Skip to content
Enforcement · ANSPDCP (Romania) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Fine against Homelux SRL

HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR.

€108,570 Fine
Romania
Art. 32 GDPR

How it connects

3 of 3 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-768/21 TR v Land Hessen In Case C-768/21, the Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning TR's challenge of… CJEU ·First Chamber Sep 26, 2024 Supervision Data Breaches Supervisory Authorities
C-60/22 UZ v Bundesrepublik Deutschland In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik… CJEU ·Fifth Chamber May 4, 2023 Right to Restriction Right to be Forgotten Personal Data
C-340/21 VB v Natsionalna agentsia za prihodite C-340/21 (VB v Natsionalna agentsia) CJEU Dec 14, 2023 Liability Controllers Processors
Guidelines 01/2021 Guidelines 01/2021 Guidelines on Examples regarding Personal Data Breach Notification Guidelines ·EDPB Jan 3, 2022 Notification Obligation Data Breaches Personal Data
S 5 SF 65/24 DS SG Nürnberg: MOVEit zero-day cyberattack via processor did not breach Art. 32 GDPR The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus… Social Court Nuremberg Jun 10, 2026 Processors Controllers Liability

Full text 3 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

July 31, 2026 Penalty for Violating the GDPR and Law No. L. and found a violation of Article 32( (1)(d) and paragraph (2) of Regulation (EU) 2016/679, as well as a violation of Article 4, paragraph (5) of Law No. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector. Accordingly, the data controller was issued the following administrative penalty: a fine of 78,570 lei, equivalent to 15,000 euros, for violating the provisions of Article 32(1)(d) and (2) (2) of Regulation (EU) 2016/679; a fine of 30,000 lei for violating Article 4(5) of Law 506/2004. , of a notification of a personal data breach, in accordance with the provisions of Article 33 of Regulation (EU) 2016/679. During the investigation, it was determined that the incident was caused by a cyberattack on the platform supporting the operation of the website administered by the data controller; at the time of the incident, the platform did not technically comply with the official version released by the manufacturer.

§

At the same time, it was found that the incident was also facilitated by the low complexity of the passwords used when creating accounts on the operator’s website, a deficiency that was not remedied after the incident. The investigation revealed that the operator failed to ensure adequate security of the processed data (first names, last names, addresses, email addresses, and passwords), including protection against unauthorized or illegal processing, as well as accidental loss, destruction, or damage. As such, it was found that the operator had not implemented adequate technical and organizational measures to ensure a level of security appropriate to the risk posed by the processing, including, among other things, the ability to ensure the confidentiality of processing systems and services, as well as the establishment of a process for the periodic testing, evaluation, and assessment of the effectiveness of technical and organizational measures to guarantee the security of the processing.

§

Furthermore, during the investigation, it was found that the controller stored information—specifically, cookies—that were not technically necessary for the operation of its website and accessed information stored on the terminal equipment of the website’s users, without obtaining their consent. At the same time, the National Supervisory Authority also imposed the following corrective measures, ordering the controller to: implement a procedural plan that includes a process for the periodic testing, evaluation, and assessment of all systems and subsequent modifications thereto made by the operator or service providers (authorized persons), particularly with regard to the website it administers; implement appropriate technical and organizational measures to control and secure access to accounts created on the website administered by the operator, including by establishing minimum password complexity requirements, use multi-factor authentication for accounts with administrative privileges, manage and deactivate inactive accounts, and apply the principle of least privilege; implement appropriate technical measures to protect the web application against unauthorized access and the exploitation of vulnerabilities, including mechanisms to detect and block attack attempts, validate and filter user-entered data, and restrict access to administrative interfaces, in order to ensure the confidentiality, integrity, and availability of the personal data being processed; for the website administered by the controller, the conditions set forth in Article 4(5) of Law 506/2004 must be cumulatively met. P