Sanction imposed on HOMELUX S.R.L. by the Romanian authority for GDPR and Law 506/2004 breaches

The Romanian authority sanctions an operator for security flaws leading to a data breach, notably the use of an outdated platform and the absence of a strong password policy.

Facts and context

The Romanian data protection authority (ANSPDCP) has today published a sanction decision against HOMELUX S.R.L. (including the imposition of a fine of 78,570 lei (€15,000) and a fine of 30,000 lei) for breaches related to data security and the storage of connection cookies.

The investigation was initiated following the operator's notification of a personal data breach resulting from a cyberattack.

Grounds for the decision

  • Obligation to ensure the security of processing (Article 32 of the GDPR): The authority found that the operator had not implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The security incident resulted from a cyberattack facilitated by the fact that the site platform was not up to date with the official manufacturer's version and that user account passwords lacked complexity. The authority concluded that the operator had not established a process for periodic testing and evaluation of the effectiveness of its measures, thus failing its obligations under Article 32(1)(d) and paragraph 2 of the GDPR.
  • Obligation to obtain consent for storing information in the terminal equipment (Article 4(5) of Law 506/2004): During its investigation, the authority also discovered that the operator stored connection cookies not technically necessary for the functioning of the site and thus accessed information in users' terminal equipment without obtaining their prior consent, in violation of applicable legislation.

Authority's decision

Consequently, the authority imposed a fine of 78,570 lei (€15,000) for the GDPR violation and a fine of 30,000 lei for the breach of Law 506/2004 on HOMELUX S.R.L.

Furthermore, the authority ordered the operator to implement several corrective measures, including: establishing a process for periodic testing and evaluation of systems; strengthening user account security (password complexity, multi-factor authentication for privileged accounts, management of inactive accounts); protecting the web application against vulnerabilities; and bringing cookie management into compliance.

Lessons learned

This decision reminds that:

  • The use of obsolete or outdated software versions on systems processing personal data constitutes a breach of the security obligation under Article 32 of the GDPR.
  • The absence of complexity requirements for user passwords is an insufficient security measure that may engage the data controller's liability in case of an incident.
  • Security of processing implies an active and regular process of testing, evaluation, and assessment of the effectiveness of technical and organisational measures, in accordance with Article 32(1)(d) of the GDPR.
  • Notification of a data breach may trigger a broader investigation by the supervisory authority into the overall compliance of the data controller, including aspects not directly related to the initial incident.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire