Skip to content
Content type · 361 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

Country: Romania (50) Clear filter
151–200 of 361 sort newestlargest fineoldest
€2,000 SHOPBAG GROUP ONLINE SRL: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 2,000 onSHOPBAG GROUP ONLINE SRL. The controller failed to respond to a request made by the DPA. ROMANIA ·Art. 58 Supervision Supervisory Authorities Controllers Mar 6, 2025
€20,000 WEBRASOFT SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on WEBRASOFT SRL. The controller failed to implement sufficient technical and organisational measures to ensure data security,… ROMANIA ·Art. 32 Security Controllers Personal Data Mar 4, 2025
€10,000 BEKO ROMANIA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on BEKO ROMANIA SA. The controller failed to implement sufficient technical and organisational measures to provide data security,… Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Mar 3, 2025
€1,000 Velvet Medical SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Velvet Medical SRL. The controller failed to provide the data subject with the requested health data. ROMANIA ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Feb 27, 2025
€2,000 Medstar S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 2,000 on Medstar S.R.L. The controller had mistakenly sent a patient's health data via unsecured email to another patient. The DPA found… ROMANIA ·Art. 32 Security Controllers Personal Data Feb 20, 2025
€2,000 Meedea Construct Prest SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 in Meedea Construct Prest SRL. The controller disclosed personal and health data of a former employee to a third party, who then… ROMANIA ·Art. 5, 6, 9 Controllers Personal Data Types of Special Categories of Personal Data Feb 17, 2025
€3,000 PPC Energie Muntenia SA: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 3,000 on PPC Energie Muntenia SA. The controller forwarded customer data to a third company, which then contacted the data subjects for… ROMANIA ·Art. 5, 6, 12 +1 Personal Data Controllers Marketing Feb 10, 2025
€3,000 Omniasig Vienna Insurance Group S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Omniasig Vienna Insurance Group S.A. The controller failed to implement sufficient technical and organisational measures to… ROMANIA ·Art. 32 Security Controllers Personal Data Feb 6, 2025
€5,000 FARMEC SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on FARMEC SA. The controller failed to implement sufficient technical and organisational measures to ensure data security,… ROMANIA ·Art. 25, 32 Security Controllers Personal Data Feb 5, 2025
€10,000 V&M Contab & Management SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on V&M Contab & Management SRL. The controller failed to implement sufficient technical and organisational measures to ensure… ROMANIA ·Art. 32, 58 Data Breaches Security Controllers Feb 4, 2025
€15,000 Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Unicredit Bank SA. The controller failed to implement sufficient technical and organisational measures to ensure data… ROMANIA ·Art. 25 Security Controllers Personal Data Feb 3, 2025
€15,000 S.P.E.E.H. HIDROELECTRICA S.A: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on S.P.E.E.H. HIDROELECTRICA S.A. The controller failed to implement sufficient technical and organisational measures to ensure… ROMANIA ·Art. 25 Security Controllers Personal Data Jan 31, 2025
€40,000 Orange Romania SA: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 40,000 on Orange Romania SA. The controller failed to fulfil a request for the erasure of data. The controller also execsevly stored and… Art. 5, 6, 7 +2 ·Non-compliance with general data processing principles Controllers Personal Data Supervisory Authorities Jan 27, 2025
€5,000 Softehnica S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Softehnica S.R.L. The controller had suffered a ransomware attack, which allowed unauthorized third parties to gain access to… ROMANIA ·Art. 32 Security Controllers Personal Data Jan 23, 2025
€15,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Vodafone Romania S.A. Personal data such as names, email addresses and customer numbers were repeatedly disclosed due to… Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Controllers Jan 20, 2025
€2,000 DELIVERY SOLUTIONS S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on DELIVERY SOLUTIONS S.A. A security incident led to the unauthorized disclosure of personal data (name, address, telephone… ROMANIA ·Art. 32 Security Controllers Personal Data Jan 17, 2025
