# Condor SA: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
- Date: 2022-03-28
- Original: https://www.enforcementtracker.com/ETid-1111
- Canonical: https://overview.legal/posts/47226
- Topics: Data Breaches, Security, Privacy by Design & Default, Personal Data, Controllers, Processing Agreement, Processing, Supervisory Authorities, Data Controller, Supervision

## Summary

The Romanian DPA has imposed a fine of EUR 2,000 on Condor SA. The controller had suffered a data breach in which unauthorized persons gained access to several documents containing personal data of employees and former employees such as place of work, surname, first name, position, salary and bank details. During its investigation, the DPA found that the controller had not taken appropriate technical and organizational measures that would ensure the protection of personal data.

## Full text

The Romanian DPA has imposed a fine of EUR 2,000 on Condor SA. The controller had suffered a data breach in which unauthorized persons gained access to several documents containing personal data of employees and former employees such as place of work, surname, first name, position, salary and bank details. During its investigation, the DPA found that the controller had not taken appropriate technical and organizational measures that would ensure the protection of personal data.

GDPR Articles: Art. 32 (1), (2), (4) GDPR
Industry: Industry and Commerce

---
Generated by overview.legal · https://overview.legal/posts/47226 · 2026-08-22
