Home » Comunicat_Presa_29_05_2026
 Română | English | Francais

29.05.2026

Sanctions for GDPR Infringement

 

In May 2026, the National Supervisory Authority for Personal Data Processing completed an investigation into UniCredit Bank S.A. and found infringements of Article 32(1)(b), Article 32(2), Article 32(4), and Article 33(1) of Regulation (EU) 2016/679.

As a result, UniCredit Bank S.A. was sanctioned with two fines totaling 62,714 lei (equivalent to 12,000 euros), as follows:

  1. A fine of 52,270 lei (equivalent to 10,000 euros) for infringing Article 32(1)(b), Article 32(2), and Article 32(4) of Regulation (EU) 2016/679, due to the failure to implement appropriate technical and organizational measures.
  2. A fine of 10,454 lei (equivalent to 2,000 euros) for infringing Article 33(1) of Regulation (EU) 2016/679, due to the failure to notify the personal data breach within the statutory time limit.

The investigation was initiated following the submission of a complaint by an individual alleging possible infringements of Regulation (EU) 2016/679.

The investigation established that, in connection with the renewal of insurance policies for customers whose policies were approaching expiry, the controller sent incorrect renewal notifications to a large number of customers through both mobile and online banking messaging services, as well as by email. The unauthorized disclosure resulted from an error in the processing of a file used to prepare the notifications.

During the investigation, it was found that the controller had failed to implement appropriate technical and organizational measures to ensure that any natural person acting under the authority of the controller or of the processor and having access to personal data processed such data only on the instructions of the controller. The controller also failed to ensure a level of security appropriate to the risks associated with the processing, including the ability to guarantee the confidentiality of personal data.

As a consequence, the incident resulted in the unauthorized disclosure of personal data (including customers’ first and last names, addresses, the address and insured value of the insured property, their status as mortgage loan customers of the bank, the expiry date of the insurance policy, and the insurance premium) to a significant number of data subjects. This occurred because insurance policy expiry notifications were mistakenly sent to individuals other than their intended recipients due to improper manual processing of a data file.

This constituted an infringement of Article 32(1)(b), Article 32(2), and Article 32(4) of Regulation (EU) 2016/679.

Furthermore, during the investigation it was established that the controller failed to notify the personal data breach within 72 hours of becoming aware of the security incident. The notification was submitted after the statutory deadline, despite the controller having concrete information regarding the breach of the confidentiality of personal data. This constituted an infringement of Article 33(1) of Regulation (EU) 2016/679.

 

Legal and Communication Department

A.N.S.P.D.C.P.