Casa Rusu SRL – €1,977 Fine (Romania, 2022)

€1,977Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal30 November 2022Romania
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Romania's data protection authority fined Casa Rusu SRL EUR 1,977 for not securing customer payment data on its website. This is important because it shows the need for strong security measures to protect sensitive information like credit card details.

What happened

Casa Rusu SRL failed to secure customer payment data on its website, leading to a data breach.

Who was affected

Customers of Casa Rusu SRL whose payment information was stored on the company's website.

What the authority found

The authority concluded that Casa Rusu SRL did not implement adequate security measures to protect customer data, violating GDPR requirements.

Why this matters

This case highlights the importance of implementing robust security measures and regularly testing them to protect customer data. Businesses should ensure their systems are secure to prevent unauthorized access.

GDPR Articles Cited

Art. 25 GDPR
Art. 32 GDPR
Full Legal Summary
Detailed

Based on a notification of a personal data breach pursuant to Article 33 GDPR by Casa Rusu SRL, a controller, the Romanian DPA started an investigation. During its investigation, the DPA found that the breach was the result of insufficient security measures in the online payments section of the controller's website. The website's data bank stored the bank details of the controller's clients. By using an unauthorized entry in the website's security form, a breach occurred which gave an unauthorized party access to the personal data of the controller's clients and data subjects, namely: the first and last name of bank card holders, their card numbers, the date and year of expiry of the bank cards, and the bank card's CVC code. The DPA's investigation showed that the controller did not implement adequate technical and organizational measures, both at the time of establishing the means of processing the personal data, and at the time of the processing itself. It also came to light that the controller did not carry out any periodic testing, evaluation, and assessment of the effectiveness of its technical and organizational measures to guarantee the security of processing as required to effectively implement the principles of the GDPR. As a consequence of the aforementioned investigation, the DPA came to the conclusion that the controller breached a number of GDPR articles. They found a violation of Article 25 GDPR, the obligation to implement data protection by design and by default, Article 32(1)(b) GDPR, the responsibility "to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services", Article 32(1)(d), the obligation to implement "a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing," and Article 32(b) GDPR, the responsibility to take into account "the risks that are presented by processing, in particular

Related Enforcement Actions (0)

No other enforcement actions found for Casa Rusu SRL in RO

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

30 November 2022

Authority

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal

Fine Amount

€1,977

9,883 RON

GDPRhub ID

gdprhub-5530

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Casa Rusu SRL - Romania (2022). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: