What the authority sanctioned in the first months of 2026 — and what any organisation can learn from these cases.
In the first months of 2026, the National Supervisory Authority for Personal Data Processing (ANSPDCP) continued to investigate and sanction controllers that fail to comply with the personal data protection requirements set out in Regulation (EU) 2016/679 (GDPR) and the applicable national legislation.
So far, the total value of the sanctions imposed in 2026 has reached 366,071 lei (approximately 71,861 euros), the result of several investigations finalised following complaints from data subjects or notifications of security incidents.
These cases highlight a number of recurring types of problems: the lack of adequate security measures, failure to respect data subjects' rights, lack of transparency regarding data processing, and non-cooperation with the supervisory authority.
The controller Money Seeds S.R.L. was fined 15,178 lei for sending unsolicited commercial messages to a person who had objected to receiving them.
The investigation showed that the controller:
The authority also ordered corrective measures, including a review of the databases and staff training on processing data for marketing purposes.
The company Premier Restaurants Romania SRL was fined 40,736 lei (8,000 euros) following a cyberattack that allowed unauthorised access to employee data such as first name, last name, email and job title.
The investigation found that adequate technical and organisational measures had not been implemented to protect the IT systems and to control access to the data.
The controller Continental Automotive Products SRL received fines totalling 76,366 lei (15,000 euros) after an Excel file containing employees' medical data was repeatedly distributed internally.
The file contained information from medical certificates, which constitutes sensitive data under the GDPR. The lack of adequate access control and security measures led to unauthorised access to this information.
A controller — a natural person who administered the website evita-teparii.ro — was fined a total of 50,890 lei (10,000 euros) for publishing identity documents and other personal data without a legal basis.
The investigation found that the controller:
The Alliance for the Union of Romanians party was fined 5,089 lei for failing to respond to a request through which a person was exercising their GDPR rights (access, erasure and objection) after receiving a personalised electoral letter.
The controller Genpact Romania SRL was fined 50,899 lei (10,000 euros) after a cyberattack led to the disclosure of employee data from several EU member states.
The incident was made possible by vulnerabilities related to passwords and to the account authentication reset process.
The company Tensa Art Design S.A., the controller of the website lensa.ro, was fined 101,794 lei (20,000 euros) for failing to respond to the authority's requests during an investigation concerning tracking cookies and behavioural advertising.
The controller Your Consulting SRL was fined 14,929 lei (3,000 euros) after an application developed by the company allowed unauthorised access to personal data, including national identification numbers (CNP) and information about people's holiday vouchers.
The clinic Hayat Dent SRL received a fine of 10,190 lei (2,000 euros) for failing to provide the authority with the information requested during an investigation into the copying of patient data by a former employee.
The analysis of the sanctions imposed in 2026 shows that the most common problems are:
These situations demonstrate that many incidents can be prevented by implementing clear internal procedures and adequate technical measures.
Most of the fines analysed could have been prevented through a few essential GDPR compliance measures:
1. Implementing adequate technical security measures
Organisations must ensure the protection of their IT systems, including through password policies, access control, encryption and the monitoring of security incidents.
2. Respecting data subjects' rights
Access, erasure or objection requests must be analysed and resolved within the legal deadline, and internal processes must allow these requests to be handled efficiently.
3. Transparency and correct information
Privacy policies must provide clear information about the purposes of processing, the legal bases and the rights of data subjects.
4. Controlling access to sensitive data
Medical data, national identification numbers (CNP) or other sensitive information must be protected through additional security measures and by limiting access to authorised persons only.
5. Cooperating with the supervisory authority
Failing to comply with ANSPDCP's requests can lead to additional sanctions, even when the initial breach is minor.
The cases analysed show that complying with GDPR requirements is not only a legal obligation, but also an essential component of managing organisational risk. In a context where security incidents and the use of personal data are becoming increasingly frequent, organisations must treat GDPR compliance as a continuous process that involves internal policies, staff training and constant monitoring of how personal data is processed.
The sanctions imposed by ANSPDCP vary considerably depending on the severity of the breach. In the first months of 2026, the total value of the fines exceeded 366,000 lei, with individual sanctions ranging from around 5,000 lei to over 100,000 lei. At European level, the GDPR sets maximum caps of up to 20 million euros or 4% of total worldwide annual turnover, depending on the type of breach.
The analysis of the 2026 sanctions reveals five recurring problems: insufficient IT security measures, incorrect handling of data subjects' requests (access, erasure, objection), lack of transparency regarding data processing, direct marketing without consent, and non-cooperation with the supervisory authority. Many of these incidents could have been prevented through clear internal procedures and adequate technical measures.
ANSPDCP sets the amount of the fine taking into account the severity and duration of the breach, the number of people affected, whether the act was intentional or negligent, the categories of data involved (sensitive data such as medical data increase the severity), the measures taken to limit the harm, and the degree of cooperation with the authority. Non-cooperation during an investigation can lead to additional sanctions, even when the initial breach is minor.
Most fines can be prevented through a few measures: implementing adequate technical security measures (password policies, access control, encryption, incident monitoring), respecting data subjects' rights within the legal deadline, transparency through clear privacy policies, controlling access to sensitive data, and cooperating with ANSPDCP. GDPR compliance should be treated as a continuous process, with internal policies, staff training and constant monitoring.
We assess your compliance programme and tell you clearly what risks you face and what to fix first.