# IRIDEX GROUP SALUBRIZARE SRL: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
- Date: 2024-05-09
- Original: https://www.enforcementtracker.com/ETid-2314
- Canonical: https://overview.legal/posts/48429
- Topics: Security, IP Address, Controllers, Personal Data, Processing Agreement, Processing, Data Controller, Supervisory Authorities, Supervision

## Summary

The Romanian DPA has imposed a fine of EUR 2,000 on IRIDEX GROUP SALUBRIZARE SRL. The controller had sent an e-mail to customers without using the blind copy option, revealing the email addresses of all recipients to the other recipients.

## Full text

The Romanian DPA has imposed a fine of EUR 2,000 on IRIDEX GROUP SALUBRIZARE SRL. The controller had sent an e-mail to customers without using the blind copy option, revealing the email addresses of all recipients to the other recipients.

GDPR Articles: Art. 32 (1) b) GDPR, Art. 32 (2), (3), (4) GDPR
Industry: Not assigned

---
Generated by overview.legal · https://overview.legal/posts/48429 · 2026-08-22
