# Unirea Medical Center S.R.L.: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
- Date: 2025-01-03
- Original: https://www.enforcementtracker.com/ETid-2685
- Canonical: https://overview.legal/posts/48800
- Topics: Healthcare, Healthcare, Security, Controllers, Personal Data, Processing Agreement, Supervisory Authorities, Processing, Supervision, Data Controller

## Summary

The Romanian DPA has imposed a fine of EUR 2,000 on Unirea Medical Center S.R.L. The controller publicly exposed the access credentials for a data subject's email account on a workstation.

## Full text

The Romanian DPA has imposed a fine of EUR 2,000 on Unirea Medical Center S.R.L. The controller publicly exposed the access credentials for a data subject's email account on a workstation.

GDPR Articles: Art. 24 GDPR, Art. 32 GDPR
Industry: Health Care

---
Generated by overview.legal · https://overview.legal/posts/48800 · 2026-08-22
