# CVA TAX & FINANCE S.R.L.: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
- Date: 2025-05-14
- Original: https://www.enforcementtracker.com/ETid-2716
- Canonical: https://overview.legal/posts/48831
- Topics: Data Breaches, Security, Insurance, Processing Agreement, Controllers, Supervisory Authorities, Personal Data, Processing, Data Controller, Supervision

## Summary

The Romanian DPA has imposed a fine of EUR 2,000 CVA TAX & FINANCE S.R.L. The controller did not implement sufficient technical and organisational measures to ensure information security, resulting in a data breach and the restriction of access to data.

## Full text

The Romanian DPA has imposed a fine of EUR 2,000 CVA TAX & FINANCE S.R.L. The controller did not implement sufficient technical and organisational measures to ensure information security, resulting in a data breach and the restriction of access to data.

GDPR Articles: Art. 32 (1), (2) GDPR
Industry: Finance, Insurance and Consulting

---
Generated by overview.legal · https://overview.legal/posts/48831 · 2026-08-22
