Romania Romania

VESTA CEU ROMÂNIA SRL.

3,000 €

GDPR enforcement action by Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) on 2024-02-26.

Rank · Sector
#144
of 167 in Transportation and Energy
Rank · Romania
#136
of 283
Rank · All fines
#2,109
of 3,050

Case details

Authority
Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
Date
2024-02-26
Controller / Processor
VESTA CEU ROMÂNIA SRL.
Sector
Transportation and Energy
Quoted Articles
Art. 32 (1) b) GDPR, Art. 32 (2), (4) GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Romanian DPA has imposed a fine of EUR 3,000 on VESTA CEU ROMÂNIA SRL. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR.
The controller had disclosed personal data such as name, place of residence, salary, CV and copies of passports to employees without authorization, who then accessed the data internally and illegally passed it on to third parties. According to the DPA, the controller had failed to implement adequate technical and organizational measures to protect personal data, which allowed such an incident to occur.

Open original source Links to the regulator's original publication or another source.

Related fines