31.07.2026
Penalty for violating the GDPR and Law no. 506/2004
The National Supervisory Authority for Personal Data Processing completed, in June 2026, an investigation into HOMELUX S.R.L. and found that the company had infringed Article 32(1)(d) and Article 32(2) of Regulation (EU) 2016/679, as well as Article 4(5) of Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector.
Accordingly, the company was sanctioned for the administrative offence as follows:
- a fine of RON 78,570, equivalent to EUR 15,000, for the infringement of Article 32(1)(d) and Article 32(2) of Regulation (EU) 2016/679;
- a fine of RON 30,000 for the infringement of Article 4(5) of Law No. 506/2004.
The investigation was initiated following a personal data breach notification submitted by HOMELUX S.R.L. pursuant to Article 33 of the GDPR.
The investigation established that the incident resulted from a cyberattack targeting the platform supporting the operation of the company’s website. At the time of the incident, the platform was not technically aligned with the official version released by the manufacturer.
The investigation also found that the incident was facilitated by the insufficient complexity of the passwords used when user accounts were created on the company’s website. This security deficiency was not remedied following the incident.
Overall, the investigation found that HOMELUX S.R.L. had failed to implement adequate security measures to protect the personal data it processed—including names, addresses, email addresses and passwords—against unauthorised or unlawful processing and against accidental loss, destruction or damage.
Furthermore, in the course of the investigation, it was established that the company stored information, including cookies that were not technically necessary for the operation of its website, and accessed information stored on the users’ terminal equipment without obtaining their consent.
At the same time, the national supervisory authority also imposed the following corrective measures, requiring the company to:
- implement a documented procedure including a process for the periodic testing, evaluation and assessment of all systems, as well as of any subsequent modifications made by the company or its service providers (processors), in particular with regard to the website operated by the company;
- implement appropriate technical and organisational measures to control and secure access to accounts created on the company’s website, including by establishing minimum password complexity requirements, implementing multi-factor authentication for accounts with administrative privileges, managing and disabling inactive accounts, and applying the principle of least privilege; implement appropriate technical measures to protect the web application against unauthorised access and the exploitation of vulnerabilities, including mechanisms for detecting and blocking attempted attacks, validating and filtering user input, and restricting access to administrative interfaces, in order to ensure the confidentiality, integrity and availability of the personal data processed;
- ensure, with regard to the website operated by the company, that all the conditions set out in Article 4(5) of Law no. 506/2004 are met cumulatively.
Legal and Communication Department
A.N.S.P.D.C.P.
