Enforcement · Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
S.P.E.E.H. HIDROELECTRICA S.A: Insufficient technical and organisational measures to ensure information security
How it connects
Related across sources
Guidance Guidelines 07/2022 on certification as a tool for transfers Guidance EDPB Annual Report 2021 Guidance Guidelines 07/2020 on the concepts of controller and processor in the GDPR Guidance Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies Guidance Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Case Law HvJ EU: Privacy Shield ongeldig verklaard (Schrems II)
Full text
The Romanian DPA has imposed a fine of EUR 15,000 on S.P.E.E.H. HIDROELECTRICA S.A. The controller failed to implement sufficient technical and organisational measures to ensure data security, resulting in a data breach.
Industry: Transportation and Energy
Original document at the source www.dataprotection.ro