Fine against GLOBAL CUSTOMER CARE SERVICES S.R.L
A personal data breach occurred because of a cyberattack on of a call centre service provider (the controller).
Status Not cited by any decision here yet
Holding
The DPA found that the controller had failed to implement adequate technical and organisational measures to ensure a level of security appropriate to the risks associated with its processing activities, violating Article 32(1)(b) GDPR, Article 32(1)(d) GDPR and Article 32(2) GDPR. According to the DPA, the controller had not adequately ensured the ongoing confidentiality of its processing systems and had failed to establish a process for regularly testing, assessing and evaluating the effectiveness of its technical and organisational security measures. The DPA considered that the incident demonstrated the inadequacy of the security measures implemented by the controller. In this context, the DPA fined the controller €5,000 (RON 26,294). In addition, the DPA ordered the controller to implement monitoring and logging systems for access to its IT infrastructure, including the retention of activity logs for at least 30 days and the introduction of a process for backing up those logs.
From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓
Thus, the confidentiality and availability of personal data were compromised and unauthorised parties gained access to the personal data of a significant number of individuals, including employees, former employees and other persons. The affected data included contact details, identification data, employment-related information, salary and benefits data, bank account details, and residence-related information. Subsequently, the controller notified the personal data breach to the DPA under Article 33 GDPR.
Full text
Machine translation of the decision, via GDPRhub — not the official text. Read the original
October 2, 2026 Fine for Violating the GDPR In August 2026, the National Supervisory Authority for Personal Data Processing concluded an investigation into the data controller GLOBAL CUSTOMER CARE SERVICES S.R.L. and found a violation of Article 32, paragraph (1)(b) and (d) and paragraph (2) of Regulation (EU) 2016/679. As a result, the data controller was fined 26,294 lei, equivalent to 5,000 euros. The investigation was initiated following the submission by the data controller, GLOBAL CUSTOMER CARE SERVICES S.R.L., of a notification of a personal data breach, in accordance with the provisions of Article 33 of Regulation (EU) 2016/679. During the investigation, it was found that, following a cyberattack on the controller’s infrastructure, the confidentiality and availability of the personal data contained therein were compromised. This led to unauthorized access to the personal data of a significant number of data subjects (employees, former employees, and other individuals). As a result, the following data was accessed without authorization: first and last names, contact information, information regarding education and professional certifications/qualifications, information regarding salary and other benefits, identification information contained in identification documents and other records, bank account information and other data necessary for making payments, details regarding previous and/or current employment relationships, residence information, data required to obtain residence permits, and contact information for representatives or designated individuals. As such, it was found that the controller had not implemented adequate technical and organizational measures to ensure a level of security appropriate to the risk posed by the processing, including, among other things, the ability to ensure the confidentiality of processing systems and services, as well as the establishment of a process for the periodic testing, evaluation, and assessment of the effectiveness of technical and organizational measures to guarantee the security of processing. At the same time, pursuant to Article 58(2)(d) of the Regulation, the controller was ordered to implement corrective measures to establish systems for monitoring and logging access to the IT infrastructure used for the processing of personal data, which must include a retention period for activity logs of at least 30 days, including the implementation of a process for saving them. Legal and Communications Department A.N.S.P.D.C.P