Skip to content
Content type · 361 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

Country: Romania (50) Clear filter
201–250 of 361 sort newestlargest fineoldest
€1,000 SC Spark Car Sharing SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 1,000 on SC Spark Car Sharing SRL. An individual had filed a complaint with the DPA because the controller had processed their email… ROMANIA ·Art. 5, 6, 7 Controllers Personal Data Consent Oct 25, 2023
€3,000 Mensajero SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Mensajero SRL. The controller had suffered a data breach where a link on the controller's website was publicly accessible… ROMANIA ·Art. 32 Security Controllers Personal Data Oct 24, 2023
€1,000 DANTE INTERNATIONAL SA: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 1,000 on DANTE INTERNATIONAL SA. The controller had sent marketing SMS to a data subject without a valid legal basis. ROMANIA ·Art. 6 Personal Data Controllers Direct Marketing Oct 20, 2023
€1,000 Cez Vânzare S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Cez Vânzare S.A.. The controller had accidentally sent emails containing personal customer data to the wrong recipients. The… ROMANIA ·Art. 32 Security Controllers Personal Data Oct 2, 2023
€25,000 RESTART ENERGY ONE S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 25,000 on RESTART ENERGY ONE S.A.. During its investigation, the DPA found that there existed a publicly accessible file on the… ROMANIA ·Art. 32 Security Personal Data Controllers Sep 26, 2023
€2,000 UAT Comuna Albeni: Insufficient cooperation with supervisory authority The Romanian DPA has fined UAT Comuna Albeni EUR 2,000 for failing to provide information requested by the DPA during an investigation. ROMANIA ·Art. 58 Supervision Supervisory Authorities Personal Data Sep 25, 2023
€1,000 NN Asigurări de Viață S.A.: Insufficient fulfilment of data subjects rights The Romanian DPA has fined NN Asigurări de Viață S.A. EUR 1,000. A person had filed a complaint for receiving advertising messages, although they had objected to receiving… ROMANIA ·Art. 21 Direct Marketing Personal Data Processing Sep 18, 2023
€70,000 Uipath SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 70,000 on Uipath SRL. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. During its investigation, the DPA… ROMANIA ·Art. 25, 32 Data Breaches Security Privacy by Design & Default Aug 21, 2023
€2,000 Med Life SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Med Life SA. The controller had refused to disclose certain video recordings of the reception of a hospital to the data… ROMANIA ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Aug 3, 2023
€3,000 ING Bank NV Amsterdam Sucursala București: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on ING Bank NV Amsterdam Sucursala București. The bank had reported a data breach to the DPA pursuant to Art. 33 GDPR. In the… ROMANIA ·Art. 32 Data Breaches Security Supervisory Authorities Jul 18, 2023
€2,500 Farmacia Ardealul SRL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 2,500 on Farmacia Ardealul SRL. The controller had reported a data breach to the DPA. During its investigation, the DPA found that an… ROMANIA ·Art. 32 Security Controllers Personal Data Jun 27, 2023
€1,000 Vodafone Romania SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Vodafone Romania SA. During its investigation, the DPA found that the controller had failed to sufficiently comply with a data… Art. 15 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Supervisory Authorities Jun 21, 2023
€40,000 Dante International SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 40,000 on Dante International SA. During its investigation, the DPA found that the controller had failed to properly comply with a… ROMANIA ·Art. 12, 17 Personal Data Controllers Supervisory Authorities Jun 20, 2023
€2,000 BRD-Groupe Société Générale S.A.: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 2,000 on BRD-Groupe Société Générale S.A.. The controller had reported a data breach to the DPA. During its investigation, the DPA found… ROMANIA ·Art. 5 Controllers Personal Data Processing Jun 15, 2023
€8,000 Artima S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on Artima S.A.. The controller had reported a data breach to the DPA. During its investigation, the DPA found that employees of… ROMANIA ·Art. 32 Security Controllers Personal Data Jun 15, 2023
€3,000 S.C. Apollo Salon S.R.L.: Insufficient cooperation with supervisory authority The Romanian DPA imposed a fine of EUR 3,000 on S.C. Apollo Salon S.R.L. for failing to provide information requested by the DPA during an investigation. ROMANIA ·Art. 58 Supervisory Authorities Supervision Personal Data Jun 6, 2023
