ANSPDCP (Romania) - Fine against Homelux SRL
How it connects
Related across sources
Full text
The DPA fined a home and furniture retailer RON 78,570 (€15,000) after a cyberattack exploited an outdated website platform and weak passwords. It also imposed a RON 30,000 (€5,715) fine for placing non-essential cookies without consent. English Summary. Facts. HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR. The controller was operating a website on a platform that had not been updated to the latest version released by the software provider. Thus, a cyberattack exploited this vulnerability and affected the personal data processed through the website. This incident was further facilitated by weak password requirements for user accounts, a deficiency that remained unremedied after the breach. As a result, personal data processed by the controller, including names, surnames, addresses, email addresses, and passwords, was disclosed to unauthorised parties. During the investigation, the DPA also found that the contro