Home » Comunicat_Presa_01_07_2026
 Română | English | Francais

01.07.2026

Sanction – cross-border processing

 

The National Supervisory Authority for Personal Data Processing completed an investigation into Ascendex Technology SRL in May 2026 and found that the company had infringed Article 12(1) and (3), in conjunction with Article 17(1), of Regulation (EU) 2016/679 (GDPR).

As a result, Ascendex Technology SRL was fined 57,839 lei, equivalent to 11,000 euros.

Under the cooperation mechanisms established by Regulation (EU) 2016/679, the National Supervisory Authority was notified by the French data protection authority (CNIL) regarding a complaint submitted by an individual residing in France against Ascendex Technology SRL.

CNIL identified the National Supervisory Authority as the lead supervisory authority in this case because the controller’s only establishment is located in Romania and the processing of personal data could affect data subjects in several Member States, pursuant to Article 4(23)(b) of the GDPR. CNIL’s proposal was accepted by the National Supervisory Authority.

During the investigation, it was established that Ascendex Technology SRL processed the complainant’s request for the erasure of personal data after approximately 12 months, but failed to provide a final response informing the complainant of the outcome of the request and failed to justify the delay in responding. This constituted a breach of Article 12(1) and (3), read together with Article 17 of the GDPR.

The investigation also found that, in the case of other data subjects from various EU Member States and from outside the European Union, the company took up to 37 months to process erasure requests.

The National Supervisory Authority considered that the circumstances of the case were sufficiently serious to warrant the imposition of an administrative fine on the controller, taking into account the criteria for determining administrative fines set out in Article 83(2) and (3) of the GDPR.

Following the investigation, the National Supervisory Authority informed the other supervisory authorities involved, including the French authority, through the cooperation procedures established under Article 60 of Regulation (EU) 2016/679, of the findings of the investigation concerning this cross-border case and of the proposed measures.

At the same time, pursuant to Article 58(2)(c) and (d) of Regulation (EU) 2016/679, the National Supervisory Authority ordered the controller to implement the following corrective measures:

  • provide an appropriate response to the complainant, as well as to other data subjects in a similar situation identified during the investigation, informing them of the manner in which their personal data erasure requests have been handled;
  • implement regular staff training to ensure that requests by data subjects exercising their rights under Regulation (EU) 2016/679 are handled correctly, clearly, transparently, and within the applicable legal time limits.

 

Legal and Communication Department

A.N.S.P.D.C.P.