# ANSPDCP (Romania) - Fine against GEROCOSSEN S.R.L.

- Type: News
- Source: GDPRhub
- Date: 2026-09-03
- Original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_Fine_against_GEROCOSSEN_S.R.L.
- Canonical: https://overview.legal/posts/353743
- Topics: Identification, Law Enforcement, Personal Data, Security, Data Breaches, Right of Access, Supervisory Authorities, Notification Obligation, Controllers

## Summary

The Romanian DPA imposed a RON 26,236.50 (€5,000) fine on a cosmetics retailer for infringing Article 32 GDPR by failing to implement adequate security measures, after a cyberattack affecting its IT infrastructure led to a personal data breach. English Summary. Facts. The controller suffered a cyberattack that affected its IT infrastructure. As a result, unauthorised parties gained access to personal data relating to some data subjects, including identification and contact details. Holding. The

## Full text

The Romanian DPA imposed a RON 26,236.50 (€5,000) fine on a cosmetics retailer for infringing Article 32 GDPR by failing to implement adequate security measures, after a cyberattack affecting its IT infrastructure led to a personal data breach. English Summary. Facts. The controller suffered a cyberattack that affected its IT infrastructure. As a result, unauthorised parties gained access to personal data relating to some data subjects, including identification and contact details. Holding. The DPA found that the controller infringed Article 32 GDPR#1b and Article 32 GDPR#2 by failing to implement adequate technical and organisational measures in order to ensure the confidentiality and integrity of its processing systems and services. In particular, the DPA considered that the controller had failed to adopt security measures appropriate to protect personal data processed through its IT infrastructure. In addition, as a corrective measure pursuant to Article 58 GDPR#2d, the DPA ordered

---
Generated by overview.legal · https://overview.legal/posts/353743 · 2026-09-03
