03.04.2026
Fine for GDPR Infringement
The National Supervisory Authority for Personal Data Processing completed an investigation in April 2026 into the data controller BLUE PROJECTS S.R.L. and found infringements of Article 32(1)(b) and (d), as well as Article 32(2), of Regulation (EU) 2016/679.
Accordingly, the controller was fined 12,734 lei, equivalent to 2,500 euros.
The investigation was initiated following the submission by BLUE PROJECTS S.R.L. of a personal data breach notification pursuant to Article 33 of Regulation (EU) 2016/679.
During the investigation, it was established that a cyberattack targeting the controller’s IT infrastructure compromised the confidentiality and availability of the personal data stored within its systems. This resulted in unauthorized access to the personal data of a significant number of data subjects, including employees, contractors, and individuals involved in correspondence. The affected personal data included: first and last names, personal identification numbers (CNP), residential addresses, contact details, email addresses, job titles and curriculum vitae (CVs).
The investigation concluded that the controller had failed to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk posed by the processing activities. These measures should have included, among other things, the capability to ensure the ongoing confidentiality of processing systems and services, as well as the implementation of a process for regularly testing, assessing, and evaluating the effectiveness of the technical and organizational measures in place to ensure the security of processing.
Furthermore, pursuant to Article 58(2)(d) of the Regulation, the supervisory authority imposed a corrective measure requiring the controller to implement, at both the technical and procedural levels, a system for monitoring data flows throughout the organization’s operations.
Legal and Communication Department
A.N.S.P.D.C.P.
