HDPA (Greece) - 7/2026
Greek DPA fines energy supplier and call centers €880K for GDPR violations.
Summary
The Greek Data Protection Authority (HDPA) has fined DEI, a Greek energy supplier, and four call-center operators a total of €880,000. The violations include inadequate technical and organizational measures, mixed-purpose calls, insufficient oversight of processors, and unauthorized use of a subcontractor. Complaints arose from data subjects receiving promotional calls despite being on the national opt-out register or having previously requested not to be contacted.
Full text
Help HDPA (Greece) - 7/2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 08:10, 29 July 2026 view sourceDs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators277 editsm Tag: Visual edit← Older edit Latest revision as of 06:41, 23 September 2026 view source Sfl (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators589 editsm Tag: Visual edit Line 13: Line 13: |Original_Source_Name_1=HDPA|Original_Source_Name_1=HDPA |Original_Source_Link_1=https://www.dpa.gr/sites/default/files/2026-07/7_2026%20anonym.pdf|Original_Source_Link_1=https://www.dpa.gr/sites/default/files/2026-07/7_2026%20anonym.pdf |Original_Source_Language_1=Greek, Modern (1453-)|Original_Source_Language_1=Greek |Original_Source_Language__Code_1=|Original_Source_Language__Code_1= Latest revision as of 06:41, 23 September 2026 HDPA - 7/2026 Authority: HDPA (Greece) Jurisdiction: Greece Relevant Law: Article 5(1)(a) GDPR Article 5(1)(b) GDPR Article 5(1)(d) GDPR Article 5(1)(e) GDPR Article 28 GDPR Article 29 GDPR Article 32 GDPR Article 11 L. 3471/2006 Type: Complaint Outcome: Upheld Started: Decided: 02.06.2026 Published: Fine: 880000.0 EUR Parties: DEI S.A. Service 800 Teleperformance Single-Member S.A. for the Provision of Services CQS Customer-Centric Services S.A. Mediatel Telephone Information Services S.A. Prelude Group Limited Partnership National Case Number/Name: 7/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Greek Original Source: HDPA (in ) Initial Contributor: ds The DPA fined an energy supplier and four call-centre operators €880,000 in total for inadequate technical and organisational measures, mixed-purpose calls, insufficient processor oversight and unauthorised use of a subcontractor. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The Greek DPA (HDPA) received twelve complaints filed against DEI, the Greek Public Power Corporation, (the controller) from telephone subscribers (data subjects) regarding the receipt of telephone calls for the purpose of promoting its products and services. The controller had outsourced the telephone calls to four call-centre companies acting as processors: CQS S.A. (Processor A), Teleperformance (Processor B), Mediatel (Processor C) and Prelude Group (Processor D). Processor D stated that it had used the services of INFOBELL (subcontractor) for the operation of its outbound calling system. The controller stated that its processors made approximately two million calls per year to provide contract-related information and conduct customer-satisfaction surveys, as well as around 50,000 promotional calls per month. The complaints concerned calls made on the controller’s behalf relating to billing and tariff information, the expiry of electricity supply contracts, customer-satisfaction surveys and other products or services. One complaint concerned an Air Miles programme, through which customers could collect airline miles. Several data subjects had either registered their telephone numbers in the national opt-out register or had expressly asked not to be contacted again. Under Article 11 of Greek Law 3471/2006, telephone subscribers may register their numbers in a national do not call register to indicate that they do not wish to receive unsolicited marketing calls. In two cases, the controller acknowledged that calls had been made to numbers included in the Greek Do Not Call register and attributed this to a technical malfunction in the process used to compare and exclude telephone numbers from the calling lists. In another case, a request not to receive further calls was processed eleven days after it was first submitted. The case file also concerned calls described by the controller and the processors as informational or as surveys regarding customer-satisfaction, during which lower-rate tariffs, e-billing or other programmes offered by the controller were mentioned. One data subject submitted recordings obtained through an access request, which documented a call involving both a customer-satisfaction survey and information about a programme offering lower charges. The DPA requested explanations from the controller and the processors. In their submissions, they argued, among other things, that the calls were linked to existing customer relationships and were intended to provide contractual or regulatory information, assess customer satisfaction or improve service quality rather than promote products. They also maintained that the calls made to numbers included in the do-not-call register resulted from isolated technical failures and referred to their contracts, opt-out procedures, staff training and quality-control measures. Holding Regarding the controller, the DPA held that it was responsible for determining the purposes of the processing and the essential means by which the telephone calls were carried out. It was therefore required to provide its processors with appropriate tools and instructions, ensure the effective consolidation of the applicable opt-out registers and adequately supervise the processors’ compliance. Moreover, it found that the controller did not have a unified, automated and fully traceable mechanism for managing the different opt-out registers. Instead, it maintained separate subsystems that could lead to discrepancies or delays. The available arrangements also lacked complete audit trails capable of showing who had carried out a call, when a number had been checked and which data had been accessed or modified. The DPA considered that the controller relied mostly on manual or administrative supervision instead of technical monitoring. The DPA further found that the controller’s agreements with its processors were insufficient to ensure the implementation of appropriate technical and organisational measures. The contracts did not contain specific periodic audits, continuous assessment mechanisms or measurable compliance requirements. They also lacked sufficiently detailed provisions regarding evidence of compliance, the prior approval of subprocessors, voice-transmission encryption, protection against internal threats and backup procedures. Regarding certain calls described as customer-satisfaction surveys or as information about energy prices, the DPA held that such calls would fall outside the rules on unsolicited marketing only where they remained strictly limited to matters affecting the existing contractual relationship. The DPA found that the calls were not limited to providing information or conducting customer-satisfaction surveys, but also included direct commercial offers aimed at retaining customers or promoting new products. It therefore characterised them as “mixed-purpose” calls, in which the provision of information served as a pretext for making offers without first checking the opt-out register. The DPA concluded that these were not isolated incidents but a systematic and established practice, as the controller stated that the agents followed predefined scripts and did not act on their own initiative. The calls therefore fell within Article 11 of Law 3471/2006. The DPA also examined the provided information relating to the Air Miles programme. It found that the policy did not clearly distinguish the relevant purposes and legal bases, used broad descriptions of the processing activities, did not explain how data accuracy would be maintained, failed to specify concrete retention periods and provided insufficiently clear information regarding the right to erasure. The DPA fined the controller €190,000 for the infringement of Article 32 GDPR, €230,000 for the infringement of Article 11 of Law 3471/2006 and €130,000 for the infringement of Article 5 GDPR. It also ordered the controller, within six months, to amend its agreements with the p
Indicators of Compromise
- url — https://www.dpa.gr/sites/default/files/2026-07/7_2026%20anonym.pdf