The Romanian authority sanctions Orange România for security failures
Facts and context
The Romanian data protection authority (ANSPDCP) has today published a sanction decision against Orange România SA, including the imposition of a total fine of 523,900 lei (equivalent to €100,000), for failures related to data protection by design and the security of processing.
The case originated from a personal data breach notification submitted by the operator itself, in accordance with Article 33 of the GDPR.
Reasons for the decision
- Data protection by design obligation (Article 25(1) of the GDPR): The authority found that the operator had not implemented appropriate technical and organizational measures during the configuration and use of its digital platforms. A synchronization error between two interconnected applications caused a misidentification between a customer's account and that of an employee. This design failure allowed a customer to access and download invoices of other customers, resulting in unauthorized disclosure of data (name, first name, addresses, identity card number, invoice details).
- Security of processing obligation (Article 32 of the GDPR): The investigation revealed that the operator had not implemented adequate security measures to protect its ticketing platform and had not periodically tested the effectiveness of its systems. The platform was publicly exposed without basic measures such as a secure connection (virtual private network), two-factor authentication, or IP address access restriction. This vulnerability enabled a cyberattack resulting in the exfiltration of a very large volume of varied personal data, including copies of identity cards, banking information, and authentication data.
Authority's decision
Consequently, the authority imposed a fine of 523,900 lei (equivalent to €100,000) on Orange România SA, divided into 104,780 lei (€20,000) for the breach of Article 25 and 419,120 lei (€80,000) for the breach of Article 32.
Furthermore, the authority ordered the operator to implement a monitoring and testing process for all its IT applications. This process must allow control of all software changes (updates, configuration changes, interconnections) and include subsequent tests to identify vulnerabilities that could lead to unauthorized access to personal data.
Lessons learned
This decision reminds that:
- Data protection by design requires particular vigilance when interconnecting applications to prevent synchronization errors that may cause incorrect account associations.
- The public exposure of a business application without fundamental security measures, such as a secure connection, multi-factor authentication, or IP filtering, constitutes a violation of the security obligation.
- The absence of regular testing and assessments of the effectiveness of security measures is itself a failure to ensure a level of security appropriate to the risk.
- A design failure in processing can lead to a data breach as serious as a vulnerability exploited by an external cyberattack.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire