Romania Romania

HOMELUX S.R.L

15,000 €

GDPR enforcement action by Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) on 2026-07-31.

Rank · Sector
#200
of 608 in Industry and Commerce
Rank · Romania
#35
of 292
Rank · All fines
#1,242
of 3,085

Case details

Authority
Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
Date
2026-07-31
Controller / Processor
HOMELUX S.R.L
Sector
Industry and Commerce
Quoted Articles
Art. 32 (1) d), (2) GDPR
Type of violation
Non-compliance with general data processing principles

Summary

The Romanian DPA has imposed a fine of EUR 15,000 on HOMELUX S.R.L. The controller notified the authority about a security breach. In the subsequent investigation investigators found that the controller had used low-complexity passwords that were not changed after the incident. Furthermore investigators found that the controller had processed data subjects' personal data via non-technically necessary cookies without their consent.

Open original source Links to the regulator's original publication or another source.

Related fines