Orange Romania SA
GDPR enforcement action by Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) on 2026-07-17.
Case details
- Authority
- Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
- Date
- 2026-07-17
- Controller / Processor
- Orange Romania SA
- Sector
- Media, Telecoms and Broadcasting
- Quoted Articles
- Art. 25 (1) GDPR, Art. 32 (1) b), d), (2), (4) GDPR
- Type of violation
- Insufficient technical and organisational measures to ensure information security
Summary
The Romanian DPA has imposed a fine of EUR 100,000 on Orange Romania SA. The controller reported that due to a synchronisation error between two of the controller's applications, users were able to access and download invoices, thereby gaining access to the personal data of data subjects, including their surnames, first names, home addresses, delivery addresses, ID card numbers and invoice numbers. The controller failed to implement adequate measures to ensure the security and integrity of personal data; furthermore no cybersecurity incident tests were run. Consequently malicious parties accessed large amounts of personal data.