The Romanian authority sanctions GEROCOSSEN S.R.L for failures in the security of personal data processing
A data breach notification following a cyberattack led the Romanian authority to sanction the data controller, not for the breach itself, but for the failure to implement appropriate technical and organizational security measures, revealed by the incident.
Facts and context
The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) published a sanction decision against GEROCOSSEN S.R.L., including the imposition of a fine of €5,000, for failures related to the security of data processing.
The case originated from the company's notification of a personal data breach following a cyberattack, which resulted in unauthorized disclosure or access to identification and contact data.
Grounds for the decision
- Obligation to ensure the security of processing (Article 32 of the GDPR): The authority found that the data controller had not implemented adequate technical and organizational measures to ensure a level of security appropriate to the risk. In particular, the investigation revealed an inability to ensure the ongoing confidentiality and integrity of processing systems and services, in violation of the provisions of Article 32, paragraph 1, point b), and paragraph 2 of the GDPR. The occurrence of the attack and the resulting data breach were considered proof of this structural security failure.
Decision of the authority
Consequently, the authority imposed a fine of 26,236.50 lei (€5,000) on GEROCOSSEN S.R.L.
Furthermore, the authority ordered the company to implement monitoring and logging systems for access to its IT infrastructure. These measures must include a retention period for access logs of at least 30 days as well as a backup process for these logs.
Lessons learned
This decision reminds that:
- Notification of a data breach can trigger a broader investigation into the overall compliance of the organization's security measures, beyond the management of the incident itself.
- The absence of monitoring and logging systems for access to information systems constitutes a failure to meet the obligation to ensure security appropriate to the risk.
- The ability to guarantee the "ongoing" confidentiality and integrity of systems, as required by the GDPR, implies the implementation of proactive measures for incident detection and analysis.
- The materialization of a security risk by a successful attack can be considered by an authority as proof of a failure in the implementation of appropriate technical and organizational measures.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire