[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fm8oK09Q4mrJJORjmd_NG1dl_t9TF2zXvxG8By8ko2P0":3},{"article":4,"iocs":45},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"5c83cc72-5c8b-42f4-9040-c54f3da3d049","ANSPDCP (Romania) - Fine against Homelux SRL","anspdcp-romania-fine-against-homelux-srl-899a72","Facts ← Older revision Revision as of 04:31, 6 August 2026 Line 97: Line 97: === Facts === === Facts === HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to [[Article 33 GDPR|Article 33 GDPR]]. HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to [[Article 33 GDPR]]. The controller was operating a website on a platform that had not been updated to the latest version released by the software provider. Thus, a cyberattack exploited this vulnerability and affected the personal data processed through the website. The controller was operating a website on a platform that had not been updated to the latest version released by the software provider. Thus, a cyberattack exploited this vulnerability and affected the personal data processed through the website. This incident was further facilitated by weak password requirements for user accounts, a deficiency that remained unremedied after the breach. This incident was further facilitated by weak password requirements for user accounts, a deficiency that remained unremedied after the breach. As a result, personal data processed by the controller, including names, surnames, addresses, email addresses, and passwords, was disclosed to unauthorised parties. As a result, personal data processed by the controller, including names, surnames, addresses, email addresses, and passwords, was disclosed to unauthorised parties. During the investigation, the DPA also found that the controller stored non-essential cookies on users' devices and accessed this information without obtaining the users' prior consent. During the investigation, the DPA also found that the controller stored non-essential cookies on users' devices and accessed this information without obtaining the users' prior consent. === Holding === First, the DPA found that the controller infringed [[Article 32 GDPR]] by failing to implement adequate technical and organisational measures to ensure a level of security appropriate to the risk presented by the processing. These shortcomings enabled a cyberattack that compromised personal data. The DPA also found that the controller had failed to establish a process for regularly testing, assessing, and evaluating the effectiveness of its security measures. For this infringement, the DPA imposed a fine of RON 78,570 (€15,000). Second, the DPA found that the controller infringed Article 4(5) of Law No. 506\u002F2004 on the processing of personal data and the protection of privacy in the electronic communications sector by placing non-essential cookies on users' devices without obtaining prior consent. The DPA noted that these cookies were not technically necessary for the operation of the website and therefore could not be deployed without user consent. For this infringement, the DPA imposed a fine of RON 30,000 (€5,715). === Holding === First, the DPA found that the controller infringed [[[[Article 32 GDPR|Article 32 GDPR]]#1d]] and [[[[Article 32 GDPR|Article 32 GDPR]]#2]] by failing to implement adequate technical and organisational measures to ensure a level of security appropriate to the risk presented by the processing. These shortcomings enabled a cyberattack that compromised personal data. The DPA also found that the controller had failed to establish a process for regularly testing, assessing, and evaluating the effectiveness of its security measures. For this infringement, the DPA imposed a fine of RON 78,570 (€15,000). Second, the DPA found that the controller infringed Article 4(5) of Law No. 506\u002F2004 on the processing of personal data and the protection of privacy in the electronic communications sector by placing non-essential cookies on users' devices without obtaining prior consent. The DPA noted that these cookies were not technically necessary for the operation of the website and therefore could not be deployed without user consent. For this infringement, the DPA imposed a fine of RON 30,000 (€5,715). In addition, as corrective measures, the DPA ordered the controller to implement a procedural plan for the regular testing, evaluation, and updating of its IT systems. The DPA also required the controller to strengthen access controls by introducing stronger password requirements, multi-factor authentication, the deactivation of inactive accounts, and the principle of least privilege. Furthermore, the DPA required the controller to implement measures aimed at reducing vulnerabilities, including mechanisms to detect and block cyberattacks and restrictions on access to administrative