[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fWX472ztkfGRA4K7uM5i8PNYX-OlfvtbwILxRnTcWj6Q":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"ec32773c-5ad7-4336-8841-b2ce03cce563","HDPA (Greece) - 15\u002F2026","hdpa-greece-15-2026-50547a","← Older revision Revision as of 09:37, 8 September 2026 Line 96: Line 96: }} }} The DPA fined the controller €200,000 and the processor €150,000, after a large-scale data breach affecting 2,500,700 data subjects occurred, due to outdated information systems, and inadequate security measures. The DPA fined the controller €200,000 and the processor €150,000, after a large-scale data breach affecting 2,500,700 data subjects occurred due to outdated information systems, and inadequate security measures. == English Summary == == English Summary == === Facts === === Facts === The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) both notified the DPA after being subject to a data breach of the information systems operated by the processor. The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) both notified the DPA after the information systems operated by the processor were subject to a data breach. During the data breach, the databases supporting the implementation of two initiatives were encrypted and possibly downloaded\u002Fstolen. This included the data of staff, the legal representative of the organisation, the applicants, and the beneficiaries (which included children) affecting approximately 2,500,700 data subjects. The breach also allowed for unauthorised persons to gain access to the data held by the processor, and disruption of the systems. During the breach, the databases supporting the implementation of two initiatives were encrypted and possibly downloaded\u002Fstolen. This included the data of staff, the legal representatives of the organisation, the applicants, and the beneficiaries (which included children) affecting a total of approximately 2,500,700 data subjects. The breach also allowed for unauthorised persons to gain access to the data held by the processor, and disruption of the systems. The controller claimed that it acted in compliance with the GDPR, notifying both the DPA and the processor immediately upon noticing the breach. The controller emphasised it took all necessary measures to address the incident, restore the availability of the systems, and minimise the impact on data subjects. The controller underscored that it merely acted as the program beneficiary, and the affected systems belonged to the processor who was in charge of actually implementing the program, blaming the incident on the processor. The controller further claimed that upon noticing the breach they immediatly acted in compliance with the GDPR, notifying both the DPA and the processor, and took all necessary measures to restore the availability of the systems, and minimise the impact on data subjects. The processor was made aware of the risks that its systems pose, and the need for their information system technologies to be improved and updated. Within which they claimed that they contacted the controller and other ministries to secure the necessary resources to allow the processor to address the vulnerabilities of its system. The processor emphasised it didn’t have the necessary financial resources to modernise the information systems, which was dependent entirely on state funding. The processor maintained that they could not stop the processing in light of the public interest, and made apparent that they were made aware of the risks that their systems pose, and the need for their information system technologies to be improved and updated. The processor claimed that they contacted the controller and other ministries to secure the necessary resources to allow the processor to address the vulnerabilities of its system. The processor emphasised it didn’t have the necessary financial resources to modernise the information systems, which was dependent entirely on state funding. === Holding === === Holding === The DPA held in light of the incident being the result of a known, reasonably foreseeable, and exploitable technical vulnerability, the processor violated [[Article 5 GDPR|Article 5(1)(f) GDPR]] and [[Article 32 GDPR]] ensuring the security of its systems. The DPA emphasised that public interest and a lack of resources do not override the security obligation, and neither act as exemptions to this obligation. The DPA held in light of the incident being the result of a known, reasonably foreseeable, and exploitable technical vulnerability, the processor violated [[Article 5 GDPR|Article 5(1)(f) GDPR]] and [[Article 32 GDPR]] ensuring the security, confidentiality and integrity of its systems. The DPA underscored that public interest and a lack of resources (financial) do not override the security obligation, and neither act as exemptions to this obligation. The DPA further contended that a violation of [[Article 32 GDPR]] by the processor does not exempt the controller from its obligations. The DPA therefore held, that the controller failed to ensure that the measures were adequate and to select a processor which provides adequate safeguards, correspondingly acting in violation of [[Article 5 GDPR|Article 5(1)(f) GDPR]] and [[Article 32 GDPR]]. The DPA further contended that a violation of [[Article 32 GDPR]] by the processor does not exempt the controller from its obligations. The DPA therefore held, that the controller failed to ensure in advance that the measures implemented by the processor were adequate and correspondingly to choose a processor which can sufficiently guarantee the implementation of such measures, thus acting in violation of [[Article 5 GDPR|Article 5(1)(f) GDPR]] and [[Article 32 GDPR]]. Furthermore, in its investigation the DPA found that there was no active contract between the processor and the controller, covering the initiatives and thus the processing operations, the DPA found both the controller and processor in violation of [[Article 28 GDPR|Article 28(3) GDPR]]. Furthermore, in its investigation the DPA found that there was no active contract between the processor and the controller, covering the implementation of the initiatives and the associated processing operations, the DPA found both the controller and processor in violation of [[Article 28 GDPR|Article 28(3) GDPR]]. As a result of the findings, the DPA imposed a fine of €200,000 on the data controller and 150,000 on the data processor, and ordered them to, effective immediately, enter into the contract required by [[Article 28 GDPR|Article 28(3) GDPR]]. As a result of the findings, the DPA imposed a fine of €200,000 on the data controller and 150,000 on the data processor, and ordered them to, effective immediately, enter into the contract required by [[Article 28 GDPR|Article 28(3) GDPR]].","Greece's Data Protection Authority (DPA) has fined the Ministry of Social Cohesion and Family €200,000 and its processor, Hellenic Local Development and Local Government Company, €150,000 following a data breach. The breach affected over 2.5 million individuals due to outdated information systems and inadequate security measures. Both entities were found in violation of GDPR articles related to data security and processor contracts.","Greece's DPA fines controller €200K and processor €150K for data breach.","Help HDPA (Greece) - 15\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editNewer edit →VisualWikitext Revision as of 12:59, 3 September 2026 view sourceSf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators53 editsmTag: Visual edit← Older edit Revision as of 09:37, 8 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators53 editsmTag: Visual editNewer edit → Line 96: Line 96: }}}} The DPA fined the controller €200,000 and the processor €150,000, after a large-scale data breach affecting 2,500,700 data subjects occurred, due to outdated information systems, and inadequate security measures. The DPA fined the controller €200,000 and the processor €150,000, after a large-scale data breach affecting 2,500,700 data subjects occurred due to outdated information systems, and inadequate security measures. == English Summary ==== English Summary == === Facts ====== Facts === The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) both notified the DPA after being subject to a data breach of the information systems operated by the processor.The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) both notified the DPA after the information systems operated by the processor were subject to a data breach. During the data breach, the databases supporting the implementation of two initiatives were encrypted and possibly downloaded\u002Fstolen. This included the data of staff, the legal representative of the organisation, the applicants, and the beneficiaries (which included children) affecting approximately 2,500,700 data subjects. The breach also allowed for unauthorised persons to gain access to the data held by the processor, and disruption of the systems.During the breach, the databases supporting the implementation of two initiatives were encrypted and possibly downloaded\u002Fstolen. This included the data of staff, the legal representatives of the organisation, the applicants, and the beneficiaries (which included children) affecting a total of approximately 2,500,700 data subjects. The breach also allowed for unauthorised persons to gain access to the data held by the processor, and disruption of the systems. The controller claimed that it acted in compliance with the GDPR, notifying both the DPA and the processor immediately upon noticing the breach. The controller emphasised it took all necessary measures to address the incident, restore the availability of the systems, and minimise the impact on data subjects.The controller underscored that it merely acted as the program beneficiary, and the affected systems belonged to the processor who was in charge of actually implementing the program, blaming the incident on the processor. The controller further claimed that upon noticing the breach they immediatly acted in compliance with the GDPR, notifying both the DPA and the processor, and took all necessary measures to restore the availability of the systems, and minimise the impact on data subjects. The processor was made aware of the risks that its systems pose, and the need for their information system technologies to be improved and updated. Within which they claimed that they contacted the controller and other ministries to