S.P.E.E.H. Hidroelectrica S.A. – €5,000 Fine (Romania, 2021)

€5,000Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal1 October 2021Romania
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

S.P.E.E.H. Hidroelectrica S.A. mistakenly sent personal data of 325 people to the wrong recipients after a data breach. This incident shows the importance of keeping personal information secure and respecting people's rights to have their data erased. The company was fined €5,000 for not following data protection rules.

What happened

S.P.E.E.H. Hidroelectrica S.A. sent personal data of 325 individuals to incorrect recipients due to a data breach.

Who was affected

325 individuals whose personal data was mistakenly sent to wrong recipients.

What the authority found

The Romanian DPA found that S.P.E.E.H. Hidroelectrica S.A. violated several GDPR provisions by failing to protect personal data adequately.

Why this matters

This case highlights the need for companies to improve their data security measures and respect user rights. It serves as a warning that failing to protect personal data can lead to significant penalties.

GDPR Articles Cited

Art. 5(1)(a) GDPR
Art. 6(1) GDPR
Art. 32(1)(b) GDPR
Art. 32(2) GDPR
Full Legal Summary
Detailed

Following a data breach, the controller S.P.E.E.H. Hidroelectrica S.A. (a supplier of hydroelectricity) erroneously sent the personal data of 325 data subjects to the wrong recipients. The data breach was reported to the Romanian DPA. The subsequent investigation clarified certain elements of the breach and revealed that the controller had been processeing the personal data of 3 data subjects who previously exercised their right to erasure and withdrawn their consent for the processing. The Romanian DPA completed an investigation and found a breach of several GDPR provisions, for which it sanctioned the controller as follows: - a fine of approx €5,000 (RON 24,739.50) for breaching the Article 32(1)(b) and Article 32(2) GDPR; - a warning for breaching the Article 5(1)(a) and Article 6(1) GDPR; - a corrective measure ordering the controller to update its technical and organisational measures to ensure a level of security appropriate to the risk of processing; - a corrective measure ordering the controller to implement a measure that will guarantee personal data is accurate and updated according to the purpose of processing.

Related Enforcement Actions (0)

No other enforcement actions found for S.P.E.E.H. Hidroelectrica S.A. in RO

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

1 October 2021

Authority

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal

Fine Amount

€5,000

Enforcement Tracker ID

ETid-891

GDPRhub ID

gdprhub-4303

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. S.P.E.E.H. Hidroelectrica S.A. - Romania (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: