Home » Comunicat_Presa_20_03_2026
 Română | English | Francais

20.03.2026

Penalties for GDPR violations

 

The National Supervisory Authority completed an investigation in February 2026 into the company Domeniul Public și Privat SA and found that it had infringed the provisions of Article 5(1)(a) and (c) and Article 5(2), Article 6, Article 12 and Article 13 of Regulation (EU) 2016/679.

Accordingly, the controller was subject to the following administrative sanctions:

  1. a fine of RON 10,190 (equivalent to EUR 2,000) for infringement of Article 5(1)(a) and (c) and Article 5(2), as well as Articles 12 and 13 of Regulation (EU) 2016/679, for the unlawful use of a body-worn camera and failure to provide the employees with the relevant information;
  2. a reprimand for infringement of Articles 12 and 13 of Regulation (EU) 2016/679, due to incomplete information regarding the audio-video recording of disciplinary investigation meetings;
  3. a fine of RON 5,095 (equivalent to EUR 1,000) for infringement of Article 5(1)(a) and (c) and Article 5(2), Article 6 of the GDPR, and the information requirements laid down in Articles 12 and 13 of Regulation (EU) 2016/679, for the unauthorized disclosure of the employee’s personal data to their general practitioner.

The investigation was initiated following a complaint submitted by an employee of the company, who reported several potential infringements of Regulation (EU) 2016/679.

As a result of the investigation, it was established that the controller had excessively processed its employees’ personal data by using a video camera (body-worn camera), although less intrusive means were available for the purpose of monitoring compliance with occupational health and safety requirements. Furthermore, the company failed to properly inform its employees about the audio-video recordings that were to be made.

Consequently, the principles of lawfulness and proportionality, as well as the obligation to provide information, as set out in Articles 5 and 12–13 of Regulation (EU) 2016/679, were infringed.

Furthermore, the investigation established that the controller had provided incomplete information regarding the recording of disciplinary investigation meetings, in breach of the requirements of Articles 12 and 13 of Regulation (EU) 2016/679.

The investigation also revealed that the controller had unlawfully disclosed an employee’s personal data to the employee’s general practitioner.

At the same time, the controller was also subject to the following corrective measures:

  • to ensure compliance with Regulation (EU) 2016/679 in respect of personal data processing operations, so as to prevent, in the future, the unlawful, excessive and non-transparent processing of employees’ personal data through the use of body-worn cameras, including by ensuring appropriate training for persons processing data under the controller’s authority, with the involvement of the data protection officer;
  • to ensure compliance with Regulation (EU) 2016/679 in respect of personal data processing operations by ensuring that a clear legal basis is established, with reference to Articles 6 and 7 and, where applicable, Articles 9 and 10 of Regulation (EU) 2016/679, in relation to the possibility of recording disciplinary investigation meetings on electronic media; by establishing limited retention periods for such recordings in accordance with the purpose of the processing; by providing all data subjects with complete and appropriate prior information, in accordance with Articles 12 and 13 of Regulation (EU) 2016/679; and by ensuring respect for the rights of data subjects, including the right of access to such recordings pursuant to Article 15 of the same Regulation;
  • to ensure compliance with Regulation (EU) 2016/679 in respect of personal data processing operations, so as to prevent, in the future, the unlawful, excessive and non-transparent disclosure of employees’ personal data, including by ensuring appropriate training for persons processing data under the controller’s authority, with the involvement of the data protection officer.

 

Legal and Communication Department

A.N.S.P.D.C.P