Back to Feed
PolicyJul 29, 2026

HDPA (Greece) - 7/2026

Greece's DPA fines energy supplier and call centers €880,000 for GDPR violations.

Summary

Greece's Data Protection Authority (DPA) imposed a total fine of €880,000 on an energy supplier and four call-center companies for multiple GDPR and data privacy violations. The penalties stem from inadequate technical and organizational measures, mixed-purpose calls, insufficient oversight of processors, and unauthorized use of subcontractors. The DPA also cited issues with the Air Miles program's policy regarding data accuracy, retention periods, and the right to erasure.

Full text

Help HDPA (Greece) - 7/2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 11:59, 28 July 2026 view sourceDs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators240 edits Tag: Decisions [1.0] Latest revision as of 08:10, 29 July 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators240 editsm Tag: Visual edit Line 128: Line 128: }}}} The DPA fined an energy supplier and four call-centre companies €880,000 in total for inadequate technical and organisational measures, mixed-purpose calls, insufficient processor oversight and unauthorised use of a subcontractor.The DPA fined an energy supplier and four call-centre operators €880,000 in total for inadequate technical and organisational measures, mixed-purpose calls, insufficient processor oversight and unauthorised use of a subcontractor. == English Summary ==== English Summary == Line 142: Line 142: The DPA requested explanations from the controller and the processors. In their submissions, they argued, among other things, that the calls were linked to existing customer relationships and were intended to provide contractual or regulatory information, assess customer satisfaction or improve service quality rather than promote products. They also maintained that the calls made to numbers included in the do-not-call register resulted from isolated technical failures and referred to their contracts, opt-out procedures, staff training and quality-control measures. The DPA requested explanations from the controller and the processors. In their submissions, they argued, among other things, that the calls were linked to existing customer relationships and were intended to provide contractual or regulatory information, assess customer satisfaction or improve service quality rather than promote products. They also maintained that the calls made to numbers included in the do-not-call register resulted from isolated technical failures and referred to their contracts, opt-out procedures, staff training and quality-control measures. === Holding ====== Holding === Regarding the controller, the DPA held that it was responsible for determining the purposes of the processing and the essential means by which the telephone calls were carried out. It was therefore required to provide its processors with appropriate tools and instructions, ensure the effective consolidation of the applicable opt-out registers and adequately supervise the processors’ compliance. Regarding the controller, the DPA held that it was responsible for determining the purposes of the processing and the essential means by which the telephone calls were carried out. It was therefore required to provide its processors with appropriate tools and instructions, ensure the effective consolidation of the applicable opt-out registers and adequately supervise the processors’ compliance. Line 155: Line 153: The DPA also examined the provided information relating to the Air Miles programme. It found that the policy did not clearly distinguish the relevant purposes and legal bases, used broad descriptions of the processing activities, did not explain how data accuracy would be maintained, failed to specify concrete retention periods and provided insufficiently clear information regarding the right to erasure. The DPA also examined the provided information relating to the Air Miles programme. It found that the policy did not clearly distinguish the relevant purposes and legal bases, used broad descriptions of the processing activities, did not explain how data accuracy would be maintained, failed to specify concrete retention periods and provided insufficiently clear information regarding the right to erasure. The DPA fined the controller €190,000 for the infringement of [[Article 32 GDPR|Article 32 GDPR]], €230,000 for the infringement of Article 11 of Law 3471/2006 and €130,000 for the infringement of [[Article 5 GDPR|Article 5 GDPR]]. It also ordered the controller, within six months, to amend its agreements with the processors by introducing explicit technical instructions, improve its technical and organisational procedures and establish a procedure for auditing the cooperating call centres. The DPA fined the controller €190,000 for the infringement of [[Article 32 GDPR]], €230,000 for the infringement of Article 11 of Law 3471/2006 and €130,000 for the infringement of [[Article 5 GDPR]]. It also ordered the controller, within six months, to amend its agreements with the processors by introducing explicit technical instructions, improve its technical and organisational procedures and establish a procedure for auditing the cooperating call centres. Regarding processor A, the DPA found that it relied on manual procedures to remove telephone numbers from calling lists. This increased the risk of human error and did not provide reliable evidence of who had recorded an objection or when the relevant change had been made. It held that processor A therefore infringed [[Article 32 GDPR|Article 32 GDPR]] and fined it €20,000. Regarding processor A, the DPA found that it relied on manual procedures to remove telephone numbers from calling lists. This increased the risk of human error and did not provide reliable evidence of who had recorded an objection or when the relevant change had been made. It held that processor A therefore infringed [[Article 32 GDPR]] and fined it €20,000. In addition, the DPA determined that processor A was also involved in a call presented as a customer-satisfaction survey during which a programme offered by the controller was mentioned. The DPA considered that the call included a direct commercial offer and therefore fell within Article 11 of Law 3471/2006, since it was directed to a subscriber who had opted out of marketing calls and imposed a €40,000 fine. In addition, the DPA determined that processor A was also involved in a call presented as a customer-satisfaction survey during which a programme offered by the controller was mentioned. The DPA considered that the call included a direct commercial offer and therefore fell within Article 11 of Law 3471/2006, since it was directed to a subscriber who had opted out of marketing calls and imposed a €40,000 fine. As regards processor B, the DPA found that its systems had produced mismatches between the controller’s customer lists and the applicable opt-out registers, resulting in calls being made to numbers that should have been excluded. The DPA considered that this demonstrated insufficient automation and a possible absence of complete records documenting the checks performed before each call. It concluded that processor B violated [[Article 32 GDPR|Article 32 GDPR]] and imposed a €50,000 fine. It also fined €40,000 processor B for violating [[Article 5 GDPR|Article 5 GDPR]] due to the shortcomings identified in the processing relating to the Air Miles programme.As regards processor B, the DPA found that its systems had produced mismatches between the controller’s customer lists and the applicable opt-out registers, resulting in calls being made to numbers that should have been excluded. The DPA considered that this demonstrated insufficient automation and a possible absence of complete records documenting the checks performed before each call. It concluded that processor B violated [[Article 32 GDPR]] and imposed a €50,000 fine. It also fined €40,000 processor B for violating [[Article 5 GDPR]] due to the shortcomings identified in the processing relating to the Air Miles programme. Regarding processor C, the DPA pointed out that the method it used for the updates of its opt-out lists, created a gap between the submission of an objection and its addition to the updated list, during which the person could still receive a call. It therefore found the procedure insufficient under [[Article 32 GDPR|Article 32 GDPR]] and fined €45,000 process

Entities

HDPA (vendor)