GD 602/2026: what data WorkinRomania.gov.ro processes, how it is protected and which registers are interconnected
Government Decision no. 602/2026, published in the Official Gazette no. 658 of 7 August 2026 and in force from the same day, is the act that puts "flesh" on the WorkinRomania.gov.ro platform. GEO 32/2026 said that a platform exists and what is done through it; GD 602/2026 says how it actually works: what data it collects about employers, agencies and workers, which state registers it connects to, what checks it performs automatically, who is responsible for security and what rights the person whose data ends up there has.
The decision was adopted under art. 3 para. (7) of GEO 32/2026 and matters to three groups of readers: employers (because it defines the operations in the platform and who may perform them), placement agencies (same rules, plus the complaints regime) and foreign workers (because their data is what is processed, and the complaint function is dedicated to them).
Who runs the platform and how it is built
The platform is a module of the MAI services hub (hub.mai.gov.ro), developed and technically administered by the Ministry of Internal Affairs through the General Directorate for Communications and Information Technology (DGCTI) — art. 3 para. (1). The module for registering and authorising employers and agencies is operationally administered by ANOFM, which configures the workflows and manages the accounts of the structure administrators in each institution — art. 3 para. (2).
Architecturally there are two components (art. 3 para. (3)–(5)):
- the public component, accessible on the internet at WorkinRomania.gov.ro, for individuals, employers and agencies;
- the internal component, exposed only through the MAI network (RCVD) and STS Extranet, used by institutional staff to process applications.
The internal component sends applications, documents and verification results to the own systems of IGI, MAE, ANAF and the Ministry of Education and Research, in a secure two-way exchange with traceability of operations — art. 3 para. (6)–(7). If the interconnection goes down, internal accounts remain available — art. 3 para. (8).
The 10 state registers it interconnects with
Art. 4 para. (1) lists the registers the platform links to directly:
| # | Register | Institution / legal basis |
|---|---|---|
| a | National Register of Persons | GEO 97/2005 |
| b | IGI IT records (applications, documents, regime of foreigners) | IGI |
| c | Register of declared job vacancies | ANOFM, art. 10 Law 76/2002 |
| d | Records of the National Trade Register Office | ONRC |
| e | eViza portal | MAE, art. 65 Law 62/2019 |
| f | REGES-ONLINE | Labour Inspection, GD 295/2025 |
| g | IT systems of the Ministry of Finance | MF / ANAF |
| h | National computerised criminal records system | IGPR, art. 34 Law 290/2004 |
| i | National automated register of persons who committed sexual offences, exploitation or offences against minors | Law 118/2019 |
| j | CNRED database | Ministry of Education and Research |
Additionally, the platform has a separate file-based mechanism for exchanging information with the National Office for Preventing and Combating Money Laundering — art. 4 para. (3).
In practice, this means that some of the conditions an official used to check on paper (tax status, criminal record, existence of the company, declared vacancy) are checked automatically, and documents are uploaded only where the condition cannot be verified directly by the authority — art. 10 para. (2).
What personal data is processed
Art. 5 is the exhaustive list of data about individuals processed in the platform:
- identification: surname, first name, date and place of birth, personal numeric code (CNP), current citizenship and citizenship at birth, sex, address of domicile/residence abroad or in Romania;
- travel and residence documents: series and number of passport/visa/residence permit, issuing authority, date of issue and expiry;
- contact: e-mail, telephone, fax;
- work and means of support: data on the workplace, proof of means of support, travel medical insurance;
- criminal history: history of final criminal convictions;
- family: marital status, name of spouse, data on children and family members;
- capacity in relation to the applicant entity (administrator, shareholder, legal representative, designated person etc.);
- status of tax debts;
- travel itinerary;
- capacity as host entity.
Who is the "data subject"? Not only the foreign worker, but also the legal representatives, shareholders, associates and administrators of companies and agencies, as well as the persons designated to operate in the platform — all fall under the definition of external user in art. 2 para. (1) letter e).
The external user and designated persons
The account in the platform belongs to the external user: the individual, legal representative, shareholder, associate or administrator of the entity — art. 2 para. (1) letter e). They may designate one or more persons with whom the entity has an employment contract or another legal relationship — art. 8 para. (1).
Designated persons may (art. 8 para. (2)): upload documents for authorisation or extension, applications for registration as employer, documents on foreign placement entities, complete and submit single applications for foreigners, upload data and documents and track the status of applications.
Two important limits:
- Initiating the application for registration as employer, authorisation as authorised employer or authorisation/extension as agency is done exclusively by the external user — art. 8 para. (3). The designated person continues, does not start.
