Skip to content
Enforcement · ANSPDCP (Romania) ·Fine against Ascendex Technology SRL EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Fine against Ascendex Technology SRL

The Romanian DPA (ANSPDCP) launched an investigation into the cryptocurrency exchange platform Ascendex Technology SRL (the controller).

Status Not cited by any decision here yet

Holding

The DPA held that the controller violated Article 12(1) GDPR and Article 12(3) GDPR, read in conjunction with Article 17 GDPR and fined it RON 57,839 (€11,000). Furthermore, it ordered the controller, under Article 58(2)(c) GDPR and Article 58(2)(d) GDPR, to provide an appropriate response to the data subject, as well as to other data subjects in similar situations, regarding the handling of their erasure requests. It also ordered the controller to implement measures for the regular staff training on the correct, clear, transparent and timely handling of data subject requests within the statutory deadlines. In addition, the DPA informed the other concerned supervisory authorities, including the French DPA, of the investigation’s findings and the proposed measures, in accordance with the cooperation procedure under Article 60 GDPR.

From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓

Summary

The DPA was notified by the French DPA (CNIL) regarding a complaint filed by a data subject in France against the controller. Since the controller’s sole establishment was in Romania and its processing substantially affected data subjects in multiple Member States, which constituted cross-border processing under Article 4(23)(b) GDPR, the Romanian DPA accepted its role as the lead supervisory authority. During the investigation, the DPA found that the controller handled the data subject’s erasure request only after approximately 12 months. It noted that the controller did not provide a final response regarding the fulfilment of the request nor justified the delay. The DPA also found that, in similar erasure requests submitted by other data subjects from various EU Member States and from outside the EU, the controller had taken up to 37 months to process the requests.

Full text 3 findings

Machine translation of the decision, via GDPRhub — not the official text. Read the original

Paragraphs carrying a topic or an applied provision show those connections inline
§

01.07.2026 Sanction – cross-border processing The National Supervisory Authority for Personal Data Processing completed, in May 2026, an investigation at the operator Ascendex Technology SRL and found a violation of the provisions of art. 12 para. (1) and (3), reported to art. 17 para. (1) of Regulation (EU) 2016/679 (GDPR). As such, the operator Ascendex Technology SRL was sanctioned with a fine in the amount of 57,839 lei, equivalent to the amount of 11,000 euros. Based on the cooperation mechanisms provided for by Regulation (EU) 2016/679, the National Supervisory Authority was notified by the French data protection authority (CNIL) regarding the complaint filed by a natural person from this state against Ascendex Technology SRL. The CNIL considered the National Supervisory Authority to be the main authority in this case, given that the controller has the only seat in Romania, and the processing of personal data could affect data subjects from several Member States, according to art. 4 par. (23) letter b) of the GDPR.

§

The CNIL proposal was accepted by the National Supervisory Authority. During the investigation, it was found that the controller Ascendex Technology SRL resolved the request of the applicant for deletion of data in approximately 12 months, but without sending him a final response regarding the resolution of his request and without justifying the exceeding of the response deadline, thus violating the provisions of art. 12 par. (1) and (3), in conjunction with art. 17 of the GDPR. Also, during the investigation, it was noted that, in the case of other data subjects from various EU Member States or outside the EU, the resolution of deletion requests by the controller lasted even 37 months. The National Supervisory Authority considered that the circumstances of the above-mentioned case present a degree of seriousness that requires the application of the fine sanction against the operator, in relation to the criteria for individualizing fines provided for in Article 83 para. (2) and (3) of the GDPR.

§

Following the investigation carried out, the National Supervisory Authority informed the other supervisory authorities involved, including the French authority, within the framework of cooperation procedures carried out under Article 60 of Regulation (EU) 2016/679, of the conclusions resulting from the investigation carried out in this case with cross-border impact and the proposed measures. At the same time, pursuant to Article 58 para. (2) lit. c) and d) of Regulation (EU) 2016/679, the National Supervisory Authority also ordered the operator to take the following corrective measures: to communicate an adequate response to the applicant, but also to other data subjects in a similar situation, according to what was found in the investigation, regarding the way to resolve requests for deletion of personal data; to provide regular training measures for staff regarding the correct, clear, transparent management and resolution, and in compliance with the legal deadlines, of requests by which data subjects exercise their rights provided for by Regulation (EU) 2016/679. Legal and Communication Department A.N.S.P.D.C.P

How it connects

3 of 3 paragraphs apply legislation or carry a topic — see them in the full text ↓
Guidelines 8/2022 identifying a controller or processor's lead supervisory authority Guidelines for identifying a controller or processor’s lead supervisory authority Guidelines ·EDPB Apr 17, 2023 Supervision Controllers Supervisory Authorities
1421/2022 Cyprus court upholds €5,000 DPA fine on Pancyprian Judo Federation for Article 31 GDPR On 3 November 2021, a data subject filed a complaint with the Cypriot DPA against an individual who managed a club affiliated with the Pancyprian Judo Federation. The complaint… ADMINISTRATIVE COURT OF CYPRUS May 20, 2026 Supervisory Authorities Processors Controllers
29 K 3490/24 VG Düsseldorf: data subjects challenge district's sharing of personal data in water-law A district (the controller), acting as the lower water authority, initiated administrative proceedings after identifying unauthorised riverbank works and a private jetty on two… Administrative Court Düsseldorf Jun 22, 2026 Personal Data Supervisory Authorities Supervision
Opinion 9/2025 Worldline Group — processor BCRs EPDB, Opinion 9/2025 on the draft decision of the French Supervisory Authority regarding the Processor Binding Corporate Rules of the Worldline Group, 2025. French SA ·Opinion ·EDPB May 21, 2025 International Transfer Processors Codes of Conduct