[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7hE8MhLy0C9VcRvOdJ5tlge6hwT5jngu7g_-UJeZ33w":3},{"article":4,"iocs":42},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"48aecedc-ad79-4313-a249-462d62d8d3a7","HDPA (Greece) - 7\u002F2026","hdpa-greece-7-2026-0e4098","Small amendments to short summary ← Older revision Revision as of 08:10, 29 July 2026 Line 128: Line 128: }} }} The DPA fined an energy supplier and four call-centre companies €880,000 in total for inadequate technical and organisational measures, mixed-purpose calls, insufficient processor oversight and unauthorised use of a subcontractor. The DPA fined an energy supplier and four call-centre operators €880,000 in total for inadequate technical and organisational measures, mixed-purpose calls, insufficient processor oversight and unauthorised use of a subcontractor. == English Summary == == English Summary == Line 142: Line 142: The DPA requested explanations from the controller and the processors. In their submissions, they argued, among other things, that the calls were linked to existing customer relationships and were intended to provide contractual or regulatory information, assess customer satisfaction or improve service quality rather than promote products. They also maintained that the calls made to numbers included in the do-not-call register resulted from isolated technical failures and referred to their contracts, opt-out procedures, staff training and quality-control measures. The DPA requested explanations from the controller and the processors. In their submissions, they argued, among other things, that the calls were linked to existing customer relationships and were intended to provide contractual or regulatory information, assess customer satisfaction or improve service quality rather than promote products. They also maintained that the calls made to numbers included in the do-not-call register resulted from isolated technical failures and referred to their contracts, opt-out procedures, staff training and quality-control measures. === Holding === === Holding === Regarding the controller, the DPA held that it was responsible for determining the purposes of the processing and the essential means by which the telephone calls were carried out. It was therefore required to provide its processors with appropriate tools and instructions, ensure the effective consolidation of the applicable opt-out registers and adequately supervise the processors’ compliance. Regarding the controller, the DPA held that it was responsible for determining the purposes of the processing and the essential means by which the telephone calls were carried out. It was therefore required to provide its processors with appropriate tools and instructions, ensure the effective consolidation of the applicable opt-out registers and adequately supervise the processors’ compliance. Line 155: Line 153: The DPA also examined the provided information relating to the Air Miles programme. It found that the policy did not clearly distinguish the relevant purposes and legal bases, used broad descriptions of the processing activities, did not explain how data accuracy would be maintained, failed to specify concrete retention periods and provided insufficiently clear information regarding the right to erasure. The DPA also examined the provided information relating to the Air Miles programme. It found that the policy did not clearly distinguish the relevant purposes and legal bases, used broad descriptions of the processing activities, did not explain how data accuracy would be maintained, failed to specify concrete retention periods and provided insufficiently clear information regarding the right to erasure. The DPA fined the controller €190,000 for the infringement of [[Article 32 GDPR|Article 32 GDPR]], €230,000 for the infringement of Article 11 of Law 3471\u002F2006 and €130,000 for the infringement of [[Article 5 GDPR|Article 5 GDPR]]. It also ordered the controller, within six months, to amend its agreements with the processors by introducing explicit technical instructions, improve its technical and organisational procedures and establish a procedure for auditing the cooperating call centres. The DPA fined the controller €190,000 for the infringement of [[Article 32 GDPR]], €230,000 for the infringement of Article 11 of Law 3471\u002F2006 and €130,000 for the infringement of [[Article 5 GDPR]]. It also ordered the controller, within six months, to amend its agreements with the processors by introducing explicit technical instructions, improve its technical and organisational procedures and establish a procedure for auditing the cooperating call centres. Regarding processor A, the DPA found that it relied on manual procedures to remove telephone numbers from calling lists. This increased the risk of human error and did not provide reliable evidence of who had recorded an objection or when the relevant change had been made. It held that processor A therefore infringed [[Article 32 GDPR|Article 32 GDPR]] and fined it €20,000. Regarding processor A, the DPA found that it relied on manual procedures to remove telephone numbers from calling lists. This increased the risk of human error and did not provide reliable evidence of who had recorded an objection or when the relevant change had been made. It held that processor A therefore infringed [[Article 32 GDPR]] and fined it €20,000. In addition, the DPA determined that processor A was also involved in a call presented as a customer-satisfaction survey during which a programme offered by the controller was mentioned. The DPA considered that the call included a direct commercial offer and therefore fell within Article 11 of Law 3471\u002F2006, since it was directed to a subscriber who had opted out of marketing calls and imposed a €40,000 fine. In addition, the DPA determined that processor A was also involved in a call presented as a customer-satisfaction survey during which a programme offered by the controller was mentioned. The DPA considered that the call included a direct commercial offer and therefore fell within Article 11 of Law 3471\u002F2006, since it was directed to a subscriber who had opted out of marketing calls and imposed a €40,000 fine. As regards processor B, the DPA found that its systems had produced mismatches between the controller’s customer lists and the applicable opt-out registers, resulting in calls being made to numbers that should have been excluded. The DPA considered that this demonstrated insufficient automation and a possible absence of complete records documenting the checks performed before each call. It concluded that processor B violated [[Article 32 GDPR|Article 32 GDPR]] and imposed a €50,000 fine. It also fined €40,000 processor B for violating [[Article 5 GDPR|Article 5 GDPR]] due to the shortcomings identified in the processing relating to the Air Miles programme. As regards processor B, the DPA found that its systems had produced mismatches between the controller’s customer lists and the applicable opt-out registers, resulting in calls being made to numbers that should have been excluded. The DPA considered that this demonstrated insufficient automation and a possible absence of complete records documenting the checks performed before each call. It concluded that processor B violated [[Article 32 GDPR]] and imposed a €50,000 fine. It also fined €40,000 processor B for violating [[Article 5 GDPR]] due to the shortcomings identified in the processing relating to the Air Miles programme. Regarding processor C, the DPA pointed out that the method it used for the updates of its opt-out lists, created a gap between the submission of an objection and its addition to the updated list, during which the person could still receive a call. It therefore found the procedure insufficient under [[Article 32 GDPR|Article 32 GDPR]] and fined €45,000 processor C. Regarding processor C, the DPA pointed out that the method it used for the updates of its opt-out lists, created a gap between the submission of an objection and its addition to the updated list, during which the person could still receive a call. It therefore found the procedure insufficient under [[Article 32 GDPR]] and fined €45,000 processor C. Furthermore, the DPA also examined a recording of a call made by processor C. Although the call was presented as a customer-satisfaction survey, the agent referred to a programme offering lower charges. The DPA therefore classified the call as a mixed-purpose communication falling within Article 11 of Law 3471\u002F2006. It also rejected the argument that the subsequent calls had been requested by the data subject, since that explanation was not supported by the call records or the recording. It imposed €55,000 a fine for this. Furthermore, the DPA also examined a recording of a call made by processor C. Although the call was presented as a customer-satisfaction survey, the agent referred to a programme offering lower charges. The DPA therefore classified the call as a mixed-purpose communication falling within Article 11 of Law 3471\u002F2006. It also rejected the argument that the subsequent calls had been requested by the data subject, since that explanation was not supported by the call records or the recording. It imposed €55,000 a fine for this. As regards processor D, the DPA found that it had used a subcontractor to carry out telephone calling activities without obtaining the controller’s prior specific or general written authorisation. It held that this was contrary to the applicable contractual terms and fined it €30,000 for breaching [[Article 28 GDPR|Article 28 GDPR]] and [[Article 29 GDPR|Article 29 GDPR]]. As regards processor D, the DPA found that it had used a subcontractor to carry out telephone calling activities without obtaining the controller’s prior specific or general written authorisation. It held that this was contrary to the applicable contractual terms and fined it €30,000 for breaching [[Article 28 GDPR]] and [[Article 29 GDPR]]. It further held that the