It was not only the cyberattack that was sanctioned, but the way it was made possible.
Following an investigation, the National Supervisory Authority for Personal Data Processing (ANSPDCP) imposed a fine of RON 637,262.50 (EUR 125,000), as a result of serious shortcomings in the protection of personal data.
The investigation was triggered after the notification of a security incident caused by a cyberattack on an application managed through an external supplier.
As a result of this incident:
The impact was major, both due to the volume of the data and its nature.
The authority found the breach of several essential obligations:
Adequate technical and organisational measures had not been implemented to:
The controller did not ensure that the supplier:
The fine reflects the cumulative severity of the situation:
It was not only the cyberattack that was sanctioned, but the way it was made possible.
To prevent similar situations, organisations must adopt a proactive approach:
Top management must understand that the lack of adequate security measures attracts significant sanctions, even when the incident is caused by an external attack.
And do not forget: the protection of personal data must be treated as an operational and strategic priority, not merely as a formal obligation.
Because ANSPDCP did not sanction the cyberattack itself, but the fact that the controller made it possible. The investigation showed that there were no real preventive measures and no effective control over the external supplier managing the application. In other words, the responsibility lies with the controller who failed to protect the data, not only with the attacker.
The controller had not implemented adequate technical and organisational measures to: ensure the confidentiality of the data, prevent unauthorised access, periodically test and evaluate the systems, and guarantee the security of processing on an ongoing basis. In addition, the authority also found a breach of Art. 28, because the controller did not ensure that the supplier provided sufficient guarantees regarding data security.
The fine of RON 637,262.50 (EUR 125,000) reflects the cumulative severity of the situation: the very large number of individuals affected, the exposure of sensitive data, the lack of any real preventive measures, the lack of effective control over suppliers, and the high risk to the rights and freedoms of the data subjects. The greater the impact and the fault, the higher the sanction.
Through a proactive approach: security measures adapted to the real risks, periodic testing and evaluation (audits, penetration tests, vulnerability monitoring), rigorous supplier management, integrating the privacy by design principle, controlling access to data and a clear incident response plan. Top management must treat data protection as an operational and strategic priority, not as a formal obligation.
We assess the security of your processing and the relationship with your suppliers, so the risk of a sanction drops.