01.09.2026
Fine for violating Law no. 506/2004 and the GDPR
The National Supervisory Authority for Personal Data Processing completed, in 2025, an investigation at the controller Money Seeds S.R.L. and found a violation of the provisions of Article 12 paragraphs (1) and (2) of Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communication sector as well as of Articles 12 to 14 of Regulation (EU) 2016/679.
As such, the controller was sanctioned as follows:
- fine in the amount of 5,000 lei for violating the provisions of Article 12 paragraphs (1) and (2) of Law no. 506/2004
- fine in the amount of 10,178 lei (equivalent to 2,000 euros) for violating the provisions of Articles 12 to 14 of Regulation (EU) 2016/679.
The investigation was initiated following a complaint from a natural person, who claimed that the controller Money Seeds S.R.L. sent him unsolicited commercial messages to his e-mail address, although he opposed receiving them.
The petitioner repeatedly requested the deletion of his data, but did not receive a response.
During the investigation, it was found that the controller processed the petitioner’s e-mail address for the purpose of sending commercial communications, although he had previously expressed his opposition.
Also, the controller did not offer the petitioner the possibility to object through a simple and free of charge means to the use of his e-mail address for direct marketing purposes, thus violating the provisions of Article 12 paragraphs (1) and (2) of Law no. 506/2004.
At the same time, it was found that the controller did not present evidence regarding the provision of complete and correct information to data subjects in accordance with Articles 13-14 of Regulation (EU) 2016/679, in relation to the provisions of Article 12 of the same legal act.
At the same time, pursuant to Article 58 paragraph (2) letter d) of Regulation (EU) 2016/679, the controller was ordered to take the following corrective measures:
- to send a response to the requests of the petitioner through which he exercised his right to erasure and opposition;
- to ensure compliance with Regulation (EU) 679/2016 of the personal data processing operations, by adopting the necessary technical and organizational measures, including in terms of reviewing the database, the IT applications used and the appropriate training of staff, so that the processing of personal data for direct marketing purposes by sending commercial communications through electronic communications services intended for the public (such as telephone, SMS, e-mail) is carried out in compliance with the provisions of Law no. 506/2004 and Regulation (EU) 2016/679, implicitly with regard to expressing opposition, ensuring correct and complete information, by providing all the information provided for in Articles 13-14 of Regulation (EU) 2016/679 and in compliance with Article 12 of the same legal act, as well as the management and appropriate handling within the legal term of the requests of the data subjects.
Legal and Communication Department
A.N.S.P.D.C.P
