On 11 June 2020, the Romanian DPA announced two controllers were fined for GDPR violations:
- a EUR 3000 fine was imposed on a cosmetic company for processing data (including health data) without a legal basis and a guarantee under 9 of GDPR;
- a EUR 3000 fine was imposed on a telecommunications company for failure to implement sufficient security measures to ensure the accuracy of data.