# ANSPDCP (Romania) - AMATO BESTSELLER S.R.L.

- Type: News
- Source: GDPRhub
- Date: 2026-08-18
- Original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_AMATO_BESTSELLER_S.R.L.
- Canonical: https://overview.legal/posts/291260
- Topics: Special Categories of Data, Integrity and Confidentiality Principle, Cookies, Telecommunications, Direct Marketing, Security, Types of Special Categories of Personal Data, Data Breaches, Supervisory Authorities, Article 9 Special Categories Processing Conditions

## Summary

The DPA imposed a 54,300 fine to a controller for violations of Article 32(4), Article 14 and Article 5(1)(c) in conjunction with Article 9 GDPR and ePrivacy Directive.The DPA imposed a RON 285,395 (€54,300) fine on a wholesale company for, amongst others, failing to implement appropriate security measures, allowing former employees to access personal data as well as for unlawfully using automated dialing and communication systems to call a significant number of data subjects. English Summary. E

## Full text

The DPA imposed a 54,300 fine to a controller for violations of Article 32(4), Article 14 and Article 5(1)(c) in conjunction with Article 9 GDPR and ePrivacy Directive.The DPA imposed a RON 285,395 (€54,300) fine on a wholesale company for, amongst others, failing to implement appropriate security measures, allowing former employees to access personal data as well as for unlawfully using automated dialing and communication systems to call a significant number of data subjects. English Summary. English Summary . Facts Facts. A general wholesale/retail trade company (controller) failed to implement adequate technical and organisational measures, such as appropriate training of its employees, in order to secure personal data from unauthorized access. Subsequently, for a specific period of time, former and current employees were able to access personal data (first name, last name, phone number, the relationship between one data subject and another, occupation, marital status, a person’s cl

## Cited law provisions (4)

### GDPR — gdpr-art-5-par-1-pnt-c-en

adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);

### GDPR — gdpr-art-32-par-4-en

The controller and processor shall take steps to ensure that any natural person acting under the authority of the controller or the processor who has access to personal data does not process them except on instructions from the controller, unless he or she is required to do so by Union or Member State law.

### GDPR — gdpr-art-9-en

Processing of special categories of personal data

### GDPR — gdpr-art-14-en

Information to be provided where personal data have not been obtained from the data subject

---
Generated by overview.legal · https://overview.legal/posts/291260 · 2026-08-22
