Home

Some companies that have chosen us

Privacy Officer and Privacy Consultant
CDP Scheme according to ISO/IEC 17024:2012
European Privacy Auditor
ISDP©10003 Certification Scheme according to ISO/IEC 17065:2012
Auditor
According to standard UNI 11697:2017
Lead Auditor ISO/IEC 27001:2022
According to standard ISO/IEC 17024:2012
Data Protection Officer
According to standard ISO/IEC 17024:2012
Anti-Bribery Lead Auditor Expert
According to standard ISO/IEC 17024:2012
ICT Security Manager
According to standard UNI 11506:2017
IT Service Management (ITSM)
According to the ITIL Foundation
Ethical Hacker (CEH)
According to the EC-Council
Network Defender (CND)
According to the EC-Council
Computer Hacking Forensics Investigator (CHFI)
According to the EC-Council
Penetration Testing Professional (CPENT)
According to the EC-Council

Professional qualifications

Stay up-to-date with world news!

Select your topics of interest:

News

Home / News
/
ROMANIAN SUPERVISORY AUTHORITY: Sanction for violation of the GDPR

ROMANIAN SUPERVISORY AUTHORITY: Sanction for violation of the GDPR

The National Supervisory Authority for Personal Data Processing completed an investigation into the operator Meedea Construct Prest SRL in January 2025 and found a violation of the provisions of art. 5 para. (1) let. a), b) and f) and para. (2) in conjunction with art. 6 and 9 of Regulation (EU) 2016/679.

As such, the operator was sanctioned:

  • with a fine of 9,949.6 lei (the equivalent of 2,000 euros).

The investigation was initiated following a complaint from an individual, who claimed that the operator Meedea Construct Prest SRL (former employer) disclosed to another third party documents related to his employment (copy of the individual employment contract, skills sheet, a medical certificate) and that third party used them in a court dispute.

During the investigation, it was found that the operator Meedea Construct Prest SRL disclosed, without complying with the legal conditions, personal and health data belonging to the petitioner (former employee), such as: name, surname, address, identity card series and number, personal identification number, position/job/occupation, signature, date of birth, home address, medical conditions, doctor’s signature and initials.

In this context, the provisions of art. 5 para. (1) letters a), b) and f) and para. (2), art. 6 and 9 of the GDPR, regarding the principles and legality of the processing of personal data, were violated, the operator being fined.

At the same time, pursuant to the provisions of art. 58 para. (2) letter b) of Regulation (EU) 2016/679, the operator was ordered to take the corrective measure to ensure compliance with the GDPR of the collection and subsequent processing of personal data, so as to avoid accessing and disclosing personal data processed in violation of the principles and conditions of lawfulness; in this regard, consideration will also be given to the application of appropriate security and confidentiality measures, by establishing written procedures and regular training of persons who process data under the authority of the operator.

https://www.dataprotection.ro/index.jsp?page=Comunicat_Presa_17_02_2025&lang=ro

Recommended to you

Advanced Research