A telecommunications services company fined EUR 100,000 for inadequate data security measures

24.07.2026

On June 17, 2026, the Romanian DPA concluded an investigation into a telecommunications services company. According to the DPA, the controller had failed to implement appropriate technical and organisational measures when configuring and operating its digital platforms to ensure the protection of its users’ rights. As a result, the DPA issued an administrative fine amounting to RON equivalent of EUR 20,000.

The investigation commenced following a personal data breach notification submitted by the controller and established that the security incident occurred within the controller’s mobile application, where one customer was able to access and download equipment invoices belonging to other customers. The incident resulted from a synchronisation error between two interconnected applications operated by the controller, which incorrectly linked a customer’s account to the account of one of the controller’s employees.

Further to its investigation, the DPA indicated that the controller had failed to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk and to periodically test the effectiveness of its security systems. This vulnerability was in a cyberattack targeting the controller’s ticketing application, resulting in the unauthorised access and disclosure of personal data processed through the application. The platform was publicly accessible without appropriate security measures, allowing a substantial volume of personal data to be unlawfully exfiltrated, including first and last names, personal identification numbers, identity card series and numbers (including copies of identity cards), bank card information, IBAN numbers, and SIM card numbers. Consequently, the DPA imposed an additional administrative fine amounting to the RON equivalent of EUR 80,000.

In addition to the fines, the DPA ordered the controller to implement appropriate technical and organisational measures by establishing a monitoring and testing process for all IT applications used in its operations, .ensuring oversight of all software changes (including updates, configuration changes, and interconnection processes) and identifying, through subsequent testing, vulnerabilities that could lead to unauthorised access to personal data.

The press release is available here (Romanian language only).

Statistics