Back to Feed
PolicyJul 28, 2026

HDPA (Greece) - 7/2026

Greek DPA fines energy supplier and call centers €880K for GDPR violations.

Summary

The Greek Data Protection Authority (HDPA) has imposed a total fine of €880,000 on DEI, an energy supplier, and four call-center companies. The penalties stem from violations including inadequate technical and organizational measures, mixed-purpose calls, insufficient oversight of processors, and unauthorized use of subcontractors. Complaints arose from data subjects receiving promotional calls despite being on opt-out registers or having requested no further contact.

Full text

Help HDPA (Greece) - 7/2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 11:59, 28 July 2026 view source Ds (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators227 edits Tag: Decisions [1.0] (No difference) Latest revision as of 11:59, 28 July 2026 HDPA - 7/2026 Authority: HDPA (Greece) Jurisdiction: Greece Relevant Law: Article 5(1)(a) GDPR Article 5(1)(b) GDPR Article 5(1)(d) GDPR Article 5(1)(e) GDPR Article 28 GDPR Article 29 GDPR Article 32 GDPR Article 11 L. 3471/2006 Type: Complaint Outcome: Upheld Started: Decided: 02.06.2026 Published: Fine: 880000.0 EUR Parties: DEI S.A. Service 800 Teleperformance Single-Member S.A. for the Provision of Services CQS Customer-Centric Services S.A. Mediatel Telephone Information Services S.A. Prelude Group Limited Partnership National Case Number/Name: 7/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Greek, Modern (1453-) Original Source: HDPA (in ) Initial Contributor: ds The DPA fined an energy supplier and four call-centre companies €880,000 in total for inadequate technical and organisational measures, mixed-purpose calls, insufficient processor oversight and unauthorised use of a subcontractor. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The Greek DPA (HDPA) received twelve complaints filed against DEI, the Greek Public Power Corporation, (the controller) from telephone subscribers (data subjects) regarding the receipt of telephone calls for the purpose of promoting its products and services. The controller had outsourced the telephone calls to four call-centre companies acting as processors: CQS S.A. (Processor A), Teleperformance (Processor B), Mediatel (Processor C) and Prelude Group (Processor D). Processor D stated that it had used the services of INFOBELL (subcontractor) for the operation of its outbound calling system. The controller stated that its processors made approximately two million calls per year to provide contract-related information and conduct customer-satisfaction surveys, as well as around 50,000 promotional calls per month. The complaints concerned calls made on the controller’s behalf relating to billing and tariff information, the expiry of electricity supply contracts, customer-satisfaction surveys and other products or services. One complaint concerned an Air Miles programme, through which customers could collect airline miles. Several data subjects had either registered their telephone numbers in the national opt-out register or had expressly asked not to be contacted again. Under Article 11 of Greek Law 3471/2006, telephone subscribers may register their numbers in a national do not call register to indicate that they do not wish to receive unsolicited marketing calls. In two cases, the controller acknowledged that calls had been made to numbers included in the Greek Do Not Call register and attributed this to a technical malfunction in the process used to compare and exclude telephone numbers from the calling lists. In another case, a request not to receive further calls was processed eleven days after it was first submitted. The case file also concerned calls described by the controller and the processors as informational or as surveys regarding customer-satisfaction, during which lower-rate tariffs, e-billing or other programmes offered by the controller were mentioned. One data subject submitted recordings obtained through an access request, which documented a call involving both a customer-satisfaction survey and information about a programme offering lower charges. The DPA requested explanations from the controller and the processors. In their submissions, they argued, among other things, that the calls were linked to existing customer relationships and were intended to provide contractual or regulatory information, assess customer satisfaction or improve service quality rather than promote products. They also maintained that the calls made to numbers included in the do-not-call register resulted from isolated technical failures and referred to their contracts, opt-out procedures, staff training and quality-control measures. Holding Regarding the controller, the DPA held that it was responsible for determining the purposes of the processing and the essential means by which the telephone calls were carried out. It was therefore required to provide its processors with appropriate tools and instructions, ensure the effective consolidation of the applicable opt-out registers and adequately supervise the processors’ compliance. Moreover, it found that the controller did not have a unified, automated and fully traceable mechanism for managing the different opt-out registers. Instead, it maintained separate subsystems that could lead to discrepancies or delays. The available arrangements also lacked complete audit trails capable of showing who had carried out a call, when a number had been checked and which data had been accessed or modified. The DPA considered that the controller relied mostly on manual or administrative supervision instead of technical monitoring. The DPA further found that the controller’s agreements with its processors were insufficient to ensure the implementation of appropriate technical and organisational measures. The contracts did not contain specific periodic audits, continuous assessment mechanisms or measurable compliance requirements. They also lacked sufficiently detailed provisions regarding evidence of compliance, the prior approval of subprocessors, voice-transmission encryption, protection against internal threats and backup procedures. Regarding certain calls described as customer-satisfaction surveys or as information about energy prices, the DPA held that such calls would fall outside the rules on unsolicited marketing only where they remained strictly limited to matters affecting the existing contractual relationship. The DPA found that the calls were not limited to providing information or conducting customer-satisfaction surveys, but also included direct commercial offers aimed at retaining customers or promoting new products. It therefore characterised them as “mixed-purpose” calls, in which the provision of information served as a pretext for making offers without first checking the opt-out register. The DPA concluded that these were not isolated incidents but a systematic and established practice, as the controller stated that the agents followed predefined scripts and did not act on their own initiative. The calls therefore fell within Article 11 of Law 3471/2006. The DPA also examined the provided information relating to the Air Miles programme. It found that the policy did not clearly distinguish the relevant purposes and legal bases, used broad descriptions of the processing activities, did not explain how data accuracy would be maintained, failed to specify concrete retention periods and provided insufficiently clear information regarding the right to erasure. The DPA fined the controller €190,000 for the infringement of Article 32 GDPR, €230,000 for the infringement of Article 11 of Law 3471/2006 and €130,000 for the infringement of Article 5 GDPR. It also ordered the controller, within six months, to amend its agreements with the processors by introducing explicit technical instructions, improve its technical and organisational procedures and establish a procedure for auditing the cooperating call centres. Regarding processor A, the DPA found that it relied on manual procedures to remove telephone numbers from calling lists. This increased the risk of human error and did not provide reliable evidence of who had recorded an objection or when the relevant change had been made. It held that processor A therefore infringed Article 32 GDPR and fined it €20,000. In addition, the DPA determined that proc

Entities

DEI S.A. (vendor)Teleperformance (vendor)CQS Customer-Centric Services S.A. (vendor)Mediatel Telephone Information Services S.A. (vendor)Prelude Group Limited Partnership (vendor)