€2,000 Unirea Medical Center S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Unirea Medical Center S.R.L. The controller publicly exposed the access credentials for a data subject's email account on a… ROMANIA ·Art. 24, 32 Personal Data Controllers Security Jan 3, 2025
€1,000 Blackcab Systems SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Blackcab Systems SRL. A individual lodged a complaint with the DPA, alleging that the controller had failed to properly respond… ROMANIA ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Nov 4, 2024
€15,000 Untold SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 15,000 on Untold SRL. During its investigation, the DPA found that the controller had failed to properly comply with a data subject's… ROMANIA ·Art. 12, 15, 17 Personal Data Controllers Supervisory Authorities Oct 30, 2024
€5,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA fined Vodafone Romania S.A. EUR 5,000 for sending emails to different recipients without including them in the blind carbon copy (BCC) list. This resulted in the… Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Telecommunications Oct 28, 2024
€10,000 Profi Rom Food SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 10,000 on Profi Rom Food SRL. During its investigation, the DPA found that the controller had forwarded copies of several employees' ID… ROMANIA ·Art. 5, 6 Controllers Personal Data Processing Oct 23, 2024
€3,000 Your Consulting SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Your Consulting SRL. The controller had suffered a data breach involving the unauthorized disclosure of personal data. During… ROMANIA ·Art. 25, 32 Security Privacy by Design & Default Controllers Oct 16, 2024
€2,000 PPC ENERGIE MUNTENIA S.A.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on PPC ENERGIE MUNTENIA S.A. for failing to respond to a data subject's request for the deletion of their personal data in a… ROMANIA ·Art. 12, 17 Personal Data Supervisory Authorities Supervision Sep 23, 2024
€3,000 Constanța South Container Terminal SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Constanța South Container Terminal SRL. The controller had suffered a data breach in which personal data of employees had been… ROMANIA ·Art. 32 Security Controllers Personal Data Sep 17, 2024
€3,000 Vodafone România SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 3,000 on Vodafone România SA for failing to respond to a data subject's request for access and deletion of their personal data in a… ROMANIA ·Art. 12, 15, 17 Personal Data Supervisory Authorities Supervision Sep 16, 2024
€1,000 SC Class IT Outsourcing SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on SC Class IT Outsourcing SRL for failing to respond to a data subject's request for the deletion of their personal data in a… ROMANIA ·Art. 12, 17 Personal Data Supervisory Authorities Supervision Sep 16, 2024
€8,000 Ana Hotels SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Ana Hotels SRL EUR 8,000. The controller had suffered a data breach which resulted in the unauthorized disclosure of personal data processed and stored… ROMANIA ·Art. 32 Security Controllers Personal Data Aug 20, 2024
€1,000 BEST ELAN ONLINE SRL: Insufficient cooperation with supervisory authority The Romanian DPA has fined BEST ELAN ONLINE SRL EUR 1,000 for failing to provide information requested by the DPA. ROMANIA ·Art. 58 Supervisory Authorities Supervision Personal Data Aug 6, 2024
€3,000 Rețele Electrice Muntenia SA.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Rețele Electrice Muntenia SA. A user who logged into their account was able to access the personal data of other customers.… ROMANIA ·Art. 32 Security Controllers Personal Data Jun 25, 2024
€1,000 Rețele Electrice Dobrogea SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Rețele Electrice Dobrogea SA. A user who logged into their account was able to access the personal data of other customers.… ROMANIA ·Art. 32 Security Controllers Personal Data Jun 25, 2024
€2,000 Corint Logistic SRL.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Corint Logistic SRL. A customer had filed a complaint with the DPA because they had received advertising text messages from the… ROMANIA ·Art. 5, 17, 21 Right to be Forgotten Personal Data Direct Marketing May 30, 2024
€2,000 IRIDEX GROUP SALUBRIZARE SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on IRIDEX GROUP SALUBRIZARE SRL. The controller had sent an e-mail to customers without using the blind copy option, revealing the… ROMANIA ·Art. 32 Controllers Security Personal Data May 9, 2024
€1,000 MEDICOVER SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on MEDICOVER SRL. The healthcare facility had mistakenly forwarded a patient file to the wrong patient. ROMANIA ·Art. 32 Security Personal Data Healthcare May 9, 2024
