HOMELUX S.R.L. — Regulatory Disclosure
- Victim: HOMELUX S.R.L.
- Date reported: 2026-07-31
- Country: RO
- Severity: Medium
Romania's data protection authority ANSPDCP sanctioned HOMELUX S.R.L. for infringing Article 32(1)(d) and (2) GDPR after the operator reported a personal data breach caused by a cyberattack on the platform running its website, which was not on the manufacturer's official version and used weak account passwords, leaving customers' names, addresses, email addresses and passwords inadequately protected. Fine: 78,570 lei (EUR 15,000) for the Article 32 infringement, plus 30,000 lei under Article 4(5) of Law no. 506/2004.