Victoriabank
  • RO
  • RU
  • EN
Кредиты
Карты
Вклады | Счета
Страхование
Трансферы
Инвестиции
Контакты
Вход в VB24
Отдел кредитования
Контакты|Блог|Новости
Victoriabank
ПерсоналПерсонал
БизнесБизнес
КонтактыВход в VB24Отдел кредитования
RO
Кредиты
НедвижимостьНедвижимость
Потребительские товарыПотребительские товары
На картуНа карту
Карты
Пропускная способностьПропускная способность
КредитныйКредитный
Вклады | Счета
АкцииАкции
ВкладыВклады
Текущий счетТекущий счет
Страхование
Здоровье
Авто
Товары
Трансферы
На банковский счет
Быстрые
Инвестиции
Государственные ценные бумаги
Рынок капитала
Продажа залога
/Privacy Hub/Privacy Policy

Policy Processing and Protection of Personal Data at B.C. “Victoriabank” S.A.

Privacy Policy

1.1. The Policy on the Processing and Protection of Personal Data in the Course of the Activities of B.C. “Victoriabank” S.A. (Privacy Policy) (hereinafter, the Policy) sets forth the general vision of the management bodies of B.C. “Victoriabank” S.A. (hereinafter, the Bank) regarding the processing and protection of personal data in the context of strengthening a robust governance framework for the Bank, promoting a strong culture of compliance with applicable legal provisions, and upholding the Bank’s principles and values.
1.2. The Bank processes the personal data (hereinafter “personal data” or “data”) of individuals in accordance with applicable legal provisions, to the highest standards of security and confidentiality, respects the fundamental rights and freedoms related to such processing, and periodically evaluates its activities in this area to ensure that these rights are respected.
1.3. This Policy is drafted in accordance with national and European Union legislation, the Bank’s internal regulations, and the regulations of the Banca Transilvania Financial Group to the extent they are applicable, as follows:
1.3.1. Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of individuals with regard to the processing of personal data and on the free movement of such data;
1.3.2. Civil Code of the Republic of Moldova No. 1107-XV of June 6, 2022;
1.3.3. Law No. 195 of July 25, 2024, on the protection of personal data (in force as of August 23, 2026);
1.3.4. Law No. 133 of July 8, 2021, on the protection of personal data;
1.3.5. Law No. 308 of December 22, 2017, on the prevention and combating of money laundering and terrorist financing;
1.3.6. Law No. 114 of May 18, 2012, on payment services and electronic money.

2.1. For the purposes of this Policy, the terms below are defined as follows:

personal data – any information relating to an identified or identifiable individual (hereinafter – data subject). An identifiable individual is an individual who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that individual;

processing – any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction;

controller – an individual or legal entity, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of processing are determined by law, the controller or the specific criteria for its designation are provided for by such laws;

processor – an individual or legal entity, public authority, agency, or other body that processes personal data on behalf of the controller;

recipient – an individual or legal entity, public authority, agency, or other body to whom personal data is disclosed, whether or not that entity is a third party. Public authorities to which personal data may be communicated in the context of a specific investigation in accordance with the law are not considered recipients; the processing of such data by those public authorities complies with applicable data protection rules, in accordance with the purposes of the processing;

third party – an individual or legal entity, public authority, agency, or body, other than the data subject, the controller, the processor, and persons who, under the direct authority of the controller or the processor, are authorized to process personal data;

consent – any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

 

2.2. In the context of this Policy, the following acronyms shall have the following meanings:

Governing Bodies – the Bank’s Board of Directors and Executive Committee

BT – Banca Transilvania Financial Group

BNM – National Bank of Moldova

CNPDCP – National Center for Personal Data Protection

3.1. The processing of personal data is carried out in accordance with the following principles:

3.1.1. the principles of lawfulness, fairness, and transparency – personal data is processed responsibly, in good faith, and in accordance with applicable law, ensuring fair and transparent treatment of the data subject.

3.1.2. the principle of purpose limitation – personal data is collected for specified, explicit, and legitimate purposes and is not further processed in a manner incompatible with those purposes.

3.1.3. the principle of data minimization – personal data are adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.

3.1.4. the principle of accuracy – personal data are kept accurate and, where necessary, kept up to date; measures are taken to ensure that data that is inaccurate, in light of the purposes of processing, is rectified or, where appropriate, erased.