interfaces. Finally, the DPA ordered the controller to ensure compliance with Article 4(5) of Law No. 506\u002F2004 on its website. In addition, as corrective measures, the DPA ordered the controller to implement a procedural plan for the regular testing, evaluation, and updating of its IT systems. The DPA also required the controller to strengthen access controls by introducing stronger password requirements, multi-factor authentication, the deactivation of inactive accounts, and the principle of least privilege. Furthermore, the DPA required the controller to implement measures aimed at reducing vulnerabilities, including mechanisms to detect and block cyberattacks and restrictions on access to administrative interfaces. Finally, the DPA ordered the controller to ensure compliance with Article 4(5) of Law No. 506\u002F2004 on its website.","The Romanian Data Protection Authority (ANSPDCP) has fined Homelux SRL a total of €20,715 for a personal data breach. The breach occurred because the company failed to update its website platform, allowing a cyberattack to exploit a vulnerability. Weak password requirements also contributed to the incident, leading to the disclosure of names, addresses, emails, and passwords. Additionally, Homelux was fined for placing non-essential cookies without user consent.","Romania's ANSPDCP fines Homelux SRL €20,715 for data breach and privacy violations.","Help ANSPDCP (Romania) - Fine against Homelux SRL: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 04:29, 6 August 2026 view sourceCerasela (talk | contribs)5 edits Tag: Decisions [1.0] Latest revision as of 04:31, 6 August 2026 view source Cerasela (talk | contribs)5 editsm Tag: Visual edit Line 97: Line 97: === Facts ====== Facts === HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to [[Article 33 GDPR|Article 33 GDPR]].HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to [[Article 33 GDPR]]. The controller was operating a website on a platform that had not been updated to the latest version released by the software provider. Thus, a cyberattack exploited this vulnerability and affected the personal data processed through the website.The controller was operating a website on a platform that had not been updated to the latest version released by the software provider. Thus, a cyberattack exploited this vulnerability and affected the personal data processed through the website. This incident was further facilitated by weak password requirements for user accounts, a deficiency that remained unremedied after the breach.This incident was further facilitated by weak password requirements for user accounts, a deficiency that remained unremedied after the breach. As a result, personal data processed by the controller, including names, surnames, addresses, email addresses, and passwords, was disclosed to unauthorised parties.As a result, personal data processed by the controller, including names, surnames, addresses, email addresses, and passwords, was disclosed to unauthorised parties. During the investigation, the DPA also found that the controller stored non-essential cookies on users' devices and accessed this information without obtaining the users' prior consent.During the investigation, the DPA also found that the controller stored non-essential cookies on users' devices and accessed this information without obtaining the users' prior consent. === Holding === First, the DPA found that the controller infringed [[Article 32 GDPR]] by failing to implement adequate technical and organisational measures to ensure a level of security appropriate to the risk presented by the processing. These shortcomings enabled a cyberattack that compromised personal data. The DPA also found that the controller had failed to establish a process for regularly testing, assessing, and evaluating the effectiveness of its security measures. For this infringement, the DPA imposed a fine of RON 78,570 (€15,000). Second, the DPA found that the controller infringed Article 4(5) of Law No. 506\u002F2004 on the processing of personal data and the protection of privacy in the electronic communications sector by placing non-essential cookies on users' devices without obtaining prior consent. The DPA noted that these cookies were not technically necessary for the operation of the website and therefore could not be deployed without user consent. For this infringement, the DPA imposed a fine of RON 30,000 (€5,715). === Holding === First, the DPA found that the controller infringed [[[[Article 32 GDPR|Article 32 GDPR]]#1d]] and [[[[Article 32 GDPR|Article 32 GDPR]]#2]] by failing to implement adequate technical and organisational measures to ensure a level of security appropriate to the risk presented by the processing. These shortcomings enabled a cyberattack that compromised personal data. The DPA also found that the controller had failed to establish a process for regularly testing, assessing, and evaluating the effectiveness of its security measures. For this infringement, the DPA imposed a fine of RON 78,570 (€15,000). Second, the DPA found that the controller infringed Article 4(5) of Law No. 506\u002F2004 on the processing of personal data and the protection of privacy in the electronic communications sector by placing non-essential cookies on users' devices without obtaining prior consent. The DPA noted that these cookies were not technically necessary for the operation of the website and therefore could not be deployed without user consent. For this infringement, the DPA imposed a fine of RON 30,000 (€5,715). In addition, as corrective measures, the DPA ordered the controller to implement a procedural plan for the regular testing, evaluation, and updating of its IT systems. The DPA also required the controller to strengthen access controls by introducing stronger password requirements, multi-factor authentication, the deactivation of inactive accounts, and the principle of least privilege. Furthermore, the DPA required the controller to implement measures aimed at reducing vulnerabilities, including mechanisms to detect and block cyberattacks and restrictions on access to administrative interfaces. Finally, the DPA ordered the controller to ensure compliance with Article 4(5) of Law No. 506\u002F2004 on its website.In addition, as corrective measures, the DPA ordered the controller to implement a procedural plan for the regular testing, evaluation, and updating of its IT systems. The DPA also required the controller to strengthen access controls by introducing stronger password requirements, multi-factor authentication, the deactivation of inactive accounts, and the principle of least privilege. Furthermore, the DPA required the controller to implement measures aimed at reducing vulnerabilities, including mechanisms to detect and block cyberattacks and restrictions on access to administrative interfaces. Finally, the DPA ordered the controller to ensure compliance with Article 4(5) of Law No. 506\u002F2004 on its website. Latest revision as of 04:31, 6 August 2026 ANSPDCP - Fine against Homelux SRL Authority: ANSPDCP (Romania) Jurisdiction: Romania Relevant Law: Article 32(1)(d) GDPR Article 32(2) GDPR Article 4 (5) Law 506\u002F2004 (implementing ePrivacy Directive) Type: Investigation Outcome: Violation Found Started: Decided: Published: 31.07.2026 Fine: 108570.0 RON Parties: HOMELUX S.R.L. National Case Number\u002FName: Fine against Homelux SRL European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Romanian; Moldavian; Moldovan Original Source: ANSPDCP (in RO) Initial Contributor: cerasela The DPA fined a home and furniture retailer RON 78,570 (€15,000) after a cyberattack exploited an outdated website platform and weak passwords. It also imposed a RON 30,000 (€5,715) fine for placing non-essential cookies without consent. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR. The controller was operating a website on a platform that had not been updated to the latest version released by the software provider. Thus, a cyberattack exploited this vulnerability and affected the personal data processed through the website. This incident was further facilitated by weak password requirements for user accounts, a deficiency that remained unremedied after the breach. As a result, personal data processed by the controller, including names, surnames, addresses, email addresses, and passwords, was disclosed to unauthorised parties. During the investigation, the DPA also found that the controller stored non-essential cookies on users' devices and accessed this information without obtaining the users' prior consent. Holding First, the DPA found that the controller infringed Article 32 GDPR by failing to implement adequate technical and organisational measures to ensure a level of security appropriate to the risk presented by the processing. These shortcomings enabled a cyberattack that compromised personal data. The DPA also found that the controller had failed to establish a process for regularly testing, assessing, and evaluating the e","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=ANSPDCP_(Romania)_-_Fine_against_Homelux_SRL&diff=52630&oldid=52629","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fc\u002Fc2\u002FLogoRO.jpg","2026-08-06T04:31:56+00:00","2026-08-06T06:00:12.634282+00:00",7,[18,21],{"name":19,"type":20},"Homelux SRL","vendor",{"name":22,"type":23},"website platform","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":24,"icon":26,"name":27,"slug":28},null,"Policy","policy",[30,35,40],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":41},{"id":42,"icon":26,"name":43,"slug":44},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]