technical and organisational measures governing its operations were outdated and incomplete. Processor D relied on manual exchanges of files and did not adequately address the risks associated with large-scale digital processing. Additionally, the DPA found that its subcontractor maintained separate calling lists outside the controller’s direct control. It fined €50,000 processor for violations of [[Article 32 GDPR|Article 32 GDPR]]. It further held that the technical and organisational measures governing its operations were outdated and incomplete. Processor D relied on manual exchanges of files and did not adequately address the risks associated with large-scale digital processing. Additionally, the DPA found that its subcontractor maintained separate calling lists outside the controller’s direct control. It fined €50,000 processor for violations of [[Article 32 GDPR]]. Moreover, the DPA ordered all processors to improve their technical procedures within six months. Moreover, the DPA ordered all processors to improve their technical procedures within six months.","Greece's Data Protection Authority (DPA) imposed a total fine of €880,000 on an energy supplier and four call-center companies for multiple GDPR and data privacy violations. The penalties stem from inadequate technical and organizational measures, mixed-purpose calls, insufficient oversight of processors, and unauthorized use of subcontractors. The DPA also cited issues with the Air Miles program's policy regarding data accuracy, retention periods, and the right to erasure.","Greece's DPA fines energy supplier and call centers €880,000 for GDPR violations.","Help HDPA (Greece) - 7\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 11:59, 28 July 2026 view sourceDs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators240 edits Tag: Decisions [1.0] Latest revision as of 08:10, 29 July 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators240 editsm Tag: Visual edit Line 128: Line 128: }}}} The DPA fined an energy supplier and four call-centre companies €880,000 in total for inadequate technical and organisational measures, mixed-purpose calls, insufficient processor oversight and unauthorised use of a subcontractor.The DPA fined an energy supplier and four call-centre operators €880,000 in total for inadequate technical and organisational measures, mixed-purpose calls, insufficient processor oversight and unauthorised use of a subcontractor. == English Summary ==== English Summary == Line 142: Line 142: The DPA requested explanations from the controller and the processors. In their submissions, they argued, among other things, that the calls were linked to existing customer relationships and were intended to provide contractual or regulatory information, assess customer satisfaction or improve service quality rather than promote products. They also maintained that the calls made to numbers included in the do-not-call register resulted from isolated technical failures and referred to their contracts, opt-out procedures, staff training and quality-control measures. The DPA requested explanations from the controller and the processors. In their submissions, they argued, among other things, that the calls were linked to existing customer relationships and were intended to provide contractual or regulatory information, assess customer satisfaction or improve service quality rather than promote products. They also maintained that the calls made to numbers included in the do-not-call register resulted from isolated technical failures and referred to their contracts, opt-out procedures, staff training and quality-control measures. === Holding ====== Holding === Regarding the controller, the DPA held that it was responsible for determining the purposes of the processing and the essential means by which the telephone calls were carried out. It was therefore required to provide its processors with appropriate tools and instructions, ensure the effective consolidation of the applicable opt-out registers and adequately supervise the processors’ compliance. Regarding the controller, the DPA held that it was responsible for determining the purposes of the processing and the essential means by which the telephone calls were carried out. It was therefore required to provide its processors with appropriate tools and instructions, ensure the effective consolidation of the applicable opt-out registers and adequately supervise the processors’ compliance. Line 155: Line 153: The DPA also examined the provided information relating to the Air Miles programme. It found that the policy did not clearly distinguish the relevant purposes and legal bases, used broad descriptions of the processing activities, did not explain how data accuracy would be maintained, failed to specify concrete retention periods and provided insufficiently clear information regarding the right to erasure. The DPA also examined the provided information relating to the Air Miles programme. It found that the policy did not clearly distinguish