Fine against Poliserv JG (PJG) SRL
A personal data breach occurred because of a cyberattack made possible through a phishing method that stole the credentials of a controller account with administrator privileges.
Holding
ANSPDCP found that the controller infringed Article 32(1)(b) GDPR and Article 32(2) GDPR by failing to implement adequate technical and organisational measures to ensure the security of personal data processing. Considering that a phishing attack compromised an administrator account and enabled unauthorised access to customers' personal data, the controller's security measures and testing procedures were not appropriate for maintaining the ongoing confidentiality, integrity, availability and resilience of processing systems and services. In addition, as a corrective measure, pursuant to Article 58(2)(d) GDPR, the DPA ordered the controller to periodically verify compliance with its data protection and information security procedures and provide regular phishing-awareness training to its personnel working with personal data. Finally, for these violations, ANSPDCP decided to fine the controller €3,000 (RON 15,728).
From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓
Full text 2 findings
Machine translation of the decision, via GDPRhub — not the official text. Read the original
August 19, 2026 Fine for Violating the GDPR In July 2026, the National Supervisory Authority for Personal Data Processing concluded an investigation into Poliserv JG (PJG) SRL and found a violation of the provisions of Article 32, paragraph (1)(b) and paragraph (2) of the General Data Protection Regulation (GDPR). As a result, Poliserv JG (PJG) SRL was fined 15,728 lei, equivalent to 3,000 euros. The investigation was initiated following the submission by Poliserv JG (PJG) SRL of a notification of a personal data breach, in accordance with the provisions of Article 33 of Regulation (EU) 2016/679. The investigation found that the data processing security breach occurred as a result of a cyberattack that exploited a vulnerability involving the credentials of a user account with administrator privileges, which had been stolen through phishing. This situation led to unauthorized access to the personal data (at least: first and last names) of certain individuals who were customers of the data controller.
Thus, it was found that the operator had not implemented adequate technical and organizational measures and had not conducted the testing, evaluate, and assess the effectiveness of the technical and organizational measures on a regular basis to ensure the security of processing, including the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of the processing systems and services. The National Supervisory Authority determined that the circumstances of the above-mentioned case are sufficiently serious to warrant the imposition of a fine against the controller, in accordance with the criteria for determining the amount of fines set forth in Article 83 of Regulation (EU) 679/2016. At the same time, pursuant to the provisions of Article 58(2)(d) of Regulation (EU) 2016/679, the controller Poliserv JG (PJG) SRL to periodically verify compliance with the implemented working procedures regarding the protection of personal data and information security, and to periodically train persons acting under the controller’s authority regarding the risks associated with the processing of personal data, including with regard to identifying and handling phishing messages and other suspicious emails. Legal and Communications Department A.N.S.P.D.C.P.