# GENPACT ROMANIA SRL: Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
- Date: 2026-02-04
- Original: https://www.enforcementtracker.com/ETid-3028
- Canonical: https://overview.legal/posts/52382
- Topics: Access Controls, Security, Controllers, Processing Agreement, Insurance, Supervisory Authorities, Personal Data, Processing, Data Controller, Supervision

## Summary

The Romanian DPA has imposed a fine of EUR 10,000 on GENPACT ROMANIA SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures. The attacker was able to exploit vulnerabilities in some passwords and in the way user accounts' authentication could be reset.

## Full text

The Romanian DPA has imposed a fine of EUR 10,000 on GENPACT ROMANIA SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures. The attacker was able to exploit vulnerabilities in some passwords and in the way user accounts' authentication could be reset.

GDPR Articles: Art. 32 (1) b), (2) GDPR
Industry: Finance, Insurance and Consulting

---
Generated by overview.legal · https://overview.legal/posts/52382 · 2026-08-22
