Romania Romania

Orange Romania SA

100,000 €

GDPR enforcement action by Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) on 2026-07-17.

Rank · Sector
#113
of 371 in Media, Telecoms and Broadcasting
Rank · Romania
#5
of 292
Rank · All fines
#502
of 3,085

Case details

Authority
Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
Date
2026-07-17
Controller / Processor
Orange Romania SA
Sector
Media, Telecoms and Broadcasting
Quoted Articles
Art. 25 (1) GDPR, Art. 32 (1) b), d), (2), (4) GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Romanian DPA has imposed a fine of EUR 100,000 on Orange Romania SA. The controller reported that due to a synchronisation error between two of the controller's applications, users were able to access and download invoices, thereby gaining access to the personal data of data subjects, including their surnames, first names, home addresses, delivery addresses, ID card numbers and invoice numbers. The controller failed to implement adequate measures to ensure the security and integrity of personal data; furthermore no cybersecurity incident tests were run. Consequently malicious parties accessed large amounts of personal data.

Open original source Links to the regulator's original publication or another source.

Related fines