Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

EURomania Clear all filters
13cases from 1 jurisdiction
€354,279Total of monetary amounts
€125,083Largest single case: RENAULT COMMERCIAL ROUMANIE S.R.L.
€10,000Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) €354,279 100 % · 13 cases

What for?

by area of law

All areas of law

  1. Data protection €354,279 100 % · 13 cases

Who?

by sector

All sectors

  1. Automotive €140,080 40 % · 2 cases
  2. Telecoms, IT and software €114,943 32 % · 2 cases
  3. Other €79,265 22 % · 5 cases
  4. Retail and e-commerce €10,000 3 % · 1 case
  5. Financial services and insurance €7,992 2 % · 2 cases
  6. Healthcare €1,999 1 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q3 20230—
Q4 20230—
Q1 20241€5,005
Q2 20240—
Q3 20240—
Q4 20241€14,998
Q1 20251€14,974
Q2 20251€10,000
Q3 20251€2,990
Q4 20250—
Q1 20263€142,079
Q2 20261€1,948
Q3 20264€162,285

13 cases

19 Aug 2026 Poliserv JG (PJG) SRLPhishing on admin account – Poliserv JG must pay 3,000 EUR RomaniaData breaches and data security €2,998

Attackers obtained the credentials of a user account with administrator rights through phishing and accessed customer data. The Romanian data protection authority (ANSPDCP) criticised the lack of technical and organisational measures and of regular effectiveness testing, imposed 15,728 lei (3,000 EUR) and ordered regular employee training, including on recognising phishing e-mails. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Admin accounts need MFA, and all employees must be able to recognise phishing – the supervisory authority now expressly orders training.

Relevance to training and awareness

Phishing recognition, protection of privileged accounts

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
19 Aug 2026

Original amount 15,728 RON, converted at the ECB reference rate of 19 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

6 Aug 2026 AMATO BESTSELLER S.R.L.AMATO BESTSELLER: 45,000 EUR plus 50,000 lei for data access and robocalls RomaniaMarketing and consent €54,316

Following several complaints, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (Romanian data protection authority, ANSPDCP) found that current and former employees, untrained and without procedural rules, had access to extensive data (including health, family and income data), that data subjects were not informed under Art. 14 GDPR, that excessive data were collected and that automated advertising calls were made without consent. Fines: 78,465 lei (15,000 EUR, Art. 32(4)), 52,310 lei (10,000 EUR, Art. 14), 104,620 lei (20,000 EUR, Art. 5/9 GDPR) and 50,000 lei (Law 506/2004); in addition, an order to provide regular employee training. Date = publication of the press release; according to the authority, the investigation was concluded in June 2026.

What organisations can take from it

Anyone giving employees access to sensitive customer data must train them and limit access on a need-to-know basis.

Relevance to training and awareness

Training employees in handling customer data; consent for advertising calls

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Marketing and consent
Legal basis
Art. 5 Abs. 1 lit. c i. V. m. Art. 9, Art. 14, Art. 32 Abs. 4 DSGVO; Art. 12 Abs. 1 Gesetz 506/2004
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
6 Aug 2026

Original amount 285,395 RON, converted at the ECB reference rate of 6 Aug 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

17 Jul 2026 Orange România SAOrange România pays 100,000 EUR after app errors and hacked ticketing system RomaniaData breaches and data security €99,969

A synchronisation error between two applications allowed a customer to retrieve other customers’ invoices in the mobile app; in addition, the ticketing platform, which was publicly accessible without VPN, MFA or IP restriction, was attacked and a very large data set (including copies of identity documents, card data, IBANs) was exfiltrated. The Romanian data protection authority (ANSPDCP) imposed fines of 104,780 lei (20,000 EUR, Art. 25) and 419,120 lei (80,000 EUR, Art. 32), a total of 523,900 lei, and ordered test and change management. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Never expose internal platforms to the internet without VPN/MFA; software changes to linked systems need testing before go-live.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 25 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
17 Jul 2026

Original amount 523,900 RON, converted at the ECB reference rate of 17 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

2 Jul 2026 Banca Transilvania S.A.Employee retrieves account statements for a third party – Banca Transilvania pays 5,000 EUR RomaniaData breaches and data security €5,002

At the request of a third party and outside the scope of his duties, a bank employee retrieved account statements of a data subject (name, IBAN, transactions, balances). The Romanian data protection authority (ANSPDCP) found insufficient technical and organisational measures and imposed 26,172 lei (5,000 EUR); the bank has paid the fine. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Access logs and clear rules against ‘favour queries’ are a duty for every bank.

Relevance to training and awareness

Access to customer data for business purposes only; handling requests from third parties

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 1, 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
2 Jul 2026

Original amount 26,172 RON, converted at the ECB reference rate of 2 Jul 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

15 Jun 2026 SSG SELECT SOLUTIONS S.R.L.Stranger in Kaufland CCTV room – service provider SSG Select Solutions pays 2,000 EUR RomaniaVideo surveillance €1,948

An employee of the service provider acting as processor for Kaufland România let a third party into a store’s video surveillance room; that person filmed the images and distributed them on social media. Kaufland reported the incident. The Romanian data protection authority (ANSPDCP) imposed 10,200 lei (2,000 EUR) on the processor and ordered additional checks of the work instructions; the fine has been paid. Date = publication of the press release; according to the authority, the investigation was concluded in April 2026.

What organisations can take from it

Anyone with access to surveillance rooms must know: video footage is confidential, and third parties have no access there.

Relevance to training and awareness

Access to surveillance rooms; staff bound by instructions

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Video surveillance
Legal basis
Art. 29, Art. 32 Abs. 1 lit. b, Abs. 2 und 4 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
15 Jun 2026

Original amount 10,200 RON, converted at the ECB reference rate of 15 Jun 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

25 Mar 2026 RENAULT COMMERCIAL ROUMANIE S.R.L.Cyber attack via service provider – Renault Commercial Roumanie pays 125,000 EUR RomaniaData processors €125,083

In an attack on an application operated by a processor, data of a very large number of persons (including personal identification numbers, driving licence and identity card numbers, vehicle identification numbers) were stolen and published. The Romanian data protection authority (ANSPDCP) criticised the lack of security measures and effectiveness testing as well as the selection of a service provider without sufficient guarantees and imposed 637,262.50 lei (125,000 EUR).

What organisations can take from it

Responsibility for customer data does not end with the service provider – check its security guarantees in advance and monitor them continuously.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data processors
Legal basis
Art. 32 Abs. 1 lit. b und d, Abs. 2 i. V. m. Art. 28 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Published
25 Mar 2026

Original amount 637,262.5 RON, converted at the ECB reference rate of 25 Mar 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Feb 2026 SC Hayat Dent SRLDental clinic Hayat Dent obstructs investigation of data leak – 2,000 EUR RomaniaData protection €1,999

The clinic’s managing director himself reported that a former employee had copied contact details and patient records of all patients and poached them for a new clinic. In the subsequent investigation, the clinic did not fully answer the requests of the Romanian data protection authority (ANSPDCP) despite a reprimand and an order; the authority therefore imposed 10,190 lei (2,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in February 2026.

What organisations can take from it

Offboarding processes must block data access immediately – and anyone reporting an incident must also support its investigation.

Relevance to training and awareness

Taking patient data when leaving; cooperation with the supervisory authority

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection
Legal basis
Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Healthcare
Published
20 Feb 2026

Original amount 10,190 RON, converted at the ECB reference rate of 20 Feb 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

19 Jan 2026 Continental Automotive Products SRLExcel list with sick notes circulated internally – Continental Automotive pays 15,000 EUR RomaniaEmployee data €14,997

An Excel file containing data from medical certificates of current and former employees was repeatedly circulated within the company; the company reported the incident itself. The Romanian data protection authority (ANSPDCP) imposed 25,455 lei (5,000 EUR) for breach of data minimisation and accountability and 50,911 lei (10,000 EUR) for insufficient security measures and ordered a monitoring and control procedure. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Employees’ health data do not belong in freely forwarded Excel lists – HR departments need fixed access limits.

Relevance to training and awareness

Handling employees’ health data, e-mail distribution lists

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Employee data
Legal basis
Art. 5 Abs. 1 lit. c und Abs. 2, Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Automotive
Published
19 Jan 2026

Original amount 76,366 RON, converted at the ECB reference rate of 19 Jan 2026.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

12 Aug 2025 Asociația Casa de Ajutor Reciproc „FLEXICREDIT”Credit association Flexicredit grants 17 loans on forged documents – 3,000 EUR RomaniaData breaches and data security €2,990

A school employee gained access to her school’s official e-mail account and sent forged documents on the basis of which the credit association concluded 17 loans in 2023/2024 without the knowledge of the data subjects. The Romanian data protection authority (ANSPDCP) criticised the insufficient identity verification for remote applications and imposed 15,141.6 lei (3,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in June 2025.

What organisations can take from it

Remote contracting requires robust identity verification – an e-mail from an ‘official’ address is no proof.

Relevance to training and awareness

Identity verification and fraud detection in remote applications

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Published
12 Aug 2025

Original amount 15,141.6 RON, converted at the ECB reference rate of 12 Aug 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

24 Apr 2025 Dante International SADante International fails to act on erasure requests – 10,000 EUR RomaniaData subject rights and transparency €10,000

Although the platform operator had repeatedly confirmed to a customer that his e-mail addresses had been deleted, he continued to receive feedback requests; in addition, certain partners could see the address. The Romanian data protection authority (ANSPDCP) found breaches of transparency and erasure obligations, imposed 49,770 lei (10,000 EUR) and ordered, among other things, training of the staff responsible.

What organisations can take from it

A confirmed erasure must actually be implemented in all systems – including feedback and partner tools.

Relevance to training and awareness

Handling erasure requests in customer service

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 12 Abs. 1 i. V. m. Art. 17 und 19 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
24 Apr 2025

Original amount 49,770 RON, converted at the ECB reference rate of 24 Apr 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

20 Jan 2025 Vodafone Romania S.A.Vodafone Romania pays 15,000 EUR for repeated data breaches caused by employees RomaniaData breaches and data security €14,974

Several reported incidents were attributable to employees or service providers: a photo of an invoice sent to third parties, open e-mail distribution lists instead of BCC, a screenshot from the customer application shared via WhatsApp and misdirected invoices. The Romanian data protection authority (ANSPDCP) found insufficient measures to ensure that employees processed data in accordance with instructions and imposed 74,526 lei (15,000 EUR); the company paid. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Many small employee errors add up to an organisational failure – awareness training is mandatory, not optional.

Relevance to training and awareness

BCC, use of messaging apps, sending customer documents

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 32 Abs. 4 i. V. m. Abs. 1 lit. b DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Telecoms, IT and software
Published
20 Jan 2025

Original amount 74,526 RON, converted at the ECB reference rate of 20 Jan 2025.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

30 Oct 2024 Untold SRLUntold SRL fails to answer access and erasure request – 15,000 EUR RomaniaData subject rights and transparency €14,998

Untold SRL left an access request and an erasure request from a data subject unanswered, even though the data subject had provided all contact details. The Romanian data protection authority (ANSPDCP) imposed 49,741 lei (10,000 EUR) in respect of access and 24,870.5 lei (5,000 EUR) in respect of erasure and ordered staff training. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Data subject requests need a ticketing system with the one-month deadline – seasonal event organisers included.

Relevance to training and awareness

Timely handling of data subject requests

Missing or inadequate training played a role in the decision.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data subject rights and transparency
Legal basis
Art. 12 Abs. 3 und 4, Art. 15, Art. 17 Abs. 1 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
30 Oct 2024

Original amount 74,611.5 RON, converted at the ECB reference rate of 30 Oct 2024.

Sources

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

5 Mar 2024 EURO MINI STORAGE ROMANIA SRLEuro Mini Storage paralysed for weeks after cyber attack – 5,000 EUR RomaniaData breaches and data security €5,005

A cyber attack on the server paralysed the company for several weeks and allowed access to customer data. The Romanian data protection authority (ANSPDCP) imposed 24,884.50 lei (5,000 EUR) for insufficient security measures and ordered access logging with a retention period of at least 30 days as well as backups. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.

What organisations can take from it

Logging and tested backups determine whether an attack means days or weeks of downtime.

Authority / court
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Area of law
Data protection · Data breaches and data security
Legal basis
Art. 24 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 DSGVO
Action
Fine
Status of proceedings
unknown
Sector
Other
Published
5 Mar 2024

Original amount 24,884.5 RON, converted at the ECB reference rate of 5 Mar 2024.

Checked against the official source on 25 Sep 2026 · Direct link

Report an error

Anonymous: we store only your text — no contact details and no IP address.

Ready for training that sticks?

Try it free for 14 days — from 1 user, no credit card, ends automatically.

Start free trial