ANSPDCP (Romania) - ANSPDCP (Romania) - Fine against Poliserv JG (PJG) SRL
Romanian DPA fines car dealer €3,000 for data security failures after phishing attack.
Summary
The Romanian Data Protection Authority (ANSPDCP) has fined Poliserv JG (PJG) SRL, a car dealership, €3,000 (RON 15,728) for failing to implement adequate technical and organizational measures to secure personal data processing. The fine was issued after a phishing attack compromised an administrator account, leading to unauthorized access to customer data, violating Article 32 of the GDPR. The DPA also mandated regular phishing awareness training and verification of data protection procedures.
Full text
Help ANSPDCP (Romania) - Fine against Poliserv JG (PJG) SRL: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 10:05, 21 August 2026 view sourceCerasela (talk | contribs)10 edits Tag: Decisions [1.0] Latest revision as of 10:38, 21 August 2026 view source Cerasela (talk | contribs)10 editsm (2 intermediate revisions by the same user not shown)Line 7: Line 7: |DPA_With_Country=ANSPDCP (Romania)|DPA_With_Country=ANSPDCP (Romania) |Case_Number_Name=ANSPDCP (Romania) - Fine against Poliserv JG (PJG) SRL|Case_Number_Name=Fine against Poliserv JG (PJG) SRL |ECLI=|ECLI= Line 88: Line 88: }}}} The Romanian DPA imposed a fine of RON 15,728 (€ 3,000) on a car dealer for failing to implement appropriate technical and organisational measures in order to guarantee the security of its processing, in breach of [[Article 32 GDPR|Article 32 GDPR]].The Romanian DPA imposed a fine of RON 15,728 (€3,000) on a car dealer for failing to implement appropriate technical and organisational measures in order to guarantee the security of its processing, in breach of [[Article 32 GDPR]]. == English Summary ==== English Summary == Line 97: Line 97: === Holding ====== Holding === ANSPDCP found that the controller infringed Article 32(1)(b) and [[Article 32 GDPR|Article 32(2) GDPR]] by failing to implement adequate technical and organisational measures to ensure the security of personal data processing. Considering that a phishing attack compromised an administrator account and enabled unauthorised access to customers' personal data, the controller's security measures and testing procedures were not appropriate for maintaining the continuity of confidentiality, integrity, availability and resilience of processing systems and services.ANSPDCP found that the controller infringed Article 32(1)(b) GDPR and [[Article 32 GDPR|Article 32(2) GDPR]] by failing to implement adequate technical and organisational measures to ensure the security of personal data processing. Considering that a phishing attack compromised an administrator account and enabled unauthorised access to customers' personal data, the controller's security measures and testing procedures were not appropriate for maintaining the ongoing confidentiality, integrity, availability and resilience of processing systems and services. In addition, as a corrective measure, pursuant to Article 58 (2) GDPR, the DPA ordered the controller to periodically verify compliance with its data protection and information security procedures and provide regular phishing-awareness training to its personnel working with personal data.In addition, as a corrective measure, pursuant to Article 58(2)(d) GDPR, the DPA ordered the controller to periodically verify compliance with its data protection and information security procedures and provide regular phishing-awareness training to its personnel working with personal data. Finally, for these violations, ANSPDCP decided to fine the controller €3,000 (RON 15,728).Finally, for these violations, ANSPDCP decided to fine the controller €3,000 (RON 15,728). Latest revision as of 10:38, 21 August 2026 ANSPDCP - Fine against Poliserv JG (PJG) SRL Authority: ANSPDCP (Romania) Jurisdiction: Romania Relevant Law: Article 32(1)(b) GDPR Article 32(2) GDPR Type: Investigation Outcome: Violation Found Started: Decided: Published: 19.08.2026 Fine: 15728.0 RON Parties: Poliserv JG (PJG) SRL National Case Number/Name: Fine against Poliserv JG (PJG) SRL European Case Law Identifier: n/a Appeal: n/a Original Language(s): Romanian Original Source: ANSPDCP (in RO) Initial Contributor: cerasela The Romanian DPA imposed a fine of RON 15,728 (€3,000) on a car dealer for failing to implement appropriate technical and organisational measures in order to guarantee the security of its processing, in breach of Article 32 GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A personal data breach occurred because of a cyberattack made possible through a phishing method that stole the credentials of a controller account with administrator privileges. Thus, the personal data of individual customers (at least their first and last names) was accessed by unauthorised parties. Holding ANSPDCP found that the controller infringed Article 32(1)(b) GDPR and Article 32(2) GDPR by failing to implement adequate technical and organisational measures to ensure the security of personal data processing. Considering that a phishing attack compromised an administrator account and enabled unauthorised access to customers' personal data, the controller's security measures and testing procedures were not appropriate for maintaining the ongoing confidentiality, integrity, availability and resilience of processing systems and services. In addition, as a corrective measure, pursuant to Article 58(2)(d) GDPR, the DPA ordered the controller to periodically verify compliance with its data protection and information security procedures and provide regular phishing-awareness training to its personnel working with personal data. Finally, for these violations, ANSPDCP decided to fine the controller €3,000 (RON 15,728). Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Romanian original. Please refer to the Romanian original for more details. August 19, 2026 Fine for Violating the GDPR In July 2026, the National Supervisory Authority for Personal Data Processing concluded an investigation into Poliserv JG (PJG) SRL and found a violation of the provisions of Article 32, paragraph (1)(b) and paragraph (2) of the General Data Protection Regulation (GDPR). As a result, Poliserv JG (PJG) SRL was fined 15,728 lei, equivalent to 3,000 euros. The investigation was initiated following the submission by Poliserv JG (PJG) SRL of a notification of a personal data breach, in accordance with the provisions of Article 33 of Regulation (EU) 2016/679. The investigation found that the data processing security breach occurred as a result of a cyberattack that exploited a vulnerability involving the credentials of a user account with administrator privileges, which had been stolen through phishing. This situation led to unauthorized access to the personal data (at least: first and last names) of certain individuals who were customers of the data controller. Thus, it was found that the operator had not implemented adequate technical and organizational measures and had not conducted the testing, evaluate, and assess the effectiveness of the technical and organizational measures on a regular basis to ensure the security of processing, including the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of the processing systems and services. The National Supervisory Authority determined that the circumstances of the above-mentioned case are sufficiently serious to warrant the imposition of a fine against the controller, in accordance with the criteria for determining the amount of fines set forth in Article 83 of Regulation (EU) 679/2016. At the same time, pursuant to the provisions of Article 58(2)(d) of Regulation (EU) 2016/679, the controller Poliserv JG (PJG) SRL to periodically verify compliance with the implemented working procedures regarding the protection of personal data and information security, and to periodically train persons acting under the controller’s authority regarding the risks associated with the processing of personal data, including with regard to identifying and handling phishing messages and other suspicious emails. Legal and Communications Department A.N.S.P.D.C.P. Retrieved from "https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_Fine_against_Poliserv_JG_(PJG)_SRL&oldid=52745" Categories: ANSPDCP (Romania)RomaniaArticle 32(1)(b) GDPRArticle 32