Home » Comunicat_Presa_25_05_2026
 Română | English | Francais

25.05.2026

25 May 2026 – Eight Years Since the GDPR Became Applicable

 

On 25 May 2026, eight years have passed since the application of Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (GDPR) across all Member States of the European Union.

On this occasion, we would like to emphasize that, throughout these eight years of GDPR application, controllers in both the public and private sectors have continued to implement the rules governing the processing of personal data, particularly those relating to the provision of information to individuals, the effective exercise of data subjects’ rights, and the safeguarding of the confidentiality and security of personal data processing.

To mark the eighth anniversary of the GDPR, we present below a summary of the most significant aspects of the activities carried out by the National Supervisory Authority during the first four months of 2026.

Between January and April 2026, the National Supervisory Authority received 5,519 complaints, notifications and personal data breach notifications, which led to the opening of 228 investigations.

Following these investigations, the Authority imposed 25 administrative fines during the first four months of 2026, amounting to a total of 1,187,492 lei (equivalent to 239,000 euros). During the same period, 42 reprimands were issued and 41 corrective measures were ordered.

With regard to complaints’ handling, the National Supervisory Authority received 5,186 complaints during the first four months of the year. 90 investigations were initiated in relation to complaints considered admissible.

During the same period, data controllers submitted 113 personal data breach notifications and 220 notifications concerning possible non-compliance with the GDPR.

Based on these 333 notifications and breach notifications, the Authority initiated 138 investigations.

The complaints, notifications and personal data breach notifications received by the National Supervisory Authority between January and April 2026 primarily concerned the following matters:

  • processing of personal data in breach of the principles and lawfulness requirements laid down in Articles 5 and 6 of the GDPR;
  • processing of personal data through video surveillance systems;
  • processing of biometric data;
  • disclosure of personal data via websites and/or social media platforms;
  • loss of correspondence by courier service providers;
  • infringements of data subjects’ rights, particularly the right of access and the right to erasure;
  • unsolicited commercial communications sent by email, telephone, or other means of communication;
  • processing of personal data in the gambling sector;
  • reporting and processing of personal data within the Romanian Credit Bureau system;
  • the use of cookies;
  • cyberattacks.

At the same time, during the first four months of 2026, the Authority continued to receive a high number of requests for opinions concerning the interpretation and application of the GDPR and other relevant legislation. During this period, the National Supervisory Authority received 358 requests for official opinions from controllers and processors in both the public and private sectors, other entities and individuals.

During the same period, the Authority also issued opinions on 36 draft legislative acts submitted by public institutions, involving the assessment of diverse and complex issues concerning the appropriate application of data protection rules across various sectors.

Furthermore, between January and April 2026, the Authority continued its public awareness activities aimed at informing the general public about the rules governing the processing of personal data.

To mark European Data Protection Day, on 28 January 2026, the Authority organized the Conference entitled: “Specific Features of Investigations into Complaint Handling – Current Developments and the Perspective of the New Regulation on the Handling of Complaints with Cross-Border Impact.” The conference was attended by representatives of national public authorities and institutions, members of the executive and legislative branches, academia, non-governmental organizations, major professional associations and unions, as well as controllers and processors from both the public and private sectors.

The conference topic was chosen in light of the adoption of Regulation (EU) 2025/2518 of the European Parliament and of the Council, establishing additional procedural rules for the enforcement of Regulation (EU) 2016/679.

During the event, the Authority highlighted important aspects of personal data processing for both controllers and processors, with particular emphasis on investigations relating to complaints with cross-border implications.

As part of this initiative, and at the proposal of the National Supervisory Authority, an informational video dedicated to the General Data Protection Regulation was broadcast on the national television channel TVR and displayed throughout the public transport network operated by the Bucharest Public Transport Company (STB).

During the first four months of 2026, the National Supervisory Authority also continued its public information activities by publishing 21 press releases, primarily concerning enforcement actions and sanctions.

Regarding international cooperation, between January and April 2026, the Authority reviewed 16 applications submitted by multinational companies for the approval of Binding Corporate Rules (BCRs).

The Authority also acted, at the request of companies seeking BCR approval, as co-reviewer for 2 sets of Binding Corporate Rules, and participated as a member of the drafting team for 2 opinions of the European Data Protection Board concerning two additional sets of Binding Corporate Rules.

With regard to litigation, during the first four months of 2026, 15 new court actions were brought against the National Supervisory Authority, 8 of which concerned challenges to infringement reports and administrative sanctions issued by the Authority.

