S.P.E.E.H. Hidroelectrica S.A. – €5,000 Fine (Romania, 2021)

€5,000Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal1 October 2021Romania
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

S.P.E.E.H. Hidroelectrica S.A. mistakenly sent personal information of 325 people to the wrong recipients after a data breach. This incident highlights the importance of protecting customer data and ensuring it is only shared with the right people. The company was fined €5,000 for failing to secure personal data properly.

What happened

S.P.E.E.H. Hidroelectrica S.A. sent personal data of 325 individuals to incorrect recipients due to a data breach.

Who was affected

The affected individuals were 325 people whose personal data was mistakenly shared with unauthorized recipients.

What the authority found

The Romanian DPA found that the company did not take adequate security measures to protect personal data, violating several GDPR provisions.

Why this matters

This case shows that companies must prioritize data security to avoid breaches and potential fines. Small businesses should regularly review their security practices to protect customer information.

GDPR Articles Cited

AI-verified

Art. 5(1)(a) GDPR
Art. 6(1) GDPR
Art. 32(1)(b) GDPR
Art. 32(2) GDPR
View original scraped data
Art. 5(1)(a) GDPR
Art. 6(1) GDPR
Art. 32(1)(b) GDPR
Art. 32(2) GDPR

Original data from scraper before AI verification against source document.

Source verified 15 March 2026
verified correct
Full Legal Summary
Detailed

Following a data breach, the controller S.P.E.E.H. Hidroelectrica S.A. (a supplier of hydroelectricity) erroneously sent the personal data of 325 data subjects to the wrong recipients. The data breach was reported to the Romanian DPA. The subsequent investigation clarified certain elements of the breach and revealed that the controller had been processeing the personal data of 3 data subjects who previously exercised their right to erasure and withdrawn their consent for the processing. The Romanian DPA completed an investigation and found a breach of several GDPR provisions, for which it sanctioned the controller as follows: - a fine of approx €5,000 (RON 24,739.50) for breaching the Article 32(1)(b) and Article 32(2) GDPR; - a warning for breaching the Article 5(1)(a) and Article 6(1) GDPR; - a corrective measure ordering the controller to update its technical and organisational measures to ensure a level of security appropriate to the risk of processing; - a corrective measure ordering the controller to implement a measure that will guarantee personal data is accurate and updated according to the purpose of processing.

Details

Fine Date

1 October 2021

Authority

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal

Fine Amount

€5,000

GDPRhub ID

gdprhub-4303

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. S.P.E.E.H. Hidroelectrica S.A. - Romania (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: