Four sanctions in a single month, at companies of very different sizes. Not one of them came from a planned inspection.
Orange România, RON 523,900 (€100,000), on 17 July. These are in fact two fines. The first, RON 104,780, under Article 25(1) GDPR: inadequate measures from the moment the means of processing were chosen. A synchronisation error between two interconnected applications allowed one customer to download other customers’ invoices. The second, RON 419,120, under Article 32: the ticketing application was publicly exposed, with no secure connection, no two-factor authentication and no IP-based access restriction. A very large volume of data was taken from there, including personal identification numbers (CNP), identity card series and numbers together with copies of the documents, bank card information, IBANs and SIM numbers.
HOMELUX, RON 108,570, on 31 July. RON 78,570 under Article 32 GDPR, plus RON 30,000 under Article 4(5) of Romanian Law no. 506/2004, for cookies that were not technically necessary, stored without users’ consent. Behind it was a cyberattack on the website platform, which did not technically match the vendor’s official version, and passwords of low complexity, left unchanged even after the incident. We covered this case at length in our analysis of the HOMELUX sanction.
Ascendex Technology, RON 57,839 (€11,000), on 1 July. Here there was no attack and no data leak. One erasure request was dealt with in about 12 months, without a final reply to the person who had submitted it and without any justification for the delay. In other cases, it took as long as 37 months. The complaint came through CNIL, the French authority, and the Romanian DPA took the case as lead authority, because the controller has its only establishment in Romania.
Banca Transilvania, RON 26,172 (€5,000), on 2 July. An employee accessed, at a third party’s request and with no work-related reason to do so, a customer’s account statements: IBAN, account type, client code, transactions, balance. The details are in the article on unauthorised access from the inside.
At Ascendex there was no security incident. The fine was imposed for the way a single person’s request was handled. At Banca Transilvania nobody came in from outside; it was an employee with wider access rights than the job required.
At Orange and HOMELUX there were indeed attacks. The authority did not sanction the attack. It sanctioned what it found when it looked at what lay behind it.
That distinction matters for any manager who believes they are safe because nothing has happened to them yet. The fine is not triggered by the incident, but by what shows up in the organisation when someone looks closely.
Orange and HOMELUX notified their own breaches, under Article 33 GDPR. Ascendex and Banca Transilvania got there through a complaint. Not one July investigation started from a planned inspection.
The conclusion some managers draw from this is that it is better not to notify. It is exactly the wrong way round. The shortcomings found at Orange and HOMELUX existed before the incident, and the investigation only brought them to light. Failing to notify would have added one more breach on top of everything that was found anyway, and the 72-hour deadline is a legal obligation, not a strategic option.
Orange and HOMELUX together account for RON 632,470 of the month’s RON 716,481. Both decisions cite Article 32(1)(d) GDPR.
Point (d) requires “a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing”. Not a policy, not a certificate, but a process: something that repeats, has a schedule and someone responsible, and leaves traces behind.
In the Orange decision, the authority states that the controller “did not periodically test the effectiveness of the security systems”. The corrective measure ordered was the implementation of a process for monitoring and testing all the applications used in the company’s operations, covering updates, configuration changes and interconnections between applications, with subsequent tests to identify vulnerabilities.
At HOMELUX, the same finding: there was no process for regularly testing, assessing and evaluating the effectiveness of the measures.
Both companies had security measures in place. What they did not have was the mechanism to find out, at regular intervals, whether those measures still held.
It starts with an inventory of applications, components, versions and suppliers. Without it you have nothing to test, because you do not know what you have.
Then comes a schedule: what gets checked, at what interval, who is responsible. Updates are tracked monthly, vulnerability scans quarterly, a more serious security test once a year. The intervals are calibrated to the risk of your own processing, not copied from somebody else.
Testing is also done after every change, including changes made by suppliers. The Orange incident started from a synchronisation between two interconnected applications, which is exactly the kind of change a company treats as technical and leaves to somebody else.
Every problem found is fixed and documented: what was found, who fixed it, when, and retesting afterwards. And the evidence is kept, because the reports, the logs and the remediation decisions are precisely what you put on the table in an investigation.
That last point is the one most of the companies we work with miss. You can do things properly and still be unable to prove anything when an investigation comes. For the authority, the difference between the two is small.
An “I don’t know” to any of them is not a problem in itself. It becomes one on the day the question comes from ANSPDCP rather than from you.
We assess your company’s technical and organisational measures against exactly the articles cited in the July decisions: Article 25 for data protection by design, Article 32 for the security of processing, Articles 12 and 17 for the deadlines on answering data subject requests. We check access rights, the consent mechanism on the website and the contracts with IT suppliers.
The result is not a report that ends up on a shelf. It is a list of priorities and the regular testing process written out, with a schedule and someone responsible, ready to start. Which is precisely the document Orange and HOMELUX did not have.
The smallest fine in July was RON 26,172, at a company that had suffered no attack at all. The largest was RON 523,900. An assessment done beforehand costs a fraction of either.
None of the four July investigations started from a planned inspection. Two came from a single person’s complaint, two from notifications the companies submitted themselves. Ascendex, a company far smaller than Orange, came to the authority’s attention through a complaint filed in France and passed to Romania through the cooperation mechanism between authorities. The size of the company is taken into account when the amount of the fine is set, but it does not keep you out of an investigation.
Orange and HOMELUX had technical and organisational measures in place. The fines were imposed for the absence of the process by which you check regularly whether those measures still work, expressly required by Article 32(1)(d) GDPR. Documents show what you set out to do; regular testing shows what happens in reality, and in an investigation the authority looks at the second.
The Regulation does not impose a fixed interval. You set it yourself, according to the risk of your processing and how often your systems change, then you keep to it and document it. A modest schedule, kept and evidenced with reports, counts for more in an inspection than an ambitious one you have never kept to. What is not accepted is having no interval at all.
The investigations at Orange and HOMELUX started from their own notifications, but the fines were imposed for shortcomings that existed before the incident. Notifying within 72 hours is a legal obligation under Article 33, and failing to do so would have added a separate breach on top of those found anyway. What exposes you to a sanction is being unable to demonstrate what measures you had and how you checked them.
The supplier can carry out the tests, but liability stays with the controller, which means you. In the Orange case, the corrective measure ordered expressly covers configuration changes and interconnections between applications, so it covers the suppliers’ work as well. That is why the contract must set out clearly the deadlines for remediation, the notification of incidents, the retention of logs and your right to check or audit what has been implemented.
Together we go through the applications, the access rights, the consent mechanism and the contracts with your suppliers, and then we leave you the regular testing process written out, with a schedule and someone responsible. Write to us and we will arrange a call.