Beko Romania SA – €9,953 Fine (Romania, 2025)

€9,953Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal3 March 2025Romania
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

An employee of a home appliances online shop, the controller, notified a data breach to the DPA, as per Article 33 GDPR. The DPA started an investigation, that revealed that an unauthorized person took advantage of a programming vulnerability and, consequently, accessed the website of the operator containing its customers’, the data subjects’, database. Thus, the person concerned had access to the personal data of a large number of data subjects of the operator, namely: name, surname, telephone number, e-mail address, domicile, product details. The investigation revealed that the controller did not carry out the regular testing, evaluation and assessment of the efficiency of technical and organisational measures to ensure the security of the processing. The DPA held that the controller did not implement the appropriate technical and organizational measures, either at the time of establishment of the means of processing, or during the processing itself, as required by Article 32 GDPR. This is further aggravated by the lack of regular testing, evaluation and assessment that the investigation revealed. The DPA found a breach of Article 32(1)(b), (d) and Article 32(2) GDPR deemed it appropriate to fine the controller RON 49,766 (€10,000). The DPA further ordered the controller to implement a data volume analysis system of their IT infrastructure.

GDPR Articles Cited

Art. 33 GDPR
Art. 32(1)(b) GDPR
Art. 32(1)(d) GDPR
Art. 32(2) GDPR
Full Legal Summary

An employee of a home appliances online shop, the controller, notified a data breach to the DPA, as per Article 33 GDPR. The DPA started an investigation, that revealed that an unauthorized person took advantage of a programming vulnerability and, consequently, accessed the website of the operator containing its customers’, the data subjects’, database. Thus, the person concerned had access to the personal data of a large number of data subjects of the operator, namely: name, surname, telephone number, e-mail address, domicile, product details. The investigation revealed that the controller did not carry out the regular testing, evaluation and assessment of the efficiency of technical and organisational measures to ensure the security of the processing. The DPA held that the controller did not implement the appropriate technical and organizational measures, either at the time of establishment of the means of processing, or during the processing itself, as required by Article 32 GDPR. This is further aggravated by the lack of regular testing, evaluation and assessment that the investigation revealed. The DPA found a breach of Article 32(1)(b), (d) and Article 32(2) GDPR deemed it appropriate to fine the controller RON 49,766 (€10,000). The DPA further ordered the controller to implement a data volume analysis system of their IT infrastructure.

Related Enforcement Actions (0)

No other enforcement actions found for Beko Romania SA in RO

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

3 March 2025

Authority

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal

Fine Amount

€9,953

49,766 RON

GDPRhub ID

gdprhub-8991

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Beko Romania SA - Romania (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: