Banks, lenders and fintechs handle their customers' financial data every day. Here, a breach is not just a fine. It costs the one thing the whole business is built on: trust.
In finance, data is the raw material. An account, a transaction history, a credit score, a national ID number, are all pieces of information that lead straight to fraud in the wrong hands. That is why the financial sector is among the most attacked in Romania and, at the same time, among the most regulated. A customer rarely forgives a leak of their banking data. Neither do the regulators.
The good news: the requirements are not a maze. They are a handful of clear frameworks that, taken together, describe roughly the same thing. Know what data you hold, protect it properly, and be able to prove it.
A bank or a non-bank lender in Romania juggles three frameworks in practice, plus the expectations of its supervisors.
Rather than treating them separately, it is simpler to see them as layers over the same core: an information-security management system that works day to day.
DORA changed the tone of the conversation. Before it, IT resilience was a recommendation. Now it is a direct obligation, with no national transposition, and it applies to a wide range of entities: banks, non-bank lenders, insurers, investment firms, payment processors, crypto service providers.
Four things it asks for concretely:
That last point catches many companies off guard. If you outsource your cloud, your payments or your IT support, their risk becomes your risk, and it has to live in your contracts and your plan.
The most common incidents in a financial institution are not spectacular attacks. They are mundane things. An employee sending a file of customer data to the wrong address. A vendor with access that is far too broad. A reused password that turns up in a public leak. A lost laptop with no encryption.
Under GDPR, the fine can climb to 20 million euros or 4% of turnover. But in a bank, the real problem comes after the fine: customers moving their money, and a press headline you keep finding on Google for years. Reputation is harder to rebuild than a penalty is to pay.
Real compliance does not start with buying a security product. It starts with an honest map of where you stand.
A programme like this is exactly what you manage in a single platform with askGDPR: records, risk assessments, policies and incident logs in one place where you can prove compliance when an inspection arrives. For the standards side, see also our information security service and audits and testing.
Beyond GDPR, banks, non-bank lenders, insurers and investment firms fall under the DORA Regulation on digital operational resilience, applicable since 17 January 2025. Many entities are also in scope of the NIS2 Directive. On top of that come the requirements and guidance issued by the National Bank of Romania (BNR) and the Financial Supervisory Authority (ASF) on IT risk.
DORA (Digital Operational Resilience Act) is the EU regulation requiring financial entities to manage IT risk, report major incidents, test the resilience of their systems and control third-party IT providers. It applies directly, without national transposition, to a wide range of entities: banks, non-bank lenders, insurers, investment firms, payment processors and crypto-asset providers.
Under GDPR, fines can reach 20 million euros or 4% of global annual turnover. For a financial institution, the reputational cost and the loss of customer trust usually outweigh the fine itself.
With an assessment of the current situation: what data it processes, where it is stored, who has access and which legal requirements apply. That GAP analysis becomes the basis for an alignment plan with clear priorities, before buying technology or writing policies.
We assess where you stand and build an alignment plan for GDPR, DORA and NIS2, tailored to a bank, a non-bank lender or a fintech.