[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f8xl1_deCFE2p25LXAweGo45pqrqoQLNGqSLS5HptXco":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":46},"bcc0a5e8-ffc5-4b61-9d1a-dcda21c056d1","romanian-dpa-fines-ai-directory-for-invalid-cookie-consent","1cf52e1e-eeff-4c84-8989-7daf5b8331c2","Romanian DPA Fines AI Directory for Invalid Cookie Consent","There's an AI for that S.R.L was fined RON 30,000 for storing non-essential cookies on user devices without obtaining valid, informed consent — a direct violation of Article 5(3) of the ePrivacy Directive. This case highlights that even smaller or niche tech companies are not exempt from EU privacy regulations, and that cookie compliance is a legal obligation, not an optional UX feature. The failure stemmed from inadequate configuration of cookie mechanisms and likely a lack of legal review of consent workflows. This matters because non-compliant cookie practices erode user trust, expose companies to regulatory fines, and may signal broader gaps in an organisation's data governance posture.","**Immediate actions:**\n- Audit all cookies currently deployed on your website and classify them as essential or non-essential using a cookie scanning tool.\n- Implement a compliant Consent Management Platform (CMP) that withholds non-essential cookies until explicit user consent is obtained.\n\n**Policy & Legal alignment:**\n- Review your cookie policy and privacy notice to ensure they clearly describe each cookie category, its purpose, and retention period.\n- Engage a legal or DPO (Data Protection Officer) review of your consent flows to verify compliance with ePrivacy Directive Article 5(3) and applicable national law.\n\n**Long-term improvements:**\n- Establish a recurring cookie compliance review cycle (at least annually or upon any significant website change).\n- Integrate privacy-by-design principles into your development lifecycle so consent mechanisms are validated before any new tracking technology is deployed.\n- Maintain documented records of consent configurations and audit logs to demonstrate accountability to regulators.",[12,13,14,15,16,17,18,19],"ePrivacy Directive Article 5(3)","GDPR Article 7 – Conditions for consent","GDPR Article 5(1)(a) – Lawfulness, fairness and transparency","GDPR Article 13 – Information to be provided where personal data are collected","NIST Privacy Framework PR.CO-P3 – Communication of privacy practices","CIS Control 3 – Data Protection","ISO\u002FIEC 27001:2022 Annex A 5.34 – Privacy and protection of PII","IAB Europe Transparency & Consent Framework (TCF)","published","2026-07-24T14:20:55.0689+00:00","2026-07-24T14:20:54.664+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=ANSPDCP_(Romania)_-_Fine_against_There%27s_an_AI_for_that_S.R.L&diff=52486&oldid=49912","anspdcp-romania-fine-against-there-s-an-ai-for-that-s-r-l-204fde","ANSPDCP (Romania) - Fine against There's an AI for that S.R.L",[28,34,40],{"id":29,"name":30,"slug":31,"description":32,"color":33},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":35,"name":36,"slug":37,"description":38,"color":39},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":41,"name":42,"slug":43,"description":44,"color":45},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]