[codicts-css-switcher id=”346″]

Global Law Experts Logo
banking and finance law romania

Our Expert in Romania

  • GOLD

Banking and Finance Law in Romania (2026): What Businesses and Lenders Need to Know

By Global Law Experts
– posted 2 hours ago

Banking and finance law romania is the legal and regulatory framework that governs how credit institutions, non-bank lenders, payment service providers and borrowers operate within the Romanian market, and in 2026 it sits at the intersection of national statute and a growing body of EU regulation. For businesses, in-house counsel, banks, non-banking financial institutions (IFNs) and credit servicers, understanding this framework is no longer optional, regulatory scrutiny of anti-money-laundering (AML) controls, payment services and data protection has intensified. This guide explains the applicable laws, the regulators who enforce them, licensing requirements, compliance obligations and the practical mechanics of lending and enforcement. It is written for decision-makers who need accuracy and actionable detail, not generic overviews.

Throughout, substantive legal points are tied to an official source so you can verify and act with confidence.

1. What is banking and finance law in Romania?

Banking and finance law in Romania covers the rules that govern the taking of deposits, the extension of credit, the provision of payment services, capital markets activity, consumer credit and the enforcement of security. It is a hybrid body of law: core national statutes published in the Official Gazette (Monitorul Oficial al României) and consolidated on the national legislation portal (legislatie.just.ro), layered over directly applicable EU regulations and transposed EU directives. For any lender or financial services business, the two layers must be read together, a gap in either can create regulatory exposure.

Key legal sources (primary laws and EU directives)

The Romanian framework draws on several pillars. Domestic banking and credit legislation, notably the emergency ordinance governing the activity of credit institutions and non-bank lenders (commonly referred to as GEO 99/2006, as subsequently amended), together with the legislation on non-bank financial institutions, governs the authorisation and supervision of credit institutions and non-bank lenders. Consolidated texts of these are accessible through legislatie. just. ro. On the EU side, the decisive instruments include the Second Payment Services Directive, Directive (EU) 2015/2366 (PSD2), the Capital Requirements Regulation and Directive framework (CRR/CRD), the General Data Protection Regulation and the EU anti-money-laundering directives.

The European Banking Authority (EBA) issues regulatory technical standards and guidelines, for example on strong customer authentication and AML, that shape Romanian supervisory practice. Because EU directives require national transposition, the operative text for any given rule may be a Romanian law published in the Official Gazette rather than the directive itself.

Who is regulated? (banks, IFNs, PSPs)

The perimeter of banking and finance law romania is defined by activity, not by name. The main regulated categories are: credit institutions (banks) that take deposits and lend; non-bank financial institutions (IFNs) that extend credit without deposit-taking; and payment institutions and electronic money issuers that provide payment services. Each category carries a distinct licensing pathway, capital expectation and conduct regime. Firms that touch consumer credit, credit broking or debt collection face additional consumer-protection and data-protection obligations, discussed below.

2. Regulators and supervisory framework (who does what)

A defining feature of Romanian banking and finance law is that oversight is shared among several authorities, each with its own powers to license, supervise, inspect and impose administrative sanctions. Mapping the right regulator to the right activity is a first-order compliance task, because an obligation owed to one authority does not discharge the duties owed to another.

National Bank of Romania (BNR)

The National Bank of Romania (BNR) is the central supervisor of credit institutions and the registrar and supervisor of IFNs. BNR authorises banks, sets and enforces prudential requirements including minimum capital and reporting obligations, conducts on-site and off-site supervision, and publishes statistics on the banking sector and on non-performing loans. BNR also exercises powers in the AML field for the institutions within its remit and can impose administrative measures and fines for breaches. Romania participates in the EU’s Single Supervisory Mechanism through close cooperation with the European Central Bank, and BNR cooperates within the European System of Financial Supervision, where the European Banking Authority’s standards shape national practice.

Financial Supervisory Authority (ASF)

The Romanian Financial Supervisory Authority (ASF) supervises non-banking financial markets, including insurance, private pensions and capital markets. Its competence is distinct from BNR’s: ASF focuses on market conduct, prudential supervision of the entities within its scope, and investor and consumer protection in those sectors. Businesses operating across both banking and capital-markets activities must identify which authority has competence over each line of business, as licensing and reporting obligations differ accordingly.

Data protection (ANSPDCP) and AML authorities

Data processing in the financial sector is overseen by the National Supervisory Authority for Personal Data Processing, ANSPDCP, which enforces the GDPR and issues guidance and decisions affecting credit reporting, debt collection and borrower profiling. AML supervision involves BNR for its supervised entities alongside the National Office for Prevention and Control of Money Laundering (ONPCSB), Romania’s financial intelligence unit, to which suspicious transactions are reported. Beneficial-ownership obligations are anchored in Romanian company and AML law published in the Official Gazette and consolidated on legislatie.just.ro. Where EU law is contested, interpretative rulings of the Court of Justice of the European Union bind Romanian courts and regulators.

3. Market structure: major banks and types of credit institutions

Romania’s financial market is dominated by universal banks, supplemented by a sizeable population of IFNs and a growing set of payment and e-money institutions. For businesses evaluating counterparties, the market structure matters because the regulatory profile, product range and risk appetite differ markedly across these categories. Current sector composition and asset data should always be verified against BNR statistics.

Top universal banks

The Romanian banking market is led by a group of large universal banks that between them hold the majority of system assets. Market participants commonly cited among the leading institutions include Banca Transilvania, BCR (Banca Comercială Română), BRD – Groupe Société Générale, Raiffeisen Bank, ING Bank Romania and OTP Bank Romania. Rankings by assets shift over time, particularly following mergers and acquisitions, so for any transaction or counterparty assessment the authoritative reference is the sector data published by the National Bank of Romania. These banks offer the full product spectrum, corporate and retail lending, payments, treasury and trade finance, and are subject to the full prudential regime.

IFNs and non-bank lenders

Non-bank financial institutions (IFNs) extend credit without taking deposits. They play a significant role in consumer credit, leasing, microfinance and factoring. IFNs are registered and supervised by BNR, and the depth of the applicable regime depends on the scale and type of activity, the framework distinguishes between different registers maintained by BNR. Non-bank lenders remain fully within the scope of AML, consumer-protection and data-protection rules, and businesses should not assume that a lighter prudential footprint means lighter conduct obligations. Verification of an IFN’s registration status against BNR records is a basic due-diligence step.

Payment institutions and e-money issuers

Payment institutions and electronic money issuers provide payment services and issue e-money without being banks. Their activity is governed by the PSD2 framework as transposed into Romanian law, supervised by BNR, and shaped by EBA technical standards. This category has grown with the expansion of fintech and open banking, and it sits at the heart of the 2026 compliance agenda for banking and finance law romania, given the emphasis on strong customer authentication and third-party access to accounts.

4. Licensing and conduct requirements for lenders, IFNs and payment service providers

Authorisation is the gateway to operating in the Romanian financial market, and conducting a regulated activity without the correct licence exposes a firm to administrative sanctions and the potential unenforceability of certain arrangements. The licensing regime differs by category, but each shares common features: a fit-and-proper assessment of management and significant shareholders, minimum capital or own-funds requirements, a clear description of permitted activities, and governance and internal-control expectations.

Bank licensing basics

Credit institutions require authorisation from the National Bank of Romania before taking deposits or lending as a bank. Applicants must satisfy minimum capital thresholds, demonstrate robust governance and risk management, and pass fit-and-proper tests for directors and qualifying shareholders. Once authorised, banks are subject to continuous prudential supervision, periodic reporting and capital requirements derived from the EU prudential framework (CRR/CRD). The exact capital and reporting requirements are set and enforced by BNR in line with EU law, and firms should confirm current thresholds directly against BNR guidance before applying.

IFN licensing in Romania

IFN licensing in Romania operates through registration with BNR, with the applicable requirements scaled to the type and volume of lending activity. An IFN must demonstrate adequate governance, internal controls and AML systems, and must register its permitted activities. Consumer-credit lending triggers additional obligations under consumer-protection legislation consolidated on legislatie.just.ro. Because the regime distinguishes between different registers depending on activity and scale, prospective IFNs should take advice on which register applies and what ongoing reporting follows. Within the broader architecture of banking and finance law romania, IFN licensing is frequently the entry point for fintech and specialist lenders.

Payment institutions (PSD2 implementation in Romania)

Payment service providers must be authorised under the PSD2 framework, Directive (EU) 2015/2366 (PSD2), as transposed into Romanian law and supervised by BNR. Authorisation requires initial capital appropriate to the services provided, safeguarding arrangements for client funds, and governance and security measures consistent with EBA standards. Firms intending to provide account information services or payment initiation services face specific requirements for access to accounts and for operational and security risk management. A practical onboarding step for any business contracting with a PSP is to confirm the provider’s authorisation and permitted services with BNR.

5. AML/CFT obligations and 2026 supervisory focus

Anti-money-laundering and counter-terrorist-financing compliance is among the most scrutinised areas of banking compliance romania in 2026. Supervisors expect lenders and IFNs to operate risk-based programmes that are documented, tested and demonstrably effective, not merely present on paper. Breaches attract significant administrative fines and reputational damage, and deficient controls can taint individual transactions.

Key AML legal instruments

Romania’s AML regime transposes successive EU anti-money-laundering directives into national law, principally the AML and counter-terrorist-financing law (commonly referred to as Law 129/2019, as amended), published in the Official Gazette and consolidated on legislatie. just. ro. The core obligations are customer due diligence (CDD), ongoing transaction monitoring, record-keeping and the reporting of suspicious transactions to the National Office for Prevention and Control of Money Laundering (ONPCSB). Enhanced due diligence applies to higher-risk relationships, including politically exposed persons and certain cross-border arrangements. EBA guidelines inform supervisory expectations on risk assessment and on the use of technology in monitoring.

Note that the EU’s new AML package, including a directly applicable AML Regulation and the AML Authority (AMLA), will progressively reshape obligations; firms should track its phased application.

Beneficial ownership and DNFBP obligations

Identifying and verifying beneficial owners is a central obligation. The beneficial-ownership register and related duties are anchored in Romanian company and AML law, with publication and procedural detail traceable through the Official Gazette (Monitorul Oficial) and the legislation portal. Designated non-financial businesses and professions (DNFBPs), including certain advisers and intermediaries, also carry AML duties where they fall within scope. For lenders, confirming the beneficial-ownership position of corporate borrowers is both an AML requirement and a credit-risk safeguard.

AML enforcement trends 2024–2026

Industry observers expect continued intensification of AML supervision through 2026, with particular focus on the quality of transaction monitoring, the adequacy of risk assessments and the completeness of beneficial-ownership records. The likely practical effect for lenders and IFNs is greater scrutiny during inspections and less tolerance for generic, box-ticking programmes. Firms should benchmark their frameworks against current BNR and EBA expectations and document the rationale behind their risk-based decisions, because the ability to evidence a reasoned approach is increasingly what distinguishes compliant programmes from exposed ones.

AML compliance checklist for lenders and IFNs

  • Risk assessment. Maintain a documented, periodically reviewed business-wide money-laundering risk assessment.
  • Customer due diligence. Apply standard, simplified or enhanced CDD based on risk, and verify identity before onboarding.
  • Beneficial ownership. Identify and verify beneficial owners of corporate customers and reconcile against the register.
  • Transaction monitoring. Operate monitoring calibrated to customer and product risk, with documented thresholds and escalation.
  • Suspicious activity reporting. Report suspicious transactions promptly to ONPCSB through the correct channel and retain the supporting rationale.
  • Record-keeping and training. Retain records for the required period and train staff on current obligations.

6. Data protection and banking (GDPR implications for lenders and payment services)

The GDPR applies in full to financial services, and gdpr banking romania issues arise at almost every stage of the customer lifecycle, from onboarding and credit assessment to debt collection and portfolio sales. The data-protection regime interacts with banking secrecy and with AML obligations, which can create apparent tensions that must be managed through careful legal analysis rather than assumption.

Legal basis: contract/performance vs legitimate interest

Every processing activity needs a lawful basis. For lenders, processing to assess and perform a loan agreement is typically grounded in performance of a contract and compliance with legal obligations (such as AML and prudential reporting), while certain analytical or marketing activities may rely on legitimate interests subject to a balancing test, or on consent. Automated decision-making and profiling in credit scoring attract specific GDPR safeguards, and firms should document the legal basis for each processing purpose. ANSPDCP guidance is the authoritative national reference.

Credit reporting and data sharing

Sharing borrower data with credit registers, with debt collectors and with purchasers of loan portfolios must be mapped against a valid lawful basis, transparency obligations and data-minimisation principles. Debt collection and credit reporting have been recurring themes in ANSPDCP enforcement, so lenders and servicers should ensure that data-sharing arrangements are supported by appropriate contracts and that data subjects are properly informed. Where EU-level interpretation of credit-data processing is in issue, rulings of the Court of Justice of the European Union are directly relevant.

ANSPDCP enforcement trends

Indications suggest that data-protection enforcement in the financial sector will remain active, with attention to transparency, lawful basis for credit reporting and the handling of debtor data. The practical takeaway for banking and finance law romania practitioners is to treat data governance as a live compliance area requiring the same rigour as AML, with documented records of processing, vendor due diligence and up-to-date privacy notices.

Data-processing checklist for lenders and servicers

  • Map processing. Maintain records of processing activities covering credit assessment, servicing, collection and portfolio sales.
  • Lawful basis. Document the legal basis for each purpose, including any legitimate-interests assessments.
  • Transparency. Provide clear privacy notices to borrowers covering credit reporting and data sharing.
  • Vendor risk. Put in place compliant processor agreements with collectors, scoring providers and servicers.
  • Transfers. Ensure any cross-border transfers rely on a valid transfer mechanism.
  • Automated decisions. Apply GDPR safeguards where credit scoring involves automated decision-making.

7. Payments, PSD2 and open banking (what businesses must know in 2026)

Payment services regulation romania is governed by PSD2 as transposed nationally, and 2026 remains a period of close supervisory attention to payment security and third-party access. For banks, merchants and fintechs alike, the operational and legal requirements around account access and authentication have direct commercial consequences. A further PSD3/PSR reform package is under development at EU level and should be monitored.

PSP licensing and passporting

Payment institutions and e-money issuers must be authorised under the PSD2 framework, Directive (EU) 2015/2366 (PSD2), and supervised by BNR. Authorisation in one EU member state can, within the single market, support cross-border provision of services through passporting, but firms must still comply with host-state conduct rules and should confirm the scope of their permissions. Businesses contracting with a PSP should verify both the authorisation and the specific services the provider is permitted to offer.

SCA and exemptions

Strong customer authentication (SCA) is a cornerstone of the PSD2 regime, requiring multi-factor authentication for electronic payments and account access subject to defined exemptions. The detailed technical standards are developed at EU level by the European Banking Authority. Merchants and payment providers must implement SCA correctly to avoid declined transactions and compliance exposure, and should keep their exemption logic aligned with current EBA standards.

Third-party provider risk management

Open banking enables account information service providers and payment initiation service providers to access customer accounts with consent. Banks must provide compliant access interfaces and manage the associated security and liability risks, while third-party providers must hold the correct authorisation and operate within consent boundaries. Robust contractual and operational controls are essential, and this area is central to the forward-looking agenda of banking and finance law romania.

8. Lending mechanics, security and NPL management in Romania

Once the regulatory perimeter is understood, the practical work of lending turns on documentation, security and enforcement. Romanian law offers a well-established toolkit of security interests, but the value of any security depends on correct perfection and on a realistic understanding of enforcement timelines. Effective npl management romania also requires early engagement with workout and insolvency options.

Common security types and perfection steps

The principal forms of security in Romanian lending are immovable mortgages over real estate, movable mortgages over tangible and intangible assets, and the assignment of receivables. Perfection generally requires registration in the relevant public register, the land register (cartea funciară) for immovable mortgages and the Electronic Archive of Security Interests in Movable Property (Registrul Național de Publicitate Mobiliară) for movable mortgages, to establish priority and enforceability against third parties. Correct registration is decisive: an unperfected security interest may rank behind later-registered creditors or fail entirely in enforcement. The governing rules are found in the Romanian Civil Code (Law 287/2009) and related legislation consolidated on legislatie.just.ro.

