Romania Romania

FAN Courier Express SRL

11,000 €

GDPR enforcement action by Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) on 2019-11-25.

Rank · Sector
#208
of 597 in Industry and Commerce
Rank · Romania
#36
of 283
Rank · All fines
#1,310
of 3,050

Case details

Authority
Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
Date
2019-11-25
Controller / Processor
FAN Courier Express SRL
Sector
Industry and Commerce
Quoted Articles
Art. 32 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The fine was imposed because the controller failed to take appropriate technical and organisational measures leading to the loss and unauthorised access to personal data (name, bank card number, CVV code, cardholder's address, personal identification number, serial and identity card number, bank account number, authorised credit limit) of approximately 1,100 data subjects.

Open original source Links to the regulator's original publication or another source.

Related fines