Natural Person – €500 Fine (Romania, 2021)

€500Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal16 February 2021Romania
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

A Romanian political party official was fined for posting a list of supporters online, revealing their personal details. The Romanian DPA found this violated GDPR rules on data security and confidentiality. This case serves as a reminder to protect personal data, especially in political contexts.

What happened

An official published a list of political supporters online, exposing their personal information.

Who was affected

Ten individuals who supported a political party in Bucharest had their personal details disclosed.

What the authority found

The Romanian DPA found the official violated GDPR by not securing personal data, breaching confidentiality and integrity requirements.

Why this matters

This ruling emphasizes the importance of securing personal data, particularly in political activities, and warns against careless data sharing.

GDPR Articles Cited

Art. 32 GDPR
Art. 5(1)(f) GDPR
Full Legal Summary
Detailed

The Romanian DPA (ANSPDCP) started an investigation after receiving a complaint against an individual who held the office of Secretary-General in a subsidiary branch of a political party in the City of Bucharest. The complainant filed the complaint based on the fact that the defendant's social networking site published a list of 10 supporters for the mayoral election in Bucharest. This list disclosed the personal data of these supporters, including their name, number of their identity document, nationality, address, political choice and signature. Is disclosing the personal data of supporters of a political party an infringement of Article 32 GDPR in conjunction with Article 5(1)(f) GDPR? The Romanian DPA (ANSPDCP) found that the controller violated Article 32 GDPR as they had not implemented appropriate technical and organisational measures to ensure a level of security necessary for the processing of personal data. By disclosing the personal data of 10 individuals, the DPA found that the controller failed to comply with the associated principle of "integrity and confidentiality" (Article 5(1)(f) GDPR). The DPA imposed a corrective measure against the controller, ordering it to erase the personal data revealed on their website. Similarly, the DPA imposed a fine of approximately 500 EUR against the controller.

Details

Fine Date

16 February 2021

Authority

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal

Fine Amount

€500

GDPRhub ID

gdprhub-3211

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Natural Person - Romania (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: