ANSPDCP (Romania) - 26.09.2023

From GDPRhub
Revision as of 12:26, 16 October 2023 by Aa (talk | contribs)
ANSPDCP - 26.09.2023
LogoRO.jpg
Authority: ANSPDCP (Romania)
Jurisdiction: Romania
Relevant Law: Article 32(1)(b) GDPR
Article 32(1)(d) GDPR
Article 4 (5) Law 506/2004 (implementing ePrivacy Directive)
Type: Investigation
Outcome: Violation Found
Started:
Decided:
Published:
Fine: 32000 EUR
Parties: n/a
National Case Number/Name: 26.09.2023
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): Romanian
Original Source: Romanian DPA (in RO)
Initial Contributor: maxinescu

An energy company was fined €25,000 for failing to implement the appropriate technical and organisational measures, following a data breach affecting at least 750 data subjects, in violation of Articles 32(1)(b) and 32(1)(d) GDPR. In addition, the company was fined €8,000 for failing to comply with cookie requirements under Law 506/2004 (implementing the ePrivacy Directive).

English Summary

Facts

The DPA opened an investigation against an energy company (the controller), after receiving a complaint regarding a data breach on the company's website. A file on the controller’s website was publicly accessible, which contained personal data of at least 750 data subjects, including data relating to subjects' name, surname, address, telephone numbers, e-mail address, contract number and date whereby subjects concluded their contract with the energy company. The file was publicly accessible for two and a half years.

During its investigation, the DPA also assessed that during the accession of the website by users, the controller employed cookies which were unnecessary for the operation of the website. The cookies were installed before the user was given the option to consent or refuse cookies. Even in instances where the user refused cookies, they were nonetheless installed on their device, irrespective of the user’s choice.

Holding

The DPA found violations of Articles 32(1)(b) and 32(1)(d) GDPR, as well as a breach of Article 4(5) of Law 506/2004.

In regards to Article 32 GDPR, the DPA found that the controller had failed to implement the appropriate technical and organisational measures to safeguard data subjects' personal data. The file had been publically accessibel

In addition to the sanctions imposed, the DPA has also imposed corrective measures, ordering the controller to implement a procedural plan including a process of periodic testing, evaluation and reassessment of all systems and their subsequent changes made by the controller or its service providers (processors), in particular with respect to the website managed by the controller.

Comment

Unfortunately, the Romanian DPA does not publish its full decisions. This summary is based on a press release.

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Romanian original. Please refer to the Romanian original for more details.

https://www.dataprotection.ro/?page=Comunicat_Presa_26_09_2023&lang=ro