[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fzy09uzF-uBdSnxRZhwSNTgp5k7Gr-kwJbNrVUC6UaHE":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"4f4bb566-ae4a-48df-9196-070f1b4d42a0","ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026","anspdcp-romania-fine-against-orange-romania-sa-of-july-17-2026-80bbd7","Small amendments to short summary ← Older revision Revision as of 08:28, 22 July 2026 Line 69: Line 69: }} }} A telecom company received a €100,000 fine for breaching Articles 25 and 32 GDPR by failing to implement adequate technical and organizational safeguards and ensure the security of personal data processing. The DPA fined €100,000 a telecom company for breaching Article 25 GDPR and Article 32 GDPR by failing to implement adequate technical and organizational safeguards and ensure the security of personal data processing. == English Summary == == English Summary == Line 79: Line 79: === Holding === === Holding === The investigation was initiated after the controller notified the DPA of a personal data breach pursuant to [[Article 33 GDPR|Article 33 GDPR]]. The investigation was initiated after the controller notified the DPA of a personal data breach pursuant to [[Article 33 GDPR]]. First, the DPA found that the controller infringed [[Article 25 GDPR|Article 25 GDPR]] by failing to implement appropriate technical and organisational measures when designing and operating its digital platforms. The DPA considered that these shortcomings enabled unauthorised access to personal data and failed to adequately protect data subjects' rights. For this infringement, the DPA imposed a fine of €20,000. First, the DPA found that the controller infringed [[Article 25 GDPR]] by failing to implement appropriate technical and organisational measures when designing and operating its digital platforms. The DPA considered that these shortcomings enabled unauthorised access to personal data and failed to adequately protect data subjects' rights. For this infringement, the DPA imposed a fine of €20,000. Second, the DPA found that the controller infringed [[Article 32 GDPR|Article 32 GDPR]] by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The DPA noted that the controller had not adequately secured its platforms and had failed to regularly test and assess the effectiveness of its security measures. For this infringement, the DPA imposed a fine of €80,000. Second, the DPA found that the controller infringed [[Article 32 GDPR]] by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The DPA noted that the controller had not adequately secured its platforms and had failed to regularly test and assess the effectiveness of its security measures. For this infringement, the DPA imposed a fine of €80,000. In addition, as a corrective measure, the DPA ordered the controller to implement a monitoring and testing process for all IT applications used in its activities. The process must include controls over software changes and vulnerability testing. In addition, as a corrective measure, the DPA ordered the controller to implement a monitoring and testing process for all IT applications used in its activities. The process must include controls over software changes and vulnerability testing. == Comment == == Comment == The decision illustrates the Romanian DPA's focus on enforcing the requirements of [[Article 25 GDPR|Article 25 GDPR]] and [[Article 32 GDPR|Article 32 GDPR]]. The DPA fined Orange Romania €100,000 for failures that led to unauthorised disclosures of personal data and a large-scale data breach, and ordered the company to strengthen its application monitoring and vulnerability-testing processes. The case follows a previous enforcement action against Orange Romania, which resulted in a €40,000 fine in 2025 for infringements relating to data subjects' rights and the unlawful retention of personal data. The decision illustrates the Romanian DPA's focus on enforcing the requirements of [[Article 25 GDPR]] and [[Article 32 GDPR]]. The DPA fined Orange Romania €100,000 for failures that led to unauthorised disclosures of personal data and a large-scale data breach, and ordered the company to strengthen its application monitoring and vulnerability-testing processes. The case follows a previous enforcement action against Orange Romania, which resulted in a €40,000 fine in 2025 for infringements relating to data subjects' rights and the unlawful retention of personal data. == Further Resources == == Further Resources ==","The Romanian Data Protection Authority (ANSPDCP) has fined Orange Romania SA €100,000 for breaching GDPR Articles 25 and 32. The company failed to implement adequate technical and organizational safeguards, leading to unauthorized access to personal data and a data breach. In addition to the fine, Orange Romania was ordered to implement enhanced monitoring and vulnerability testing for its IT applications.","Orange Romania fined €100,000 for GDPR violations related to data breach.","Help ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 17:04, 21 July 2026 view sourceCerasela (talk | contribs)1 edit Tag: submission [1.0] Latest revision as of 08:28, 22 July 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators221 editsm Tag: Visual edit Line 69: Line 69: }}}} A telecom company received a €100,000 fine for breaching Articles 25 and 32 GDPR by failing to implement adequate technical and organizational safeguards and ensure the security of personal data processing.The DPA fined €100,000 a telecom company for breaching Article 25 GDPR and Article 32 GDPR by failing to implement adequate technical and organizational safeguards and ensure the security of personal data processing. == English Summary ==== English Summary == Line 79: Line 79: === Holding ====== Holding === The investigation was initiated after the controller notified the DPA of a personal data breach pursuant to [[Article 33 GDPR|Article 33 GDPR]].The investigation was initiated after the controller notified the DPA of a personal data breach pursuant to [[Article 33 GDPR]]. First, the DPA found that the controller infringed [[Article 25 GDPR|Article 25 GDPR]] by failing to implement appropriate technical and organisational measures when designing and operating its digital platforms. The DPA considered that these shortcomings enabled unauthorised access to personal data and failed to adequately protect data subjects' rights. For this infringement, the DPA imposed a fine of €20,000.First, the DPA found that the controller infringed [[Article 25 GDPR]] by failing to implement appropriate technical and organisational measures when designing and operating its digital platforms. The DPA considered that these shortcomings enabled unauthorised access to personal data and failed to adequately protect data subjects' rights. For this infringement, the DPA imposed a fine of €20,000. Second, the DPA found that the controller infringed [[Article 32 GDPR|Article 32 GDPR]] by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The DPA noted that the controller had not adequately secured its platforms and had failed to regularly test and assess the effectiveness of its security measures. For this infringement, the DPA imposed a fine of €80,000.Second, the DPA found that the controller infringed [[Article 32 GDPR]] by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The DPA noted that the controller had not adequately secured its platforms and had failed to regularly test and assess the effectiveness of its security measures. For this infringement, the DPA imposed a fine of €80,000. In addition, as a corrective measure, the DPA ordered the controller to implement a monitoring and testing process for all IT applications used in its activities. The process must include controls over software changes and vulnerability testing.In addition, as a corrective measure, the DPA ordered the controller to implement a monitoring and testing process for all IT applications used in its activities. The process must include controls over software changes and vulnerability testing. == Comment ==== Comment == The decision illustrates the Romanian DPA's focus on enforcing the requirements of [[Article 25 GDPR|Article 25 GDPR]] and [[Article 32 GDPR|Article 32 GDPR]]. The DPA fined Orange Romania €100,000 for failures that led to unauthorised disclosures of personal data and a large-scale data breach, and ordered the company to strengthen its application monitoring and vulnerability-testing processes. The case follows a previous enforcement action against Orange Romania, which resulted in a €40,000 fine in 2025 for infringements relating to data subjects' rights and the unlawful retention of personal data.The decision illustrates the Romanian DPA's focus on enforcing the requirements of [[Article 25 GDPR]] and [[Article 32 GDPR]]. The DPA fined Orange Romania €100,000 for failures that led to unauthorised disclosures of personal data and a large-scale data breach, and ordered the company to strengthen its application monitoring and vulnerability-testing processes. The case follows a previous enforcement action against Orange Romania, which resulted in a €40,000 fine in 2025 for infringements relating to data subjects' rights and the unlawful retention of personal data. == Further Resources ==== Further Resources == Latest revision as of 08:28, 22 July 2026 ANSPDCP - Fine against Orange Romania SA of July 17, 2026 Authority: ANSPDCP (Romania) Jurisdiction: Romania Relevant Law: Article 25(1) GDPR Article 32(1)(b) GDPR Article 32(1)(d) GDPR Article 32(2) GDPR Article 32(4) GDPR Type: Investigation Outcome: Violation Found Started: Decided: Published: 17.07.2026 Fine: 100,000 EUR Parties: Orange Romania SA National Case Number\u002FName: Fine against Orange Romania SA of July 17, 2026 European Case Law Identifier: n\u002Fa Appeal: Unknown Original Language(s): Romanian Original Source: ANSPDCP (in RO) Initial Contributor: cerasela The DPA fined €100,000 a telecom company for breaching Article 25 GDPR and Article 32 GDPR by failing to implement adequate technical and organizational safeguards and ensure the security of personal data processing. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A customer (the data subject) of Orange Romania SA (the controller) was able to access and download invoices belonging to other customers. As a result, personal data such as names, addresses, delivery addresses, ID document details, and invoice information were disclosed. The incident was caused by a mismatch between two interconnected applications, which incorrectly linked the data subject's account to an employee account. During the investigation, another vulnerability was identified in the controller's ticketing application. The platform was publicly accessible and lacked adequate security measures, such as VPN protection, multi-factor authentication, and IP-based access restrictions. This vulnerability enabled a cyberattack that resulted in the theft of a large volume of personal data, including names, contact details, national identification numbers, copies of identity documents, banking-related information, login credentials, customer codes, and IBAN numbers. Holding The investigation was initiated after the controller notified the DPA of a personal data breach pursuant to Article 33 GDPR. First, the DPA found that the controller infringed Article 25 GDPR by failing to implement appropriate technical and organisational measures when designing and operating its digital platforms. The DPA considered that these shortcomings enabled unauthorised access to personal data and failed to adequately protect data subjects' rights. For this infringement, the DPA imposed a fine of €20,000. Second, the DPA found that the controller infringed Article 32 GDPR by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The DPA noted that the controller had not adequately secured its platforms and had failed to regularly test and assess the effectiveness of its security measures. For this infringement, the DPA imposed a fine of €80,000. In addition, as a corrective measure, the DPA ordered the controller to implement a monitoring and testing process for all IT applications used in its activities. The process must include controls over software changes and vulnerability testing. Comment The decision illustrates the Romanian DPA's focus on enforcing the requirements of Article 25 GDPR and Article 32 GDPR. The DPA fined Orange Romania €100,000 for failures that ","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=ANSPDCP_(Romania)_-_Fine_against_Orange_Romania_SA_of_July_17,_2026&diff=52440&oldid=52429","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fc\u002Fc2\u002FLogoRO.jpg","2026-07-22T08:28:49+00:00","2026-07-22T10:00:21.282064+00:00",7,[18,21],{"name":19,"type":20},"Orange Romania SA","vendor",{"name":22,"type":23},"digital platforms","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":24,"icon":26,"name":27,"slug":28},null,"Policy","policy",[30,35,40,45],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":41},{"id":42,"icon":26,"name":43,"slug":44},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":46},{"id":47,"icon":26,"name":48,"slug":49},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]