Our Expert in Romania
No results available
Banking and finance law romania is the legal and regulatory framework that governs how credit institutions, non-bank lenders, payment service providers and borrowers operate within the Romanian market, and in 2026 it sits at the intersection of national statute and a growing body of EU regulation. For businesses, in-house counsel, banks, non-banking financial institutions (IFNs) and credit servicers, understanding this framework is no longer optional, regulatory scrutiny of anti-money-laundering (AML) controls, payment services and data protection has intensified. This guide explains the applicable laws, the regulators who enforce them, licensing requirements, compliance obligations and the practical mechanics of lending and enforcement. It is written for decision-makers who need accuracy and actionable detail, not generic overviews.
Throughout, substantive legal points are tied to an official source so you can verify and act with confidence.
Banking and finance law in Romania covers the rules that govern the taking of deposits, the extension of credit, the provision of payment services, capital markets activity, consumer credit and the enforcement of security. It is a hybrid body of law: core national statutes published in the Official Gazette (Monitorul Oficial al României) and consolidated on the national legislation portal (legislatie.just.ro), layered over directly applicable EU regulations and transposed EU directives. For any lender or financial services business, the two layers must be read together, a gap in either can create regulatory exposure.
The Romanian framework draws on several pillars. Domestic banking and credit legislation, notably the emergency ordinance governing the activity of credit institutions and non-bank lenders (commonly referred to as GEO 99/2006, as subsequently amended), together with the legislation on non-bank financial institutions, governs the authorisation and supervision of credit institutions and non-bank lenders. Consolidated texts of these are accessible through legislatie. just. ro. On the EU side, the decisive instruments include the Second Payment Services Directive, Directive (EU) 2015/2366 (PSD2), the Capital Requirements Regulation and Directive framework (CRR/CRD), the General Data Protection Regulation and the EU anti-money-laundering directives.
The European Banking Authority (EBA) issues regulatory technical standards and guidelines, for example on strong customer authentication and AML, that shape Romanian supervisory practice. Because EU directives require national transposition, the operative text for any given rule may be a Romanian law published in the Official Gazette rather than the directive itself.
The perimeter of banking and finance law romania is defined by activity, not by name. The main regulated categories are: credit institutions (banks) that take deposits and lend; non-bank financial institutions (IFNs) that extend credit without deposit-taking; and payment institutions and electronic money issuers that provide payment services. Each category carries a distinct licensing pathway, capital expectation and conduct regime. Firms that touch consumer credit, credit broking or debt collection face additional consumer-protection and data-protection obligations, discussed below.
A defining feature of Romanian banking and finance law is that oversight is shared among several authorities, each with its own powers to license, supervise, inspect and impose administrative sanctions. Mapping the right regulator to the right activity is a first-order compliance task, because an obligation owed to one authority does not discharge the duties owed to another.
The National Bank of Romania (BNR) is the central supervisor of credit institutions and the registrar and supervisor of IFNs. BNR authorises banks, sets and enforces prudential requirements including minimum capital and reporting obligations, conducts on-site and off-site supervision, and publishes statistics on the banking sector and on non-performing loans. BNR also exercises powers in the AML field for the institutions within its remit and can impose administrative measures and fines for breaches. Romania participates in the EU’s Single Supervisory Mechanism through close cooperation with the European Central Bank, and BNR cooperates within the European System of Financial Supervision, where the European Banking Authority’s standards shape national practice.
The Romanian Financial Supervisory Authority (ASF) supervises non-banking financial markets, including insurance, private pensions and capital markets. Its competence is distinct from BNR’s: ASF focuses on market conduct, prudential supervision of the entities within its scope, and investor and consumer protection in those sectors. Businesses operating across both banking and capital-markets activities must identify which authority has competence over each line of business, as licensing and reporting obligations differ accordingly.
Data processing in the financial sector is overseen by the National Supervisory Authority for Personal Data Processing, ANSPDCP, which enforces the GDPR and issues guidance and decisions affecting credit reporting, debt collection and borrower profiling. AML supervision involves BNR for its supervised entities alongside the National Office for Prevention and Control of Money Laundering (ONPCSB), Romania’s financial intelligence unit, to which suspicious transactions are reported. Beneficial-ownership obligations are anchored in Romanian company and AML law published in the Official Gazette and consolidated on legislatie.just.ro. Where EU law is contested, interpretative rulings of the Court of Justice of the European Union bind Romanian courts and regulators.
Romania’s financial market is dominated by universal banks, supplemented by a sizeable population of IFNs and a growing set of payment and e-money institutions. For businesses evaluating counterparties, the market structure matters because the regulatory profile, product range and risk appetite differ markedly across these categories. Current sector composition and asset data should always be verified against BNR statistics.
