The Romanian authority sanctions AMATO BESTSELLER S.R.L for non-compliant commercial prospecting
Facts and context
The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) today published a sanction decision against AMATO BESTSELLER S.R.L. (including the imposition of a total fine of 285,395 lei, approximately €54,560) for breaches related to security, information to data subjects, data minimization, and commercial prospecting.
The investigation was initiated following several complaints from data subjects reporting potential GDPR violations.
Grounds for the decision
- Obligation to ensure that personnel act only on instructions (Article 32(4) of the GDPR): The authority found that the controller had not implemented measures to ensure that its personnel accessed data only on instruction. In the absence of adequate procedures, policies, and training, employees and former employees were able to access personal data of a considerable number of individuals without authorization. The data concerned included identification information, details about personal and professional life, family data, income information, and health data.
- Obligation to inform when collecting data indirectly (Article 14 of the GDPR): It was established that the operator did not provide data subjects with correct and complete information about the processing of their personal data. The information provided did not comply with the transparency and content requirements set out by the GDPR.
- Obligation of data minimization (Article 5(1)(c) of the GDPR) and processing of special categories of data (Article 9 of the GDPR): The investigation revealed that the company processed excessive data that was neither adequate, relevant, nor limited to what was necessary for the purposes pursued. This collection included special categories of data, notably health data, in violation of the minimization principle.
- Prohibition of prospecting by automated calling without consent (Article 12(1) of Law 506/2004): The authority also found that the operator conducted commercial communications to a significant number of individuals using automated calling systems without human intervention. These calls were made without users having previously given their explicit consent to receive such communications, in violation of electronic communications legislation.
Authority's decision
Consequently, the authority imposed a total fine of 285,395 lei (approximately €54,560) on AMATO BESTSELLER S.R.L., allocated as follows: €15,000 for the violation of Article 32(4), €10,000 for that of Article 14, €20,000 for breaches of Articles 5(1)(c) and 9, and 50,000 lei for the violation of Law 506/2004.
Furthermore, the authority ordered the company to implement several corrective measures:
- Define and implement clear procedures on data flows, differentiated staff access, and periodic employee training.
- Ensure complete and transparent information to data subjects, in accordance with Articles 12 and 14 of the GDPR.
- Guarantee that data processing respects the minimization principle for each purpose.
- Establish a mechanism to collect explicit and prior consent from individuals before any unsolicited commercial communication.
Lessons learned
This decision reminds that:
- Data security relies not only on technical measures but also on robust organizational measures, including clear policies, precise instructions, and regular staff training to prevent unauthorized access.
- The collection of any data, especially special categories such as health data, must be rigorously justified by the purpose of the processing and strictly limited to what is necessary.
- The transparency obligation requires providing complete and accurate information to data subjects, including when data is not collected directly from them.
- Consent for commercial prospecting by automated calling must be explicit and obtained prior to any communication; absence of refusal does not constitute consent.
- A lack of internal governance (absence of procedures, training) is an aggravating factor that can lead to multiple and cumulative GDPR violations.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire