Awareness Lessons
4 weeks ago
Romanian DPA Fines Dormeo Home for Ignoring Customer Opt-Out Requests
Dormeo Home S.R.L. was fined €2,000 by Romania's data protection authority for continuing to send marketing communications after a customer explicitly exercised their GDPR right to object. This violation highlights a failure to operationalize data subject rights into actual business processes — the opt-out request was received but not acted upon. Such failures erode customer trust, expose organizations to regulatory penalties, and demonstrate that GDPR compliance must be embedded in day-to-day operations, not just documented in policies. Even relatively small fines carry reputational damage and signal a systemic breakdown in data governance.
Tactical Insight
Immediate actions
- Establish a centralized suppression/opt-out list that is immediately updated and propagated to all marketing platforms upon receipt of a right-to-object request.
- Audit all active marketing campaigns to verify that existing opt-out records are being honored across email, SMS, and phone channels.
Process & Governance improvements
- Define and enforce a maximum response SLA (e.g., 72 hours) for processing data subject rights requests, with documented accountability.
- Implement a mandatory pre-send suppression check that cross-references contact lists against the opt-out database before any campaign is executed.
- Assign a designated Data Protection Officer or compliance owner responsible for overseeing and auditing the handling of data subject requests.
Detection & Monitoring measures
- Log all data subject rights requests with timestamps and resolution status, and generate alerts if requests remain unresolved beyond the defined SLA.
- Conduct quarterly compliance audits of marketing systems to verify that opt-out mechanisms are functioning correctly end-to-end.