Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) · 9 December 2022
Casa Rusu S.R.L.
Insufficient technical and organisational measures to ensure information security
- Regulator
- Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
- Decided
- 9 December 2022
- Country
- Romania
- Sector
- Industry and Commerce
- Regulator’s reference
- Not recorded
- Fino case number
- 2022/RO/004
What happened
Following the notification of a data breach, which gave unauthorized parties access to bank details, the Romanian DPA investigated a controller, concluded that it was in breach of Article 25 and 32 GDPR based on its lacking security measures, ordered the controller to take corrective measures, and fined the controller 9,883.60 RON (equivalent to €2000).
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 25Data protection by design and by default25(1)Read →
- Art. 32Security of processing32(1)(b) · 32(2)Read →
- Accountability
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2022/RO/004.