Home » Comunicat_Presa_28_04_2026
 Română | English | Francais

28.04.2026

Fine for GDPR Infringement

 

The National Supervisory Authority for Personal Data Processing completed an investigation in March 2026 into the data controller CROWD ENTERTAINMENT LIMITED and found infringements of Article 5(1)(a), (d) and Article 5(2), as well as Article 5(1)(a), (c) and Article 5(2) of Regulation (EU) 2016/679.

Accordingly, the controller was sanctioned with:

  • A fine of 101,904 lei (equivalent to 20,000 euros) for infringing Article 5(1)(a), (d) and Article 5(2) of Regulation (EU) 2016/679.
  • A fine of 76,428 lei (equivalent to 15,000 euros) for infringing Article 5(1)(a), (c) and Article 5(2) of Regulation (EU) 2016/679.

The investigation was initiated following a complaint from a data subject who alleged that they had received a marketing SMS from Crowd Entertainment Ltd. (the owner of several online gambling platforms) without having provided consent for the use of their personal data for marketing purposes.

During the investigation, it was established that the controller had collected the complainant’s telephone number when another individual created an online gaming account on one of the controller’s platforms. The controller failed to verify the accuracy of the personal data provided, thereby infringing Article 5(1)(a), (d) and Article 5(2) of Regulation (EU) 2016/679.

The investigation further found that the controller had unlawfully and excessively collected and stored documents containing the complainant’s personal data, including a copy of the complainant’s identity document and a selfie photograph. These documents were requested in the context of handling the complainant’s request to identify the source from which their telephone number had been obtained and to provide evidence of the consent allegedly relied upon for marketing purposes.

As a result, the controller was also fined for breaching Article 5(1)(a), (c) and Article 5(2) of Regulation (EU) 2016/679.

In addition, the supervisory authority imposed the following corrective measures on the controller:

  • To ensure that its personal data processing operations comply with Regulation (EU) 2016/679 by adopting the necessary technical and organizational measures, in accordance with Articles 24 and 25 of the Regulation, to ensure compliance with the data processing principles set out in Article 5. These measures must ensure the collection and subsequent processing of accurate personal data relating to individuals who wish to register an account on the controller's online gambling platforms.
  • To ensure compliance with Regulation (EU) 2016/679 by adopting the necessary technical and organizational measures, including appropriate staff training, in accordance with Articles 24 and 25 of the Regulation, to ensure compliance with the data processing principles laid down in Article 5. These measures must ensure that only personal data necessary for the specified processing purposes are collected and processed, and that the excessive collection and storage of personal data or documents containing personal data are avoided.

 

Legal and Communication Department

A.N.S.P.D.C.P.