secure the necessary resources to allow the processor to address the vulnerabilities of its system. The processor emphasised it didn’t have the necessary financial resources to modernise the information systems, which was dependent entirely on state funding.The processor maintained that they could not stop the processing in light of the public interest, and made apparent that they were made aware of the risks that their systems pose, and the need for their information system technologies to be improved and updated. The processor claimed that they contacted the controller and other ministries to secure the necessary resources to allow the processor to address the vulnerabilities of its system. The processor emphasised it didn’t have the necessary financial resources to modernise the information systems, which was dependent entirely on state funding. === Holding ====== Holding === The DPA held in light of the incident being the result of a known, reasonably foreseeable, and exploitable technical vulnerability, the processor violated [[Article 5 GDPR|Article 5(1)(f) GDPR]] and [[Article 32 GDPR]] ensuring the security of its systems. The DPA emphasised that public interest and a lack of resources do not override the security obligation, and neither act as exemptions to this obligation.The DPA held in light of the incident being the result of a known, reasonably foreseeable, and exploitable technical vulnerability, the processor violated [[Article 5 GDPR|Article 5(1)(f) GDPR]] and [[Article 32 GDPR]] ensuring the security, confidentiality and integrity of its systems. The DPA underscored that public interest and a lack of resources (financial) do not override the security obligation, and neither act as exemptions to this obligation. The DPA further contended that a violation of [[Article 32 GDPR]] by the processor does not exempt the controller from its obligations. The DPA therefore held, that the controller failed to ensure that the measures were adequate and to select a processor which provides adequate safeguards, correspondingly acting in violation of [[Article 5 GDPR|Article 5(1)(f) GDPR]] and [[Article 32 GDPR]].The DPA further contended that a violation of [[Article 32 GDPR]] by the processor does not exempt the controller from its obligations. The DPA therefore held, that the controller failed to ensure in advance that the measures implemented by the processor were adequate and correspondingly to choose a processor which can sufficiently guarantee the implementation of such measures, thus acting in violation of [[Article 5 GDPR|Article 5(1)(f) GDPR]] and [[Article 32 GDPR]]. Furthermore, in its investigation the DPA found that there was no active contract between the processor and the controller, covering the initiatives and thus the processing operations, the DPA found both the controller and processor in violation of [[Article 28 GDPR|Article 28(3) GDPR]].Furthermore, in its investigation the DPA found that there was no active contract between the processor and the controller, covering the implementation of the initiatives and the associated processing operations, the DPA found both the controller and processor in violation of [[Article 28 GDPR|Article 28(3) GDPR]]. As a result of the findings, the DPA imposed a fine of €200,000 on the data controller and 150,000 on the data processor, and ordered them to, effective immediately, enter into the contract required by [[Article 28 GDPR|Article 28(3) GDPR]].As a result of the findings, the DPA imposed a fine of €200,000 on the data controller and 150,000 on the data processor, and ordered them to, effective immediately, enter into the contract required by [[Article 28 GDPR|Article 28(3) GDPR]]. Revision as of 09:37, 8 September 2026 HDPA - 15\u002F2026 Authority: HDPA (Greece) Jurisdiction: Greece Relevant Law: Article 5(1)(f) GDPR Article 28(3) GDPR Article 32 GDPR Type: Other Outcome: n\u002Fa Started: Decided: 28.07.2026 Published: Fine: 200,000 + 150,000 EUR Parties: Υπουργείο Κοινωνικής Συνοχής και Οικογένειας Ελληνική Εταιρεία Τοπικής Ανάπτυξης και Αυτοδιοίκησης National Case Number\u002FName: 15\u002F2026 European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Greek Original Source: DPA.GR (in EL) Initial Contributor: sf The DPA fined the controller €200,000 and the processor €150,000, after a large-scale data breach affecting 2,500,700 data subjects occurred due to outdated information systems, and inadequate security measures. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Commen","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=HDPA_(Greece)_-_15\u002F2026&diff=52942&oldid=52913","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F4\u002F49\u002FLogoGR.jpg","2026-09-08T09:37:48+00:00","2026-09-08T10:00:13.925103+00:00",7,[18,21],{"name":19,"type":20},"Hellenic Local Development and Local Government Company","vendor",{"name":22,"type":23},"Ministry of Social Cohesion and Family","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":24,"icon":26,"name":27,"slug":28},null,"Policy","policy",[30,35,40,42],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":41},{"id":24,"icon":26,"name":27,"slug":28},{"category":43},{"id":44,"icon":26,"name":45,"slug":46},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]