# Lugera & Makler Broker S.R.L.: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
- Date: 2021-04-19
- Original: https://www.enforcementtracker.com/ETid-637
- Canonical: https://overview.legal/posts/46752
- Topics: Security, Controllers, Processors, Insurance, Privacy by Design & Default, Processing Agreement, Supervisory Authorities, Processing, Data Processor, Personal Data

## Summary

The Romanian DPA (ANSPDCP) has imposed a fine of EUR 1,500 on Lugera & Makler Broker S.R.L.. The controller had accidentally destroyed data of customers of Raiffeisen Bank S.A., for which it acted as processor. The ANSPDCP states that the incident occurred due to the fact that the controller had not taken sufficient technical and organizational measures to ensure an adequate level of protection of the data processing.

## Full text

The Romanian DPA (ANSPDCP) has imposed a fine of EUR 1,500 on Lugera & Makler Broker S.R.L.. The controller had accidentally destroyed data of customers of Raiffeisen Bank S.A., for which it acted as processor. The ANSPDCP states that the incident occurred due to the fact that the controller had not taken sufficient technical and organizational measures to ensure an adequate level of protection of the data processing.

GDPR Articles: Art. 29 GDPR, Art. 32 (2), (4) GDPR
Industry: Finance, Insurance and Consulting

---
Generated by overview.legal · https://overview.legal/posts/46752 · 2026-08-22
