[codicts-css-switcher id=”346″]

Global Law Experts Logo
saas customer refusing pay after platform

Saas Customer Refusing to Pay After a Platform Outage, Romania: What to Do

By Razvan Alexandru Olaru
– posted 1 week ago

When a SaaS customer withholds payment after a platform outage, the dispute is simultaneously commercial, technical and legal. The outcome will usually depend on the contract, the nature and consequences of the outage, the invoices withheld and the quality of the evidence preserved immediately after the incident. Romanian law provides remedies for contractual non-performance, non-payment and, in appropriate cases, force majeure, but none of these outcomes follows automatically from the mere occurrence of downtime.

This guide presents a practical sequence for Romanian providers and customers—from incident triage and contract analysis to negotiation and debt recovery. The suggested timelines and drafting examples are operational recommendations, not statutory deadlines or safe-harbour clauses.

Immediate Steps After Payment Is Withheld

The first objective is to avoid worsening either the evidentiary or contractual position. The provider should preserve the technical record, identify the contractual regime that applied during the incident and ensure that customer communications distinguish confirmed facts from matters still under investigation.

Who should be involved

  • SRE / DevOps: reconstruct the event timeline, affected services, geographic and customer scope, root cause and recovery actions, preserving the underlying logs before routine rotation or deletion.

  • Billing / Finance: identify each outstanding invoice, its due date, contractual interest or dunning status, the amounts genuinely disputed and any credit already calculated or granted.

  • Legal / external counsel: review the governing law, SLA, limitation and sole-remedy provisions, dispute procedure, notice requirements and potential litigation-preservation measures before substantive admissions or enforcement steps are taken.

  • CISO / DPO: determine whether the incident involved a personal data breach and whether notification or documentation duties arise under the GDPR, Law No. 190/2018 or another applicable cyber or sectoral regime.

A platform outage does not automatically start a 72-hour notification period to ANSPDCP. Under Articles 4(12) and 33 GDPR, the controller must first determine whether there has been a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, access to, or loss of availability of personal data. If a personal data breach has occurred, notification to the competent supervisory authority is required without undue delay and, where feasible, within 72 hours after the controller became aware of it, unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. A processor must notify the controller without undue delay under Article 33(2), while the controller remains responsible for the authority-notification assessment.

Initial customer communication

A controlled initial notice should ordinarily:

  1. acknowledge the incident and describe the confirmed duration, scope and current service status;

  2. avoid speculation about root cause or legal responsibility while the investigation remains incomplete;

  3. identify the applicable SLA and the contractual timetable for an incident report or credit request;

  4. preserve the parties’ rights without using aggressive boilerplate that undermines the operational message; and

  5. provide a realistic date for the next update.

An illustrative formulation is: “We are reviewing the incident under the Service Level Agreement in Schedule [X]. Based on the information currently confirmed, the affected service was unavailable between [time] and [time]. We will provide the incident report and any applicable service-credit calculation by [date]. Nothing in this notice constitutes an admission of liability or a waiver of either party’s rights under the Agreement or applicable law.”

Goodwill credits should be documented as one-off commercial measures and distinguished from contractual service credits. They do not automatically create a binding “precedent,” although repeated conduct, inconsistent reservations or subsequent contractual interpretation may complicate the parties’ position. Equally, service suspension should not be presented as a retaliatory measure. Its availability depends on the contract and/or Article 1556 Civil Code, the seriousness and proportionality of the reciprocal non-performance, applicable notice or cure requirements, good faith and any overriding continuity, consumer, data-access or sector-specific duties.

Contract Analysis: Which Clauses Matter?

The starting point is the complete contractual set in force when the outage occurred: master agreement, order form, SLA, data-processing agreement, acceptable-use policy, amendments and any incorporated online terms. Version control matters, particularly where the provider has changed online terms after signature.

Clause checklist

  • Downtime and exclusions: determine how availability is measured and whether scheduled maintenance, emergency maintenance, customer systems or specified third-party events are excluded.

  • Availability target: confirm the percentage, measurement window, time zone, monitoring source and denominator. A 99.9% monthly target permits only approximately 43–45 minutes of qualifying downtime in a 30- or 31-day month; a two-hour qualifying outage would ordinarily fall below that target.

  • Service-credit mechanism: identify the formula, cap, claim window and procedural prerequisites, and whether credits are exclusive or cumulative with other remedies.

  • Limitation and exclusion of liability: examine the claims to which the cap applies, excluded heads of loss, carve-outs and the restrictions imposed by Articles 1203 and 1355 Civil Code or consumer law.

  • Payment pending dispute: separate genuinely disputed amounts from invoices or portions that remain undisputed and due.

  • Suspension, termination and cure: identify the legal and contractual thresholds, notice method, cure period, data-export rights and consequences of suspension or termination.

  • Force majeure and third-party dependencies: determine whether the contract modifies the Civil Code regime, allocates cloud or connectivity risk, requires notice or evidence, and distinguishes force majeure from ordinary supplier failure.

  • Dispute resolution: confirm governing law, jurisdiction or arbitration, senior-management escalation and any mandatory contractual pre-action steps.

Standard terms and “unusual clauses”

Under Article 1203 Civil Code, specified standard terms—including clauses benefiting the proposer by limiting liability, permitting unilateral termination or suspension, and clauses restricting the other party’s defences, providing tacit renewal, choosing applicable law, arbitration or derogation from court jurisdiction—produce effects only if expressly accepted in writing by the other party. This rule does not mean that every negotiated limitation clause is invalid; it means that incorporation into standard terms alone may be insufficient for clauses falling within Article 1203.

Article 1355 Civil Code imposes a separate substantive limit: liability for material damage caused intentionally or through gross negligence cannot be excluded or limited by agreement, while liability for harm to physical or mental integrity or health cannot be removed or reduced except as permitted by law. Accordingly, the statement that B2B caps or sole-remedy provisions “apply as agreed” is too absolute. Their effect depends on formation, express acceptance where required, interpretation, the conduct involved, mandatory rules and the claim actually advanced.

In B2C arrangements, Law No. 193/2000 and Directive 93/13/EEC add unfair-terms controls. A non-negotiated term may be unfair where, contrary to good faith, it creates a significant imbalance to the consumer’s detriment; transparency and the statutory indicative list also matter. Consumer-facing SaaS terms should therefore be reviewed separately from negotiated enterprise contracts.

Service credits and damages

Contract wording Likely issue requiring analysis
“Service credits are Customer’s sole and exclusive remedy for failure to meet the SLA.” May restrict remedies for the defined SLA failure if validly incorporated and enforceable, but does not automatically exclude every claim arising from the same incident or override Articles 1203, 1355, consumer law or another mandatory rule.
“Without prejudice to other rights, Customer is entitled to the following service credits.” Credits are not contractually exclusive; any damages claim still requires proof of breach, recoverable loss, causation, foreseeability and compliance with contractual procedures.
“Provider’s aggregate liability shall not exceed [amount].” Scope, aggregation period, claim category, carve-outs, express acceptance and mandatory limitations must be tested. The cap should not be assumed valid for intent or gross negligence.
“Customer shall pay all undisputed amounts when due.” Supports recovery of the undisputed balance, but does not itself determine whether a particular amount is genuinely disputed or whether the customer may invoke Article 1556 Civil Code.

The existence of a credit remedy does not by itself establish that withholding an entire invoice is lawful or unlawful. The analysis must compare the value and seriousness of the respective obligations, the contractual allocation of remedies and whether the customer’s non-payment is proportionate to the provider’s alleged non-performance.

Contractual Liability, Force Majeure, Good Faith and Avoidable Loss

Contractual non-performance

Under the Civil Code’s general contractual-liability framework, the customer may seek the contractual remedies available for unjustified or culpable non-performance, subject to the agreement and mandatory law. The provider may, in turn, pursue due fees, interest and recovery costs where the customer’s withholding is not contractually or legally justified. Before taking either position, the parties should identify whether the outage breached the availability commitment, another obligation of result, an obligation of means or no contractual obligation at all because an exclusion applies.

Force majeure

Article 1351(2) Civil Code defines force majeure as an external, unforeseeable, absolutely invincible and inevitable event. The elements are cumulative, but the contract may define, allocate or procedurally regulate force-majeure risk, subject to mandatory rules and Article 1203 where standard terms deprive a party of the ordinary benefit of the doctrine.

A cloud-region failure, cyberattack, natural disaster or government measure is not automatically force majeure. The assessment turns on the actual cause, foreseeability at contract formation, architecture and redundancy commitments, available prevention or recovery measures, causal connection and the contractual allocation of dependency risk. A certificate or third-party status page may support the factual record but does not bind the court to find force majeure.

Force majeure should also be connected to the obligation allegedly rendered impossible. An outage affecting the provider’s service does not ordinarily make the customer’s accrued monetary payment physically impossible; conversely, a provider cannot rely on an external event if the contractual architecture placed the relevant risk on it or if its own acts materially caused the non-performance. Article 1634 Civil Code and the parties’ clause should be analysed alongside Article 1351 when impossibility of performance is invoked.

Good faith and avoidable loss

Articles 14 and 1170 Civil Code require good faith in exercising civil rights and performing contractual obligations. Good faith does not create a free-standing power for a court to rewrite every commercially harsh term, but it affects the parties’ conduct, interpretation and exercise of remedies.

Article 1534 Civil Code addresses avoidable loss: the debtor is not liable for damage that the creditor could have avoided with minimum diligence, while contributory fault may reduce recovery under the applicable rules. It is therefore more precise to speak of limits on recoverable damage and reasonable loss-avoidance conduct than of an unlimited reciprocal “duty to mitigate.” A customer withholding three months of fees after a brief outage and a provider suspending a business-critical service over a genuinely minor disputed amount may each face arguments based on proportionality, good faith, causation and avoidable loss, but the result remains fact-specific.

Evidence Preservation

Digital evidence is often short-lived. Preservation should begin promptly and should maintain the native records, relevant metadata and an intelligible audit trail without obstructing service restoration.

Evidence Preservation step Relevance
System, application and security logs Export the relevant time window in native format; record source, time zone, collection method and hash; preserve access controls. Duration, scope, cause and integrity of the incident reconstruction.
SLA and monitoring data Export raw measurements and the calculation method, including exclusions and maintenance windows. Whether the contractual availability target was missed.
Incident and change tickets Preserve history, approvals, timestamps and linked deployments without altering the originals. Response steps, causation and control changes.
Third-party evidence Preserve provider notices and status-page captures internally with timestamps and provenance. Avoid uploading confidential evidence to a public archive without legal and security review. External dependency, notice and allocation of responsibility.
Customer communications Preserve complete threads, attachments, headers and support-portal exports. Notice, representations, requests, admissions and cure opportunities.
Contract versions Preserve the signed agreement and evidence identifying the incorporated online terms applicable on the incident date. Governing obligations and remedies.
Billing records Export invoices, due dates, credits, payment history, interest calculations and dunning notices. Certainty, liquidity and maturity of the claimed debt.
Privacy and security assessment Preserve the breach assessment, risk reasoning, controller/processor notices and any regulatory submission. GDPR and related incident duties.

The company should not assume that marking a post-mortem “prepared at the direction of legal counsel” automatically makes it privileged. Romanian professional secrecy protects the lawyer-client relationship under Law No. 51/1995 and the Statute of the legal profession, but the protection of internal investigations and mixed technical reports is context- and jurisdiction-dependent. Counsel should define the purpose, authorship, distribution and separation between operational root-cause material and confidential legal advice before the report is commissioned.

Hashes and a collection log are useful integrity measures, but Romanian civil procedure does not impose one universal “chain-of-custody” template for every commercial electronic document. Where evidence risks disappearing before proceedings, counsel should consider the specific procedures for preservation of evidence and urgent findings under Articles 359–365 Civil Procedure Code, rather than assuming that an ordinary screenshot will always suffice.

Negotiation and Commercial Escalation

The following timetable is illustrative and should be adapted to the contractual notice periods, invoice maturity, limitation concerns, customer criticality and incident severity:

  • Days 0–7: preserve evidence, stabilise the service, determine whether a personal data breach occurred, calculate contractual credits and communicate confirmed facts.

  • Days 7–30: exchange the incident report and invoice position, require payment of clearly undisputed amounts, and explore a documented credit or settlement without prejudice to rights.

  • Days 30–60: complete senior-management escalation and any contractual mediation or cure step; issue a formal payment notice through a provable channel.

  • Thereafter: select the payment-order procedure, ordinary proceedings, arbitration or a negotiated termination based on the evidence, forum clause, claim complexity and recoverability.

For qualifying commercial transactions, Law No. 72/2013 may entitle the creditor to statutory or contractual late-payment interest and recovery costs, including the statutory minimum compensation, provided its scope and conditions are met. The claim should be calculated rather than asserted generically, and any contractual interest or penalty should be tested against applicable mandatory rules.

The litigation decision should remain commercial. Relevant considerations include the net recoverable amount, evidence of the SLA breach, the validity and scope of the credit and cap provisions, procedural cost, solvency and asset location, relationship value, confidentiality and the probability that a factually complex outage defence will displace a fast-track debt procedure.

Romanian Proceedings and Cross-Border Enforcement

Payment order (ordonanță de plată)

Articles 1014–1025 Civil Procedure Code establish a special procedure for certain, liquid and due monetary claims arising from a civil contract and evidenced in the legally permitted manner. It is not limited to debts that the customer informally calls “undisputed,” nor is it guaranteed whenever an invoice exists. If the debtor raises a defence that requires evidence unsuitable for the summary framework, the court may reject the payment-order request without preventing an ordinary action on the merits.

Before filing, Article 1015 requires the creditor to serve a 15-day payment demand through a judicial enforcement officer or by registered letter with declared content and acknowledgement of receipt. Proof of service must accompany the application. Article 1022 sets a 45-day period for deciding the request, excluding the time required to serve procedural documents and delays caused by the creditor; this is a statutory case-management period, not a guaranteed end-to-end enforcement timeline.

New claims and documents may currently be submitted through the national ReJust electronic registry where the relevant service and court are available. The ordinary Romanian Courts Portal is primarily a public case-information resource and should not be described as a universal electronic-filing platform.

Ordinary proceedings, arbitration and interim measures

An ordinary claim may be more appropriate where the outage dispute requires expert evidence, extensive interpretation of the SLA, set-off, damages or other factually complex defences. Arbitration is available only where a valid arbitration agreement covers the dispute; Article 1203 may require express written acceptance where the arbitration clause appears in standard terms. No universal “months to award” timetable can be promised.

An ordonanță președințială under Article 997 Civil Procedure Code permits urgent provisional measures where the claimant shows an appearance of right and the statutory urgency conditions, without deciding the merits. It is not a generic substitute for the preservation-of-evidence mechanisms under Articles 359–365 and cannot be assumed available simply because the dispute concerns data or a service outage.

Cross-border matters

For civil and commercial judgments within the scope of Regulation (EU) No. 1215/2012, Brussels I Recast governs jurisdiction, recognition and enforcement in participating EU states and generally removes the need for a separate declaration of enforceability. Its scope, jurisdiction agreements, service requirements and defences must still be checked.

Foreign or non-domestic arbitral awards may be recognised and enforced under the 1958 New York Convention where its territorial and commercial-reservation requirements and the relevant national procedural conditions are met. The Convention facilitates enforcement; it does not guarantee it or remove the limited refusal grounds.

Illustrative Drafting Provisions

The following language is a negotiation starting point and must be calibrated to the service, customer category and allocation of technical dependencies:

  • Availability: “Availability” means the percentage of minutes in the Measurement Period during which the production Service is capable of processing authorised requests, measured by [method and monitoring point], excluding only [defined exclusions]. Provider shall retain the underlying measurement data for [period].”

  • Credits: “If Availability falls below [target], Customer may request the service credit in the table below within [period]. Subject to mandatory law and the exclusions and carve-outs in this Agreement, the credit shall be [the sole remedy for the defined SLA failure / without prejudice to other remedies].”

  • Payment pending dispute: “Customer shall notify a good-faith invoice dispute, with reasonable particulars, within [period] and shall pay all amounts not genuinely disputed when due. The parties shall escalate the disputed amount under clause [X].”

  • Suspension: “Provider may suspend the affected Service for a material failure to pay an undisputed amount only after giving [period] written notice and an opportunity to cure, unless immediate action is required by law or to address a material security risk. Suspension shall be proportionate and shall not affect agreed data-export rights.”

  • Liability cap: “Subject to liability that cannot lawfully be excluded or limited, Provider’s aggregate liability arising from [defined scope and period] shall not exceed [amount]. The cap does not apply to material damage caused intentionally or through gross negligence and is subject to the other carve-outs expressly agreed.”

