[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fSivjR9G9HZvPc7c8C_NH878ZnLAxoXYgWsNtFV7fN6I":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"64effcc2-488c-4e82-b398-58ae475d6be1","HDPA (Greece) - 14\u002F2026","hdpa-greece-14-2026-bf1bec","Created page with \"{{DPAdecisionBOX |Jurisdiction=Greece |DPA-BG-Color= |DPAlogo=LogoGR.jpg |DPA_Abbrevation=HDPA |DPA_With_Country=HDPA (Greece) |Case_Number_Name=14\u002F2026 |ECLI= |Original_Source_Name_1=ΑΡΧΗ ΠΡΟΣΤΑΣΙΑΣ ΔΕΔΟΜΕΝΩΝ |Original_Source_Link_1=https:\u002F\u002Fwww.dpa.gr\u002Fsites\u002Fdefault\u002Ffiles\u002F2026-08\u002F14_2026%20anonym.pdf |Original_Source_Language_1=Greek |Original_Source_Language__Code_1=EL |Original_Source_Name_2= |Original_Source_Link_2= |Original_Source_Langua...\" Show changes","The Hellenic Open University (HOU) experienced a ransomware attack that led to a data breach affecting 30,000 individuals, with 813 GB of personal data leaked and posted on the dark web. The Greek Data Protection Authority (HDPA) ordered HOU to implement improved authentication measures and targeted training for system administrators, citing human error as the cause. The university was also required to notify affected individuals and take steps to mitigate damages.","Greek DPA orders university to improve security after ransomware attack impacting 30,000 individuals.","Help HDPA (Greece) - 14\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 08:24, 18 August 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators3 edits Tag: Decisions [1.0] (No difference) Latest revision as of 08:24, 18 August 2026 HDPA - 14\u002F2026 Authority: HDPA (Greece) Jurisdiction: Greece Relevant Law: Article 32 GDPR Article 33 GDPR Article 34 GDPR Article 58(2)(d) GDPR Type: Complaint Outcome: n\u002Fa Started: Decided: Published: Fine: n\u002Fa Parties: n\u002Fa National Case Number\u002FName: 14\u002F2026 European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Greek Original Source: ΑΡΧΗ ΠΡΟΣΤΑΣΙΑΣ ΔΕΔΟΜΕΝΩΝ (in EL) Initial Contributor: sf The DPA ordered a university to implement improved authentication measures as well as targeted training plans for system administrators after the university was subject to a ransomware attack affecting the personal data of 30,000 individuals. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The Hellenic Open University (‘the controller’) submitted initial and supplementary notifications to the DPA after it was subject to a data breach resulting from a ransomware attack. The breach affected the personal data of 30,000 individuals in the controller’s information system and involved a leak of 813 GB of personal data that was later posted on the dark web but with restricted access as to its content. After respective requests and instructions by the DPA, the controller communicated the data breach to the affected individuals in accordance with Article 34 GDPR since the DPA considered a public notice insufficient. The controller also provided the DPA with further information, amongst others, regarding the nature of the breach and personal data affected. The HOU took measures to prevent successful installation of malware in the future and to prevent future incidents and take measures to mitigate damage to affected parties, in accordance with Article 33 GDPR. Holding The DPA held that the controller complied with its notification obligations under Article 33 and Article 34 GDPR, despite the initial notification being supplemented at a later time. Regarding the controller’s compliance with Article 32 GDPR (i.e. the obligation to implement adequate security measures), the DPA held that the cause of the incident was a human error, which could have been prevented through targeted training and improved authentication measures with individuals which have access to the system administration. In accordance with Article 58(2)(d) GDPR, the DPA ordered the controller to implement targeted training plans for system administrators and to fully implement the security measures mentioned above, within 6 months of this decision and to inform the DPA of such. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Greek original. Please refer to the Greek original for more details. Athens, July 15, 2026 Ref. No.: 3164 DECISION 14\u002F2026 The Data Protection Authority (hereinafter the “Authority”), met, following an invitation from the acting Chair, Deputy , Georgios Batzalexis, for a meeting via teleconference on November 4, 2025, in order to examine the case referred to in the background section of this decision. Present at the meeting were the Authority’s Deputy Chair, Georgios Batzalexis, and the regular members Spyridon Vlachopoulos, Konstantinos Lambrinoudakis, Charalambos Anthopoulos, Christos Kalloniatis, and Katerina Iliadou, as well as the alternate members Demosthenes Vougioukas, serving as rapporteur, and Maria Psalla, replacing regular member Grigoris Tsolias, who, although duly summoned in writing, was unable to attend due to a conflict of interest. Also present, by order of the Vice President, without the right to vote, were Georgia Panagopoulou and Ioannis Lykotrafitis, IT specialists, serving as assistant rapporteurs, and Irini Papageorgopoulou, an employee of the Authority’s Administrative Affairs Department , as secretary. The Authority took the following into account: The Hellenic Open University (hereinafter “HOU”) submitted to the Authority, pursuant to Regulation (EU) 2016\u002F679 (General Data Protection Regulation—hereinafter GDPR), the initial notification of a personal data breach, ref. no. Γ\u002FΕΙΣ\u002F8375\u002F31-10-2024, regarding a personal data breach, which was subsequently supplemented by the supplementary notification bearing ref. no. Γ\u002FΕΙΣ\u002F8569\u002F07-11-2024. 