Home » Comunicat_Presa_28.08.2026
 Română | English | Francais

28.08.2026

Penalty for infringement of the GDPR

 

The National Supervisory Authority for Personal Data Processing completed, in July 2026, an investigation into the data controller GEROCOSSEN S.R.L. and found that it had infringed Article 32(1)(b) and Article 32(2) of Regulation (EU) 2016/679.

Accordingly, the data controller was fined RON 26,236.50, equivalent to EUR 5,000.

The investigation was initiated following the submission by GEROCOSSEN S.R.L. of a personal data breach notification pursuant to Article 33 of Regulation (EU) 2016/679.

The personal data breach occurred as a result of a cyberattack targeting the data controller’s IT infrastructure, which resulted in the unauthorised disclosure of or unauthorised access to the personal data of certain data subjects, including identification data and contact details.

The investigation established that the data controller had failed to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by the processing, including the ability to ensure the confidentiality and integrity of processing systems and services, thereby infringing Article 32(1)(b) and Article 32(2) of Regulation (EU) 2016/679.

Furthermore, pursuant to Article 58(2)(d) of the Regulation, the National Supervisory Authority imposed on the data controller the corrective measure to implement systems for monitoring and logging access to the IT infrastructure used for the processing of personal data, including a minimum retention period of 30 days for access logs, as well as a process for backing up such logs.

 

Legal and Communication Department

A.N.S.P.D.C.P.