Romania Romania

Națională Poșta Română

5,000 €

GDPR enforcement action by Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) on 2026-06-12.

Rank · Sector
#136
of 168 in Transportation and Energy
Rank · Romania
#95
of 284
Rank · All fines
#1,851
of 3,051

Case details

Authority
Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
Date
2026-06-12
Controller / Processor
Națională Poșta Română
Sector
Transportation and Energy
Quoted Articles
Art. 32 (1) b), (2), (4) GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Roman DPA has imposed a fine of EUR 5,000 on the Națională Poșta Română. The controller suffered a data breach which resulted in postal items beeing destroyed, which caried personal data. The data breach resulted due to the fact, that the controller failed to ensure that its employees only processed the data they had to process in the context of their tasks.

Open original source Links to the regulator's original publication or another source.

Related fines