On 10 June 2026, the General Anti-fraud Directorate announced the result of an inspection at a construction company: labour purchases of 27 million lei, declared on the basis of invoices issued in the name of four shell companies, according to ANAF, Romania's national tax administration, “through the abusive use of the RO e-Factura system”. Estimated loss: around 8.7 million lei, representing liabilities on the salary income of people who were actually working but appeared nowhere in the records. The press release ends predictably: the Anti-fraud Directorate will refer the matter to the criminal investigation bodies.
Note the technical detail, because it says everything about 2026: the scheme described in the press release was not discovered by counting box files. The invoices had themselves been transmitted through the state's own IT system. This is the new starting point for every tax evasion case and, equally, for every serious defence.
Since July 2024 for B2B and January 2025 for B2C, the invoice is transmitted through the national system, receives the electronic seal of the Ministry of Finance, and stays there, with a timestamp. Since 1 January 2026, the time limit for transmission has been 5 working days from issue, instead of the earlier 5 calendar days, a change made by O.U.G. nr. 89/2025, the “omnibus ordinance” published at the end of 2025.
The standard tax audit file, extended to small taxpayers from 1 January 2025. In 2026, the obligation is fully in force: those with a monthly VAT period file monthly, the rest, including non-VAT-registered taxpayers, file quarterly. Failure to file on time: a fine of 1,000 to 5,000 lei; incorrect or incomplete information: 500 to 1,500 lei.
The UIT code links the transport to the document that justifies it. The grace period ended on 31 December 2025. Confiscation of the value of undeclared goods operates on a graduated scale, over a 12 month period: a fine only for the first breach, then 15%, 50% and 100% for subsequent breaches; 12 months with no breaches resets the scale.
The pre-filled P300 return is generated and made available in the SPV (Spațiul Privat Virtual), the tax authority's secure online portal. However, the regime for the compliance notice (notificare de conformare) changed radically from 1 January 2026, as detailed below.
The fines, however, are the uninteresting part. The truly serious element is different: through Legea nr. 126/2024, the legislature expanded the definition of “legal documents” in Legea nr. 241/2005, and an electronic invoice issued, transmitted and received through RO e-Factura expressly fell within this category. The consequence: recording, in an electronic invoice, expenses without real transactions or fictitious transactions, falls directly within the scope of the tax evasion offences, punishable by 3 to 10 years' imprisonment and a ban on certain rights, or a fine.
What is more, the same law separately criminalises the bad-faith use of the RO e-Factura system, in order to create the appearance of legality for fictitious transactions or to conceal the real transactional flow of goods and services. If the loss exceeds the equivalent of EUR 500,000, the penalty limits increase by 3 years; above EUR 1,000,000, by 5 years. The reporting system has therefore become the subject matter of the offence, not merely a source of data.
The difference between SAF-T and a traditional inspection is one of kind, not of degree. In a traditional inspection, the tax authority requested samples and reconstructed the picture. With SAF-T, it receives, in a structured, periodic and machine-readable format: accounts, ledgers, business partners, stock, assets, payments. Not a sample, the whole record. And e-Transport offers something bookkeeping never did: a direct comparison between the goods invoiced and the goods that actually moved.
The regime for the “RO e-TVA compliance notice” changed radically from 1 January 2026: O.U.G. nr. 89/2025 brought to an end the provisions of O.U.G. nr. 70/2024 on the taxpayer's response to the notice, removing both the obligation to submit the justifying note and the sanctions for non-compliance, including where the differences between the pre-filled return (P300) and the return filed (D300) exceed 5,000 lei.
The reason given publicly was ANAF's lack of capacity to review the volume of responses individually. For taxable persons applying cash-basis VAT, the sending of notices is suspended until 30 September 2026, pending completion of the IT tools needed to fill in the pre-filled return. From a sanctioning tool, e-TVA has, for now, become an information flow.