- The designated person operates only after confirming the designation in the platform — art. 8 para. (4).
Liability for data and documents entered by designated persons stays with the entity — art. 8 para. (5). Revocation is done from the platform, takes effect immediately and does not affect operations already carried out — art. 8 para. (6). The entity has an obligation to periodically check the list of designated persons and to immediately revoke those who have left the company or are no longer authorised to act — art. 8 para. (7). For an HR department this means a new routine: on every departure from the team, revoking access in WorkinRomania.gov.ro goes on the offboarding list.
How an application is generated: the automatic checks
The registration/authorisation application is generated only after the user (art. 10 para. (3)):
- confirms that the identification data are real and current;
- gives consent for the processing of personal data;
- and the platform automatically finds that the uploaded documents are signed with a qualified electronic signature.
Documents are uploaded electronically, signed with qualified signature, only for the conditions the authorities cannot verify directly — art. 10 para. (2). The application may be withdrawn until it is resolved by ANOFM — art. 10 para. (4).
For the single application (long-stay visa for employment or extension of the right of stay for work, where GEO 194/2002 provides for filing through the platform), generation happens only after full completion of the forms and after the system automatically checks that documents have been uploaded for all categories required by GEO 194/2002 and that the numerical limits on foreigners employed or placed under GEO 32/2026 are respected — art. 11 para. (3). The extension application can be withdrawn until resolved; the visa application only until it is sent to eViza — art. 11 para. (4).
The firm job offer and automatic rejection
Art. 12 contains the rule with the biggest practical impact for employers:
- The firm job offer is retrieved automatically from ANOFM's register of vacancies declared under art. 10 of Law 76/2002; the user only fills in the additional information — para. (1).
- The platform automatically checks whether the occupation in the offer appears on the List of shortage occupations — para. (2).
- Offers that do not mention an occupation from the list are rejected automatically, with notification to the user and designated persons — para. (3).
Consequence: if the job was not declared vacant at ANOFM or the occupation is not on the list (or is written with a different COR code from the one on the list), the offer never even reaches an official. Check the list and the vacancy declaration before entering the platform.
Scheduling of filings and queue transparency
Art. 9 allows DGCTI to configure mechanisms for scheduling the filing of applications, at the request of ANOFM, IGI or MAE, in relation to their operational capacity, respecting transparency, non-discrimination and proportionality. Scheduling is configured separately for each application type (registration, employer authorisation, agency authorisation) and, for single applications, separately for D/AM1 and D/AM2 visas — para. (3)–(4). The platform must publicly display the number of applications filed, in processing and resolved — para. (5). In other words, there may be filing windows, and the queue is visible.
Resolution and communication of acts
Applications are analysed by internal users through the internal component or through the own systems of interconnected institutions; decisions are recorded in the platform and underpin the administrative act — art. 14 para. (1)–(2). Administrative acts issued under GEO 32/2026 or GEO 194/2002 are communicated through the platform and can be seen in the account of the external user and designated persons — para. (3). The platform automatically sends SMS and e-mail notifications to the contact details linked to the accounts, about the need to access the platform — para. (4). Don't wait for the envelope: check the account.
Art. 16 adds a mechanism that works on its own: depending on sanctions applied, the platform automatically updates the status of the employer or agency, applies technical restrictions on placing new foreigners and automatically unlocks the functions for changing employer.
Complaints by foreign workers
Art. 2 para. (1) letter f) defines the complaint as the function through which foreigners with an employment contract can report situations of abuse. Art. 15 details it: standardised electronic form, with multilingual support, in which the situation is described and documents or multimedia files (photo, video, audio) can be uploaded — para. (1)–(2). The complaint is routed automatically, through secure channels and in real time, to the competent authority, and the complainant's identification data are accessible exclusively to the authorities resolving it — para. (3). The minimum recipients are the Labour Inspection, IGI and ANOFM — para. (4). The platform allows communication between complainant and authority through the dedicated module, and the authority uploads its conclusions and measures — para. (5)–(6).
For the worker, this means an official channel that does not pass through the employer or agency, and in which their identity is not visible to any entity other than the authority doing the check.
Security measures
DGCTI, as technical administrator, must ensure at least (art. 17 para. (1)): user authentication, including multi-factor for public component accounts; access and privilege control; encryption of data in transit and at rest; intrusion detection and prevention; network segmentation; logging of operations; monitoring of security events; backup and disaster recovery; continuous monitoring of availability and integrity. Interconnected institutions are each responsible for the security of their own systems — art. 7 para. (2). Cyber incidents are reported promptly to the CSIRT within MAI's General Directorate for Internal Protection — art. 17 para. (3). DGCTI must make detailed user guides available through the platform — art. 17 para. (2).
