Skip to content
News · GDPRhub EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026

How it connects

Full text

A telecom company received a €100,000 fine for breaching Articles 25 and 32 GDPR by failing to implement adequate technical and organizational safeguards and ensure the security of personal data processing. English Summary. Facts. A customer (the data subject) of Orange Romania SA (the controller) was able to access and download invoices belonging to other customers. As a result, personal data such as names, addresses, delivery addresses, ID document details, and invoice information were disclosed. The incident was caused by a mismatch between two interconnected applications, which incorrectly linked the data subject's account to an employee account. During the investigation, another vulnerability was identified in the controller's ticketing application. The platform was publicly accessible and lacked adequate security measures, such as VPN protection, multi-factor authentication, and IP-based access restrictions. This vulnerability enabled a cyberattack that resulted in the

Similar Content