the relevant purposes and legal bases, used broad descriptions of the processing activities, did not explain how data accuracy would be maintained, failed to specify concrete retention periods and provided insufficiently clear information regarding the right to erasure. The DPA fined the controller €190,000 for the infringement of [[Article 32 GDPR|Article 32 GDPR]], €230,000 for the infringement of Article 11 of Law 3471\u002F2006 and €130,000 for the infringement of [[Article 5 GDPR|Article 5 GDPR]]. It also ordered the controller, within six months, to amend its agreements with the processors by introducing explicit technical instructions, improve its technical and organisational procedures and establish a procedure for auditing the cooperating call centres. The DPA fined the controller €190,000 for the infringement of [[Article 32 GDPR]], €230,000 for the infringement of Article 11 of Law 3471\u002F2006 and €130,000 for the infringement of [[Article 5 GDPR]]. It also ordered the controller, within six months, to amend its agreements with the processors by introducing explicit technical instructions, improve its technical and organisational procedures and establish a procedure for auditing the cooperating call centres. Regarding processor A, the DPA found that it relied on manual procedures to remove telephone numbers from calling lists. This increased the risk of human error and did not provide reliable evidence of who had recorded an objection or when the relevant change had been made. It held that processor A therefore infringed [[Article 32 GDPR|Article 32 GDPR]] and fined it €20,000. Regarding processor A, the DPA found that it relied on manual procedures to remove telephone numbers from calling lists. This increased the risk of human error and did not provide reliable evidence of who had recorded an objection or when the relevant change had been made. It held that processor A therefore infringed [[Article 32 GDPR]] and fined it €20,000. In addition, the DPA determined that processor A was also involved in a call presented as a customer-satisfaction survey during which a programme offered by the controller was mentioned. The DPA considered that the call included a direct commercial offer and therefore fell within Article 11 of Law 3471\u002F2006, since it was directed to a subscriber who had opted out of marketing calls and imposed a €40,000 fine. In addition, the DPA determined that processor A was also involved in a call presented as a customer-satisfaction survey during which a programme offered by the controller was mentioned. The DPA considered that the call included a direct commercial offer and therefore fell within Article 11 of Law 3471\u002F2006, since it was directed to a subscriber who had opted out of marketing calls and imposed a €40,000 fine. As regards processor B, the DPA found that its systems had produced mismatches between the controller’s customer lists and the applicable opt-out registers, resulting in calls being made to numbers that should have been excluded. The DPA considered that this demonstrated insufficient automation and a possible absence of complete records documenting the checks performed before each call. It concluded that processor B violated [[Article 32 GDPR|Article 32 GDPR]] and imposed a €50,000 fine. It also fined €40,000 processor B for violating [[Article 5 GDPR|Article 5 GDPR]] due to the shortcomings identified in the processing relating to the Air Miles programme.As regards processor B, the DPA found that its systems had produced mismatches between the controller’s customer lists and the applicable opt-out registers, resulting in calls being made to numbers that should have been excluded. The DPA considered that this demonstrated insufficient automation and a possible absence of complete records documenting the checks performed before each call. It concluded that processor B violated [[Article 32 GDPR]] and imposed a €50,000 fine. It also fined €40,000 processor B for violating [[Article 5 GDPR]] due to the shortcomings identified in the processing relating to the Air Miles programme. Regarding processor C, the DPA pointed out that the method it used for the updates of its opt-out lists, created a gap between the submission of an objection and its addition to the updated list, during which the person could still receive a call. It therefore found the procedure insufficient under [[Article 32 GDPR|Article 32 GDPR]] and fined €45,000 process","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=HDPA_(Greece)_-_7\u002F2026&diff=52532&oldid=52514","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F4\u002F49\u002FLogoGR.jpg","2026-07-29T08:10:00+00:00","2026-07-29T10:00:47.245529+00:00",7,[18],{"name":19,"type":20},"HDPA","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":21,"icon":23,"name":24,"slug":25},null,"Policy","policy",[27,32,37],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":38},{"id":39,"icon":23,"name":40,"slug":41},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]