€5,000 CENTRUL MEDICAL UNIREA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on CENTRUL MEDICAL UNIREA SRL. The controller had suffered a data breach in which personal data of patients and employees were… ROMANIA ·Art. 32 Security Controllers Personal Data May 8, 2024
€2,000 ALPHA BANK ROMANIA SA.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on ALPHA BANK ROMANIA SA. The controller had suffered a data breach due to an employee mismanaging recording systems. During its… Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Apr 23, 2024
€2,000 S.C. Tensa Art Design S.A..: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on S.C. Tensa Art Design S.A.. The controller had processed the personal data of a data subject for marketing purposes without the… ROMANIA ·Art. 6 Personal Data Consent Controllers Apr 22, 2024
€5,000 EURO MINI STORAGE ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of 5,000 euros on EURO MINI STORAGE ROMANIA SRL. The controller had suffered a data breach in which customer data was accessed without… Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Mar 5, 2024
€3,000 VESTA CEU ROMÂNIA SRL.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on VESTA CEU ROMÂNIA SRL. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA ·Art. 32 Data Breaches Security Controllers Feb 26, 2024
€2,000 Account Exchange SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on Account Exchange SRL for using personal data without the consent of the data subjects. ROMANIA ·Art. 5, 6 Consent Personal Data Processing Feb 7, 2024
€500 Owners' association: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 500 on an owners' association for publishing personal data of an individual in a WhatsApp group without a valid legal basis and for… ROMANIA ·Art. 5, 6, 12 Personal Data Supervisory Authorities Supervision Feb 5, 2024
€2,000 Sectorul 1 al Municipiului București: Insufficient cooperation with supervisory authority The Romanian DPA has fined Sectorul 1 al Municipiului București EUR 2,000 for failing to provide information requested by the DPA during an investigation. ROMANIA ·Art. 58 Supervision Supervisory Authorities Personal Data Jan 30, 2024
€3,000 TECHNINK LEB SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on TECHNINK LEB SRL. The controller had suffered a data breach in which personal customer data had been unlawfully disclosed.… ROMANIA ·Art. 32 Security Controllers Personal Data Jan 15, 2024
€17,000 Alior Bank SA: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 17,000 on Alior Bank SA. The investigation was initiated following complaints that the bank continued to send unsolicited electronic… ROMANIA ·Art. 5, 6 Personal Data Processing Supervisory Authorities Jan 12, 2024
€200 Private individual: Insufficient cooperation with supervisory authority The Romanian DPA has fined a private individual EUR 200 for failing to provide information requested by the DPA during an investigation. ROMANIA ·Art. 58 Supervisory Authorities Supervision Personal Data Dec 15, 2023
€3,000 Veranda Obor S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Veranda Obor S.A.. The controller had disclosed personal data (e.g. name, e-mail adress etc.) of lottery participants on its… ROMANIA ·Art. 32 Personal Data Security Controllers Dec 11, 2023
€24,000 Hora Credit IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 24,000 on Hora Credit IFN SA. The controller had accidentally sent documents containing the personal data of another person to a customer by… ROMANIA ·Art. 12, 15, 32 +1 Personal Data Controllers Security Dec 7, 2023
€1,500 Libra Internet Bank SA: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 1500 on Libra Internet Bank SA for failing to comply with an order issued by the DPA. ROMANIA ·Art. 58 Supervisory Authorities Supervision Personal Data Nov 20, 2023
€110,000 Rompetrol Downstream SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 110,000 on Rompetrol Downstream SRL. The controller had suffered a data breach in which customer data was repeatedly accessed and used… ROMANIA ·Art. 32 Security Right of Access Controllers Nov 13, 2023
€3,000 OTP BANK ROMANIA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on OTP BANK ROMANIA SA. The controller had accidentally transmitted personal data of an individual to an unauthorized third party.… Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Nov 3, 2023
€500 Homeowners Association: Insufficient cooperation with supervisory authority Fine for failure to comply with an order of the supervisory authority. ROMANIA ·Art. 58 Supervision Supervisory Authorities Personal Data Oct 27, 2023