Details:

Summary The Romanian DPA (ANSPDCP) has imposed a fine of EUR 200 on the operator of the website declaratieppr.ro. During the Covid19 pandemic, visitors to the site were able to fill out a form that was required to leave their place of residence. Personal data such as name, address and ID number were collected for this purpose. However, the controller was unable to prove that it was processing the data lawfully. In addition, the controller had not sufficiently informed the data subjects about the processing of the data when collecting their personal data and had not implemented sufficient technical and organizational measures to ensure the security of the data processing.
Link: link
Related articles:  Art. 5 (1) a), b), (2) GDPR, Art. 6 (1) GDPR, Art. 13 (1), (2), (3) GDPR, Art. 32 (2) GDPR
Type: Non-compliance with general data processing principles
Fine: EUR 200
Sector Individuals and Private Associations

 

All data is based on The CMS’s Law GDPR Enforcement Tracker Source: https://www.enforcementtracker.com/

Tags: case law