ANSPDCP (Romania) - Fine against There's an AI for that S.R.L: Difference between revisions

From GDPRhub
m GDPRhub EU cleanup
 
Line 33: Line 33:
|GDPR_Article_Link_2=
|GDPR_Article_Link_2=


|EU_Law_Name_1=Article 5(3) of Directive 2002/58/EC  
|EU_Law_Name_1=Article 5(3) ePrivacy Directive 2002/58/EC  
|EU_Law_Link_1=https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32002L0058
|EU_Law_Link_1=https://eur-lex.europa.eu/eli/dir/2002/58/oj
|EU_Law_Name_2=
|EU_Law_Name_2=
|EU_Law_Link_2=
|EU_Law_Link_2=

Latest revision as of 12:58, 24 July 2026

ANSPDCP - Fine against There's an AI for that S.R.L
Authority: ANSPDCP (Romania)
Jurisdiction: Romania
Relevant Law:
Article 5(3) ePrivacy Directive 2002/58/EC
Art. 4 (5)(a) of Law no. 506/2004
Art. 4 (5)(a)(b) of Law no. 506/2004
Type: Complaint
Outcome: Upheld
Started:
Decided:
Published:
Fine: 30.000 RON
Parties: There's an AI for that S.R.L
National Case Number/Name: Fine against There's an AI for that S.R.L
European Case Law Identifier: n/a
Appeal: n/a
Original Language(s): Romanian
Original Source: ANSPDCP (in RO)
Initial Contributor: RP

The DPA fined the operator of a website RON 30,000 (€6,000) for setting non-essential cookies without clear information or valid consent, breaching the ePrivacy Directive.

English Summary

Facts

In October 2025, the Romanian National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal – ANSPDCP) concluded an investigation into THERE’S AN AI FOR THAT S.R.L., a company operating a website that used cookies. The investigation began after a data subject submitted a complaint alleging a possible breach of data protection rules.

Holding

The ANSPDCP found that the controller’s website stored cookies that were not technically necessary on users’ devices. The authority also found that users were not provided with clear and complete information about these cookies and that their explicit consent had not been obtained before such cookies were placed.

The ANSPDCP held that the controller violated Article 4(5)(a) and Article 4(5)(b) of Law No. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector (implementing ePrivacy Directive).

As a result, the authority imposed an administrative fine of RON 30,000 (€6,000) on the controller for processing data through non-essential cookies without proper information or consent.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Romanian original. Please refer to the Romanian original for more details.

04.11.2025

Sanction for violation of Law no. 506/2004

 

The National Supervisory Authority for Personal Data Processing completed, in October 2025, an investigation at the operator THERE’S AN AI FOR THAT S.R.L and found a violation of the provisions of art. 4 para. (5) let. a) and b) of Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector. 

As such, the operator was sanctioned with a fine of 30,000 lei.

The investigation was initiated following a complaint by an individual regarding a possible violation of the provisions of the legislation in the field of personal data protection.

During the investigation, the National Supervisory Authority for Personal Data Processing found that on the website owned by the operator, cookies were stored that were not technically necessary on the users' equipment, without clear and complete information and without the express consent of the data subjects.

In this context, the operator was fined for violating the provisions of art. 4 para. (5) let. a) and b) of Law no. 506/2004.

 

Legal and Communication Department

A.N.S.P.D.C.P