Personal data breach
If a personal data breach occurs, the controller where it happened assesses the breach, consults the other joint controllers and notifies ANSPDCP and/or informs the data subjects, under art. 33–34 GDPR or art. 36 and 39 of Law 363/2018, depending on the purpose of processing — art. 18 para. (1). The assessment involves the data protection officer (DPO), a person from the structure where the incident occurred and, where appropriate, one from IT&C; notification and information are done by the DPO — para. (2)–(3).
How long data and logs are kept
Personal data are stored on Romanian territory, according to the archival nomenclatures of the joint controllers and the National Archives Law 16/1996 — art. 19 para. (1). On expiry of the terms and after selection, data are deleted automatically and irreversibly, except those used in judicial proceedings, which follow the regime of evidence — para. (2).
Separately, the platform keeps a record of processing operations from which one can identify who did what (art. 21): workstation or IP and user, categories of information accessed, type of operation, concrete reason for processing, operation code or program, exact date and time (year, month, day, hour, minute, second) — para. (2). The log is used only for data protection monitoring and security and is deleted after 5 years, with the same judicial exception — para. (3)–(4). Legal persons, public or private, that use the platform set their own internal procedures for compliance with the GD and data protection law — para. (5). The latter is an obligation for the private employer too: having an account is not enough, you must also have a written procedure on who uses it and how.
Training of users
Internal and external users and designated persons are trained on data protection before access is validated and then at least once a year — art. 20 para. (1). Training covers processing exclusively for job duties, under legal procedures and in compliance with data protection law — para. (2) — and is done by the entity's DPO designated under art. 37 GDPR — para. (3). The wording "at entity level" implies that, for a private employer, training the persons it designates is its own responsibility.
Data subject rights
The rights of access, rectification, erasure, restriction etc. are exercised under Chapter III GDPR and handled under the own procedures of the joint controllers (ANOFM, MMFTSS, MAI, MAE, Ministry of Finance, Ministry of Justice) — art. 22 para. (1). Controllers must display, in public spaces and on websites, a guide to exercising rights with the contact details of the controller and the DPO, plus template request forms — para. (2)–(4). Requests for rectification or erasure are notified between controllers immediately — para. (6); a restriction of processing ordered by one of the controllers responsible for data is notified to MAI (the technical administrator) within 24 hours at most — para. (7).
A worker who wants to know what data about them is in the platform can therefore make an access request to any of the joint controllers, using the template form they are obliged to publish.
Public reports and statistics
Art. 6 requires the internal component to generate automatically, anonymised, reports on: the number of employers registered, authorised, suspended and struck off by CAEN codes; agencies authorised, suspended or with authorisation withdrawn, with the number of foreigners for which they were authorised; single applications filed, pending, approved and rejected, broken down by D/AM1 and D/AM2 visa type, by employer/agency and citizenship; visas issued by type; COR occupations for which contracts were uploaded and visas issued; the quota of foreign workers. It is the first time the labour market statistics for non-EU workers can be tracked on the real flow, not on estimates.
What you concretely have to do, as employer or agency
- Validated account in hub.mai.gov.ro for the legal representative/administrator, then registration and validation in WorkinRomania.gov.ro — art. 2 para. (1) letters a)–b).
- Qualified electronic signature for all uploaded documents — art. 10 para. (2)–(3).
- Declare vacancies at ANOFM and check the occupation on the List of shortage occupations before uploading the firm offer — art. 12.
- Designate the persons who operate in the platform, have them confirm the designation, keep the list clean and revoke immediately on departure — art. 8.
- Write an internal procedure for using the platform and protecting data and train the designated persons before access and annually — art. 20, art. 21 para. (5).
- Check the account, not the mail: administrative acts are communicated in the platform, and the SMS/e-mail only alerts you — art. 14.
What it means for the foreign worker
Their data — from passport to marital status and criminal record — is processed by a system with encryption, logging and automatic deletion on expiry, in which every access leaves a trace for 5 years. They have a protected multilingual complaint channel to which the employer and agency have no access. And they have the right to ask any of the joint controllers what data exists about them, using the form those controllers must publish.
This resource is for information purposes and reflects the text of GD no. 602/2026 published in the Official Gazette no. 658 of 7 August 2026, as well as GEO 32/2026 (OG 335/27.04.2026). The official texts and the communications of the competent institutions prevail. For specific situations, we recommend consulting a specialist.