S.P.E.E.H. Hidroelectrica S.A. – €5,000 Fine (Romania, 2021)

€5,000Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal1 November 2021Romania
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

S.P.E.E.H. Hidroelectrica S.A. mistakenly sent personal data of 325 people to the wrong recipients after a data breach. This incident highlights the importance of keeping personal information secure and following the rules about data processing. The company was fined for not protecting data properly.

What happened

S.P.E.E.H. Hidroelectrica S.A. sent personal data of 325 people to the wrong recipients due to a data breach.

Who was affected

The affected individuals were 325 people whose personal data was sent to unintended recipients.

What the authority found

The Romanian DPA found that S.P.E.E.H. Hidroelectrica S.A. violated GDPR rules by failing to implement adequate security measures.

Why this matters

This case serves as a reminder for companies to prioritize data security and compliance with GDPR. Businesses must ensure they have strong protections in place to avoid similar breaches.

GDPR Articles Cited

AI-verified

Art. 32(1)(b) GDPR
View original scraped data
Art. 32(1) b) GDPR
(2) GDPR

Original data from scraper before AI verification against source document.

Source verified 14 March 2026
verified correct
Full Legal Summary
Detailed

The Romanian DPA (ANSPDCP) has imposed a fine of EUR 5,000 on S.P.E.H. Hidroelectrica S.A.. The controller had notified the DPA of several breaches of personal data protection under Art. 33 of the GDPR. The data breach led to the data of 325 individuals being accessed unlawfully or passed on to the wrong recipients. The DPA considered this to be a breach by the controller of its obligation under Art. 32 (1) b), (2) GDPR to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk represented by the processing. In addition, the DPA found that the controller had processed personal data of three customers after they had exercised their right to erase their data and revoked their consent to the processing. The processing was therefore carried out without a valid legal basis. The DPA imposed a fine of EUR 5,000 for a breach of Art. 32 (1) b), (2) GDPR. For a violation of Art. 5 (1) a) GDPR, Art. 6 (1) a) GDPR, the DPA further issued a warning.

Details

Fine Date

1 November 2021

Authority

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal

Fine Amount

€5,000

Enforcement Tracker ID

ETid-891

About this data

Data: CMS GDPR Enforcement Tracker
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. S.P.E.E.H. Hidroelectrica S.A. - Romania (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: