Romania Romania

Romanian Post National Company

2,000 €

GDPR enforcement action by Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) on 2020-07-30.

Rank · Sector
#158
of 176 in Transportation and Energy
Rank · Romania
#174
of 292
Rank · All fines
#2,298
of 3,132

Case details

Authority
Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
Date
2020-07-30
Controller / Processor
Romanian Post National Company
Sector
Transportation and Energy
Quoted Articles
Art. 32 GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

Processing of personal data, namely the telephone numbers and e-mail addresses of 81 data subjects, by the Romanian Post as data controller, failing appropriate technical and organisational measures, such as pseudonymisation.

Open original source Links to the regulator's original publication or another source.

Related fines