The Romanian authority sanctions Altex România for data security issues

A fine of €10,000 is imposed on a retailer for a vulnerability in its mobile application that allowed unauthorized access to a third party's data, aggravated by the failure to notify the breach to the authority and the data subject.

Facts and context

The National Supervisory Authority for Personal Data Processing (ANSPDCP) today published a sanction decision against Altex România S.R.L (including the imposition of a total fine of €10,000) for breaches related to data security and breach management.

The case began following complaints from a natural person reporting possible GDPR violations.

Grounds for the decision

The investigation revealed that a technical vulnerability in the data controller's mobile application allowed a user, during the validation process of their own account, to access the personal data of a third party. The following breaches were identified:

  • Obligation to ensure the security of processing (Article 32 of the GDPR): The authority considered that the existence of this flaw, which led to unauthorized access to data such as the name, first name, invoices, and delivery addresses of a third party, demonstrated that the company had not implemented sufficient technical and organizational measures to ensure a level of security and confidentiality appropriate to the risk.
  • Obligation to notify a data breach to the supervisory authority (Article 33 of the GDPR): It was found that, following this security incident, the data controller did not notify the personal data breach to the ANSPDCP, thus failing its legal obligation.
  • Obligation to communicate a data breach to the data subject (Article 34 of the GDPR): The authority also noted that the company did not inform the data subject whose data had been compromised of the incident, thereby depriving them of the opportunity to take protective measures.

Authority's decision

Consequently, the authority imposed a fine of €10,000 on Altex România S.R.L, broken down as follows: €7,000 for the violation of Article 32, €2,000 for the violation of Article 33, and €1,000 for the violation of Article 34.

Furthermore, the authority ordered the data controller to revise its user account validation and authentication mechanisms, implement periodic vulnerability testing for its application, and establish internal procedures for managing security incidents, including the assessment of notification obligations. The company must also ensure regular training of its staff on these topics and respond in writing to the complainant.

Lessons learned

This decision reminds that:

  • The mere existence of an exploited technical vulnerability is sufficient to characterize a breach of the security obligation under Article 32 of the GDPR.
  • Authentication and account validation processes on mobile applications are critical points that must be subject to regular and thorough security testing.
  • Managing a security incident does not stop at its technical resolution; it must imperatively include an analysis of notification obligations to the supervisory authority and communication to the data subjects.
  • A single technical incident can lead to multiple sanctions if the subsequent notification and communication obligations are not respected, each breach being sanctioned separately.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire