Obtaining a Romanian Class II gambling license answers an entry question: may this company provide the licensed service? It leaves management with a harder one: how does the company stay operational, compliant and commercially viable once it is licensed? This guide reflects the legal framework as reviewed on 10 October 2026.
The answer lies in connecting decisions that are usually made separately. Sales chooses customers, engineering controls access, finance pays the regulatory charges and compliance prepares the reports. A sustainable supplier needs all four working from the same understanding of its permitted activities, its customers and its costs. Otherwise a commercially attractive contract can bring obligations the technology cannot meet, and an apparently profitable account can absorb more compliance and support effort than its margin covers.
For Class II suppliers, Law 141/2025 made that connection essential. Its amendments to OUG 77/2009 tightened the restrictions on supporting unlicensed gambling and introduced specific technical and reporting duties, which must now be read together with Law 239/2025. The practical goal is a business that can demonstrate lawful delivery every day and can afford to keep doing so. The license itself, its fees and the application route are covered in our Romania Class 2 (B2B) license guide.
Start from the licensed activity
Class II licenses are granted by activity. Art. 148 of the methodological norms approved by HG 111/2016 provides for Class II licensing per activity, valid for ten years on condition that the fees are paid. Art. 149 sets different requirements for different suppliers, including software rights, hosting resources and, where applicable, professional qualifications or independence.
Translate the license into a working description of what the company actually sells and delivers, and review it whenever the product or delivery model changes. Moving from software distribution into platform management, adding a payment function or acquiring another supplier can change the analysis.
A useful internal rule: make regulatory classification part of product approval. Before committing to a launch date, identify the activity, the contracting entity, the delivery chain and any additional permission or evidence needed. That avoids discovering a licensing problem after development costs and customer expectations have built up. Where a new entity is needed for the activity, see company formation for a Romanian Class 2 license.
Customer selection is an operational control
Art. 1(5⁴) OUG 77/2009 prohibits Class II licensees from supplying services to remote-gambling entities or domains accessible from Romanian IP addresses without the required ONJN Class I license and valid authorizations. The background to this rule is in Romania bans Class II suppliers from serving unlicensed gambling sites.
A sound onboarding process links the contracting company to the brands, domains, applications and downstream operators that actually use the service. Checking only the contracting intermediary can leave the real distribution chain unexplained. Plan periodic and event-driven reviews of each customer’s status, covering changes in domains, ownership, authorizations and access patterns. Absence from the ONJN blacklist should never be the sole basis for approving a relationship.
Contracts should give the supplier the information and the practical authority to carry out those reviews:
- disclosure of downstream recipients of the service;
- notice of regulatory changes affecting the customer;
- access to the relevant records;
- clear rights to restrict or suspend service where continued delivery would be unlawful.
The suspension mechanism must work outside office hours. A clause that allows intervention only after a long commercial escalation can leave the technical team unable to act when it needs to.
Independent geolocation and blocking
For licensees in software, platform management and hosting, and payment processing, art. 1(5⁵) goes further: their technical solutions must determine players’ real location within the supplier’s own systems, independently of the information passed through platform integration.
That raises a design question for each supplier. What information does the service receive, how reliable is it, and can the system distinguish the relevant operator and access route? Engineering and compliance should agree on the evidence required before choosing a technical solution. Testing should cover:
- missing location data;
- conflicting signals;
- new domains;
- failures in an intermediary’s data feed.
These are practical control recommendations; the statute does not prescribe a single implementation.
Under art. 1(5⁷), as amended by Law 239/2025 (art. XXXV) with effect from 18 December 2025, a covered supplier that identifies an entity without a Class I license allowing gambling access from Romanian territory must block participants’ access to its systems and immediately request remediation.
Operational continuity therefore means being able to stop one unlawful use of the service while keeping delivery reliable everywhere else. Wherever the architecture allows, controls should act at the level of the customer, domain or integration. The incident record should link detection, the licensing assessment, the block, the remediation request and the basis for any later restoration. Agree escalation responsibilities in advance, including who can act when the account owner is unavailable.
Reporting that follows from the process
Two reports come out of this process, with different scopes:
| Report | Provision | Content | Timing |
|---|---|---|---|
| On-request report | Art. 1(5⁶) | Countries from which players access the supplier’s system; identity of the gambling-access providers serving participants in Romania and/or Romanian citizens not tax-resident elsewhere | Whenever ONJN asks |
| Monthly consolidated report | Art. 1(5⁸) | Number of participants blocked under art. 1(5⁷) and the domains, platforms and applications used | By the 10th of each month, inclusive, for the previous month |
The on-request provision still refers to Romanian citizens without tax residence elsewhere, while the blocking trigger now concerns access from Romanian territory. A reporting process should distinguish:
- participants from sessions or rejected requests;
- statutory blocks from fraud or responsible-gambling restrictions;
- a verified absence of reportable events from missing data.
Where a company files nil returns, it should document the basis and confirm the applicable ONJN filing arrangements: art. 1(5⁸) contains no express zero-activity exemption, but it does not set out a detailed nil-return procedure either. Each element of both reports is explained in Class II reporting obligations under Law 141/2025.
