Orange Romania Fined €100K for GDPR Failures in Data Protection and Security Controls
Orange Romania SA was fined €100,000 by the Romanian Data Protection Authority for failing to implement adequate technical and organizational measures as required by GDPR Articles 25 (Data Protection by Design and by Default) and 32 (Security of Processing). The breach resulted in unauthorized access to personal data, demonstrating that insufficient security controls in large telecommunications environments can directly expose customer information. This case underscores that GDPR compliance is not a checkbox exercise — regulators expect ongoing, demonstrable investment in security safeguards. The remediation order requiring enhanced monitoring and vulnerability testing signals that reactive security postures are no longer acceptable under European data protection law.
Tactical Insight
Immediate actions
- Conduct a gap assessment against GDPR Articles 25 and 32 to identify missing technical and organizational safeguards across all IT systems processing personal data.
- Perform an emergency vulnerability scan of all internet-facing and customer-data-handling applications to identify and remediate exploitable weaknesses.
Long-term improvements
- Embed Data Protection by Design principles into the software development lifecycle so security controls are built in from the start, not bolted on afterward.
- Establish a formal, recurring vulnerability management programme with defined SLAs for remediation based on risk severity.
- Maintain a comprehensive data mapping inventory to ensure all personal data flows are known, protected, and subject to appropriate access controls.
Detection & monitoring measures
- Deploy continuous security monitoring and anomaly detection on systems that store or process personal data to enable rapid identification of unauthorized access.
- Schedule regular penetration testing and third-party security audits of IT applications at least annually or after significant system changes.