SYNOBIS MEDICAL S.R.L – €2,000 Fine (Romania, 2024)

€2,000Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal10 December 2024Romania
final
ePrivacy
Fine

SYNOBIS MEDICAL S.R.L. was fined for collecting personal data through cookies without getting users' consent. This matters because it shows that companies must be clear about how they use cookies and ensure they have permission before tracking users. Website owners should review their cookie practices to avoid similar issues.

What happened

SYNOBIS MEDICAL S.R.L. collected personal data from users through cookies without obtaining their consent.

Who was affected

Website visitors who accessed SYNOBIS MEDICAL S.R.L.'s site and had their data collected through cookies.

What the authority found

The Romanian DPA found that SYNOBIS MEDICAL S.R.L. violated GDPR by not providing clear information about cookies and failing to get user consent.

Why this matters

This case highlights the importance of transparency in cookie usage. Companies should ensure they have proper consent mechanisms in place to protect user privacy.

GDPR Articles Cited

AI-verified

Art. 12(GDPR)
Art. 14(GDPR)
View original scraped data
Art. 12(GDPR)
Art. 14(GDPR)

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Art. 4(5) Law 506/2004
Art. 13(1)(i) Law 506/2004
Source verified 7 April 2026
articles corrected
national law identified
amount discrepancy
Full Legal Summary
Detailed

The Romanian DPA was notified by a website user of possible data protection violations y SYNOBIS MEDICAL S.R.L., the controller. Upon investigation, the DPA found that it was impossible to enter the website of the controller without the users´ personal data being collected through cookies. Moreover, the data subject could not access their data. The DPA found that the controller was collecting and storing personal data that was collected, through cookies, from the users´ equipment without obtaining their express consent. Moreover, the controller did also not inform the users of the presence of said cookies, violating [https://www.dataprotection.ro/servlet/ViewDocument?id=173 Article 4(5) and 13(1)(i) Law 506/2004], Romanian law on the processing of personal data and protection of privacy in the electronic communications sector (implementation of the E-Privacy Directive). Moreover, the controller did not inform the data subject of whose personal data they collected, and processed through the website, violating Article 12 and 14 GDPR. Consequently, the DPA deemed it appropriate to impose a fine of RON 10,000 (€4,972) to the controller.

Violations (3)

Cookies Placed Before Consent
critical

Non-essential cookies (tracking, advertising) are placed on the user's device before obtaining valid consent.

Art. 6(1) GDPR

Third-Party Cookies Without Consent
critical

Third-party tracking cookies or scripts are loaded without obtaining prior user consent.

Art. 13, 14 GDPR

Unclear Cookie Information
high

The cookie banner or cookie policy provides vague, incomplete, or unclear information about what cookies are used and why.

Art. 12, 13 GDPR

Related Enforcement Actions (0)

No other enforcement actions found for SYNOBIS MEDICAL S.R.L in RO

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

10 December 2024

Authority

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal

Fine Amount

€2,000

10,000 RON

GDPRhub ID

gdprhub-8656

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified
Cookie relevance: 100%

Cite as: Cookie Fines. SYNOBIS MEDICAL S.R.L - Romania (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: