[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDfpolRhGfS7yot6k6LbT7J_Wjo4C-xRHJ3GQDKnQAV8":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"92430de2-2e4c-4710-a913-599d4fc3976d","ANSPDCP (Romania) - AMATO BESTSELLER S.R.L.","anspdcp-romania-amato-bestseller-s-r-l-7b4099","Created page with \"{{DPAdecisionBOX |Jurisdiction=Romania |DPA-BG-Color= |DPAlogo=LogoRO.jpg |DPA_Abbrevation=ANSPDCP |DPA_With_Country=ANSPDCP (Romania) |Case_Number_Name=AMATO BESTSELLER S.R.L. |ECLI= |Original_Source_Name_1=Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal |Original_Source_Link_1=https:\u002F\u002Fwww.dataprotection.ro\u002F?page=Comunicat_Presa_06.08.2026&lang=ro |Original_Source_Language_1=Romanian |Original_Source_Language__Code_1=RO |Origina...\" New page {{DPAdecisionBOX |Jurisdiction=Romania |DPA-BG-Color= |DPAlogo=LogoRO.jpg |DPA_Abbrevation=ANSPDCP |DPA_With_Country=ANSPDCP (Romania) |Case_Number_Name=AMATO BESTSELLER S.R.L. |ECLI= |Original_Source_Name_1=Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal |Original_Source_Link_1=https:\u002F\u002Fwww.dataprotection.ro\u002F?page=Comunicat_Presa_06.08.2026&lang=ro |Original_Source_Language_1=Romanian |Original_Source_Language__Code_1=RO |Original_Source_Name_2= |Original_Source_Link_2= |Original_Source_Language_2= |Original_Source_Language__Code_2= |Type=Complaint |Outcome=Upheld |Date_Started= |Date_Decided= |Date_Published= |Year= |Fine=285395.0 |Currency=RON |GDPR_Article_1=Article 5(1)(c) GDPR |GDPR_Article_Link_1=Article 5 GDPR#1c |GDPR_Article_2=Article 9 GDPR |GDPR_Article_Link_2=Article 9 GDPR |GDPR_Article_3=Article 32(4) GDPR |GDPR_Article_Link_3=Article 32 GDPR#4 |GDPR_Article_4=Article 12 GDPR |GDPR_Article_Link_4=Article 12 GDPR |GDPR_Article_5=Article 14 GDPR |GDPR_Article_Link_5=Article 14 GDPR |GDPR_Article_6= |GDPR_Article_Link_6= |GDPR_Article_7= |GDPR_Article_Link_7= |EU_Law_Name_1= |EU_Law_Link_1= |EU_Law_Name_2= |EU_Law_Link_2= |National_Law_Name_1=Article 12(1) Law 506\u002F2004 |National_Law_Link_1= |National_Law_Name_2= |National_Law_Link_2= |National_Law_Name_3= |National_Law_Link_3= |Party_Name_1= |Party_Link_1= |Party_Name_2= |Party_Link_2= |Appeal_To_Body= |Appeal_To_Case_Number_Name= |Appeal_To_Status= |Appeal_To_Link= |Initial_Contributor= | }} The DPA imposed a 54,300 fine to a controller for violations of Article 32(4), Article 14 and Article 5(1)(c) in conjunction with [[Article 9 GDPR|Article 9 GDPR]] and ePrivacy Directive. == English Summary == === Facts === A general wholesale\u002Fretail trade company (controller) failed to implement adequate technical and organisational measures, such as appropriate training of its employees, in order to secure personal data from unauthorized access. Subsequently, for a specific period of time, former and current employees were able to access personal data (first name, last name, phone number, the relationship between one data subject and another, occupation, marital status, a person’s classification within a specific social category, city of domicile\u002Fresidence, income data, family data, and health data\u002Fspecial categories of personal data) of a considerable amount of data subjects. The controller did not provide accurate and complete information to the data subjects and engaged in excessive data processing. Additionally, the controller sent commercial communications using automated dialing and communication systems that do not require human intervention, by dialing the telephone number and conducting conversations with a significant number of data subjects, without the data subjects having given their prior express consent to receive such communications. === Holding === The DPA held that the data controller violated [[Article 32 GDPR|Article 32(4) GDPR]] by failing to prevent unauthorized access of personal data to current and former employees of the data controller. The data controller violated [[Article 14 GDPR|Article 14 GDPR]] by failing to provide accurate and complete information to the data subjects. The excessive data processing (including special categories of data and health data), without ensuring that such processing was adequate, relevant, and limited to what is necessary in relation to the purposes for which the data were processed amounted to a violation of the data minimisation principle under Article 5(1)(c) in conjunction with [[Article 9 GDPR|Article 9 GDPR]]. Additionally, the DPA held that commercial communications using automated dialing and communication systems that do not require human intervention by dialing the telephone number and conducting conversations with a significant number of data subjects, without the data subjects having given their prior express consent to receive such communications, constitutes a violation of Article 12(1) of Law 506\u002F2004, the Romanian law implementing