Skip to content
Enforcement · ANSPDCP (Romania) ·02/07/2026 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

The Romanian DPA (ANSPDCP) launched an investigation into a bank, Banca Transilvania S.A

(the controller), following a data subject’s complaint.

€26,172 Fine
Romania
Art. 32 GDPR

Holding

The DPA found that the controller had failed to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. It noted that the controller had not sufficiently ensured that employees acting under its authority and having access to customers’ personal data processed those data only on its instructions. It held that this failure resulted in the unauthorised access to the data subject’s personal data for personal purposes. The DPA therefore found that the controller infringed Article 32(1) GDPR, Article 32(2) GDPR and Article 32(4) GDPR and imposed a fine of RON 26,172 (€5,000). Furthermore, the DPA ordered the controller to implement appropriate technical and organisational measures to prevent employees from unlawfully accessing personal data for personal purposes.

From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓

Summary

The data subject claimed that their personal data associated with their bank account had been processed without their consent. During the investigation the DPA found that an employee of the controller had accessed the data subject's bank account statements without authorisation and outside the scope of their official duties, at the request of a third party. The personal data included the data subject’s surname, first name, IBAN, account type, client code, transaction data and account balances.

Full text 2 findings

Machine translation of the decision, via GDPRhub — not the official text. Read the original

Paragraphs carrying a topic or an applied provision show those connections inline
§

02/07/2026 Sanction for violation of the GDPR The National Supervisory Authority for Personal Data Processing completed, in June 2026, an investigation at the operator Banca Transilvania S.A. and found a violation of the provisions of art. 32 para. (1), (2) and (4) of Regulation (EU) 2016/679. As such, the operator was sanctioned with a fine of 26,172 lei, equivalent to 5,000 euros. The investigation was initiated following a complaint from a natural person, a data subject, who claimed that his personal data associated with his bank account had been processed without his consent. During the investigation, it was found that an employee of the operator, at the request of a third party, accessed, outside of his/her job duties, account statements of the data subject in an unauthorized manner, affecting the following categories of personal data: name, surname, bank account number (IBAN), account type, client code, transaction data and account balance.

§

As such, it was found that the operator did not implement technical and organizational measures to ensure a level of security appropriate to the risk presented by the processing, in order to ensure that employees acting under its authority and having access to the personal data of the bank's customers only process them at its request, which led to unauthorized access, for personal purposes, to the data subject's data. Consequently, in relation to the criteria for individualizing the sanction provided for in art. 83 para. (2) of Regulation (EU) 2016/679, the operator Banca Transilvania S.A. was fined for violating the provisions of art. 32 par. (1), (2) and (4) of Regulation (EU) 2016/679. At the same time, pursuant to the provisions of art. 58 par. (2) letter b) of Regulation (EU) 2016/679, the corrective measure was ordered against the operator to ensure compliance with Regulation (EU) 2016/679 of the personal data processing operations, by implementing appropriate technical and organizational measures, so as to avoid illegal access, in the personal interest of employees, to the personal data of individuals whose data the operator processes. The operator paid the contravention fine imposed by ANSPDCP. Legal and Communication Department A.N.S.P.D.C.P

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-768/21 TR v Land Hessen In Case C-768/21, the Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning TR's challenge of… CJEU ·First Chamber Sep 26, 2024 Supervision Data Breaches Integrity and Confidentiality Principle
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) CJEU Jan 12, 2023 Supervisory Authorities IP Address Supervision
C-60/22 UZ v Bundesrepublik Deutschland In Case C-60/22, the CJEU (Fifth Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning UZ, a third-country national, and the Bundesrepublik… CJEU ·Fifth Chamber May 4, 2023 Right to Restriction Right to be Forgotten Personal Data
S 5 SF 65/24 DS SG Nürnberg: MOVEit zero-day cyberattack via processor did not breach Art. 32 GDPR The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus… Social Court Nuremberg Jun 10, 2026 Processors Controllers Integrity and Confidentiality Principle