S.P.E.E.H. Hidroelectrica S.A. – €5,000 Fine (Romania, 2021)

€5,000Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal1 October 2021Romania
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Following a data breach, the controller S.P.E.E.H. Hidroelectrica S.A. (a supplier of hydroelectricity) erroneously sent the personal data of 325 data subjects to the wrong recipients. The data breach was reported to the Romanian DPA. The subsequent investigation clarified certain elements of the breach and revealed that the controller had been processeing the personal data of 3 data subjects who previously exercised their right to erasure and withdrawn their consent for the processing. The Romanian DPA completed an investigation and found a breach of several GDPR provisions, for which it sanctioned the controller as follows: - a fine of approx €5,000 (RON 24,739.50) for breaching the Article 32(1)(b) and Article 32(2) GDPR; - a warning for breaching the Article 5(1)(a) and Article 6(1) GDPR; - a corrective measure ordering the controller to update its technical and organisational measures to ensure a level of security appropriate to the risk of processing; - a corrective measure ordering the controller to implement a measure that will guarantee personal data is accurate and updated according to the purpose of processing.

GDPR Articles Cited

Art. 5(1)(a) GDPR
Art. 6(1) GDPR
Art. 32(1)(b) GDPR
Art. 32(2) GDPR
Full Legal Summary

Following a data breach, the controller S.P.E.E.H. Hidroelectrica S.A. (a supplier of hydroelectricity) erroneously sent the personal data of 325 data subjects to the wrong recipients. The data breach was reported to the Romanian DPA. The subsequent investigation clarified certain elements of the breach and revealed that the controller had been processeing the personal data of 3 data subjects who previously exercised their right to erasure and withdrawn their consent for the processing. The Romanian DPA completed an investigation and found a breach of several GDPR provisions, for which it sanctioned the controller as follows: - a fine of approx €5,000 (RON 24,739.50) for breaching the Article 32(1)(b) and Article 32(2) GDPR; - a warning for breaching the Article 5(1)(a) and Article 6(1) GDPR; - a corrective measure ordering the controller to update its technical and organisational measures to ensure a level of security appropriate to the risk of processing; - a corrective measure ordering the controller to implement a measure that will guarantee personal data is accurate and updated according to the purpose of processing.

Related Enforcement Actions (0)

No other enforcement actions found for S.P.E.E.H. Hidroelectrica S.A. in RO

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

1 October 2021

Authority

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal

Fine Amount

€5,000

Enforcement Tracker ID

ETid-891

GDPRhub ID

gdprhub-4303

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. S.P.E.E.H. Hidroelectrica S.A. - Romania (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: