25.03.2026
Penalty for GDPR violation
The National Supervisory Authority for Personal Data Processing completed, in March 2026, an investigation into the controller RENAULT COMMERCIAL ROUMANIE S.R.L. and found a violation of Article 32(1)(b) and (d) and Article 32(2), in conjunction with Article 28(1), of Regulation (EU) 2016/679.
Accordingly, the controller was sanctioned with:
- a fine amounting to RON 637,262.50, equivalent to EUR 125,000, for violating the provisions of Article 32(1)(b) and (d) and Article 32(2), in conjunction with Article 28(1), of Regulation (EU) 2016/679.
The investigation was initiated following the submission by RENAULT COMMERCIAL ROUMANIE S.R.L. of a notification of a personal data breach, pursuant to Article 33 of Regulation (EU) 2016/679.
During the investigation, it was established that, following a cyberattack targeting an application operated by the controller through a processor, various categories of personal data belonging to a very large number of data subjects were accessed and unlawfully disclosed by being published on a platform.
The personal data accessed and disclosed included: first name, last name, personal telephone number, business telephone number, home address, driving licence number, email address, postal address, personal identification number, vehicle identification number, date of birth, identity card series and number, job title, employer, and personal identification number for employees.
Accordingly, it was established that the controller had failed to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by the processing, including, among other things, the ability to ensure the confidentiality of processing systems and services, as well as the implementation of a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures in order to ensure the security of the processing.
It was also established that the controller had failed to ensure that it engaged only processors providing sufficient guarantees for the implementation of appropriate technical and organisational measures, in accordance with the provisions of Article 28(1) of the GDPR.
Legal and Communication Department
A.N.S.P.D.C.P
