On 2 July 2026, the Romanian supervisory authority announced a new sanction. Not a cyberattack, not hackers — a curious employee and access controls that were too weak.
It all started with a complaint from a person who reported that their data had been used unlawfully. Following the investigation, the authority found that a bank employee had accessed the person’s account statements — with no work duty justifying the access — at the request of a third party. Name, IBAN, account type, client code, transactions and balance were exposed.
The fine: RON 26,172, the equivalent of €5,000, for breaching Article 32(1), (2) and (4) GDPR. The bank paid it. Beyond the fine, the authority ordered corrective measures: putting in place technical and organisational measures that prevent this kind of access.
Article 32 requires “security of processing”: technical measures (who can open what, access logs, alerts) and organisational ones (procedures, training, checks) appropriate to the risk. The key point of this decision: risk does not only come from outside. An employee with overly broad, unsupervised access rights is, in the eyes of the law, a vulnerability of the controller — not an excuse.
That is why the bank answers for it, not just the employee: the controller must build the system so that curiosity or “a favour for a friend” cannot turn into a data leak.
The amount looks small for a bank. The message is not: the Romanian DPA consistently sanctions unauthorised internal access, and a single complaint is enough to trigger an investigation in which the controller must show all its measures. Those who have them get off lightly. Those who do not pay twice: the fine, and their clients’ trust.
Because the GDPR places responsibility on the controller: the company must implement measures that prevent unauthorised access, including by its own employees. The employee may face separate disciplinary or criminal liability, but the administrative fine targets the controller that did not protect its data well enough.
Technical and organisational measures appropriate to the risk: access control, access logging, regular testing of the measures, internal procedures and staff training. There is no single mandatory checklist — the controller chooses measures fit for its activity, but must be able to demonstrate they are sufficient.
Through an audit of access rights (who can access what, and why) and of the logs (who actually accessed what). If your systems keep no access logs, that is the first problem to fix — without them you can neither detect nor prove anything.
We audit your access rights and security measures together, with concrete remediation steps — before a complaint does it for you. Get in touch.