06.08.2026
Penalty for violating the GDPR and Law no. 506/2004
The National Supervisory Authority for Personal Data Processing completed an investigation in June 2026 into AMATO BESTSELLER S.R.L., as data controller, and found that the company had infringed Article 32(4), Article 14, and Article 5(1)(c), read in conjunction with Article 9, of Regulation (EU) 2016/679, as well as Article 12(1) of Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector.
As a result, the data controller was subject to the following administrative fines:
- a fine of RON 78,465, equivalent to EUR 15,000, for infringement of Article 32(4) of Regulation (EU) 2016/679;
- a fine of RON 52,310, equivalent to EUR 10,000, for infringement of Article 14 of Regulation (EU) 2016/679;
- a fine of RON 104,620, equivalent to EUR 20,000, for infringement of Article 5(1)(c), read in conjunction with Article 9, of Regulation (EU) 2016/679;
- a fine of RON 50,000 for infringement of Article 12(1) of Law no. 506/2004.
The investigation was initiated following complaints submitted by several data subjects, who reported potential infringements of Regulation (EU) 2016/679.
As part of the investigation, it was established that the data controller had infringed Article 32(4) of the GDPR, as it had failed to take measures to ensure that any natural person acting under its authority and having access to personal data did not process such data except on its instructions. Accordingly, the data controller had failed to properly instruct its own employees and to provide them with working procedures/policies regarding the processing of personal data of data subjects in a manner ensuring an appropriate level of security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, through the implementation of appropriate technical and organisational measures.
This deficiency resulted in employees and former employees of the data controller having unauthorised access, for a certain period of time, to personal data belonging to a considerable number of data subjects, including first and last names, telephone numbers, the degree of kinship between one data subject and another, occupation, marital status, membership of a particular social category, city of domicile/residence, income-related information, family data, and health data/special categories of personal data.
Furthermore, it was established that the data controller had infringed Article 14 of the GDPR, as it had failed to provide data subjects with accurate and complete information, in accordance with the requirements of the GDPR.
In addition, the investigation established that the data controller had carried out excessive processing of personal data, including special categories of personal data and health data, without ensuring that such data were adequate, relevant and limited to what was necessary in relation to the purposes for which they were processed, thereby infringing the principle of “data minimisation” laid down in Article 5(1)(c), read in conjunction with Article 9, of the GDPR.
During the course of the investigation, it was also established that the data controller had carried out direct marketing communications using automated calling and communication systems that did not require the intervention of a human operator, by calling the telephone numbers and conducting conversations with a significant number of data subjects, without the relevant users having given their prior express consent to receive such communications, in violation of Article 12(1) of Law no. 506/2004.
At the same time, the national supervisory authority also imposed the following corrective measures, requiring the data controller to:
- include, in all procedures/working policies applicable at the level of the data controller, clear instructions regarding the flow of personal data processed by the data controller, the flow of documents containing personal data, for each processing purpose and method, as well as details concerning employees’ differentiated access to certain activities involving personal data, and to provide periodic training to employees and other natural or legal persons processing personal data under the authority of AMATO BESTSELLER S.R.L.;
- ensure that data subjects whose personal data are processed by the data controller receive clear, complete and accurate information, in accordance with Article 14 of the GDPR and the transparency requirements set out in Article 12 of the GDPR;
- process personal data in compliance with Article 5(1)(c) of the GDPR, for each processing purpose separately;
- ensure that the data subject provides prior express consent to the receipt of unsolicited communications.
Legal and Communication Department
A.N.S.P.D.C.P.
