[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fIkJ9Zp70wT8j2Ccshb99lM1NS6xWN8wTekWtppIVRF4":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"fece0fcb-284e-46d4-b868-b903406f67bc","ANSPDCP (Romania) - Fine against GLOBAL CUSTOMER CARE SERVICES S.R.L","anspdcp-romania-fine-against-global-customer-care-services-s-r-l-ba5391","Created page with \"{{DPAdecisionBOX |Jurisdiction=Romania |DPA-BG-Color= |DPAlogo=LogoRO.jpg |DPA_Abbrevation=ANSPDCP |DPA_With_Country=ANSPDCP (Romania) |Case_Number_Name=Fine against GLOBAL CUSTOMER CARE SERVICES S.R.L |ECLI= |Original_Source_Name_1=ANSPDCP |Original_Source_Link_1=https:\u002F\u002Fwww.dataprotection.ro\u002F?page=Comunicat_Presa_02_10_2026&lang=ro |Original_Source_Language_1=Romanian |Original_Source_Language__Code_1=RO |Original_Source_Name_2= |Original_Source_Link_2= |Original...\" New page {{DPAdecisionBOX |Jurisdiction=Romania |DPA-BG-Color= |DPAlogo=LogoRO.jpg |DPA_Abbrevation=ANSPDCP |DPA_With_Country=ANSPDCP (Romania) |Case_Number_Name=Fine against GLOBAL CUSTOMER CARE SERVICES S.R.L |ECLI= |Original_Source_Name_1=ANSPDCP |Original_Source_Link_1=https:\u002F\u002Fwww.dataprotection.ro\u002F?page=Comunicat_Presa_02_10_2026&lang=ro |Original_Source_Language_1=Romanian |Original_Source_Language__Code_1=RO |Original_Source_Name_2= |Original_Source_Link_2= |Original_Source_Language_2= |Original_Source_Language__Code_2= |Type=Investigation |Outcome=Violation Found |Date_Started= |Date_Decided= |Date_Published=02.10.2026 |Year=2026 |Fine=26294.0 |Currency=RON |GDPR_Article_1=Article 32(1)(b) GDPR |GDPR_Article_Link_1=Article 32 GDPR#1b |GDPR_Article_2=Article 32(1)(d) GDPR |GDPR_Article_Link_2=Article 32 GDPR#1d |GDPR_Article_3=Article 32(2) GDPR |GDPR_Article_Link_3=Article 32 GDPR#2 |GDPR_Article_4= |GDPR_Article_Link_4= |GDPR_Article_5= |GDPR_Article_Link_5= |EU_Law_Name_1= |EU_Law_Link_1= |EU_Law_Name_2= |EU_Law_Link_2= |National_Law_Name_1= |National_Law_Link_1= |National_Law_Name_2= |National_Law_Link_2= |Party_Name_1=GLOBAL CUSTOMER CARE SERVICES S.R.L. |Party_Link_1= |Party_Name_2= |Party_Link_2= |Party_Name_3= |Party_Link_3= |Appeal_To_Body= |Appeal_To_Case_Number_Name= |Appeal_To_Status= |Appeal_To_Link= |Initial_Contributor=cerasela | }} The DPA fined a controller RON 26,294 (€5,000) for failing to implement adequate security measures, which led to a breach affecting the confidentiality and availability of personal data following a cyberattack. == English Summary == === Facts === A personal data breach occurred because of a cyberattack on of a call centre service provider (the controller). Thus, the confidentiality and availability of personal data were compromised and unauthorised parties gained access to the personal data of a significant number of individuals, including employees, former employees and other persons. The affected data included contact details, identification data, employment-related information, salary and benefits data, bank account details, and residence-related information. Subsequently, the controller notified the personal data breach to the DPA under [[Article 33 GDPR|Article 33 GDPR]]. === Holding === The DPA found that the controller had failed to implement adequate technical and organisational measures to ensure a level of security appropriate to the risks associated with its processing activities, violating [[Article 32 GDPR|Article 32 GDPR]] #1b [[Article 32 GDPR|Article 32 GDPR]]#1d and Article 32#2. According to the DPA, the controller had not adequately ensured the ongoing confidentiality of its processing systems and had failed to establish a process for regularly testing, assessing and evaluating the effectiveness of its technical and organisational security measures. The DPA considered that the incident demonstrated the inadequacy of the security measures implemented by the controller. In this context, the DPA fined the controller €5,000 (RON 26,294). In addition, the DPA ordered the controller to implement monitoring and logging systems for access to its IT infrastructure, including the retention of activity logs for at least 30 days and the introduction of a process for backing up those logs. == Comment == This decision adds to the growing number of recent Romanian DPA cases involving personal data breaches and infringements of [[Article 32 GDPR|Article 32 GDPR]], which appear to represent one of the most frequent categories of sanctions issued by the national supervisory authority. == Further Resources == ''Share blogs or news articles here!'' == English Machine Translation of the Decision == The decision below is a machine translation of the Romanian original. Please refer to the Romanian original for more details. October 2, 2026 Fine for Violating the GDPR In August 2026, the National Supervisory Authority for Personal Data Processing concluded an investigation into the data controller GLOBAL CUSTOMER CARE SERVICES S.R.L. and found a violation of Article 32, paragraph (1)(b) and (d) and paragraph (2) of Regulation (EU) 2016\u002F679. As a result, the data controller was fined 26,294 lei, equivalent to 5,000 euros. The investigation was initiated following the submission by the data controller, GLOBAL CUSTOMER CARE SERVICES S.R.L., of a notification of a personal data breach, in accordance with the provisions of Article 33 of Regulation (EU) 2016\u002F679. During the investigation, it was found that, following a cyberattack on the controller’s infrastructure, the confidentiality and availability of the personal data contained therein were compromised. This led to unauthorized access to the personal data of a significant number of data subjects (employees, former employees, and other individuals). As a result, the following data was accessed without authorization: first and last names, contact information, information regarding education and professional certifications\u002Fqualifications, information regarding salary and other benefits, identification information contained in identification documents and other records, bank account information and other data necessary for making payments, details regarding previous and\u002For current employment relationships, residence information, data required to obtain residence permits, and contact information for representatives or designated individuals. As such, it was found that the controller had not implemented adequate technical and organizational measures to ensure a level of security appropriate to the risk posed by the processing, including, among other things, the ability to ensure the confidentiality of processing systems and services, as well as the establishment of a process for the periodic testing, evaluation, and assessment of the effectiveness of technical and organizational measures to guarantee the security of processing. At the same time, pursuant to Article 58(2)(d) of the Regulation, the controller was ordered to implement corrective measures to establish systems for monitoring and logging access to the IT infrastructure used for the processing of personal data, which must include a retention period for activity logs of at least 30 days, including the implementation of a process for saving them. Legal and Communications Department A.N.S.P.D.C.P","Romania's data protection authority (ANSPDCP) has fined Global Customer Care Services S.R.L. €5,000 (RON 26,294) following a cyberattack that compromised personal data. The company failed to implement adequate security measures, violating GDPR Article 32. The breach exposed sensitive information including contact details, identification data, employment and salary information, and bank account details.","Romania's ANSPDCP fines Global Customer Care Services S.R.L. €5,000 for data breach.","Help ANSPDCP (Romania) - Fine against GLOBAL CUSTOMER CARE SERVICES S.R.L: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 15:39, 9 October 2026 view source Cerasela (talk | contribs)18 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 15:39, 9 October 2026 ANSPDCP - Fine against GLOBAL CUSTOMER CARE SERVICES S.R.L Authority: ANSPDCP (Romania) Jurisdiction: Romania Relevant Law: Article 32(1)(b) GDPR Article 32(1)(d) GDPR Article 32(2) GDPR Type: Investigation Outcome: Violation Found Started: Decided: Published: 02.10.2026 Fine: 26294.0 RON Parties: GLOBAL CUSTOMER CARE SERVICES S.R.L. National Case Number\u002FName: Fine against GLOBAL CUSTOMER CARE SERVICES S.R.L European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Romanian Original Source: ANSPDCP (in RO) Initial Contributor: cerasela The DPA fined a controller RON 26,294 (€5,000) for failing to implement adequate security measures, which led to a breach affecting the confidentiality and availability of personal data following a cyberattack. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A personal data breach occurred because of a cyberattack on of a call centre service provider (the controller). Thus, the confidentiality and availability of personal data were compromised and unauthorised parties gained access to the personal data of a significant number of individuals, including employees, former employees and other persons. The affected data included contact details, identification data, employment-related information, salary and benefits data, bank account details, and residence-related information. Subsequently, the controller notified the personal data breach to the DPA under Article 33 GDPR. Holding The DPA found that the controller had failed to implement adequate technical and organisational measures to ensure a level of security appropriate to the risks associated with its processing