Share deal

The buyer acquires the target entity itself. Contracts and assets generally remain with that entity, but so do its historical liabilities and compliance exposure.

Decision pointShare dealAsset deal
What transfersOwnership of the target company.Identified assets, contracts, liabilities or business components.
Historic liabilitiesRemain inside the acquired company and therefore affect the buyer economically.Generally remain with the seller unless assumed by contract or transferred by law.
Contracts and permitsUsually remain with the same legal entity, subject to change-of-control clauses and regulatory rules.May require individual assignment, consent, novation or reissuance.
EmployeesRemain employed by the target.A business transfer may trigger employee-transfer rules and information or consultation duties.
Core documentShare purchase agreement.Business or asset transfer agreement plus asset-specific instruments.

Why must legal due diligence come before the SPA is finalised?

Due diligence should identify the matters that can change the decision to buy, the valuation, the deal timetable or the contractual protection. A report that merely lists documents does not complete the task. Each material finding should be converted into a transaction response.

Share purchase agreement Romania due diligence represented by a green maze with a clear route
Legal due diligence helps the buyer identify risks and determine the appropriate route to a protected transaction. AI-generated illustration.

The scope normally covers corporate title and governance, financing and security, material contracts, real estate, employment, tax, disputes, permits, regulatory compliance, intellectual property, IT, data protection, environmental matters and beneficial ownership. Sector, size and business model determine the emphasis.

Due diligence map
Convert each finding into a deal response

Select a finding to see the appropriate contractual response.

Remediation

Require the seller or target to correct a curable defect before closing and deliver objective evidence that the correction is complete.

WorkstreamKey questionsPossible SPA response
Corporate and titleDoes the seller own the shares? Do the articles of association create pre-emption rights, and are there pledges, options, capital defects or approval restrictions?Title warranty, release condition, shareholder waiver, completion deliverable.
Material contractsDo customers, lenders or suppliers have termination, consent or change-of-control rights?Consent condition, covenant, retention or price adjustment.
EmploymentAre remuneration, dismissals, contractors, collective arrangements and key-person dependencies compliant?Remediation, employment warranty, specific indemnity, retention plan.
TaxAre filings complete? Are there audits, arrears, related-party risks or unsupported tax treatments?Tax covenant, tax warranty, escrow, special indemnity.
IP, technology and dataDoes the target own or validly license critical IP? Are cybersecurity and GDPR controls adequate?Assignment, licence cure, warranty, remediation plan, indemnity.
Disputes and regulationAre there claims, investigations, licences, sanctions, environmental or sector-specific risks?Regulatory condition, conduct covenant, indemnity or exclusion from the deal.

Which clauses matter most in a Romanian share purchase agreement?

The SPA should describe the transaction as one coherent mechanism. Definitions, price, conditions, warranties, disclosure, indemnities, limitations, covenants and closing deliverables must work together. Imported English-law wording should not be used without checking how it operates under the chosen governing law and Romanian mandatory rules.

Clause navigator
How does each protection work?

Select a clause family to see its transaction function.

Warranties

Contractual statements about the target, shares and business. Their value depends on scope, disclosure, knowledge qualifiers, repetition, claim rules and available recovery.

ProtectionPrincipal functionDrafting question
WarrantyAllocates risk if a contractual statement about the target or business is inaccurate.What is warranted, when is it true, and how do disclosure and seller knowledge qualify it?
Specific indemnityAllocates a defined known or identified exposure.What event triggers payment, which losses are covered and do general limitations apply?
Condition precedentPrevents closing until a necessary event, consent or approval occurs.Who controls satisfaction, what evidence is required, and when may either party terminate?
Pre-closing covenantControls how the target operates between signing and closing.Which actions need buyer consent without giving the buyer unlawful premature control?
Limitation regimeSets time limits, thresholds, caps, exclusions and claim procedure.Which claims are carved out, and does the recovery structure match the seller’s credit risk?

How should the purchase price be structured?

The price clause should explain both the headline value and the route from that value to the amount paid. A fixed price is not necessarily simple if debt, cash, working capital, leakage, earn-outs, holdbacks or currency conversion remain unresolved.

MechanismHow it worksMain negotiation risk
Locked-boxPrice is based on historic accounts at an agreed date, protected by a no-leakage covenant.Reliability of the accounts, leakage definition and permitted payments.
Completion accountsPrice adjusts after closing by reference to closing debt, cash, working capital or other metrics.Accounting policies, hierarchy of rules, timetable and expert determination.
Earn-outPart of the consideration depends on future performance or milestones.Control of the business, metric manipulation, extraordinary items and information rights.
Escrow or holdbackPart of the price is retained or deposited to support identified obligations or claims.Release triggers, duration, permitted deductions and insolvency protection.

A buyer should not treat escrow as a substitute for a coherent claims regime. The SPA should state whether recovery is limited to the escrow, whether the buyer may set off, how competing claims are handled and what happens when the escrow expires.

What is the difference between signing and closing?

Signing creates the contractual commitment. Closing completes the agreed transfer and payment once the applicable conditions are satisfied or waived. They may occur on the same day in a simple transaction, but regulatory approvals, third-party consents, financing or restructuring often require a split process.

Transaction roadmap
From exclusivity to effective control

Select a stage to review the principal legal control.

Term sheet

Align structure, valuation, exclusivity, confidentiality, process and principal conditions before the parties spend heavily on diligence and drafting.

Which Romanian approvals and filings can affect closing?

The regulatory analysis should begin before the SPA timetable is agreed. A condition drafted after signing cannot restore leverage or time already lost.

Corporate approval and ONRC registration

For an SRL transfer to an outside buyer, Article 202 of Company Law no. 31/1990 applies together with the target’s articles of association. The parties should verify statutory approval thresholds and any pre-emption or consent rights created by the articles of association, as well as pledges and other restrictions. The applicable ONRC registration formalities and the update of the company’s shareholder register should be built into the completion process.

ANAF notification and tax-debt safeguards

The practical scope of Article V of Law no. 239/2025, as amended by Government Emergency Ordinance no. 13/2026, should be verified in light of the transaction structure and current ONRC and ANAF practice. Although the regime was introduced in the context of transfers affecting company control, registration practice during 2026 has raised questions regarding its application to a broader range of SRL share transfers, as discussed in this analysis of emerging ONRC practice. The parties should confirm the current notification, tax-certificate, guarantee and registration requirements before signing and again before filing.

Merger control

An acquisition of sole or joint control may constitute an economic concentration. Under Competition Law no. 21/1996, the Romanian thresholds are generally met where the combined worldwide turnover of the undertakings concerned exceeds EUR 10 million and at least two undertakings concerned each achieved Romanian turnover exceeding EUR 4 million in the previous financial year. The EU Merger Regulation may apply instead where its thresholds are met. Closing before the required clearance can expose the parties to gun-jumping risk.

Investment screening

Romania’s investment-screening regime under Government Emergency Ordinance no. 46/2022 was substantially amended by Government Emergency Ordinance no. 17/2026. The general value threshold is now EUR 5 million, but a transaction below the threshold may still be examined if it may affect security, public order or EU projects or programmes. The rules can apply to EU and non-EU investors, and the filing contribution is EUR 5,000 where an authorisation application is required. Sector, investor, control, value and transaction structure must be screened early.

Sector approvals, lender consents, foreign-subsidy review or contractual change-of-control notices may also be relevant. The SPA should allocate responsibility, information, cooperation, remedies and the long-stop date for each approval.

What should happen at closing?

Closing should be a coordinated exchange, not a loose collection of signatures. The SPA should identify every deliverable, who provides it, its agreed form and whether all actions are deemed simultaneous.

  1. Confirm conditions. Record satisfaction or valid waiver of every closing condition.
  2. Approve the transfer. Deliver the required shareholder and corporate resolutions.
  3. Transfer the shares. Execute the required instruments and update the shareholder register.
  4. Pay the consideration. Follow the funds flow, escrow and debt repayment arrangements.
  5. Release security. Deliver releases of share pledges, guarantees or target security where agreed.
  6. Change governance. Coordinate resignations, appointments, powers of attorney and bank mandates.
  7. Deliver control items. Transfer corporate books, credentials, keys, seals and agreed records.
  8. Complete filings. Submit ONRC and ANAF documents, together with beneficial-owner filings where required under the applicable transparency rules, within the relevant timetable.

What limitations should apply to seller liability?

Seller limitations often include a de minimis threshold, basket, aggregate cap, time limits, mitigation, exclusion of double recovery and a formal claim procedure. Tax, title, authority, fraud and specific indemnities may have different limits. The commercial result depends on how these provisions interact, not on any one headline cap.

The buyer should also test recoverability. A contractual claim against a seller with no accessible assets may provide little protection. Escrow, holdback, bank security, parent guarantee or warranty and indemnity insurance may be considered depending on transaction size and risk.

A buyer’s pre-signing checklist

  1. Define the acquisition perimeter. Confirm percentage, target entities, securities and excluded items.
  2. Verify title and authority. Check ownership, encumbrances, approvals and signatory powers.
  3. Complete risk-focused due diligence. Prioritise issues that affect value, continuity or closing.
  4. Translate findings into protections. Allocate each material issue to remediation, price, condition, warranty, indemnity or withdrawal.
  5. Select the price mechanism. Define accounting rules, leakage, debt, cash, working capital and dispute resolution.
  6. Screen regulatory approvals. Review merger control, investment screening, sector approvals and third-party consents.
  7. Align signing and closing. Specify conditions, conduct rules, long-stop date, termination and closing deliverables.
  8. Test recovery. Check caps, time limits, exclusions, seller credit and available security.
  9. Plan filings and integration. Prepare ONRC and ANAF filings, beneficial-owner filings where required under the applicable transparency rules, governance steps and day-one actions.

The bottom line

A Romanian SPA should be the final expression of the buyer’s investigation and the parties’ negotiated risk allocation. The strongest agreement is not the longest. It is the one that identifies what is being bought, states how price is calculated, prevents closing before essential approvals, allocates known and unknown risks clearly and gives the parties an executable closing process.

Planning the acquisition or sale of a Romanian company?

A focused transaction review can cover deal structure, legal due diligence, SPA negotiation, regulatory screening, signing, closing and Romanian corporate implementation.

Book a Consultation

Frequently asked questions

Is a share purchase agreement mandatory in Romania?

A written transfer instrument is normally required to document and implement the transaction. In a negotiated acquisition, the SPA is the central agreement because it also records price mechanics, conditions, warranties, indemnities and closing. The required form and supporting corporate documents depend on the target’s legal form and transaction structure.

What is the difference between an SPA and a shareholders’ agreement?

The SPA governs the acquisition of shares and the allocation of transaction risk between buyer and seller. A shareholders’ agreement governs the continuing relationship among shareholders after the investment, including governance, reserved matters, funding, transfers, deadlock and exit. A minority investment may require both documents.

Can signing and closing occur on the same day?

Yes, where no unsatisfied conditions or approvals require a split process. If merger control, investment screening, financing, third-party consent or pre-closing remediation is required, signing normally precedes closing and the SPA must regulate the interim period and long-stop date.

Does due diligence remove the need for warranties?

No. Due diligence and warranties serve different functions. Diligence helps the buyer identify and evaluate risk. Warranties allocate contractual risk for inaccurate statements, subject to disclosure and limitations. Known issues may require remediation, a price adjustment or a specific indemnity rather than reliance on a general warranty.

When is Romanian investment-screening approval required?

The analysis depends on the investor, target activity, transaction structure, control or durable participation, sensitive sector and investment value. The general threshold is EUR 5 million after OUG no. 17/2026, but lower-value transactions may still be examined where security, public-order or relevant EU interests may be affected.

What happens after the SPA closes?

The parties must complete the agreed corporate, Trade Register and ANAF steps, as well as beneficial-owner filings where required under the applicable transparency rules. They must also release or retain escrow as applicable, implement governance changes and perform post-closing covenants. Price-adjustment, earn-out, indemnity and integration obligations may continue long after legal ownership changes.

Disclaimer: This article provides general information and does not constitute legal or tax advice. The correct structure, approvals, tax treatment and contractual protections depend on the parties, target, sector and facts of each transaction.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Commercial lease agreement in Romania with office key and floor plan

Commercial Lease Agreement Romania: 12 Key Clauses

Commercial real estate · Romania

A commercial lease is a long-term allocation of occupancy cost, operational responsibility and exit risk. Review the legal and practical controls before the premises, rent and fit-out commitments become difficult to unwind.

12 key clausesLandlord and tenant viewRomanian Civil Code focus
Decision lens Can the premises support the business, and can the contract control the downside? Use the interactive maps below to move from the commercial brief to signing, operation and exit.

A commercial lease agreement in Romania can commit a company to years of rent, service charges and restoration costs. The commercial decision therefore depends not only on the monthly headline rent, but also on whether the premises can lawfully support the tenant’s activity and whether the contract allocates operational risks clearly.

Commercial lease agreement in Romania with office key and floor plan
Commercial premises and lease documentation in Romania.

This guide is intended for landlords and companies leasing offices, retail units, warehouses and other business premises. It explains the principal clauses to check under the Romanian Civil Code and the related property, tax and authorisation framework. Residential leases and leases of public property follow additional rules and are outside this article’s main scope.

Is a written commercial lease mandatory in Romania?

Romanian law does not generally require a privately owned commercial lease to be notarised for validity. A signed written contract is nevertheless essential for evidence, enforceability, tax treatment and protection against third parties.

The lease relationship is governed principally by the Romanian Civil Code, especially the general rules on lease agreements. The parties have broad contractual freedom in a business-to-business transaction, but statutory rules apply where the lease is silent, and certain mandatory provisions of Romanian law may apply irrespective of contractual wording.

Under Article 1798 of the Civil Code, a lease concluded in authentic form, or a privately signed lease registered with the competent tax authority, may constitute an enforceable title for rent payment under the conditions stated by law. Tax registration affects enforceability, not the validity of the lease. It is not a universal requirement for the existence of every corporate lease, although the applicable tax and registration duties must still be checked for the particular landlord and transaction.

For leases requiring stronger protection against a future buyer or other third parties, the parties should assess land-book registration. The correct mechanism depends on the property, the lease term and the landlord’s registered title. A company entering a long-term lease should not assume that signature alone gives the same protection as registration.

Lease signing roadmap
From premises selection to rent commencement

Select a stage to see the legal control that should be completed before moving forward.

Define the commercial scope

Fix the exact premises, intended activity, timetable, fit-out assumptions, headline rent and critical conditions before detailed drafting begins.

What should be checked before the commercial lease is signed?

Verify the landlord, title, cadastral identity, permitted use, technical condition and authorisation route before the lease becomes unconditional.

The tenant should compare the land-book extract and cadastral plan with the space actually offered. The review should cover ownership, mortgages, litigation annotations, existing leases, access rights, parking, common areas and the landlord’s authority to grant the agreed use. These checks overlap with a focused real estate due diligence review in Romania.

The proposed activity must also be compatible with the building’s authorised use and applicable planning, fire-safety, sanitary, environmental and sector-specific requirements. A contractual statement that the tenant will obtain “all permits” does not solve a structural problem with the premises. The lease should distinguish permits relating to the building from those relating to the tenant’s own business.

For buildings or units covered by Law no. 372/2005, the owner must address the applicable energy-performance certificate obligations when leasing. The current framework covers offices, retail and other occupied commercial uses, subject to statutory exemptions. See the official energy performance legislation.

CheckTenant questionContract response
Title and authorityDoes the landlord own and control the exact premises?Attach current land-book and corporate authority evidence.
Permitted useCan the intended activity operate lawfully here?Make effectiveness or rent commencement conditional where appropriate.
Physical conditionWho bears existing defects and compliance works?Use a detailed handover report, photos and defect list.
Third-party rightsCould a lender, buyer or other tenant disrupt use?Consider lender consent, non-disturbance and land-book protection.
Utilities and capacityAre power, HVAC, access and loading capacity sufficient?Define technical specifications and remedies for shortfalls.

The 12 clauses that determine the real commercial risk

Commercial lease risk selector
Where can the lease create the greatest exposure?

Select a clause to see the negotiation priority.

Total occupancy cost

Model base rent, indexation, VAT, service charge, utilities, insurance contributions and one-off fit-out or reinstatement expenses.

1. Parties, authority and guarantees

Identify each party by its full legal name, registered office, registration number and tax code. Confirm the signatory’s authority. If a parent company, bank or shareholder gives security, specify whether it is a guarantee, autonomous demand guarantee, deposit or another instrument, together with its cap, duration and claim procedure.

2. Exact premises and permitted use

The lease should attach a plan and state the exclusive area, common-area allocation, parking and access rights. “Office use” or “commercial use” may be too vague. Describe the actual activity and deal with signage, customer access, deliveries, opening hours, hazardous materials and exclusivity if commercially relevant.

3. Term, commencement and long-stop date

Separate the signature date, handover date, fit-out access date, lease commencement and rent commencement. If delivery or permits are delayed, a long-stop date should allow the affected party to terminate. The Civil Code limits leases to a maximum statutory duration, so unusually long structures require specific review.

4. Rent, currency and indexation

State the currency, payment currency, exchange-rate source, due date and invoicing mechanics. An indexation clause should identify the index, reference period, first adjustment date, whether decreases apply and whether there is a cap or floor. Avoid combining indexation with discretionary “market rent” language unless the valuation procedure is clear.

5. VAT, withholding and invoicing

The lease of immovable property is generally VAT-exempt under the Romanian Fiscal Code, subject to important statutory exceptions and the landlord’s option to apply VAT under the prescribed procedure. Ancillary services, bundled supplies, invoicing structures and certain categories of premises may require distinct treatment. The contract should state whether figures include or exclude VAT and what happens if the VAT treatment changes. The parties should also align invoicing with the applicable Romanian electronic invoicing rules. For wider compliance context, see the site’s Romanian tax guidance.

6. Service charge and operating costs

Define recoverable costs, allocation formula, budget, reconciliation, audit rights and exclusions. Capital expenditure, financing costs, structural defects, landlord negligence, vacancy costs and costs relating to other tenants should not be hidden in a generic “all building expenses” clause. Retail leases may also involve marketing contributions and turnover reporting.

Cost itemPoint to negotiateTypical control
Base rentArea, currency, payment date and rent-free periodRent schedule attached to the lease
IndexationIndex, floor, cap and first adjustmentWorked example and no double escalation
Service chargeRecoverable categories and allocationAnnual budget, reconciliation and audit right
UtilitiesMetered consumption versus allocationSeparate meters or transparent formula
VATExempt or taxable treatmentExpress net/gross wording and change mechanism
ReinstatementRemoval and restoration at exitAgreed baseline and pre-expiry inspection

7. Deposit and financial security

Specify the amount, currency, replenishment duty, permitted deductions, return deadline and whether interest accrues. A bank guarantee should state the required issuing bank, wording, expiry buffer and renewal consequences. The landlord should not have an unlimited right to draw security for disputed amounts.

8. Handover, condition and defects

A signed handover protocol should record keys, meters, systems, inventory, photographs and defects. Define the condition standard at delivery and the remedy if the premises fail the agreed technical specifications. The tenant should not inadvertently accept latent or structural defects merely by taking possession.

9. Fit-out, alterations and ownership of improvements

Address design approval, permits, contractors, access, insurance, health and safety, delays and damage. The lease must also say whether improvements become the landlord’s property, whether compensation is available and what must be removed at expiry. These provisions should be coordinated with the construction-law implications of fit-out works.

10. Repairs, maintenance and building services

The Civil Code places core delivery, maintenance and peaceful-use obligations on the landlord, while the tenant normally bears routine repairs resulting from ordinary use, subject to the contract and the nature of the defect. A commercial lease should allocate structure, roof, façade, common systems, HVAC, internal installations and statutory upgrades expressly, together with response times and self-help rights.

Responsibility map
Who controls each category of work?

Select the responsible actor. The final allocation must be stated in the lease and coordinated with insurance and access rights.

Landlord-controlled matters

Ownership, structural integrity, roof and façade, common systems and building-level approvals normally require the landlord’s control and cooperation.

MatterStarting allocationLease control
Structure, roof and façadeLandlordResponse deadline, access and tenant remedy if use is disrupted
Routine internal maintenanceTenantStandard of care and exclusions for latent defects
Common building systemsLandlord or service-charge regimeService levels, cost allocation and outage remedies
Tenant fit-outTenant, subject to approvalDesign approval, permits, ownership and reinstatement
Statutory upgradeDepends on cause and scopeBuilding-level versus activity-specific responsibility

11. Assignment, subletting and corporate change

The Romanian Civil Code contains specific rules on assignment and subletting, which are frequently modified by commercial lease clauses. The contract should therefore state whether landlord consent is required and on what conditions. The tenant may seek objective consent standards for group reorganisations, business transfers and subleases, while the landlord may require financial tests or continued liability.

12. Default, termination, force majeure and hardship

List the defaults that justify termination, notice method, cure periods and consequences. Non-payment, unlawful use, loss of permits and abandonment need different treatment. Insolvency provisions should be reviewed together with the applicable insolvency legislation: Article 123 of Law no. 85/2014 maintains ongoing contracts at the opening of insolvency proceedings and may limit clauses that terminate or accelerate solely because insolvency has commenced. Force majeure should address genuine impossibility, while hardship or major economic disruption requires a separate allocation because increased cost alone is not automatically force majeure.

What happens if the building is sold?

A tenant should not rely on a simple “sale does not affect the lease” sentence. Ongoing protection depends on the Civil Code’s opposability rules and the steps taken to make the lease effective against the buyer.

Articles 1811 and following of the Civil Code regulate when a lease is opposable to a purchaser and the consequences of transferring the leased property. For registered immovable property, notation of the lease in the Land Registry is a central opposability mechanism; other statutory rules may apply depending on the property and transaction. The lease should require the landlord to notify a sale, procure the buyer’s assumption of obligations and transfer the deposit or guarantees correctly. For material long-term premises, the tenant should assess Land Registry notation and lender non-disturbance arrangements. The seller’s continuing liability, if any, should be stated rather than assumed.

Can the landlord enforce unpaid rent without a full lawsuit?

Potentially yes. A qualifying lease may constitute an enforceable title for rent, but enforceability depends on the contract’s form or tax registration and on the claim being due and sufficiently determined.

Article 1798 of the Civil Code gives qualifying leases enforcement value for rent. Separate rules may also support restitution of the premises when a fixed-term lease expires. Parties should coordinate default clauses with Romanian civil procedure and should not assume that a contractual label such as “enforceable” creates enforcement rights by itself. Broader non-payment strategies are covered in the guide to recovering unpaid business claims in Romania.

Exit & default risk map
How can the lease relationship end?

Select a route to review the clause that should control notice, cost and handover.

Expiry of the agreed term

Set the handover date, inspection process, reinstatement standard, deposit reconciliation and treatment of any continued occupation.

Exit eventDocument to controlMain financial exposure
Fixed-term expiryExpiry notice and handover protocolReinstatement, dilapidations and deposit deductions
Tenant breakBreak notice complying exactly with the clausePenalty, incentive repayment or remaining liabilities
Termination for breachDefault notice and evidence of cure periodArrears, damages, security draw and enforcement costs
Property saleBuyer assumption and opposability evidenceDeposit transfer and continuity of tenant rights
Continued occupationWritten extension or renewal termsUncertain rent, duration and exit notice

Landlord and tenant negotiation checklist

  1. Verify title, cadastral identity, authority and encumbrances.
  2. Confirm that the building and the intended activity can obtain the necessary approvals.
  3. Attach the plan, technical specifications, handover standard and fit-out rules.
  4. Model rent, indexation, VAT, service charge, utilities and exit costs.
  5. Allocate structural, routine and statutory repair obligations precisely.
  6. Align guarantees with actual exposure and release dates.
  7. Negotiate cure periods, break rights, long-stop dates and restoration obligations.
  8. Assess tax registration, enforceability and land-book protection.
  9. Record condition, meters, defects and assets in the handover protocol.
  10. Retain signed notices, invoices, approvals and service-charge reconciliations.

The bottom line

A commercial lease agreement in Romania is primarily a long-term allocation of business risk. The strongest contract is not necessarily the longest. It is the one that identifies the premises accurately, prices the full occupancy cost, makes the authorisation path workable and provides realistic remedies when delivery, operation or exit does not go as planned.

Before committing to a significant lease, both landlord and tenant should coordinate the legal document with technical due diligence, tax treatment, insurance and the operational timeline. A focused contract review in Romania can identify inconsistencies before the commercial timetable makes them expensive to correct.

Frequently Asked Questions

Must a Romanian commercial lease be notarised?

No, not as a general validity rule for a private commercial property. However, authentic form, tax registration and land-book notation can have different consequences for enforcement and opposability. The right structure depends on the parties, term, property and intended protection.

Can rent be stated in euros but paid in Romanian lei?

Yes, parties often denominate rent in euros and provide payment in lei. The lease should identify the exchange-rate source and date, address bank charges and avoid ambiguity about whether indexation applies before or after currency conversion.

Is VAT charged on commercial rent in Romania?

The lease of immovable property is generally VAT-exempt, subject to important statutory exceptions and the landlord’s option to apply VAT under the prescribed procedure. Ancillary services, bundled supplies, invoicing structures and certain premises may receive distinct treatment. The lease should state whether amounts are net or gross and allocate change-of-law risk.

Who pays for repairs in a Romanian commercial lease?

The Civil Code provides a default allocation, broadly separating the landlord’s obligation to maintain usable premises from routine tenant repairs. Commercial contracts usually refine this substantially. Structure, building systems, internal installations, negligence and statutory upgrades should each be addressed expressly.

Can a tenant terminate a fixed-term commercial lease early?

Only if the contract or applicable law provides a right to do so, or if a sufficiently serious breach justifies termination. Businesses should negotiate express break rights, notice periods, conditions and any repayment of incentives rather than rely on a general expectation of early exit.

Does the lease continue if the property is sold?

It may continue against the buyer when the Civil Code’s opposability requirements are satisfied. The tenant should assess land-book notation, the landlord’s sale obligations and any lender arrangements, particularly for high-value fit-out or a long remaining term.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.

Corporate data breach response centre managing a GDPR incident in Romania

GDPR Data Breach in Romania: 72-Hour Guide

A GDPR data breach in Romania creates an immediate legal decision window. The company must contain the incident, determine whether personal data were compromised, assess the risk to individuals and decide whether the Romanian supervisory authority, the ANSPDCP, must be notified within 72 hours.

GDPR data breach response and personal data security in Romania

What companies should know immediately:

  • The 72-hour period runs from the controller’s awareness of the breach, not necessarily from the moment the incident first occurred.
  • Every personal data breach must be documented, even when notification is not required.
  • The ANSPDCP must be notified unless the breach is unlikely to create a risk to individuals’ rights and freedoms.
  • Affected individuals must also be informed without undue delay when the breach is likely to create a high risk.
  • An incomplete investigation does not justify silence. GDPR permits information to be submitted in phases.

This guide is designed for Romanian companies, foreign investors, directors, compliance teams and data protection officers responding to an actual or suspected incident. It should be used together with an incident-specific legal and technical assessment. For preventive support and breach response, see our data protection services in Romania.

What qualifies as a personal data breach?

Article 4(12) of the General Data Protection Regulation defines a personal data breach as a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data. The concept is wider than a cyberattack and covers confidentiality, integrity and availability incidents.

Breach typeWhat it meansCommon exampleImmediate check
ConfidentialityPersonal data are accessed or disclosed without authorisation.An email with customer files is sent to the wrong recipient, credentials are stolen or an attacker exfiltrates a database.Who received or accessed the data, and can further access be stopped?
IntegrityPersonal data are altered without authorisation or by accident.Payroll details are changed, records are corrupted or an unauthorised user modifies a customer account.Which records changed, can the original data be restored, and were decisions made using incorrect data?
AvailabilityPersonal data become unavailable or are destroyed.Ransomware encrypts files, a database is deleted or a lost device contains the only copy of records.Are reliable backups available, how long will services be disrupted, and could the loss harm individuals?

A security event that does not involve personal data is not a personal data breach under GDPR. Conversely, a small incident can still be a breach. Under the data protection rules applicable in Romania, the number of affected people matters, but so do the sensitivity of the data, the ease of identification, the possible consequences and the vulnerability of the people concerned.

When does the 72-hour notification period start?

Article 33 requires notification without undue delay and, where feasible, no later than 72 hours after the controller becomes aware of the breach. According to the EDPB breach-notification guidelines, awareness exists when the controller has a reasonable degree of certainty that a security incident occurred and led to personal data being compromised.

A brief initial investigation may be necessary to determine whether personal data were actually affected. That does not permit an organisation to delay investigation or postpone escalation. Once there is reasonable certainty, the clock runs even if the full cause, exact number of records or final consequences are still being investigated.

72-hour incident clock
From awareness to notification

Select a stage to see the priority. The timetable is operational guidance, not a replacement for immediate action.

Confirm awareness

Record when the controller first reached a reasonable degree of certainty that personal data had been compromised. Preserve the facts supporting that timestamp.

Do not wait for a final forensic report before making the legal notification decision. Article 33 expressly permits phased notification when all information cannot be provided at the same time.

Must every breach be notified to the ANSPDCP?

No. Every breach must be recorded internally, but not every breach must be reported to the authority. The controller must assess the likely impact on the rights and freedoms of natural persons. The result falls into one of three practical levels.

Notification decision matrix
Choose the response level

Select a risk level to see the corresponding GDPR response. The conclusion must be supported by documented facts.

Document internally

If the breach is unlikely to result in a risk to individuals, authority notification is not required. The breach, assessment, effects and remedial action must still be recorded.

Assessment resultRequired actionTypical considerations
Unlikely to create riskDocument the breach and the reasons for not notifying.Strong effective safeguards, limited data, verified recovery, no realistic adverse effect and reliable containment.
Likely to create riskNotify the competent supervisory authority without undue delay and, where feasible, within 72 hours.Possible identity theft, fraud, loss of confidentiality, discrimination, financial loss, reputational harm or loss of control over data.
Likely to create high riskNotify the authority and communicate with affected individuals without undue delay, unless an Article 34 exception applies.Special-category data, credentials or financial data, vulnerable people, large-scale exposure, easy identification or serious likely consequences.

Risk is not determined by a single formula. The company should consider the type of breach, nature and volume of data, identifiability, severity and likelihood of consequences, number and characteristics of affected people, and the effectiveness of safeguards such as encryption. The EDPB’s practical breach examples are useful benchmarks, but the actual incident must be assessed on its own facts.

What must an ANSPDCP notification contain?

Article 33(3) establishes the minimum information. The ANSPDCP’s current online notification form requests additional operational details that allow the authority to understand the incident and the controller’s response.

Notification fieldWhat the company should prepare
Nature of the breachA concise incident summary, whether confidentiality, integrity or availability was affected, and the relevant systems and processing operations.
People and recordsCategories and approximate number of affected data subjects, plus categories and approximate number of personal data records.
Contact pointName and contact details of the DPO or another person able to provide further information.
Likely consequencesThe realistic adverse effects for individuals, including how they could occur and which groups face the greatest exposure.
MeasuresContainment and remediation already performed, further measures proposed, and actions intended to mitigate adverse effects.
TimelineIncident date and time where known, detection, awareness, response milestones and reasons for any notification made after 72 hours.
Additional contextProcessors involved, security measures, cross-border aspects, other authorities notified and whether the filing is initial or supplemental.

If exact figures are not yet available, provide reasonable estimates and state that the investigation continues. Under Article 33(4), missing information may be supplied in phases without undue further delay. If the filing occurs after 72 hours, it must include reasons for the delay.

How is a breach notified in Romania?

The ANSPDCP maintains a dedicated personal data breach notification page with access to its online form. Before submission, the company should identify the correct controller, confirm whether the incident also affects other group entities or joint controllers, and determine whether the ANSPDCP is the competent or lead supervisory authority for any cross-border processing.

The notification should be consistent with the internal breach register, technical evidence, communications plan and any supplemental filing. A company should not understate confirmed facts, speculate beyond the evidence or present an incomplete notification as final.

Enforcement point: the ANSPDCP has publicly reported sanctions for failure to notify a personal data breach within the 72-hour period. Breach-notification obligations under Articles 33 and 34 also fall within the GDPR administrative-fine tier of up to EUR 10 million or, for an undertaking, up to 2% of total worldwide annual turnover for the preceding financial year, whichever is higher. The actual measure depends on the Article 83 assessment and the circumstances of the case.

Who should be involved in the response?

A data breach cannot be handled by IT alone. The legal assessment depends on verified technical facts, while technical containment must preserve evidence and avoid creating inconsistent records. A small decision team should be activated immediately, with clear authority and one incident chronology.

Response team
Four connected workstreams

Select a workstream to see its principal responsibility. All teams should work from the same verified timeline.

Security and IT

Contain the incident, preserve logs and forensic evidence, confirm affected systems and data, remove persistence, restore safely and record every material action.

  • Security and IT: containment, forensic preservation, affected-system analysis, eradication, recovery and evidence of technical safeguards.
  • DPO and legal counsel: awareness timestamp, controller or processor status, risk assessment, authority competence, notification drafting and privilege strategy where applicable.
  • Management and communications: decision authority, resources, operational continuity, messaging and escalation to insurers or relevant corporate bodies.
  • Processors and vendors: incident facts, contractual notification, audit cooperation, subprocessor information and coordinated remedial action.

What is the difference between a controller and a processor?

The controller decides why and how personal data are processed and carries the Article 33 duty to notify the competent supervisory authority. A processor must notify the controller without undue delay after becoming aware of a personal data breach. GDPR does not give processors a separate 72-hour period for notifying the controller.

Data processing agreements should therefore establish an immediate escalation channel, minimum incident information, continuous updates, preservation duties and cooperation with notifications and communications. A processor’s delayed or incomplete report does not remove the controller’s obligation once the controller becomes aware.

RolePrimary breach dutyContractual control
ControllerAssess risk, document every breach, notify the competent authority where required and communicate with individuals where high risk is likely.Maintain response governance and require processors to provide prompt, usable incident information.
ProcessorNotify the controller without undue delay and assist with the controller’s Article 32–36 obligations.Define rapid reporting, evidence preservation, subprocessor escalation, investigation access and update frequency.
Joint controllersAllocate responsibilities transparently, while each remains accountable for the GDPR obligations applicable to it.Agree in advance who leads investigation, authority contact and data-subject communication.

Vendor and technology contracts should be reviewed before an incident occurs. Our IT law services in Romania cover data-processing terms, security obligations, audit rights and incident-response clauses.

When must affected individuals be informed?

Under Article 34, the controller must communicate the breach to affected individuals without undue delay when it is likely to result in a high risk to their rights and freedoms. This obligation is separate from the 72-hour authority-notification rule. The communication must use clear and plain language and explain the nature of the breach, the contact point, likely consequences and measures taken or proposed.

