You will be redirected to the website of our parent company, Schönherr Rechtsanwälte GmbH: www.schoenherr.eu
On 14 July 2026, a ransomware attack fully compromised the IT systems of the National Agency for Cadastre and Land Registration (ANCPI). The e-Terra platform, e-mail services and internal applications became non-functional. The consequences are unprecedented. Notaries cannot authenticate deeds. Banks cannot grant mortgage loans. Developers cannot complete cadastral receptions. Thousands of transactions remain suspended.
The central question is simple, but the stakes are enormous: can this cyberattack qualify as force majeure within the meaning of Art. 1351 of the Civil Code? The answer matters in practice, not just in theory. It determines whether market participants can avoid penalties, whether developers can invoke an objective impossibility to comply with permitting deadlines, and whether the transactional chain can be unblocked without major financial losses.
The validity periods of building permits, urbanism certificates and endorsements run imperatively, regardless of whether the State's IT systems are operational. Law No. 50/1991 conditions the issuance of a building permit on the submission of an updated land book excerpt and a cadastral plan excerpt issued by the OCPI (the local cadastre and land registration office).
The gridlock creates a vicious circle: the investor who needs to apply for an extension of the building permit cannot obtain the required cadastral documentation, and the expiry of the permit entails restarting the entire procedure, with all associated costs and urban planning risks. In parallel, urbanism certificates still within their validity period but which can no longer be used to support a timely permit application — due to the lack of cadastral documentation — risk expiring without having produced their intended effect, forcing the investor to restart this stage as well, with new costs and timelines. The consequence is the same: the irreversible loss of administrative rights, caused by an event the investor did not bring about.
A pragmatic solution would be to submit the permit application file based on the most recent land book excerpt available, accompanied by a sworn statement in which the applicant confirms that the legal status of the property has not changed, together with an undertaking to supplement the file as soon as ANCPI's services become operational again. Law No. 50/1991 allows the file to be supplemented within a maximum period of three months from notification by the issuing authority, and the urbanism certificate and endorsements would be deemed submitted within their validity period, thus preventing the irreversible loss of administrative acts obtained at significant cost and effort, due to a gridlock the applicant did not cause.
Alternatively, legislative intervention is required to extend the administrative deadlines affected by the incident. In this regard, we welcome the initiative of the College of Geodesists of Romania (Colegiul Geodezilor din România)[1] to officially request such an extension, confirming that the gridlock affects public-law deadlines that no private participant can suspend or modify in the absence of an express legal basis.
In complex transactions (M&A, project finance), contracts provide for conditions precedent linked to the registration of the project's real rights in the land book. In the current context, these conditions are objectively impossible to satisfy. The potential consequences include expiry of drawdown deadlines, loss of financing and, in extreme cases, failure to complete the transaction where the relevant conditions cannot be satisfied by the long-stop date.
Renewable energy projects (photovoltaic and wind farms, BESS) depend on cadastral operations at every critical stage, from the registration of land rights to permitting documentation. Grid connection agreements, CfDs and building permit deadlines contain no suspension mechanisms correlated with the unavailability of state systems: failure to meet a grid connection deadline results in the irreversible loss of allocated capacity. The financial exposure, quantifiable in millions of euros, cannot realistically be recovered from either ANCPI or the perpetrators of the attack.
Art. 1351(2) of the Civil Code defines force majeure as any event that is external, unforeseeable, absolutely insurmountable and unavoidable — cumulative conditions. The analysis below applies from the perspective of real estate market participants (sellers, buyers, developers, banks, notaries), not from the perspective of ANCPI. The distinction is fundamental: even if ANCPI could be considered at fault for cybersecurity deficiencies, market participants cannot, under any circumstances, be held liable for this.
International precedent supports this analysis, even if it does not provide a uniform solution. Internationally, the ransomware attack on the Cadastral Office of the Slovak Republic (January 2025) generated professional opinions in favour of a force majeure qualification, while noting that deadlines are not automatically extended by the mere invocation of that classification. In January 2022, two German companies (Oiltanking and Mabanaft) publicly declared force majeure following a cyberattack (confirmed by Reuters, BBC and AP) — the most explicit precedent of this kind worldwide. International practice nevertheless remains divided, with outcomes varying according to the specific circumstances of each case.
Force majeure, even where established, does not automatically extend contractual, statutory or administrative deadlines. It operates as a mechanism for exemption from liability in contractual relationships, not as a tool for extending deadlines. A finding of force majeure suspends liability for non-performance, but does not substitute for the parties' will or modify ope legis the deadlines agreed by the parties or prescribed by law. This gives rise to a paradoxical situation: market participants benefit from an exonerating cause, but, absent proactive steps on their part, have no certain legal basis for extending the very deadlines whose non-compliance is justified by that cause.
We recommend at least three categories of immediate actions:
We also recommend that future contracts include force majeure clauses explicitly covering cyberattacks on public IT systems, providing for automatic suspension mechanisms and correlative extension of contractual deadlines for the duration of the unavailability.
The provisions of Art. 1634(3) and Art. 1557(2) of the Civil Code, applicable to contractual relationships, do not operate with respect to public-law deadlines (validity of building permits, urbanism certificates, approvals). These deadlines cannot be automatically suspended or extended by invoking force majeure, in the absence of an express legal basis. Accordingly, legislative intervention is not merely welcome but indispensable. A relevant precedent is Decree of the President of Romania No. 195/2020 on the establishment of the state of emergency, which provided for the automatic extension of the validity of documents issued by public authorities for the duration of the state of emergency during the COVID pandemic, precisely to fill a gap that private-law mechanisms cannot bridge. Similar legislative intervention is required in the case of the ANCPI gridlock to extend administrative deadlines whose running is contingent on the functioning of an IT system over which the State has a monopoly.
Prior to the attack, the deadline for the delivery of dwellings eligible for the reduced 9 % VAT rate (dwellings not exceeding RON 600,000, excluding VAT, with a maximum usable area of 120 sqm) was set at 31 July 2026. The resulting financial difference can be as much as RON 72,000 per transaction.
Under Law No. 161/2026 (in force as of 7 August 2026), the delivery deadline was extended to 30 September 2026, subject to certain specific conditions. The intervention is welcome, but its positive impact depends heavily on the timely restoration of ANCPI's systems.
Through this extension, the legislator implicitly acknowledged that the ANCPI gridlock generates an objective impossibility to complete real estate transactions. The same rationale applies, a fortiori, to developers exceeding, through no fault of their own, the deadlines in their permits, to investors unable to fulfil conditions precedent, and to renewable energy operators who cannot meet grid connection deadlines.
In our view, the cyberattack on ANCPI meets the cumulative conditions for qualification as force majeure from the perspective of real estate market participants, with the caveat that unforeseeability remains the condition most exposed to challenge. The incident highlights a structural vulnerability: e-Terra is not a mere digital tool but the critical infrastructure on which Romania's entire real estate circuit depends — from the authentication of notarial deeds and the granting of mortgage loans to the issuance of building permits and the grid connection of renewable energy projects. The consequences of the gridlock — contractual, administrative and fiscal — differ significantly from case to case, depending on the type of operation affected, the applicable clauses and the stage of the transaction at the time of the incident. There is, therefore, no one-size-fits-all solution that can be mechanically applied to all situations. In a context without precedent for Romania's real estate market, an individualised legal assessment of each situation and the prompt adoption of appropriate protective measures are not merely advisable but essential for limiting damages.
Mădălina
Mitan
Partner
romania