Concerning judicial challenges to administrative fines imposed by the National Supervisory Authority since the GDPR became applicable, it is noteworthy that, out of a total of 448 fines imposed on controllers between 2019 and May 2026 under the GDPR, only 135 fines (approximately 30%) have been challenged before the courts.

Of the 96 court proceedings concluded to date, 72 cases were decided in favour of the National Supervisory Authority, either by fully upholding the fines imposed by the Authority or by confirming the legality of the infringement reports while reducing the amount of the fine or replacing it with a warning.

In order to ensure that the public is fully informed and to assist controllers seeking to correctly apply data protection rules, we present below, by way of illustration, excerpts from several significant cases in which the courts confirmed the legality and merits of the infringement reports issued by the National Supervisory Authority, thereby endorsing the Authority's approach in assessing those cases.

  1. Recently, the Timișoara Court of Appeal, by a final and binding judgment, upheld the fines imposed by the National Supervisory Authority on Restart Energy One S.A., amounting to 25,000 euros for infringement of Article 32(1)(b) and (d), read in conjunction with Article 32(2) of Regulation (EU) 2016/679 (GDPR), as well as 40,000 lei for infringement of Article 4(5) of Law No. 506/2004. The Court held that: “The appellant committed the administrative offence provided for in Article 12(1) of Law No. 190/2018, in conjunction with Article 83(4)(a) of the GDPR, the arguments put forward not being capable of proving its lack of liability, the offence being committed through negligence, and the appellant’s assertion that the court of first instance completely disregarded the technical explanations provided is unfounded."

Regarding the proportionality of the EUR 25,000 fine, the Court stated “The appellant argued that the absence of actual damage and the lack of complaints from the persons concerned rendered the infringement insufficiently serious and exempted it from liability. However, the offence attributed to the appellant is one of endangerment rather than one requiring a harmful result. The purpose of the sanction is to reinforce compliance with data protection rules and, consequently, the protection of data subjects. Therefore, it was not necessary to demonstrate actual harm suffered by any individual, and the absence of any socially harmful consequences is irrelevant in this respect.”

Or, having regard to all the circumstances of the case and the amount of the fine imposed, the Court finds that the fine of 124,150 lei (equivalent to 25,000 euros at the National Bank of Romania exchange rate of 11 September 2023) complies with the principle of proportionality and was imposed in accordance with the criteria set out in Article 83(2) of the GDPR. Accordingly, there are no grounds to reduce the fine or replace it with a “reprimand”.

The fine is well below the statutory maximum of 10 million euros, despite the fact that at least 750 data subjects had been affected, since the appellant, as controller, had failed to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risks of processing, resulting in the unauthorised disclosure of and access to personal data over a period of two years and six months, namely 28 April 2020 – 9 November 2022, notwithstanding its obligation under Article 5(1)(f) of the GDPR.

With respect to the second infringement, the Court found that “following inspections carried out on the website https://restartenergy.ro/, it was established that RESTART ENERGY ONE S.A. stored information, namely cookies that were not technically necessary for the functioning of the website, or accessed information stored on users' terminal equipment without obtaining the users' consent (by clicking the 'Accept' button), at least during the period from 17 October 2022 to 9 November 2022. The company failed to comply with the cumulative conditions laid down in Article 4(5)(a) and (b) of Law No. 506/2004, namely obtaining users’ consent for the cookies used on the website and providing prior information regarding the general purposes of processing, the retention period, the categories of information stored and accessed, and whether third parties would be permitted to store or access information on users’ terminal equipment, constituting an administrative offence provided for in Article 13(1)(i) of Law No. 506/2004, as amended.

Regarding the appellant’s request to replace the fine with a reprimand or reduce its amount, the Court held that “This request is unfounded.”

The Court further observed “The appellant argued that all deficiencies identified during the inspection had been remedied immediately and that no harm had been caused to the data subjects, relying on the absence of damage and complaints.”

However, taking into account those circumstances, as well as the seriousness of the infringement and the number of data subjects affected, the Court concluded that “There are no grounds to reduce the fine to the statutory minimum of 5,000 lei or to replace it with a reprimand. The infringements are aggravated by the cumulative nature of the breaches. The legislature intended to sanction the social risk created by such conduct rather than requiring proof of actual damage.”

  1. By a final judgment, the Bucharest Court of Appeal, confirming the judgment of the Bucharest Tribunal (first instance), also upheld the 10,000 euros fine imposed on PPC Energie Muntenia S.A. for infringement of Article 32 of the GDPR.

Thus, the Court held that “The fact that the security incident of 23 November 2020 occurred accidentally as a result of human error, without the appellant demonstrating any exceptional circumstances, confirms the infringement of Article 32 GDPR, given the specific nature of the incident and the fact that insufficient measures had been implemented to eliminate the relevant risk. The appellant itself acknowledges that certain provisions of Article 32 were infringed but merely argues that not the entirety of Article 32 was breached, without substantiating that argument. Consequently, the Court confirms the Tribunal’s conclusion that both the description of the facts and their legal classification were correctly established by the supervisory authority.”

The Court also stated that “The fact that Enel had implemented security measures does not preclude a finding that the infringement occurred, since those measures proved insufficient and inappropriate, allowing the security incident to occur, regardless of the fact that it originated from human operational error. Moreover, the appellant itself acknowledges that the human factor can never be completely eliminated from operational processes, yet it failed to identify appropriate safeguards capable of preventing similar errors in the future. (...) The appellant is fully responsible for the actions of its employees, including situations where they fail to comply with internal procedures, as occurred in the present case. No exceptional circumstances have been demonstrated that would explain the human error leading to the security incident. Rather, it was the type of irregularity that could arise in an indeterminate number of situations.”

With regard to the amount of the fine imposed to the controller for the breach of Article 32 of Regulation (EU) 2016/679, the Court held that the imposition of a fine of EUR 10,000 is proportionate, particularly considering that the statutory maximum is the higher of EUR 10 million or 2% of the undertaking's total worldwide annual turnover. More importantly, Enel had previously been sanctioned for similar infringements with fines of EUR 3,000 and EUR 4,000 which demonstrates repeated infringements of the same GDPR provisions and justifies the imposition of a more severe sanction in response to the controller’s continued non-compliance.”

The Court therefore concluded that “the fine was appropriately individualised, taking into account the infringement established, its circumstances and consequences, as well as the sanctions previously imposed on the appellant for similar infringements, which the appellant unjustifiably disregards.”

With regard to the sanction imposed on the same controller for failing to notify the National Supervisory Authority of the personal data breach, contrary to Article 33 of the GDPR, the Court held that “The arguments concerning the low likelihood that the security incident would give rise to a risk to the rights and freedoms of natural persons cannot be accepted, given that the data disclosed included not only the data subject’s name but also the customer’s identification code; taken together, these data were capable of providing access to the customer’s account and, consequently, enabling unauthorised access to invoices and the personal data contained therein, the misuse of which could give rise to adverse consequences.”

The Court further held that “The appellant’s reliance on the exception to the obligation to notify, applicable where the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons, is unfounded, Enel’s assessment of the likelihood of risk being incorrect, as it failed to take into account the full scope of the personal data disclosed, as well as both the actual and the potential impact on the data subject arising from their unlawful processing.”

  1. By a final judgment, the Iași Court of Appeal upheld the 10,000 euros fine imposed by the National Supervisory Authority on Body Line S.R.L. for infringements of Articles 5, 6, 9, 17 and Article 32(2) of Regulation (EU) 2016/679.

Thus, with regard to the first fine of 5,000 euros for the infringement of Articles 5, 6 and 9 of the GDPR, the Court heldThe Authority correctly found, in the contested infringement minutes, that the appellant had infringed Articles 5, 6 and 9 of Regulation (EU) 2016/679, since a video recording depicting the complainant (...) was published on the appellant’s Facebook page without his consent, the publication being accompanied by comments referring to the individual’s ethnic origin (...). The Court of Appeal emphasises that Article 9(1) of the GDPR expressly prohibits the processing of personal data revealing racial or ethnic origin, publishing a video together with comments indicating that one of the persons filmed was of Arab origin is clearly capable of infringing those provisions.”

The appellant’s arguments that the respondent issued the infringement minutes without any supporting evidence, relying exclusively on the complainant’s allegations, are unfounded.

As is apparent from the infringement report, after examining the complaint submitted to it, the Authority verified the content published on the appellant's Facebook page and established that both on 9 February 2023 and later, on the date when the infringement report was issued (28 July 2023), the video recording showing the complainant from both the front and the rear, without any facial blurring, remained publicly available, accompanied by comments referring to his ethnic origin. Furthermore, the existence of that recording on the Facebook page during the Authority’s investigation was expressly acknowledged by the company’s administrator, who confirmed both that the recording remained available and that it had not been deleted by the date on which the company submitted its written response.

