30.01.2026
Fines for GDPR violations
The National Supervisory Authority for Personal Data Processing completed, in January 2026, an investigation into a natural person acting as a data controller and established that it had infringed Article 83(5)(e), as well as Articles 5, 6, 9, 10, 12 to 14, Article 12(3) and (4), and Article 17(1) of Regulation (EU) 2016/679.
As a result, the controller was subject to the following administrative fines:
- RON 5,089 (equivalent to EUR 1,000) for the infringement of Article 83(5)(e) of Regulation (EU) 2016/679;
- RON 25,445 (equivalent to EUR 5,000) for the infringement of Articles 5, 6, 9 and 10 of Regulation (EU) 2016/679;
- RON 15,267 (equivalent to EUR 3,000) for the infringement of Articles 12 to 14 of Regulation (EU) 2016/679;
- RON 5,089 (equivalent to EUR 1,000) for the infringement of Article 12(3) and (4) and Article 17(1) of Regulation (EU) 2016/679.
The investigation was initiated following two complaints alleging that identity cards containing personal data had been published on the website evita-teparii.ro, operated by a natural person acting as the data controller.
The complaints further alleged that the controller had failed to respond to a request for the erasure of personal data relating to a natural person, as well as to requests concerning defamatory posts published in relation to that individual.
In addition, it was alleged that the website operated by the controller failed to provide the controller’s identification details and other information required to be made available pursuant to the GDPR.
In the course of the investigation, the authority established that the controller, as the operator of the website evita-teparii.ro, had failed to respond to the Authority’s requests and to provide the information sought for the purposes of enabling the Authority to exercise its investigative powers under the GDPR. Such failure constituted an infringement of Article 83(5)(e), read in conjunction with Article 58(1), of Regulation (EU) 2016/679.
The authority further established that the controller had processed personal data without a valid legal basis and in breach of the principles relating to the processing of personal data laid down by Regulation (EU) 2016/679.
In particular, the personal data of certain individuals had been unlawfully processed and those individuals had been publicly denigrated and characterised as “debtors” and/or “swindlers”. The Authority therefore found that such processing was in breach of Articles 5 and 6 of Regulation (EU) 2016/679.
Furthermore, the controller unlawfully processed special categories of personal data, namely data concerning the sexual life of a natural person, as well as data relating to a possible criminal conviction, thereby infringing Articles 9 and 10 of Regulation (EU) 2016/679.
By way of example, the personal data that were unlawfully processed and disclosed included, inter alia: first and last names, images (photographs), mobile telephone numbers, email addresses, information relating to professional activities, data concerning alleged criminal convictions, and information concerning an individual’s intimate life.
At the same time, it was established that the controller processed the personal data of natural persons (data subjects) who were labelled as “debtors”/“swindlers” on the website evita-teparii.ro, without ensuring that the data subjects were provided with fair, complete and transparent information regarding the processing of their personal data, and without effectively facilitating and ensuring the exercise of the rights of data subjects provided for under Articles 12 to 14 of the GDPR.
Furthermore, in the course of the investigation, it was established that the controller had failed to respond to the data subject’s request for the erasure of their personal data from the website operated by the controller and had failed to take measures to erase such data. This constituted an infringement of Article 12(3) and (4) and Article 17(1) of Regulation (EU) 2016/679.
In order to ensure compliance with the GDPR, the National Supervisory Authority for Personal Data Processing also imposed on the controller the following corrective measures:
- to bring the processing operations involving personal data collected and processed through the website evita-teparii.ro into compliance with Regulation (EU) 2016/679, having regard to the provisions of Articles 5, 6, 9 and 10 of Regulation (EU) 2016/679, and to submit to the National Supervisory Authority for Personal Data Processing an analysis of the measures taken and the resulting outcome;
- to bring the processing operations involving personal data collected and processed through the website evita-teparii.ro into compliance with Regulation (EU) 2016/679, by ensuring that data subjects are duly informed and that their rights are respected, having regard to the provisions of Articles 12 to 22 of the Regulation;
- to comply with the data subject’s request for the erasure of their personal data and to provide a response to that request.
Legal and Communication Department
A.N.S.P.D.C.P