Do not, however, draw the wrong conclusion. The fact that you are no longer required to respond does not mean the discrepancy disappears. It remains calculated, stored and available as an indication for risk analysis, it is simply that you are no longer asked to explain it before someone draws conclusions from it.
Until recently, a tax evasion case was built retrospectively: the inspection requested documents, the taxpayer produced them, the tax authority compared what it had been given with what it found at business partners. There was, inevitably, a window, between the act and the check, in which the records could be “tidied up”.
That window has closed. The data is already with ANAF, timestamped, transmitted by the taxpayer themselves. Accounts “adjusted” retroactively are no longer merely risky: in most cases, they are impossible to reconcile with what the state already holds. And the attempt itself produces new evidence of intent. Legea nr. 126/2024 expressly criminalises altering, destroying or concealing accounting records, the memory of electronic fiscal cash registers, or other means of data storage, including electronic ones, as well as keeping double sets of accounts by electronic means.
On the analysis side, ANAF has announced a move from extensive inspection to “smart”, risk-based inspection: from 1 January 2026, risk analysis becomes the standard method of selection, and the Big Data platform (SIDI), which is to generate risk scores, feed an electronic register of tax risks and build historical taxpayer profiles, is expected to become operational in the second half of 2026.
WARNING: an asymmetry the defence must name explicitly. The application of Article 7(10) of the Tax Procedure Code, the taxpayer's right to request that they be told the tax risk class or subclass they have been placed in, has been suspended until 31 December 2026 by Article V of O.U.G. nr. 13/2026, in force since 9 March 2026; the information is not due to be available directly in the SPV until 1 January 2027, on the stated ground that digitalisation has not been completed. In concrete terms: in 2026 you are selected on the basis of risk, but you have no right to find out what risk you have been assigned, or on what criteria. The algorithm that triggers the inspection cannot be challenged, because it cannot be known.
It flags anomalies: discrepancies between the return and e-Factura, deductions with no matching upstream transaction, business partners behaving like shell companies, gaps between e-Transport and invoicing.
Every invoice has two ends in the same system, so ANAF can reconstruct the chain: who invoices whom, who declares, who pays, where the flow breaks. This is the method used today to detect carousel chains.
The inspection, an unannounced check or an anti-fraud inspection, verifies the hypothesis and records the findings in a report or in minutes.
Under Article 132 of the Tax Procedure Code, the file moves to the prosecutor's office, digital records and all. The point at which an inspection becomes a criminal case is covered separately.
In criminal proceedings, the data is obtained through its own procedural means. The most important is a computer search (Article 168 of the Code of Criminal Procedure): during the criminal investigation, the judge for rights and freedoms can authorise one, at the prosecutor's request, where discovering and gathering evidence requires the examination of an IT system or a storage medium. The request is decided in chambers, without summoning the parties, with the prosecutor's mandatory participation, and the warrant must state, among other things, the period for which it is issued, its purpose and the IT system concerned. In practice, this means seizing servers, cloning storage media, forensic IT expert reports, and a volume of data that frequently exceeds the scope of the case.
This is the part few people make use of: the data that accuses is the same data that can prove the transactions were real.
A real transaction leaves converging traces: an order, transport with a UIT code, receipt of the goods, bank payment, consumption of materials, hours worked, correspondence. A case that treats a transaction as “fictitious” on the basis of a single indication, usually the supplier's tax conduct, is countered with the complete file of traceability evidence.
The systems do not “find” anything; they compare. Frequent causes of a perfectly lawful mismatch: cash-basis VAT, timing differences in chargeability, storno entries and corrected invoices, self-billing, reverse charge, exempt transactions, account-mapping errors in SAF-T, rejections and resubmissions in e-Factura.
The chain of custody, the hash values of the disk images, the metadata, the conditions under which items were seized, whether the limits of the warrant were respected, the presence of the specialist, every link is checkable. Digital evidence gathered outside the warrant or without integrity safeguards is open to challenge, and the procedural stage for this is the preliminary chamber.
