Back to all lessons
Awareness Lessons
4 weeks ago

Romanian DPA Fines Dormeo Home for Ignoring Customer Opt-Out Requests

Dormeo Home S.R.L. was fined €2,000 by Romania's data protection authority for continuing to send marketing communications after a customer explicitly exercised their GDPR right to object. This violation highlights a failure to operationalize data subject rights into actual business processes — the opt-out request was received but not acted upon. Such failures erode customer trust, expose organizations to regulatory penalties, and demonstrate that GDPR compliance must be embedded in day-to-day operations, not just documented in policies. Even relatively small fines carry reputational damage and signal a systemic breakdown in data governance.

Tactical Insight

Immediate actions

  • Establish a centralized suppression/opt-out list that is immediately updated and propagated to all marketing platforms upon receipt of a right-to-object request.
  • Audit all active marketing campaigns to verify that existing opt-out records are being honored across email, SMS, and phone channels.

Process & Governance improvements

  • Define and enforce a maximum response SLA (e.g., 72 hours) for processing data subject rights requests, with documented accountability.
  • Implement a mandatory pre-send suppression check that cross-references contact lists against the opt-out database before any campaign is executed.
  • Assign a designated Data Protection Officer or compliance owner responsible for overseeing and auditing the handling of data subject requests.

Detection & Monitoring measures

  • Log all data subject rights requests with timestamps and resolution status, and generate alerts if requests remain unresolved beyond the defined SLA.
  • Conduct quarterly compliance audits of marketing systems to verify that opt-out mechanisms are functioning correctly end-to-end.