Back to Feed
PolicySep 8, 2026

HDPA (Greece) - 15/2026

Greece's DPA fines Ministry and company €350K for data breach affecting 2.5M individuals.

Summary

Greece's Data Protection Authority (HDPA) fined the Ministry of Social Cohesion and Family €200,000 and the Hellenic Local Development and Local Government Company €150,000 following a data breach. The incident, which affected approximately 2,500,700 individuals, occurred due to outdated information systems and inadequate security measures within the processor's systems. Personal data compromised included names, tax IDs, dates of birth, bank information, and contact details.

Full text

Help HDPA (Greece) - 15/2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 11:42, 8 September 2026 view sourceSf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators57 editsmTag: Visual edit← Older edit Latest revision as of 14:33, 8 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators57 editsmTag: Visual edit Line 103: Line 103: The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information systems operated by the processor were subject to a data breach.The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information systems operated by the processor were subject to a data breach. The data breach concerned databases used for the implementation of two initiatives, the Daycare Centers Program and the Neighborhood Nannies Program. These databases included data relating to staff, legal representatives of the organisation, the applicants, and the beneficiaries of the initiatives (which included children) affecting a total of approximately 2,500,700 data subjects. The processor also suffered disruption of the systems.The data breach concerned databases used for the implementation of two initiatives, the Daycare Centers Program and the Neighborhood Nannies Program. These databases included data relating to staff, legal representatives of the organisation, the applicants, and the beneficiaries of the initiatives (which included children) affecting a total of approximately 2,500,700 data subjects. Such personal data included names, tax ID's, date of birth, bank information and address and contact details of the individuals. The processor also suffered disruption of the systems. The controller blamed the incident on the processor and claimed that upon noticing the breach they immediately acted in compliance with the GDPR, notifying both the DPA and the processor, and took all necessary measures to restore the availability of the systems, and minimise the impact on data subjects. The controller blamed the incident on the processor and claimed that upon noticing the breach they immediately acted in compliance with the GDPR, notifying both the DPA and the processor, and took all necessary measures to restore the availability of the systems, and minimise the impact on data subjects. Latest revision as of 14:33, 8 September 2026 HDPA - 15/2026 Authority: HDPA (Greece) Jurisdiction: Greece Relevant Law: Article 5(1)(f) GDPR Article 28(3) GDPR Article 32 GDPR Type: Other Outcome: n/a Started: Decided: 28.07.2026 Published: Fine: 200,000 + 150,000 EUR Parties: Υπουργείο Κοινωνικής Συνοχής και Οικογένειας Ελληνική Εταιρεία Τοπικής Ανάπτυξης και Αυτοδιοίκησης National Case Number/Name: 15/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Greek Original Source: DPA.GR (in EL) Initial Contributor: sf The DPA fined the controller €200,000 and the processor €150,000, after a large-scale data breach affecting 2,500,700 data subjects occurred due to outdated information systems, and inadequate security measures. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information systems operated by the processor were subject to a data breach. The data breach concerned databases used for the implementation of two initiatives, the Daycare Centers Program and the Neighborhood Nannies Program. These databases included data relating to staff, legal representatives of the organisation, the applicants, and the beneficiaries of the initiatives (which included children) affecting a total of approximately 2,500,700 data subjects. Such personal data included names, tax ID's, date of birth, bank information and address and contact details of the individuals. The processor also suffered disruption of the systems. The controller blamed the incident on the processor and claimed that upon noticing the breach they immediately acted in compliance with the GDPR, notifying both the DPA and the processor, and took all necessary measures to restore the availability of the systems, and minimise the impact on data subjects. The processor admitted that it was aware of the risks that their systems pose, and the need for system improvement and update. The processor claimed that to remediate to these risks, it had previously requested the controller and other ministries to grant financial resources to modernise the information systems. The processor's financial resources in relation to the project were dependent entirely on state funding. The processor also argued that despite its awareness of the risks, it could not stop the processing in light of the public interest. Holding The processor The DPA held that the incident being the result of a known, reasonably foreseeable, and exploitable technical vulnerability, the processor violated its obligations to ensure data integrity, confidentiality and security, under Articles 5(1)(f) and 32 GDPR. The DPA rejected the argument according to which the public interest prevented the processor from stopping the processing. It underscored that public interest and a lack of resources (financial) do not override the security obligation, and neither act as exemptions to this obligation. The controller The DPA further contended that a violation of Article 32 GDPR by the processor does not exempt the controller from its obligations. The DPA therefore held, that the controller failed to ensure in advance that the measures implemented by the processor were adequate and correspondingly to choose a processor which can sufficiently guarantee the implementation of such measures. The controller therefore also violated Articles 5(1)(f) and 32 GDPR. Absence of contract Furthermore, in its investigation the DPA found that there was no active contract between the processor and the controller, covering the implementation of one of the initiatives and the associated processing operations, the DPA found both the controller and processor in violation of Article 28(3) GDPR. As a result of the findings, the DPA imposed a fine of €200,000 on the data controller and 150,000 on the data processor, and ordered them to, effective immediately, enter into the contract required by Article 28(3) GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Greek original. Please refer to the Greek original for more details. Athens, July 28, 2026 Ref. No. 3163 DECISION 15/2026 The Data Protection Authority (hereinafter the “Authority”), met, upon invitation by the Acting Chair, Deputy , Georgios Batzalexis, for a meeting via teleconference on December 11, 2025, following a postponement from the meeting scheduled for December 2, 2025, in order to examine the case referred to in the background of this document. Present were the Deputy Chairman, Georgios Batzalexis, and the regular members Spyros Vlachopoulos, Konstantinos Lambrinoudakis, Charalambos Anthopoulos, Christos Kalloniatis, and Katerina Iliadou, as well as the alternate members Demosthenes Vougioukas, as rapporteur, and Maria Psalla, replacing regular member Grigoris Tsolias, who, although duly summoned in writing, did not was unable to attend due to a conflict of interest. Present, at the request of the Vice Chair, without the right to vote, were Georgia Panagopoulou and Ioannis Lykotrafitis, experts IT specialists, serving as assistant rapporteurs,

Entities

Hellenic Local Development and Local Government Company (vendor)Daycare Centers Program (product)Neighborhood Nannies Program (product)