Skip to content
News · GDPRhub EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

ANSPDCP (Romania) - ANSPDCP (Romania) - Fine against Poliserv JG (PJG) SRL

How it connects

Full text

The Romanian DPA imposed a fine of RON 15,728 (€ 3,000) on a car dealer for failing to implement appropriate technical and organisational measures in order to guarantee the security of its processing, in breach of Article 32 GDPR. English Summary. Facts. A personal data breach occurred because of a cyberattack made possible through a phishing method that stole the credentials of a controller account with administrator privileges. Thus, the personal data of individual customers (at least their first and last names) was accessed by unauthorised parties. Holding. ANSPDCP found that the controller infringed Article 32(1)(b) and Article 32(2) GDPR by failing to implement adequate technical and organisational measures to ensure the security of personal data processing. Considering that a phishing attack compromised an administrator account and enabled unauthorised access to customers' personal data, the controller's security measures and testing procedures were not appropriate for

Similar Content