On 6 August 2026, the Romanian DPA concluded an investigation into a retail company. According to the DPA, the controller committed several GDPR infringements concerning data security, transparency, and data minimization. As a result, the DPA issued administrative fines amounting to RON equivalent of EUR 45,000.
The investigation commenced following complaints submitted by several data subjects, who reported possible GDPR violations. During the investigation, the Romanian DPA found that the company failed to adequately instruct its employees or provide them with relevant internal procedures or policies governing the processing of personal data, resulting in insufficient safeguards against unauthorized or unlawful processing. This deficiency resulted in current and former employees having unauthorized access to personal data relating to a significant number of data subjects, including names, surnames, telephone numbers, degrees of kinship between data subjects, occupations, marital status, classification of individuals within social categories, cities of domicile/residence, income data, family data, and health data.
The investigation further established that the controller had failed to comply with its transparency obligations under GDPR by not providing data subjects with complete information regarding the processing of their personal data. Moreover, it was found that the company had collected and processed personal data beyond what was necessary for its stated purposes, including special categories of personal data.
The DPA further determined that the controller made automated commercial communications without human intervention by calling the telephone numbers and conducting conversations with a significant number of data subjects, without having obtained their prior express consent to receive such communications, leading to an additional administrative fine amounting to approximately the RON equivalent of EUR 10,000.
In addition to the fine, the DPA ordered the controller to implement appropriate internal procedures for processing personal data and to restrict employees’ access rights based on operational needs, provide regular data protection training, and update its privacy notices to comply with the GDPR’s transparency requirements. The DPA further required the controller to ensure compliance with the data minimization principle and obtain valid consent prior to conducting automated marketing campaigns.
The press release is available here (Romanian only).
