# BRD-Groupe Société Générale S.A.: Non-compliance with general data processing principles

- Type: Enforcement
- Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
- Date: 2023-06-15
- Original: https://www.enforcementtracker.com/ETid-1894
- Canonical: https://overview.legal/posts/48009
- Topics: Data Breaches, Personal Data, IP Address, Processing Agreement, Controllers, Insurance, Processing, Supervisory Authorities, Supervision, Data Controller

## Summary

The Romanian DPA has imposed a fine of EUR 2,000 on BRD-Groupe Société Générale S.A.. The controller had reported a data breach to the DPA. During its investigation, the DPA found that the controller had unlawfully disclosed personal data of a bank client and other individuals.

## Full text

The Romanian DPA has imposed a fine of EUR 2,000 on BRD-Groupe Société Générale S.A.. The controller had reported a data breach to the DPA. During its investigation, the DPA found that the controller had unlawfully disclosed personal data of a bank client and other individuals.

GDPR Articles: Art. 5 (1) a), b), f) GDPR, Art. 5 (2) GDPR
Industry: Finance, Insurance and Consulting

---
Generated by overview.legal · https://overview.legal/posts/48009 · 2026-08-22
