Romanian Cosmetics Retailer Fined €5,000 for GDPR Security Failures After Cyberattack
GEROCOSSEN S.R.L. failed to implement adequate technical and organizational security measures as required by GDPR Article 32, leaving its IT infrastructure vulnerable to a cyberattack that resulted in a personal data breach. This case illustrates that GDPR compliance is not merely a documentation exercise — it demands active, demonstrable security controls proportionate to the risks of processing personal data. Regulators increasingly hold organizations accountable not just for breaches themselves, but for the absence of preventive security practices that could have reduced the likelihood or impact of an attack. Even smaller retailers handling customer data must treat data protection as a core operational responsibility, not an afterthought.
Tactical Insight
Immediate Actions
- Conduct a rapid security assessment of all IT systems that store or process personal data to identify exploitable vulnerabilities.
- Enforce strong authentication (MFA) on all systems containing customer personal data to reduce unauthorized access risk.
Long-term Improvements
- Establish a formal Information Security Management System (ISMS) aligned with ISO 27001 or NIST CSF to ensure ongoing GDPR Article 32 compliance.
- Perform regular penetration testing and vulnerability assessments on internet-facing assets at least annually.
- Document and maintain a data inventory mapping what personal data is held, where it lives, and what controls protect it.
Detection & Response Measures
- Deploy security monitoring and alerting tools (SIEM/EDR) to detect anomalous activity on systems holding personal data.
- Create and rehearse a Data Breach Response Plan that includes GDPR-mandated 72-hour breach notification procedures to supervisory authorities.