Home

Some companies that have chosen us

Privacy Officer and Privacy Consultant
CDP Scheme according to ISO/IEC 17024:2012
European Privacy Auditor
ISDP©10003 Certification Scheme according to ISO/IEC 17065:2012
Auditor
According to standard UNI 11697:2017
Lead Auditor ISO/IEC 27001:2022
According to standard ISO/IEC 17024:2012
Data Protection Officer
According to standard ISO/IEC 17024:2012
Anti-Bribery Lead Auditor Expert
According to standard ISO/IEC 17024:2012
ICT Security Manager
According to standard UNI 11506:2017
IT Service Management (ITSM)
According to the ITIL Foundation
Ethical Hacker (CEH)
According to the EC-Council
Network Defender (CND)
According to the EC-Council
Computer Hacking Forensics Investigator (CHFI)
According to the EC-Council
Penetration Testing Professional (CPENT)
According to the EC-Council

Professional qualifications

Stay up-to-date with world news!

Select your topics of interest:

News

Home / News
/
ROMANIAN SUPERVISORY AUTHORITY: Sanctions for the violation of GDPR

ROMANIAN SUPERVISORY AUTHORITY: Sanctions for the violation of GDPR

The Authority has completed, on 14.04.2020, an investigation at the operator Banca Comercială Română SA, he found out that some provision had been violated, respectively art. 32 cpv. (4) in conjunction with Art. 32 cpv. (1) and para. (2) of the General Data Protection Regulation.

The operator of Banca Comercială Română SA was fined 24163.50 lei, the equivalent of EUR 5000.

The investigation was initiated upon receipt of a complaint and, during its conduct, The National Supervisory Authority found that Banca Comercială Română SA did not implement adequate technical and organisational measures to ensure a level of security appropriate to the risk of processing.

At the same time, the processor has not taken any measures to ensure that any natural person acting under his authority who has access to personal data processes them only at his request, unless such an obligation is incumbent upon him under the law. Union or national law.

Therefore, it was found that there was a collection of copies of individual client identity documents (minors and legal representatives) by the personal telephone of an employee of the operator, as well as the transmission of copies of these documents to the operator, through the Whatsapp application, in violation of the internal working procedure.

SOURCE: AUTORITA’ PER LA PROTEZIONE DEI DATI DELLA ROMANIA

Recommended to you

Advanced Research