The Romanian authority fines Poliserv JG for GDPR violation following a phishing attack
The Romanian authority sanctions a company for a data breach resulting from a phishing attack, highlighting that the lack of regular testing of the effectiveness of security measures and staff training constitutes a failure to comply with the security obligation of processing.
Facts and context
The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) issued a sanction decision against Poliserv JG (PJG) SRL, including a fine of €3,000, for breaches related to data processing security.
The case originated from a notification of a personal data breach made by the company itself, in accordance with Article 33 of the GDPR.
Grounds for the decision
- Obligation to ensure the security of processing (Article 32 of the GDPR): The authority found that a phishing cyberattack allowed the theft of an administrator account's credentials, leading to unauthorized access to personal data (at least first and last names) of clients. It considered that the controller had not implemented appropriate technical and organizational measures, notably by failing to conduct periodic tests and assessments of the effectiveness of its measures to ensure the security of processing. This failure compromised the ability to ensure the confidentiality, integrity, availability, and continuous resilience of systems, in violation of the requirements of Article 32, paragraph 1, point b), and paragraph 2.
Authority's decision
Consequently, the authority imposed a fine of 15,728 lei (approximately €3,000) on Poliserv JG (PJG) SRL.
Furthermore, the authority ordered the company to periodically verify compliance with internal procedures related to data protection and information security. It also mandated regular training of personnel under its authority on risks related to data processing, including the identification and management of phishing messages and other suspicious emails.
Lessons learned
This decision reminds that:
- The implementation of technical and organizational security measures must be complemented by periodic tests and assessments to ensure their effectiveness over time.
- Regular staff training on threat identification, such as phishing, is an essential organizational measure to prevent unauthorized access to data.
- A data breach resulting from a successful phishing attack is likely to reveal a deficiency in security measures, engaging the controller's responsibility under Article 32 of the GDPR.
- The security of processing relies as much on robust and regularly audited internal procedures as on employee awareness and continuous training.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire