The Romanian authority fines Dormeo Home SRL for non-compliance with the right to object
The Romanian data protection authority sanctions a company for failing to respect an individual's right to object to direct marketing, emphasizing that merely receiving the request is not sufficient without its effective implementation.
Facts and context
The National Supervisory Authority for Personal Data Processing (ANSPDCP) today published a sanction decision against Dormeo Home SRL, including the imposition of a fine of 10,517 lei (equivalent to €2,000) for breaches related to the right to object.
The investigation was initiated following a complaint from a data subject who, after exercising their right to object to direct marketing, continued to receive unsolicited calls and messages.
Reasons for the decision
- Obligation to respect the right to object (Article 21 of the GDPR): The authority found that although the data subject explicitly exercised their right to object to the processing of their data for direct marketing purposes, the company did not implement the necessary measures to comply with this request. The investigation revealed that the individual continued to receive commercial phone calls and text messages after their objection request. The authority therefore concluded that continuing this processing despite the expressed objection constituted a violation of the GDPR.
Authority's decision
Consequently, the authority imposed a fine of 10,517 lei (equivalent to €2,000) on Dormeo Home SRL.
Furthermore, the authority ordered the company to take appropriate technical and organizational measures to ensure compliance with the GDPR provisions, particularly regarding the processing of data for marketing purposes and to ensure the effective respect of data subjects' rights by itself and its processors.
Lessons learned
This decision reminds that:
- The implementation of the right to object must be effective and immediate. It is not enough to acknowledge receipt of the request; the controller must ensure that the processing of data for direct marketing purposes ceases across all communication channels.
- The absence of technical and organizational measures to manage and apply objection requests constitutes a breach in itself, rendering any subsequent processing for marketing purposes unlawful.
- The controller is required to ensure that respect for individuals' rights, including the right to object, is also guaranteed by any processors acting on its behalf.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire