GDPR Compliance Policy

1. Introduction and Purpose

1.1. General Statement of Commitment

Romania for Business (“the Company”, “we”, “us”, “our”) is committed to protecting the privacy and personal data of everyone whose information we process in the course of our activities, including clients, prospective clients, website visitors, employees, contractors, and business partners. This GDPR Compliance Policy (“Policy”) sets out, in a structured and detailed manner, the principles, safeguards, and procedures that govern our processing of personal data, and reflects our accountability obligations under Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the “GDPR”).

1.2. Complementary Romanian Legislation

Because the Company operates from, and provides services within, Romania, this Policy is also framed with reference to the domestic legislation that supplements the GDPR, most notably:

  • Law No. 190/2018 on measures implementing the GDPR, which addresses matters left to the discretion of Member States, including certain rules on the processing of special categories of data and on penalties;
  • Law No. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector, which governs matters such as cookies, direct marketing communications, and traffic data, and which is addressed in more detail in our separate Cookie Policy; and
  • Guidance, decisions, and enforcement practice issued by the National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, “ANSPDCP”), Romania’s national data protection authority.

1.3. Purpose of This Document

This Policy serves two complementary purposes. First, it provides transparency to individuals about how their personal data is handled by the Company, in fulfilment of our information obligations under Articles 13 and 14 of the GDPR. Second, it functions as an internal governance document, setting expectations for our staff, consultants, and partners regarding the standards to be observed whenever personal data is collected, used, stored, or shared in connection with our business.

2. Who We Are and How to Reach Us

2.1. Data Controller

For the purposes of the GDPR, Romania for Business acts as the data controller in respect of personal data processed through our website, our client relationships, and our general business operations, except where expressly stated otherwise (for example, where we act as a data processor on behalf of a client under a separate data processing agreement).

2.2. Contact Details

  • Email: info@romania-for-business.com
  • Website: https://romania-for-business.com/

2.3. Data Protection Contact Point

Depending on the scale and nature of our processing activities, we may designate an internal Data Protection Officer (DPO) or an equivalent responsible contact person, in line with Articles 37 to 39 of the GDPR.

3. Principles Governing Our Processing of Personal Data

We structure all our data processing activities around the core principles set out in Article 5 of the GDPR. In practical terms, this means:

3.1. Lawfulness, Fairness, and Transparency

  • We only process personal data where we have identified and can demonstrate a valid legal basis for doing so, as described in Section 5 below.
  • We aim to be open and clear with individuals about what data we collect, why we collect it, and what we do with it, avoiding hidden or unexpected uses.

3.2. Purpose Limitation

  • We collect personal data for specified, explicit, and legitimate purposes, which are communicated to the individual concerned at or before the point of collection.
  • We do not further process personal data in a manner that is incompatible with those original purposes, unless a new legal basis is established and, where required, the individual is informed accordingly.

3.3. Data Minimisation

  • We seek to limit the personal data we collect to what is genuinely adequate, relevant, and necessary in relation to the purposes for which it is processed.
  • Where a service can reasonably be delivered with less data, we aim to adjust our intake forms and procedures accordingly.

3.4. Accuracy

  • We take reasonable steps to ensure that personal data we hold is accurate and, where necessary, kept up to date.
  • Individuals are encouraged to inform us promptly of any changes to their personal details, and we will correct inaccurate data without undue delay upon becoming aware of it.

3.5. Storage Limitation

  • We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable legal, regulatory, or professional retention obligations (see Section 8 below).
  • Once a retention period expires and no overriding legal basis for continued storage exists, we securely delete or anonymise the relevant data.

3.6. Integrity and Confidentiality

  • We implement appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage, as further described in Section 9 below.

3.7. Accountability

  • We maintain internal records, policies, and procedures sufficient to demonstrate our compliance with the principles above, including this Policy, our records of processing activities, and, where applicable, data protection impact assessments.

4. Categories of Personal Data We Process

4.1. Client and Prospective Client Data

This may include, depending on the nature of the engagement, identification details (name, date of birth, nationality, identification document numbers), contact details, company affiliation and role, details relevant to the corporate or business services requested (such as shareholding structure, beneficial ownership information, or tax identification numbers), and correspondence exchanged in the course of the engagement.

4.2. Website Visitor Data

This includes information collected automatically when visiting our website, such as IP address, browser type, device information, pages visited, and cookie-derived identifiers, as described in greater detail in our separate Cookie Policy.

4.3. Employee, Contractor, and Partner Data

Where applicable, this includes data relating to our own personnel and associated professionals, such as contact and identification details, professional qualifications, and information necessary for the administration of the employment or engagement relationship.

4.4. Special Categories of Data

We do not, as a rule, seek to collect special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious beliefs, health data, or biometric data) within the meaning of Article 9 of the GDPR, unless such data is incidentally and unavoidably necessary for a specific, clearly identified purpose connected to a client engagement, in which case additional safeguards and, where required, explicit consent or another Article 9 legal basis will be applied.

5. Legal Bases for Processing

Depending on the specific activity in question, we rely on one or more of the following legal bases under Article 6(1) of the GDPR:

5.1. Performance of a Contract

  • Where processing is necessary to perform a contract with a client, or to take steps prior to entering into a contract at the client’s request, such as preparing a proposal or conducting preliminary due diligence.

5.2. Legal Obligation

  • Where processing is required to comply with a legal obligation to which we are subject, including obligations arising under anti-money laundering legislation (see our AML Policy), tax law, or accounting and record-keeping requirements.

5.3. Legitimate Interests

  • Where processing is necessary for our legitimate interests, or those of a third party, and those interests are not overridden by the interests or fundamental rights and freedoms of the individual concerned. Examples include maintaining the security of our website, communicating with prospective clients who have expressed interest in our services, and improving our services through aggregated analytics.
  • Where we rely on legitimate interests, we conduct a balancing assessment to confirm that the processing is proportionate and that adequate safeguards are in place.

5.4. Consent

  • Where processing depends on the individual’s consent, such as certain non-essential cookies or, where applicable, direct marketing communications, we obtain that consent freely, specifically, and in an informed manner, and we allow it to be withdrawn as easily as it was given.

5.5. Vital Interests and Public Interest

  • These bases are not typically relevant to our ordinary business activities but are retained here for completeness and would only be invoked in exceptional circumstances permitted by law.

6. How We Use Personal Data

6.1. Delivering Our Services

  • To assess client needs, prepare proposals, carry out company formation, registered office, tax, accounting liaison, and business consultancy services, and to communicate with clients throughout the engagement.

6.2. Compliance with Legal and Regulatory Obligations

  • To satisfy our obligations under anti-money laundering legislation, tax reporting requirements, and other applicable Romanian and EU law, including retaining records for the periods described in our AML Policy and Section 8 below.

6.3. Communication and Client Relationship Management

  • To respond to enquiries, provide updates on ongoing engagements, and, where appropriate and consented to, share relevant updates about our services.

6.4. Website Operation and Improvement

  • To operate, secure, and improve our website, and to understand, in aggregate, how visitors use our online content, as further described in our Cookie Policy.

6.5. Complaint Handling

  • To investigate and resolve complaints in accordance with our Complaint Handling Policy.

7. Sharing and Disclosure of Personal Data

7.1. Categories of Recipients

We may share personal data, strictly on a need-to-know basis, with the following categories of recipients:

  • Professional advisers and service providers engaged by the Company, such as accountants, notaries, translators, or IT service providers, bound by appropriate confidentiality and, where relevant, data processing arrangements;
  • Romanian public authorities and registries, such as the National Trade Registry Office (ONRC), tax authorities (ANAF), and, where legally required, the National Office for Prevention and Control of Money Laundering (ONPCSB);
  • Courts, arbitral tribunals, or law enforcement authorities, where disclosure is required or permitted by law;
  • Any successor entity in the event of a corporate reorganisation, merger, or transfer of business, subject to appropriate safeguards.

7.2. No Sale of Personal Data

We do not sell, rent, or otherwise trade personal data to third parties for their own independent marketing purposes.

7.3. International Transfers

  • Where personal data is transferred outside the European Economic Area (EEA), for example when using a cloud service provider or software tool with servers located outside the EEA, we ensure that an appropriate transfer mechanism is in place, such as an adequacy decision issued by the European Commission, the European Commission’s Standard Contractual Clauses, or another mechanism recognised under Chapter V of the GDPR.
  • We select service providers and tools with due regard to their own data protection safeguards and, where necessary, incorporate additional contractual and technical measures to protect data transferred internationally.

8. Data Retention

8.1. General Approach

  • We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, taking into account the nature of the data, the purpose of processing, and any applicable statutory retention obligations.

8.2. Specific Retention Periods

  • Client due diligence documentation and related records are retained for a minimum of five (5) years following the end of the business relationship, in accordance with anti-money laundering legislation and our AML Policy.
  • Accounting and tax-related records are retained for the periods prescribed under Romanian fiscal and accounting legislation.
  • Complaint records are retained for a minimum of three (3) years, in accordance with our Complaint Handling Policy.
  • Website analytics and cookie-derived data are retained in accordance with the periods described in our Cookie Policy.

8.3. Deletion and Anonymisation

  • Upon expiry of the applicable retention period, and provided no overriding legal ground for continued retention exists, personal data is securely deleted or irreversibly anonymised.

9. Security Measures

9.1. Technical Measures

  • We employ appropriate technical safeguards, which may include encryption of data in transit and at rest where appropriate, access controls, firewalls, and secure backup procedures, calibrated to the risk associated with the relevant processing activity.

9.2. Organisational Measures

  • We limit access to personal data to personnel and associated professionals who require it to perform their duties, and we provide training on data protection obligations, in line with our AML Policy’s training requirements where relevant.
  • We enter into confidentiality and, where appropriate, data processing agreements with third parties who process personal data on our behalf.

9.3. Incident Response

  • In the event of a personal data breach, we assess the risk to the rights and freedoms of affected individuals and, where required under Articles 33 and 34 of the GDPR, notify ANSPDCP without undue delay, and in any event within seventy-two (72) hours of becoming aware of the breach where feasible, and communicate the breach to affected individuals where the breach is likely to result in a high risk to their rights and freedoms.

10. Rights of Data Subjects

Subject to the conditions and exceptions set out in the GDPR, individuals whose personal data we process have the following rights, each of which can be exercised by contacting us at the details set out in Section 2 above:

10.1. Right of Access (Article 15)

  • The right to obtain confirmation as to whether we process personal data concerning the individual, and, if so, to obtain a copy of that data together with certain supplementary information about the processing.

10.2. Right to Rectification (Article 16)

  • The right to request correction of inaccurate personal data, and to have incomplete personal data completed.

10.3. Right to Erasure (“Right to Be Forgotten”) (Article 17)

  • The right to request deletion of personal data in certain circumstances, such as where the data is no longer necessary for the purpose for which it was collected, subject to any overriding legal obligation we may have to retain it.

10.4. Right to Restriction of Processing (Article 18)

  • The right to request that we limit the way we use personal data in certain circumstances, for example while the accuracy of the data is being verified.

10.5. Right to Data Portability (Article 20)

  • The right, where processing is based on consent or contract and carried out by automated means, to receive personal data provided to us in a structured, commonly used, and machine-readable format, and to have it transmitted to another controller where technically feasible.

10.6. Right to Object (Article 21)

  • The right to object, on grounds relating to the individual’s particular situation, to processing based on legitimate interests, and an unconditional right to object to processing carried out for direct marketing purposes.

10.7. Rights Related to Automated Decision-Making (Article 22)

  • The Company does not currently engage in decision-making based solely on automated processing, including profiling, which produces legal effects concerning individuals or similarly significantly affects them. Should this change, individuals will be informed and afforded the rights set out in Article 22 of the GDPR.

10.8. Right to Withdraw Consent

  • Where processing is based on consent, the right to withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

10.9. Right to Lodge a Complaint

  • The right to lodge a complaint with ANSPDCP, or with the supervisory authority of another EU Member State where the individual resides, works, or where the alleged infringement occurred, as further described in Section 11 below.

10.10. How We Respond to Requests

  • We respond to requests to exercise these rights without undue delay, and in any event within one (1) month of receipt, extendable by a further two months for complex or numerous requests, in which case we will inform the individual of the extension and the reasons for it within the first month, in accordance with Article 12(3) of the GDPR.
  • We may request additional information to verify the identity of the person making the request, where reasonably necessary to ensure personal data is not disclosed to an unauthorised party.

11. Supervisory Authority

11.1. Right to Lodge a Complaint

Without prejudice to any other administrative or judicial remedy, every individual has the right to lodge a complaint with a supervisory authority if they consider that the processing of their personal data infringes the GDPR.

11.2. Romanian Supervisory Authority

  • Name: National Supervisory Authority for Personal Data Processing (ANSPDCP)
  • Website: https://www.dataprotection.ro/

We encourage individuals to contact us first at info@romania-for-business.com so that we may attempt to resolve any concern directly, though this is not a precondition to lodging a complaint with ANSPDCP or pursuing judicial remedies.

12. Related Policies

This Policy should be read together with our other published policies, which address specific aspects of our data protection and compliance framework in greater detail:

  • Privacy Policy, addressing our processing of personal data in relation to the website and client relationships more broadly;
  • Cookie Policy, addressing our use of cookies and similar technologies;
  • AML Policy, addressing our obligations under anti-money laundering legislation, including client due diligence and record-keeping;
  • Complaint Handling Policy, addressing how complaints, including data protection complaints, are received and resolved.

13. Updates to This Policy

13.1. Review Cycle

We review this Policy at least annually, and more frequently where required by changes in applicable law, guidance issued by ANSPDCP, or material changes to our processing activities.

14. Contact

Romania for Business
Email: info@romania-for-business.com
Website: https://romania-for-business.com/

This Policy is published for the information of clients, prospective clients, and visitors to the Romania for Business website, and reflects our internal data protection governance framework under the GDPR and applicable Romanian legislation. It does not constitute legal advice.