04.02.2026
Sanction – cross-border processing
The National Supervisory Authority for Personal Data Processing completed, in December 2025, an investigation into GENPACT ROMANIA SRL and found that the company had violated the provisions of Article 32(1)(b) and Article 32(2) of Regulation (EU) 2016/679.
Accordingly, the company was subject to an administrative fine amounting to RON 50,899, equivalent to EUR 10,000.
In this case, considering that GENPACT ROMANIA SRL has its main establishment in Romania, the National Supervisory Authority for Personal Data Processing acted as the supervisory authority of the controller's main establishment, competent to act as the lead supervisory authority for the cross-border processing carried out by GENPACT ROMANIA SRL, in accordance with the procedure laid down in Article 60 of Regulation (EU) 2016/679.
The investigation was initiated following the controller's submission of a personal data breach notification pursuant to the General Data Protection Regulation.
Thus, GENPACT ROMANIA SRL notified a personal data breach consisting of the unauthorized access to personal data, through a cyberattack, relating to a significant number of the controller's users.
In the course of the investigation, the National Supervisory Authority for Personal Data Processing found that GENPACT ROMANIA SRL had failed to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk presented by the processing, in particular with regard to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to personal data.
This resulted in the unauthorized disclosure of personal data (employee name, internal employee number, business email address, department, internal job title, the address of the Genpact office where they work, the date on which the employee account was created, and the country code) relating to a significant number of data subjects across the EU. The breach occurred through a cyberattack that exploited password vulnerabilities and weaknesses in the authentication reset mechanism of a compromised user account.
The National Supervisory Authority for Personal Data Processing considered that the circumstances of the above-mentioned case were sufficiently serious to warrant the imposition of an administrative fine on the controller, taking into account the criteria for the determination of fines set out in Article 83 of Regulation (EU) 2016/679.
We note that the controller has paid the administrative fine imposed.
Legal and Communication Department
A.N.S.P.D.C.P
