[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fOKEDMqATIXWtCRDeICO6okfJRSi6q5fVSAdLQcEIBOM":3},{"article":4,"iocs":49},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":26,"category":27,"article_tags":31},"98c2b2d2-f0fe-433b-8555-5848056d4ec4","ANSPDCP (Romania) - Fine against Homelux SRL","anspdcp-romania-fine-against-homelux-srl-9a712b","Created page with \"{{DPAdecisionBOX |Jurisdiction=Romania |DPA-BG-Color= |DPAlogo=LogoRO.jpg |DPA_Abbrevation=ANSPDCP |DPA_With_Country=ANSPDCP (Romania) |Case_Number_Name=Fine against Homelux SRL |ECLI= |Original_Source_Name_1=ANSPDCP |Original_Source_Link_1=https:\u002F\u002Fwww.dataprotection.ro\u002F?page=Comunicat_Presa_31.07.2026&lang=ro |Original_Source_Language_1=Romanian; Moldavian; Moldovan |Original_Source_Language__Code_1=RO |Original_Source_Name_2= |Original_Source_Link_2= |Original_So...\" New page {{DPAdecisionBOX |Jurisdiction=Romania |DPA-BG-Color= |DPAlogo=LogoRO.jpg |DPA_Abbrevation=ANSPDCP |DPA_With_Country=ANSPDCP (Romania) |Case_Number_Name=Fine against Homelux SRL |ECLI= |Original_Source_Name_1=ANSPDCP |Original_Source_Link_1=https:\u002F\u002Fwww.dataprotection.ro\u002F?page=Comunicat_Presa_31.07.2026&lang=ro |Original_Source_Language_1=Romanian; Moldavian; Moldovan |Original_Source_Language__Code_1=RO |Original_Source_Name_2= |Original_Source_Link_2= |Original_Source_Language_2= |Original_Source_Language__Code_2= |Type=Investigation |Outcome=Violation Found |Date_Started= |Date_Decided= |Date_Published=31.07.2026 |Year=2026 |Fine=108570.0 |Currency=RON |GDPR_Article_1=Article 32(1)(d) GDPR |GDPR_Article_Link_1=Article 32 GDPR#1d |GDPR_Article_2=Article 32(2) GDPR |GDPR_Article_Link_2=Article 32 GDPR#2 |GDPR_Article_3= |GDPR_Article_Link_3= |GDPR_Article_4= |GDPR_Article_Link_4= |EU_Law_Name_1= |EU_Law_Link_1= |EU_Law_Name_2= |EU_Law_Link_2= |National_Law_Name_1=Article 4 (5) Law 506\u002F2004 (implementing ePrivacy Directive) |National_Law_Link_1=https:\u002F\u002Flegislatie.just.ro\u002FPublic\u002FDetaliiDocument\u002F56973 |National_Law_Name_2= |National_Law_Link_2= |National_Law_Name_3= |National_Law_Link_3= |Party_Name_1=HOMELUX S.R.L. |Party_Link_1=https:\u002F\u002Fwww.homelux.ro\u002F |Party_Name_2= |Party_Link_2= |Party_Name_3= |Party_Link_3= |Appeal_To_Body= |Appeal_To_Case_Number_Name= |Appeal_To_Status= |Appeal_To_Link= |Initial_Contributor=cerasela | }} The DPA fined a home and furniture retailer RON 78,570 (€15,000) after a cyberattack exploited an outdated website platform and weak passwords. It also imposed a RON 30,000 (€5,715) fine for placing non-essential cookies without consent. == English Summary == === Facts === HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to [[Article 33 GDPR|Article 33 GDPR]]. The controller was operating a website on a platform that had not been updated to the latest version released by the software provider. Thus, a cyberattack exploited this vulnerability and affected the personal data processed through the website. This incident was further facilitated by weak password requirements for user accounts, a deficiency that remained unremedied after the breach. As a result, personal data processed by the controller, including names, surnames, addresses, email addresses, and passwords, was disclosed to unauthorised parties. During the investigation, the DPA also found that the controller stored non-essential cookies on users' devices and accessed this information without obtaining the users' prior consent. === Holding === First, the DPA found that the controller infringed [[[[Article 32 GDPR|Article 32 GDPR]]#1d]] and [[[[Article 32 GDPR|Article 32 GDPR]]#2]] by failing to implement adequate technical and organisational measures to ensure a level of security appropriate to the risk presented by the processing. These shortcomings enabled a cyberattack that compromised personal data. The DPA also found that the controller had failed to establish a process for regularly testing, assessing, and evaluating the effectiveness of its security measures. For this infringement, the DPA imposed a fine of RON 78,570 (€15,000). Second, the DPA found that the controller infringed Article 4(5) of Law No. 506\u002F2004 on the processing of personal data and the protection of privacy in the electronic communications sector by placing non-essential cookies on users' devices without obtaining prior consent. The DPA noted that these cookies were not technically necessary for the operation of the website and therefore could not be deployed without user consent. For this infringement, the DPA imposed a fine of RON 30,000 (€5,715). In addition, as corrective measures, the DPA ordered the controller to implement a procedural plan for the regular testing, evaluation, and updating of its IT systems. The DPA also required the controller to strengthen access controls by introducing stronger password requirements, multi-factor authentication, the deactivation of inactive accounts, and the principle of least privilege. Furthermore, the DPA required the controller to implement measures aimed at reducing vulnerabilities, including mechanisms to detect and block cyberattacks and restrictions on access to administrative interfaces. Finally, the DPA ordered the controller to ensure compliance with Article 4(5) of Law No. 506\u002F2004 on its website. == Comment == This case shows that basic security weaknesses, such as outdated software and weak password policies, can lead to significant GDPR liability when they contribute to a personal data breach. It also underlines that cookie compliance remains a distinct enforcement area, capable of attracting additional fines alongside GDPR sanctions. == Further Resources == ''Share blogs or news articles here!'' == English Machine Translation of the Decision == The decision below is a machine translation of the Romanian; Moldavian; Moldovan original. Please refer to the Romanian; Moldavian; Moldovan original for more details. July 31, 2026 Penalty for Violating the GDPR and Law No. 506\u002F2004 In June 2026, the National Supervisory Authority for Personal Data Processing concluded an investigation into the data controller HOMELUX S.R.L. and found a violation of Article 32( (1)(d) and paragraph (2) of Regulation (EU) 2016\u002F679, as well as a violation of Article 4, paragraph (5) of Law No. 506\u002F2004 on the processing of personal data and the protection of privacy in the electronic communications sector. Accordingly, the data controller was issued the following administrative penalty: a fine of 78,570 lei, equivalent to 15,000 euros, for violating the provisions of Article 32(1)(d) and (2) (2) of Regulation (EU) 2016\u002F679; a fine of 30,000 lei for violating Article 4(5) of Law 506\u002F2004. The investigation was initiated following the submission by the data controller, HOMELUX S.R.L., of a notification of a personal data breach, in accordance with the provisions of Article 33 of Regulation (EU) 2016\u002F679. During the investigation, it was determined that the incident was caused by a cyberattack on the platform supporting the operation of the website administered by the data controller; at the time of the incident, the platform did not technically comply with the official version released by the manufacturer. At the same time, it was found that the incident was also facilitated by the low complexity of the passwords used when creating accounts on the operator’s website, a deficiency that was not remedied after the incident. The investigation revealed that the operator failed to ensure adequate security of the processed data (first names, last names, addresses, email addresses, and passwords), including protection against unauthorized or illegal processing, as well as accidental loss, destruction, or damage. As such, it was found that the operator had not implemented adequate technical and organizational measures to ensure a level of security appropriate to the risk posed by the processing, including, among other things, the ability to ensure the confidentiality of processing systems and services, as well as the establishment of a process for the periodic testing, evaluation, and assessment of the effectiveness of technical and organizational measures to guarantee the security of the processing. Furthermore, during the investigation, it was found that the controller stored information—specifically, cookies—that were not technically necessary for the operation of its website and accessed information stored on the terminal equipment of the website’s users, without obtaining their consent. At the same time, the National Supervisory Authority also imposed the following corrective measures, ordering the controller to: implement a procedural plan that includes a process for the periodic testing, evaluation, and assessment of all systems and subsequent modifications thereto made by the operator or service providers (authorized persons), particularly with regard to the website it administers; implement appropriate technical and organizational measures to control and secure access to accounts created on the website administered by the operator, including by establishing minimum password complexity requirements, use multi-factor authentication for accounts with administrative privileges, manage and deactivate inactive accounts, and apply the principle of least privilege; implement appropriate technical measures to protect the web application against unauthorized access and the exploitation of vulnerabilities, including mechanisms to detect and block attack attempts, validate and filter user-entered data, and restrict access to administrative interfaces, in order to ensure the confidentiality, integrity, and availability of the personal data being processed; for the website administered by the controller, the conditions set forth in Article 4(5) of Law 506\u002F2004 must be cumulatively met. Legal and Communications Department A.N.S.P.D.C.P","The Romanian Data Protection Authority (ANSPDCP) has fined Homelux SRL a total of RON 108,570 (approximately €20,715) for two distinct violations. A cyberattack exploited an outdated website platform and weak passwords, leading to a data breach and a fine of RON 78,570 (€15,000) under GDPR Article 32. Additionally, Homelux SRL was fined RON 30,000 (€5,715) for placing non-essential cookies without user consent, violating national ePrivacy laws.","Romania's ANSPDCP fines Homelux SRL €15,000 for data breach and €5,715 for cookie violations.","Help ANSPDCP (Romania) - Fine against Homelux SRL: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 04:29, 6 August 2026 view source Cerasela (talk | contribs)5 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 04:29, 6 August 2026 ANSPDCP - Fine against Homelux SRL Authority: ANSPDCP (Romania) Jurisdiction: Romania Relevant Law: Article 32(1)(d) GDPR Article 32(2) GDPR Article 4 (5) Law 506\u002F2004 (implementing ePrivacy Directive) Type: Investigation Outcome: Violation Found Started: Decided: Published: 31.07.2026 Fine: 108570.0 RON Parties: HOMELUX S.R.L. National Case Number\u002FName: Fine against Homelux SRL European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Romanian; Moldavian; Moldovan Original Source: ANSPDCP (in RO) Initial Contributor: cerasela The DPA fined a home and furniture retailer RON 78,570 (€15,000) after a cyberattack exploited an outdated website platform and weak passwords. It also imposed a RON 30,000 (€5,715) fine for placing non-essential cookies without consent. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR. The controller was operating a website on a platform that had not been updated to the latest version released by the software provider. Thus, a cyberattack exploited this vulnerability and affected the personal data processed through the website. This incident was further facilitated by weak password requirements for user accounts, a deficiency that remained unremedied after the breach. As a result, personal data processed by the controller, including names, surnames, addresses, email addresses, and passwords, was disclosed to unauthorised parties. During the investigation, the DPA also found that the controller stored non-essential cookies on users' devices and accessed this information without obtaining the users' prior consent. Holding First, the DPA found that the controller infringed [[Article 32 GDPR#1d]] and [[Article 32 GDPR#2]] by failing to implement adequate technical and organisational measures to ensure a level of security appropriate to the risk presented by the processing. These shortcomings enabled a cyberattack that compromised personal data. The DPA also found that the controller had failed to establish a process for regularly testing, assessing, and evaluating the effectiveness of its security measures. For this infringement, the DPA imposed a fine of RON 78,570 (€15,000). Second, the DPA found that the controller infringed Article 4(5) of Law No. 506\u002F2004 on the processing of personal data and the protection of privacy in the electronic communications sector by placing non-essential cookies on users' devices without obtaining prior consent. The DPA noted that these cookies were not technically necessary for the operation of the website and therefore could not be deployed without user consent. For this infringement, the DPA imposed a fine of RON 30,000 (€5,715). In addition, as corrective measures, the DPA ordered the controller to implement a procedural plan for the regular testing, evaluation, and updating of its IT systems. The DPA also required the controller to strengthen access controls by introducing stronger password requirements, multi-factor authentication, the deactivation of inactive accounts, and the principle of least privilege. Furthermore, the DPA required the controller to implement measures aimed at reducing vulnerabilities, including mechanisms to detect and block cyberattacks and restrictions on access to administrative interfaces. Finally, the DPA ordered the controller to ensure compliance with Article 4(5) of Law No. 506\u002F2004 on its website. Comment This case shows that basic security weaknesses, such as outdated software and weak password policies, can lead to significant GDPR liability when they contribute to a personal data breach. It also underlines that cookie compliance remains a distinct enforcement area, capable of attracting additional fines alongside GDPR sanctions. Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Romanian; Moldavian; Moldovan original. Please refer to the Romanian; Moldavian; Moldovan original for more details. July 31, 2026 Penalty for Violating the GDPR and Law No. 506\u002F2004 In June 2026, the National Supervisory Authority for Personal Data Processing concluded an investigation into the data controller HOMELUX S.R.L. and found a violation of Article 32( (1)(d) and paragraph (2) of Regulation (EU) 2016\u002F679, as well as a violation of Article 4, paragraph (5) of Law No. 506\u002F2004 on the processing of personal data and the protection of privacy in the electronic communications sector. Accordingly, the data controller was issued the following administrative penalty: a fine of 78,570 lei, equivalent to 15,000 euros, for violating the provisions of Article 32(1)(d) and (2) (2) of Regulation (EU) 2016\u002F679; a fine of 30,000 lei for violating Article 4(5) of Law 506\u002F2004. The investigation was initiated following the submission by the data controller, HOMELUX S.R.L., of a notification of a personal data breach, in accordance with the provisions of Article 33 of Regulation (EU) 2016\u002F679. During the investigation, it was determined that the incident was caused by a cyberattack on the platform supporting the operation of the website administered by the data controller; at the time of the incident, the platform did not technically comply with the official version released by the manufacturer. At the same time, it was found that the incident was also facilitated by the low complexity of the passwords used when creating accounts on the operator’s website, a deficiency that was not remedied after the incident. The investigation revealed that the operator failed to ensure adequate security of the processed data (first names, last names, addresses, email addresses, and passwords), including protection against unauthorized or illegal processing, as well as accidental loss, destruction, or damage. As such, it was found that the operator had not implemented adequate technical and organizational measures to ensure a level of security appropriate to the risk posed by the processing, including, among other things, the ability to ensure the confidentiality of processing systems and services, as well as the establishment of a process for the periodic testing, evaluation, and assessment of the effectiveness of technical and organizational measures to guarantee the security of the processing. Furthermore, during the investigation, it was found that the controller stored information—specifically, cookies—that were not technically necessary for the operation of its website and accessed information stored on the terminal equipment of the website’s users, without obtaining their consent. At the same time, the National Supervisory Authority also imposed the following corrective measures, ordering the controller to: implement a procedural plan that includes a process for the periodic testing, evaluation, and assessment of all systems and subsequent modifications thereto made by the operator or service providers (authorized persons), particularly with regard to the website it administers; implement appropriate technical and organizational measures to control and secure access to accounts created on the website administered by the operator, including by establishing minimum password complexity requirements, use multi-factor authentication for accounts with administrative privileges, manage and deactivate inactive accounts, and apply the principle of least privilege; implement appropriate technical measures to protect the web application against unauthorized access and the exploita","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=ANSPDCP_(Romania)_-_Fine_against_Homelux_SRL&diff=52629&oldid=0","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fc\u002Fc2\u002FLogoRO.jpg","2026-08-06T04:29:24+00:00","2026-08-06T06:00:12.634282+00:00",7,[18,21,24],{"name":19,"type":20},"ANSPDCP","vendor",{"name":22,"type":23},"website platform","product",{"name":25,"type":20},"Homelux SRL","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":26,"icon":28,"name":29,"slug":30},null,"Policy","policy",[32,37,42,44],{"category":33},{"id":34,"icon":28,"name":35,"slug":36},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":38},{"id":39,"icon":28,"name":40,"slug":41},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":43},{"id":26,"icon":28,"name":29,"slug":30},{"category":45},{"id":46,"icon":28,"name":47,"slug":48},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]