Romania Romania

Private Individual

200 €

GDPR enforcement action by Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) on 2021-07-30.

Rank · Sector
#332
of 351 in Individuals and Private Associations
Rank · Romania
#281
of 285
Rank · All fines
#3,017
of 3,059

Case details

Authority
Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
Date
2021-07-30
Controller / Processor
Private Individual
Sector
Individuals and Private Associations
Quoted Articles
Art. 5 (1) a), b), (2) GDPR, Art. 6 (1) GDPR, Art. 14 (1), (4) GDPR
Type of violation
Insufficient legal basis for data processing

Summary

The Romanian DPA (ANSPDCP) has imposed a fine of EUR 200 on a private individual due to the unlawful disclosure of personal data. The controller had disclosed personal data of several individuals by distributing some materials in households of the municipality and through posts on his personal Facebook account. This involved, on the one hand, a photo of a salary statement of the data subject, whereby, among other things, the surname, first name, place of work and salary could be extracted. The other was a photo of a file from the register of children enrolled in the kindergarten of the municipality, whereby personal data of a minor child were disclosed.
The DPA found that the controller had processed the data without a legal basis and had not informed the data subjects about the processing of their data.

Open original source Links to the regulator's original publication or another source.

Related fines