RO EN
← Back to Blog GDPR Fine €5,000 for ACCOUNTING & AUDIT CONSULTING SRL – ANSPDCP Sanction for Data Security Failures

GDPR Fine €5,000 for ACCOUNTING & AUDIT CONSULTING SRL – ANSPDCP Sanction for Data Security Failures

Published on: 04.05.2026  ·  Views: 7

Investigation Overview

In April 2025, the Romanian Data Protection Authority (ANSPDCP) finalized an investigation into ACCOUNTING & AUDIT CONSULTING SRL, following a personal data breach notification submitted under Article 33 GDPR.

The authority found a violation of Article 32 (1) and (2) GDPR and imposed a fine of 24,887 RON (approximately €5,000).

What happened

Unauthorized individuals gained illegal access to personal data belonging to employees of the operator’s clients.

The compromised data included:


This type of data involves a high risk, particularly regarding identity theft and financial misuse.

Identified deficiencies

The authority concluded that the operator failed to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.

Specifically, the operator failed to prevent:


This reflects both technical and organizational shortcomings.

Corrective measures

Under Article 58(2)(d) GDPR, the authority imposed corrective measures, including:


Real impact

Beyond the financial penalty, such incidents may lead to:


Key lessons

Operators should implement:


Conclusion

This case highlights that inadequate security measures inevitably lead to breaches and sanctions.

Data protection must be treated as an ongoing operational priority, not a formal compliance exercise.


Share: Facebook LinkedIn