Enforcement · Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
ING Bank N.V. Amsterdam - Bucharest office: Insufficient technical and organisational measures to ensure information security
How it connects
Related across sources
Guidance Guidelines 07/2020 on the concepts of controller and processor in the GDPR Guidance Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 News Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Guidance Guidelines 04/2021 on Codes of Conduct as tools for transfers News DeFine is a calculator for GDPR fines based on method of the EDPB Guidance Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications
Full text
The Romanian DPA (ANSPDCP) imposed a fine of EUR 1,000 on ING Bank N.V. Amsterdam - Bucharest Branch. It was found that the controller had sent files to a contractual partner in order to issue insurance policies. The sent files contained outdated information, as employees of the insurance policy monitoring department had not checked and processed the insurance policies according to the work process, which affected 270 people. Considering these aspects, it was found that the technical and organizational measures taken by the controller were insufficient, which resulted in the breach of confidentiality of personal data.
Industry: Finance, Insurance and Consulting
Original document at the source www.dataprotection.ro