Enforcement · Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
ING Bank NV Amsterdam Sucursala București: Insufficient technical and organisational measures to ensure information security
How it connects
Related across sources
Guidance EDPB Annual Report 2021 Guidance Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidance EDPB Annual Report 2023 Guidance Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement Guidance Guidelines 01/2022 on data subject rights - Right of access Guidance Guidelines 07/2022 on certification as a tool for transfers
Full text
The Romanian DPA has imposed a fine of EUR 20,000 on ING Bank NV Amsterdam Sucursala București. The bank had reported a data breach to the DPA pursuant to Art. 33 GDPR. Several personal data of customers, such as ID card data, bank data, bank card data, etc., were accessed and disclosed without authorization. This resulted in payment transactions being carried out by unauthorized third parties. During its investigation, the DPA found that the bank had failed to implement adequate technical and organizational measures to protect personal data, which allowed the unauthorized access.
Industry: Finance, Insurance and Consulting
Original document at the source www.dataprotection.ro