the ePrivacy Directive. The DPA imposed on the controller to include in all applicable work procedures\u002Fpolicies clear instructions regarding the flow of personal data within the controller’s organisation and the flow of documents containing personal data, specify differentiated employee access to certain activities involving personal data, as well as provide periodic training to employees and other natural or legal persons who process personal data. Moreover, the DPA imposed fines totalling Romania RON 285,395 (€54,300). == Comment == ''Share your comments here!'' == Further Resources == ''Share blogs or news articles here!'' == English Machine Translation of the Decision == The decision below is a machine translation of the Romanian original. Please refer to the Romanian original for more details. August 6, 2026 Penalty for Violating the GDPR and Law No. 506\u002F2004 In June 2026, the National Supervisory Authority for Personal Data Processing concluded an investigation into the data controller AMATO BESTSELLER S.R.L. and found a violation of the provisions of Art. 32, para. (4), Article 14, and Article 5(1)(c) in conjunction with Article 9 of Regulation (EU) 2016\u002F679, as well as a violation of the provisions of Article 12( (1) of Law No. 506\u002F2004 on the processing of personal data and the protection of privacy in the electronic communications sector. Accordingly, the data controller was sanctioned with: - a fine of 78,465 lei, equivalent to 15,000 euros, for violating the provisions of Article 32(4) of Regulation (EU) 2016\u002F679; - a fine of 52,310 lei, equivalent to 10,000 euros, for violating the provisions of Article 14 of Regulation (EU) 2016\u002F679; - a fine of 104,620 lei, equivalent to 20,000 euros, for violating the provisions of Article 5(1)(c) in conjunction with Article 9 of Regulation (EU) 2016\u002F679; (1)(c) in conjunction with Article 9 of Regulation (EU) 2016\u002F679; - a fine of 50,000 lei for violating the provisions of Article 12(1) of Law 506\u002F2004. The investigation was launched following complaints submitted by several data subjects, who reported possible violations of Regulation (EU) 2016\u002F679. The investigation found that the controller violated the provisions of Article 32(4) (4) of the GDPR, as it failed to take measures to ensure that any natural person acting under its authority and having access to personal data processes such data only at its request. Consequently, the controller failed to train its own employees and failed to inform them of work procedures and policies for processing the personal data of data subjects in a manner that ensures their adequate security, protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, by taking appropriate technical or organizational measures. This deficiency allowed, for a certain period of time, current and former employees of the controller to have unauthorized access to personal data (first name, last name, phone number, the relationship between one data subject and another, occupation, marital status, a person’s classification within a specific social category, city of domicile\u002Fresidence, income data, family data, and health data\u002Fspecial categories of personal data) belonging to a considerable number of data subjects. At the same time, it was found that the controller violated the provisions of Article 14 of the GDPR because it failed to provide accurate and complete information to the data subjects, in accordance with the provisions of the GDPR. Furthermore, the investigation revealed that the controller engaged in excessive data processing (including special categories of data and health data) without ensuring that such processing was appropriate, relevant, and limited to what is necessary, in relation to the purposes for which it was processed, in violation of the “data minimization” principle set forth in Article 5(1)(c) in conjunction with Article 9 of the GDPR. During the investigation, it was also found that the controller sent commercial communications using automated calling and communication systems that do not require human intervention, by dialing telephone numbers and conducting conversations with a significant number of data subjects, without the data subjects having previously given their express consent to receive such communications, in violation of the provisions of Article 12(1) of Law 506\u002F2004. At the same time, the National Supervisory Authority also imposed the following corrective measures, ordering the controller to: include in all applicable procedures and work policies clear instructions regarding the flow of personal data within the organization and the flow of documents containing personal data, for each specific purpose and method of processing, to specify differentiated employee access to certain activities