€1,000 Global Baby Brand SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 1,000 on Global Baby Brand SRL. A person had filed a complaint with the DPA alleging that the controller had sent commercial SMS… ROMANIA ·Art. 7 Consent Personal Data Controllers May 23, 2023
€18,000 AUTOMOBILE BAVARIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 18,000 on AUTOMOBILE BAVARIA SRL. The data controller had notified the authority of a data breach pursuant to Art. 33 GDPR. Unknown… ROMANIA ·Art. 25, 32 Data Breaches Security Privacy by Design & Default May 18, 2023
€5,000 Compania Națională Poșta Română S.A.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 5,000 on the Romanian Post (Compania Națională Poșta Română S.A.). During its investigation, the DPA found that the controller had… ROMANIA ·Art. 5, 6 Controllers Personal Data Processing May 16, 2023
€1,000 NN Asigurări de Viață S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,00 on the insurance company NN Asigurări de Viață S.A.. The controller had notified the authority of a data breach pursuant to Art. 33… ROMANIA ·Art. 32 Data Breaches Security Controllers May 12, 2023
€1,500 NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,500 on the insurance company NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.. The controller had… ROMANIA ·Art. 32 Data Breaches Security Controllers May 12, 2023
€11,000 Libra Internet Bank SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 11,000 on Libra Internet Bank SA. An individual had filed a complaint against the bank due to the bank's failure to fully comply with… ROMANIA ·Art. 12, 15 Personal Data Supervisory Authorities Supervision May 11, 2023
€1,000 Tensa Art Design SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Tensa Art Design SA. The controller failed to comply with a data subject's right to object. ROMANIA ·Art. 12 Personal Data Controllers Supervisory Authorities Apr 24, 2023
€3,000 Partidul Uniunea Salvați România: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 3,000 on the party 'Partidul Uniunea Salvați România'. The controller had published personal data of persons with different degrees of… ROMANIA ·Art. 5, 6 Personal Data Controllers Processing Apr 19, 2023
€3,000 REGENCY COMPANY SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 3,000 on REGENCY COMPANY SRL. The controller had installed video surveillance cameras in its premises for the purpose of monitoring… ROMANIA ·Art. 5, 6 Controllers Consent Processing Apr 7, 2023
€3,000 Tensa Art Design SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 3,000 on Tensa Art Design SRL. An individual had filed a complaint for receiving promotional messages despite having filed an objection… ROMANIA ·Art. 21 Right to Object Direct Marketing Personal Data Apr 4, 2023
€450 Private individual: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 450 on an private individual. The individual had published personal data of numerous people on a social network without their consent. ROMANIA ·Art. 5, 6 Personal Data Consent Processing Mar 27, 2023
€5,000 Tehnoplus Industry SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 5,000 on Tehnoplus Industry SRL. An employee of the company had filed a complaint with the DPA because the controller had installed a… ROMANIA ·Art. 5, 6 Retention Period Controllers Processing Mar 23, 2023
€3,000 Med Life S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… ROMANIA ·Art. 32 Security Personal Data Controllers Mar 16, 2023
€1,000 Centrul Medical dr. Furtună Dan: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Centrul Medical dr. Furtună Dan. The controller had sent results of a medical test via WhatsApp to the wrong recipient. As a… ROMANIA ·Art. 32 Security Personal Data Controllers Mar 16, 2023
€10,000 Alianța pentru Unirea Românilor: Non-compliance with general data processing principles The Romanian DPA imposed a fine of EUR 10,000 on Alianța pentru Unirea Românilor. During its investigation, the DPA found that the controller collected personal data on its… ROMANIA ·Art. 5 Retention Period Personal Data Controllers Mar 15, 2023
€4,000 Partidul Uniunea Salvați România: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined the Partidul Uniunea Salvați România party EUR 4,000. The controller had suffered a phishing attack in which the attackers gained unauthorized access to… ROMANIA ·Art. 32 Security Encryption Right of Access Mar 15, 2023
€3,000 Tinmar Energy SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Tinmar Energy SA EUR 3,000. The controller had suffered a data breach in which third parties gained unauthorized access to personal data such as first… ROMANIA ·Art. 32 Security Right of Access Personal Data Mar 14, 2023
