Romanian banks will require SPV consent to access tax data for credit checks
A draft ANAF ordinance would make individuals and companies give electronic consent via the SPV system before banks can retrieve their tax filings for loan assessments.
Romania’s tax authority ANAF is reviewing a draft order that would require both natural persons and legal entities to grant permission via the Spațiul Privat Virtual (SPV) before banks can access their fiscal information. The rule supersedes the February 2022 ordinance and mandates that banks, classified as private legal entities, request D100, D101 and D300 declarations for the last twelve months, provided a standardized electronic consent—valid for five working days—is recorded.
Consent for individuals with an active SPV account is given solely through that platform; those without SPV must sign a written or electronic form that includes identifying details and IP data. ANAF’s CNIF will automatically verify the consent’s validity and match taxpayer identifiers before transmitting the requested data. Additional obligations include pre- and post-audit of IT systems, digital certificate renewal, and granular consent for each data-processing purpose, all intended to improve credit-risk assessment and reduce fraud.
Why it matters
It changes how Romanian lenders verify borrowers, impacting credit access and fraud prevention.
In this story