Where these provisions form part of the provider’s standard terms, each clause falling within Article 1203 should be brought specifically to the customer’s attention and expressly accepted in writing. A generic click accepting an entire terms document should not be assumed sufficient without examining the contracting flow and evidence of acceptance.

Conclusion

A payment dispute following a SaaS outage should be handled as a structured contractual and evidentiary exercise. The provider should preserve the technical record, determine whether the SLA was actually breached, assess any privacy or sectoral notification duty, separate disputed from undisputed sums and test every proposed remedy against the contract and mandatory Romanian law.

The most serious risks in practice are categorical assumptions: that every outage triggers ANSPDCP notification, every third-party failure is force majeure, every liability cap is enforceable, every non-payment permits immediate suspension, or every invoice qualifies for a rapid payment order. None of these propositions is universally correct. A disciplined, proportionate escalation supported by reliable evidence is the stronger approach.

Last reviewed: 10 August 2026.

Need Legal Advice?

For specialist advice on this topic, contact Razvan Alexandru Olaru at Olawru.

Sources

  1. Romanian Civil Code — Law No. 287/2009, consolidated text

  2. Romanian Civil Procedure Code — Law No. 134/2010, consolidated text

  3. Law No. 72/2013 on late payment in commercial transactions

  4. Law No. 193/2000 on unfair terms in consumer contracts

  5. GDPR — Regulation (EU) 2016/679

  6. EDPB Guidelines 9/2022 on personal-data-breach notification

  7. ReJust national electronic registry

  8. Regulation (EU) No. 1215/2012 — Brussels I Recast

  9. UNCITRAL — New York Convention

  10. CMS — force majeure under Romanian law

  11. CMS — digital litigation in Romania

  12. Legal 500 — Romanian payment-order procedure

  13. SCL — unusual clauses under Article 1203 Civil Code

  14. Chambers and Partners — Litigation 2026: Romania

FAQs

Can a customer legally withhold payment after a platform outage in Romania?
Not automatically. The answer depends on the affected obligations, the SLA and credit mechanism, whether the customer has a damages or set-off claim, and the proportionality requirements governing the exception of non-performance under Article 1556 Civil Code. Amounts unrelated to the incident or genuinely undisputed may remain payable.
Potentially, but not necessarily immediately. The provider should verify the express suspension clause, Article 1556 Civil Code, materiality and proportionality, notice and cure requirements, Article 1203 express acceptance where standard terms are used, and any duties concerning data access, consumer protection or regulated services.
No. The controller must first determine whether a personal data breach occurred. Loss of availability can qualify, but notification is required under Article 33 GDPR only where the breach is not unlikely to create a risk to individuals’ rights and freedoms. If a personal data breach occurred, Article 33(5) requires it to be documented even where authority notification is unnecessary; retaining the initial assessment is also prudent where the conclusion is that no personal data breach occurred.
Not by label alone. The party invoking Article 1351 must establish an external, unforeseeable, absolutely invincible and inevitable event, causation and the effect on the relevant obligation, subject to the parties’ allocation of cloud and resilience risk. Ordinary supplier failure or inadequate redundancy may not meet the test.
It may be, particularly in a negotiated B2B agreement, but its scope and validity must be tested under Articles 1203 and 1355 Civil Code and, for consumers, Law No. 193/2000. It should not be assumed to exclude claims outside the defined SLA failure or liability that cannot lawfully be limited.
It is suitable for a certain, liquid and due monetary contractual claim supported by the required evidence, after the Article 1015 payment demand. A technically complex outage defence, damages claim or set-off may make ordinary proceedings more appropriate if it cannot be resolved within the payment-order evidentiary framework.
No. Romanian professional secrecy protects qualifying lawyer-client communications, but a mixed technical report does not become privileged merely because it carries a label. Counsel should structure the mandate, purpose, authorship and circulation in light of Romanian law and any other jurisdiction likely to assess protection.
Judgments within Brussels I Recast may circulate within participating EU states under its recognition and enforcement rules. Foreign or non-domestic arbitral awards may benefit from the New York Convention. In both cases, scope, forum, service, documentation and available refusal grounds must be verified for the destination state.
corporate lawyer netherlands
By Global Law Experts

posted 36 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Saas Customer Refusing to Pay After a Platform Outage, Romania: What to Do

Send welcome message

Custom Message