The jurisdiction of the body that handled the case is a matter of absolute nullity, not a matter of detail, and it is all the more relevant in evasion cases, where the jurisdiction rules were changed in 2024.
This has to be said clearly, in keeping with the presumption of innocence: a supplier that later becomes inactive does not retroactively turn the buyer into someone who has committed an offence. The case law of the Court of Justice of the European Union consistently protects a taxable person who neither knew nor could have known that the transaction was part of fraud committed further up the supply chain, the right to deduct cannot be refused for someone else's conduct, in the absence of proof of involvement or of a lack of diligence.
The real risk of automation is that a risk score becomes, through institutional repetition, a presumption of guilt: the system flags, the inspection confirms the system's hypothesis, the referral takes over the inspection's finding. The role of the defence is to break this chain at the first documentable link.
GDPR and the limits on processing. The processing of tax data has a legal basis, and the public interest in combating evasion is legitimate. The problems do not come from there, but from proportionality and transparency: the retention period, risk criteria that are not publicly documented, the absence of any algorithmic audit, the impossibility, in 2026, of finding out one's own risk classification. In a criminal case, these are not academic questions: seizing data that goes beyond the scope of the warrant, and processing data unrelated to the case, are arguments going to lawfulness.
Download your own data from the SPV: invoices issued and received in RO e-Factura against your sales and purchase ledgers.
Document internally the reason for every difference, even though from 2026 you are no longer required to respond to the notice. The justifying note you no longer owe ANAF, you owe to your own defence file.
Account mapping and tax codes generate most of the innocent “anomalies”. Also check the consistency between e-Transport and e-Factura for goods with a high tax risk.
Checks in public registers, correspondence, evidence of the service actually being performed. These are built beforehand, not afterwards. See also what documents ANAF can request.
With metadata, not just printed out on paper. A printed PDF proves nothing about integrity.
No changes to the records. Call your lawyer. A last-minute “clean-up” is, in itself, a criminal offence. The strategy for this is covered in the defence in the tax evasion case.
The paradigm has changed: the state no longer has to look for the data, it already has it. What it does not have, and what remains to be proved beyond any reasonable doubt, is intent. That is where the case is won or lost.
Yes, and more than ever. The data does not prove intent, and tax evasion requires intent, not merely a discrepancy. The systems show correlations; the prosecutor has to prove conduct amounting to evasion. Symmetrically, the same data can prove the transactions were real and can show that the flagged mismatch has a lawful, technical explanation.
From 1 January 2026, the obligation to respond and the sanctions for non-compliance were removed by O.U.G. nr. 89/2025, including for differences of more than 5,000 lei; for persons applying cash-basis VAT, the sending of notices is suspended until 30 September 2026. The professional recommendation, however, remains to document internally the reason for the differences: the discrepancy does not disappear from the system and can later be used as a risk indicator.
Yes, under the conditions set out by law. A computer search is ordered by the judge for rights and freedoms, at the prosecutor's request (Article 168 of the Code of Criminal Procedure), and the warrant has limits: a period, a purpose, and the IT system concerned. You have the right to be assisted by a lawyer, to ask for your objections to be recorded, and to request copies. Exceeding the limits of the warrant and the absence of integrity safeguards are raised in the preliminary chamber.
No. Criminal liability is personal, and the right to deduct cannot be refused to a taxable person who neither knew nor could have known that the transaction was part of fraud committed further up the chain. The prosecution has to prove involvement or a lack of reasonable diligence. Documenting checks on business partners in advance is the most effective defence.
Informative material, updated on 18 July 2026. It does not constitute legal or tax advice; individual situations must be assessed on their own facts. The presumption of innocence applies until a final judgment.
If the matter involves a criminal complaint or an open file, the related analyses are grouped under economic criminal law. For how the defence is built, see tax evasion defence.
Time limits run from the date of communication. A first conversation clarifies what is being alleged, what you need to substantiate and how the defence is built, before an estimate becomes a tax assessment decision.