From Incident to Compliance Lesson: What the ANSPDCP Says About Data Security

Compliance Isn’t Just a Claim – It Must Be Demonstrated: Lessons from the ANSPDCP’s Latest Sanction Regarding Article 32 of the GDPR.

Thank you for reading this post, don't forget to subscribe!

The National Supervisory Authority for Personal Data Processing (ANSPDCP) provides a relevant benchmark for understanding the obligation set forth in the provisions of Article 32 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), commonly known as the “GDPR” or “RGPD.”

The investigation, recently launched following the controller’s notification of a cyberattack on its infrastructure, revealed deficiencies regarding system confidentiality, the periodic testing of security measures, and access monitoring.

The Authority also ordered, as a corrective measure, the implementation of logging mechanisms, with logs to be retained for at least 30 days. The provisions of Article 32 require maintaining a level of protection appropriate to the risk throughout the entire duration of processing. In this context, periodic testing, access monitoring, and the remediation of vulnerabilities are components of the compliance obligation, not merely technical best practices. The ANSPDCP sanction must therefore be understood within a broader framework of accountability and proof of compliance. The controller must be able to demonstrate not only the existence of policies and controls, but also that these have been assessed, tested, and adapted in light of the specific risks. Even the 30-day log retention period should be treated with caution. This represents a corrective measure ordered in the specific circumstances of the case and cannot be transformed into a general storage standard.

Essentially, Article 32 of the GDPR requires continuous security governance, in which risk assessments, technical measures, monitoring, testing, and documentation must form a coherent whole capable of demonstrating, at any time, the adequacy of the level of protection adopted by the controller.

Source: ANSPDCP website: https://www.dataprotection.ro/