Compliance Radar
Who was sanctioned, and for what?
Fines, court rulings and incidents from Europe and North America: 718 cases from 32 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.
Click a bar to drill down one level.
Where?
by authority- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) €354,279 100 % · 13 cases
What for?
by area of lawAll areas of law
Who?
by sectorAll sectors
When?
per quarter, by date of decision| Period | Cases | Total |
|---|---|---|
| Q3 2023 | 0 | — |
| Q4 2023 | 0 | — |
| Q1 2024 | 1 | €5,005 |
| Q2 2024 | 0 | — |
| Q3 2024 | 0 | — |
| Q4 2024 | 1 | €14,998 |
| Q1 2025 | 1 | €14,974 |
| Q2 2025 | 1 | €10,000 |
| Q3 2025 | 1 | €2,990 |
| Q4 2025 | 0 | — |
| Q1 2026 | 3 | €142,079 |
| Q2 2026 | 1 | €1,948 |
| Q3 2026 | 4 | €162,285 |
13 cases
19 Aug 2026 Poliserv JG (PJG) SRLPhishing on admin account – Poliserv JG must pay 3,000 EUR €2,998
Attackers obtained the credentials of a user account with administrator rights through phishing and accessed customer data. The Romanian data protection authority (ANSPDCP) criticised the lack of technical and organisational measures and of regular effectiveness testing, imposed 15,728 lei (3,000 EUR) and ordered regular employee training, including on recognising phishing e-mails. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Admin accounts need MFA, and all employees must be able to recognise phishing – the supervisory authority now expressly orders training.
Phishing recognition, protection of privileged accounts
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 19 Aug 2026
Original amount 15,728 RON, converted at the ECB reference rate of 19 Aug 2026.
- ANSPDCP – Comunicat de presă 19.08.2026 (Poliserv JG (PJG) SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
6 Aug 2026 AMATO BESTSELLER S.R.L.AMATO BESTSELLER: 45,000 EUR plus 50,000 lei for data access and robocalls €54,316
Following several complaints, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (Romanian data protection authority, ANSPDCP) found that current and former employees, untrained and without procedural rules, had access to extensive data (including health, family and income data), that data subjects were not informed under Art. 14 GDPR, that excessive data were collected and that automated advertising calls were made without consent. Fines: 78,465 lei (15,000 EUR, Art. 32(4)), 52,310 lei (10,000 EUR, Art. 14), 104,620 lei (20,000 EUR, Art. 5/9 GDPR) and 50,000 lei (Law 506/2004); in addition, an order to provide regular employee training. Date = publication of the press release; according to the authority, the investigation was concluded in June 2026.
Anyone giving employees access to sensitive customer data must train them and limit access on a need-to-know basis.
Training employees in handling customer data; consent for advertising calls
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Marketing and consent
- Legal basis
- Art. 5 Abs. 1 lit. c i. V. m. Art. 9, Art. 14, Art. 32 Abs. 4 DSGVO; Art. 12 Abs. 1 Gesetz 506/2004
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 6 Aug 2026
Original amount 285,395 RON, converted at the ECB reference rate of 6 Aug 2026.
- ANSPDCP – Comunicat de presă 06.08.2026 (AMATO BESTSELLER S.R.L.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
17 Jul 2026 Orange România SAOrange România pays 100,000 EUR after app errors and hacked ticketing system €99,969
A synchronisation error between two applications allowed a customer to retrieve other customers’ invoices in the mobile app; in addition, the ticketing platform, which was publicly accessible without VPN, MFA or IP restriction, was attacked and a very large data set (including copies of identity documents, card data, IBANs) was exfiltrated. The Romanian data protection authority (ANSPDCP) imposed fines of 104,780 lei (20,000 EUR, Art. 25) and 419,120 lei (80,000 EUR, Art. 32), a total of 523,900 lei, and ordered test and change management. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Never expose internal platforms to the internet without VPN/MFA; software changes to linked systems need testing before go-live.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 25 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 17 Jul 2026
Original amount 523,900 RON, converted at the ECB reference rate of 17 Jul 2026.
- ANSPDCP – Comunicat de presă 17.07.2026 (Orange România SA) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
2 Jul 2026 Banca Transilvania S.A.Employee retrieves account statements for a third party – Banca Transilvania pays 5,000 EUR €5,002
At the request of a third party and outside the scope of his duties, a bank employee retrieved account statements of a data subject (name, IBAN, transactions, balances). The Romanian data protection authority (ANSPDCP) found insufficient technical and organisational measures and imposed 26,172 lei (5,000 EUR); the bank has paid the fine. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Access logs and clear rules against ‘favour queries’ are a duty for every bank.
