# Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
- Date: 2025-02-03
- Original: https://www.enforcementtracker.com/ETid-2688
- Canonical: https://overview.legal/posts/48803
- Topics: Data Breaches, Security, Controllers, Processing Agreement, Insurance, Supervisory Authorities, Personal Data, Law Enforcement, Processing, Supervision

## Summary

The Romanian DPA has imposed a fine of EUR 15,000 on Unicredit Bank SA. The controller failed to implement sufficient technical and organisational measures to ensure data security, resulting in two separate data breaches.

## Full text

The Romanian DPA has imposed a fine of EUR 15,000 on Unicredit Bank SA. The controller failed to implement sufficient technical and organisational measures to ensure data security, resulting in two separate data breaches.

GDPR Articles: Art. 25 (1) GDPR
Industry: Finance, Insurance and Consulting

---
Generated by overview.legal · https://overview.legal/posts/48803 · 2026-08-22
