The National Supervisory Authority has finalized, on the 7th of November 2019, an investigation with the controller SC CNTAR TAROM SA and noted the infringement of Article 32 paragraph (4) in conjunction with Article 32 paragraphs (1) and (2) of the General Data Protection Regulation.
The investigation was carried out as a result of a data breach notification of the supervisory authority by SC CNTAR TAROM SA dating the 13th of September 2019.
The controller SC CNTAR TAROM SA was sanctioned with a fine of 95,194 lei, the equivalent of 20,000 euros.
The sanction was applied to the controller due to the fact that it did not implement adequate technical and organisational measures in order to ensure that any natural person acting under its authority and having access to personal data only processes them following its request. Related to this aspect, the controller has not taken any appropriate measures in order to ensure a level of security corresponding to the risk generated by the unauthorised disclosure or the unauthorised access to the personal data transmitted, stored or otherwise processed.
This situation led to the unauthorised access, by an employee, of the booking application and the photographing of a list containing the personal data of 22 TAROM passengers/clients and to the unauthorised disclosure in the online environment of this list.
ion of personal data of the beneficiaries of the accommodation services, by reference to the provisions of Article 32 of Regulation (EU) 2016/679.
To read the press release in Romanian, click here
For further information, please contact the Romanian Supervisory Authority: email@example.com
The press release published here does not constitute official EDPB communication, nor an EDPB endorsement. This press release was originally published by the national supervisory authority and was published here at the request of the SA for information purposes. As the press release is represented here as it appeared on the SA's website or other channels of communication, the news item is only available in English or in the Member State's official language with a short introduction in English. Any questions regarding this press release should be directed to the supervisory authority concerned.