A €8,000 fine: The 3 Hidden Lessons Every Company in Romania Must Learn
GDPRfines may seem to be an abstract issue for companies that have not faced them directly. They are often perceived as figures in a press release, removed from...
GDPRfines may seem to be an abstract problem for companies that have not faced them directly. They are often perceived as figures in a press release, away from daily operational reality. However, recently, a case in Romania has brought these risks to the forefront. PGS SOFA & CO SRL, a large furniture manufacturer with 772 employees, has been fined with €8,000 by the National Supervisory Authority (ANSPDCP). Beyond numbers, this case acts as an X-ray of the cyber governance failure, offering three painful but essential games, which no company in Romania can afford to ignore.
The True Sin: Negligence, Not Just Cyber Attack
The first and most important lesson is that the sanction was not applied. Just because The company was the victim of a cyber attack. The attacks happen, and regulators understand this. The central point of the ANSPDCP decision was the company’s failure to demonstrate that it has implemented appropriate security measures to prevent or limit such an incident.
The most serious violation, according to the authority, was that of Article 32(2) ofGDPR. This aspect highlights a governance failure, not just a technical vulnerability. The key finding in the ANSPDCP communication is eloquent:
The controller has not carried out periodic testing, evaluation and assessment of the effectiveness of technical and organizational measures to guarantee the security of the processing.
The lesson is sharp: holding security policies is irrelevant without evidence of their rigorous and constant testing. In front of the regulator, the lack of this evidence turns a victim of a cyber attack into a culprit operator of negligence, a distinction that is at the heart of the entireGDPRphilosophy.
Index in Treatment: A Banal Mistake with Serious Consequences
Often, the best clues about the cause of a problem are found in the proposed solution. In this case, the corrective measures imposed by the ANSPDCP are extremely revealing. The Authority has compelled the company to implement two specific measures under Article 58(2)(d):
• Implementarea Multifactor authentication (MFA) for all accounts with remote access.
• Implementarea unei politici de complexitate a parolelor.
These measures are not random; they function as a post-incident diagnosis. The mandatory implementation of MFA and a complex password policy directly indicates the weak link: network access was compromised by weak, single-factor credentials, most likely for a remote connection (VPN or RDP).
The message is strong: a catastrophic breach, which exposed highly sensitive data such as employees’ salaries, but also customers’ and collaborators’ bank accounts, was triggered by a fundamental negligence in cybersecurity.
Top of the iceberg: Why €8,000 Is the Smallest Problem
The €8,000 fine, although visible, is only a small part of the total cost of this incident.The actual impact is much deeper and more expensive, covering several areas:
• The operational costs: This diplomatic formulation — “restricting the operator’s access to its own IT infrastructure” — actually describes an operational disaster, most likely a ransomware attack. For a furniture manufacturer with 772 employees, this means shutting down production lines, the inability to process orders, issue bills or manage logistics. Every hour of IT paralysis translates into direct financial losses and delays in the supply chain, with an exponentially greater impact than the fine itself.
• Costurile de remediere: The company is now required to allocate an unforeseen but considerable budget to comply. We are not just talking about the cost of some software licenses for MFAs. We are talking about a complex implementation and integration project that can take months, consulting costs for auditing new policies and, most importantly, training costs for hundreds of employees. These are forced investments made under pressure, not as part of a planned strategy.
• Reputation and human costs: Per the most toxic cost is human. Endangering salaries and bank accounts for “a significant number of employees, customers and collaborators” destroys confidence from within. A company that cannot protect its own team’s financial data faces low morale, risk of leaving and opens the door to civil action by affected individuals, whose private data is now potentially in the hands of cybercriminals.
Here are the specific sources used to describe the incident and its consequences, organized by categories:
Sanction and investigation of the ANSPDCP
Information about the cyberattack, violated articles of the GDPR, the fine imposed and mandatory corrective measures comes directly from the official communications of the supervisory authority and the legal analysis of the case:
Details of Source(s)
-
Sanction (Data & Sum) — The fine of RON 40.663 (equivalent to EUR 8.000) applied to the operator PGS SOFA & CO SRL was announced on 17.11.2025.
-
GDPR Articles Violated – Violation of Article 32 (1) (b) and (d) and (2) of Regulation (EU) 2016/679 (GDPR) has been found.
-
The Operator has not implemented appropriate technical and organizational measures and has not carried out the periodic testing, evaluation and evaluation of the effectiveness of security measures.
-
Mandatory Corrective Measures – Corrective measures have been ordered (according to Article 58(2)(d)), including the implementation of multifactorial authentication (MFA) and a password complexity policy for remote access accounts.
-
Main Source (ANSPDCP Communication) — Communicat_Presa_17.11.2025 - Dataprotection.ro
-
Tracker & Analysis — The information is corroborated byGDPREnforcement Tracker and analyzed in detail in the Regulatory Sanction and Data Security Failure Analysis Report.
The nature of the attack and compromised data
The description of the incident as a “cyber attack” and details of the data exposed are taken from the ANSPDCP official statement and the analysis reports:
Details of Source(s)
-
The attack was a cyber attack that resulted in unauthorized access and at the same time restricted the operator’s access to its own IT infrastructure.
-
Sensitive Data Exposed – The data accessed unauthorized belonged to a significant number of employees, customers and collaborators, including: identification data, salaries and bank accounts.
-
Data Risk – Exposure to salaries and bank accounts involves a high risk of financial damage, identity theft or fraud.
3. Contextul Corporativ al PGS SOFA & CO SRL
Information about the identity and scale of the company helps to establish the jurisdictional context and GDPR obligations:
Details of Source(s)
-
Company identification — The legal name is PGS SOFA & CO SRL, with tax code 6416487.
-
Main business — The company is a manufacturer of furniture (fabrication of furniture, especially carpets), classified under code CAEN 3109.
-
Location — The headquarters is in Oradea, Bihor County.
-
Corporate affiliation — The company is a member of Parisot/P3G Group, a European furniture leader, founded in France.
-
Company size — By 2024, the company had 772 employees.
A Mirror for Your Own Safety
Finally, the case of PGS SOFA & CO is not a simple story about a fine, but a clear warning: in the eyes of the law, being a victim without being able to demonstrate proactive vigilance equals negligence. Failure to secure the most trivial digital “doors” can trigger devastating operational, remedy and human costs, which make any financial sanction seem trivial.
This case is not just a news, but a mirror.The final question is: How safe is your company’s digital infrastructure’s “front door?”
ZebraByteeditorial material on digital security, infrastructure, privacy and compliance, kept in the company's technical archive.