Skip to content
Enforcement · Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Orange Romania SA: Insufficient technical and organisational measures to ensure information security

€100,000 Fine
Orange Romania SA
Romania
Art. 25 GDPR Art. 32 GDPR
Media, Telecoms and Broadcasting
Decided 2026-07-17

How it connects

Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE) Background informationDate of final decision: 28 August 2026National caseLegal Reference(s): Article 5 (Principles relating to processing of personal data), Article 32 (Security… Sep 3, 2026 Data Breaches Notification Obligation Integrity and Confidentiality Principle
2016 IEHC 323 On 25 May 2018, Michael Veale, the data subject, submitted an access and data portability request to Meta Platforms Ireland Limited (MPIL) (then Facebook Ireland Limited), the controller He requested access to all personal data concerning him stored in the controller's internal "Hive" data warehouse under Article 15 GDPR, including the data in raw form and… 2016 IEHC 323 ·High Court Aug 21, 2026 Data Portability Right of Access Procedures Right of Access
ROT 25/8349, 25/8350, 25/6295, 25/6296 and 25/6297 A data subject submitted 73 separate GDPR requests to the Municipal Executive of Rotterdam, the controller, between November 2024 and February 2025 Most requests contained several sub-requests and relied on Articles 5, 6, 10, 14, 15, 16, 17 and 19 GDPR. The controller refused the requests under Articles 15, 16, 17 and 19 GDPR… ROT 25/8349, 25/8350, 25/6295, 25/6296 and 25/6297 ·Rb. Rotterdam Aug 19, 2026 Right of Access Procedures Right of Access Personal Data
7 A 170/24 VG Osnabrück - 7 A 170/24 A firearms authority (the controller) sent the holder of a hunting license and a firearms ownership card (the data subject) information required under Articles 13 and 14 GDPR… Administrative Court Osnabrück Aug 19, 2026 Right to Restriction Right of Access Procedures Accuracy
M 32 E 26.3990 The author of a manuscript (the data subject) submitted their text to an editorial office of a quarterly journal for review in November 2025 The journal was published by a private publishing company and overseen by several co-editors, including two professors at a Bavarian university (the alleged controller). The data… VG München - M 32 E 26.3990 ·Administrative Court Munich Aug 11, 2026 Right of Access Procedures Right of Access Controllers
W137 2334047-1 The data subject did not pay for items ordered and collected from a pharmacy (controller) After several reminders, the controller commissioned a debt collection agency, which pointed to several enforcement proceedings against the data subject. The controller then… BVwG - W137 2334047-1 ·Federal Administrative Court Aug 3, 2026 Legitimate Interest Retention Period Professional Secrecy

We hold a reference to this item, not its text.

www.enforcementtracker.com Read at the source

Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) · Jul 17, 2026