ANSPDCP (Romania) - Fine against GEROCOSSEN S.R.L.
Romanian DPA fines cosmetics retailer €5,000 for inadequate security measures leading to data breach.
Summary
The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) imposed a €5,000 fine on GEROCOSSEN S.R.L., a cosmetics retailer, for violating Article 32 GDPR by failing to implement adequate technical and organizational security measures. A cyberattack on the company's IT infrastructure exposed personal data including identification and contact details. The DPA ordered corrective measures including access monitoring, logging systems, 30-day log retention, and backup procedures.
Full text
Help ANSPDCP (Romania) - Fine against GEROCOSSEN S.R.L.: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 12:49, 3 September 2026 view source Cerasela (talk | contribs)13 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 12:49, 3 September 2026 ANSPDCP - Fine against GEROCOSSEN S.R.L. Authority: ANSPDCP (Romania) Jurisdiction: Romania Relevant Law: Article 32(1)(b) GDPR Article 32(2) GDPR Type: Investigation Outcome: Violation Found Started: Decided: Published: 28.08.2026 Fine: 26236.0 RON Parties: GEROCOSSEN S.R.L. National Case Number/Name: Fine against GEROCOSSEN S.R.L. European Case Law Identifier: n/a Appeal: n/a Original Language(s): Romanian Original Source: ANSPDCP (in RO) Initial Contributor: cerasela The Romanian DPA imposed a RON 26,236.50 (€5,000) fine on a cosmetics retailer for infringing Article 32 GDPR by failing to implement adequate security measures, after a cyberattack affecting its IT infrastructure led to a personal data breach. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The controller suffered a cyberattack that affected its IT infrastructure. As a result, unauthorised parties gained access to personal data relating to some data subjects, including identification and contact details. Holding The DPA found that the controller infringed Article 32 GDPR#1b and Article 32 GDPR#2 by failing to implement adequate technical and organisational measures in order to ensure the confidentiality and integrity of its processing systems and services. In particular, the DPA considered that the controller had failed to adopt security measures appropriate to protect personal data processed through its IT infrastructure. In addition, as a corrective measure pursuant to Article 58 GDPR#2d, the DPA ordered the controller to implement access monitoring and logging systems within the IT infrastructure used for personal data processing. The authority further required the controller to retain access logs for at least 30 days and to introduce backup procedures for those logs. Finally, the Romanian DPA fined the controller €5,000 (RON 26,236.50). Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Romanian original. Please refer to the Romanian original for more details. August 28, 2026 Penalty for GDPR Violation In July 2026, the National Supervisory Authority for Personal Data Processing concluded an investigation into the data controller GEROCOSSEN S.R.L. and found a violation of the provisions of Article 32(1)(b) and (2) of Regulation (EU) 2016/679. As a result, the data controller was fined 26,236.50 lei, equivalent to 5,000 euros. The investigation was initiated following the submission by the data controller, GEROCOSSEN S.R.L., of a notification of a personal data breach, in accordance with the provisions of Article 33 of Regulation (EU) 2016/679. The data breach occurred as a result of a cyberattack on the controller’s IT infrastructure, a situation that led to the unauthorized disclosure of or unauthorized access to personal data belonging to data subjects (identification data, contact information). During the investigation, it was found that the controller had not implemented adequate technical and organizational measures to ensure a level of security appropriate to the risk posed by the processing, including the ability to ensure the confidentiality and integrity of processing systems and services, thereby violating the provisions of Article 32(1)(b) and (2) of Regulation (EU) 2016/679. At the same time, pursuant to Article 58(2)(d) of the Regulation, the controller was ordered to implement corrective measures to establish monitoring/logging of access to the IT infrastructure used for the processing of personal data, including a retention period for access logs of at least 30 days, as well as the implementation of a backup process for these logs. Legal and Communications Directorate A.N.S.P.D.C.P Retrieved from "https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_Fine_against_GEROCOSSEN_S.R.L.&oldid=52909" Categories: ANSPDCP (Romania)RomaniaArticle 32(1)(b) GDPRArticle 32(2) GDPR2026Romanian This page was last edited on 3 September 2026, at 12:49. Content is available under Creative Commons Attribution-NonCommercial-ShareAlike unless otherwise noted. Privacy policy About GDPRhub Disclaimers