The National Supervisory Authority for Personal Data Processing completed, in January 2025 , an investigation at the operator WEBRASOFT SRL and found a violation of the provisions of art. 32 para. (1) let. b) and d) art. 32 para. (2) of Regulation (EU) 2016/679.
As such, the operator was fined 99,518.00 lei (equivalent to 20,000 EURO).
The investigation was initiated following a notification of a personal data breach, in accordance with the provisions of Article 33 of Regulation (EU) 2016/679.
During the investigation, it was found that the operator who owned an online billing site was the victim of a cyber attack, through which the server on which the customer database was stored was illegally accessed.
At the same time, during the investigation, it emerged that the attacker had unauthorized access to personal data held by the operator, which affected the confidentiality of personal data of a large number of customers (surname, first name, personal identification number, home address, telephone number, e-mail address, bank account number).
As a result, it was found that WEBRASOFT SRL did not carry out periodic testing, evaluation and assessment of the effectiveness of technical and organizational measures to guarantee the security of processing , designed to effectively implement the data protection principles and integrate the necessary safeguards into the processing , to meet the requirements of Regulation (EU) 2016/679 and to protect the rights of data subjects, including the ability to ensure the continued confidentiality, integrity, availability and resilience of processing systems and services .
This situation led to unauthorized access by a third party to personal data held by the controller, thus violating the provisions of art. 32 para. (1) letters b) and d) and art. 32 para. (2) of the GDPR .
Pursuant to art. 58 par. (2) letter d) of Regulation (EU) 2016/679, the technical and organizational implementation of a logging system of all valid accesses/errors regarding unsuccessful access attempts on the servers in the operator’s IT infrastructure was ordered, with their retention for a period of at least 30 days, including the back-up of the logging files (logs).
We note that the operator paid the fine imposed.
https://www.dataprotection.ro/index.jsp?page=Comunicat_Presa_04_03_2025&lang=ro