Editing ANSPDCP (Romania) - Fine against Vodafone România S.A. 4
From GDPRhub
The edit can be undone. Please check the comparison below to verify that this is what you want to do, and then publish the changes below to finish undoing the edit.
Latest revision | Your text | ||
Line 58: | Line 58: | ||
== Comment == | == Comment == | ||
In Romania there are two parallel provisions that require a controller to implement security measures: Article 32 of the GDPR and Article 3(1) of the Law no. 506/2004. The latter is the transposition of the E-Privacy Directive | In Romania there are two parallel provisions that require a controller to implement security measures: Article 32 of the GDPR and Article 3(1) of the Law no. 506/2004. The latter is the transposition of the E-Privacy Directive, which, additionally to provisions included in the Directive, imposes the obligation to implement security measures. | ||
In the current decision, the Romanian DPA applied only the provisions of the Law no. 506/2004 with regard to the lack of security measure. For a decision where both laws were applied see [[ANSPDCP - Fine against Telekom Romania mobile communications S.A. 2]]. | In the current decision, the Romanian DPA applied only the provisions of the Law no. 506/2004 with regard to the lack of security measure. For a decision where both laws were applied see [[ANSPDCP - Fine against Telekom Romania mobile communications S.A. 2]]. |