Corporate changes and the regulatory inbox
Corporate administration needs its own route into compliance. Art. 12(2) OUG 77/2009 requires significant changes to be notified within 48 hours through online submission, or within five working days from registration of the change for postal or registry submission. ONJN Order 33/2025 lists the changes, including beneficial-owner details, administrators, shareholders, registered office, company name, share capital and relevant ancillary-service contracts. Whether a given change applies depends on the change and the licensed business.
Legal, finance, procurement and company-secretarial teams should therefore flag changes before they are implemented; a monthly reporting meeting is too slow for a 48-hour deadline.
The regulatory inbox also needs an owner and cover during absences. Art. 149(4) of the norms requires Class II holders to provide an electronic address and treats documents sent there as communicated. A non-resident EU/EEA licensee acts through its authorized representative in Romania, so the representative and the licensee must agree in writing who watches that inbox and how fast documents are passed on. We provide this as part of our Romanian representation and ONJN reporting service.
AML and data protection: map the real role
Compliance also needs accurate boundaries. ONJN’s AML instructions (Order 370/2021, arts. 2–3) define the gambling-service provider by reference to organizing and operating gambling and distinguish it from a supplier acting as a commercial partner. A Class II supplier should assess its actual activities, and any other regulated status, before deciding which direct AML obligations apply. A payment-services business warrants a different assessment from a business limited to software distribution.
Record that assessment and revisit it when the business changes. Agree how the company supports customers’ lawful information requests: a customer’s due-diligence questionnaire, a contractual information obligation and a direct statutory reporting duty are different things, and treating them as one creates either gaps or unnecessary cost.
Data protection needs the same precision, because GDPR duties follow the actual processing role:
- where the supplier processes personal data for an operator, art. 28 GDPR governs the processing agreement and any subcontracting;
- processing for the supplier’s own compliance purposes needs a separate assessment of role and legal basis;
- retention, access controls and international transfers (Chapter V) should reflect those purposes;
- under art. 33, a processor notifies the controller of a personal-data breach without undue delay; the controller’s notification to the supervisory authority is generally due within 72 hours, subject to the statutory conditions.
Build these duties into incident response. An outage may require customer communication, a security investigation and preservation of reporting evidence at the same time. Recovery exercises should test whether the company can restore both the service and its compliance controls: restoring transaction processing while location checks or event records stay down creates a new problem during recovery.
The commercial model: fees, pricing and margin
The commercial analysis starts with the recurring cash commitments set by statute:
| Item | Amount | When | Basis |
|---|---|---|---|
| Annual license fee, per listed Class II category | €20,000 | At least ten days before each yearly anniversary | OUG 77/2009 Annex; HG 111/2016, art. 148 |
| Annual Class II contribution | €15,000 | By 25 January for later years | OUG 77/2009, art. 10(4) and (6) |
| Total for one category | €35,000 a year |
That is a planning example for one licensed category, not a full cost estimate. The budget must also cover staff, legal support, technical controls, hosting, security, testing or certification where relevant, insurance and ordinary tax. Several licensed activities each need their own fee assessment. The one-off costs of getting licensed are on the Class 2 license page.
Price each customer at its real cost to serve. A low-volume account that needs bespoke integrations, repeated investigations and heavy regulatory support may be worth less than a smaller contract running on standard controls. Commercial teams should define:
- which support is included in the price;
- how exceptional work is charged;
- when a change in law triggers a review of scope or price.
Revenue-share agreements need particular care over permitted deductions, reporting access and reconciliation rights: the nominal percentage alone does not show what the supplier actually earns.
A simple illustration: if the annual fixed costs attributable to the Romanian business are €120,000 and the contribution margin after variable delivery costs is 60%, the business needs €200,000 of annual revenue to cover those fixed costs (€120,000 ÷ 0.60). Both inputs are assumptions, not Romanian market benchmarks. Test the result against slower customer onboarding, late payments, rising support costs and the loss of the largest account.
Liquidity, accountability and sanctions
Liquidity lets management make the right decisions without weakening controls. A supplier that depends on one customer’s next payment will find a required suspension commercially painful even when the legal position is clear. A practical cash plan reserves the upcoming regulatory payments and models a period of interrupted revenue. Customer concentration, overdue receivables and reliance on a single hosting or integration partner deserve regular management attention. All recurring dates are collected in the deadlines and taxes that keep your license alive.
Accountability makes the model durable. A monthly management review should bring together:
- upcoming payments and filings;
- unresolved customer-status questions;
- reporting exceptions and service incidents;
- receivables and customer-level margins.
Each issue needs an owner and a decision date. Periodic sampling of real incidents and submissions shows whether the written procedures match how the company actually works.
The stakes justify the effort. Prohibited supply and misleading information to the authorities can engage the criminal provisions of art. 25 OUG 77/2009, and art. 25(3) expressly links the offense in paragraph (1)(m) to revocation of the Class II license. The specific conduct and its legal elements matter, so different failures should not be treated as carrying one generic sanction.
The standard to aim for
A commercially durable Class II business can show how each customer was approved, how its services stay within scope, how incidents are handled and how delivery is funded. Its managers know which revenue they can keep earning lawfully and which commitments they can support profitably. That is the standard after licensing: reliable service, demonstrable compliance, and enough financial resilience to maintain both.
This article is general legal information, not advice on a particular company’s circumstances. Confirm ONJN’s current filing channels and templates before submitting reports or notifications.