Skip to content
Enforcement · ANSPDCP (Romania) ·Fine against Poliserv JG (PJG) SRL EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Fine against Poliserv JG (PJG) SRL

A personal data breach occurred because of a cyberattack made possible through a phishing method that stole the credentials of a controller account with administrator privileges.

€15,728 Fine
Romania
Art. 32 GDPR

Holding

ANSPDCP found that the controller infringed Article 32(1)(b) GDPR and Article 32(2) GDPR by failing to implement adequate technical and organisational measures to ensure the security of personal data processing. Considering that a phishing attack compromised an administrator account and enabled unauthorised access to customers' personal data, the controller's security measures and testing procedures were not appropriate for maintaining the ongoing confidentiality, integrity, availability and resilience of processing systems and services. In addition, as a corrective measure, pursuant to Article 58(2)(d) GDPR, the DPA ordered the controller to periodically verify compliance with its data protection and information security procedures and provide regular phishing-awareness training to its personnel working with personal data. Finally, for these violations, ANSPDCP decided to fine the controller €3,000 (RON 15,728).

From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓

Full text 2 findings

Machine translation of the decision, via GDPRhub — not the official text. Read the original

Paragraphs carrying a topic or an applied provision show those connections inline
§

August 19, 2026 Fine for Violating the GDPR In July 2026, the National Supervisory Authority for Personal Data Processing concluded an investigation into Poliserv JG (PJG) SRL and found a violation of the provisions of Article 32, paragraph (1)(b) and paragraph (2) of the General Data Protection Regulation (GDPR). As a result, Poliserv JG (PJG) SRL was fined 15,728 lei, equivalent to 3,000 euros. The investigation was initiated following the submission by Poliserv JG (PJG) SRL of a notification of a personal data breach, in accordance with the provisions of Article 33 of Regulation (EU) 2016/679. The investigation found that the data processing security breach occurred as a result of a cyberattack that exploited a vulnerability involving the credentials of a user account with administrator privileges, which had been stolen through phishing. This situation led to unauthorized access to the personal data (at least: first and last names) of certain individuals who were customers of the data controller.

§

Thus, it was found that the operator had not implemented adequate technical and organizational measures and had not conducted the testing, evaluate, and assess the effectiveness of the technical and organizational measures on a regular basis to ensure the security of processing, including the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of the processing systems and services. The National Supervisory Authority determined that the circumstances of the above-mentioned case are sufficiently serious to warrant the imposition of a fine against the controller, in accordance with the criteria for determining the amount of fines set forth in Article 83 of Regulation (EU) 679/2016. At the same time, pursuant to the provisions of Article 58(2)(d) of Regulation (EU) 2016/679, the controller Poliserv JG (PJG) SRL to periodically verify compliance with the implemented working procedures regarding the protection of personal data and information security, and to periodically train persons acting under the controller’s authority regarding the risks associated with the processing of personal data, including with regard to identifying and handling phishing messages and other suspicious emails. Legal and Communications Department A.N.S.P.D.C.P.

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-768/21 TR v Land Hessen In Case C-768/21, the Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning TR's challenge of… CJEU ·First Chamber Sep 26, 2024 Supervision Data Breaches Integrity and Confidentiality Principle
C-687/21 BL v MediaMarktSaturn Hagen-Iserlohn GmbH In Case C-687/21, the Court of Justice of the European Union interpreted Articles 5, 24, 32, and 82 of the GDPR in response to a preliminary ruling request from the Amtsgericht… CJEU ·Third Chamber Jan 25, 2024 Liability Integrity and Confidentiality Principle Data Breaches
C-60/22 UZ v Bundesrepublik Deutschland In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik… CJEU ·Fifth Chamber May 4, 2023 Right to Restriction Right to be Forgotten Personal Data
C-741/21 GP v juris GmbH In Case C-741/21, the Court of Justice of the European Union (Third Chamber) addressed a preliminary reference from the Landgericht Saarbrücken in proceedings between data subject… CJEU ·Third Chamber Apr 11, 2024 Liability Personal Data Integrity and Confidentiality Principle