Enforcement · Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
SC Raiffeisen Bank SA: Non-compliance with general data processing principles
The Romanian DPA has imposed a fine of EUR 2,000 on SC Raiffeisen Bank SA.
Full text
The Romanian DPA has imposed a fine of EUR 2,000 on SC Raiffeisen Bank SA. An individual had filed a complaint with the DPA for receiving text messages about money transfers to certain persons that they had not effected. During its investigation, the DPA found that the bank had accidentally used the telephone number of the data subject for transaction purposes in 44 cases. The data subject was not a customer of the bank and had not requested the transactions.
Industry: Finance, Insurance and Consulting
How it connects
Related across sources
C-288/12 Judgment of the Court (Grand Chamber), 8 April 2014.#European Commission v Hungary.#Failure of a Member State to fulfil obligations — Directive 95/46/EC — Protection of individuals with regard to the processing of personal data and the free movement of such data — Article 28(1) — National supervisory authorities — Independence — National legislation prematurely bringing to an end the term served by the supervisory authority — Creation of a new supervisory authority and appointment of another per The European Commission brought an infringement action against Hungary before the Court of Justice (Grand Chamber) under Article 258 TFEU, alleging that Hungary violated Article… CJEU Apr 8, 2014 Supervision Supervisory Authorities Personal Data
SAN 3154/2026 National court annuls DPA sanction against KFC Spain over website privacy information In May 2021, a data subject lodged a complaint with the DPA against KFC Restaurants Spain, S.L.U., the controller, concerning the processing of personal data through its website.… Jul 16, 2026 Supervisory Authorities Personal Data Controllers
Opinion 9/2020 Reinsurance Group of America — processor BCRs ·Opinion ·EDPB Apr 14, 2020 International Transfer Processors Codes of Conduct
Opinion 8/2020 Reinsurance Group of America — controller BCRs ·Opinion ·EDPB Apr 14, 2020 International Transfer Codes of Conduct Supervisory Authorities
Opinion 22/2022 Hilti Group — controller BCRs ·Opinion ·EDPB Sep 7, 2022 International Transfer Codes of Conduct Controllers
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Jul 7, 2021 Controllers Processors IP Address