HOMELUX S.R.L
15,000 €
GDPR enforcement action by Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) on 2026-07-31.
Rank · Sector
#200
of 608 in Industry and Commerce
Rank · Romania
#35
of 292
Rank · All fines
#1,242
of 3,085
Case details
- Authority
- Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
- Date
- 2026-07-31
- Controller / Processor
- HOMELUX S.R.L
- Sector
- Industry and Commerce
- Quoted Articles
- Art. 32 (1) d), (2) GDPR
- Type of violation
- Non-compliance with general data processing principles
Summary
The Romanian DPA has imposed a fine of EUR 15,000 on HOMELUX S.R.L. The controller notified the authority about a security breach. In the subsequent investigation investigators found that the controller had used low-complexity passwords that were not changed after the incident. Furthermore investigators found that the controller had processed data subjects' personal data via non-technically necessary cookies without their consent.
Open original source
Links to the regulator's original publication or another source.
Related fines
Romania
2019-06-27
130,000 €
ETid-57
UNICREDIT BANK SA
Finance, Insurance and Consulting
Romania
2026-03-25
125,000 €
ETid-3071
RENAULT COMMERCIAL ROUMANIE S.R.L.
Industry and Commerce
Romania
2023-11-13
110,000 €
ETid-2112
Rompetrol Downstream SRL
Transportation and Energy
Romania
2020-12-17
100,000 €
ETid-489
Banca Transilvania SA
Finance, Insurance and Consulting
Romania
2026-07-17
100,000 €
ETid-3223
Orange Romania SA
Media, Telecoms and Broadcasting
Romania
2023-08-21
70,000 €
ETid-2013
Uipath SRL
Industry and Commerce