With regard to the 4,000 euros fine imposed for infringement of Article 17 GDPR, the Court found that “The documents contained in the case file demonstrate that, prior to submitting his complaint to ANSPDCP, (...) requested that the appellant to remove the recording from its Facebook page, a request which the appellant failed to comply with (...).

By refusing to comply with that request, the appellant infringed Article 17(d) of Regulation (EU) 2016/679.”

Regarding the 1,000 euros fine imposed for infringement of Article 32(2) of the GDPR, the Court held that “As controller, the claimant failed to provide evidence that it had implemented adequate technical and organisational measures to ensure the confidentiality of the personal data processed through the audio-video surveillance system installed in its fitness centres; as a result, the recording made on 19 November 2022 was accessed and disseminated on the operator’s Facebook pages, in breach of Article 32(1) and (2) of Regulation (EU) 2016/679.”

With regard to the determination of the amount of the sanction, the Court of Appeal held that: “The appellant was imposed a total fine of EUR 10,000. Pursuant to Article 83(5) of the GDPR, the fine for each of the three infringements established against the appellant could have been up to 4% of the undertaking’s total worldwide annual turnover for the preceding financial year, whichever amount was higher. Since the appellant’s annual turnover, as recorded in the infringement report, amounted to 3,671,268 lei (page 10 of the infringement minutes), the maximum fine that could have been imposed was 146,850.72 lei. The total fine imposed on the appellant was therefore well below the maximum provided for by the GDPR and was fully justified in light of the seriousness of the infringements established, taking into account the appellant’s conduct."

  1. The Cluj Court of Appeal, by a final judgment, upheld the 100,000 euros fine imposed by the National Supervisory Authority on Banca Transilvania S.A. for infringement of Article 32(1) and (2), read in conjunction with Article 5(1)(f) General Data Protection Regulation.

The same conclusion had previously been reached by the Cluj Tribunal in Civil Judgment no. 1309 of 6 May 2021, which was upheld in its entirety on appeal.

In reaching its decision, the Court of Appeal held:

As regards the appellant’s argument that the activities listed in Article 39 of the Regulation do not amount to an “express” obligation to provide training, it is clear from Article 39 that the appellant, acting through its designated representatives, is under an obligation to ensure the training and education of its personnel in the field of personal data protection (...).

These legal provisions clearly establish the appellant’s obligation to train, educate and inform its employees regarding data protection. It is equally evident that the appellant was required to take measures to ensure compliance with the Regulation, which necessarily includes verifying (or 'testing') whether employees had correctly understood the information provided during training sessions. This follows from Article 39(b) of the Regulation, which requires the monitoring of compliance with the Regulation and with other Union and national data protection rules (…). Likewise, Article 32(1)(d) of the Regulation establishes a specific obligation to conduct testing, which is incumbent upon the appellant.”

The Court further observed that “the organisational measures referred to in Article 32(1)(d) of the Regulation clearly include staff information and training measures.

It is true that the GDPR allows the appellant to exercise its organisational discretion in determining the manner in which training and/or testing should be carried out. Such a legislative approach is justified, given that entities subject to obligations under the GDPR differ significantly in their organisational structures and operations, which cannot be accommodated within a uniform regulatory model. What is essential is that, while benefiting from this discretion, those subject to the Regulation demonstrate that they have implemented effective measures. Where such evidence is provided, liability cannot be attributed to them.”

However, the appellant failed to implement effective measures in this regard. The manner in which the infringement was committed demonstrated a lack of knowledge of the procedures governing the processing of personal data, the employees’ inability to identify and recognise the data to which they had access as personal data, and, according to the evidence, the employee who disclosed the data externally had received no effective training in the field of personal data protection. As regards the other three employees, no evidence was produced as to how any deficiencies in their understanding of the applicable procedures had been identified, assessed, and remedied to ensure that those procedures were properly and fully understood.

Furthermore, the appropriate technical and organisational measures required under the Regulation extend beyond merely providing training through an online course followed by a ten-question test in order for the training to be regarded as completed.”

The Cluj Court of Appeal also correctly found that “The disclosure of the personal data was intentional, as correctly established by the court of first instance, since the customer’s message, which the employees apparently found amusing, was forwarded successively not through negligence but deliberately. (...)

The speed with which the messages were forwarded and the allegedly humorous nature of the customer’s message cannot mitigate the appellant’s liability or justify the employees’ conduct. It is evident that an ordinary message, no different from the dozens of messages processed daily by employees, would not have prompted them to take photographs and distribute them.

Indeed, this is precisely the type of situation in which effective training, verification of employees’ understanding of data protection rules, the implementation of other appropriate measures, and monitoring of compliance would have proved useful.

The Court of Appeal further held that “The fact that the appellant is unable to control the number of persons who may gain access to the customer's personal data via the internet is obvious and does not constitute a mitigating circumstance but, on the contrary, it demonstrates a lack of diligence in implementing appropriate training, organisational measures, testing, and monitoring, precisely because it is well known that information published online cannot be controlled in terms of its further dissemination and remains widely accessible, the appellant should have appreciated the need to implement effective safeguards to prevent personal data from entering the online environment.

The content of the customer’s message, which prompted the employees to breach the applicable data protection rules, and the fact that the message became widely circulated because of its content, which did not originate from the bank, do not diminish the appellant’s liability. As already explained, it is entirely foreseeable for an employer that employees would not ordinarily be tempted to circulate routine customer messages. It is precisely in cases involving unusual or amusing messages, such as the one at issue, that training, organisational safeguards, testing, and monitoring become particularly necessary.”

With regard to the criteria applied in determining the amount of the administrative fine, the Cluj Court of Appeal held that “The seriousness of the infringement is further demonstrated by the manner in which the personal data were disseminated, through the internet, the email containing the customer’s personal data circulated extensively in the public domain, with summaries of the information being reproduced by blogs, television channels, and news websites, the extremely large number of individuals gaining access to the customer’s personal data for an indeterminate period of time through a wide variety of communication channels.

As regards the appellant’s alleged “inability to control” the dissemination of personal data over the internet, the Court has already observed that precisely this reality, well known to any professional data controller, should have prompted greater diligence in adopting measures aimed at preventing breaches of personal data protection rules.

From this perspective, the appellant’s arguments concerning the alleged impracticability of additional measures, or the recognition of such circumstances, are irrelevant for the purpose of mitigating liability and were rightly not regarded as decisive by the court of first instance.

What is relevant is the manner in which the appellant acted in the circumstances of the present case. In this respect, both this Court and the court of first instance concluded that the training, testing, and monitoring measures implemented by the appellant were clearly inadequate. (...)

With regard to the criterion laid down in Article 83(2)(k) of the Regulation, this also correctly supported the imposition of a fine of 100,000 euros. As to the appellant’s argument that it derived no financial benefit from the infringement, the absence of financial gain is itself a factor demonstrating the proper proportionality of the fine. The imposition of an administrative fine does not require proof that the controller obtained any financial advantage from the infringement. Taking into account the trust placed by customers in the bank, as a professional institution, to ensure that their personal data would not be unlawfully disclosed, the bank’s obligations as a data controller, the technical resources available to it for safeguarding personal data, the criteria referred to above, the statutory maximum fine, and the factors listed in Article 83(2) GDPR, the fine of 100,000 euros was correctly determined, being necessary, in accordance with Article 83(1) GDPR, for the fine to be not only proportionate but also effective and dissuasive.

  1. By a final judgment, the Bucharest Court of Appeal, like the court of first instance (the Bucharest Tribunal), upheld the 20,000 euros administrative fine imposed on Vreau Credit S.R.L. for infringements of Article 32(4), read in conjunction with Article 32(1) and (2), and Article 33(1) of the GDPR.

Thus, addressing the appellant’s arguments concerning the lawfulness of the infringement report, the Court held that “In imposing the sanction, the supervisory authority took into account all the criteria set out in Article 83 [GDPR], together with additional relevant factors, all of which were sufficient to enable the courts to carry out a subsequent review of the lawfulness of the decision.”

Regarding the amount of the fine imposed for the infringement of Article 32(1), (2), and (4) of Regulation (EU) 2016/679, the Bucharest Court of Appeal found that “The appellant’s arguments that it had implemented appropriate measures to ensure compliance with the Regulation were correctly rejected by the court of first instance, as they were contradicted by the facts established during the investigation. Those facts demonstrated the unauthorised disclosure of personal data relating to an exceptionally large number of customers - 1,177 natural persons - through the transmission of photocopies of their identity documents to unauthorised persons (employees of another data controller, Raiffeisen Bank), who in turn disclosed those data to a third party (Biroul de Credit S.A.).

The large number of affected individuals demonstrates that this method of processing constituted, in reality, a routine practice of the controller. Although written procedures formally existed, the controller failed to ensure their effective implementation.”

The Bucharest Court of Appeal further held “In the present case, no evidence was produced demonstrating the implementation of the 'appropriate technical and organisational measures’ required to ensure a level of security appropriate to the risk, nor was there any evidence that employees had received training aimed at preventing the type of infringement that occurred. The supervisory authority correctly observed that the appellant’s obligation extended beyond merely drafting written procedures. It was also required to establish binding rules for all employees concerning the security of processing operations and the confidentiality of personal data. In the absence of such measures, and in the absence of evidence of effective and adequate staff training, the mere existence of written procedures remained ineffective and, as established, resulted in serious consequences for the privacy and private life of its customers.

With regard to the sanction imposed on the same controller for failing to notify the National Supervisory Authority of the personal data breach, the Bucharest Court of Appeal correctly held that “Since the appellant failed to demonstrate that it had notified the supervisory authority within the time limit prescribed by the Regulation, it was correctly found to have breached its statutory obligations, and the imposition of sanctions was therefore justified."

The Court dismisses the appellant’s submissions [Vreau Credit SRL] concerning the existence of customer consent to the processing of their personal data, which allegedly justified its conclusion that notification was unnecessary.

The Court finds that the annexes submitted by the appellant [Vreau Credit SRL] in the proceedings before the court of first instance (...) do not demonstrate that its customers gave their unequivocal consent to the disclosure of their personal data or to their processing by a third party, still less to the use of those data by a third party to conduct searches in the Credit Bureau’s database outside the scope of the contractual relationship.

It was correctly observed, following an examination of the documents submitted by the appellant, that its customers had not been properly informed about the processing operations, nor had they been asked to provide their express and unambiguous consent. Consequently, they were not given any opportunity to express their freely given, specific and informed consent, as required by Article 7(1), read in conjunction with Article 4(11) of the GDPR.”

  1. By judgment of the Bucharest Tribunal, the 7,000 euros fine imposed by the National Supervisory Authority on CDI Transport Intern și International S.R.L. was upheld. In addressing the arguments challenging the lawfulness of the infringement report, the court held that it “complies with the requirements of Articles 16 and 17 of Government Ordinance No. 2/2001, containing sufficient particulars to enable the claimant to know precisely the allegations against it and to present its defence before the court.

The Tribunal further found that “The claimant was correctly sanctioned for the infringements described in the infringement minutes, having failed to produce evidence demonstrating that the processing operations were carried out in compliance with the applicable legal provisions.

The findings of fact established during the inspection are, in essence, not disputed, the claimant merely arguing that the fine imposed in respect of the first infringement is excessive and that the infringement report does not contain a sufficiently specific description of the second infringement.”

The Bucharest Tribunal also found that “The claimant neither argued nor proved, in relation to the second infringement, that it had provided the data subjects whose personal data it processes with all the information required under Articles 12 to 22 of the GDPR, in accordance with Article 12 thereof, o documentary evidence being submitted to demonstrate that such information had been provided to the data subjects. Accordingly, the reprimand imposed in respect of the second infringement was correctly applied.”

Regarding the amount of the fine imposed for infringement of Article 58(1)(a) and (e) and Article 12(1) of Regulation (EU) 2016/679, the Tribunal held that “The fine imposed for the first infringement, equivalent to 7,000 euros, fulfils both the preventive and punitive purposes of administrative sanctions and reflects the specific circumstances in which the infringement was committed, in compliance with Article 21(3) of Government Ordinance no. 2/2001.”

On appeal, the Bucharest Court of Appeal partially upheld the controller’s appeal and reduced the fine, holding that “The imposition of a fine of 2,000 euros on the appellant for infringement of Article 58(1)(a) and (e) of the Regulation is proportionate to the relatively low degree of social harm associated with the administrative offence, taking into account all the circumstances in which it was committed.”

The Court further observed that “This reduced level of the administrative fine is sufficient to achieve the punitive and preventive objectives of the applicable legal provisions, so as to discourage the appellant from committing similar infringements in the future. Should such infringements recur, substantially more severe sanctions would be warranted.”

 

Legal and Communication Department

A.N.S.P.D.C.P.