17.07.2026
Sanction for GDPR Violation
The National Supervisory Authority for Personal Data Processing concluded an investigation into Orange Romania S.A. in June 2026 and found violations of Articles 25(1), 32(1)(b) and (d), and 32(2) and (4) of Regulation (EU) 2016/679.
As a result, Orange Romania S.A. was sanctioned with two fines totaling 523,900 lei (equivalent to 100,000 euros), as follows:
- A fine of 104,780 lei (equivalent to 20,000 euros) for violating Article 25(1) of Regulation (EU) 2016/679, due to the failure to implement appropriate technical and organizational measures both when determining the means of processing and during the actual processing of personal data.
- A fine of 419,120 lei (equivalent to 80,000 euros) for violating Articles 32(1)(b) and (d), 32(2), and 32(4) of Regulation (EU) 2016/679, due to the failure to implement appropriate technical and organizational measures to ensure the confidentiality and security of personal data processing.
The investigation was initiated following the controller's submission of a personal data breach notification pursuant to Article 33 of Regulation (EU) 2016/679.
According to the notification, the security incident occurred within the controller's mobile application, where one customer was able to access and download equipment invoices belonging to other customers. The incident resulted from a synchronization error between two interconnected applications operated by the company, which led to the incorrect association of a customer account with that of a company employee.
During the investigation, the Authority found that the controller had failed to implement appropriate technical and organizational measures when configuring and operating its digital platforms in order to protect the rights of its users. As a consequence, the personal data of multiple data subjects was unlawfully disclosed, including: first and last names, residential addresses, delivery addresses, identity card series and numbers, invoice series and numbers, and invoice issue dates. This constituted a breach of Article 25(1) of Regulation (EU) 2016/679.
The investigation also established that the controller had failed to implement appropriate technical and organizational measures to ensure an adequate level of security for the platforms it managed and had not regularly tested the effectiveness of its security systems. This vulnerability enabled a cyberattack targeting access to the controller's ticketing application, resulting in unauthorized access to and unauthorized disclosure of personal data that had been transmitted, stored, or otherwise processed. The platform was publicly accessible without essential security safeguards, such as a secure VPN connection, multi-factor authentication (MFA), or IP-based access restrictions.
As a result, a very large volume of personal data was unlawfully exfiltrated, including: names and surnames; postal addresses; telephone numbers; email addresses; personal identification numbers (CNPs); identity card series and numbers, including copies of identity cards; bank card information, including expiration dates and card issuers; authentication credentials that could potentially serve as access keys for communication between applications (past or current); customer codes; IBAN numbers; SIM card numbers; and employee job function classifications.
Pursuant to Article 58(2)(d) of Regulation (EU) 2016/679, the Authority also imposed a corrective measure requiring the controller to implement technical and organizational procedures for the continuous monitoring and testing of all IT applications used in its operations. These procedures must ensure oversight of all software changes (including updates, configuration changes, and interconnection processes) and include follow-up testing designed to identify vulnerabilities that could lead to unauthorized access to personal data.
Legal and Communication Department
A.N.S.P.D.C.P.