involving personal data, as well as to provide periodic training to employees and other natural or legal persons who process personal data under the authority of AMATO BESTSELLER SRL; to ensure clear, complete, and accurate information is provided to data subjects whose personal data is processed by the controller, in accordance with Article 14 of the GDPR and under the transparency requirements set forth in Article 12 of the GDPR; to process personal data in compliance with Article 5(1)(c) of the GDPR for each specific purpose; to ensure that the data subject has given prior express consent to receive unsolicited communications.” Legal and Communications Department A.N.S.P.D.C.P","The Romanian data protection authority (ANSPDCP) has fined AMATO BESTSELLER S.R.L. a total of 285,395 RON (approximately €54,300) for multiple violations of GDPR and the ePrivacy Directive. The company failed to implement adequate security measures, allowing unauthorized access to sensitive personal data by current and former employees. Additionally, they engaged in excessive data processing, failed to provide accurate information to data subjects, and sent commercial communications without prior consent.","Romania's ANSPDCP fines AMATO BESTSELLER S.R.L. for GDPR and ePrivacy violations.","Help ANSPDCP (Romania) - AMATO BESTSELLER S.R.L.: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 13:55, 14 August 2026 view source Lh (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators2 edits Tag: Decisions [1.0] (No difference) Latest revision as of 13:55, 14 August 2026 ANSPDCP - AMATO BESTSELLER S.R.L. Authority: ANSPDCP (Romania) Jurisdiction: Romania Relevant Law: Article 5(1)(c) GDPR Article 9 GDPR Article 32(4) GDPR Article 12 GDPR Article 14 GDPR Article 12(1) Law 506\u002F2004 Type: Complaint Outcome: Upheld Started: Decided: Published: Fine: 285395.0 RON Parties: n\u002Fa National Case Number\u002FName: AMATO BESTSELLER S.R.L. European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Romanian Original Source: Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (in RO) Initial Contributor: n\u002Fa The DPA imposed a 54,300 fine to a controller for violations of Article 32(4), Article 14 and Article 5(1)(c) in conjunction with Article 9 GDPR and ePrivacy Directive. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A general wholesale\u002Fretail trade company (controller) failed to implement adequate technical and organisational measures, such as appropriate training of its employees, in order to secure personal data from unauthorized access. Subsequently, for a specific period of time, former and current employees were able to access personal data (first name, last name, phone number, the relationship between one data subject and another, occupation, marital status, a person’s classification within a specific social category, city of domicile\u002Fresidence, income data, family data, and health data\u002Fspecial categories of personal data) of a considerable amount of data subjects. The controller did not provide accurate and complete information to the data subjects and engaged in excessive data processing. Additionally, the controller sent commercial communications using automated dialing and communication systems that do not require human intervention, by dialing the telephone number and conducting conversations with a significant number of data subjects, without the data subjects having given their prior express consent to receive such communications. Holding The DPA held that the data controller violated Article 32(4) GDPR by failing to prevent unauthorized access of personal data to current and former employees of the data controller. The data controller violated Article 14 GDPR by failing to provide accurate and complete information to the data subjects. The excessive data processing (including special categories of data and health data), without ensuring that such processing was adequate, relevant, and limited to what is necessary in relation to the purposes for which the data were processed amounted to a violation of the data minimisation principle under Article 5(1)(c) in conjunction with Article 9 GDPR. Additionally, the DPA held that commercial communications using automated dialing and communication systems that do not require human intervention by dialing the telephone number and conducting conversations with a significant number of data subjects, without the data subjects having given their prior express consent to receive such communications, constitutes a violation of Article 12(1) of Law 506\u002F2004, the Romanian law implementing the ePrivacy Directive. The DPA imposed on the controller to include in all applicable work procedures\u002Fpolicies clear instructions regarding the flow of personal data within the controller’s organisation and the flow of documents containing personal data, specify differentiated employee access to certain activities involving personal data, as well as provide periodic training to employees and other natural or legal persons who process personal data. Moreover, the DPA imposed fines totalling Romania RON 285,395 (€54,300). Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Romanian original. Please refer to the Romanian original for more details. August 6, 2026 Penalty for Violating the GDPR and Law No. 506\u002F2004 In June 2026, the National Supervisory Authority for Personal Data Processing concluded an investigation into the data controller AMATO BESTSELLER S.R.L. and found a violation of the provisions of Art. 32, para. (4), Article 14, and Article 5(1)(c) in conjunction with Article 9 of Regulation (EU) 2016\u002F679, as well as a violation of the provisions of Article 12( (1) of Law No. 506\u002F2004 on the processing of personal data and the protection of privacy in the electronic communications sector. Accordingly, the data controller was sanctioned with: - a fine of 78,465 lei, equivalent to 15,000 euros, for violating the provisions of Article 32(4) of Regulation (EU) 2016\u002F679; - a fine of 52,310 lei, equivalent to 10,000 euros, for violating the provisions of Article 14 of Regulation (EU) 2016\u002F679; - a fine of 104,620 lei, equivalent to 20,000 euros, for violating the provisions of Article 5(1)(c) in conjunction with Article 9 of Regulation (EU) 2016\u002F679; (1)(c) in conjunction with Article 9 of Regulation (EU) 2016\u002F679; - a fine of 50,000 lei for violating the provisions of Article 12(1) of Law 506\u002F2004. The investigation was launched following complaints submitted by several data subjects, who reported possible violations of Regulation (EU) 2016\u002F679. The investigation found that the controller violated the provisions of Article 32(4) (4) of the GDPR, as it failed to take measures to ensure that any natural person acting under its authority and having access to personal data processes such data only at its request. Consequently, the controller failed to train its own employees and failed to inform them of work procedures and policies for processing the personal data of data subjects in a manner that ensures their adequate security, protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, by taking appropriate technical or organizational measures. This deficiency allowed, for a certain period of time, current and former employees of the controller to have unauthorized access to personal data (first name, last name, phone number, the relationship between one data subject and another, occupation, marital status, a person’s classification within a specific social category, city of domicile\u002Fresidence, income data, family data, and health data\u002Fspecial categories of personal data) belonging to a considerable number of data subjects. At the same time, it was found that the controller violated the provisions of Article 14 of the GDPR because it failed to provide accurate and complete information to the data subjects, in accordance with the provisions of the GDPR. Furthermore, the investigation revealed that the controller engaged in excessive data processing (including special categories of data and health data) without ensuring that such processing was appropriate, relevant, and limited to what is necessary, in relation to the purposes for which it was processed, in violation of the “data minimization” principle set forth in Article 5(1)(c) in conjunction with Article 9 of the GDPR. During the investigation, it was also found that the controller sent commercial communications using automated calling and communication systems that do not require human intervention, by dialing telephone numbers and conducting conversations with a significant number of data subjects, without the data subjects having previously given their express consent to receive such communications, in violation of the provisions of Article 12(1) of Law 506\u002F2004. At the same time, the National Supervisory Authority also imposed the following corrective measures, orderi","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=ANSPDCP_(Romania)_-_AMATO_BESTSELLER_S.R.L.&diff=52696&oldid=0","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fc\u002Fc2\u002FLogoRO.jpg","2026-08-14T13:55:21+00:00","2026-08-14T14:00:22.008421+00:00",7,[18,21],{"name":19,"type":20},"AMATO BESTSELLER S.R.L.","vendor",{"name":22,"type":23},"ePrivacy Directive","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":24,"icon":26,"name":27,"slug":28},null,"Policy","policy",[30,35,40,42],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":41},{"id":24,"icon":26,"name":27,"slug":28},{"category":43},{"id":44,"icon":26,"name":45,"slug":46},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]