1 According to the notification, the incident consists of a breach of the confidentiality and availability of the Hellenic Open University’s personal data, as a result of a malicious external ransomware attack on its information systems. The breach affects approximately 30,000 data subjects, including students, graduates, faculty, administrative staff, and HOU suppliers, whom the HOU states have been notified due to the grave nature of the potential consequences of the incident. Specifically, it is noted that this was done, on the one hand, through an announcement on the main website (www.eap.gr) for the academic community and stakeholders (students, alumni, faculty, administrative staff, suppliers), and, on the other hand, through announcements and email messages for faculty and administrative staff. Copies of the relevant updates\u002Fannouncements are attached to this supplementary notification. Finally, the Hellenic Open University notes that, since this is a ransomware attack by the RansomHub cyber-extortion group, it is necessary to conduct a thorough investigation to fully determine the nature of the breach and the instance in which personal data has been compromised. After reviewing the initial and supplementary notifications, the Authority sent document no. Γ\u002FΕΞΕ\u002F3339\u002F26-11-2024 to the Hellenic Open University, requesting that it to submit, within a reasonable period of time, a new supplementary or complete\u002Ffinal notification clarifying points such as: the nature of the breach and the instance in which personal data has been compromised, the security measures taken before and after the incident, as well as the results of its investigation, along with the relevant evidence. Furthermore, the Authority, in the same document, requested the EAP to specify whether any further specific information provided to the affected individuals regarding the actions they should take to protect themselves. Since the EAP had not submitted any new supplementary or complete\u002Ffinal notification or any other written update, the Authority, in its ref. no. Γ\u002FΕΞΕ\u002F536\u002F07-02-2025, again requested EAP to provide the aforementioned requested information or other relevant written information regarding the reasons for the delay in responding to its letter. Subsequently, the EAP submitted a second supplementary notification of a personal data breach, bearing ref. no. Γ\u002FΕΙΣ\u002F1364\u002F14-02-2025 second supplementary notification of a personal data breach, informing the Authority, among other things, that the investigation into the incident is ongoing and that a file 813 GB in size has reportedly been leaked and posted on a dark web platform, although full access to its contents has not yet been possible. For this reason, the EAP notes that it has not yet issued a specific notification to the data subjects, as it first wishes to identify the data subjects whose personal data is contained in this file. The Authority then, in document no. Γ\u002FΕΞΕ\u002F766\u002F06-03-2025, instructed the EAP to immediately notify all potential data subjects of the personal data breach, in accordance with Article 34(4) of the GDPR. In this document, the Authority notes, among other things, that even if the EAP is unable to determine with accuracy which data subjects have been affected by the breach, due to ","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=HDPA_(Greece)_-_14\u002F2026&diff=52706&oldid=0","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F4\u002F49\u002FLogoGR.jpg","2026-08-18T08:24:07+00:00","2026-08-18T10:00:16.310753+00:00",7,[18,21],{"name":19,"type":20},"HDPA","vendor",{"name":22,"type":23},"Hellenic Open University","product","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":24,"icon":26,"name":27,"slug":28},null,"Breaches","breaches",[30,32,37,42],{"category":31},{"id":24,"icon":26,"name":27,"slug":28},{"category":33},{"id":34,"icon":26,"name":35,"slug":36},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":38},{"id":39,"icon":26,"name":40,"slug":41},"7d8b5ab8-ea0b-4ced-ae97-ec251b86993a","Ransomware","ransomware",{"category":43},{"id":44,"icon":26,"name":45,"slug":46},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",[48],{"type":49,"value":41,"context":50},"malware","Type of attack that caused the data breach."]