Skip to content
Enforcement · ANSPDCP (Romania) ·Spitalul Veterinar Tineretului SRL EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Spitalul Veterinar Tineretului SRL

Status Not cited by any decision here yet

€5,242 Fine
Romania
Art. 15 GDPR

Holding

The DPA found a violation of Article 15(1) GDPR and Article 15(3) GDPR and issued a fine of RON 5,242 (€1,000). Moreover, the DPA ordered the controller to give the data subject access to the requested copies as provided for in Article 15(3) GDPR, to the extent that they are still available, and to revisit their practice on how to handle access requests, including ensuring an effective response to the requests of data subjects pursuant to Article 12 GDPR – Article 22 GDPR, and providing all requested information. Moreover, the controller was ordered to regularly train their staff in this regard.

From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓

Summary

Facts — A data subject filed an access request with the veterinary clinic Spitalul Veterinar Tineretului SRL (controller) concerning copies of a telephone conversation and video recordings from within the controller’s premises covering a time period that the data subject was on the premises. The data subject was dissatisfied with the way the controller handled their request and lodged a complaint with the DPA.

Full text

Machine translation of the decision, via GDPRhub — not the official text. Read the original

October 7, 2026 Penalty for GDPR Violation The National Supervisory Authority for Personal Data Processing has concluded an investigation into the data controller Spitalul Veterinar Tineretului SRL and found a violation of the provisions of Article 15, paragraphs (1) and (3) of Regulation (EU) 2016/679. Accordingly, the data controller was fined 5,242 lei (equivalent to 1,000 euros). The investigation was initiated following a complaint filed by an individual who was dissatisfied with how Spitalul Veterinar Tineretului SRL handled their request for access to personal data. During the investigation, the National Supervisory Authority for Personal Data Processing found that the data controller had not properly addressed the data subject’s request for a copy of a telephone conversation with a hospital employee, as well as video recordings from within Spitalul Veterinar Tineretului SRL, covering a specified time period in which the data subject also appeared. At the same time, the following corrective measures were ordered against the controller: - providing a complete response to the petitioner, in accordance with her request, including providing a copy of the telephone conversation she had on the specified date and during the specified time period, and issuing a copy of the requested video recordings, in compliance with the provisions of Article 15( (3) of Regulation (EU) 2016/679, taking into account the European Data Protection Board’s Guidelines No. 3/2019 on the processing of personal data by video means, to the extent that such footage is still available; - adopting internal procedures or revising existing internal procedures regarding how to address requests submitted by data subjects pursuant to Regulation (EU) 2016/679 (Articles 12–22), ensuring compliance in all cases with the applicable provisions regarding the prompt review and resolution of such requests, so that the controller ensures that it effectively responds to requests from data subjects, including by providing all requested information, as well as by regularly training the controller’s staff in this regard. Legal and Communications Department A.N.S.P.D.C.P.

How it connects

C/09/697386 / HA ZA 26-52 Den Haag District Court: 51 gamblers sue Unibet operator Risepoint over unanswered GDPR The District Court of The Hague (the Court) considered an action brought by 51 individuals who had participated in online gambling offered through the website Unibet before 1… Rb. Den Haag Sep 2, 2026 Right of Access Personal Data Data Portability
C-579/21 Proceedings brought by J.M In Case C-579/21, the Court of Justice of the European Union ruled on a preliminary reference from the Itä-Suomen hallinto-oikeus (Administrative Court of Eastern Finland)… CJEU ·First Chamber Jun 22, 2023 Right of Access Personal Data Right to Restriction
C-169/23 Nemzeti Adatvédelmi és Információszabadság Hatóság v UC In Case C-169/23, the Court of Justice of the European Union (Third Chamber) ruled on a preliminary reference from the Kúria (Hungary) concerning whether the Budapest Metropolitan… CJEU ·Third Chamber Nov 28, 2024 Personal Data Legitimate Interest Fairness & Transparency
C-416/23 Österreichische Datenschutzbehörde v F R In Case C-416/23, the Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Austrian Supreme Administrative Court concerning the… CJEU ·First Chamber Jan 9, 2025 Right of Access Supervision Personal Data
C-154/21 RW v Österreichische Post AG The Court of Justice of the European Union (First Chamber), in response to a preliminary reference from the Oberster Gerichtshof (Austrian Supreme Court), interpreted Article… CJEU ·First Chamber Jan 12, 2023 Personal Data Right of Access Recipient
C-272/19 VQ v Land Hessen In a preliminary ruling requested by the Verwaltungsgericht Wiesbaden in proceedings between VQ and Land Hessen, the CJEU addressed whether the GDPR applies to the processing of… CJEU ·Third Chamber Jul 9, 2020 Material scope (GDPR) Personal Data Public Authority