# ANSPDCP (Romania) - Fine against GLOBAL CUSTOMER CARE SERVICES S.R.L

- Type: Enforcement
- Source: ANSPDCP (Romania)
- Date: 2026-10-09
- Original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_Fine_against_GLOBAL_CUSTOMER_CARE_SERVICES_S.R.L
- Canonical: https://overview.legal/posts/593306
- Topics: Personal Data, Data Breaches, Notification Obligation, Security, Identification, Controllers, Supervisory Authorities, Law Enforcement

## Summary

Facts — A personal data breach occurred because of a cyberattack on of a call centre service provider (the controller). Thus, the confidentiality and availability of personal data were compromised and unauthorised parties gained access to the personal data of a significant number of individuals, including employees, former employees and other persons. The affected data included contact details, identification data, employment-related information, salary and benefits data, bank account details, and residence-related information. Subsequently, the controller notified the personal data breach to the DPA under Article 33 GDPR. Holding — The DPA found that the controller had failed to implement adequate technical and organisational measures to ensure a level of security appropriate to the risks associated with its processing activities, violating Article 32(1)(b) GDPR, Article 32(1)(d) GDPR and Article 32(2) GDPR. According to the DPA, the controller had not adequately ensured the ongoing confidentiality of its processing systems and had failed to establish a process for regularly testing, assessing and evaluating the effectiveness of its technical and organisational security measures. The DPA considered that the incident demonstrated the inadequacy of the security measures implemented by the controller. In this context, the DPA fined the controller €5,000 (RON 26,294). In addition, the DPA ordered the controller to implement monitoring and logging systems for access to its IT infrastructure, including the retention of activity logs for at least 30 days and the introduction of a process for backing up those logs.

## Full text

October 2, 2026 Fine for Violating the GDPR In August 2026, the National Supervisory Authority for Personal Data Processing concluded an investigation into the data controller GLOBAL CUSTOMER CARE SERVICES S.R.L. and found a violation of Article 32, paragraph (1)(b) and (d) and paragraph (2) of Regulation (EU) 2016/679. As a result, the data controller was fined 26,294 lei, equivalent to 5,000 euros. The investigation was initiated following the submission by the data controller, GLOBAL CUSTOMER CARE SERVICES S.R.L., of a notification of a personal data breach, in accordance with the provisions of Article 33 of Regulation (EU) 2016/679. During the investigation, it was found that, following a cyberattack on the controller’s infrastructure, the confidentiality and availability of the personal data contained therein were compromised. This led to unauthorized access to the personal data of a significant number of data subjects (employees, former employees, and other individuals). As a result, the following data was accessed without authorization: first and last names, contact information, information regarding education and professional certifications/qualifications, information regarding salary and other benefits, identification information contained in identification documents and other records, bank account information and other data necessary for making payments, details regarding previous and/or current employment relationships, residence information, data required to obtain residence permits, and contact information for representatives or designated individuals. As such, it was found that the controller had not implemented adequate technical and organizational measures to ensure a level of security appropriate to the risk posed by the processing, including, among other things, the ability to ensure the confidentiality of processing systems and services, as well as the establishment of a process for the periodic testing, evaluation, and assessment of the effectiveness of technical and organizational measures to guarantee the security of processing. At the same time, pursuant to Article 58(2)(d) of the Regulation, the controller was ordered to implement corrective measures to establish systems for monitoring and logging access to the IT infrastructure used for the processing of personal data, which must include a retention period for activity logs of at least 30 days, including the implementation of a process for saving them. Legal and Communications Department A.N.S.P.D.C.P

## Cited law provisions (6)

### GDPR — gdpr-art-32-par-1-pnt-b-en

the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;

### GDPR — gdpr-art-32-par-1-pnt-d-en

a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.

### GDPR — gdpr-art-32-par-2-en

In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.

### GDPR — gdpr-art-58-par-2-pnt-d-en

to order the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specified manner and within a specified period;

### GDPR — gdpr-art-32-en

Security of processing

### GDPR — gdpr-art-33-en

Notification of a personal data breach to the supervisory authority

---
Generated by overview.legal · https://overview.legal/posts/593306 · 2026-10-09
