19.01.2026
Sanctions for infringing the GDPR
The National Supervisory Authority for Personal Data Processing completed, in December 2025, an investigation at the controller Continental Automotive Products SRL and found the violation of the provisions of Article 5 paragraph (1) letter c) and paragraph (2) and Article 32 paragraph (1) letter b) and paragraph (2) of Regulation (EU) 2016/679.
As such, the controller was sanctioned with:
- a fine in the amount of 25,455 lei (equivalent to 5,000 euros) for infringing the provisions of Article 5 paragraph (1) letter c) and paragraph (2) of Regulation (EU) 2016/679;
- a fine in the amount of 50,911 lei (equivalent to 10,000 euros) for infringing the provisions of Article 32 paragraph (1) letter b) and paragraph (2) of Regulation (EU) 2016/679.
The investigation was initiated following the transmission by the controller Continental Automotive Products SRL of a notification regarding the breach of personal data security, in accordance with the provisions of Article 33 of Regulation (EU) 2016/679.
According to the information mentioned in the notification form, an excel file containing a centralizer with the controller’s employees, including medical data, was repeatedly distributed internally.
The excel file contained data from the medical certificates of employees and former employees from a certain period of time.
The investigation also revealed that the controller did not implement sufficient technical and organizational measures to guarantee the security of data and the resilience of the processing systems. This vulnerability allowed unauthorized access to a series of personal data for a significant number of employees and former employees.
Thus, a lack of responsibility of the controller was found in implementing appropriate technical and organizational measures to minimize the risk of unauthorized disclosure/access to personal data.
At the same time, the controller was also ordered the corrective measure to implement, within a technical and organizational procedure, all processes involving the processing of personal data, including the establishment of a monitoring and control process for the immediate identification of any incidents of personal data security breaches
Legal and Communication Department
A.N.S.P.D.C.P
