The Romanian authority sanctions Banca Transilvania for security breach

A data security breach is characterized when an employee accesses a client's banking information without authorization, even if this access is carried out outside their duties and at the request of a third party, thereby engaging the responsibility of their employer.

Facts and context

The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) has today published a sanction decision against Banca Transilvania S.A. (including the imposition of a fine of €5,000 (26,172 lei)) for breaches related to data security.

The investigation was initiated following a complaint from an individual contesting the processing of their bank account data without their consent.

Reasons for the decision

  • Obligation to ensure the security of processing (Article 32 of the GDPR): The authority found that a bank employee accessed without authorization and outside their service duties the account statements of the data subject, at the request of a third party. This access concerned the name, first name, bank account number, account type, client code, as well as data related to transactions and account balances. The ANSPDCP concluded that the controller had not implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk, notably to ensure that employees acting under its authority only process personal data on its instructions. This failure allowed unauthorized access to the complainant's data for personal purposes.

Authority's decision

Consequently, the authority imposed a fine of €5,000 (26,172 lei) on Banca Transilvania S.A.

Furthermore, the authority ordered the controller to bring its processing operations into compliance with the GDPR. This corrective measure requires the implementation of adequate technical and organizational measures to prevent any illegal access to clients' personal data by employees for personal purposes.

Lessons learned

This decision reminds that:

  • The responsibility of the controller is engaged in case of unlawful access to data by one of its employees, even if the latter acts outside their duties and for personal purposes.
  • Technical and organizational security measures must specifically aim to ensure that employees with access to data only process it on the controller's instructions.
  • Access rights management and access control constitute a fundamental security measure, particularly for financial data, to prevent access abuses by internal staff.
  • Employee access to personal data must be strictly limited to what is necessary for the performance of their tasks, in accordance with the need-to-know principle.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire