ANSPDCP (Romania) - 29.12.2025
| ANSPDCP - 29.12.2025 | |
|---|---|
![]() | |
| Authority: | ANSPDCP (Romania) |
| Jurisdiction: | Romania |
| Relevant Law: | Article 5(1)(a) GDPR Article 6 GDPR Article 12 GDPR Article 13 GDPR Article 32(1) GDPR |
| Type: | Complaint |
| Outcome: | Upheld |
| Started: | |
| Decided: | |
| Published: | 29.12.2025 |
| Fine: | 10,177 RON |
| Parties: | Ordinul Asistenților Medicali Generaliști, Moașelor și Asistenților Medicali din România – Filiala Neamț |
| National Case Number/Name: | 29.12.2025 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Romanian |
| Original Source: | ANSPDCP (in RO) |
| Initial Contributor: | dt |
The DPA fined a professional nurses' organisation RON 10,177 (€2,000) for its unlawful use of surveillance cameras. Furthermore, the DPA issued warnings for failing to provide prior information to data subjects and for failing to implement security measures.
English Summary
Facts
The Romanian DPA (ANSPDCP) launched an investigation into Ordinul Asistenților Medicali Generaliști, Moașelor și Asistenților Medicali din România – Filiala Neamț (the controller), a professional association, following a complaint by a data subject regarding the installation of a surveillance camera facing the data subject’s desk without informing the data subject about the existence of the camera.
Holding
The DPA noted that the controller processed images of its employees and of students attending its courses without showing that it carried out prior consultations of the employees and/or the labour union.
The DPA found that the controller processed personal data without a legal basis, violating Article 5(1)(a) GDPR and Article 6 GDPR.
Furthermore, the DPA concluded that the controller did not check if less intrusive measures could have been used and did not implement appropriate technical and organisational measures for the processing of personal data, violating Article 32 GDPR.
Moreover, the DPA found that the controller did not carry out prior informing of the data subjects regarding the processing activities, violating Article 12 GDPR and Article 13 GDPR.
Therefore, the DPA issued a fine of RON 10,177 (€2,000) for violating Article 5(1)(a) GDPR and Article 6 GDPR, a warning for violating Article 32(1) GDPR and another warning for violating Article 12 GDPR and Article 13 GDPR, along with ordering the controller to take specific corrective measures.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Romanian original. Please refer to the Romanian original for more details.
29.12.2025 Sanctions for violation of the GDPR The National Supervisory Authority for Personal Data Processing completed, in November 2025, an investigation at the operator Order of General Nurses, Midwives and Medical Assistants of Romania – Neamț Branch and found a violation of the provisions of art. 5 para. (1) letter a), art. 6, art. 32 para. (1), art. 12 and art. 13 of the General Data Protection Regulation (GDPR). As such, the operator was sanctioned as follows: fine in the amount of 10,177 lei, equivalent to 2,000 EURO for violating the provisions of art. 5 para. (1) letter a) and art. 6 of the GDPR; warning for violating the provisions of art. 32 para. (1) of the GDPR; warning for violation of the provisions of art. 12 and art. 13 of the GDPR. The investigation was initiated following a complaint by which the petitioner claimed that the operator had installed a video surveillance camera facing the office where he worked, as well as the fact that he had not been informed about the existence of the video surveillance system. During the investigation, the National Supervisory Authority found that the operator had processed the image of its employees and students, through video surveillance cameras installed in the offices and in the classroom, without providing proof that it had carried out prior consultation with the employees/union before installing and putting into operation the video surveillance system at the workplace. It was also found that the operator did not prove that other less intrusive forms and methods for achieving the purpose pursued by the employer had not previously proven their effectiveness and that the operator did not implement appropriate technical and organizational measures to ensure the security and confidentiality of personal data processed through the video surveillance system. At the same time, the investigation also found that the operator did not present evidence showing that it had fully informed the data subjects about the processing of data through the video surveillance system, which constitutes a violation of the provisions of art. 12 and 13 of the GDPR. At the same time, the operator was ordered to take the following corrective measures: eliminating the use of the video surveillance system installed in the offices and in the classroom, for which there is no express legal basis for processing the personal data of its employees, in relation to art. 5 and 6 of the GDPR; providing full information to data subjects, in relation to all activities involving the processing of personal data, by providing all the information provided for in art. 13 and 14 of the GDPR, as appropriate, as well as in compliance with the conditions provided for in art. 12 of the GDPR; implementing appropriate technical and organizational security measures for all personal data processing, in particular for processing carried out through video surveillance cameras, in accordance with art. 24, 29 and 32 of the GDPR; taking the necessary measures so that, in the future, the compliance of processing operations with the provisions of the GDPR is ensured, namely that the video cameras installed outside the building record images only from the perimeter belonging to the operator, and not from the public domain. We would like to point out that the operator has paid the fine imposed for the offence. Legal and Communication Department A.N.S.P.D.C.P.




