# S.C. Wine Point S.R.L.: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
- Date: 2022-06-15
- Original: https://www.enforcementtracker.com/ETid-1230
- Canonical: https://overview.legal/posts/47345
- Topics: Integrity and Confidentiality Principle, Professional Secrecy, Security, IP Address, Personal Data, Controllers, Processing Agreement, Privacy by Design & Default, Direct Marketing, Supervisory Authorities

## Summary

The Romanian DPA has imposed a fine of EUR 3,000 on S.C. Wine Point S.R.L.. A data subject had filed a complaint with the DPA for having received an advertising e-mail from the controller, which contained a distribution list in which the e-mail addresses of 810 other persons, as well as their own, were visible to the other recipients. During its investigation, the DPA found that the controller had failed to take appropriate technical and organizational measures to ensure the confidentiality of t

## Full text

The Romanian DPA has imposed a fine of EUR 3,000 on S.C. Wine Point S.R.L.. A data subject had filed a complaint with the DPA for having received an advertising e-mail from the controller, which contained a distribution list in which the e-mail addresses of 810 other persons, as well as their own, were visible to the other recipients. During its investigation, the DPA found that the controller had failed to take appropriate technical and organizational measures to ensure the confidentiality of the personal data processed.

GDPR Articles: Art. 32 (1) b) GDPR
Industry: Industry and Commerce

---
Generated by overview.legal · https://overview.legal/posts/47345 · 2026-08-22
