July 2026 GDPR Fine: the Employee Who Illegally Accessed a Client’s Accounts
Romania’s DPA fined Banca Transilvania €5,000 (Art. 32 GDPR): an employee illegally accessed a client’s accounts at a third party’s request. How to prevent it.
Read →Practical guides on compliance and information security — GDPR, NIS2, DORA, DPO — explained in plain language.
Romania’s DPA fined Banca Transilvania €5,000 (Art. 32 GDPR): an employee illegally accessed a client’s accounts at a third party’s request. How to prevent it.
Read →A standardised form for notifying data breaches. Why and when it is used, who fills it in and where it is sent — and what to prepare in advance.
Read →You have the right to complain about a company that misused your data. Step by step, free and without a lawyer — and what happens after you file.
Read →Who can be appointed DPO: the expertise the law requires, why it cannot be the CEO or head of IT, and when internal or outsourced makes more sense.
Read →Once you appoint a DPO, there is an easily forgotten duty: communicating their contact details to the authority. When, how and what to submit to ANSPDCP.
Read →The myth of a mandatory DPO certification, debunked: what the GDPR actually requires, what a course is worth, and what genuinely makes a credible DPO.
Read →What the DPO function really costs: an internal salary plus taxes, training and tooling, or a fixed outsourced fee. The factors that matter and how to choose.
Read →What a clinic or healthcare company must have in place to comply with the GDPR: the controller's obligations, by article, plus a free self-assessment.
Read →DPO stands for Data Protection Officer. What the role is, what tasks it covers, when it is mandatory and what is not part of the job — explained simply.
Read →The Romanian authority fined a retail operator over 52,000 lei — for lacking security measures and for failing to meet the breach notification obligations. What we take away.
Read →Employees already use AI tools, often without the company knowing. The real risks and how to keep them under control with an AI policy.
Read →Had a data breach? When you must notify, how to file within 72 hours and what happens next.
Read →Not just IT's job. What it actually protects (confidentiality, integrity, availability) and where a company starts.
Read →The best technology falls to one wrong click. How to grow people who take care on their own, not out of fear.
Read →The people controls in Annex A, across three stages: before employment, during it, and on leaving.
Read →Hotels, guesthouses and agencies collect a lot of data at every booking. Passports, payments, marketing and booking systems, with no hassle.
Read →Employee consent is usually not valid. What basis you use, how long you keep CVs, and what is allowed when monitoring.
Read →Medical data is the most sensitive data about a person. How a hospital, clinic or practice protects it properly, with no hassle for the staff.
Read →Most banking fraud is not a technical break-in but a trick. What today's attacks look like and which measures actually stop fraud.
Read →Banks, lenders and fintechs must meet GDPR, DORA and NIS2 at the same time. The legal framework and the practical security steps, explained for management.
Read →
An employee of a security provider let a third party into the surveillance room and footage ended up online — a €10,200 GDPR fine.
Read →When a model can be pulled overnight, depending on a single AI provider becomes a real business-continuity risk.
Read →
Enforcement in numbers: ~370 ANSPDCP fines, the top sanctions, and what the Digital Omnibus will change.
Read →Tracking pixels require prior consent under the CNIL and the ePrivacy Directive — even in B2B.
Read →
An example of GDPR being misappropriated as a pretext to block information of public interest.
Read →
ANSPDCP fined a controller RON 637,262.50 after a cyberattack — the missing Art. 32 and Art. 28 safeguards made it possible.
Read →
Monitoring deployed without a GDPR analysis turns into sanctions. Prove it's necessary and proportionate — before deployment.
Read →
Facial recognition of employees can breach the GDPR when a less intrusive system already meets the need.
Read →
Document controls, manage risks and centralise security policies within a single ISMS — ready for audits.
Read →
Records of processing, data subject requests, security measures, risks and incidents — all audit-ready in one system.
Read →
Over 366,000 lei in GDPR fines from ANSPDCP in early 2026 — and the recurring mistakes you can learn to avoid.
Read →AI is used daily, but without clear rules it becomes a real information-security and GDPR risk. The answer is governance, not a ban.
Read →What banks, lenders and insurers process, on what legal basis, how long they keep it and what rights clients have — GDPR fundamentals for finance.
Read →NIS 2 is not an IT project, but one of governance, risk and continuity, with explicit management accountability.
Read →A practical information security guide for business resilience: the basic measures that actually matter, the link to GDPR (Art. 32) and ISO 27001.
Read →Most breaches start with a person, not a firewall. How to turn employees from a risk into your first line of defence — plus a free self-assessment and a GDPR AI assistant.
Read →Received someone else's data by mistake? What you may and may not do, who to notify and when it becomes a data breach — step by step.
Read →
Two fines after an Excel file with employees' medical data circulated internally — and how to avoid a similar penalty.
Read →
Seven simple questions that show management where the real vulnerabilities are — a practical checklist, not bureaucracy.
Read →
Data disclosure, denial of access, cookies without consent, video surveillance and cyberattacks — and how to prevent them.
Read →
Photos of your children, home and holiday spot look harmless, but can hand an attacker the missing pieces.
Read →On 19 November 2025 the European Commission published the Digital Omnibus package. The 6 GDPR changes to watch.
Read →Don't read endlessly — just ask us. We'll tell you clearly what applies to you and what you need to do.