Skip to content
News · GDPRhub EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

ANSPDCP (Romania) - Fine against GEROCOSSEN S.R.L.

The Romanian DPA imposed a RON 26,236.50 (€5,000) fine on a cosmetics retailer for infringing Article 32 GDPR by failing to implement adequate security measures, after a cyberattack affecting its IT infrastructure led to a personal data breach. English Summary. Facts. The controller suffered a cyberattack that affected its IT infrastructure. As a result, unauthorised parties gained access to personal data relating to some data subjects, including identification and contact details. Holding. The

How it connects

Full text

The Romanian DPA imposed a RON 26,236.50 (€5,000) fine on a cosmetics retailer for infringing Article 32 GDPR by failing to implement adequate security measures, after a cyberattack affecting its IT infrastructure led to a personal data breach. English Summary. Facts. The controller suffered a cyberattack that affected its IT infrastructure. As a result, unauthorised parties gained access to personal data relating to some data subjects, including identification and contact details. Holding. The DPA found that the controller infringed Article 32 GDPR#1b and Article 32 GDPR#2 by failing to implement adequate technical and organisational measures in order to ensure the confidentiality and integrity of its processing systems and services. In particular, the DPA considered that the controller had failed to adopt security measures appropriate to protect personal data processed through its IT infrastructure. In addition, as a corrective measure pursuant to Article 58 GDPR#2d, the DPA ordered