Communication is not required when one of the Article 34(3) conditions applies:

  • appropriate protection measures applied to the affected data and made them unintelligible to unauthorised persons, such as effective encryption;
  • subsequent measures ensure that the high risk is no longer likely to materialise; or
  • individual communication would involve disproportionate effort, in which case a public communication or similarly effective measure is required.

The message should help people protect themselves. Depending on the incident, practical steps may include changing credentials, enabling multi-factor authentication, contacting a bank, monitoring accounts, watching for targeted phishing or using a dedicated support contact. Avoid minimising the event or overwhelming recipients with technical detail.

How should breach risk be assessed?

The legal threshold concerns risk to people, not only damage to the company. Business interruption, contractual liability and reputational harm matter to the response, but they do not replace the individual-rights analysis required by Articles 33 and 34.

Breach risk map
Where can harm materialise?

Select a risk area to review typical consequences. More than one area may apply to the same incident.

Identity fraud and impersonation

Identification data, credentials, signatures or financial information may enable account takeover, fraudulent transactions or convincing social-engineering attacks.

High-risk indicators include sensitive or criminal-offence data, authentication credentials, detailed financial or identity information, data concerning children or other vulnerable people, large-scale exposure, malicious exfiltration, weak safeguards and consequences that are difficult for individuals to reverse. Effective encryption, rapid verified retrieval from a trusted recipient and prompt credential revocation may reduce risk, but each control must be tested against the facts.

What evidence and documentation should be preserved?

Article 33(5) requires the controller to document every personal data breach, including the facts, effects and remedial action. The record must allow the supervisory authority to verify compliance. A defensible incident file should include:

  • the original alert, detection data and a precise incident chronology;
  • the awareness timestamp and the facts supporting it;
  • affected systems, processing activities, data categories, people and record estimates;
  • logs, forensic images, access records, emails, vendor reports and chain-of-custody information where relevant;
  • containment, eradication, recovery and mitigation actions;
  • the risk and high-risk assessments, including reasons and assumptions;
  • the decision to notify or not notify, approvals and any delay explanation;
  • copies of the initial and supplemental ANSPDCP filings;
  • data-subject communications or the documented Article 34 exception; and
  • post-incident findings, corrective actions and responsibility for completion.

Records should distinguish confirmed facts from estimates and hypotheses. The company should also consider cybersecurity, contractual and insurance requirements, DORA and other sector-specific reporting duties, and criminal-law reporting duties. These may use different thresholds and deadlines from GDPR.

A practical 72-hour response checklist

  1. Activate the incident team. Establish one decision lead, secure communications and a contemporaneous chronology.
  2. Contain without destroying evidence. Isolate affected resources, revoke compromised access and preserve logs and forensic material.
  3. Confirm whether personal data are involved. Identify the controller, processor, systems, processing activities and data flows.
  4. Record the awareness timestamp. Explain when reasonable certainty was reached and what facts supported it.
  5. Map the scope. Identify data categories, affected people, approximate record volumes, jurisdictions and vulnerable groups.
  6. Assess risk to individuals. Analyse likelihood, severity, safeguards, realistic misuse and reversibility of harm.
  7. Decide on authority notification. Notify unless the breach is unlikely to create risk. Use phased notification if necessary.
  8. Assess high risk separately. Decide whether individuals must be informed and prepare clear protective guidance.
  9. Coordinate other duties. Review processors, insurers, contractual partners, cybersecurity rules and sector regulators.
  10. Continue and close the response. Supplement filings, verify recovery, complete remediation and retain the breach record.

For a broader preventive review, use our GDPR compliance checklist for Romanian companies. Even though the checklist was published earlier, the core governance controls remain relevant and should be checked against current processing and security practices.

Frequently asked questions

Does the 72-hour period start when IT sees the first suspicious alert?

Not necessarily. The EDPB treats a controller as aware when it has a reasonable degree of certainty that a security incident occurred and compromised personal data. A short initial investigation may establish whether a breach occurred, but it must begin promptly and cannot be used to delay awareness artificially.

Must every ransomware incident be notified to the ANSPDCP?

Not automatically, but ransomware often creates availability, integrity and possibly confidentiality risks. The controller must determine whether personal data were affected, whether exfiltration or unauthorised access occurred, whether reliable backups exist and what consequences are likely for individuals. The conclusion and supporting facts must be documented.

Is an email sent to the wrong recipient a reportable breach?

It is normally a confidentiality breach if personal data were disclosed without authorisation. Whether ANSPDCP notification is required depends on the risk assessment, including the data involved, recipient, ability to retrieve or delete the message, evidence of access and possible consequences. The incident must still be recorded internally.

Can a company notify before the investigation is complete?

Yes. Article 33 permits phased notification when all required information cannot be provided at the same time. The initial notification should contain the available facts and make clear what remains under investigation. Additional information must be supplied without undue further delay.

Does a processor notify the ANSPDCP directly?

The processor’s express Article 33 duty is to notify the controller without undue delay. The controller assesses and makes the supervisory-authority notification. Separate duties may arise from the processor’s own role in other processing, contractual arrangements, cross-border circumstances or sector-specific law.

Must affected people always be informed?

No. Direct communication is required when the breach is likely to result in a high risk, unless an Article 34(3) exception applies. Authority notification uses the lower threshold of likely risk. A breach may therefore require ANSPDCP notification without requiring direct communication to individuals.

What happens if the 72-hour deadline is missed?

The company should notify without further delay and explain why the filing is late. A missed deadline does not remove the notification obligation. The authority may consider the delay, cooperation, mitigation, severity and other Article 83 factors when deciding on corrective measures or a fine.

Need urgent advice on a GDPR data breach in Romania?

We help companies assess notification thresholds, prepare ANSPDCP filings, coordinate processor responses and draft communications to affected individuals.

Book a consultation

Legal disclaimer: This article provides general information and does not constitute legal advice. The applicable response depends on the facts, the company’s role, the data and individuals affected, the competent authority and any sector-specific obligations. Obtain advice for the specific incident.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Commercial invoice overlooking the Bucharest skyline, illustrating late payment in Romania

Late Payment in Romania: Penalties, Interest and Legal Remedies

When is a Romanian invoice late — and what can a creditor recover?

A missed payment deadline in Romania is not only a collections problem. It can trigger statutory penalty interest, a fixed recovery compensation and, with the right contract, a pre-agreed penalty clause — without the creditor having to prove any loss.

Overdue commercial invoice, payment deadline and legal documents in a Romanian law office

Late-payment claims may include interest, recovery compensation and documented collection costs.

Late payment in Romania is heavily regulated for business-to-business transactions. Under Law 72/2013, which transposes EU Directive 2011/7, a B2B invoice is generally payable within about 30 days unless the parties expressly agreed a longer term — capped at 60 days unless a longer term is not abusive. On late payment, provided the creditor has performed its obligations and the delay is imputable to the debtor, a professional creditor can claim the applicable statutory or contractual late-payment interest or penalty, together with the €40 flat recovery compensation and recoverable collection costs. For money obligations assumed in the exercise of an undertaking’s activity, the debtor is in delay by operation of law, so interest runs from maturity without a formal demand, subject to the statutory conditions. Exact figures depend on the contract and on the reference rate published by the National Bank of Romania.

Most foreign suppliers start with a practical question: when can you demand more than the unpaid principal, and how do you recover an unpaid invoice in Romania? This guide explains when a payment becomes late, which charges a creditor can add, which payment terms are valid (and which clauses are void), and the realistic recovery route from a first demand through to enforcement.

The rules below focus on business-to-business transactions governed by Romanian law. They apply on top of the general contract-law regime: the Romanian Civil Code and, for commercial transactions, the specific late-payment law, Law 72/2013, based on EU Directive 2011/7 on combating late payment.

What can a Romanian creditor charge on a late invoice?

Penalty interest, plus a fixed €40 recovery compensation, plus enforceable recovery costs — and, if the contract says so, a daily contractual penalty. Penalty interest, the €40 minimum compensation and a contractual penalty do not require proof of actual loss. Additional recovery costs, however, must be substantiated. These rights accrue provided the creditor has performed its obligations and the delay is imputable to the debtor.

Romanian law gives a creditor who is not paid at maturity a right to moratory damages — penalty interest — running from the due date until payment, at the rate agreed in the contract or, absent agreement, at the statutory rate, without having to prove any loss (Civil Code, Article 1535). The debtor cannot defend by showing the creditor suffered a smaller loss.

Depending on the contract, the creditor may claim the applicable statutory or contractual late-payment interest or penalty, together with the €40 minimum compensation and recoverable collection costs. Whether a contractual late-payment penalty may be cumulated with another form of moratory damages depends on the drafting and legal nature of the contractual remedies.

  1. Statutory or contractual penalty interest — at the rate agreed by the parties or, absent agreement, the statutory penalty interest at the reference rate plus 8 percentage points for professional relations, applied for each semester on the rate in force at the start of that semester (Law 72/2013, Article 4, read with OG 13/2011, Article 3).
  2. Fixed minimum compensation of €40 — a flat amount of recovery damages, payable in lei at the exchange rate on the payment date, in addition to the interest (Law 72/2013, Article 10).
  3. Substantiated recovery costs — collection expenses actually incurred and established can be claimed as damages (Law 72/2013, Article 9).
  4. Contractual penalty clause — a pre-agreed per-day penalty, enforceable without proof of loss (Civil Code, Article 1538), subject to the statutory reduction grounds in Civil Code, Article 1541. Whether it may be cumulated with other moratory damages depends on the contract’s drafting.

Risk: A creditor who ignores the interest route and waits silently may still recover the principal, but documentation matters. If the debtor later disputes the amount, the creditor must show when each sum became due. Keep invoices, delivery or acceptance evidence and the calculation of interest from maturity.

When is a payment legally late?

At the contractual due date, or generally 30 calendar days after the debtor receives the invoice when no term was agreed. In B2B contracts, an agreed payment term longer than 60 days is valid only if it is not abusive (grossly unfair) to the creditor.

The starting point is the term agreed in the contract. The parties may choose the payment date, subject to an important limit in business relations: the contractual payment term cannot exceed 60 calendar days, and a longer term is permitted only if the clause is not abusive under Law 72/2013, Article 5.

When the contract is silent, Law 72/2013, Article 3 fixes the moment from which penalty interest runs. For a professional creditor, interest runs after 30 calendar days from receipt by the debtor of the invoice or of any equivalent payment request. Where the date of receipt is uncertain or the invoice is received before the goods or services, the law uses the date of delivery of the goods or performance of the services as the reference point.

For money obligations assumed in the exercise of an undertaking’s activity, the debtor is in delay by operation of law: interest begins to run at maturity without any formal demand or notification (Civil Code, Article 1523). A written reminder still matters — it creates evidence of the claim and of the date from which the debtor was asked to pay, which becomes relevant in litigation.

These rights accrue only where the statutory conditions are met: in particular, the creditor and its subcontractors must have performed their contractual obligations, and the delay must be imputable to the debtor. The debtor must not have paid the amount due at maturity and must be unable to show that the delay is not attributable to it (Law 72/2013, Article 3(1)).

SituationInterest startsBasis
Payment term agreed in the contractOn the day after the contractual due date, generally without a formal demandCivil Code Art. 1535; Art. 1523 (enterprise money obligations)
No payment term agreed (B2B)30 calendar days after the debtor receives the invoice or equivalent payment requestLaw 72/2013, Art. 3(3)
Invoice received before delivery of goods or services30 calendar days after delivery or performanceLaw 72/2013, Art. 3(3)
Debtor is a public authorityGenerally 30 days; exceptionally up to 60 days where expressly stipulated and objectively justified; public healthcare institutions: maximum 60 daysLaw 72/2013, Art. 6–7

For public authorities, the general legal payment term is 30 calendar days. Exceptionally, the parties may stipulate a term of up to 60 calendar days if it is set out expressly in the contract and in the procurement documentation and is objectively justified by the nature or the specific characteristics of the contract (Law 72/2013, Article 7). For public healthcare institutions and public entities providing medical services, the legal payment term is capped at 60 calendar days (Law 72/2013, Article 6(4)).

