A vulnerability in a mobile app drew a fine from the Romanian authority — not so much for the incident itself, as for the way it was handled afterwards.
Some of the most instructive lessons in data protection come not from doctrine, but from the decision-making practice of the supervisory authority. In May 2026, the National Supervisory Authority for Personal Data Processing (ANSPDCP) closed an investigation into a major electronics and home-appliance retailer and found infringements of several GDPR provisions. The consequences: three separate fines and a set of mandatory corrective measures.
The case warrants a close reading, because it reflects a risk to which any organisation operating an app, an online store or a customer database is exposed.
The investigation was triggered by a complaint lodged with the authority. The checks established that, owing to a technical vulnerability in the operator's mobile app — at the level of the account validation process — one user was able to access another data subject's personal data.
The exposed data included names, invoices and delivery addresses. This was not a sophisticated external attack, but a weakness in the operator's own system — the category of risk that most often remains undetected until an external complaint is made.
The authority found three distinct failures, each sanctioned separately.
ANSPDCP imposed three administrative fines, amounting to over 52,000 lei (approximately 10,000 euros):
The structure of the penalty is notable: although the fine for the security deficiency was the largest, the two fines relating to the notification obligations together added a further 3,000 euros or so. In other words, a significant part of the penalty was imposed not because a breach occurred, but because of the failure to notify it properly.
Beyond the fines, the authority ordered the operator, under Art. 58 GDPR, to take a series of mandatory corrective measures:
The relevance of the decision lies not in the scale of an attack, but in the mundane nature of the deficiencies that produced it — situations that can arise in any organisation. A few practical conclusions:
In essence, the case confirms a recurring pattern in ANSPDCP's practice: the most costly consequences stem not from bad faith, but from the absence of a few simple rules — set down in procedures and applied consistently.
For three distinct failures: the absence of adequate technical and organisational security measures (Art. 32 GDPR), failure to notify the breach to ANSPDCP (Art. 33) and failure to inform the data subject (Art. 34). The fines totalled over 52,000 lei, the equivalent of about 10,000 euros.
Through a technical vulnerability in the operator's mobile app, in the account validation process. It allowed one user to access another data subject's personal data: first name, surname, invoices and delivery addresses.
Because, beyond the incident itself, the controller failed to meet two autonomous obligations: it did not notify the authority within the legal 72-hour deadline (Art. 33) and it did not inform the data subject whose data had been exposed (Art. 34). Each unmet obligation is a distinct infringement and was sanctioned separately.
Reviewing the account validation and authentication mechanisms, periodic vulnerability testing of the app, adopting internal procedures for incident handling and for assessing notification obligations, regular staff training, and sending a written reply to the person who lodged the complaint.
We help you prevent situations like this: we test the security of your apps and systems, set up your breach notification procedure and train your team — exactly the measures the authority required in this case.