The Romanian authority sanctions Ascendex Technology SRL for failing to meet data erasure deadlines in a cross-border case
Facts and context
The Romanian data protection authority (ANSPDCP) has today published a sanction decision against Ascendex Technology SRL, including the imposition of a fine of €11,000, for failures related to the management of data subject rights requests.
The case originated from a complaint submitted by the French authority (CNIL), which designated the Romanian authority as the lead supervisory authority due to the sole establishment of the data controller in Romania, pursuant to Article 4, point 23, letter b), of the GDPR.
Grounds for the decision
- Obligation to facilitate the exercise of rights and to respond within deadlines (Article 12 and Article 17 of the GDPR): The authority found that the data controller processed the complainant's erasure request within about 12 months, without providing a final response or justifying the legal deadline overrun. The investigation also revealed that other erasure requests from data subjects in various Member States or third countries were processed with delays of up to 37 months. The authority concluded that these failures violated the obligations to facilitate the exercise of rights and to provide a response within the prescribed deadlines.
Authority's decision
Consequently, the authority imposed a fine of 57,839 lei (approximately €11,000) on Ascendex Technology SRL.
Furthermore, the authority ordered the data controller to provide an appropriate response to the complainant and other data subjects in similar situations, and to implement regular training for its staff on managing data subject rights requests in compliance with GDPR requirements.
Lessons learned
This decision reminds that:
- Compliance with response deadlines to data subject rights requests (one month, extendable by two months) is a strict obligation, and delays of several months constitute a serious violation.
- Failure to respond to a data subject, even if their request is processed internally, constitutes a separate breach of the transparency and information obligation.
- Any extension of the response deadline beyond one month must be duly justified to the data subject, in accordance with Article 12, paragraph 3, of the GDPR.
- The discovery of systemic failures affecting multiple data subjects over a long period is an aggravating factor considered by authorities when determining the amount of the sanction.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire