Enel Energie Muntenia SA, utility, fined EUR 3k for GDPR

On 25/Feb/2020, Enel Energie Muntenia SA received a privacy fine of EUR 3,000. The enforcement authority (Romanian National Supervisory Authority for Personal Data Processing) has cited these legal provisions in imposing the fine on Enel Energie Muntenia SA: Article 32 GDPR/ GDPR/

Essentials

Date of enforcement action:
25/Feb/2020
Jurisdiction: Fine imposed:
Romania Flag for Romania, which is the jurisdiction taking enforcement action EUR 3,000 (US$3,300)
Defendant company or entity: Industry segment:
Enel Energie Muntenia SA Utilities /

Case summary

On 25.02.2020, the National Supervisory Authority completed an investigation at the utility operator Enel Energie Muntenia SA and found that it violated the provisions of art. 32 of the General Regulation on Data Protection (GDPR), regarding the security of processing.

The operator Enel Energie Muntenia SA was sanctioned with a fine of 14,423.7 lei, the equivalent of 3,000 EURO.

The violation of the security and confidentiality of personal data consisted in the fact that the operator Enel Energie Muntenia SA mis-transmitted by email the details of a client a natural person, including personal data (name and surname, address, e-mail address, customer code, “eneltel” code).

The operator Enel Energie Muntenia SA was sanctioned for not implementing adequate technical and organizational measures in order to ensure a level of security appropriate to the processing risk generated in particular, accidentally or illegally, by unauthorized disclosure or unauthorized access to personal data.

The National Supervisory Authority carried out the investigation following a notification submitted by a customer of the operator, which was accompanied by conclusive evidence of the matters complained of.

At the same time, a corrective measures were applied to the operator Enel Energie Muntenia SA, based on the provisions of art. 58 para. (2) lit. i) of the GDPR.

Thus, the operator was obliged to ensure compliance with the General Regulation on Data Protection by implementing adequate and effective security measures, both from a technical and organizational point of view, within 30 working days from the these orders.

(Romanian DPA)

Applicable legal provisions

Enforcement information

Enforcement authority: Type of enforcement action:
Romanian National Supervisory Authority for Personal Data Processing Flag for Romania, which is the jurisdiction taking enforcement action Penalty notice
Subject to appeal?
Not known (only the material in the press release has been provided)

File or case number

N/A

Cite this fine in your work

Data Privacy Fines Index. (2020-02-25 04:24) Enel Energie Muntenia SA, utility, fined EUR 3k for GDPR. dataprivacyfines.com. Retrieved from https://dataprivacyfines.com/fine/enel-energie-muntenia-sa-utility-fined-eur-3k-for-gdpr/

Entry last updated: 2020-05-05 04:33 GMT.