Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) · 18 May 2022
Kredyt Inkaso Investments RO S.A
Insufficient legal basis for data processing
Fine€5,000Fine issued
- Regulator
- Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
- Decided
- 18 May 2022
- Country
- Romania
- Sector
- Finance, Insurance and Consulting
- Regulator’s reference
- Not recorded
- Fino case number
- 2022/RO/035
What happened
The Romanian DPA fined a credit institution and collection agency approximately €5,000 (24.740 RON) for unlawfully disclosing the personal data of an employee to doctors and medical units.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal dataRead →
- Art. 6Lawfulness of processingRead →
- Art. 9Processing of special categories of personal dataRead →
- Art. 33Notification of a personal data breach to the supervisory authorityRead →
- Data breach
- Data principles
- Special categories
- Unlawful processing
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2022/RO/035.