3.1.5. the principle of storage limitation – personal data shall be stored only for as long as is necessary to fulfill the purposes for which it is processed. However, such data may be retained for longer periods, in accordance with legal provisions, for archiving, scientific research, or statistical purposes, subject to appropriate technical and organizational measures to ensure the protection of the rights and freedoms of data subjects.

3.1.6. the principle of integrity and confidentiality — the processing of personal data shall be carried out securely, through the implementation of appropriate technical and organizational measures to ensure their adequate protection. These measures will include preventing unauthorized or unlawful processing, as well as protecting the data against accidental loss, destruction, or damage.

4.1. Depending on the purpose of processing personal data and/or the nature of the contractual relationship with the bank (employee, customer, partner, etc.), as well as taking into account the specific nature of the activities carried out, the following categories of personal data may be processed:

4.1.1. identification data: data included in the identity document, first name, last name, national identification number (IDNP), date and place of birth, citizenship, etc.;

4.1.2. contact information: home or residence address, mailing address, email, phone number, etc.;

4.1.3. professional information such as: profession or occupation, position held, employer or nature of self-employed activities, as well as, where applicable, public office held, etc.;

4.1.4. data regarding family status: marital status, matrimonial regime, number of dependents, family relationships, information about marriage or cohabitation, etc.;

4.1.5. information regarding financial status: income, bank transactions and their history, property owned, etc.;

4.1.6. banking information: IBAN codes, bank account, bank card details, as well as other information necessary for identification or transaction processing, etc.;

4.1.7. biometric data: data resulting from specific processing techniques relating to the physical, physiological, or behavioral characteristics of a natural person that allow for or confirm the unique identification of that person, such as facial images or fingerprint data.

4.1.8. electronic signature, handwritten signature, etc.;

4.1.9. image: photo (from the provided identification document, as well as the photo taken when using online services) and video (video recording);

4.1.10. voice: recorded during telephone conversations with bank representatives (e.g., call center services, as well as other departments involved in discussions with bank customers);

4.1.11. political affiliation: information related to the status of a politically exposed person, in specific cases, which is processed in accordance with applicable legislation on the prevention and combating of money laundering and terrorist financing;

4.1.12.  other data necessary for business purposes.

The Bank processes personal data to ensure the provision of financial and banking services, the fulfillment of contractual obligations, compliance with applicable legal requirements and regulations, as well as to protect the legitimate rights and interests of the Bank and the data subjects.

5.1. Personal data is processed within the Bank for the following purposes, as applicable:

5.1.1. Establishing, performing, and terminating contractual relationships with customers for the provision of banking services and products;

5.1.2. Establishing, executing, and terminating employment relationships with the bank’s employees;

5.1.3. Entering into, performing, and terminating contractual relationships regarding the bank’s procurement of goods, services, and works;

5.1.4. The provision of banking products and services, including online, both to the bank’s customers and to other individuals who occasionally use these services;

5.1.5. Implementing measures to identify, assess, and manage risks related to the prevention of fraud, money laundering, and terrorist financing, including the application of know-your-customer procedures, risk analysis, and the reporting of suspicious transactions;

5.1.6. Assessing customers’ financial standing, determining their debt levels, and managing credit risk related to the credit products offered by the Bank;

5.1.7. Reporting information to the competent authorities (the National Bank of Moldova, the State Tax Service, the Credit History Bureau, etc.) and accessing data from the databases managed by them, in accordance with applicable law;

5.1.8. Compliance with legal obligations regarding the provision of information, upon request by public authorities, private entities, and other requesters as provided by law;

5.1.9. Debt collection and management of enforcement proceedings, including the administration and prosecution of legal actions;

5.1.10. Issuing insurance documents and determining payment obligations in the event of insured risks, where the banking product includes insurance (life/property);

5.1.11. Monitoring and verifying transactions to prevent fraud and investigate security incidents;

5.1.12. Handling customer requests and complaints through all available communication channels, including online;

5.1.13. Ensuring the security of premises, as well as the protection of people and property, through video surveillance systems;

5.1.14. Recording, storing, and archiving communications conducted through various channels (online, by phone, email, etc.) to improve service quality and optimize contractual processes;

5.1.15. Conducting direct marketing campaigns to promote the Bank’s services and products, including through digital channels, based on the consent of the data subjects or the Bank’s legitimate interest, as applicable;

5.1.16. Creating and using profiles based on personal data to improve the products and services offered, as well as to send general or personalized marketing communications. Communications may be sent through various channels (e.g., mail, telephone, email), including through entities within the BT Financial Group.

