HDPA (Greece) - 14/2026
Greek DPA finds Hellenic Open University compliant after ransomware attack impacting 30,000 individuals.
Summary
The Hellenic Open University (HOU) experienced a ransomware attack that led to a data breach affecting 30,000 individuals and the leak of 813 GB of personal data. Despite the incident, the Greek Data Protection Authority (DPA) found HOU compliant with GDPR notification obligations. However, the DPA ordered HOU to implement targeted training for system administrators and improve authentication measures, citing human error as the cause of the breach.
Full text
Help HDPA (Greece) - 14/2026: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 08:24, 18 August 2026 view sourceSf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators11 edits Tag: Decisions [1.0] Revision as of 07:04, 19 August 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators11 editsmTag: Visual editNewer edit → Line 25: Line 25: |Outcome=|Outcome= |Date_Started=|Date_Started= |Date_Decided=|Date_Decided=15 July 2026 |Date_Published=|Date_Published= |Year=|Year= Line 97: Line 97: === Facts ====== Facts === The Hellenic Open University (‘the controller’) submitted initial and supplementary notifications to the DPA after it was subject to a data breach resulting from a ransomware attack. The breach affected the personal data of 30,000 individuals in the controller’s information system and involved a leak of 813 GB of personal data that was later posted on the dark web but with restricted access as to its content.The Hellenic Open University (‘the controller’) submitted initial and supplementary notifications to the DPA after it was subject to a data breach resulting from a ransomware attack. The breach affected the personal data of 30,000 individuals in the controller’s information system and involved a leak of 813 GB of personal data that was later posted on the dark web but with restricted access as to its content. After respective requests and instructions by the DPA, the controller communicated the data breach to the affected individuals in accordance with [[Article 34 GDPR|Article 34 GDPR]] since the DPA considered a public notice insufficient. The controller also provided the DPA with further information, amongst others, regarding the nature of the breach and personal data affected. The HOU took measures to prevent successful installation of malware in the future and to prevent future incidents and take measures to mitigate damage to affected parties, in accordance with [[Article 33 GDPR|Article 33 GDPR]]. After respective requests and instructions by the DPA, the controller communicated the data breach to the affected individuals in accordance with [[Article 34 GDPR]] since the DPA considered a public notice insufficient. The controller also provided the DPA with further information, amongst others, regarding the nature of the breach and personal data affected. The HOU took measures to prevent successful installation of malware in the future and to prevent future incidents and take measures to mitigate damage to affected parties, in accordance with [[Article 33 GDPR]]. === Holding ====== Holding === The DPA held that the controller complied with its notification obligations under Article 33 and [[Article 34 GDPR|Article 34 GDPR]], despite the initial notification being supplemented at a later time.The DPA held that the controller complied with its notification obligations under Article 33 and [[Article 34 GDPR]], despite the initial notification being supplemented at a later time. Regarding the controller’s compliance with [[Article 32 GDPR|Article 32 GDPR]] (i.e. the obligation to implement adequate security measures), the DPA held that the cause of the incident was a human error, which could have been prevented through targeted training and improved authentication measures with individuals which have access to the system administration. Regarding the controller’s compliance with [[Article 32 GDPR]] (i.e. the obligation to implement adequate security measures), the DPA held that the cause of the incident was a human error, which could have been prevented through targeted training and improved authentication measures with individuals which have access to the system administration. In accordance with [[Article 58 GDPR|Article 58(2)(d) GDPR]], the DPA ordered the controller to implement targeted training plans for system administrators and to fully implement the security measures mentioned above, within 6 months of this decision and to inform the DPA of such.In accordance with [[Article 58 GDPR|Article 58(2)(d) GDPR]], the DPA ordered the controller to implement targeted training plans for system administrators and to fully implement the security measures mentioned above, within 6 months of this decision and to inform the DPA of such. Revision as of 07:04, 19 August 2026 HDPA - 14/2026 Authority: HDPA (Greece) Jurisdiction: Greece Relevant Law: Article 32 GDPR Article 33 GDPR Article 34 GDPR Article 58(2)(d) GDPR Type: Complaint Outcome: n/a Started: Decided: 15 July 2026 Published: Fine: n/a Parties: n/a National Case Number/Name: 14/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Greek Original Source: ΑΡΧΗ ΠΡΟΣΤΑΣΙΑΣ ΔΕΔΟΜΕΝΩΝ (in EL) Initial Contributor: sf The DPA ordered a university to implement improved authentication measures as well as targeted training plans for system administrators after the university was subject to a ransomware attack affecting the personal data of 30,000 individuals. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The Hellenic Open University (‘the controller’) submitted initial and supplementary notifications to the DPA after it was subject to a data breach resulting from a ransomware attack. The breach affected the personal data of 30,000 individuals in the controller’s information system and involved a leak of 813 GB of personal data that was later posted on the dark web but with restricted access as to its content. After respective requests and instructions by the DPA, the controller communicated the data breach to the affected individuals in accordance with Article 34 GDPR since the DPA considered a public notice insufficient. The controller also provided the DPA with further information, amongst others, regarding the nature of the breach and personal data affected. The HOU took measures to prevent successful installation of malware in the future and to prevent future incidents and take measures to mitigate damage to affected parties, in accordance with Article 33 GDPR. Holding The DPA held that the controller complied with its notification obligations under Article 33 and Article 34 GDPR, despite the initial notification being supplemented at a later time. Regarding the controller’s compliance with Article 32 GDPR (i.e. the obligation to implement adequate security measures), the DPA held that the cause of the incident was a human error, which could have been prevented through targeted training and improved authentication measures with individuals which have access to the system administration. In accordance with Article 58(2)(d) GDPR, the DPA ordered the controller to implement targeted training plans for system administrators and to fully implement the security measures mentioned above, within 6 months of this decision and to inform the DPA of such. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Greek original. Please refer to the Greek original for more details. Athens, July 15, 2026 Ref. No.: 3164 DECISION 14/2026 The Data Protection Authority (hereinafter the “Authority”), met, following an invitation from the acting Chair, Deputy , Georgios Batzalexis, for a meeting via teleconference on November 4, 2025, in order to examine the case referred to in the background section of this decision. Present at the meeting were the Authority’s Deputy Chair, Georgios Batzalexis, and the regular members Spyridon Vlachopoulos, Konstantinos Lambrinoudakis, Charalambos Anthopoulos, Christos Kalloniatis, and Katerina Iliadou, as well as the alternate members Demosthenes Vougioukas, serving as rapporteur, and Maria Psalla, replacing regular member Grigoris Tsolias, who, although duly summoned in writin
Indicators of Compromise
- malware — ransomware