First fine for the application of GDPR Article 25 in Romania
dataprotection.ro
dataprotection.ro
1) The first fine by the Romanian supervisory authority; and
2) The first fine for breach of Article 25.
That's why I chose first Art. 25 fine as the original submission title.
e.g. Why I have to pay 10kk when Unicredit Bank pay only 130k?
Grandparent comment implies otherwise.
https://www.cnil.fr/en/cnils-restricted-committee-imposes-fi...
* google was found in violation of 7 different articles
* it was considered to not have done anything to stop the problem and had reiterated the offense
* the issue affected a significantly larger amount of users (e.g. all android users in france)
Can anybody just shoot them an e-mail to start an investigation?
Justice is not just about the law as written but also whether it can be enforced, the GDPR is not enforced in any meaningful way in the UK and companies know that.
So yeah, this case raises eyebrows, given most foreign banks in Romania are proteges of corrupt politicians and the GDPR agency is lead by members of an infamously corrupt party. Perhaps this bank did something right, to actually get the fine.