activities, violating Article 32 GDPR #1b Article 32 GDPR#1d and Article 32#2. According to the DPA, the controller had not adequately ensured the ongoing confidentiality of its processing systems and had failed to establish a process for regularly testing, assessing and evaluating the effectiveness of its technical and organisational security measures. The DPA considered that the incident demonstrated the inadequacy of the security measures implemented by the controller. In this context, the DPA fined the controller €5,000 (RON 26,294). In addition, the DPA ordered the controller to implement monitoring and logging systems for access to its IT infrastructure, including the retention of activity logs for at least 30 days and the introduction of a process for backing up those logs. Comment This decision adds to the growing number of recent Romanian DPA cases involving personal data breaches and infringements of Article 32 GDPR, which appear to represent one of the most frequent categories of sanctions issued by the national supervisory authority. Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Romanian original. Please refer to the Romanian original for more details. October 2, 2026 Fine for Violating the GDPR In August 2026, the National Supervisory Authority for Personal Data Processing concluded an investigation into the data controller GLOBAL CUSTOMER CARE SERVICES S.R.L. and found a violation of Article 32, paragraph (1)(b) and (d) and paragraph (2) of Regulation (EU) 2016\u002F679. As a result, the data controller was fined 26,294 lei, equivalent to 5,000 euros. The investigation was initiated following the submission by the data controller, GLOBAL CUSTOMER CARE SERVICES S.R.L., of a notification of a personal data breach, in accordance with the provisions of Article 33 of Regulation (EU) 2016\u002F679. During the investigation, it was found that, following a cyberattack on the controller’s infrastructure, the confidentiality and availability of the personal data contained therein were compromised. This led to unauthorized access to the personal data of a significant number of data subjects (employees, former employees, and other individuals). As a result, the following data was accessed without authorization: first and last names, contact information, information regarding education and professional certifications\u002Fqualifications, information regarding salary and other benefits, identification information contained in identification documents and other records, bank account information and other data necessary for making payments, details regarding previous and\u002For current employment relationships, residence information, data required to obtain residence permits, and contact information for representatives or designated individuals. As such, it was found that the controller had not implemented adequate technical and organizational measures to ensure a level of security appropriate to the risk posed by the processing, including, among other things, the ability to ensure the confidentiality of processing systems and services, as well as the establishment of a process for the periodic testing, evaluation, and assessment of the effectiveness of technical and organizational measures to guarantee the security of processing. At the same time, pursuant to Article 58(2)(d) of the Regulation, the controller was ordered to implement corrective measures to establish systems for monitoring and logging access to the IT infrastructure used for the processing of personal data, which must include a retention period for activity logs of at least 30 days, including the implementation of a process for saving them. Legal and Communications Department A.N.S.P.D.C.P Retrieved from \"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=ANSPDCP_(Romania)_-_Fine_against_GLOBAL_CUSTOMER_CARE_SERVICES_S.R.L&oldid=53357\" Categories: ANSPDCP (Romania)RomaniaArticle 32(1)(b) GDPRArticle 32(1)(d) GDPRArticle 32(2) GDPR2026Romanian This page was last edited on 9 October 2026, at 15:39. Content is available under Creative Commons Attribution-NonCommercial-ShareAlike unless otherwise noted. Privacy policy About GDPRhub Disclaimers","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=ANSPDCP_(Romania)_-_Fine_against_GLOBAL_CUSTOMER_CARE_SERVICES_S.R.L&diff=53357&oldid=0","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fc\u002Fc2\u002FLogoRO.jpg","2026-10-09T15:39:18+00:00","2026-10-09T16:00:22.917797+00:00",7,[18],{"name":19,"type":20},"GLOBAL CUSTOMER CARE SERVICES S.R.L.","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,32,37,42],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":38},{"id":39,"icon":23,"name":40,"slug":41},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":43},{"id":21,"icon":23,"name":24,"slug":25},[]]