Skip to content
Enforcement · ANSPDCP (Romania) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

ANSPDCP fines Banca Transilvania RON 26,172 for inadequate security over unauthorized

Original title: ANSPDCP (Romania) - 02/07/2026

€26,172 Fine
Romania
Art. 32 GDPR
Summary

Facts — The Romanian DPA (ANSPDCP) launched an investigation into a bank, Banca Transilvania S.A. (the controller), following a data subject’s complaint. The data subject claimed that their personal data associated with their bank account had been processed without their consent. During the investigation the DPA found that an employee of the controller had accessed the data subject's bank account statements without authorisation and outside the scope of their official duties, at the request of a third party. The personal data included the data subject’s surname, first name, IBAN, account type, client code, transaction data and account balances. Holding — The DPA found that the controller had failed to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. It noted that the controller had not sufficiently ensured that employees acting under its authority and having access to customers’ personal data processed those data only on its instructions. It held that this failure resulted in the unauthorised access to the data subject’s personal data for personal purposes. The DPA therefore found that the controller infringed Article 32(1) GDPR, Article 32(2) GDPR and Article 32(4) GDPR and imposed a fine of RON 26,172 (€5,000). Furthermore, the DPA ordered the controller to implement appropriate technical and organisational measures to prevent employees from unlawfully accessing personal data for personal purposes.

How it connects

Full text

02/07/2026 Sanction for violation of the GDPR The National Supervisory Authority for Personal Data Processing completed, in June 2026, an investigation at the operator Banca Transilvania S.A. and found a violation of the provisions of art. 32 para. (1), (2) and (4) of Regulation (EU) 2016/679. As such, the operator was sanctioned with a fine of 26,172 lei, equivalent to 5,000 euros. The investigation was initiated following a complaint from a natural person, a data subject, who claimed that his personal data associated with his bank account had been processed without his consent. During the investigation, it was found that an employee of the operator, at the request of a third party, accessed, outside of his/her job duties, account statements of the data subject in an unauthorized manner, affecting the following categories of personal data: name, surname, bank account number (IBAN), account type, client code, transaction data and account balance. As such, it was found that the operator did not implement technical and organizational measures to ensure a level of security appropriate to the risk presented by the processing, in order to ensure that employees acting under its authority and having access to the personal data of the bank's customers only process them at its request, which led to unauthorized access, for personal purposes, to the data subject's data. Consequently, in relation to the criteria for individualizing the sanction provided for in art. 83 para. (2) of Regulation (EU) 2016/679, the operator Banca Transilvania S.A. was fined for violating the provisions of art. 32 par. (1), (2) and (4) of Regulation (EU) 2016/679. At the same time, pursuant to the provisions of art. 58 par. (2) letter b) of Regulation (EU) 2016/679, the corrective measure was ordered against the operator to ensure compliance with Regulation (EU) 2016/679 of the personal data processing operations, by implementing appropriate technical and organizational measures, so as to avoid illegal access, in the personal interest of employees, to the personal data of individuals whose data the operator processes. The operator paid the contravention fine imposed by ANSPDCP. Legal and Communication Department A.N.S.P.D.C.P

Similar Content