ANSPDCP (Romania) - ANSPDCP (Romania) - Fine against Poliserv JG (PJG) SRL
How it connects
Related across sources
Full text
The Romanian DPA imposed a fine of RON 15,728 (€ 3,000) on a car dealer for failing to implement appropriate technical and organisational measures in order to guarantee the security of its processing, in breach of Article 32 GDPR. English Summary. Facts. A personal data breach occurred because of a cyberattack made possible through a phishing method that stole the credentials of a controller account with administrator privileges. Thus, the personal data of individual customers (at least their first and last names) was accessed by unauthorised parties. Holding. ANSPDCP found that the controller infringed Article 32(1)(b) and Article 32(2) GDPR by failing to implement adequate technical and organisational measures to ensure the security of personal data processing. Considering that a phishing attack compromised an administrator account and enabled unauthorised access to customers' personal data, the controller's security measures and testing procedures were not appropriate for