Home » Comunicat_Presa_02_07_2026
 Română | English | Francais

01.07.2026

Sanction for GDPR Violation

 

The National Supervisory Authority for Personal Data Processing concluded an investigation into Banca Transilvania S.A. in June 2026 and found violations of Article 32(1), (2), and (4) of Regulation (EU) 2016/679.

Accordingly, the controller was fined 26,172 lei, equivalent to 5,000 euros.

The investigation was initiated following a complaint submitted by a natural person (the data subject), who alleged that personal data associated with their bank account had been processed without their consent.

During the investigation, it was established that an employee of the controller, at the request of a third party, had unauthorizedly accessed the data subject's bank account statements outside the scope of their job responsibilities. The following categories of personal data were affected: first and last name, bank account number (IBAN), account type, customer identification code, transaction details, and account balances.

The Authority found that the controller had failed to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risks associated with the processing. In particular, the controller failed to ensure that employees acting under its authority and having access to customers’ personal data processed such data only on the controller’s instructions. This failure enabled the unauthorized access to the data subject's personal data by an employee for personal purposes.

Consequently, taking into account the criteria for determining administrative fines set out in Article 83(2) of Regulation (EU) 2016/679, Banca Transilvania S.A. was fined for violating Article 32(1), (2), and (4) of Regulation (EU) 2016/679.

Furthermore, pursuant to Article 58(2)(b) of Regulation (EU) 2016/679, the Authority ordered the controller to implement corrective measures to ensure that its personal data processing operations comply with Regulation (EU) 2016/679. Specifically, the controller was required to implement appropriate technical and organizational measures to prevent employees from unlawfully accessing, for personal purposes, the personal data of individuals whose data the controller processes.

The controller paid the administrative fine imposed by the ANSPDCP.

 

Legal and Communication Department

A.N.S.P.D.C.P.