Enforcement · Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Civil law firm 'Sabou, Burz & Cuc': Insufficient legal basis for data processing
How it connects
Related across sources
Guidance Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority (AT SA) regarding the certification criteria of BDO Consulting GmbH Case Law Deutsche Wohnen SE v Staatsanwaltschaft Berlin News Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Guidance EDPB Annual Report 2021 Guidance Guidelines 04/2021 on Codes of Conduct as tools for transfers Literature General Data Protection Regulation (GDPR) ambiguity, national diversity and data protection officer certification: Implementing Art. 39(1) GDPR in France, Italy, Luxembourg and Spain
Full text
The Romanian DPA has fined the civil law firm 'Sabou, Burz & Cuc' EUR 1,000. The DPA launched an investigation after a client complained that the controller had published their personal data in a WhatsApp group used by several lawyers of a bar association without their prior consent. The DPA found that the controller had processed the data without a valid legal basis, as they had published the data for a purpose other than that originally agreed with the data subject.
Industry: Finance, Insurance and Consulting
Original document at the source www.dataprotection.ro