Back to Feed
PolicyAug 14, 2026

ANSPDCP (Romania) - AMATO BESTSELLER S.R.L.

Romania's ANSPDCP fines AMATO BESTSELLER S.R.L. for GDPR and ePrivacy violations.

Summary

The Romanian data protection authority (ANSPDCP) has fined AMATO BESTSELLER S.R.L. a total of 285,395 RON (approximately €54,300) for multiple violations of GDPR and the ePrivacy Directive. The company failed to implement adequate security measures, allowing unauthorized access to sensitive personal data by current and former employees. Additionally, they engaged in excessive data processing, failed to provide accurate information to data subjects, and sent commercial communications without prior consent.

Full text

Help ANSPDCP (Romania) - AMATO BESTSELLER S.R.L.: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 13:55, 14 August 2026 view source Lh (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators2 edits Tag: Decisions [1.0] (No difference) Latest revision as of 13:55, 14 August 2026 ANSPDCP - AMATO BESTSELLER S.R.L. Authority: ANSPDCP (Romania) Jurisdiction: Romania Relevant Law: Article 5(1)(c) GDPR Article 9 GDPR Article 32(4) GDPR Article 12 GDPR Article 14 GDPR Article 12(1) Law 506/2004 Type: Complaint Outcome: Upheld Started: Decided: Published: Fine: 285395.0 RON Parties: n/a National Case Number/Name: AMATO BESTSELLER S.R.L. European Case Law Identifier: n/a Appeal: n/a Original Language(s): Romanian Original Source: Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (in RO) Initial Contributor: n/a The DPA imposed a 54,300 fine to a controller for violations of Article 32(4), Article 14 and Article 5(1)(c) in conjunction with Article 9 GDPR and ePrivacy Directive. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A general wholesale/retail trade company (controller) failed to implement adequate technical and organisational measures, such as appropriate training of its employees, in order to secure personal data from unauthorized access. Subsequently, for a specific period of time, former and current employees were able to access personal data (first name, last name, phone number, the relationship between one data subject and another, occupation, marital status, a person’s classification within a specific social category, city of domicile/residence, income data, family data, and health data/special categories of personal data) of a considerable amount of data subjects. The controller did not provide accurate and complete information to the data subjects and engaged in excessive data processing. Additionally, the controller sent commercial communications using automated dialing and communication systems that do not require human intervention, by dialing the telephone number and conducting conversations with a significant number of data subjects, without the data subjects having given their prior express consent to receive such communications. Holding The DPA held that the data controller violated Article 32(4) GDPR by failing to prevent unauthorized access of personal data to current and former employees of the data controller. The data controller violated Article 14 GDPR by failing to provide accurate and complete information to the data subjects. The excessive data processing (including special categories of data and health data), without ensuring that such processing was adequate, relevant, and limited to what is necessary in relation to the purposes for which the data were processed amounted to a violation of the data minimisation principle under Article 5(1)(c) in conjunction with Article 9 GDPR. Additionally, the DPA held that commercial communications using automated dialing and communication systems that do not require human intervention by dialing the telephone number and conducting conversations with a significant number of data subjects, without the data subjects having given their prior express consent to receive such communications, constitutes a violation of Article 12(1) of Law 506/2004, the Romanian law implementing the ePrivacy Directive. The DPA imposed on the controller to include in all applicable work procedures/policies clear instructions regarding the flow of personal data within the controller’s organisation and the flow of documents containing personal data, specify differentiated employee access to certain activities involving personal data, as well as provide periodic training to employees and other natural or legal persons who process personal data. Moreover, the DPA imposed fines totalling Romania RON 285,395 (€54,300). Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Romanian original. Please refer to the Romanian original for more details. August 6, 2026 Penalty for Violating the GDPR and Law No. 506/2004 In June 2026, the National Supervisory Authority for Personal Data Processing concluded an investigation into the data controller AMATO BESTSELLER S.R.L. and found a violation of the provisions of Art. 32, para. (4), Article 14, and Article 5(1)(c) in conjunction with Article 9 of Regulation (EU) 2016/679, as well as a violation of the provisions of Article 12( (1) of Law No. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector. Accordingly, the data controller was sanctioned with: - a fine of 78,465 lei, equivalent to 15,000 euros, for violating the provisions of Article 32(4) of Regulation (EU) 2016/679; - a fine of 52,310 lei, equivalent to 10,000 euros, for violating the provisions of Article 14 of Regulation (EU) 2016/679; - a fine of 104,620 lei, equivalent to 20,000 euros, for violating the provisions of Article 5(1)(c) in conjunction with Article 9 of Regulation (EU) 2016/679; (1)(c) in conjunction with Article 9 of Regulation (EU) 2016/679; - a fine of 50,000 lei for violating the provisions of Article 12(1) of Law 506/2004. The investigation was launched following complaints submitted by several data subjects, who reported possible violations of Regulation (EU) 2016/679. The investigation found that the controller violated the provisions of Article 32(4) (4) of the GDPR, as it failed to take measures to ensure that any natural person acting under its authority and having access to personal data processes such data only at its request. Consequently, the controller failed to train its own employees and failed to inform them of work procedures and policies for processing the personal data of data subjects in a manner that ensures their adequate security, protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, by taking appropriate technical or organizational measures. This deficiency allowed, for a certain period of time, current and former employees of the controller to have unauthorized access to personal data (first name, last name, phone number, the relationship between one data subject and another, occupation, marital status, a person’s classification within a specific social category, city of domicile/residence, income data, family data, and health data/special categories of personal data) belonging to a considerable number of data subjects. At the same time, it was found that the controller violated the provisions of Article 14 of the GDPR because it failed to provide accurate and complete information to the data subjects, in accordance with the provisions of the GDPR. Furthermore, the investigation revealed that the controller engaged in excessive data processing (including special categories of data and health data) without ensuring that such processing was appropriate, relevant, and limited to what is necessary, in relation to the purposes for which it was processed, in violation of the “data minimization” principle set forth in Article 5(1)(c) in conjunction with Article 9 of the GDPR. During the investigation, it was also found that the controller sent commercial communications using automated calling and communication systems that do not require human intervention, by dialing telephone numbers and conducting conversations with a significant number of data subjects, without the data subjects having previously given their express consent to receive such communications, in violation of the provisions of Article 12(1) of Law 506/2004. At the same time, the National Supervisory Authority also imposed the following corrective measures, orderi

Entities

AMATO BESTSELLER S.R.L. (vendor)ePrivacy Directive (product)