€2,000 Modaone SRL: Insufficient fulfilment of information obligations The Romanian DPA has imposed a fine of EUR 2,000 on Modaone SRL. An individual had filed a complaint with the DPA for having received advertising messages by e-mail, although they… ROMANIA ·Art. 12, 13 Personal Data Controllers Supervisory Authorities Mar 13, 2023
€2,250 Finopro IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,250 on Finopro IFN SA. The controller had suffered a ransomware attack in which unauthorized third parties gained access to personal… ROMANIA ·Art. 32 Security Right of Access Personal Data Mar 6, 2023
€3,000 Integral Collection SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3000 on Integral Collection SRL. The controller had suffered a ransomware attack in which unauthorized third parties gained access to… ROMANIA ·Art. 32 Security Right of Access Personal Data Mar 6, 2023
€5,000 Medijobs Platform SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Medijobs Platform SRL. The controller had informed the DPA about a data breach according to Art. 33 GDPR. Unauthorized third… ROMANIA ·Art. 32 Data Breaches Security Controllers Feb 8, 2023
€1,000 Tensa Art Design SA: Insufficient fulfilment of data subjects rights The Romanian data protection authority (AEPD) has imposed a fine of EUR 1,000 on Tensa Art Design SA. A data subject had objected to a further newsletter subscription and however… ROMANIA ·Art. 21 Personal Data Controllers Processing Feb 1, 2023
€1,000 Dentist: Insufficient legal basis for data processing The Romanian DPA has fined a dentist EUR 1,000. The controller had published medical information of a patient, such as photos and X-rays, in an article on a medical blog. However,… ROMANIA ·Art. 6, 9 Healthcare Consent Controllers Jan 31, 2023
€1,000 Dent Estet Clinic SA: Insufficient fulfilment of data breach notification obligations The Romanian DPA has fined Dent Estet Clinic SA (dental practice) EUR 1,000. An employed dentist at the practice had published medical information of a patient, such as photos and… ROMANIA ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jan 31, 2023
€1,000 Dante Internațional SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Dante Internațional SA. A data subject had filed a complaint with the DPA against the controller due to the fact that the… ROMANIA ·Art. 17 Personal Data Controllers Supervisory Authorities Jan 18, 2023
€2,000 BRISTOL LOGISTICS SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on BRISTOL LOGISTICS SA. The DPA received a notification from BRISTOL LOGISTICS SA of a personal data breach under Art. 33 GDPR.… ROMANIA ·Art. 32 Data Breaches Notification Obligation Security Jan 12, 2023
€3,000 Apă Canal Ilfov SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Apă Canal Ilfov SA. The controller sent an e-mail with personal data to several recipients in an open distribution list. This… ROMANIA ·Art. 32 Personal Data Controllers Security Jan 4, 2023
€500 Homeowners Association: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 500 on a homeowners' association. The controller had publicly posted a list with the first and last names of all members of the… ROMANIA ·Art. 5 Controllers Personal Data Processing Jan 3, 2023
€3,000 Kaufland Romania SCS: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Kaufland Romania SCS. The controller had reported a data breach to the DPA according to Art. 33 GDPR. An employee had taken… Art. 29, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Dec 27, 2022
€10,000 SUDREZIDENȚIAL Broker S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on SUDREZIDENȚIAL Broker S.R.L.. An employee of the controller had unauthorizedly published an Excel spreadsheet containing… ROMANIA ·Art. 32 Security Personal Data Controllers Dec 22, 2022
€5,000 Societatea Energetică Electrica S.A.: Insufficient data processing agreement The Romanian DPA has fined Societatea Energetică Electrica S.A. EUR 5,000 for a violation of Art. 28 (3) a) GDPR. ROMANIA ·Art. 28 Processors Supervisory Authorities Supervision Dec 15, 2022
€2,000 Casa Rusu S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Casa Rusu S.R.L. . The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had used an… ROMANIA ·Art. 25, 32 Data Breaches Privacy by Design & Default Security Dec 9, 2022
€3,000 OTP LEASING ROMANIA IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on OTP LEASING ROMANIA IFN SA. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. An individual had… Art. 25, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Nov 25, 2022
€1,000 Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Medicover S.R.L.. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA ·Art. 32 Data Breaches Personal Data Security Nov 24, 2022