Home » Comunicat_Presa_26.06.2026
 Română | English | Francais

26.06.2026

Fine for Breach of Law No. 506/2004

 

The National Supervisory Authority for Personal Data Processing completed an investigation into AVIZIERO S.R.L. in June 2026 and found that the company had infringed Article 4(5)(a) and (b) of Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector.

As a result, the controller was fined with 5,000 lei.

The investigation was initiated following a complaint submitted by an individual regarding a potential breach of personal data protection legislation.

During the investigation, the National Supervisory Authority for Personal Data Processing found that, at the time the website was accessed, the controller’s website used cookies that were not technically necessary.

These cookies enabled the storage of, and access to, information on users’ terminal equipment without providing data subjects with clear and complete information and without obtaining their prior consent.

Accordingly, it was established that the controller allowed the storage of information on, and access to information stored in, users’ terminal equipment when they accessed its website, in breach of Article 4(5)(a) and (b) of Law No. 506/2004.

It should be noted that Article 4(5) of Law No. 506/2004 provides as follows:

“(5) The storage of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user shall be permitted only where all of the following conditions are met:

(a) the subscriber or user concerned has given their consent;

(b) prior to giving such consent, the subscriber or user has been provided, in accordance with Article 12 of Law no. 677/2001, as amended and supplemented, with clear and comprehensive information which:

(i) is presented in clear and easily understandable language and is readily accessible to the subscriber or user;

(ii) includes information regarding the purpose of the processing of the information stored on, or accessed from, the subscriber’s or user’s terminal equipment.

Where the provider allows third parties to store information on, or access information stored in, the subscriber’s or user’s terminal equipment, the information referred to in points (i) and (ii) shall also include the general purpose of the processing carried out by such third parties and information on how the subscriber or user may use the settings of their internet browser or other similar technologies to delete stored information or refuse third-party access to such information.”

 

Legal and Communication Department

A.N.S.P.D.C.P.