Enforcement · Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
ROUMASPORT SRL: Insufficient legal basis for data processing
The Romanian DPA has imposed a fine of EUR 5,000 on ROUMASPORT SRL.
Full text
The Romanian DPA has imposed a fine of EUR 5,000 on ROUMASPORT SRL. The controller accessed surveillance cameras to monitor its employees without a sufficient legal basis. The controller also used the data for disciplinary purposes.
Industry: Employment
How it connects
Related across sources
C-362/14 Maximillian Schrems v Data Protection Commissioner C-362/14 (Schrems I) CJEU Oct 6, 2015 Privacy Shield Supervision IP Address
Guidelines 3/2019 processing of personal data through video devices Guidelines ·EDPB Jan 30, 2020 Personal Data Processing Material scope (GDPR)
C-311/18 Data Protection Commissioner v Facebook Ireland and Maximillian Schrems C-311/18 (Schrems II) CJEU Jul 16, 2020 Privacy Shield Processing Agreement International Transfer
Guidelines 3/2018 territorial scope of the GDPR (Article 3) Guidelines on the territorial scope of the GDPR Guidelines ·EDPB Nov 12, 2019 Territorial scope (GDPR) IP Address Processors
10 A 5144/23 VG Hannover: Controller appeals DPA reprimand over unlawful workplace video surveillance The owner of a doner kebab production facility (the controller) had installed video cameras to monitor virtually every room of the business premises. Cameras were placed in the… Administrative Court Hannover Aug 7, 2026 Controllers Supervisory Authorities Legitimate Interest
C-807/21 Deutsche Wohnen SE v Staatsanwaltschaft Berlin C-807/21 (Deutsche Wohnen) CJEU Dec 5, 2023 Fines Public Authority Processors