19.08.2026
Administrative fine for infringement of the GDPR
The National Supervisory Authority for Personal Data Processing completed, in July 2026, an investigation into Poliserv JG (PJG) S.R.L. and found that it had infringed Article 32(1)(b) and Article 32(2) of the General Data Protection Regulation (GDPR).
Accordingly, Poliserv JG (PJG) S.R.L. was fined RON 15,728, equivalent to EUR 3,000.
The investigation was initiated following the submission by Poliserv JG (PJG) S.R.L. of a personal data breach notification pursuant to Article 33 of Regulation (EU) 2016/679.
The investigation established that the personal data breach had occurred as a result of a cyberattack exploiting the credentials of a user account with administrator privileges, which had been obtained through phishing.
This resulted in unauthorised access to the personal data (at least first and last names) of certain natural persons who were customers of the data controller.
It was therefore established that the data controller had failed to implement appropriate technical and organisational measures and had failed to carry out regular testing, assessment and evaluation of the effectiveness of the technical and organisational measures implemented to ensure the security of processing, including the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services.
The National Supervisory Authority considered that the circumstances of the case were sufficiently serious to warrant the imposition of an administrative fine on the data controller, taking into account the criteria for determining the amount of administrative fines set out in Article 83 of Regulation (EU) 2016/679.
At the same time, pursuant to Article 58(2)(d) of Regulation (EU) 2016/679, the National Supervisory Authority also imposed the corrective measure on Poliserv JG (PJG) S.R.L. to periodically verify compliance with the implemented procedures concerning the protection of personal data and information security, and to provide periodic training to persons acting under the authority of the data controller regarding the risks associated with the processing of personal data, including the identification and handling of phishing messages and other suspicious emails.
Legal and Communication Department
A.N.S.P.D.C.P.
