The National Authority for the Supervision of Personal Data Processing (ANSPDCP) has fined Unicredit Romania 12,000 euros for violating legislation regarding the protection of personal data. The investigation, completed in May 2026, was triggered by a complaint that reported possible violations. ANSPDCP found that the bank had sent erroneous notifications to clients with expired insurance policies, disclosing names, addresses, and other personal information. The error was caused by improper processing of a file.
Unicredit was fined with two penalties: 10,000 euros for failing to implement security measures and 2,000 euros for delaying the notification of the security incident. The bank did not provide an adequate level of data protection, which led to the unauthorized disclosure of clients' personal information.
Sources
Latest News
17:30
17:26
17:26
17:25
17:24
See more news