The parties cannot contract around the invoice date itself: any clause fixing a term for issuing or receiving the invoice is absolutely void (Law 72/2013, Article 5(3)).

How is the interest rate calculated?

Parties may agree their own rate or penalty, but in transactions governed by Law 72/2013 a clause that excludes late-payment interest or sets it below the statutory penalty interest is treated as abusive. Absent an agreement, the statutory penalty interest in professional relations is set at the reference rate plus 8 percentage points per year.

  • Agreed rate or penalty clause. The contract may set a specific annual interest rate or a per-day penalty, for example 0.1% or 0.5% per day. Such clauses are valid and enforceable without proof of loss, subject to reduction by a court on the statutory grounds under Civil Code Article 1541. In transactions governed by Law 72/2013, a clause that excludes late-payment interest or sets it below the statutory penalty-interest level is treated as abusive under Article 14(a).
  • Statutory rate. If the parties did not agree a rate, Law 72/2013, Article 4 applies the statutory penalty interest calculated under Article 3 of OG 13/2011. For professional relations, the rate is the reference rate plus 8 percentage points, with the rate in force on the first calendar day of each semester applying for the whole semester.

The BNR reference rate in force on 1 July 2026 was 6.50%. Accordingly, the statutory B2B penalty interest applicable throughout the second semester of 2026 is 14.50% per annum. Because the reference rate moves, always confirm the rate currently in force on the National Bank of Romania website before relying on a figure.

Tip: For recurring commercial relationships, agree the interest or penalty rate in the contract. A clearly drafted penalty clause removes any argument about which statutory rate applies and creates a strong, predictable claim on each overdue invoice.

The €40 flat compensation and recovery costs

In B2B relations, a creditor is entitled to a flat minimum compensation of €40 per late payment, in addition to the applicable late-payment interest or penalty and to the costs of any enforcement procedure.

Law 72/2013, Article 10 gives the creditor the right to demand, when the conditions for late payment are met, the equivalent in lei at the exchange rate on the payment date of €40, representing flat-rate minimum damages for the costs of recovering the claim. The obligation to pay this amount matures at the same time as penalty interest starts running.

This flat amount is additional to the applicable late-payment interest or penalty and to the costs of any subsequent enforcement procedure. CJEU case law confirms that the fixed €40 minimum is payable for each commercial transaction not paid on time and evidenced by an invoice or an equivalent payment request, even where several invoices are pursued in a single claim (Case C-585/20, BFF Finance Iberia). Where a single contract provides for successive supplies or services subject to separate payment deadlines, the €40 minimum is payable for each late payment (Case C-419/21).

On top of the €40, Article 9 allows the creditor to claim recovery expenses actually incurred and established. By contrast, the €40 itself does not require proof of loss and remains the simplest element to assert on each unpaid invoice.

Which payment terms are valid — and which clauses are void?

A B2B payment term is capped at 60 days unless a longer term is not abusive. Clauses postponing the start of interest, requiring a formal demand before interest runs, or excluding penalty interest or recovery compensation are unenforceable.

Law 72/2013, Article 12 establishes the general test: a clause or practice is abusive where it creates, in a grossly unfair way (“vădit inechitabil”), rights and obligations significantly unbalanced to the creditor’s detriment. Article 13 sets the criteria a court considers, including serious deviation from established good practice, absence of objective reasons for derogating from the statutory payment terms or interest rate, and the counterparty’s dominant position towards an SME. Article 14 identifies clauses deemed abusive by law, without need for further assessment, and Article 15 sanctions abusive clauses by absolute nullity.

Clauses of the following type are deemed abusive by law and are therefore absolutely null under Law 72/2013, Articles 14 and 15:

  • clauses excluding penalty interest or setting it below the statutory penalty interest;
  • clauses fixing a moment for the interest to start later than the statutory moment;
  • clauses making interest depend on a formal putting-in-delay even though the debtor is in delay by operation of law;
  • in contracts between professionals and public authorities, a payment term exceeding what Article 7(1) allows when the exceptional conditions are not met;
  • clauses excluding the possibility of additional damages.

Mistake: relying on a 90-day payment term “because the client insisted”

In B2B contracts a term beyond 60 days is only valid if it is not abusive. A term imposed by the larger counterparty without objective justification is exposed to challenge and will not stop the statutory interest from running.

Mistake: waiting for a formal demand before recognising interest

For enterprise money obligations, delay arises by operation of law. The claim for interest starts at maturity. The creditor does not first have to send a formal notification.

Mistake: writing “0% interest” into the contract to keep the client happy

A clause that excludes penalty interest altogether is unenforceable against a professional creditor and can be disregarded. The statutory interest will still apply.

How to recover an unpaid invoice in Romania: the practical route

The route runs from a written demand, through the payment-order procedure for certain, liquid and due contractual claims, to court judgment and enforcement. Most commercial claims follow these steps, but timing, documents and evidence requirements should be checked against the specific contract before acting.

Documents illustrating the recovery of an unpaid invoice through demand, court proceedings and enforcement in Romania

Recovering an unpaid invoice normally progresses from a documented demand to court proceedings and, where necessary, enforcement.

  1. Commercial reminder. Send a payment request identifying the invoice, due date and interest accruing. Even where delay is automatic, this creates documentary evidence and often resolves the matter.
  2. Statutory summons. Before filing under the payment-order procedure, the creditor must serve a formal summons under Article 1015 of the Code of Civil Procedure through a judicial executor or by registered letter with declared contents and acknowledgment of receipt, granting 15 days to pay.
  3. Court action. If the debtor contests the claim or amount, recover through ordinary court proceedings for the principal, interest and costs.
  4. Enforcement. Once the creditor holds an enforceable title, a judicial executor can attach bank accounts, receivables or other debtor assets.

Risk: The payment-order procedure is not a substitute for litigation when determining the debtor’s defence requires evidentiary administration incompatible with the summary nature of the procedure. The claim must concern a certain, liquid and due contractual obligation established within the documentary framework. Otherwise, the creditor may have to pursue the claim through ordinary proceedings.

Which route fits which situation?

RouteBest forKey document or conditionMain business consideration
Written demand plus statutory interestOverdue but still cooperative counterpartiesInvoice, contract and evidence of deliveryPreserves the relationship while demonstrating the claim
Payment-order procedureCertain, liquid and due contractual claims for a sum of moneyWritten evidence establishing the contractual claim and proof of the mandatory Article 1015 summonsFaster track for clear claims; genuine disputes may derail it
Ordinary court actionDisputed liability, quantum or set-off argumentsFull evidence of the relationship, delivery and defaultLonger timeline; costs can include interest and fees
Enforcement by judicial executorDebtor with assets who does not pay voluntarilyEnforceable title, such as a payment order or judgmentAttachments and garnishment become available

The payment-order and enforcement rules are contained in the Romanian Code of Civil Procedure. Our dedicated guide to the payment ordinance procedure in Romania explains the conditions and required documents. The broader debt recovery in Romania guide covers the complete collection strategy.

Illustrative scenarios

No penalty clause in the contract

A Romanian buyer does not pay a 30-day invoice of €10,000. Because the money obligation was assumed in a business activity, interest runs from maturity without a formal demand at the statutory B2B rate, and the €40 flat compensation applies. The supplier can demand the principal, interest and the €40 in one written request.

Contract with a 0.5% daily penalty

The parties agreed a daily penalty of 0.5% of the unpaid amount. On a disputed invoice, the creditor can claim the contractual penalty without proving any loss under Civil Code Article 1538. A court may reduce the penalty only on statutory grounds, such as partial beneficial performance or a penalty that is manifestly excessive compared with the foreseeable loss.

Debtor contests the invoice

The debtor claims the services were defective and refuses payment. Because the claim is genuinely disputed, the payment-order route may not resolve the matter. The supplier should prepare evidence of performance and acceptance and assess ordinary litigation against the amount at stake.

How to protect your position before and after maturity

The strongest position starts before the invoice is issued. Interest and penalties are easier to claim when the contract supports them and the documentation confirms what was delivered, when it was delivered and for which price.

  1. Set a compliant payment term. Align the due date with Law 72/2013, generally up to 60 days in B2B transactions, and state it clearly in the contract.
  2. Agree a penalty or interest rate. Include a per-day penalty clause or an agreed annual interest rate so there is no argument about the statutory rate.
  3. Invoice promptly and completely. Issue the invoice with an unambiguous due date and complete references to the contract and delivery documents.
  4. Confirm receipt and delivery. Keep signed delivery notes, acceptance records or other evidence that the goods or services were provided.
  5. Send a written reminder at maturity. Restate the amount, due date, interest formula and €40 compensation. This becomes part of the evidence supporting the claim.
  6. Calculate interest from the correct date. Use the contractual due date or the applicable 30-day statutory threshold, with the semester rate in force at the start of each semester.
  7. Assess the payment-order procedure early. For a certain, liquid and due contractual claim established through documentary evidence, consider the faster procedure rather than waiting while interest and costs accumulate.
  8. Preserve the enforcement option. If payment does not follow, instruct counsel or a judicial executor before the debtor transfers assets.

The Bottom Line

Late payment in Romania is not merely a collections nuisance. It is a regulated event that gives the creditor a defined set of remedies. A professional creditor can claim the applicable statutory or contractual late-payment interest or penalty, the €40 minimum compensation and substantiated recovery costs. Late-payment interest or a contractual penalty and the €40 minimum compensation do not require proof of actual loss, while additional recovery costs must be established. Getting the payment terms, penalty clause and paper trail right from the beginning converts an overdue invoice into a clearly quantified claim that can be pursued through the payment-order procedure or the ordinary courts.

Frequently asked questions

Do I have to send a formal notice before interest starts running?

For money obligations assumed in the exercise of an undertaking’s activity, the debtor is in delay by operation of law and interest runs from maturity without a formal demand. A written reminder is still advisable as evidence and may be required for other remedies.

What is the statutory interest rate for late payment in Romania?

In professional relations, it is the reference rate plus 8 percentage points per year. With the reference rate at 6.5%, that is approximately 14.5% per annum. Confirm the current reference rate published by the National Bank of Romania before relying on a figure.

Is the €40 compensation automatic?

In B2B relations, yes. When the conditions for late payment are met, the creditor may demand the lei equivalent of €40 as flat-rate minimum recovery damages, in addition to penalty interest and enforcement costs.

Can we agree a payment term longer than 60 days?

Only if the clause is not abusive or grossly unfair to the creditor. A longer term imposed without objective justification is exposed to challenge. Clauses fixing the invoice issue or receipt date are absolutely void.

Are contractual penalty clauses enforceable without proof of loss?

Yes. A penalty clause entitles the creditor to the agreed amount without proving any loss. A court may reduce the penalty only in limited statutory circumstances, including where the penalty is manifestly excessive compared with the foreseeable loss.

Does late payment allow the creditor to terminate the contract?

Non-performance can give rise to termination rights where the statutory conditions are met. Termination is assessed separately from the interest claim and carries its own consequences, so it should be considered with counsel before being used.

Disclaimer: This article provides general legal information about Romanian and EU late-payment rules and does not constitute legal or tax advice. Interest rates, deadlines and remedies depend on the contract, the parties’ status and the specific facts. Figures such as the reference rate change over time.

AI Notice: AI-assisted content, reviewed and approved by a qualified Romanian lawyer.

Romanian company director liability and corporate governance risk assessment

Romanian Company Director Liability: Duties and Risks

When can Romanian company director liability arise?

The company is a separate legal person, but that shield is not absolute. A director may face personal exposure for breach of corporate duties, insolvency misconduct, bad-faith tax conduct, a personal guarantee or other unlawful acts.