Access to customer data for business purposes only; handling requests from third parties
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 1, 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 2 Jul 2026
Original amount 26,172 RON, converted at the ECB reference rate of 2 Jul 2026.
- ANSPDCP – Comunicat de presă 02.07.2026 (Banca Transilvania S.A.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
15 Jun 2026 SSG SELECT SOLUTIONS S.R.L.Stranger in Kaufland CCTV room – service provider SSG Select Solutions pays 2,000 EUR €1,948
An employee of the service provider acting as processor for Kaufland România let a third party into a store’s video surveillance room; that person filmed the images and distributed them on social media. Kaufland reported the incident. The Romanian data protection authority (ANSPDCP) imposed 10,200 lei (2,000 EUR) on the processor and ordered additional checks of the work instructions; the fine has been paid. Date = publication of the press release; according to the authority, the investigation was concluded in April 2026.
Anyone with access to surveillance rooms must know: video footage is confidential, and third parties have no access there.
Access to surveillance rooms; staff bound by instructions
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Video surveillance
- Legal basis
- Art. 29, Art. 32 Abs. 1 lit. b, Abs. 2 und 4 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 15 Jun 2026
Original amount 10,200 RON, converted at the ECB reference rate of 15 Jun 2026.
- ANSPDCP – Comunicat de presă 15.06.2026 (SSG SELECT SOLUTIONS S.R.L.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
25 Mar 2026 RENAULT COMMERCIAL ROUMANIE S.R.L.Cyber attack via service provider – Renault Commercial Roumanie pays 125,000 EUR €125,083
In an attack on an application operated by a processor, data of a very large number of persons (including personal identification numbers, driving licence and identity card numbers, vehicle identification numbers) were stolen and published. The Romanian data protection authority (ANSPDCP) criticised the lack of security measures and effectiveness testing as well as the selection of a service provider without sufficient guarantees and imposed 637,262.50 lei (125,000 EUR).
Responsibility for customer data does not end with the service provider – check its security guarantees in advance and monitor them continuously.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data processors
- Legal basis
- Art. 32 Abs. 1 lit. b und d, Abs. 2 i. V. m. Art. 28 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Automotive
- Published
- 25 Mar 2026
Original amount 637,262.5 RON, converted at the ECB reference rate of 25 Mar 2026.
- ANSPDCP – Comunicat de presă 25.03.2026 (RENAULT COMMERCIAL ROUMANIE S.R.L.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Feb 2026 SC Hayat Dent SRLDental clinic Hayat Dent obstructs investigation of data leak – 2,000 EUR €1,999
The clinic’s managing director himself reported that a former employee had copied contact details and patient records of all patients and poached them for a new clinic. In the subsequent investigation, the clinic did not fully answer the requests of the Romanian data protection authority (ANSPDCP) despite a reprimand and an order; the authority therefore imposed 10,190 lei (2,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in February 2026.
Offboarding processes must block data access immediately – and anyone reporting an incident must also support its investigation.
Taking patient data when leaving; cooperation with the supervisory authority
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection
- Legal basis
- Art. 58 Abs. 1, Art. 83 Abs. 5 lit. e DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Healthcare
- Published
- 20 Feb 2026
Original amount 10,190 RON, converted at the ECB reference rate of 20 Feb 2026.
- ANSPDCP – Comunicat de presă 20.02.2026 (SC Hayat Dent SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
19 Jan 2026 Continental Automotive Products SRLExcel list with sick notes circulated internally – Continental Automotive pays 15,000 EUR €14,997
An Excel file containing data from medical certificates of current and former employees was repeatedly circulated within the company; the company reported the incident itself. The Romanian data protection authority (ANSPDCP) imposed 25,455 lei (5,000 EUR) for breach of data minimisation and accountability and 50,911 lei (10,000 EUR) for insufficient security measures and ordered a monitoring and control procedure. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Employees’ health data do not belong in freely forwarded Excel lists – HR departments need fixed access limits.
Handling employees’ health data, e-mail distribution lists
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Employee data
- Legal basis
- Art. 5 Abs. 1 lit. c und Abs. 2, Art. 32 Abs. 1 lit. b und Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Automotive
- Published
- 19 Jan 2026
Original amount 76,366 RON, converted at the ECB reference rate of 19 Jan 2026.
- ANSPDCP – Comunicat de presă 19.01.2026 (Continental Automotive Products SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
12 Aug 2025 Asociația Casa de Ajutor Reciproc „FLEXICREDIT”Credit association Flexicredit grants 17 loans on forged documents – 3,000 EUR €2,990
A school employee gained access to her school’s official e-mail account and sent forged documents on the basis of which the credit association concluded 17 loans in 2023/2024 without the knowledge of the data subjects. The Romanian data protection authority (ANSPDCP) criticised the insufficient identity verification for remote applications and imposed 15,141.6 lei (3,000 EUR). Date = publication of the press release; according to the authority, the investigation was concluded in June 2025.
Remote contracting requires robust identity verification – an e-mail from an ‘official’ address is no proof.
Identity verification and fraud detection in remote applications
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Financial services and insurance
- Published
- 12 Aug 2025
Original amount 15,141.6 RON, converted at the ECB reference rate of 12 Aug 2025.
- ANSPDCP – Comunicat de presă 12.08.2025 (Asociația Casa de Ajutor Reciproc „FLEXICREDIT”) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
24 Apr 2025 Dante International SADante International fails to act on erasure requests – 10,000 EUR €10,000
Although the platform operator had repeatedly confirmed to a customer that his e-mail addresses had been deleted, he continued to receive feedback requests; in addition, certain partners could see the address. The Romanian data protection authority (ANSPDCP) found breaches of transparency and erasure obligations, imposed 49,770 lei (10,000 EUR) and ordered, among other things, training of the staff responsible.
A confirmed erasure must actually be implemented in all systems – including feedback and partner tools.
Handling erasure requests in customer service
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 12 Abs. 1 i. V. m. Art. 17 und 19 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Retail and e-commerce
- Published
- 24 Apr 2025
Original amount 49,770 RON, converted at the ECB reference rate of 24 Apr 2025.
- ANSPDCP – Comunicat de presă 24.04.2025 (Dante International SA) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
20 Jan 2025 Vodafone Romania S.A.Vodafone Romania pays 15,000 EUR for repeated data breaches caused by employees €14,974
Several reported incidents were attributable to employees or service providers: a photo of an invoice sent to third parties, open e-mail distribution lists instead of BCC, a screenshot from the customer application shared via WhatsApp and misdirected invoices. The Romanian data protection authority (ANSPDCP) found insufficient measures to ensure that employees processed data in accordance with instructions and imposed 74,526 lei (15,000 EUR); the company paid. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Many small employee errors add up to an organisational failure – awareness training is mandatory, not optional.
BCC, use of messaging apps, sending customer documents
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 32 Abs. 4 i. V. m. Abs. 1 lit. b DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Telecoms, IT and software
- Published
- 20 Jan 2025
Original amount 74,526 RON, converted at the ECB reference rate of 20 Jan 2025.
- ANSPDCP – Comunicat de presă 20.01.2025 (Vodafone Romania S.A.) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
30 Oct 2024 Untold SRLUntold SRL fails to answer access and erasure request – 15,000 EUR €14,998
Untold SRL left an access request and an erasure request from a data subject unanswered, even though the data subject had provided all contact details. The Romanian data protection authority (ANSPDCP) imposed 49,741 lei (10,000 EUR) in respect of access and 24,870.5 lei (5,000 EUR) in respect of erasure and ordered staff training. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Data subject requests need a ticketing system with the one-month deadline – seasonal event organisers included.
Timely handling of data subject requests
Missing or inadequate training played a role in the decision.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data subject rights and transparency
- Legal basis
- Art. 12 Abs. 3 und 4, Art. 15, Art. 17 Abs. 1 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 30 Oct 2024
Original amount 74,611.5 RON, converted at the ECB reference rate of 30 Oct 2024.
- ANSPDCP – Comunicat de presă 30.10.2024 (Untold SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link
Report an error
5 Mar 2024 EURO MINI STORAGE ROMANIA SRLEuro Mini Storage paralysed for weeks after cyber attack – 5,000 EUR €5,005
A cyber attack on the server paralysed the company for several weeks and allowed access to customer data. The Romanian data protection authority (ANSPDCP) imposed 24,884.50 lei (5,000 EUR) for insufficient security measures and ordered access logging with a retention period of at least 30 days as well as backups. Date = publication of the press release; according to the authority, the investigation was concluded in the previous month.
Logging and tested backups determine whether an attack means days or weeks of downtime.
- Authority / court
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Area of law
- Data protection · Data breaches and data security
- Legal basis
- Art. 24 Abs. 1, Art. 32 Abs. 1 lit. b und d, Abs. 2 DSGVO
- Action
- Fine
- Status of proceedings
- unknown
- Sector
- Other
- Published
- 5 Mar 2024
Original amount 24,884.5 RON, converted at the ECB reference rate of 5 Mar 2024.
- ANSPDCP – Comunicat de presă 05.03.2024 (EURO MINI STORAGE ROMANIA SRL) Press release of an authority
Checked against the official source on 25 Sep 2026 · Direct link