5.1.17. Conducting assessments of customer satisfaction and the quality of banking services to ensure the continuous improvement of the customer experience;

5.1.18. Collecting and processing data for statistical purposes, with a view to evaluating and improving the performance and efficiency of banking services;

5.1.19. Other purposes relevant to and specific to the Bank’s activities, in accordance with applicable internal and external regulations.

6. The processing of personal data is carried out on the following legal grounds:

6.1. compliance with a legal obligation to which the Bank is subject, when processing is necessary to comply with applicable legal requirements;

6.2. the conclusion or performance of a contract to which the data subject is a party, or to take steps at the data subject’s request prior to entering into a contract;

6.3 the legitimate interests of the Bank and/or third parties, provided that such interests do not override the fundamental rights and freedoms of the data subject;

6.4. the performance of a task carried out in the public interest, including the application of know-your-customer measures for the purpose of preventing and combating money laundering and terrorist financing;

6. 5. the data subject’s freely given, informed, and unambiguous consent.

In situations where legal provisions require the processing of certain personal data or where such data is necessary for the conclusion or performance of contracts, regarding products/services or for carrying out occasional transactions, refusal to provide or allow the processing of such data may result in the inability to become or remain a customer of the Bank, as well as/or the inability to process the requested transactions.

Withdrawal of consent takes effect only prospectively and results in the cessation of the processing of personal data based on this ground, without affecting the lawfulness of processing carried out previously or of processing based on other legal grounds.

The Bank will cease processing personal data in the event of withdrawal of consent or the exercise of the right to object, except in situations where such processing is justified by another legal basis.

7.1. The Bank, as the data controller, processes personal data in accordance with applicable law. A person is a data subject in the context of the Bank’s data processing in the capacity of:

7.1.2. Employee/member of management bodies: an employee, a collaborator of the Bank, and a member of management bodies, including contract staff.

7.1.3. Individual customers: individuals who access or use financial products and services offered by the Bank.

7.1.4. Legal representative/authorized representative of customers: persons acting on behalf of customers, whether natural persons or legal entities.

7.1.5. Job applicant: a person applying for a job at the Bank.

7.1.6. Business partners/suppliers: individuals or representatives of legal entities with whom the Bank conducts business.

7.1.7. Visitor: individuals who visit the Bank’s premises, whose data may be collected, including through video surveillance systems, as well as individuals who use the Bank’s official websites, social media pages, remote banking systems, online applications, virtual assistants, etc.;

7.1.8. Participants in campaigns or contests: individuals who participate in events, promotions, contests, or other activities organized by the Bank.

7.1.9. Individuals involved in transactions: individuals whose data is processed in the context of carrying out transactions, such as payment recipients or other involved parties.

7.2. Data subjects are informed of the purpose and conditions of personal data processing through the privacy notices included in the forms used by the Bank in the course of providing its services (e.g., applications, contracts, questionnaires, declarations, etc.), as well as through the publication of relevant information on the Bank’s official website (specific information notices), through automated remote service systems, and through other communication channels established within the Bank.

Under applicable law, individuals whose personal data is processed have the following rights:
8.1. the right to information – is ensured by the bank through this privacy policy, information notices, forms used in customer relations, as well as through the publication of relevant information on the bank’s official website and other communication channels.
8.2. the right of access - Data subjects may request confirmation that the bank is processing their personal data, as well as access to such data, including information regarding the purposes of processing, the recipients or categories of recipients to whom the data is disclosed, and any other relevant details.
8.3. right to rectification – Data subjects have the right to request that the Bank correct any inaccurate data concerning them or, where applicable, complete any incomplete data;
8.4. the right to erasure (“the right to be forgotten”) – data subjects may request the erasure of their personal data when it is no longer necessary for the purposes for which it was collected, when they withdraw their consent and there is no other legal basis for processing, or when erasure is necessary to comply with a legal obligation of the Bank.
8.5. the right to restriction of processing – data subjects may request that the use of their personal data be restricted in certain situations, such as: when they contest the accuracy of the data (pending verification), when the processing is unlawful, but do not wish to have the data erased, when the data is necessary to defend a legal claim in court, etc.
8.6. the right to data portability – data subjects may request that the Bank, in accordance with the law, provide certain personal data in a structured, commonly used, and machine-readable format. At their request, the data may be transferred directly to another controller, if this is technically feasible.
8.7. Right to Object – Data subjects have the right to object, at any time, to the processing of their data for marketing purposes or when the processing is based on the Bank’s legitimate interest, if there are reasons related to their particular situation.
8.8. the right regarding automated individual decision-making – grants data subjects the right not to be subject to a decision made exclusively by automated means, including profiling, if it produces legal effects concerning them or similarly significantly affects them. They may express their views, challenge the decision, and request human intervention, namely a review of the automated decision by a Bank employee.
8.9. The right to file a complaint with the National Center for the Protection of Personal Data – Data subjects have the right to file a complaint with the National Center for the Protection of Personal Data if they believe their rights have been violated.
The exercise of the rights mentioned above, with the exception of the right to file a complaint with the National Center for Personal Data Protection, can be exercised by: submitting a request to any branch of BC “Victoriabank” SA or sending the request electronically to the email address: dcp@vb.md. The bank will respond to requests without delay, in accordance with applicable law.

9.1. The Bank processes personal data provided directly by the data subject or indirectly by third parties (for example, through an authorized person or other representatives in the relationship with the Bank), as well as data generated or inferred as a result of interaction with the data subject through various communication channels used by the Bank. In addition, the Bank may collect and process personal data from external sources, as follows:

  • public institutions and authorities (for example: the State Tax Service, the National Social Insurance House, etc.). In this regard, the Bank may access or query the databases of these entities, in accordance with the law, to obtain relevant information, such as: tax status (including tax identification number), data regarding income and employment status, information from asset declarations (in the case of politically exposed persons), as well as data provided by credit reporting agencies, including information regarding the types of loans taken out, the level of indebtedness, or membership in a group of debtors, etc.

  • electronic registers and databases (for example: the courts’ portal, entities authorized to manage databases regarding persons subject to international asset-freeze sanctions or politically exposed persons, etc.). In this context, upon initiation of or during the relationship with the Bank, checks may be performed, including, but not limited to: (i) querying the court portal to identify any pending litigation; (ii) consulting credit bureaus to assess payment behavior and debt levels, particularly when applying for credit products and monitoring them, etc.; (iii) checking databases of designated individuals and those subject to international asset-freezing sanctions, as well as those classified as politically exposed persons, etc.

  • entities involved in payment transactions (e.g., Visa/Mastercard, merchants that accept card payments, banks, etc.). In this regard, the Bank may receive and process personal data necessary for executing and processing transactions. Furthermore, in the context of other types of transactions (e.g., credit transfers, direct debits, etc., the Bank may receive personal data from other banks or payment institutions with which the transaction was initiated via payment systems or interbank communication networks (such as SWIFT, etc.).

  • business partners, in particular service providers for the Bank. In certain situations, the Bank may receive and process personal data from business partners, within the limits of the law and contractual relationships.

  • online platforms (social media and other publicly accessible sources), including data aggregators. The Bank may collect and process publicly available personal data, in accordance with the law, directly from such sources or through providers specializing in the collection and aggregation of information from open sources.

  • other companies for which the Bank provides payment services (securities issuers, insurance companies, etc.).

  • The Central Depository, in its capacity as the registry company for the Bank’s shares.

9.2. In certain situations, we may obtain personal data from the Bank’s customers or their representatives (for example: the customer’s family members, etc.), members of the Bank’s management bodies (or their affiliates, etc.), if such data is necessary in the context of the legal relationship with the Bank’s customer.

9.3. Refusal to provide the Bank with personal data may, in certain situations, make it impossible to establish a relationship with the Bank or to contract for the desired product or service.

10.1. Personal data is processed by the Bank in accordance with the timeframes established by applicable law and internal regulations, for a period that shall not exceed the time necessary to achieve the purposes for which it was collected and subsequently processed.
10.2. The Bank has a legal obligation to retain all documents and information necessary for the implementation of know-your-customer measures, including those relating to customers and beneficial owners, for a period of 5 years from the termination of the business relationship or from the date of an occasional transaction. This data will be retained in an appropriate format so that it can be provided, upon request, to the competent authorities and/or used as evidence in court.
10.3. In exceptional cases, and only at the request of the authorities, the retention period for certain types of information may be extended by up to an additional 5 years.
10.4. Video footage captured by video surveillance systems will be stored for a period of 30 days. As an exception, the data retention period may be extended if permitted by applicable law. The Bank may retain video recordings for an extended period based on a legitimate interest, namely: defending the rights and interests of the Bank or the data subject in court, interaction with public authorities, the initiation of internal inquiries or investigations, etc.
10.5. The processing (storage) of personal data for a longer period, for statistical and analytical purposes (if applicable, by anonymizing them), will be carried out in accordance with applicable law and in compliance with the safeguards regarding the processing of personal data stipulated by applicable regulations, and only for the period necessary to achieve these purposes.
10.6. Upon expiration of the processing period, personal data is destroyed or deleted depending on the medium on which it was stored, with records of this action maintained in accordance with internal regulations. In the case of obligations expressly provided for by law, such data may be retained, in accordance with the rules of the State Archives Service, for archiving purposes in the public interest.

11.1. Information containing personal data is treated by the Bank as confidential. This data will not be transferred to third parties, except in cases where the Bank is required or, as per , permitted by law to provide it to: public authorities, supervisory authorities, tax authorities, courts, or other competent bodies, in accordance with applicable legal regulations.

11.2. The transfer of personal data is subject to review to verify the purpose and legal basis for the disclosure of the data. The Bank may disclose personal data, in accordance with the law, to the following categories of recipients:

  • persons authorized or designated by the customer (e.g., representatives);

  • financial and banking entities (e.g., Banca Transilvania and other entities that are part of the Banca Transilvania financial group, correspondent banks, participants in payment systems);

  • credit reporting agencies;

  • insurance companies;

  • property appraisers (in the context of lending);

  • guarantee funds/entities;

  • assignees;

  • notaries, attorneys, bailiffs, courts, and public authorities, etc.;

Data may also be transmitted to service providers, such as:

  • IT and maintenance providers, etc.;

  • archiving and courier services, etc.;

  • debt collection;

  • payment/card processing;

  • communication services (SMS/email);

  • marketing, etc.

11.3. When personal data is transferred to third parties, the recipient is informed of the need to process such data solely for the requested purpose, via the information notice placed in the footer of any document classified by the Bank, depending on the level of confidentiality. In the case of the Bank’s suppliers and business partners acting as data processors, instructions regarding data processing are provided, and guarantees regarding data security are required through specific contractual clauses, confidentiality agreements, and, where applicable, relevant certifications and other appropriate measures. 11.4. The cross-border transfer of personal data is carried out in accordance with legal provisions or international agreements to which the Republic of Moldova is a party. Data may be disclosed to competent international authorities, within the limits established by applicable law, in compliance with applicable safeguards regarding the protection of personal data. The Bank may transfer personal data outside the Republic of Moldova only under the conditions provided by applicable law, when:

  • the destination country ensures an adequate level of protection for personal data; or

  • adequate safeguards are in place to protect the data, such as contractual clauses or other recognized legal mechanisms.

12.1. The Bank implements, develops, and maintains appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or destruction.

12.2. The Bank employs advanced security technologies and methods, along with rigorous policies governing employees and work procedures (including antivirus solutions, firewalls, DLP, and data encryption systems, etc.). All operational and data processing systems operate in secure environments to ensure that information is protected against unauthorized access.

12.3. Access to the Bank’s information and systems is permitted only to authorized persons, for well-defined purposes, and in strict accordance with internal security policies and job responsibilities.

12.4. Employees are trained upon hiring regarding the importance of maintaining the confidentiality of information, as well as during subsequent thematic training sessions.

Victoriabank

Follow us:

FacebookLinkedInYouTubeTikTokInstagram
accident insurance1303Număr unic

Publication of Information

Bank Governance
Economic and Financial Activity
Banking Products and Services
Rates and General Terms and Conditions
Business Rates and General Terms and Conditions
Governance framework, own funds and capital requirements, capital buffers

Customer Support

Contacts
Suggestions
ESG Reports
Anti-Fraud Reports
Complaints

Online Safety

Privacy Hub
About VB24
About VB24 Business
Open Banking

© Victoriabank 2026. All rights reserved.

Footer iconVictoriabank — a member of the deposit insurance scheme in the Republic of Moldova
Victoriabank

Follow us:

FacebookLinkedInYouTubeTikTokInstagram
1303Număr unic
Footer icon
Victoriabank — a member of the deposit insurance scheme in the Republic of Moldova

© Victoriabank 2026. All rights reserved.