On 31 July 2026, the Romanian DPA (ANSPDCP) announced a sanction against HOMELUX S.R.L., after a cyberattack on the platform that kept its website running.
The National Supervisory Authority for Personal Data Processing completed its investigation into HOMELUX S.R.L. in June 2026 and made the outcome public on 31 July 2026. The authority found a breach of Article 32(1)(d) and (2) of Regulation (EU) 2016/679, as well as a breach of Article 4(5) of Romanian Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector. Two fines followed, totalling RON 108,570:
The two legal bases are not the same thing. One belongs to the GDPR and its sanctioning regime, the other to the national law that governs cookies and access to the user’s terminal equipment. A company can be in order on one and outside the law on the other, and an inspection covers both in the same visit. The case is a warning for any organisation that runs a website, an online shop, a platform with user accounts or an app that collects personal data.
The investigation began after the controller itself submitted a personal data breach notification under Article 33 GDPR. This is exactly the mechanism we covered in our guide to notifying ANSPDCP: you report the breach within 72 hours, and the authority then checks what measures you had in place before the incident.
The incident was caused by a cyberattack on the platform that kept the website administered by the controller running. At the time it happened, the platform did not technically match the official version released by the vendor. The practical point is this: a platform that has been modified, or left behind the official version, falls outside vendor support, and the security fixes published officially no longer apply to it as they should.
The authority also noted that the incident was made easier by the low complexity of the passwords used when accounts were created on the site, a shortcoming that had not been fixed even after the incident. The data involved was first names, surnames, addresses, email addresses and passwords. The authority’s wording deserves to be read in full: the controller did not ensure adequate security of the data processed “including against unauthorised or unlawful processing and against accidental loss, destruction or damage”. Article 32 covers accidental losses too, not only attacks.
The GDPR does not ask organisations to react after an attack. It asks them to implement and keep in place technical and organisational measures appropriate to the risks of the processing. In this case, the Romanian DPA found that the controller had not implemented such measures, “including inter alia the ability to ensure the confidentiality of processing systems and services”, and that it lacked a process for regularly testing, assessing and evaluating their effectiveness.
That is the core of the sanction. Compliance is not demonstrated with a security policy, an SSL certificate and a signed contract with the firm that maintains the website. The organisation must be able to put concrete evidence on the table:
This is the same pattern the authority sanctioned in the July 2026 fine for unauthorised access: Article 32 applies in the same way, whether the risk comes from inside or from outside.
Many companies treat website security as the job of the developer, the hosting company or whoever maintains the platform. From a GDPR perspective, the controller remains liable for how the data processed on its behalf is protected.
The Romanian DPA ordered the implementation of a documented plan covering the regular testing, assessment and evaluation of all systems and of any later changes made by the controller or by its service providers, expressly qualified as processors, in particular for the website administered by the controller. In other words, the changes your supplier makes go into your testing plan, not theirs.
Contracts with IT suppliers must therefore set out clearly:
Simply mentioning a general obligation to “comply with the GDPR” in a contract is not enough.
In this case, the low complexity of passwords was expressly named among the factors that made the incident easier, and the fact that it was not corrected even after the breach weighed in the decision.
Companies must set minimum requirements for password length and complexity and block passwords that are easy to guess or already exposed in public leaks. For administrative accounts, multi-factor authentication should be a standard measure, not an option. Access rights are granted on the least privilege principle: each user gets only the access their work requires.
Inactive or unused accounts, and those left behind by former employees and contractors, must be identified and deactivated within a written deadline, not “whenever we remember”.
During the investigation, the Romanian DPA found that the controller had stored on users’ devices cookies that were not technically necessary for the website to work, and had accessed information in their terminal equipment, without their consent. The legal basis for the sanction is Article 4(5) of Law no. 506/2004, not the GDPR.
For analytics, advertising, profiling or tracking cookies, showing a banner solves nothing. These technologies must be blocked until the user makes a choice. The same logic applies to tracking tools outside the website, such as tracking pixels in newsletters.
A proper consent management mechanism must meet at least the following conditions:
Open the browser console on your own site and look at what loads before the visitor presses anything. That is where the difference between a banner and real blocking shows.
Besides the two fines, the authority ordered corrective measures. They group into four obligations, from which everything else follows:
The measures show how the authority views data security: a continuous, documented and verifiable process, not a list you tick once.
Organisations that run websites and online platforms should go through at least these checks:
A negative answer to any of these questions points to a risk that needs to be assessed and fixed.
The fine was not imposed because a cyberattack took place. No organisation can eliminate that risk entirely. The problem was the absence of appropriate measures and of a continuous process through which their effectiveness is tested, assessed and demonstrated.
A security incident brings out more than a technical vulnerability. It shows where you stand on governance, contracting, supplier control, access management and privacy. The cases we followed in the 2026 ANSPDCP fines repeat the same pattern.
The question worth asking is not “Do we have security measures?”, but: can we demonstrate that the measures are appropriate, up to date, tested and applied in practice?
INFOSHARE Consulting helps organisations assess and reduce data protection and information security risks through:
Yes. From a GDPR perspective, the controller remains liable for how the data processed on its behalf is protected, no matter who technically administers the platform. In the HOMELUX case, the authority ordered a documented plan for regular testing and assessment that also covers changes made by suppliers or processors. Your contract with the IT supplier must set out clearly the deadlines for fixing vulnerabilities, regular tests, prompt notification of incidents, retention of logs and your right to check the measures in place.
A repeatable process, with a schedule and someone responsible for it, not a check done once when the site was launched. In practice: updating the platform and its extensions, an inventory of components, versions and suppliers, vulnerability scans and security tests at set intervals, documented remediation of the issues found and retesting after changes. The evidence counts as much as the measures: the reports, the logs and the remediation decisions are what you show the authority in an investigation.
No, not if the analytics, advertising or profiling scripts start before the user chooses anything. Article 4(5) of Law no. 506/2004 requires prior consent for any cookie that is not technically necessary, and refusing must be as simple as accepting, with no pre-ticked boxes. Check what actually loads in the browser before the choice is made and keep proof of consent; a cookie policy that is correct on paper does not make up for a banner that blocks nothing.
The notification is not the cause of the sanction. The HOMELUX investigation started from the notification the controller submitted under Article 33 GDPR, but the fine was imposed for the absence of appropriate security measures and of a regular testing process, shortcomings that existed before the incident. Notifying within 72 hours is a legal obligation, and failing to do so would have added one more breach. What exposes you to a sanction is being unable to demonstrate what measures you had and how you checked them.
We go through the platform and its components, the consent mechanism, the contracts with your IT suppliers and the technical measures applied to the data, with remediation steps in order of priority. A check done before an incident costs far less than an investigation. Get in touch.