18.06.2026
Sanction for GDPR Infringement
The National Supervisory Authority for Personal Data Processing completed an investigation into Altex România S.R.L. in May 2026 and found that the company had infringed Article 32(1)(b) and (d) and Article 32(2), Article 33(1), and Article 34(1) of Regulation (EU) 2016/679.
As a result, Altex România S.R.L. was imposed the following administrative fines:
- a fine of 36,461 lei (equivalent to 7,000 euros) for infringing Article 32(1)(b) and (d) and Article 32(2) of Regulation (EU) 2016/679, as the controller failed to implement appropriate technical and organisational measures;
- a fine of 10,417 lei (equivalent to 2,000 euros) for infringing Article 33(1) of Regulation (EU) 2016/679, as the controller failed to notify the National Supervisory Authority of the personal data breach;
- a fine of 5,208 lei (equivalent to 1,000 euros) for infringing Article 34(1) of Regulation (EU) 2016/679, as the controller failed to inform the affected data subject that a personal data breach had occurred.
The investigation was initiated following complaints submitted by an individual alleging possible infringements of Regulation (EU) 2016/679.
The investigation established that, due to a technical vulnerability in the controller’s mobile application during the account validation process for the complainant, personal data belonging to a third party became accessible.
As a result of this malfunction, personal data of a third party, including their first name, last name, invoices, and delivery addresses, were accessed without authorisation.
During the investigation, it was found that the controller had failed to implement sufficient appropriate technical and organisational measures to ensure the security and confidentiality of personal data, as required under Article 32(1) and (2) of Regulation (EU) 2016/679.
In addition, it was established that the controller failed to notify the National Supervisory Authority of the personal data breach and also failed to inform the affected data subject, thereby infringing Articles 33 and 34 of Regulation (EU) 2016/679.
Furthermore, pursuant to Article 58(2)(d) of Regulation (EU) 2016/679, the National Supervisory Authority ordered the controller to implement the following corrective measures:
- review the validation and authentication mechanisms associated with user accounts;
- implement procedures for the periodic testing of vulnerabilities affecting the mobile application;
- establish internal procedures for handling security incidents and assessing notification obligations under Articles 33 and 34 of Regulation (EU) 2016/679;
- provide regular training to staff responsible for managing security incidents and handling requests from data subjects;
- send a written response to the complainant addressing the issues raised in the complaint.
Legal and Communication Department
A.N.S.P.D.C.P.
