ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026
Romania's DPA fines Orange Romania €100K for inadequate data security safeguards under GDPR Articles 25 and 32.
Summary
Romania's ANSPDCP (data protection authority) fined Orange Romania SA €100,000 (RON 523,900) on July 17, 2026, for breaching GDPR Articles 25 and 32 by failing to implement adequate technical and organizational security measures. The violations were identified after a data breach where customers could access other customers' invoices and personal data due to application misconfigurations, and a publicly accessible ticketing platform lacking VPN, MFA, and IP restrictions was exploited to steal customer data including names, IDs, banking info, and credentials.
Full text
Help ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 17:15, 22 July 2026 view sourceCerasela (talk | contribs)3 editsmTag: Visual edit← Older edit Latest revision as of 12:06, 28 July 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators229 editsmTag: Visual edit Line 69: Line 69: }}}} The DPA fined RON 523,900 (€100,000) a telecom company for breaching Article 25 GDPR and Article 32 GDPR by failing to implement adequate technical and organizational safeguards and ensure the security of personal data processing.The DPA fined RON 523,900 (€100,000) a telecom company for breaching Article 25 GDPR and Article 32 GDPR by failing to implement adequate technical and organisational safeguards and ensure the security of personal data processing. == English Summary ==== English Summary == Latest revision as of 12:06, 28 July 2026 ANSPDCP - Fine against Orange Romania SA of July 17, 2026 Authority: ANSPDCP (Romania) Jurisdiction: Romania Relevant Law: Article 25(1) GDPR Article 32(1)(b) GDPR Article 32(1)(d) GDPR Article 32(2) GDPR Article 32(4) GDPR Type: Investigation Outcome: Violation Found Started: Decided: Published: 17.07.2026 Fine: 523,900 RON Parties: Orange Romania SA National Case Number/Name: Fine against Orange Romania SA of July 17, 2026 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Romanian Original Source: ANSPDCP (in RO) Initial Contributor: cerasela The DPA fined RON 523,900 (€100,000) a telecom company for breaching Article 25 GDPR and Article 32 GDPR by failing to implement adequate technical and organisational safeguards and ensure the security of personal data processing. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A customer (the data subject) of Orange Romania SA (the controller) was able to access and download invoices belonging to other customers. As a result, personal data such as names, addresses, delivery addresses, ID document details, and invoice information were disclosed. The incident was caused by a mismatch between two interconnected applications, which incorrectly linked the data subject's account to an employee account. During the investigation, another vulnerability was identified in the controller's ticketing application. The platform was publicly accessible and lacked adequate security measures, such as VPN protection, multi-factor authentication, and IP-based access restrictions. This vulnerability enabled a cyberattack that resulted in the theft of a large volume of personal data, including names, contact details, national identification numbers, copies of identity documents, banking-related information, login credentials, customer codes, and IBAN numbers. Holding The investigation was initiated after the controller notified the DPA of a personal data breach pursuant to Article 33 GDPR. First, the DPA found that the controller infringed Article 25 GDPR by failing to implement appropriate technical and organisational measures when designing and operating its digital platforms. The DPA considered that these shortcomings enabled unauthorised access to personal data and failed to adequately protect data subjects' rights. For this infringement, the DPA imposed a fine of RON 104,780 (€20,000). Second, the DPA found that the controller infringed Article 32 GDPR by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The DPA noted that the controller had not adequately secured its platforms and had failed to regularly test and assess the effectiveness of its security measures. For this infringement, the DPA imposed a fine of RON 419,120 (€80,000). In addition, as a corrective measure, the DPA ordered the controller to implement a monitoring and testing process for all IT applications used in its activities. The process must include controls over software changes and vulnerability testing. Comment The decision illustrates the Romanian DPA's focus on enforcing the requirements of Article 25 GDPR and Article 32 GDPR. The DPA fined Orange Romania €100,000 for failures that led to unauthorised disclosures of personal data and a large-scale data breach, and ordered the company to strengthen its application monitoring and vulnerability-testing processes. The case follows a previous enforcement action against Orange Romania, which resulted in a €40,000 fine in 2025 for infringements relating to data subjects' rights and the unlawful retention of personal data. Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Romanian original. Please refer to the Romanian original for more details. The National Supervisory Authority for Personal Data Processing completed, in June 2026, an investigation at the operator Orange Romania SA and found a violation of the provisions of art. 25 paragraph (1), art. 32 paragraph (1) letter b) and d) and art. 32 paragraph (2) and (4) of Regulation (EU) 2016/679. Consequently, Orange Romania SA was sanctioned with two fines in the amount of 523,900 lei (equivalent to 100,000 EURO), as follows: 1. with a fine in the amount of 104,780 lei (equivalent to 20,000 euros) for violating the provisions of art. 25 paragraph (1) of Regulation (EU) 2016/679, regarding the lack of implementation of appropriate technical and organizational measures, both at the time of establishing the means of processing and during the actual processing; 2. with a fine in the amount of 419,120 lei (equivalent to the amount of 80,000 euros) for violating the provisions of art. 32 paragraph (1) letter b) and d), paragraphs (2) and (4) of Regulation (EU) 2016/679, regarding the lack of implementation of appropriate technical and organizational measures to ensure the confidentiality and appropriate security of the processing. The investigation was initiated following the transmission by the operator of a notification regarding the breach of personal data security, according to the provisions of art. 33 of Regulation (EU) 2016/679. Thus, the operator notified that the security incident occurred in the mobile application owned by it, where a customer was able to access and download equipment invoices belonging to other customers. This occurred as a result of a synchronization error between two interconnected applications of the operator which thus generated a wrong identification between a customer account and that of a company employee. Regarding this aspect, during the investigation, it was found that the operator did not implement adequate technical and organizational measures when configuring and using its digital platforms to protect the rights of its users. This situation led to the unauthorized disclosure of personal data of several data subjects, such as: name, surname, home address, delivery address, series and number of the identity card, series and number of the invoice, date of its issuance, thus violating the provisions of art. 25 paragraph. (1) of Regulation (EU) 2016/679. At the same time, during the investigation, it was also found that the operator did not implement adequate technical and organizational measures to ensure an appropriate level of security to protect the managed platforms and did not periodically test the effectiveness of the security systems. This vulnerability allowed a cyber attack on the access security in the operator's ticketing application, which thus led to unauthorized access and unauthorized disclosure of personal data transmitted, stored or processed. The platform was publicly exposed without security measures, such as secure connection (VPN), two-step authentication (MFA) or IP-based access restriction. As a result, a ver