Commissioner (Cyprus) - Online Platform “Agora”
Cyprus DPA fines MEP €6,000 for violating GDPR cooperation obligations.
Summary
The Cyprus Data Protection Authority (DPA) has fined a Member of the European Parliament (MEP) €6,000 for failing to cooperate with an investigation into his digital platform, "Agora." The platform processed sensitive data, including political opinions and biometric information, and the MEP initially refused to suspend its operation despite requests. The DPA found the MEP violated his obligation to cooperate under Article 31 of the GDPR, even without a prior determination of substantive non-compliance.
Full text
Help Commissioner (Cyprus) - Online Platform “Agora”: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 08:23, 28 September 2026 view sourceApostolos (talk | contribs)16 editsmTag: Visual edit← Older edit Latest revision as of 08:50, 28 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators93 editsmTag: Visual edit Line 103: Line 103: In October 2025, the DPA initiated an ex officio investigation after discovering that the digital platform/application "Agora" was launched under the responsibility of an MEP, the controller. The platform offered user participation in opinion polls, expression of political opinions, and applications for parliamentary candidacy. It also required user identification through ID cards and biometric data analysis. In October 2025, the DPA initiated an ex officio investigation after discovering that the digital platform/application "Agora" was launched under the responsibility of an MEP, the controller. The platform offered user participation in opinion polls, expression of political opinions, and applications for parliamentary candidacy. It also required user identification through ID cards and biometric data analysis. Because of large-scale processing and the involvement of special categories of data (political opinions), the DPA requested that the controller submit a Data Protection Impact Assessment (DPIA) for prior consultation under Articles 35 and 36 GDPR. The DPA also repeatedly requested the controller to temporarily suspend the platform's operation until the consultation process was concluded. Because of large-scale processing and the involvement of special categories of data (political opinions), the DPA requested that the controller submit a Data Protection Impact Assessment (DPIA) for prior consultation under [[Article 35 GDPR|Articles 35]] and [[Article 36 GDPR|36 GDPR]]. The DPA also repeatedly requested the controller to temporarily suspend the platform's operation until the consultation process was concluded. Subsequently, the controller submitted an incomplete DPIA with pending mitigation measures and only partially suspended certain features (such as voting mechanisms and candidate data collection). However, on 23 February 2026, the DPA found that personal data processing was still ongoing, including user registration, identity verification, and access to candidate profiles. On the same day, the controller publicly stated in a livestream that there was "no chance" he would take down the app. Subsequently, the controller submitted an incomplete DPIA with pending mitigation measures and only partially suspended certain features (such as voting mechanisms and candidate data collection). However, on 23 February 2026, the DPA found that personal data processing was still ongoing, including user registration, identity verification, and access to candidate profiles. On the same day, the controller publicly stated in a livestream that there was "no chance" he would take down the app. Line 109: Line 109: The DPA stressed that the controller’s obligation to cooperate with the supervisory authority is autonomous. An infringement does not require a prior determination of substantive non-compliance (e.g., regarding legal basis or security measures) or proof of actual harm to data subjects.The DPA stressed that the controller’s obligation to cooperate with the supervisory authority is autonomous. An infringement does not require a prior determination of substantive non-compliance (e.g., regarding legal basis or security measures) or proof of actual harm to data subjects. Following, the DPA held that the controller violated his obligation to cooperate with the supervisory authority under [[Article 31 GDPR]] and imposed an administrative fine of €6,000 under Article 58(2)(i) and [[Article 83 GDPR|Article 83(4)(a) GDPR]]. Following, the DPA held that the controller violated his obligation to cooperate with the supervisory authority under [[Article 31 GDPR]] and imposed an administrative fine of €6,000 under [[Article 58 GDPR|Article 58(2)(i)]] and [[Article 83 GDPR|Article 83(4)(a) GDPR]]. == Comment ==== Comment == ''Share your comments here!''''Share your comments here!'' Latest revision as of 08:50, 28 September 2026 Commissioner - Online Platform “Agora” Authority: Commissioner (Cyprus) Jurisdiction: Cyprus Relevant Law: Article 31 GDPR Article 35 GDPR Article 36 GDPR Article 58(2)(i) GDPR Article 83(4)(a) GDPR Type: Investigation Outcome: Violation Found Started: 29.10.2025 Decided: 17.09.2026 Published: 22.09.2026 Fine: 6,000 EUR Parties: n/a National Case Number/Name: Online Platform “Agora” European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Greek Original Source: Commissioner (Cyprus) (in EL) Initial Contributor: Apostolos Karasakalidis The DPA fined an MEP €6,000 for failing to cooperate with the supervisory authority under Article 31 GDPR, particularly, after he refused to fully comply with repeated requests to temporarily suspend the operations of his online platform "Agora". Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts In October 2025, the DPA initiated an ex officio investigation after discovering that the digital platform/application "Agora" was launched under the responsibility of an MEP, the controller. The platform offered user participation in opinion polls, expression of political opinions, and applications for parliamentary candidacy. It also required user identification through ID cards and biometric data analysis. Because of large-scale processing and the involvement of special categories of data (political opinions), the DPA requested that the controller submit a Data Protection Impact Assessment (DPIA) for prior consultation under Articles 35 and 36 GDPR. The DPA also repeatedly requested the controller to temporarily suspend the platform's operation until the consultation process was concluded. Subsequently, the controller submitted an incomplete DPIA with pending mitigation measures and only partially suspended certain features (such as voting mechanisms and candidate data collection). However, on 23 February 2026, the DPA found that personal data processing was still ongoing, including user registration, identity verification, and access to candidate profiles. On the same day, the controller publicly stated in a livestream that there was "no chance" he would take down the app. Holding The DPA stressed that the controller’s obligation to cooperate with the supervisory authority is autonomous. An infringement does not require a prior determination of substantive non-compliance (e.g., regarding legal basis or security measures) or proof of actual harm to data subjects. Following, the DPA held that the controller violated his obligation to cooperate with the supervisory authority under Article 31 GDPR and imposed an administrative fine of €6,000 under Article 58(2)(i) and Article 83(4)(a) GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Greek original. Please refer to the Greek original for more details. Republic of Cyprus OFFICE OF THE COMMISSIONER FOR THE PROTECTION OF PERSONAL DATA DECISION App AND/OR THE “Agora” ONLINE PLATFORM Retrieved from "https://gdprhub.eu/index.php?title=Commissioner_(Cyprus)_-_Online_Platform_“Agora”&oldid=53195" Categories: Commissioner (Cyprus)CyprusArticle 31 GDPRArticle 35 GDPRArticle 36 GDPRArticle 58(2)(i) GDPRArticle 83(4)(a) GDPR2026Greek This page was last edited on 28 September 2026, at 08:50. Content is available under Creative Commons Attribution-NonCommercial-ShareAlike unless otherwise noted. Privacy policy About GDPRhub Disclaimers