COMPANYSEPARATE LEGAL PERSONLiability shield BREACH OF DUTYloss + causationINSOLVENCYArticle 169 conductTAX LIABILITYbad-faith conductPERSONAL GUARANTEEcontractual exposure AI-generated illustration

Romanian company director liability does not arise automatically from the company’s debts. Personal liability requires a separate legal basis, such as a damaging breach of the director’s mandate or statutory duties, conduct that contributed to insolvency, bad-faith conduct connected with unpaid taxes, or a personal contractual commitment. Foreign directors should verify their registered powers, keep an evidence trail for material decisions and escalate financial distress early.

Accepting a director appointment in Romania is more than an administrative formality. Understanding Romanian company director liability requires reviewing both the legal mandate and the director’s actual decision-making role. The director may represent the company, commit it contractually, manage assets and supervise accounting, tax, employment and regulatory processes. Those powers carry duties to the company under the articles of association, shareholder resolutions, the rules on mandate and Romanian company law.

The exact framework depends on the company form and governance structure. The Romanian term administrator may refer to an administrator of a limited liability company (SRL) or a member of the board of directors of a joint-stock company (SA). An SA may also use a two-tier system with a management board and supervisory board. The appointment document and the articles of association should therefore be read before applying any general rule.

Is a Romanian company director personally liable for company debts?

Generally, no. An ordinary supplier, landlord or lender claim is normally against the company. The director becomes personally exposed only where the creditor or another claimant can rely on a distinct statutory, contractual or delictual basis and prove the elements required for that route.

This distinction matters. A company’s inability to pay does not, by itself, transfer every unpaid invoice to its director. Equally, the words “limited liability” do not protect a director from consequences of their own conduct.

SituationUsual starting pointPotential director exposure
Ordinary commercial debtThe company is the contracting party and primary debtor.No automatic personal liability merely because the company does not pay.
Breach of mandate or company-law dutyThe company may have suffered loss through the director’s act or omission.Liability may arise if breach, damage and causation are established under the applicable rules.
Insolvency misconductThe company enters insolvency with unpaid liabilities.The insolvency court may order persons who contributed to insolvency through conduct listed in Article 169 to bear part or all of the liabilities, within the causally connected loss.
Unpaid tax obligationsThe company remains the tax debtor.Joint liability may be established in the bad-faith situations listed in Article 25 of the Fiscal Procedure Code.
Personal guaranteeThe company receives finance, a lease or credit.The director may be liable under the separate guarantee they signed, according to its terms.
Separate unlawful actThe director acts personally as well as for the company.Civil, administrative or criminal consequences may apply depending on the specific act and statute.

Do not confuse shareholder liability with director liability. A shareholder’s exposure as an investor and a director’s exposure as a manager are different questions. One person may hold both roles, but each potential claim needs its own legal basis.

What are the core duties of a Romanian company director?

Articles 72 and 73 of Romanian Companies Law no. 31/1990 connect administrators’ obligations and liability to the rules on mandate and the special provisions of the Companies Law. They also identify responsibility toward the company for matters including the reality of capital contributions, the actual existence of distributed dividends, legally required registers, implementation of shareholder resolutions and strict performance of duties imposed by law and the articles of association.

Duty areaPractical meaningUseful evidence
Act within authorityFollow the law, articles of association, appointment terms and valid shareholder or board resolutions.Current constitutional documents, authority matrix, registered representation powers and written approvals.
Protect company interestsUse management powers for the company rather than for an undisclosed personal or third-party benefit.Conflict disclosures, abstentions, independent valuations and documented commercial rationale.
Make informed decisionsObtain information proportionate to the value, urgency and risk of the decision.Board packs, forecasts, legal and financial advice, alternatives considered and minutes.
Supervise records and complianceEnsure required registers and accounting records exist and that delegated functions are reasonably monitored.Compliance calendar, management reports, tax confirmations, audit trails and escalation logs.
Implement corporate decisionsCarry out valid shareholder decisions accurately and within the company’s legal powers.Signed resolutions, implementation plans, filings and completion records.
Preserve confidentialityProtect confidential information and business secrets during and, where applicable, after the mandate.Access controls, confidentiality undertakings and documented return or deletion of company information.

For SA board members, Article 1441 of Romanian Companies Law no. 31/1990 expressly requires prudence and diligence of a good administrator, loyalty in the company’s interest and confidentiality. It also recognises an informed-business-decision protection where the director was reasonably entitled to believe that the decision served the company and relied on adequate information. That provision should not be copied mechanically into an SRL analysis; the SRL’s own statutory rules, mandate and constitutional documents must be assessed.

Decision record

A defensible director decision has four layers

1AUTHORITYWho may decide?Which approval?2INFORMATIONFacts and forecastsProfessional advice3CONFLICTSDisclose interestsManage participation4MINUTESRationale and voteActions and follow-up AI-generated illustration
The file should show how the decision was authorised, informed, conflict-checked and implemented—not merely its eventual outcome.

How do SRL and SA director duties differ?

An SRL is usually managed by one or more administrators appointed through the articles of association or by the shareholders. Article 197 contains SRL-specific administration rules and refers expressly to Articles 75, 76, 77(1) and 79. Articles 72 and 73 remain central to the mandate-based duties and liability framework, but the articles of association are also essential because they define individual or joint representation, reserved matters, term of office and internal approval limits.

An SA has a more prescriptive governance framework. In the one-tier system, a board of directors may delegate management to directors; in the two-tier system, the management board operates under a supervisory board. Duties, delegation, conflicts, meeting procedure and the mechanics of corporate liability actions can therefore differ materially from an SRL.

Foreign group policy is not enough. A director of a Romanian subsidiary must apply the subsidiary’s Romanian-law documents and duties. Instructions from the parent company, investor or beneficial owner do not automatically excuse an act outside authority or against the Romanian company’s interests.

Before accepting or using the mandate, confirm the director provisions in the Romanian articles of incorporation. Where governance rights are also allocated between investors, coordinate those documents with the shareholder agreement while recognising that a private agreement does not replace mandatory corporate rules or Trade Register formalities.

When can the company claim against a director?

A corporate claim typically focuses on whether the director breached an applicable duty and caused quantifiable loss to the company. The decision and representation mechanics depend on the company form, the alleged conduct and the applicable articles of the Companies Law. Article 155 contains the general-meeting mechanism for an SA action against directors for damage caused to the company through breach of their duties.

Approval by shareholders should not be treated as a universal release. The legal effect depends on what was disclosed, the nature of the decision, the company form, mandatory law, third-party rights and whether the approving body had authority. A director should still require accurate materials and record concerns.

Unauthorised transaction

A director signs beyond registered or internal powers and the company suffers loss. Liability, enforceability and internal recourse require separate analysis of the authority documents and third-party circumstances.

Related-party benefit

Company assets or opportunities are directed to a connected party without transparent approval, adequate information or defensible commercial terms.

Ignored compliance warning

Management receives a specific accounting, tax or regulatory warning but takes no proportionate action, allowing avoidable loss to increase.

When can insolvency create personal exposure?

Financial distress is a critical turning point. Article 66 of Romanian Insolvency Law no. 85/2014 generally requires an insolvent debtor to apply to the tribunal within a maximum of 30 days from the onset of insolvency, subject to the statute’s rules for good-faith restructuring negotiations. The competent tax authority must be notified of the intended insolvency application 15 days before filing, and proof of that notification must be attached to the application. A legal entity’s application is signed by the persons authorised to represent it under its constitutional documents; a shareholder resolution is not required by Article 66(5).

Under Article 169, the insolvency court may order management or supervisory members, any individual or legal entity exercising control over the debtor’s financial or operational decisions regardless of formal title, and other persons who contributed to insolvency through listed conduct to bear part or all of the debtor’s liabilities, without exceeding the loss causally connected to that conduct.

Article 169 risk categoryExamples of evidence reviewed
Using company assets or credit for personal or third-party benefitRelated-party payments, asset transfers, undocumented loans and non-commercial terms.
Conducting personal business under cover of the companyRevenue diversion, overlapping contracts, beneficial ownership and use of company resources.
Continuing activity in personal interest when cessation of payments was clearly approachingCash-flow forecasts, creditor ageing, director benefits and the rationale for continued trading.
Fictitious, unlawful or missing accountingLedgers, source documents, backups, handover records and access to accounting systems.
Diverting or concealing assets, or fictitiously increasing liabilitiesAsset registers, disposals, inventory movements, invoices and connected-party balances.
Transferring assets or a significant part of the business to a closely related personTransfers made while the debtor is in financial difficulty, compliance with Article 73(2¹) of the Companies Law, the relationship between the parties, continuation of the business through the new entity and evidence of an intention to shield assets from creditors.
Ruinous financing used to delay cessation of paymentsPricing, security, repayment prospects, alternatives considered and decision minutes.
Preferential payment to one creditor shortly before cessationPayment sequence, creditor relationship, maturity dates and justification.
Other intentional conduct contributing to insolvencyThe specific act, intent, resulting loss and causal connection to insolvency.

Law no. 239/2025 inserted Article 169(1)(e1), which specifically targets the transfer of assets or a significant part of the business of a debtor in financial difficulty to a person closely related to the debtor, where the obligations imposed by Article 73(21) of the Companies Law are breached and the transfer is intended to continue the activity through the new entity while shielding assets from the debtor’s creditors.

A final Article 169 liability judgment now has consequences beyond the payment order. Under Article 169(10), the person may not be appointed as a company administrator and, if already serving as an administrator elsewhere, loses that right for 10 years from the date the judgment becomes final. The person is also barred for 5 years from founding companies or acquiring a controlling participation in a new company.

Distress response

The evidence trail becomes more important as liquidity deteriorates

1MONITORCash and arrears2VERIFYSolvency status3ADVISELegal and financial4DECIDERestructure or file5PRESERVERecords and handoverAI-generated illustration
Early monitoring and documented advice help directors distinguish temporary pressure from statutory insolvency and respond within the applicable deadline.

Failure to hand over accounting records can create a rebuttable presumption of fault and causation under Article 169. For collegial management or supervisory bodies, a member who opposed the relevant act and recorded the opposition may have a specific defence under Article 169(5). A silent disagreement is therefore much weaker than a properly documented one.

When can a director become jointly liable for Romanian tax debts?

Article 25 of Romanian Fiscal Procedure Code no. 207/2015 creates specific joint-liability routes for overdue tax obligations. They are not triggered merely by holding office. The relevant provisions require the statutory circumstances and, for the principal director-related routes, bad faith.

Potential cases include administrators or other persons who, in bad faith:

  • caused the debtor’s insolvency by transferring or concealing its assets;
  • failed during their mandate to request the opening of insolvency proceedings for tax obligations from that period that remained unpaid when insolvency was declared;
  • caused the non-declaration or non-payment at maturity of tax obligations;
  • caused an unjustified tax refund or reimbursement; or
  • caused tax debts to accumulate and prevented their payment in the circumstances covered by Article 25(21).

A tax assessment against the company and a decision establishing the director’s joint liability are different acts. The facts, legal basis, procedural steps and challenge deadlines should be reviewed immediately when a director receives a Romanian tax notice.

Can delegation, resignation or shareholder instructions remove liability?

Delegation

Delegating finance, tax or operations does not necessarily eliminate a director’s own supervision duties. The appropriate level of oversight depends on the company form, governance structure, importance of the function, warning signs and the director’s legal powers. A clear written delegation and regular reporting are stronger than an informal assumption that “the accountant handles it.”

Resignation

Resignation can end future management authority once effective and properly implemented, but it does not erase possible liability for earlier acts or omissions. The director should document the handover, return company property, preserve relevant records and ensure required Trade Register formalities are handled.

Shareholder or parent-company instructions

A shareholder instruction does not automatically legalise conduct that breaches mandatory law or the director’s duties to the Romanian company. Material instructions should be checked against reserved matters, representation rules, corporate benefit, conflicts and insolvency considerations.

Directors’ and officers’ insurance

D&O insurance may fund defence costs or certain covered claims, but wording, exclusions, notification duties, deductibles and Romanian mandatory law matter. It cannot be assumed to cover fraud, intentional misconduct, all tax exposure, fines or every insolvency claim.

Practical checklist for foreign directors of Romanian companies

  1. Verify the mandate. Obtain the current articles of association, appointment decision and Trade Register extract.
  2. Map authority. Distinguish individual representation, joint signatures, shareholder reserved matters and internal approval thresholds.
  3. Build a reporting pack. Receive timely cash-flow, tax, accounting, litigation, employment and regulatory information.
  4. Document material decisions. Record information reviewed, options, conflicts, rationale, vote and follow-up responsibility.
  5. Control related-party dealings. Disclose interests and obtain the approvals and supporting valuation appropriate to the transaction.
  6. Supervise filings and records. Use a compliance calendar and require evidence of submission and payment—not verbal confirmation alone.
  7. Escalate warnings. Investigate missed tax payments, unpaid salaries, creditor enforcement, deteriorating liquidity and missing records promptly.
  8. Record disagreement. Use the legally appropriate board record and written notification; do not rely on an informal objection.
  9. Assess distress early. Seek Romanian insolvency and tax advice before the statutory filing window is lost, allow for the 15-day advance tax-authority notification and scrutinise transfers to closely related persons.
  10. Plan the exit. Coordinate resignation, handover, registrations, access removal, record preservation and insurance notification.

The bottom line

Romanian company director liability is conduct-based, not an automatic consequence of a company debt. The strongest protection is disciplined governance: understand the mandate, obtain adequate information, act within authority and in the company’s interest, manage conflicts, preserve reliable records and respond quickly to tax or insolvency warning signs.

Foreign directors should not wait for a dispute to reconstruct the decision process. A focused Romanian-law governance review can identify gaps in signing authority, reserved matters, minutes, compliance reporting and distress procedures before they create personal exposure.

Frequently asked questions

Is an SRL administrator automatically liable for the company’s unpaid debts?

No. The SRL is normally the debtor. Personal liability requires a separate legal or contractual basis, such as breach of the administrator’s duties causing loss, Article 169 insolvency conduct, Article 25 bad-faith tax conduct or a personal guarantee.

Does being a shareholder change a director’s liability?

Shareholder and director exposure are separate. A person who holds both roles may face different claims in each capacity, but liability must be analysed under the legal basis applicable to that role and conduct.

Can shareholder approval protect a Romanian director?

Approval can be relevant, but it is not a universal defence. Its effect depends on the company form, authority of the approving body, quality of disclosure, mandatory law, third-party rights and the conduct involved.

Does resignation end a director’s potential liability?

Resignation can end future authority once effective, but it does not erase potential liability for earlier conduct. Proper handover, registration, preservation of records and insurance notification remain important.

What should a director do if they disagree with a board decision?

Obtain advice on the correct procedure, state the reasons clearly and ensure the opposition is recorded and notified in the form required by the applicable governance rules. This is particularly important for collegial bodies and insolvency-related decisions.

Can D&O insurance eliminate personal liability?

No. It may cover certain defence costs and claims, but policy terms, exclusions, notice requirements and mandatory law apply. Fraud, intentional conduct, fines, tax exposure and insolvency claims may be excluded or limited.

Disclaimer: This article provides general legal information and does not constitute legal, tax or insolvency advice. Director duties and liability depend on the company form, constitutional documents, appointment terms, decision-making process, actual conduct and the law applicable to the specific facts.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.

Two corporate professionals reviewing AI transparency controls, compliance dashboards, and synthetic content verification tools on screens in an office setting.

EU AI Act in Romania: 2026 Guide for Foreign Companies

Artificial intelligence and digital regulation · 2026

EU AI Act in Romania: 2026 Guide for Foreign Companies

Foreign companies operating in Romania may be subject to the EU AI Act even when the parent company, vendor or development team is outside the European Union. This practical guide explains the scope rules, the obligations already applying in 2026, the later high-risk deadlines and the records a Romanian business should build now.

The analysis should be read together with the official AI Act text, the Commission’s AI Act implementation page and the current guidance available through the AI Act Service Desk.

Two corporate professionals reviewing AI transparency controls, compliance dashboards, and synthetic content verification tools on screens in an office setting.
AI compliance is a governance process: classify, document, train and monitor.

What is the practical answer for a foreign company?

A Romanian subsidiary, branch or other local operation should begin with an inventory of the AI systems it provides, deploys, imports, distributes or uses for work. The company should then identify whether the system is prohibited, high-risk, subject to transparency duties, or outside the main AI Act obligations. The label used by the vendor is not decisive: the same tool may create different legal questions depending on its function, users, outputs and place of use.

Scope first

Map the Romanian entity, the foreign group, the provider, the deployer, the users and where the output is used. A foreign parent does not automatically remove EU exposure.

Article 2 analysis

Obligations now

AI literacy, prohibited-practice controls, GPAI-related obligations and the new transparency rules must be considered according to the applicable role and system.

2026 operating baseline

Evidence later

Keep an AI register, vendor file, training record, human-oversight process and incident route so the business can show how it reached its classification.

Governance that scales
Key point: the AI Act does not create a universal “AI officer” requirement for every Romanian business. Responsibility must be allocated in a way that fits the company’s systems, roles, risk profile and existing compliance structure.

AI Act timeline for companies operating in Romania

The original AI Act timetable has been supplemented by the Digital Omnibus on AI. The current implementation page of the European Commission identifies the dates below. A deadline table should be treated as a planning tool, not as a substitute for checking the final text and any sector-specific transition rule.

Completed1 August 2024
Entry into force

The Regulation entered into force. The legal framework began its transition period, while later provisions were scheduled to apply in stages.

Applied2 February 2025
Prohibitions and literacy

The prohibited-practice rules and the Article 4 AI-literacy obligation became applicable. Businesses should already have training and prohibited-use controls in place.

Applied2 August 2026
Transparency and supervision

Transparency obligations for certain AI systems, broader enforcement powers and the Commission’s AI Office and national authorities’ implementation work become operational.

Deferred2 December 2027
Selected high-risk uses

Following the Digital Omnibus, high-risk systems in sensitive Annex III areas, including employment, apply from this date. Product-embedded high-risk rules have a later transition.

Rule or milestoneCurrent application pointWhat the Romanian operation should do
Prohibited AI practicesApplied from 2 February 2025; an additional prohibition concerning certain non-consensual intimate or child sexual abuse material applies from 2 December 2026.Screen use cases before procurement or deployment and escalate any practice that may manipulate, exploit, socially score or infer protected characteristics.
AI literacyApplied from 2 February 2025 and enforced by national market-surveillance authorities from 2 August 2026.Adopt role-based training and retain evidence of the measures taken, rather than relying on a generic awareness email.
Transparency rulesApplied from 2 August 2026 for the relevant Article 50 systems and outputs.Review chatbot notices, synthetic-content marking, deepfake disclosures and the editorial process for public-interest text.
Annex III high-risk systemsSelected high-risk use cases, including employment, apply from 2 December 2027 after the Digital Omnibus transition.Classify and plan early. The later date does not remove GDPR, employment, consumer or fundamental-rights duties that may apply now.
High-risk systems in regulated productsExtended transition until 2 August 2028 under the current Commission summary.Coordinate product-safety, sectoral and AI Act analysis with the provider and any notified-body or conformity route.

The Commission’s current AI Act timeline identifies the staged dates and the changes introduced by the Digital Omnibus.

Does the AI Act apply to a foreign company operating in Romania?

Often, yes. The scope is not limited to companies incorporated in an EU Member State. The Regulation covers providers placing AI systems or general-purpose AI models on the Union market, deployers located in the Union, and providers or deployers in a third country where the output produced by the system is used in the Union. Importers, distributors, certain product manufacturers, authorised representatives and affected persons are also expressly addressed.

This creates several common patterns for international groups. A US or UK parent may provide a generative AI platform used by its Romanian subsidiary. A Romanian company may deploy a recruitment tool supplied by a vendor in another country. A group may centralise procurement and security while the local entity makes decisions affecting Romanian workers or customers. The legal analysis should identify each role instead of treating “the group” as a single operator.

Question 1Is the system used in the EU?

If the Romanian entity deploys the system, or its output is used in Romania or elsewhere in the Union, the scope analysis moves beyond the location of the parent company.

Question 2Who provides it?

Record the provider, importer, distributor, group company, authorised representative and vendor chain. Contract labels are useful evidence but do not replace the legal role analysis.

Question 3Who deploys it?

Identify the business unit that determines the purpose and use. The deployer may be the Romanian company, a foreign shared-service centre or another group entity depending on the facts.

Question 4Who is affected?

Employees, applicants, customers and other persons in the Union may be affected even when the technical processing or model hosting takes place outside Romania.

Do not rely on the hosting location alone: cloud hosting, a foreign parent or a vendor’s “EU AI Act compliant” statement does not by itself determine whether the Romanian entity has obligations.

Which AI uses should a Romanian company classify first?

A useful first inventory is operational rather than theoretical. Start with tools that make recommendations, rank people, generate customer-facing outputs, analyse sensitive information, control access to services or influence employment decisions. Include tools purchased by individual teams if company data or company accounts are used.

Business useWhy it needs early reviewFirst evidence to collect
Recruitment, CV screening or candidate scoringEmployment and access-to-self-employment uses are listed in Annex III and may engage high-risk analysis once the relevant rules apply.Vendor description, decision logic, data sources, human review and impact on applicants.
Employee monitoring, task allocation or performance evaluationAI used to affect working relationships or monitor behaviour may fall within the employment category and also raise labour-law and GDPR questions.Purpose, affected groups, indicators, decision owner, notice, consultation and challenge route.
Customer chatbot or voice assistantInteractive systems may require a clear notice that the person is interacting with AI unless the interaction is obvious in context.Interface screenshots, notice wording, escalation to a person and accessibility check.
AI-generated public-facing images, audio or textArticle 50 can require machine-readable marking or disclosure, subject to the relevant exception and content type.Generation workflow, labelling method, human review, editorial responsibility and publication record.
Credit, insurance, access or eligibility decisionsSome essential private or public service uses are listed as high-risk and can intersect with anti-discrimination and sectoral rules.Decision criteria, datasets, human oversight, explanation path and affected-person rights.

Do not classify a system only by the word “AI” in a sales brochure. Ask what the tool actually does, which people it affects, whether it generates or ranks content, whether it makes or supports a decision, and whether it is integrated into a regulated product. The Commission’s AI Act Service Desk provides tools and guidance that can support this initial assessment.

Which AI practices are prohibited?

The AI Act bans certain practices because their risks are considered unacceptable. Examples include harmful manipulation or deception, harmful exploitation of vulnerabilities, social scoring, certain forms of individual criminal-offence prediction, untargeted scraping to create facial-recognition databases, workplace or education emotion recognition, and biometric categorisation to infer protected characteristics, subject to the precise legal wording and exceptions.

For a foreign company with Romanian staff, the workplace emotion-recognition prohibition deserves particular attention. A vendor may market a “wellbeing”, “engagement” or “productivity” product without describing it as emotion recognition. The business should look at the functionality and the data signals used, not only the product name. The same applies to tools that claim to infer personality, intent, reliability or risk from communications.

Procurement gate

Require the business owner to describe the system’s purpose, data sources, affected people and output before purchase or activation.

Red-flag review

Escalate tools involving vulnerability exploitation, social scoring, biometric inference, emotion recognition or behavioural prediction.

Decision record

Record why the company concluded that a use is permitted, prohibited, outside scope or subject to another compliance route.

What transparency duties apply from 2 August 2026?

Article 50 covers specific interactions and outputs. A provider of an AI system intended to interact directly with natural persons must ensure that people are informed that they are interacting with an AI system unless this is obvious in context. Providers of systems generating synthetic audio, image, video or text must ensure that outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, subject to the stated limits and exceptions.

Deployers have additional duties in defined situations. People exposed to emotion-recognition or biometric-categorisation systems must be informed. A deployer of an image, audio or video deepfake must disclose that the content was artificially generated or manipulated, subject to the artistic and other exceptions. Text generated or manipulated by AI and published to inform the public on matters of public interest must also be disclosed, but the obligation does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility.

This is why the website’s ordinary AI Notice and a public disclosure under Article 50 should not be treated as identical. An editorial footer may be useful transparency, but it does not automatically satisfy every machine-readable marking or user-facing notice requirement. Each workflow should be checked according to the system, output, audience and publication context.

Practical control: create a short content decision tree: AI-assisted editing, substantially generated content, deepfake or synthetic media, public-interest text, customer interaction. Assign the corresponding label, machine-readable marker, human review and approval record.

Does every AI-generated business article or image need a label?

No single answer applies to every output. The AI Act distinguishes between the type of system, the type of output and the way the content is published or presented. Standard editing that does not substantially alter the input may fall within an exception to the machine-readable marking duty. A human review and editorial-control exception may apply to certain public-interest text. Deepfakes have their own disclosure rule, while chatbots require a direct-interaction analysis.

The company should document the workflow instead of making a broad statement such as “all AI content is exempt” or “all AI content must be labelled in the same way”. Keep the prompt or source material where appropriate, the generated version, the human changes, the responsible editor, the final label and the publication channel. This is particularly useful where content is repurposed across websites, advertisements, social media and customer communications.

What does AI literacy require?

Article 4 requires providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy for staff and other persons dealing with the operation and use of AI systems on their behalf. The measures should take account of technical knowledge, experience, education, training, the context in which the systems are used and the people or groups on whom the systems are used.

This is a context-based obligation, not a fixed annual course or a universal certification. A marketing employee using a writing assistant, an HR manager using a candidate-ranking tool and an engineer managing a model deployment do not need identical training. The employer should explain relevant limitations, data handling, hallucination and reliability risks, prohibited uses, escalation routes, human review and the consequences of relying on outputs.

Identify AI users

List employees, contractors and other persons acting on the company’s behalf who operate or use an AI system. Include occasional users where the risk justifies it.

Match training to context

Separate basic safe-use guidance from role-specific instruction for HR, legal, customer service, developers, procurement and management.

Keep training records

Retain the audience, date, topics, materials, completion evidence and any follow-up testing or policy acknowledgement.

Update after change

Reassess training when a new system, material model update, high-risk use, incident or regulatory guidance changes the risk profile.

The Commission’s AI-literacy Q&A explains that enforcement of Article 4 is handled by national market-surveillance authorities and that there is no one-size-fits-all competence framework. A Romanian business should therefore build a proportionate internal record rather than wait for a template course.

What should employers know about recruitment and workplace AI?

Annex III identifies AI systems intended for recruitment or selection, including targeted job advertising, application analysis and candidate evaluation. It also identifies systems used to make decisions affecting terms of work-related relationships, promotion or termination, allocate tasks based on individual behaviour or personal traits, or monitor and evaluate performance and behaviour.

Under the current Commission timeline, the rules for high-risk systems in these sensitive areas apply from 2 December 2027 following the Digital Omnibus transition. This does not create a compliance holiday. A Romanian employer must still consider GDPR, Romanian labour law, anti-discrimination rules, information duties, collective arrangements, employment records, confidentiality and the possibility of human challenge. A vendor’s score should not become an unexplained substitute for a lawful employment decision.

Before deploying such a tool, the employer should identify who makes the final decision, what the AI output means, whether a person can disregard it, what data is used, whether a candidate or employee can obtain an explanation, and what happens if the system produces an incorrect or discriminatory result. The analysis should also consider whether the foreign group’s HR platform is being deployed by the Romanian entity or merely accessed for central administration.

Separate the dates: the later high-risk deadline concerns the AI Act’s high-risk requirements. It does not suspend GDPR or employment-law obligations that may arise from the same processing or decision today.

Vendor contracts and AI due diligence

A foreign company should not accept a short vendor statement as its entire AI Act file. The contract and due-diligence record should allow the Romanian operation to understand the system’s intended purpose, role allocation, technical limitations, data use, security, logging, human oversight, incident cooperation, transparency features and change-management process.

Purpose and role

Ask whether the supplier is a provider, GPAI provider, importer, distributor or another operator, and whether the Romanian entity is a deployer. Retain the product description, role matrix and contract.

Data and outputs

Check what data is processed, where it is stored, whether prompts or outputs train a model, and whether personal data can be isolated. Keep the data-flow map, DPA and security schedule.

Human oversight

Confirm whether the operator can intervene, override, suspend or test the system and whether those limits are communicated. Keep the operating procedure and testing logs.

Incidents and changes

Agree how model changes, outages, security events and regulatory requests are communicated. Keep notice SLAs, version history and audit rights.

Exit and continuity

Plan how the company will retrieve records, delete data and continue operations if the tool is withdrawn or reclassified. Keep the exit and retention plan.

Where the tool is supplied by a group company, the intercompany agreement should be tested in the same way as an external vendor contract. The Romanian entity may need practical access to information even when procurement, model management and security are centralised abroad.

How does the AI Act interact with GDPR and Romanian employment law?

The AI Act does not replace GDPR. Article 2 expressly preserves the application of Union data-protection, privacy and communications rules. A company may therefore need a lawful basis, purpose limitation, data minimisation, transparency, retention controls, processor arrangements, security measures and, where relevant, a data-protection impact assessment in addition to its AI Act analysis.

Workplace deployment adds another layer. If an AI tool ranks applicants, monitors employees, allocates tasks or recommends termination, the employer should consider the Labour Code, anti-discrimination protections, employee information and consultation, internal policies and the safeguards around automated decision-making. A human reviewer is important, but “human in the loop” is not a complete answer if the reviewer simply approves an unexplained score.

For customer-facing systems, consumer-protection and sectoral obligations may also apply. For regulated products, product-safety rules, conformity assessment and technical documentation may interact with the AI Act. The right approach is a combined compliance map that shows which regime addresses which risk.

AI Act

Classifies the system and creates duties tied to the operator role, risk level, transparency, literacy and governance.

GDPR

Controls personal-data processing, individual rights, security, profiling and the relationship between controller and processor.

Employment and sector law

Protects workers, customers and regulated activities through additional information, fairness, safety and challenge requirements.

Who supervises the AI Act in Romania?

Enforcement is shared. The European Commission’s AI Office supervises general-purpose AI providers and certain connected systems, while national competent authorities supervise other AI systems. The European Data Protection Supervisor has a specific role for systems used by EU institutions. The Romanian entity should monitor the national designation and implementation measures relevant to its activity instead of assuming that every question goes to one central EU authority.

The AI Act also allows complaints, investigations, information requests and other enforcement tools. The applicable authority may consider the nature, gravity and duration of an infringement, affected persons, the operator’s size and turnover, cooperation, responsibility, mitigation and whether the conduct was intentional or negligent.

What penalties can apply?

Article 99 sets maximum levels for several categories, while Member States establish the detailed national penalty and enforcement rules. Non-compliance with prohibited practices can reach up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher. Other listed operator obligations, including certain deployer and transparency duties, can reach up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. Incorrect, incomplete or misleading information supplied to authorities can attract a separate maximum of EUR 7.5 million or 1% of worldwide annual turnover.

For SMEs and start-ups, Article 99 provides a lower-of-the-two limits approach for the amounts or percentages referred to in the provision. The figures are maximums, not automatic fines. Authorities must assess the individual circumstances and procedural safeguards remain relevant. Companies should avoid both extremes: treating the maximum as inevitable or assuming that a small local subsidiary has no exposure because the parent owns the technology.

Practical AI Act compliance checklist for a Romanian operation

01 · InventoryBuild the AI register

List systems, vendors, users, business owners, locations, outputs, affected people and group-company relationships. Include pilots and shadow AI.

02 · ClassifyAssign the legal route

Screen scope, prohibited practices, high-risk categories, transparency duties, GPAI dependencies, sector rules and applicable transition dates.

03 · ControlPut safeguards in place

Set access rules, human review, notices, marking, training, procurement controls, incident escalation and data-protection measures.

04 · EvidenceKeep the decision trail

Retain the classification rationale, vendor file, contract, training evidence, approvals, tests, incidents, changes and review date.

Create an inventory

Owner: Legal, IT, procurement and business owners. Output: an AI register with purpose, provider, deployer, data and affected persons.

Approve use cases

Owner: management with legal and security input. Output: a classification note, prohibited-use sign-off and escalation route.

Train users

Owner: HR, compliance and system owners. Output: role-based AI-literacy materials and completion evidence.

Review public outputs

Owner: marketing, communications and editorial owners. Output: a disclosure, marking and human-review record.

Monitor change

Owner: system owner and vendor manager. Output: version, incident, access, performance and reassessment logs.

Common mistakes made by foreign groups

“The parent handles it”

Central governance can help, but the Romanian operation still needs to know its role, local use, affected people and evidence available to it.

“The vendor is compliant”

Vendor compliance material is an input. It does not answer whether the Romanian entity is a deployer, importer or affected operator in the actual workflow.

“The deadline is 2027”

The later high-risk date does not postpone AI literacy, prohibited-practice controls, transparency duties or GDPR and employment-law analysis.

“A human checked it”

A nominal reviewer may not provide meaningful oversight. Define authority to challenge, override, document and stop the system.

“A footer solves labelling”

Website disclosure, user notice and machine-readable marking answer different questions. Match the control to the content and channel.

“Only official AI tools count”

Shadow AI used with company data can create the same confidentiality, data-protection and output risks as an approved platform.

Frequently asked questions

Does the AI Act apply if our parent company is outside the EU?

It may. Scope can arise because the Romanian entity deploys an AI system in the Union or because output from a third-country system is used in the Union. Analyse the actual provider, deployer, importer and output-use roles.

Are AI recruitment tools high-risk from 2 August 2026?

Not necessarily under the current transition timetable. Annex III includes recruitment and worker-management uses, but the Commission currently identifies 2 December 2027 for the selected sensitive high-risk areas after the Digital Omnibus changes. GDPR, employment and anti-discrimination duties can apply earlier.

Must employees disclose every use of ChatGPT or another writing assistant?

No universal AI Act rule requires disclosure of every private drafting step. The right control depends on the system, output, audience, content type, company policy and whether Article 50 applies. The employer should set a clear internal policy for confidential or regulated material.

Is an AI officer mandatory in Romania?

The AI Act does not impose a universal AI-officer title for every company. A foreign group should nevertheless allocate responsibility for inventory, classification, training, procurement, transparency, incidents and regulatory liaison.

Does using a human reviewer remove AI Act and GDPR risk?

No. Meaningful human oversight can be important, but it does not erase the underlying classification, transparency, data-protection, fairness or employment-law analysis. The reviewer must have information, time and authority to challenge the output.

Can we rely entirely on the AI vendor’s compliance statement?

No. Vendor material should be verified against the Romanian workflow, contract, data, users and role allocation. Keep evidence of the questions asked, the answers received and the decision made by the company.

Need to assess AI use in a Romanian business?

A Romanian business lawyer can help map the group structure, classify AI systems, review vendor terms, align GDPR and employment safeguards, and prepare a proportionate evidence file.

Contact Atrium Romanian Lawyers

This page provides general information only and does not constitute legal advice, a legal opinion or the creation of a lawyer-client relationship. Legal solutions depend on the specific facts, systems, contracts and legislation in force at the relevant time.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.