Back to Feed
PolicySep 3, 2026

ANSPDCP (Romania) - Fine against GEROCOSSEN S.R.L.

Romania's ANSPDCP fines cosmetics retailer GEROCOSSEN S.R.L. €5,000 for GDPR violations after a cyberattack.

Summary

The Romanian Data Protection Authority (ANSPDCP) has fined GEROCOSSEN S.R.L., a cosmetics retailer, RON 26,236.50 (approximately €5,000) for failing to implement adequate security measures. This penalty follows a cyberattack that compromised the company's IT infrastructure, leading to a personal data breach. The authority found that GEROCOSSEN SRL infringed Article 32 of the GDPR by not ensuring appropriate technical and organizational measures to protect personal data.

Full text

Help ANSPDCP (Romania) - Fine against GEROCOSSEN S.R.L.: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 12:58, 3 September 2026 view sourceCerasela (talk | contribs)13 editsmTag: Visual edit← Older edit Latest revision as of 13:06, 3 September 2026 view source Cerasela (talk | contribs)13 editsmTag: Visual edit Line 28: Line 28: |Date_Published=28.08.2026|Date_Published=28.08.2026 |Year=2026|Year=2026 |Fine=26236.0|Fine=26236.50 |Currency=RON|Currency=RON Latest revision as of 13:06, 3 September 2026 ANSPDCP - Fine against GEROCOSSEN S.R.L. Authority: ANSPDCP (Romania) Jurisdiction: Romania Relevant Law: Article 32(1)(b) GDPR Article 32(2) GDPR Type: Investigation Outcome: Violation Found Started: Decided: Published: 28.08.2026 Fine: 26236.50 RON Parties: GEROCOSSEN S.R.L. National Case Number/Name: Fine against GEROCOSSEN S.R.L. European Case Law Identifier: n/a Appeal: n/a Original Language(s): Romanian Original Source: ANSPDCP (in RO) Initial Contributor: cerasela The Romanian DPA imposed a RON 26,236.50 (€5,000) fine on a cosmetics retailer for infringing Article 32 GDPR by failing to implement adequate security measures, after a cyberattack affecting its IT infrastructure led to a personal data breach. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts Gerocossen SRL (the controller) suffered a cyberattack that affected its IT infrastructure. As a result, unauthorised parties gained access to personal data relating to some data subjects, including identification and contact details. Holding The DPA found that the controller infringed Article 32(1)(b) GDPR and Article 32(2) GDPR by failing to implement adequate technical and organisational measures in order to ensure the confidentiality and integrity of its processing systems and services. In particular, the DPA considered that the controller had failed to adopt security measures appropriate to protect personal data processed through its IT infrastructure. In addition, as a corrective measure pursuant to Article 58(2)(d) GDPR, the DPA ordered the controller to implement access monitoring and logging systems within the IT infrastructure used for personal data processing. The authority further required the controller to retain access logs for at least 30 days and to introduce backup procedures for those logs. Finally, the Romanian DPA fined the controller €5,000 (RON 26,236.50). Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Romanian original. Please refer to the Romanian original for more details. August 28, 2026 Penalty for GDPR Violation In July 2026, the National Supervisory Authority for Personal Data Processing concluded an investigation into the data controller GEROCOSSEN S.R.L. and found a violation of the provisions of Article 32(1)(b) and (2) of Regulation (EU) 2016/679. As a result, the data controller was fined 26,236.50 lei, equivalent to 5,000 euros. The investigation was initiated following the submission by the data controller, GEROCOSSEN S.R.L., of a notification of a personal data breach, in accordance with the provisions of Article 33 of Regulation (EU) 2016/679. The data breach occurred as a result of a cyberattack on the controller’s IT infrastructure, a situation that led to the unauthorized disclosure of or unauthorized access to personal data belonging to data subjects (identification data, contact information). During the investigation, it was found that the controller had not implemented adequate technical and organizational measures to ensure a level of security appropriate to the risk posed by the processing, including the ability to ensure the confidentiality and integrity of processing systems and services, thereby violating the provisions of Article 32(1)(b) and (2) of Regulation (EU) 2016/679. At the same time, pursuant to Article 58(2)(d) of the Regulation, the controller was ordered to implement corrective measures to establish monitoring/logging of access to the IT infrastructure used for the processing of personal data, including a retention period for access logs of at least 30 days, as well as the implementation of a backup process for these logs. Legal and Communications Directorate A.N.S.P.D.C.P Retrieved from "https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_Fine_against_GEROCOSSEN_S.R.L.&oldid=52914" Categories: ANSPDCP (Romania)RomaniaArticle 32(1)(b) GDPRArticle 32(2) GDPR2026Romanian This page was last edited on 3 September 2026, at 13:06. Content is available under Creative Commons Attribution-NonCommercial-ShareAlike unless otherwise noted. Privacy policy About GDPRhub Disclaimers

Entities

ANSPDCP (vendor)GEROCOSSEN S.R.L. (product)