Fino

ANSPDCP (Romania) · 28 August 2026

GEROCOSSEN S.R.L.

About: Data security

FineRON26,236.5≈ €4,990Violation found
Regulator
ANSPDCP (Romania)
Decided
28 August 2026
Country
Romania
Sector
Not given
Regulator’s reference
Fine against GEROCOSSEN S.R.L.
Fino case number
2026/RO/032
Export as PDF

What happened

The Romanian DPA imposed a RON 26,236.50 (€5,000) fine on a cosmetics retailer for infringing Article 32 GDPR by failing to implement adequate security measures, after a cyberattack affecting its IT infrastructure led to a personal data breach.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2026/RO/032.