RO EN
← Back to Blog ANSPDCP fines CV PRO CONSULT S.R.L. for violating Article 32 GDPR: RON 9,955 penalty following major cyberattack

ANSPDCP fines CV PRO CONSULT S.R.L. for violating Article 32 GDPR: RON 9,955 penalty following major cyberattack

Published on: 28.04.2026  ·  Views: 24

Incident background: data breach notification under Article 33 GDPR

The investigation was initiated after CV PRO CONSULT S.R.L. submitted a data breach notification, as required by Article 33 GDPR. The operator reported a cyberattack that compromised its internal IT infrastructure, leading to:


Personal data exposed during the breach

The cyberattack resulted in unauthorized access to a significant volume of personal data, including:


These categories of data are considered high‑risk, and their exposure may lead to identity theft, fraud, or professional harm.

ANSPDCP findings: inadequate technical and organizational measures

The Authority concluded that the operator failed to implement appropriate technical and organizational measures, in breach of Article 32 GDPR. Key deficiencies included:


Corrective measures imposed

Under Article 58(2)(d) GDPR, ANSPDCP ordered the operator to:


The operator has paid the imposed fine.

Conclusion: a strong reminder for organizations handling sensitive data

This case highlights the critical importance of:


In an era of increasing cyber threats, GDPR compliance is not merely a legal requirement but a fundamental component of enterprise risk management.


Share: Facebook LinkedIn