Romania Romania

GENPACT ROMANIA SRL

10,000 €

GDPR enforcement action by Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) on 2026-02-04.

Rank · Sector
#214
of 332 in Finance, Insurance and Consulting
Rank · Romania
#54
of 292
Rank · All fines
#1,488
of 3,132

Case details

Authority
Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
Date
2026-02-04
Controller / Processor
GENPACT ROMANIA SRL
Sector
Finance, Insurance and Consulting
Quoted Articles
Art. 32 (1) b), (2) GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Romanian DPA has imposed a fine of EUR 10,000 on GENPACT ROMANIA SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures. The attacker was able to exploit vulnerabilities in some passwords and in the way user accounts' authentication could be reset.

Open original source Links to the regulator's original publication or another source.

Related fines