Enforcement timelines and remedies

Enforcement in Romania can proceed through court-supervised execution via a judicial enforcement officer (executor judecătoresc), and, for certain security, through accelerated routes where the security instrument constitutes an enforceable title (titlu executoriu). Timelines vary considerably depending on the asset type, whether the debtor raises defences, and court workload; real-estate enforcement typically takes longer than enforcement over movables or receivables. Common defences include challenges to the enforceability of the title or to the enforcement procedure itself (contestația la executare), which can extend timelines. Because outcomes are fact-specific, lenders should obtain a realistic enforcement assessment at the point of structuring, not only at default.

Insolvency interface and restructuring

Where a borrower becomes insolvent, enforcement rights interact with the insolvency regime (principally Law 85/2014 on insolvency prevention and insolvency procedures, as amended), which can impose a stay on individual enforcement and channel recovery through collective procedures. Restructuring and pre-insolvency mechanisms may offer a route to preserve value, and secured creditors generally retain priority over the proceeds of their collateral subject to the applicable rules. For NPL portfolios, lenders should weigh restructuring, individual enforcement and portfolio sale, each of which carries distinct regulatory, data-protection and tax considerations. BNR statistics on non-performing loans provide a useful benchmark for sector conditions.

Comparison of security types and enforcement routes in Romania

Security type Registration / perfection Typical enforcement route Indicative enforcement timeline Common limitations
Immovable mortgage (real estate) Registration in the land register Court-supervised execution via enforcement officer Longer, subject to debtor defences and court workload Valuation volatility; procedural challenges
Movable mortgage Registration in the Electronic Archive of Security Interests in Movable Property Execution over movable assets; accelerated routes where applicable Shorter than real estate, asset-dependent Asset depreciation; possession and identification issues
Assignment of receivables Registration and notification to the assigned debtor Collection directly from the account debtor Can be rapid where receivables are clean Set-off and counterclaims; debtor solvency
Bank account mortgage Registration and account-bank arrangements Enforcement against credited balances Rapid where funds are present Balance volatility; competing claims

Timelines above are indicative only; actual duration depends on the asset, the debtor’s conduct and court caseload, and should be assessed case by case. Where enforcement and recovery in Romania are likely, build the analysis into the transaction structure from the outset.

9. Practical compliance checklist for businesses and lenders (2026)

The obligations above converge into a single operating reality: firms must run integrated compliance programmes covering licensing, AML, payments, data protection, credit reporting and sanctions. The consolidated checklist below brings the key action items together for businesses and lenders navigating banking and finance law romania in 2026.

Onboarding and KYC checklist

  • Verify authorisation. Confirm your own permissions and those of counterparties with BNR or ASF as applicable.
  • Customer due diligence. Complete risk-based CDD and beneficial-ownership checks before onboarding.
  • Sanctions screening. Screen customers and transactions against applicable sanctions lists.
  • Consumer-credit rules. Apply consumer-protection disclosures where lending to consumers.

Ongoing monitoring and reporting

  • Transaction monitoring. Maintain calibrated monitoring and timely suspicious-transaction reporting to ONPCSB.
  • Prudential and regulatory reporting. Meet BNR reporting deadlines and capital requirements.
  • Payments security. Keep SCA and open-banking controls aligned with current EBA standards.
  • Regulatory change. Track new Official Gazette publications and supervisory notices.

Data protection and vendor risk management

  • Records of processing. Keep processing records current across the lending lifecycle.
  • Lawful basis and notices. Document lawful bases and provide transparent privacy notices.
  • Processor agreements. Put compliant contracts in place with servicers, collectors and scoring providers.
  • Breach readiness. Maintain incident-response and breach-notification procedures.

10. Where to get regulatory updates and legal help

Regulatory change in this field is continuous, and relying on secondary summaries is a false economy. The most reliable approach is to monitor primary sources directly and to engage specialist counsel for jurisdiction-specific questions.

Subscriptions and official feeds

Monitor the National Bank of Romania for supervisory notices, prudential guidance and banking-sector statistics; the Financial Supervisory Authority for non-banking markets; ANSPDCP for data-protection decisions and guidance; the European Banking Authority for technical standards; and EUR-Lex for EU instruments such as PSD2. For the exact text and publication dates of Romanian laws, consult the Official Gazette and the consolidated texts on legislatie.just.ro. For market data, the Bucharest Stock Exchange and mainstream market-data providers are appropriate references, though they are not legal sources.

When to instruct Romanian counsel

Instruct Romanian legal counsel when structuring new lending or security, when entering a regulated activity, when responding to a supervisory inquiry, when transferring loan portfolios or borrower data, and before any contested enforcement. Jurisdiction-specific interpretation, particularly where national transposition, perfection steps or enforcement procedure is involved, requires professional advice. You can find legal counsel in Romania through the Global Law Experts directory, and more detail on the broader practice area via the Banking & Finance, Romania practice page.

Conclusion

Banking and finance law romania in 2026 is a demanding but navigable field, combining Romanian statute with EU regulation across AML, payment services and data protection. The firms that manage it well are those that treat compliance as an integrated programme, verifying authorisation, documenting AML and GDPR decisions, implementing payment-security controls, and structuring security and enforcement with realistic timelines in mind. Because the framework changes frequently and interpretation is often jurisdiction-specific, the most reliable strategy is to monitor primary sources directly and to engage specialist Romanian counsel for transactions, regulatory inquiries and contested enforcement. Used alongside the regulators’ own guidance, this guide gives businesses and lenders a practical foundation for operating with confidence under banking and finance law romania.

Last updated: October 2026.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Cristiana Petropoulos at Tiller Legal, a member of the Global Law Experts network.

Sources

  1. National Bank of Romania (BNR)
  2. Romanian Financial Supervisory Authority (ASF)
  3. EUR-Lex, Directive (EU) 2015/2366 (PSD2)
  4. ANSPDCP (Romanian Data Protection Authority)
  5. Romanian Legislation Portal (legislatie.just.ro)
  6. Monitorul Oficial al României (Official Gazette)
  7. European Banking Authority (EBA)
  8. Court of Justice of the European Union

FAQs

What laws govern banking and finance in Romania?
Banking and finance in Romania is governed by national statutes, including banking, credit, consumer-credit and civil-code provisions consolidated on legislatie.just.ro and published in the Official Gazette, read together with directly applicable EU law and transposed EU directives such as PSD2 (Directive (EU) 2015/2366), the GDPR and the AML directives. Supervision is shared mainly between the National Bank of Romania, the Financial Supervisory Authority and ANSPDCP, with AML reporting to the ONPCSB.
Deposit-taking and lending as a bank require authorisation from the National Bank of Romania. Lending without taking deposits is typically carried out through a non-bank financial institution (IFN) that must be registered with and supervised by BNR, with requirements scaled to activity and volume. Carrying out a regulated activity without the correct authorisation exposes a firm to administrative sanctions, so verify your permissions with BNR before lending.
AML compliance requires a documented, risk-based programme: a business-wide risk assessment, customer due diligence (with enhanced measures for higher-risk relationships), beneficial-ownership identification, ongoing transaction monitoring, suspicious-transaction reporting to the ONPCSB, record-keeping and staff training. Obligations derive from Romanian AML legislation transposing the EU directives and from EBA guidelines, and supervisors in 2026 expect programmes to be demonstrably effective, not merely documented.
Yes, but only where there is a valid lawful basis under the GDPR, transparency obligations are met, data is minimised and a compliant processor or transfer arrangement is in place. Credit reporting and debt collection are recurring themes in ANSPDCP enforcement, so data-sharing arrangements should be supported by appropriate contracts and clear privacy notices, with any cross-border transfer relying on a valid mechanism.
Enforcement timelines vary by asset type, by whether the debtor raises defences and by court workload. Enforcement over movables, receivables and account balances is generally faster than enforcement of an immovable mortgage over real estate, which tends to take longer. Because timelines are fact-specific, obtain a case-specific enforcement assessment at the structuring stage rather than relying on general estimates.
m&a lawyer fees vietnam
By Global Law Experts

posted 43 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Banking and Finance Law in Romania (2026): What Businesses and Lenders Need to Know

Send welcome message

Custom Message