12.06.2026
Sanction for GDPR Infringement
In May 2026, the National Supervisory Authority for Personal Data Processing completed an investigation into Compania Națională Poșta Română and found infringements of Article 32(1)(b), Article 32(2), and Article 32(4) of the General Data Protection Regulation.
As a result, Compania Națională Poșta Română was fined with 26,026 lei (equivalent to 5,000 euros).
The investigation was initiated following the submission by the Constanța General Directorate for Social Assistance of a personal data breach notification, reporting that postal items sent to natural and legal persons through the Compania Națională Poșta Română had not been delivered to their intended recipients.
The investigation established that the processor, Compania Națională Poșta Română, had failed to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risks associated with the processing. It also failed to ensure that any natural person acting under the authority of the processor and having access to personal data processed such data only on the instructions of the controller.
As a consequence, postal items containing personal data were lost or destroyed. The affected data included names, surnames, addresses, tax obligations, information relating to individuals’ financial circumstances, data concerning criminal offences, information contained in social investigation reports, as well as any other personal data included in the postal items. These postal items consisted of correspondence sent by the Constanța General Directorate for Social Assistance through Compania Națională Poșta Română and concerned a large number of data subjects.
In addition, pursuant to Article 58(2)(d) of Regulation (EU) 2016/679, the controller was ordered also the corrective measure to implement the corrective measure of reviewing and updating the technical and organizational measures adopted following its assessment of the risks to the rights and freedoms of individuals. This included reviewing and updating its procedures relating to the protection of personal data in order to ensure that personal data are protected against accidental loss, destruction, or damage.
Legal and Communication Department
A.N.S.P.D.C.P.