The Romanian banking market is led by a group of large universal banks that between them hold the majority of system assets. Market participants commonly cited among the leading institutions include Banca Transilvania, BCR (Banca Comercială Română), BRD – Groupe Société Générale, Raiffeisen Bank, ING Bank Romania and OTP Bank Romania. Rankings by assets shift over time, particularly following mergers and acquisitions, so for any transaction or counterparty assessment the authoritative reference is the sector data published by the National Bank of Romania. These banks offer the full product spectrum, corporate and retail lending, payments, treasury and trade finance, and are subject to the full prudential regime.
Non-bank financial institutions (IFNs) extend credit without taking deposits. They play a significant role in consumer credit, leasing, microfinance and factoring. IFNs are registered and supervised by BNR, and the depth of the applicable regime depends on the scale and type of activity, the framework distinguishes between different registers maintained by BNR. Non-bank lenders remain fully within the scope of AML, consumer-protection and data-protection rules, and businesses should not assume that a lighter prudential footprint means lighter conduct obligations. Verification of an IFN’s registration status against BNR records is a basic due-diligence step.
Payment institutions and electronic money issuers provide payment services and issue e-money without being banks. Their activity is governed by the PSD2 framework as transposed into Romanian law, supervised by BNR, and shaped by EBA technical standards. This category has grown with the expansion of fintech and open banking, and it sits at the heart of the 2026 compliance agenda for banking and finance law romania, given the emphasis on strong customer authentication and third-party access to accounts.
Authorisation is the gateway to operating in the Romanian financial market, and conducting a regulated activity without the correct licence exposes a firm to administrative sanctions and the potential unenforceability of certain arrangements. The licensing regime differs by category, but each shares common features: a fit-and-proper assessment of management and significant shareholders, minimum capital or own-funds requirements, a clear description of permitted activities, and governance and internal-control expectations.
Credit institutions require authorisation from the National Bank of Romania before taking deposits or lending as a bank. Applicants must satisfy minimum capital thresholds, demonstrate robust governance and risk management, and pass fit-and-proper tests for directors and qualifying shareholders. Once authorised, banks are subject to continuous prudential supervision, periodic reporting and capital requirements derived from the EU prudential framework (CRR/CRD). The exact capital and reporting requirements are set and enforced by BNR in line with EU law, and firms should confirm current thresholds directly against BNR guidance before applying.
IFN licensing in Romania operates through registration with BNR, with the applicable requirements scaled to the type and volume of lending activity. An IFN must demonstrate adequate governance, internal controls and AML systems, and must register its permitted activities. Consumer-credit lending triggers additional obligations under consumer-protection legislation consolidated on legislatie.just.ro. Because the regime distinguishes between different registers depending on activity and scale, prospective IFNs should take advice on which register applies and what ongoing reporting follows. Within the broader architecture of banking and finance law romania, IFN licensing is frequently the entry point for fintech and specialist lenders.
Payment service providers must be authorised under the PSD2 framework, Directive (EU) 2015/2366 (PSD2), as transposed into Romanian law and supervised by BNR. Authorisation requires initial capital appropriate to the services provided, safeguarding arrangements for client funds, and governance and security measures consistent with EBA standards. Firms intending to provide account information services or payment initiation services face specific requirements for access to accounts and for operational and security risk management. A practical onboarding step for any business contracting with a PSP is to confirm the provider’s authorisation and permitted services with BNR.
Anti-money-laundering and counter-terrorist-financing compliance is among the most scrutinised areas of banking compliance romania in 2026. Supervisors expect lenders and IFNs to operate risk-based programmes that are documented, tested and demonstrably effective, not merely present on paper. Breaches attract significant administrative fines and reputational damage, and deficient controls can taint individual transactions.
Romania’s AML regime transposes successive EU anti-money-laundering directives into national law, principally the AML and counter-terrorist-financing law (commonly referred to as Law 129/2019, as amended), published in the Official Gazette and consolidated on legislatie. just. ro. The core obligations are customer due diligence (CDD), ongoing transaction monitoring, record-keeping and the reporting of suspicious transactions to the National Office for Prevention and Control of Money Laundering (ONPCSB). Enhanced due diligence applies to higher-risk relationships, including politically exposed persons and certain cross-border arrangements. EBA guidelines inform supervisory expectations on risk assessment and on the use of technology in monitoring.
Note that the EU’s new AML package, including a directly applicable AML Regulation and the AML Authority (AMLA), will progressively reshape obligations; firms should track its phased application.
Identifying and verifying beneficial owners is a central obligation. The beneficial-ownership register and related duties are anchored in Romanian company and AML law, with publication and procedural detail traceable through the Official Gazette (Monitorul Oficial) and the legislation portal. Designated non-financial businesses and professions (DNFBPs), including certain advisers and intermediaries, also carry AML duties where they fall within scope. For lenders, confirming the beneficial-ownership position of corporate borrowers is both an AML requirement and a credit-risk safeguard.
Industry observers expect continued intensification of AML supervision through 2026, with particular focus on the quality of transaction monitoring, the adequacy of risk assessments and the completeness of beneficial-ownership records. The likely practical effect for lenders and IFNs is greater scrutiny during inspections and less tolerance for generic, box-ticking programmes. Firms should benchmark their frameworks against current BNR and EBA expectations and document the rationale behind their risk-based decisions, because the ability to evidence a reasoned approach is increasingly what distinguishes compliant programmes from exposed ones.
The GDPR applies in full to financial services, and gdpr banking romania issues arise at almost every stage of the customer lifecycle, from onboarding and credit assessment to debt collection and portfolio sales. The data-protection regime interacts with banking secrecy and with AML obligations, which can create apparent tensions that must be managed through careful legal analysis rather than assumption.
Every processing activity needs a lawful basis. For lenders, processing to assess and perform a loan agreement is typically grounded in performance of a contract and compliance with legal obligations (such as AML and prudential reporting), while certain analytical or marketing activities may rely on legitimate interests subject to a balancing test, or on consent. Automated decision-making and profiling in credit scoring attract specific GDPR safeguards, and firms should document the legal basis for each processing purpose. ANSPDCP guidance is the authoritative national reference.
Sharing borrower data with credit registers, with debt collectors and with purchasers of loan portfolios must be mapped against a valid lawful basis, transparency obligations and data-minimisation principles. Debt collection and credit reporting have been recurring themes in ANSPDCP enforcement, so lenders and servicers should ensure that data-sharing arrangements are supported by appropriate contracts and that data subjects are properly informed. Where EU-level interpretation of credit-data processing is in issue, rulings of the Court of Justice of the European Union are directly relevant.
Indications suggest that data-protection enforcement in the financial sector will remain active, with attention to transparency, lawful basis for credit reporting and the handling of debtor data. The practical takeaway for banking and finance law romania practitioners is to treat data governance as a live compliance area requiring the same rigour as AML, with documented records of processing, vendor due diligence and up-to-date privacy notices.
Payment services regulation romania is governed by PSD2 as transposed nationally, and 2026 remains a period of close supervisory attention to payment security and third-party access. For banks, merchants and fintechs alike, the operational and legal requirements around account access and authentication have direct commercial consequences. A further PSD3/PSR reform package is under development at EU level and should be monitored.
Payment institutions and e-money issuers must be authorised under the PSD2 framework, Directive (EU) 2015/2366 (PSD2), and supervised by BNR. Authorisation in one EU member state can, within the single market, support cross-border provision of services through passporting, but firms must still comply with host-state conduct rules and should confirm the scope of their permissions. Businesses contracting with a PSP should verify both the authorisation and the specific services the provider is permitted to offer.
Strong customer authentication (SCA) is a cornerstone of the PSD2 regime, requiring multi-factor authentication for electronic payments and account access subject to defined exemptions. The detailed technical standards are developed at EU level by the European Banking Authority. Merchants and payment providers must implement SCA correctly to avoid declined transactions and compliance exposure, and should keep their exemption logic aligned with current EBA standards.
Open banking enables account information service providers and payment initiation service providers to access customer accounts with consent. Banks must provide compliant access interfaces and manage the associated security and liability risks, while third-party providers must hold the correct authorisation and operate within consent boundaries. Robust contractual and operational controls are essential, and this area is central to the forward-looking agenda of banking and finance law romania.
Once the regulatory perimeter is understood, the practical work of lending turns on documentation, security and enforcement. Romanian law offers a well-established toolkit of security interests, but the value of any security depends on correct perfection and on a realistic understanding of enforcement timelines. Effective npl management romania also requires early engagement with workout and insolvency options.
The principal forms of security in Romanian lending are immovable mortgages over real estate, movable mortgages over tangible and intangible assets, and the assignment of receivables. Perfection generally requires registration in the relevant public register, the land register (cartea funciară) for immovable mortgages and the Electronic Archive of Security Interests in Movable Property (Registrul Național de Publicitate Mobiliară) for movable mortgages, to establish priority and enforceability against third parties. Correct registration is decisive: an unperfected security interest may rank behind later-registered creditors or fail entirely in enforcement. The governing rules are found in the Romanian Civil Code (Law 287/2009) and related legislation consolidated on legislatie.just.ro.
Enforcement in Romania can proceed through court-supervised execution via a judicial enforcement officer (executor judecătoresc), and, for certain security, through accelerated routes where the security instrument constitutes an enforceable title (titlu executoriu). Timelines vary considerably depending on the asset type, whether the debtor raises defences, and court workload; real-estate enforcement typically takes longer than enforcement over movables or receivables. Common defences include challenges to the enforceability of the title or to the enforcement procedure itself (contestația la executare), which can extend timelines. Because outcomes are fact-specific, lenders should obtain a realistic enforcement assessment at the point of structuring, not only at default.
Where a borrower becomes insolvent, enforcement rights interact with the insolvency regime (principally Law 85/2014 on insolvency prevention and insolvency procedures, as amended), which can impose a stay on individual enforcement and channel recovery through collective procedures. Restructuring and pre-insolvency mechanisms may offer a route to preserve value, and secured creditors generally retain priority over the proceeds of their collateral subject to the applicable rules. For NPL portfolios, lenders should weigh restructuring, individual enforcement and portfolio sale, each of which carries distinct regulatory, data-protection and tax considerations. BNR statistics on non-performing loans provide a useful benchmark for sector conditions.
| Security type | Registration / perfection | Typical enforcement route | Indicative enforcement timeline | Common limitations |
|---|---|---|---|---|
| Immovable mortgage (real estate) | Registration in the land register | Court-supervised execution via enforcement officer | Longer, subject to debtor defences and court workload | Valuation volatility; procedural challenges |
| Movable mortgage | Registration in the Electronic Archive of Security Interests in Movable Property | Execution over movable assets; accelerated routes where applicable | Shorter than real estate, asset-dependent | Asset depreciation; possession and identification issues |
| Assignment of receivables | Registration and notification to the assigned debtor | Collection directly from the account debtor | Can be rapid where receivables are clean | Set-off and counterclaims; debtor solvency |
| Bank account mortgage | Registration and account-bank arrangements | Enforcement against credited balances | Rapid where funds are present | Balance volatility; competing claims |
Timelines above are indicative only; actual duration depends on the asset, the debtor’s conduct and court caseload, and should be assessed case by case. Where enforcement and recovery in Romania are likely, build the analysis into the transaction structure from the outset.
The obligations above converge into a single operating reality: firms must run integrated compliance programmes covering licensing, AML, payments, data protection, credit reporting and sanctions. The consolidated checklist below brings the key action items together for businesses and lenders navigating banking and finance law romania in 2026.
Regulatory change in this field is continuous, and relying on secondary summaries is a false economy. The most reliable approach is to monitor primary sources directly and to engage specialist counsel for jurisdiction-specific questions.
Monitor the National Bank of Romania for supervisory notices, prudential guidance and banking-sector statistics; the Financial Supervisory Authority for non-banking markets; ANSPDCP for data-protection decisions and guidance; the European Banking Authority for technical standards; and EUR-Lex for EU instruments such as PSD2. For the exact text and publication dates of Romanian laws, consult the Official Gazette and the consolidated texts on legislatie.just.ro. For market data, the Bucharest Stock Exchange and mainstream market-data providers are appropriate references, though they are not legal sources.
Instruct Romanian legal counsel when structuring new lending or security, when entering a regulated activity, when responding to a supervisory inquiry, when transferring loan portfolios or borrower data, and before any contested enforcement. Jurisdiction-specific interpretation, particularly where national transposition, perfection steps or enforcement procedure is involved, requires professional advice. You can find legal counsel in Romania through the Global Law Experts directory, and more detail on the broader practice area via the Banking & Finance, Romania practice page.
Banking and finance law romania in 2026 is a demanding but navigable field, combining Romanian statute with EU regulation across AML, payment services and data protection. The firms that manage it well are those that treat compliance as an integrated programme, verifying authorisation, documenting AML and GDPR decisions, implementing payment-security controls, and structuring security and enforcement with realistic timelines in mind. Because the framework changes frequently and interpretation is often jurisdiction-specific, the most reliable strategy is to monitor primary sources directly and to engage specialist Romanian counsel for transactions, regulatory inquiries and contested enforcement. Used alongside the regulators’ own guidance, this guide gives businesses and lenders a practical foundation for operating with confidence under banking and finance law romania.
Last updated: October 2026.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Cristiana Petropoulos at Tiller Legal, a member of the Global Law Experts network.
posted 16 minutes ago
posted 21 minutes ago
posted 24 minutes ago
posted 43 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message