18.08.2025
Sanction for infringing GDPR
The National Supervisory Authority for Personal Data Processing, completed, in July 2025, an investigation at the controller SC Elite Conta SRL and found a violation of the provisions of Article 32 paragraph (1) letters b) and d) and Article 32 paragraph (2) of Regulation (EU) 2016/679.
As such, the controller was sanctioned with a fine of 15,227.70 lei (the equivalent of 3,000 euros).
The investigation was initiated following the transmission by the controller of a notification regarding the breach of personal data security, according to the provisions of Article 33 of Regulation (EU) 2016/679.
Thus, the controller notified the fact that, following a cyberattack, a series of categories of personal data of a significant number of data subjects were affected, such as: name, surname, personal identification number, series and number of the identity card, signature, domicile, position and salary.
At the same time, during the investigation, it emerged that the controller had not implemented, at the time of the cyberattack, security measures with specific requirements regarding secure access to network storage equipment that would reduce the risk of unauthorized access to the aforementioned personal data.
As a result, it was found that SC Elite Conta SRL did not implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of the processing, including the ability to ensure the confidentiality of the processing systems and services and a process for periodically testing, evaluating and assessing the effectiveness of the technical and organizational measures.
This situation led to the unauthorized disclosure or unauthorized access by a third party to personal data held by the controller, thus violating the provisions of Article 32 paragraph (1) letters b) and d) and paragraph (2) of Regulation (EU) 2016/679.
Pursuant to Article 58 paragraph (2) letter d) of Regulation (EU) 2016/679, the corrective measure to implement appropriate technical and organizational measures, including by ensuring operating systems with active support from the manufacturer, complete and updated antivirus solutions on all IT equipment in the Elite Conta SRL network (servers, work devices), respectively securing external access, as appropriate, to the Elite Conta SRL infrastructure equipment (VPN, MFA, IP restriction) was also ordered.
We mention that the controller paid the fine imposed.
Legal and Communication Department
A.N.S.P.D.C.P