Home » Comunicat presa investigatii aprilie
 Română | English | Francais

Press Release

 

Representatives of the National Supervisory Authority for Personal Data Processing carried out a series of investigations at data controllers in the tourism sector in order to verify the compliance with the provisions of Law no. 677/2001 on the protection of individuals with regard to the processing of personal data and the free movement of such data, as well as with those of Law no. 506/2004 on the processing of personal data and the protection of private life In the electronic communications’ sector.

From the investigations finalised by applying a sanction, we would like to mention the following:

1. As a result of the investigation carried out at SC Vega Turism SA, the following contraventions were ascertained:

- Failure to submit notification and malevolent notification, namely the failure to submit a notification under the conditions of article 22 paragraph (1) of Law no. 677/2001, as this data controller didn’t submit a notification for its processing of personal data with the purpose of monitoring/ensuring the security of persons/spaces and/or of public/private goods by using a video surveillance system from 2012 onwards, which constitutes the contravention provided by article 31 of Law no. 677/2001, as modified and amended;

- The illegal processing of personal data, namely infringing the provisions of article 12 paragraph (1) of Law no. 677/2001 as on the date the minutes of the investigation at SC Vega Turism SA were concluded, the data controller provided no proof of informing the data subjects for processing the personal data with the purpose of “commercials, marketing, advertising”, “hotel and tourist services” and “monitoring/ensuring the security of persons/areas and/or of public/private goods”, which constitutes the contravention provided by article 32 of Law no. 677/2001, as modified and amended;

- Failure to observe the conditions provided by article 4 paragraph (5) of Law no. 506/2004, as modified and amended, as SC Vega Turism SA, for the information stored in the equipment used by end users for the website www.hotelvega.ro, failed to cumulatively meet the conditions provided by article 4 paragraph (5) letters a) and b) of Law no. 506/2004, namely obtaining the end users’ consent for the cookies used on the web site www.hotelvega.ro and provide the information prior to obtaining the users’ consent, the cookies’ lifespan, what information is stored and accessed, as well as allowing the storage and/or the access of third parties to the information stored on the end users’ equipment, which  represents the contravention provided by article 13 paragraph (1) letter i) of Law no. 506/2004, as modified and amended.

As a result of all of the issues mentioned above, the National Supervisory Authority for Personal Data Processing applied a fine to this data controller with a total amount of 8000 lei.

 

2. During the investigation carried out at SC Dovia 95 Impex SRL the following contraventions were ascertained:

- Failure to submit notification and malevolent notification, namely the failure to submit a notification as SC Dovia 95 Impex SRL didn’t submit a notification in accordance with the provisions of article 22 pargraph (1) of Law no. 677/2001 for its processing of personal data for the purposes of “hotel and tourist services” and “monitoring/ensuring the security of persons/areas and/or of public/private goods” through its vide surveillance system, which constitutes the contravention provided by article 31 o Law no. 677/2001.

- the illegal processing of personal data, infringing the provisions of article 4 paragraph (1) letter c) of Law no. 677/2001, as SC Dovia 95 Impex SRL excessively processed its employees’ personal data using the video surveillance system in the hotel and therefore infringed the provisions of article 8 pragraph (3) of NSAPDP’s Decision 52/2012, as well as those of article 12 paragraph (1) of Law no. 677/2001 and also due to the fact that the data controller had taken no measure to inform the data subjects for the processing of their personal data in the propose of “hotel and tourism services”, which constitutes the contravention provided by article 32 of Law no. 677/2001.

Therefore, the National Supervisory Authority for Personal Data Processing applied a sanction with a total amount of 8000 lei to this data controller.

 

3. During the investigation carried out at SC K & D London Entertainment SRL the following contraventions were ascertained:

- Failure to submit notification and malevolent notification under the conditions of article 22 of Law no. 677/2001, as K & D London Entertainment SRL didn’t notify its processing of personal data in the purpose of “monitoring/ensuring the security of persons/areas and/or of public/private goods” using its video surveillance system and infringing the provisions of article 22 paragraph (1) of Law no. 677/2001, which constitutes the contravention provided by article 31 of Law no. 677/2001;

- the illegal processing of personal data in the sense of infringing the provisions of article 12 of Law no. 677/2001, as SC K & D London Entertainment SRL provided no proof of informing its clients (data subjects) on the form used to enlist them in the loyalty programme, nor with regard to processing their personal data for “hotel and tourism services” and didn’t provide any evidence of informing clients on the use of the video surveillance system, which constitutes the contravention provided by article 32 of Law no. 677/2001;

- failure to observe the obligations on confidentiality and applying the security measures, namely not complying with the obligation to apply security measures and maintain the confidentiality of the data processing as provided under article 20 of Law no. 677/2001, as modified and amended, as the security procedure for the processing of personal data wasn’t entirely compliant with the provisions of Order no. 52/2002, which constitutes the contravention provided by article 33 of Law no. 677/2001, as modified and amended.

As a result of the issues mentioned above, the National Supervisory Authority for Personal Data Processing applied a fine with a total amount of 9000 lei to this data controller.

 

4. During the investigation carried out at SC Confiden Travel SRL the following contraventions were ascertained:

- Failure to notify and malevolent notification, namely failure to comply with the obligation under the conditions provided by article 22 of Law no. 677/2001 as SC Confiden Travel SRL didn’t notify its processing of personal data carried out for the purpose of “hotel and tourism services” and “commercials, marketing and advertising” as well as for video surveillance, which constitutes the contravention provided by article 31 of Law no. 677/2001;

- the illegal processing of personal data as SC Confiden Travel SRL couldn’t provide any evidence that it informed the data subjects in accordance with the provisions of Article 12 of Law no. 677/2001, for its processing of personal data for the purpose of “hotel and tourism services” and “commercials, marketing and advertising”, which constitutes the contravention provided by article 32 of Law no. 677/2001;

- failure to comply with the obligations on confidentiality and applying the security measures, namely the contravention provided by article 33 of Law no. 677/2001, as modified and amended, by failing to comply with the obligations on the security measures and ensuring the confidentiality of the data processing, as provided by article 20 of Law no. 677/2001, as SC Confiden Travel SRL hadn’t drawn up and implemented a security policy for its processing of personal data and its employees charged with processing personal data didn’t receive adequate training in this respect;

- failure to comply with the conditions provided by article 4 paragraph (5) of Law no. 506/2004, as modified and amended, as SC Confiden Travel SRL, for the information stored and accessed on the end users’ equipment for its website www.ramadapitesti.ro, cumulatively failed to comply with the obligations provided by article 4 paragraph (5) letters a) and b) of Law no. 506/2004, as modified and amended, namely obtaining the end users’ consent for the cookies used on that website and providing, prior to obtaining the consent, the information on the general purpose for using cookies, their lifespan, which information is stored and accessed as well as whether third parties are allowed access to this information, which constitutes the contravention provided by article 13 paragraph (1) letter i) of Law no. 506/2004, as modified and amended.

As a result of the issues mentioned above, the National Supervisory Authority for Personal Data Processing applied a sanction with a total amount of 11.000 lei for this data controller.