ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026
How it connects
Related across sources
Full text
A telecom company received a €100,000 fine for breaching Articles 25 and 32 GDPR by failing to implement adequate technical and organizational safeguards and ensure the security of personal data processing. English Summary. Facts. A customer (the data subject) of Orange Romania SA (the controller) was able to access and download invoices belonging to other customers. As a result, personal data such as names, addresses, delivery addresses, ID document details, and invoice information were disclosed. The incident was caused by a mismatch between two interconnected applications, which incorrectly linked the data subject's account to an employee account. During the investigation, another vulnerability was identified in the controller's ticketing application. The platform was publicly accessible and lacked adequate security measures, such as VPN protection, multi-factor authentication, and IP-based access restrictions. This vulnerability enabled a cyberattack that resulted in the